Fear and Hacking in Las Vegas ----------------------------- by Joel Deane July 22, 1997 Part One: Friday Within a few hours of arriving, the pranks are underway. Passing counterfeit $1 and $20 notes, spotting federal agents, selling contraband merchandise like the perennially popular "Microshit" T-shirt, hacking the hotel phone system until it surrenders free calls. "The phone system has lost," one hacker gleefully pronounces. Welcome to Def Con Five, the biggest hacker conference in the United States-- a three day network-gamble-drink-athon at the Aladdin Hotel Casino, right in the dusty heart of Sin City's Las Vegas Boulevard. Like most conventions, Def Con's opening morning is all about lines; as in standing in 'em. Stand in line at the airport baggage check... stand in line at the taxi rank... stand in line at the hotel check-in... stand in line at the registration.... By now it's pushing midday and, speaking for myself, I'm in no mood to discuss the finer points of social engineering. For courage, I buy myself a mega-margarita-- a stiff concoction in a half-yard glass that tastes like a Tequila Slurpie-- and, with a wistful look toward the blackjack tables, slouch into Def Con's ostentatious convention room-- which looks like it was decorated by Ricardo Montalban. Now is as good a time as any to discuss the finer points of the Aladdin Hotel and Casino. Sure, its motto is "Your wish is our command," and, yeah, some woman dressed like Barbara Eden out of I Dream of Jeannie is wandering around the slot machines, but that doesn't alter the fact that this joint's a dump-- a gold and maroon safari suit compared to the fluorescent Lycra of the strip's newer, Disneyland-like attractions. The security guards have no trouble picking the hackerfest participants out from the Aladdin's regular crowd-- families, retired couples, country music fans. I'm stopped more than once by baffled guards, six-shooters strapped to their thighs, wanting to know just what this Def Con thing's all about. "Hacking," I reply. Blank expressions. "Computer hacking," I expound. One of the guards, a woman, nods. I've made contact. I plunge on and say, "So now you know what hackers look like"-- and we're back to the blank looks. Then again, the convention goers-- henceforth to be known as Defheads-- don't seem to care. Now that they've registered, most of the Defheads roam around the Ricardo Room, buying up every black Def Con Five T-shirt they can lay their hands on. The Def Con mugs and baseball caps are also steady sellers. There's a couple of book stalls, too, pushing titles like How to Get Anything on Anybody and The Encyclopedia of Personal Surveillance. Not to mention the trash-and-treasure stall of cellular phones-- going cheap at $10 a pop-- and telephony paraphernalia up on the stage. Slurping on my mega-margarita, I shuffle past the stalls, but am more interested in the geeks than the gear. They are not what I expected, these Defheads. They're much too diverse a group to pigeonhole. Sitting in the corner, on the Fantasy Island carpet, are what looks like a bunch of computer nerds: pale fingers clicking away at their laptops. Over there, complete with dyed black hair, are some computer goths. Clean-cut, wearing running shoes, reading newspapers: those two twentysomethings are either lost jocks or Feds, I'll wager. And there, by the booth with the Buddha-sized bust of Mr. T, we're talking genuine cyberpunks, folks. Ages range from teenagers to gray-beards, hair styles range from hippie to hoodlum, fashion sense ranges from black T-shirts to, well, white T-shirts. What most Defheads have most in common is that they are male and they are white. There are a few minorities in attendance, and a noticeable contingent of women, but Def Con is, by and large, a boy thing. Yeddish Monoxide, a 16-year-old first-time Defhead from New Mexico, is here to learn. "I heard about all the stuff that they do. All the seminars," he says. Monoxide, who works in computer sales, skipped town without his parents permission to come to Def Con. He says he doesn't consider himself a hacker-- yet. "I am not good enough," he says. "I still have a long way to go. I would like to become that good because there's money in it." With about 1,000 attendees, Jeff Moss, organizer of this and the four previous hackerfests, says this Def Con is the biggest yet. Milling around with the teenage wannabe Kevin Poulsens is the real thing: elite hackers like Mudge, able to find a hole in just about any software or system, and crypto-czars like Bruce Schneier, author of Applied Cryptography. And don't forget those Feds. "This year we have got a lot of Federal attention. Federal agents, people from the military," says Moss, a 27-year-old computer security expert. And what about the rest of the Defheads? "I would say 30, 40 percent are hangers-on that want to learn," he says. "Probably 10 percent are groupies that just like to be around people. And the rest are probably genuinely in the industry or professionals." Lucky for my mega-margarita soaked brain, the only action this afternoon is a talk by James Jorasch on how the casinos cheat and how to beat the system. It's an interesting talk, sprinkled with anecdotes, but the most practical advice I glean is that it's good to talk to the dealer. Why? It slows the game, which means you get more free drinks for your gambling buck. (I'll be careful not to spend that advice all at once.) Part Two: Friday Night "I am the only cypherpunk in Las Vegas." So says Las Vegan Steve Schear. It's early Friday evening, the cocktail hour, and I'm propped at one of the Aladdin Hotel and Casino's garish bars with Schear and two other corporate hackers-- Adam Shostack and Sameer Parekh. Contrary to the media image of hackers being pimple-faced adolescents, these three are business-card toting grown-ups. In many respects, they represent the post-War Games evolution of the hacker. Sure, back in the early and mid-80s, the likes of Steve, Adam and Sameer might have dreamed of doing a Matