[01:06.120 --> 01:07.260] Hello again, everyone. [01:07.800 --> 01:09.000] One more, another talk. [01:09.280 --> 01:10.460] So this is going to be an exciting one. [01:10.500 --> 01:13.100] I think I'm super excited to see this one. [01:14.300 --> 01:16.540] As always, a couple of housekeeping things. [01:16.900 --> 01:18.840] The talk that was scheduled for 10 p.m. [01:19.200 --> 01:23.820] tonight, the social steganography talk will not be tonight. [01:23.900 --> 01:25.200] It will be tomorrow morning at 10 a.m. [01:25.720 --> 01:29.240] In place of that tonight, we'll have a medical device with security and privacy issues. [01:29.380 --> 01:32.840] He's dead, Jim, not really talk here in 206 at 10 o'clock tonight. [01:33.000 --> 01:34.360] So come by if you can. [01:34.560 --> 01:37.180] I know it competes with our other event, Hackers Got Talent. [01:37.320 --> 01:41.040] But if you can come in and support our speakers, that would be fantastic. [01:41.580 --> 01:43.780] Although I know Hackers Got Talent could be quite interesting. [01:43.900 --> 01:46.720] If you want to go to Hackers Got Talent, you don't have to sign up. [01:46.860 --> 01:50.340] Just show up, show off your talent, and maybe you'll win something. [01:51.520 --> 01:53.440] Workshop helpers are needed for tomorrow. [01:53.440 --> 02:02.400] So if you are interested in being a workshop helper and volunteering for the last day, just stop down at the info desk or reach out to Mitch over the Matrix chat and let him know that you would like to help. [02:03.280 --> 02:05.380] Please keep your phone muted during the presentation. [02:05.600 --> 02:10.840] The audio equipment is quite sensitive and it picks up pretty much anything that you would hear in the room. [02:11.200 --> 02:13.960] So with that, let's go ahead and jump into the talk. [02:14.080 --> 02:15.220] Cat-shaped hacker hardware. [02:15.400 --> 02:19.400] How I'd Accidentally Made a Business at 18 by Alex Lind. [02:20.180 --> 02:21.360] Thank you for introducing me. [02:23.360 --> 02:24.100] Hey, everyone. [02:24.380 --> 02:29.940] So today I'm going to be telling you guys the story of how I accidentally made a hardware business at 18. [02:30.140 --> 02:31.160] Thank you guys for coming. [02:31.300 --> 02:37.620] This is my first talk at the HOPE conference and actually my first hacker conference and my first talk. [02:37.720 --> 02:38.880] So this is all very new to me. [02:43.080 --> 02:44.480] My name is Alex Lind. [02:44.680 --> 02:48.800] I'm an open source hardware developer and also a cyber security content creator. [02:49.180 --> 02:57.740] Over the past year, I've been creating cyber security content for the YouTube show and also cyber security vendor Hak5. [02:57.740 --> 03:10.700] I generally create educational tutorials focusing on things like how to use basic hacking tools, hardware hacking tools, and also some other things in a similar vein to that. [03:10.700 --> 03:21.080] This has been a pretty great gig for me since I only recently started exploring more cyber security and infosec related stuff. [03:21.080 --> 03:22.820] So, oh, I guess I'm not presenting. [03:26.610 --> 03:27.090] Yes. [03:33.720 --> 03:34.900] Just a sec here. [03:35.120 --> 03:35.300] Cool. [03:42.490 --> 03:42.970] Okay. [03:42.970 --> 03:46.130] So, I'm an open source hardware developer and cyber security content creator. [03:46.370 --> 03:53.250] I've been creating content mostly on the Hak5 show where I create educational tutorials and walkthroughs for beginners. [03:54.550 --> 03:56.110] So this has been pretty great for me. [03:56.290 --> 04:05.310] I've been able to teach myself new things and also give back to the community and sort of walk people through the process as myself am learning about some of these things. [04:08.370 --> 04:17.390] I come from mostly a background of hardware and software, but over the course of the past year, I've been teaching myself more cyber security and infosec related stuff. [04:17.630 --> 04:21.930] And I've sort of been using all these skills in order to develop the product that I'm going to be showing you guys today. [04:22.570 --> 04:27.470] So my specialty is mostly with low cost microcontrollers and also embedded systems. [04:27.970 --> 04:30.430] I have done things like designed IoT products. [04:30.430 --> 04:34.950] I've created stuff around platforms like Arduino and Espressif. [04:35.310 --> 04:35.830] that kind of thing. [04:36.110 --> 04:42.190] And my focus is mostly on sustainable design and signals intelligence, which are two things that really pique my interest. [04:43.630 --> 04:45.190] Microcontrollers in particular are really cool. [04:45.370 --> 04:46.890] I like that they're low cost and they're cheap. [04:47.150 --> 04:56.410] And I like finding ways to hack and break stuff with them and also find new ways to push their boundaries to do things, which is what we're going to be looking at in my project here today. [05:01.130 --> 05:02.270] What are my hobbies? [05:03.230 --> 05:11.010] So as it turns out, I created this presentation last night and my friend Cody helped me fill out some of the slides. [05:11.530 --> 05:18.190] So some of my favorite hobbies and pastimes include rootin', tootin', shootin' and repping the great treasure state of Montana. [05:20.610 --> 05:21.730] So thank you, Cody. [05:24.050 --> 05:33.050] I'm going to give you guys my backstory in just a little bit and tell you guys how I ended up in the great treasure state and also how I came to undertake some of these hobbies. [05:33.370 --> 05:38.810] But when I'm not rootin', tootin' and shootin', you can usually find me skateboarding or practicing piano. [05:38.950 --> 05:41.330] Those are some of my other hobbies. [05:41.330 --> 05:44.410] And here you can see when I met my hero, Bigfoot. [05:49.080 --> 05:50.600] So what is this presentation about? [05:50.820 --> 06:00.100] So I'm going to first give you guys some context and also sort of some insight to where I came from and how I got where I am today. [06:00.320 --> 06:13.320] I'm going to talk to you guys about the ideation and the creation process of the hardware tool called the Nugget, which is what my business is about. [06:13.320 --> 06:21.920] I'm going to talk about how I scaled this project into large-scale production and how we also started selling this through a renowned cybersecurity vendor, which is Hak5. [06:22.280 --> 06:25.840] I'm also going to tell you guys about some mistakes that I made in this process. [06:26.220 --> 06:33.660] So hopefully if any of you are developers or makers, you can learn from this and not make the same mistakes that I did. [06:36.660 --> 06:38.180] So what is the Nugget? [06:38.560 --> 06:45.560] So the Nugget is a cat-shaped board that we designed as a tool for beginners to teach them about various hacking topics. [06:45.900 --> 06:53.800] So here you can see a picture of actually a naked Nugget and its enclosure slash case next to it. [06:53.980 --> 07:00.180] But this is the cat-shaped board that we've been working on developing the past year, me and my friend Cody, who's in the audience. [07:00.920 --> 07:04.560] Currently we have two splits and variations of this product. [07:04.560 --> 07:08.720] We have a version that's for teaching people about USB hacking. [07:09.140 --> 07:12.300] So stuff like keystroke injection, HID attacks, that kind of thing. [07:12.740 --> 07:17.120] And then we also have a version of the board that's designed to teach beginners about Wi-Fi hacking. [07:17.960 --> 07:22.680] So my friend Cody's background is also in low-cost microcontrollers. [07:22.800 --> 07:26.560] He's also interested in signals intelligence and Wi-Fi hacking and that kind of thing. [07:26.780 --> 07:30.540] So this was a great overlap for us and this is why we chose these two topics. [07:30.540 --> 07:32.540] So we find this particularly interesting. [07:33.440 --> 07:37.640] But besides that, the Nugget is also a great beginner soldering kit. [07:37.900 --> 07:39.240] It's mostly through-hole components. [07:39.380 --> 07:41.180] There's also some surface mount components. [07:42.660 --> 07:44.920] And it's also a great beginner programming tool. [07:45.100 --> 07:50.180] So actually the other week in Los Angeles I hosted a beginner soldering workshop featuring the Nugget. [07:50.300 --> 07:57.820] From time to time we host different workshops in different areas depending on what it is. [07:57.820 --> 07:59.580] It's sort of kind of a multi-tool Wii. [08:00.460 --> 08:04.860] It covers like a wide preview of things like USB hacking, Wi-Fi hacking, soldering, that kind of thing. [08:05.080 --> 08:07.220] So yeah, let's dive right in. [08:07.980 --> 08:10.220] So first I'm going to give you guys some context about myself. [08:12.500 --> 08:14.340] I'm going to go ahead and get started with that. [08:15.680 --> 08:17.360] So let's start off with my story. [08:17.640 --> 08:19.040] How did I get started with hacking? [08:19.300 --> 08:27.740] So sometime around five years ago when I was in middle school, we were issued Texas instrument calculators. [08:28.040 --> 08:32.780] And if there was anything I wanted to do in math class, it sure as hell wasn't math. [08:32.940 --> 08:35.120] So I taught myself how to program using these calculators. [08:36.600 --> 08:39.820] Using a built-in language, a built-in interpreted language on the calculator. [08:40.080 --> 08:44.820] And I got started with programming by teaching myself how to code video games. [08:46.100 --> 08:52.080] And eventually started selling it to kids at school so they also wouldn't have to pay attention in dreadful math class. [08:52.080 --> 08:54.380] So that's how I got started with programming. [08:54.620 --> 08:58.260] And I eventually taught myself how to hack when I wasn't satisfied enough with that. [08:58.400 --> 09:09.120] I started taking apart my calculator, I taught myself assembly, and I started doing hardware modifications to it so I could do crazy stuff like overclock it, add built-in Wi-Fi, and a whole bunch of other crazy stuff like that. [09:09.920 --> 09:21.240] Eventually, going into high school, like every beginner, I learned about the two basic hardware platforms, which were Arduino and Raspberry Pi, and those really piqued my interest. [09:21.520 --> 09:32.700] So I taught myself how to use that, I learned a little bit about Linux, and I eventually went down the rabbit hole of learning how to use Kali Linux and that kind of thing for nefarious purposes. [09:33.820 --> 09:36.560] So at the time, I was basically a complete beginner to this. [09:38.060 --> 09:44.580] And I went through the process, or I went through the struggle rather, of trying to find great documentation on some of the stuff that I was trying to learn. [09:45.080 --> 09:53.460] So once I eventually figured out some of the stuff that I was trying to achieve, I figured there would probably be other beginners out there who are also trying to learn this kind of stuff. [09:53.500 --> 09:59.960] So I started creating YouTube videos and walkthroughs of various topics that I was struggling with. [10:01.080 --> 10:09.920] Once people started finding these useful, I started branching out into creating my own projects, some of which you can see here on my YouTube channel that I started. [10:10.380 --> 10:17.380] And I started developing an interest for lower-cost boards like Arduinos, microcontrollers, and that kind of thing. [10:17.660 --> 10:21.340] And that's sort of where I gained an interest for signals intelligence. [10:22.060 --> 10:23.820] So this is one of my very first projects. [10:24.940 --> 10:27.120] If you can see that over here, that's called the AuditPi. [10:27.220 --> 10:30.480] It was basically just a Raspberry Pi-based platform for signals intelligence. [10:31.120 --> 10:41.180] And then eventually I started working on some more complex projects using the Raspberry Pi for doing things like war skating and also detecting creeps, which I'll talk about in just a second here. [10:43.880 --> 10:45.120] So some of my work. [10:46.060 --> 10:49.560] One of the first projects that I worked on was called the Creep Detector. [10:50.380 --> 10:54.140] So I wish I included more pictures here, but I can give you a brief overview of what this was. [10:54.400 --> 10:56.780] This is one of the first projects that I ever did. [10:57.780 --> 11:00.800] And this was also my first signals intelligence-based projects. [11:01.420 --> 11:06.640] So the basic idea behind this was I wanted to find a way... [11:06.640 --> 11:10.260] Or rather the initial idea was how can we... [11:11.800 --> 11:13.020] Let me think how to put this. [11:15.500 --> 11:20.740] So the big idea behind this was how can you use war driving to track down someone that's stalking you. [11:21.620 --> 11:24.480] So this is my first signals intelligence project. [11:24.480 --> 11:28.040] It was Raspberry Pi based and it used a program called Kismet. [11:28.680 --> 11:38.940] Which is a war driving software that's used to gather Wi-Fi reconnaissance and basically let you create a map of where certain Wi-Fi devices are located in proximity to you. [11:39.340 --> 11:42.300] So I used a combination of different tools like Python. [11:42.640 --> 11:45.380] I used Linux utilities and stuff like that to sort of string this together. [11:45.980 --> 12:01.880] And I was able to create a successful proof of concept that let me determine if someone was stalking you by analyzing this data and seeing if the presence of certain devices like cell phones or laptops are detected at multiple GPS points in a certain path that you travel. [12:03.500 --> 12:06.360] Some of my other work... I didn't get to expand these into new slides. [12:07.140 --> 12:13.760] But these are some of my other projects that I've worked on related to signals intelligence and also some of my other interests like sustainability. [12:14.240 --> 12:20.280] The probe hunter was my first commissioned device that I created entirely using microcontrollers. [12:20.800 --> 12:30.840] So this was commissioned to me by a client who had a strange request to create a device to help him track down a cell phone that he lost in the forest. [12:31.300 --> 12:34.100] So the way I ended up solving this problem was pretty novel. [12:34.580 --> 12:37.180] We'll take a look at this more in just a second here. [12:37.940 --> 12:51.620] But I basically created a Wi-Fi device that looked for the emissions of a particular type of Wi-Fi packet called a probe frame, which is sent out by phones and laptops and other things like that when they're searching for previously connected Wi-Fi devices. [12:52.600 --> 13:08.740] I created a device that was able to sniff for that and basically look for the emissions of these particular types of Wi-Fi packets and I helped him create a device that was able to track down the physical presence of his cell phone even though it was turned off and lost in an arbitrary place. [13:09.520 --> 13:15.880] Pylar was another project that I started sometime in high school, which was basically an AI-powered composter. [13:16.760 --> 13:20.320] This was my first project doing full-stack embedded development. [13:20.540 --> 13:22.640] I created a web application for this. [13:22.860 --> 13:26.280] There was a combination of hardware involved and also software development. [13:26.280 --> 13:53.260] And then sometime towards the end of high school, I was commissioned with a crazy-ass project called Crypto for Gas where basically I was proposed to create a mesh network at gas stations that allows truckers to just roll in and automatically have their gas paid for using cryptocurrency so that way they wouldn't have to actually get out of their trucks. [13:53.260 --> 14:06.120] So this is a really interesting proof of concept that helped me really develop skills in really weird areas that all eventually tied together and helped me create the project that I'm going to be showing you guys in a little, which is the nugget. [14:06.520 --> 14:16.940] But I got to explore a lot of interesting things like mesh networking, various niche areas of the Wi-Fi protocol, hardware development, and stuff like that. [14:21.250 --> 14:34.650] So towards the end of high school, I had found at the very last minute that I was one of the only people in my class to have not applied to colleges towards the very end. [14:36.090 --> 14:44.670] So I was kind of in this weird gray area where I didn't really know what I wanted to do, but I was working on all these other projects that I had distracted myself with throughout all these years. [14:45.130 --> 14:47.290] And I realized that I didn't really want to go to college. [14:47.430 --> 14:49.770] I really didn't know what was right for me. [14:50.290 --> 14:55.410] And that also staying at home also wasn't an option for me because I didn't want to become complacent. [14:55.570 --> 14:57.810] And since my home life kind of sucked. [14:58.170 --> 14:59.250] So what did I do instead? [14:59.450 --> 15:02.830] I decided to start my own company, sort of. [15:02.830 --> 15:15.010] This ended up not going so great, but I started LIND Labs, which was basically just a little project where I started advertising some of the things I do. [15:15.130 --> 15:16.890] I showed people some of the projects I was working on. [15:16.970 --> 15:20.190] I received a few commissions, but it wasn't enough to sustain myself or move out. [15:21.110 --> 15:27.350] But at this point, one of my friends, Cody, said, Hey, why don't you come out here to Montana for a few weeks? [15:28.730 --> 15:32.490] And you can stack some video content, help create videos for us. [15:32.650 --> 15:35.270] At the time, he was working at Hak5. [15:35.550 --> 15:43.750] So he offered that I could come out there and make a couple videos, stack a little bit of money and then move back and decide what to do. [15:43.830 --> 15:44.930] So I thought, Oh, this is a great idea. [15:45.030 --> 15:45.730] Maybe I'll do that. [15:46.010 --> 15:50.730] And hopefully have a more elucidated or like clear path at that point. [15:50.730 --> 15:55.510] So I decided to come out there for two weeks over the summer to figure out what I wanted to do. [15:55.810 --> 16:02.570] But as a contingency plan, I also applied for community college, just in case. [16:04.030 --> 16:07.730] But then also, it happened to coincide with... [16:12.230 --> 16:14.210] Oh yeah, but then on top of that... [16:14.210 --> 16:16.210] Actually, I'm going to go ahead and move on to the next slide. [16:25.810 --> 16:27.530] So on top of moving out there... [16:28.970 --> 16:30.090] He also proposed... [16:30.910 --> 16:31.930] Sorry, I'll need a second. [16:38.610 --> 16:40.550] So on top of moving out there... [16:42.090 --> 16:48.870] At the time, my friend Cody was working on developing another hardware platform with one of his friends, which ended up not working out. [16:49.030 --> 16:54.830] So he had a bunch of extra microcontrollers and also components on hand that we needed to figure out what to do with. [16:54.830 --> 17:05.890] So I decided to help him out, since I had some experience developing hardware, to basically just create a kit or something like that to sell all of these extra components and basically take these off his hands. [17:06.790 --> 17:07.230] So... [17:07.230 --> 17:08.790] Just a... [17:10.230 --> 17:12.410] Spoiler alert of how this ended up turning out. [17:12.690 --> 17:15.170] Those two weeks ended up becoming a whole year. [17:16.690 --> 17:26.330] And this fun little project to get rid of some extra components that we had on hand and ended up turning into a high-intensity startup that now consumes most of our available time. [17:28.730 --> 17:35.090] And turned into this huge logistics game and also development game for us over the course of this past year, which I'll be telling you guys about. [17:36.710 --> 17:39.390] So this was the initial design that we came up with. [17:40.550 --> 17:46.450] So basically my friend had a stockpile of WiFi microcontrollers and also screens from a previous project. [17:48.830 --> 17:51.850] And we needed to figure out what to do with all of these components. [17:52.090 --> 17:55.330] So we created this design that we called the Hack Hat. [17:55.450 --> 17:58.070] We basically just slapped everything we had onto this board here. [17:58.270 --> 18:04.210] And we figured that eventually, at some point, we could come up with a more clear idea of what the product would actually do. [18:04.210 --> 18:08.010] But that, in the meantime, it would just support community-based products. [18:08.210 --> 18:10.230] And that it was a beginner soldering kit. [18:10.430 --> 18:12.050] So at this point, we actually... [18:14.530 --> 18:18.290] We worked with some other platforms before, like Arduino and that kind of thing. [18:18.450 --> 18:23.010] And we hosted some things like beginner soldering workshops. [18:23.350 --> 18:33.370] So just as an initial idea, we decided to create this little beginner soldering kit where people can throw on a screen, a microcontroller, and buttons into this Gameboy-esque form factor. [18:34.630 --> 18:37.990] Even though we didn't really have any software or anything to run on this. [18:39.350 --> 18:44.710] But just to sort of spice things up, we also made it Catboy themed, as you can see in this picture over here. [18:48.800 --> 18:51.980] So this is where we made our first mistake. [18:52.140 --> 18:53.400] So let's talk about this. [18:53.520 --> 18:57.120] So this section is called Why All-in-One Hardware Platforms Suck. [18:57.120 --> 19:01.040] This slide was initially titled Why Your All-in-One Hardware Platforms Suck. [19:01.180 --> 19:11.280] But after getting some feedback on this, some friends told me that was a little bit controversial since I'm sure at some point almost every maker has had the idea to create a hardware multi-tool. [19:11.420 --> 19:13.880] But that's the exact point that I want to address with this part here. [19:14.140 --> 19:17.840] This was the first mistake that we made with developing this product. [19:18.440 --> 19:25.840] So we basically jumped right in to just creating a hardware platform with no clear idea of what we wanted to do with it. [19:25.840 --> 19:43.820] But all we had was just a bunch of spare components on hand and we threw it onto this board and we decided, oh, since there's a bunch of free resources out there like Arduino, CircuitPython, and that kind of thing, we can create the hardware platform and basically just have people figure out what to do with this tool since there's already so many community resources available. [19:43.820 --> 19:47.700] And I have actually seen this play out a lot of times. [19:47.880 --> 20:03.860] I personally have friends who have tried to create platforms like this where they'll just create like a general multi-tool that's like a bunch of expansion kits or sensors or like that kind of thing and they expect people to figure out what to do with it based off community resources that are already out there. [20:04.060 --> 20:07.520] And that's the first big mistake that we made with developing this project. [20:09.220 --> 20:21.160] So the first reason why this is a bad idea is if you're developing a multi-tool or something that's trying to appeal to everyone, that doesn't really work out since you're really the only one who understands how this product works. [20:23.140 --> 20:31.140] The problem is if you're trying to sell this as an actual consumer product or something that people want to buy, if it's a multi-tool, people aren't really going to know what to do with it. [20:31.340 --> 20:36.140] They don't have a clear-cut idea and it's just hard to figure out. [20:36.240 --> 20:40.260] You can't really just throw this into people's hands and expect them to figure out what to do with it if it's a multi-tool. [20:40.780 --> 20:44.480] Like this random product that I found here that's supposed to be an all-in-one hardware platform. [20:44.680 --> 20:45.700] I don't know what the hell that's for. [20:47.520 --> 20:53.740] And also more issues come later down the line when you're actually trying to develop this into a full-fledged product. [20:53.740 --> 21:05.280] Because if everything is a feature, you can't really figure out what features need to be improved upon since there's just so much to manage and there's not really much room to improve. [21:07.060 --> 21:10.880] So let's take a look at the first failed product that I tried to create. [21:10.980 --> 21:13.140] This is probe hunter, which I talked a little bit about earlier. [21:14.180 --> 21:16.660] Hopefully I can elucidate a little more clearly what it does. [21:16.980 --> 21:20.380] So this was the very first device that I was commissioned. [21:20.380 --> 21:25.400] So basically some random person hit me up and said, Hey, I lost my cell phone in a forest. [21:25.540 --> 21:27.680] Do you have any idea how I can track this thing down? [21:28.240 --> 21:31.020] So at the time I knew a little bit about signals intelligence. [21:32.000 --> 21:34.540] And I knew a little bit about how the Wi-Fi protocol worked. [21:34.860 --> 21:37.380] So I said, alright, well basically your phone is locked. [21:37.500 --> 21:38.040] It's turned off. [21:38.200 --> 21:39.720] It's presumably somewhere out there. [21:40.340 --> 21:48.840] We can use Wi-Fi in order to track down this device by looking for a particular type of Wi-Fi packet that your phone will still be emitting even though it's off. [21:49.560 --> 21:52.160] And that type of Wi-Fi packet is called a probe request. [21:52.460 --> 22:01.420] So basically Wi-Fi devices when they're attempting to connect to previously joined networks they'll send out something called a probe request to look for these networks. [22:01.920 --> 22:04.240] They'll shout the names out and hope that they spot one of them. [22:04.520 --> 22:08.240] So I created this device that specifically sniffed for probe requests. [22:08.240 --> 22:09.200] I called it the probe hunter. [22:10.000 --> 22:15.360] And once it latched on to one of these requests, it used the signal strength... [22:15.360 --> 22:22.620] Or rather it would start tracking the signal strength and it used a directional antenna in order to pinpoint the exact location. [22:22.920 --> 22:25.520] So it was a pretty crazy proof of concept. [22:25.800 --> 22:32.280] Turns out the guy was able to use it to find lost cell phones that were in waterproof bags inside of a local river, which is interesting. [22:32.280 --> 22:36.160] And he ended up sending me my first cell phone because I was poor and didn't have a phone. [22:36.160 --> 22:36.940] So that was pretty cool. [22:39.320 --> 22:42.000] So that was the first project that I created. [22:44.600 --> 22:48.540] But eventually I decided that I wanted this to be more than just that. [22:48.640 --> 22:52.160] I wanted this to be a Wi-Fi multi-tool for doing a lot of other things. [22:52.280 --> 23:05.000] I wanted it to be able to do stuff like wardriving, general purpose Wi-Fi reconnaissance, and I also wanted it to be just a general purpose IoT multi-tool that can be used for really anything that's based off of Wi-Fi. [23:05.000 --> 23:11.040] So I started adding a bunch of bells and whistles and unnecessary features to it because I decided that that's what people would want. [23:12.100 --> 23:15.280] So I started slapping random things on there like an SD card reader. [23:15.440 --> 23:18.540] I slapped on a GPS and a bunch of other random features. [23:18.840 --> 23:23.680] And the issue with this was that it was trying to solve multiple unrelated problems in a single design. [23:23.680 --> 23:30.360] So once I started trying to actually sell this product, I got a lot of questions asking just like, what does it do? [23:30.680 --> 23:35.280] Because it was no longer for a single purpose and it was just really confusing as to what it's actually used for. [23:39.900 --> 23:45.020] That being said, modularity and extensibility aren't entirely discounted though. [23:46.400 --> 23:56.080] As I mentioned in a previous slide, since you are the only one who knows how this multi-tool works, if that's what you're working with, then you're the one who knows the ins and out of the features. [23:56.280 --> 24:00.460] And if you're working on projects that are just for yourself, then that's okay. [24:00.680 --> 24:02.920] Like for example, this was another project that I worked on. [24:02.920 --> 24:07.540] This is actually one of the prototypes for the crazy Crypto for Gas project. [24:08.000 --> 24:09.880] That I was also commissioned. [24:09.940 --> 24:24.960] Since the client didn't really care about the underlying hardware, I was able to use my crazy all-in-one IoT hardware platform, which was, as you can see, the exact same circuit board here is being used as one of these nodes. [24:25.100 --> 24:28.940] I was able to reuse that as the underlying hardware for this project. [24:29.380 --> 24:36.520] So in this case, this is okay, since I'm the only one who knew what was going on under the hood, and since the client didn't really care about that. [24:36.700 --> 24:38.860] It wasn't something that I was trying to sell to the general public. [24:39.060 --> 24:43.940] It was a specific application, and I was able to personally use this multi-tool. [24:44.160 --> 24:48.860] So in some cases, it's okay to add extensibility if it's for a personal project. [24:49.040 --> 24:49.640] That's what I found. [24:51.900 --> 24:58.080] So there were some design choices that I made, which serendipitously ended up working out great for me. [24:58.080 --> 25:00.660] in terms of the components that I selected. [25:01.020 --> 25:08.860] One of them, which ended up being persistently great, is this particular Wi-Fi microcontroller called the D1 Mini. [25:09.300 --> 25:14.020] So in the top here, you can see this little board that has a Wi-Fi chip attached to it. [25:14.100 --> 25:14.880] That's called the D1 Mini. [25:15.840 --> 25:20.780] So that's basically the Wi-Fi chip that I chose in order to unify all these projects. [25:20.960 --> 25:21.520] It's really great. [25:21.540 --> 25:22.080] It's small. [25:22.080 --> 25:25.840] It comes with a lot of plug-and-play modules like this SD card reader. [25:26.180 --> 25:31.160] They also have some other add-on sensors and stuff like that, that actually plug in directly to these boards. [25:31.520 --> 25:33.400] So when I was designing this... [25:33.400 --> 25:44.360] When I was designing these platforms with extensibility and modularity in mind, I chose this particular form factor since it offered me the most flexibility. [25:44.360 --> 25:53.900] And I thought like, oh, if other users pick up this platform and want to add more stuff to it, then this is the perfect form factor since they can slap on something like a micro SD card for saving data. [25:54.040 --> 25:56.540] They can slap on temperature sensors or other stuff like that. [25:59.940 --> 26:04.860] And it turns out this ended up being the base module that we used in the product that we're selling today. [26:05.440 --> 26:06.540] Just by complete chance. [26:07.360 --> 26:13.440] So let's look at the first case study of a company that actually gets the idea right. [26:13.440 --> 26:18.280] So first we're going to look at Hak5 products, which is where we're currently selling the Nugget product. [26:19.300 --> 26:26.920] So the reason why I think Hak5 has got their business model down right is each of their devices is single purpose. [26:27.080 --> 26:27.800] It's clear cut. [26:28.060 --> 26:33.760] And you can basically explain what each of them does in a one sentence elevator pitch. [26:33.960 --> 26:35.680] Like for example, the USB rubber ducky. [26:35.760 --> 26:38.020] It's an inconspicuous USB attack platform. [26:38.040 --> 26:39.040] It looks like a USB. [26:39.320 --> 26:42.100] You plug it into someone's computer since it just looks like a flash drive. [26:42.100 --> 26:45.060] But then it starts attacking them and runs keystrokes. [26:45.840 --> 26:47.080] You have the... [26:48.040 --> 26:49.460] I actually forget what that one's called. [26:49.920 --> 26:50.240] But basically... [26:50.880 --> 26:51.500] What was that? [26:51.660 --> 26:52.400] The land turtle? [26:53.220 --> 26:54.460] I don't think that one's the land turtle. [26:54.580 --> 26:56.160] I know the top one's the plunder bug. [26:56.320 --> 26:58.820] But that one's like a man in the middle for Ethernet. [26:58.960 --> 27:00.860] And then the bottom one I think is the packet squirrel. [27:01.500 --> 27:03.300] Which is used for also deploying packets. [27:03.580 --> 27:10.720] But basically Hak5 does this thing where they segment all of their products into different specific use cases. [27:10.720 --> 27:12.380] They have stuff for attacking Wi-Fi. [27:12.540 --> 27:13.640] They have stuff for USB attacks. [27:13.860 --> 27:14.280] That kind of thing. [27:14.760 --> 27:16.020] And I think they really get that right. [27:16.260 --> 27:22.220] Because when a beginner comes and sees these products, it's really easy for them to differentiate between them. [27:22.400 --> 27:24.520] And choose which one they need for their specific application. [27:24.960 --> 27:32.200] If you present them a multi-faceted multi-tool that's sort of ambiguous, they really won't know what the hell to do with it. [27:32.200 --> 27:35.320] They're gonna have a hard time understanding and coming up with their own ideas. [27:36.200 --> 27:37.500] When there's just so much to choose from. [27:37.720 --> 27:39.100] I think that's one thing that Hak5 gets right. [27:40.600 --> 27:44.480] And also just some insider information that we have about like Hak5 products. [27:44.880 --> 27:48.380] Under the hood, lots of them actually have almost the exact same hardware. [27:49.000 --> 28:09.400] But in order to sort of package this way, in order to sort of package these products in a way that customers can understand, they basically take that hardware, slap it into a new form factor, and then basically sell it with like a new big idea behind like what the product actually does. [28:11.940 --> 28:23.880] The second reason why I feel like all-in-one hardware platforms are kind of a bad idea is you need to decide the skill level that you're trying to appeal to. [28:24.320 --> 28:26.400] So there's basically three tiers of... [28:28.380 --> 28:29.860] Okay, I'll get to that in a second. [28:30.160 --> 28:31.760] There's basically three tiers of people. [28:31.880 --> 28:33.980] There's people who are beginners in the space. [28:34.120 --> 28:38.880] There's people who are kind of intermediate, they're tech literate, they're familiar with. [28:39.960 --> 28:41.280] Technical jargon, that kind of stuff. [28:41.460 --> 28:42.280] And then there's advanced people. [28:43.020 --> 28:49.420] When you're trying to sell to beginners, I find that if you're trying to sell them a multi-tool, they'll generally get lost, which I just mentioned. [28:49.920 --> 28:55.880] If you're trying to sell to advanced users, I find that generally they don't want multi-tools since they... [28:56.480 --> 29:01.080] Generally, there's a trade-off between functionality and how much stuff is actually packaged into one product. [29:01.600 --> 29:14.760] But typically, the kind of users that I see eating up or consuming these actual products are intermediate users who think they want an all-in-one tool but end up getting lost once they realize that they're hit with hard limitations. [29:15.980 --> 29:22.540] So let's look at an interesting device, which I'm sure some of you guys might have heard of, called the Flipper Zero. [29:23.080 --> 29:24.960] So this is a really novel product. [29:25.420 --> 29:34.120] It's essentially a multi-tool for exploring penetration testing or hardware testing with multiple different wireless protocols. [29:34.120 --> 29:37.040] So this is a really interesting device. [29:37.320 --> 29:43.240] There's been a lot of hype that's been built up around this over the course of, I think, maybe two or three years now. [29:43.800 --> 29:45.680] But this is a really cute form factor. [29:45.820 --> 29:54.000] It's a gamified device that's meant to allow people to hack and screw around with multiple types of wireless protocols. [29:55.440 --> 29:56.520] So this is really cool. [29:56.680 --> 29:57.240] It's really cute. [29:57.400 --> 29:58.420] It's beginner-friendly. [29:58.620 --> 30:02.620] It's something that you can pick up and understand pretty intuitively. [30:02.620 --> 30:08.300] One thing that I think they went wrong with was... [30:08.300 --> 30:10.940] Well, actually, they do have great developer documentation. [30:10.940 --> 30:18.360] But one thing that I think sort of left some users of this product disappointed was the fact that there's poor use case documentation. [30:18.780 --> 30:22.160] So essentially, they dumped this product into the hands of multiple customers. [30:23.980 --> 30:33.300] And I just find that a lot of beginners were actually kind of like shied away from using this product once they realized like they didn't actually know what to do with all of these capabilities. [30:34.020 --> 30:41.480] There's a lot of interesting features packed into this like stuff for sub-gigahertz hacking, radio... [30:42.700 --> 30:44.700] I forget what other frequencies are in there. [30:44.820 --> 30:46.840] I think there's like Wi-Fi, Bluetooth, and stuff like that. [30:47.280 --> 30:52.160] But it was a really novel idea to have this like all-in-one tool that could do a whole bunch of other attacks. [30:52.160 --> 30:56.340] Oh, yeah, there's also like RFID attacks, NFC, that kind of thing. [30:56.740 --> 31:05.500] And there are some proof of concepts out there where I've seen this used in situations for like opening up garage doors or like Tesla charging ports or cool stuff like that. [31:07.420 --> 31:11.820] But it's typically like more advanced users that are like figuring out how to do these hacks. [31:12.000 --> 31:17.200] And it just like falls completely deaf to like beginners who don't really know how to use this thing. [31:17.200 --> 31:21.780] So I found like some beginners that ended up with this product were a little bit disappointed. [31:27.480 --> 31:34.160] So we ended up not taking any of that advice because we didn't learn that at this point. [31:34.340 --> 31:38.960] So once we started developing our platforms... [31:38.960 --> 31:45.780] Once we started developing the Hack Hat platform, we personally found ourselves kind of lost and didn't really know what to do with it. [31:45.780 --> 31:51.120] So we had the grand idea of deciding to create more form factors. [31:51.580 --> 31:59.780] So in addition to creating the Hack Hat, we decided to also create this other board here called the Long Hat, which was basically a battery powered version. [32:00.360 --> 32:12.720] But we still faced the issue where both of these were just general multi-tools and we ended up creating a second iteration that was battery powered and portable and basically did nothing at this point. [32:13.420 --> 32:15.460] Except run community-based projects. [32:17.260 --> 32:26.500] And then we came up with a joke idea to repackage this platform into a small cat-shaped conference badge that people could just carry around on a lanyard or something like that. [32:27.040 --> 32:33.840] And we discovered an interesting project called the Wi-Fi DeAuthor, which is made by an independent maker called Space Hume. [32:34.060 --> 32:43.260] But basically this is a Wi-Fi hacking platform that runs on the Wi-Fi chip that we have on this board here. [32:43.660 --> 32:45.060] And we flashed it to our board. [32:45.200 --> 32:47.440] It worked with the built-in buttons. [32:47.500 --> 32:49.420] I should probably charge my laptop so it doesn't die. [32:52.220 --> 32:54.360] It worked with the built-in buttons that we had on here. [32:54.500 --> 33:00.760] And it was a pretty intuitive interface that lets you run Wi-Fi hacks and that kind of thing. [33:00.820 --> 33:01.660] And it was an instant hit. [33:01.800 --> 33:08.720] Once we started showing this off on Twitter and that kind of thing, people were really interested to see this packaged into a cat-shaped form factor. [33:09.420 --> 33:12.540] And people also found it really cool that this thing could be used for Wi-Fi hacking. [33:13.540 --> 33:24.400] So while this sort of ditched the initial idea of having like a beginner soldering kit since there were now some SMD components, the cat theme and cat-shaped board ended up being a hit. [33:24.460 --> 33:25.720] So we decided to focus on that. [33:28.640 --> 33:33.080] And this was also the initial ideation and the initial design for the product. [33:35.660 --> 33:47.100] And then also in the initial creation process, we went through quite a few interesting design choices like the Wi-Fi penis, which for obvious reasons ended up being rejected. [33:49.160 --> 33:55.580] So at this point, we had an interesting dichotomy, or I guess in this case, whatever three different boards are. [33:55.780 --> 33:58.620] So we had three different form factors for this product. [33:58.800 --> 34:01.080] We had the Wi-Fi nugget, the hat cat, and the long cat. [34:01.980 --> 34:05.180] And still no clear-cut purpose or goal for what these products would do. [34:05.320 --> 34:07.060] We figured, hey, we have a hardware platform. [34:07.400 --> 34:08.800] Let's put this in the hands of people. [34:08.960 --> 34:16.260] I guess they'll figure out what to do with it since there's already stuff that's out there that supports this, like Arduino and that kind of thing. [34:20.060 --> 34:25.800] So we identified... we eventually identified the need to come up with a big unifying idea to sell this product. [34:29.160 --> 34:31.080] And these are the reasons why. [34:32.020 --> 34:32.500] So... [34:33.980 --> 34:41.400] In order to have a big idea, and in order to actually sell this product, it comes down to four... [34:42.680 --> 34:47.240] I think basically four points that we've identified over the course of just experimenting the past year. [34:47.500 --> 34:52.040] You need a no-nonsense clear elevator pitch that you can use in order to explain what the product does. [34:52.040 --> 35:01.200] If you're telling someone this is a multi-tool that you can use for Wi-Fi hacking, for a beginner soldering kit, and for prototyping with electronics, that doesn't really fly. [35:01.360 --> 35:06.940] It needs to be able to stand on its own and have a more clear-cut goal, kind of like the Hak5 products that I pitched earlier. [35:07.240 --> 35:12.000] It needs to have cohesive branding and also something that makes it unique from competitors. [35:12.660 --> 35:18.360] So also another thing that I see falling flat sometimes is stuff like beginner soldering kits. [35:18.640 --> 35:24.060] That's something that we also learned very early on, marketing this as something that basically everything... [35:24.060 --> 35:26.440] Something that basically everyone else was trying to do. [35:26.660 --> 35:27.440] Didn't really fly. [35:27.680 --> 35:28.520] But the one... [35:29.160 --> 35:39.560] The one one-up that we had over other people that were trying to sell stuff was serendipitously the cat-themed and cat-shaped platform that we decided on. [35:42.310 --> 35:44.610] So the first month of... [35:50.670 --> 35:58.630] So now I'm gonna sort of delineate and walk you guys through the development cycle and also how we actually brought this product to market. [36:03.970 --> 36:04.990] Do you know if I have power? [36:05.210 --> 36:05.890] There's a little rep. [36:14.450 --> 36:22.470] So in the first month we quickly identified that keeping up with all three hardware platforms that we developed, even as cool and promising as they seemed, was a terrible idea. [36:22.650 --> 36:31.750] So the first thing we did was we decided to drop the other two platforms, the Hackat and the Longcat, since most people were interested in this cat-shaped board and since it seemed to have the most promise. [36:32.210 --> 36:38.330] So we doubled down on this and we decided we're different from all of our other competitors who are also making beginner soldering kits. [36:38.770 --> 36:41.010] What we have here is an absolute score. [36:41.130 --> 36:42.610] It's a beginner Wi-Fi multi-tool. [36:42.750 --> 36:43.290] It does everything. [36:43.430 --> 36:44.430] It's a beginner soldering kit. [36:44.990 --> 36:46.210] It does Wi-Fi hacking. [36:46.450 --> 36:47.630] You can do hardware development. [36:47.630 --> 36:48.650] You can program on it. [36:48.790 --> 36:49.310] Whatever you want. [36:50.850 --> 36:51.890] Terrible idea, by the way. [36:54.390 --> 37:04.750] So before we actually decided that we wanted to focus on the Nugget, we actually ran through a couple painstaking iterations of the other hardware platforms, the Hackat and the Longcat up here. [37:05.370 --> 37:09.150] Worked on some more designs where we sort of experimented with the form factor. [37:09.370 --> 37:12.010] We tried different breakout modules and stuff like that. [37:12.150 --> 37:15.410] But then eventually gave that up once we decided the Nugget was what we're sticking with. [37:16.090 --> 37:18.710] So come around to month two, we eventually... [37:21.550 --> 37:23.230] We made some improvements to the platform. [37:23.450 --> 37:25.790] We had a second version of the Nugget. [37:25.970 --> 37:30.610] And we sort of decided to lean into the Wi-Fi hacking aspects. [37:30.670 --> 37:33.770] And some people were interested in the de-author project that we were showing off. [37:34.290 --> 37:42.470] So on the Hak5 show, at this time I was already creating some beginner content for things like hacking with Linux tools and that kind of thing. [37:42.810 --> 37:46.430] And we decided to just show this off as a little project video on the show. [37:46.430 --> 37:51.790] And this is the first project that I did, which was detecting Wi-Fi attacks on the Wi-Fi Nugget. [37:51.970 --> 37:53.250] That's what we decided to call it. [37:54.470 --> 37:57.310] So turns out a lot of people were really interested in this. [37:57.490 --> 37:59.250] They liked the beginner demonstration. [37:59.250 --> 38:01.570] They liked the hardware that I was showing off. [38:04.530 --> 38:08.990] And we actually made our first sale within minutes of posting the video. [38:14.410 --> 38:19.150] Oh yeah, and then in terms of development, I started focusing on the... [38:19.150 --> 38:20.950] using it as a Wi-Fi hacking tool. [38:21.210 --> 38:27.370] While my friend Cody also simultaneously worked on developing more programming-oriented stuff with MicroPython. [38:28.110 --> 38:34.970] Somewhere around the third month of developing this product, we got a little more community feedback on this tool. [38:35.510 --> 38:36.930] It was in the hands of more people. [38:37.090 --> 38:39.670] I'd say somewhere around 100 people started using this thing. [38:40.810 --> 38:42.190] It still didn't really have... [38:42.190 --> 38:43.190] Let me check the tone. [38:44.610 --> 38:45.050] Oof. [38:48.550 --> 38:55.270] So we didn't really have our own idea for this project. [38:55.330 --> 38:57.530] We were still running community-based tools on this. [38:57.690 --> 39:02.530] But we started hosting our first few workshops around the LA area featuring this tool. [39:02.790 --> 39:04.330] It was still a multi-tool. [39:04.430 --> 39:06.770] So we were doing random things wherever we could. [39:06.870 --> 39:07.990] We were teaching Python with it. [39:08.070 --> 39:10.490] We were teaching Wi-Fi hacking and even soldering classes. [39:12.410 --> 39:15.690] Come around to month four of this project floating out there. [39:15.910 --> 39:17.630] We still didn't have our own independent software. [39:17.870 --> 39:29.610] But I was leaning more heavily into Wi-Fi hacking since it seemed that a lot of people were picking up on this particular subject and a lot of people were interested in a low-cost tool that could do that. [39:29.870 --> 39:37.010] Since typically, if you're getting started with Wi-Fi hacking or that kind of thing, you'll need a fancy setup on Linux. [39:37.010 --> 39:39.010] You'll need a Wi-Fi dongle or something like that. [39:39.010 --> 39:42.990] But with the board that we were selling, anybody could do it with a low-cost microcontroller. [39:43.150 --> 39:43.830] And it was also cute. [39:44.110 --> 39:49.530] And plus, we were programming beginner-friendly graphics and a little interface for it. [39:50.790 --> 39:57.670] But come around this time, both me and my friend were sort of developing this product in two different ways. [39:57.790 --> 40:02.230] I was focusing more on the hacking aspect, whereas my friend was taking it more towards a programming route. [40:02.890 --> 40:14.130] So my friend started looking into programming with MicroPython and CircuitPython to see where we could take it with beginners that were trying to get started with programming. [40:16.150 --> 40:27.510] And right at this time, the developers of the D1 Mini form factor happened to come out with a new form factor called the S2 Mini, which happened to be the exact same form factor in shape of our previous Wi-Fi module. [40:27.910 --> 40:33.050] But the thing is, this had some one-ups over the previous module in that it was faster at USB-C. [40:33.410 --> 40:36.430] It could... it was dual-core. [40:36.570 --> 40:38.210] It could run, like, a whole bunch of cool applications. [40:38.610 --> 40:43.150] And it supported a version of Python that was really cool called CircuitPython. [40:43.310 --> 40:46.150] Unfortunately, it didn't support Wi-Fi attacks, though. [40:49.360 --> 40:52.080] So we ended up creating two splits of this product. [40:52.860 --> 40:55.360] I'm a little bit rushed for time, so I might have to skip some slides. [40:56.020 --> 40:58.580] So we ended up creating two splits of this product. [40:58.580 --> 41:01.940] So you can see that we dropped the Hack Hat and the Long Cat and the Wi-Fi Nugget. [41:02.780 --> 41:06.200] We decided to rename to the D1 Wi-Fi Nugget, which is kind of confusing. [41:06.440 --> 41:08.660] And then we had this new player called the S2 Wi-Fi Nugget. [41:08.860 --> 41:19.440] And this is sort of where we started facing branding issues, because now people were extra confused as to what the hell this product was for now that we had two kind of arbitrarily named and confusingly named products. [41:19.800 --> 41:29.360] And also since we were taking these in two different directions, I was focusing on how to use it as a hacking tool, whereas my friend Cody was exploring some more stuff in programming and that kind of thing. [41:29.540 --> 41:32.140] And we were trying to find something to unify these all together. [41:32.420 --> 41:41.120] So now we had a split of these two products where I was focusing more on the D1 platform and my friend was focusing on the S2 platform. [41:42.820 --> 41:48.940] Around the fourth or fifth month of developing, we decided to just start selling this on our own store. [41:48.940 --> 41:57.140] So now we were selling two products, but this led to inevitable confusion where people were confused about which one to buy. [41:57.280 --> 41:59.920] They didn't really understand the distinctions between the two products. [42:01.000 --> 42:09.020] Also the issue with the S2 module that we ran into was that the newer version of the software development kit didn't support like Wi-Fi attacks. [42:09.620 --> 42:17.200] So some people were buying this module that was better at programming but not Wi-Fi hacking, thinking they could do the same thing and they ended up getting a little bit pissed. [42:17.660 --> 42:23.720] So now we had this interesting dichotomy, we had this naming confusion and people still didn't really have a clear idea of what this product was for. [42:25.260 --> 42:35.760] So at that point we decided we needed a piece of software that was completely our own, something that we could create our own elevator pitch for and something that was strongly associated with our product. [42:35.980 --> 42:41.160] Because at this point we were running mostly community-based projects like CircuitPython, like the deauthor and that kind of thing. [42:41.560 --> 42:44.460] So that's where we came up with the idea for the Nugget Invader. [42:44.460 --> 42:48.240] This was supposed to be a piece of software that runs on the Wi-Fi Nugget. [42:48.640 --> 42:51.680] And it was designed to be a Wi-Fi hacking tool. [42:52.180 --> 42:57.040] At first it was designed to be an all-in-one tool for things like network attacks and also network defense. [42:58.000 --> 43:00.500] Where it could do things like boot people off Wi-Fi networks. [43:01.360 --> 43:04.020] as well as also detect network threats. [43:04.940 --> 43:05.820] And that kind of thing. [43:10.060 --> 43:17.080] As you can see we didn't really learn from, or I didn't learn from my mistake initially where I tried to still create this software thing as like an all-in-one tool. [43:18.200 --> 43:21.520] But we eventually broke this out into two projects called the Invader and the Defender. [43:21.900 --> 43:25.720] The first one being a network attack tool, the second one being a defense tool. [43:25.720 --> 43:32.360] But it was still kind of confusing since these were software-based projects that could be run on the D1 Nugget. [43:32.600 --> 43:36.500] And since CircuitPython was the programming language that we were running on the S2 Nugget. [43:36.800 --> 43:39.900] So there was even more brand confusion that was caused around this. [43:40.320 --> 43:43.820] And people were conflating our software with the hardware names. [43:43.960 --> 43:47.840] And they still had problems differentiating between the two platforms that we created. [43:49.300 --> 43:51.480] I'm gonna go ahead and skip through these ones a little bit. [43:52.940 --> 43:56.480] Eventually we came to an interesting point where the S2 Nugget ended up... [43:56.480 --> 44:04.480] We ended up pivoting towards the S2 version of the Nugget once we realized that one of the cool features it supported was the ability to run USB attacks. [44:04.840 --> 44:08.680] Since we were selling mostly to the Hak5 audience and since their gig was mostly... [44:09.400 --> 44:11.960] is mostly USB hot plug attacks and that kind of thing. [44:12.180 --> 44:19.400] We decided to develop a software platform for it called the Rubber Nugget. [44:24.740 --> 44:42.720] But basically just as I had started to double down on the Nugget Invader and when we thought we were gonna start selling these products through the Hak5 store after like a month of intensive development we decided to switch over to this product since it had a much clearer purpose and since it was more in line with the audience that we were trying to sell to. [44:47.830 --> 44:50.930] So this is where things also became super confusing. [44:51.130 --> 45:07.690] It's a little bit hard to explain but as all this stuff was going on we also decided to make a slimmer like smaller version of the Nugget and we were left in this absolute hell where we had three different products two of which were beginner kits, we had like a small version and then all this crazy software that was floating out there. [45:09.790 --> 45:21.010] We eventually did a soft launch on the Hak5 store of 300 of these devices running this new USB attack software that we came up with called the Rubber Nugget which I'll show you a little bit in a second here. [45:22.150 --> 45:23.590] But it was all very last minute. [45:23.770 --> 45:26.390] At this point we had just decided what we wanted our product to do. [45:26.630 --> 45:42.990] And this was focused just around the S2 platform but we decided that we wanted our tool to be a USB attack platform that could run beginner USB attacks and could also be used to guide users through the basics of running USB hacks. [45:46.900 --> 45:50.640] So this was one of the graphics that we created for the initial launch. [45:52.540 --> 46:04.080] But the way we pitched this was that the USB Nugget, confusingly enough we branded it as the software name, the Rubber Nugget is a beginner tool for learning how to run USB attacks. [46:04.080 --> 46:06.160] And that's really what we were focusing on. [46:06.480 --> 46:11.420] But we never really solved our issue of all the other hardware platforms and software that was floating out there. [46:11.640 --> 46:14.400] So this was all kind of ambiguous and up in the air. [46:14.540 --> 46:17.200] And there was still a lot of brand confusion for us and product confusion. [46:24.000 --> 46:26.820] So what did we learn from this whole crisis? [46:30.080 --> 46:35.460] We're still sort of coming down from this initial launch and working on sorting out our branding. [46:36.520 --> 46:39.780] So we still have three products that are floating out there. [46:39.920 --> 46:44.120] We still have different softwares that we're trying to differentiate between. [46:44.720 --> 46:48.920] But what we learned ultimately was that you can't make a product that appeals to everyone. [46:50.280 --> 46:51.580] That was our biggest screw up. [46:52.040 --> 46:56.920] Everything from the hardware level down to the software that we were creating, you can't really create like an all-in-one platform. [46:59.800 --> 47:03.780] And that you really need to figure out the niche that you're trying to appeal to. [47:04.040 --> 47:10.680] In our case, we worked a little bit backwards where at first we just created this random hardware platform and we didn't really focus on who we were trying to sell to. [47:11.000 --> 47:19.460] But what we eventually came around to was figuring out that we cornered a particular part of the cybersecurity market through Hak5. [47:19.460 --> 47:29.120] And we eventually figured out that the best thing to do was to focus on the beginners in that community since we had a really friendly tool. [47:29.360 --> 47:37.020] And to try to sell our product sort of in that light. [47:42.790 --> 48:03.030] So what I also learned from this is the best way to sort of engender or rep the product that you're trying to create is if you want to create something successful, you should take inspiration from others who are sort of in your space, but don't exactly copy from them. [48:03.210 --> 48:29.070] So sort of my process for this is after identifying the niche that you're trying to appeal to, figure out who's your direct competition, figure out ways that you can achieve parity to the products that are on your level, eventually overcome that and then move up from there and target other companies or brands or things like that that you feel like are a little bit above you, [48:29.230 --> 48:34.210] but you eventually want to achieve like their status. [48:39.210 --> 48:45.270] If you're trying to sell a product to somebody, what you really need to do with their product is be able to tell a story with it. [48:46.410 --> 48:54.470] In our case, this was focusing on the cat-themed and cat-shaped aspect of it and making it a gamified interface that was easy for beginners to understand. [48:55.290 --> 48:57.990] This is still something that we're working on developing. [48:58.430 --> 49:01.250] But cohesive branding is also a very important thing. [49:01.250 --> 49:04.050] I feel like we had a lot of trouble branding this product. [49:04.270 --> 49:17.130] But once we eventually focused on the areas that we got right, like for example, the beginner-friendly interface and that kind of thing, that's when it all started to make sense and people started to understand our product. [49:21.830 --> 49:27.690] And also the last thing is understanding a business model that works for you. [49:27.690 --> 49:33.970] In our case, pairing content with the hardware that we were selling ended up working out for us. [49:36.070 --> 49:40.130] This would probably look different depending on what you're trying to do, but yeah. [49:40.550 --> 49:46.550] And also that you can't really have an all-in-one multi-tool platform. [49:49.640 --> 49:51.740] And then just some other mistakes that we made. [49:53.560 --> 49:58.280] At some point or another, we ended up getting too cocky along the development process. [49:58.600 --> 50:01.140] And there were points where we wouldn't test out our products. [50:01.340 --> 50:06.680] Like recently we ordered 500 assembled modules of these boards from China. [50:06.680 --> 50:11.220] Now that we're trying to outsource our assembly process. [50:13.100 --> 50:18.580] And we basically swapped out one of our components for a slightly cheaper version that we never tested out. [50:18.580 --> 50:23.020] But it turns out the supplier completely screwed up the design. [50:24.320 --> 50:27.980] So now we have 500 broken boards on hand that we'll have to manually fix. [50:28.760 --> 50:32.320] But the lesson that we learned from that is that everything should be extensively tested. [50:36.850 --> 50:37.230] Cool. [50:37.450 --> 50:40.610] Does anybody have any questions about anything? [50:40.770 --> 50:41.690] Also, thank you guys for coming. [50:42.830 --> 50:42.930] Yeah. [50:47.630 --> 50:48.910] Thank you, Alex, for the talk. [50:49.050 --> 50:50.510] I think we can do one question. [50:51.170 --> 50:51.550] Cool. [50:51.690 --> 50:52.750] Does anyone have one question? [50:53.330 --> 50:53.770] I [50:56.910 --> 50:57.450] have a question. [50:57.670 --> 50:57.950] Yes. [50:58.370 --> 50:59.350] Where do you sell? [50:59.510 --> 51:01.410] Like what kind of places do you sell your stuff? [51:03.190 --> 51:03.630] Yeah. [51:04.110 --> 51:08.050] Initially we started selling these just through our store personally. [51:08.430 --> 51:12.650] Sort of as like an experiment before we were going to launch through the Hak5 store. [51:13.310 --> 51:17.390] So we sort of used that as like a testing grounds to see like what people thought of the platform. [51:17.610 --> 51:19.310] We also were running smaller batches there. [51:20.050 --> 51:25.890] So that way we weren't like fully committed to like doing a full production run with like a product that we were like unsure of. [51:26.430 --> 51:30.590] So first we were selling on our store which is hakcat.com, H-A-K-C-A-T.com. [51:32.130 --> 51:36.950] We did a soft launch through the Hak5 store at hak5.org and we're hoping to sell more of these in the future. [51:39.510 --> 51:39.870] Excellent. [51:40.050 --> 51:40.290] All right. [51:40.430 --> 51:41.730] Well, thank you so much for the talk. [51:41.910 --> 51:41.950] Of course. [51:41.950 --> 51:42.770] It was fascinating. [51:43.390 --> 51:44.910] Thank you audience for attending the talk. [51:45.970 --> 51:53.310] If you want to post any content, if you post in the Matrix chat, everyone in the audience can go access the Matrix chat and see anything you have. [51:53.430 --> 51:57.870] If you have any other questions for Alex, go ahead and reach out to him through the Matrix chat. [51:57.870 --> 51:57.950] All right. [51:59.590 --> 52:04.750] And our next talk tonight is going to be Don't Get Tangled Up in Your Cape, Hero Culture is a Negative Force in Cybersecurity. [52:04.750 --> 52:06.750] That will start in about eight minutes. [52:06.810 --> 52:08.350] So come back if you can.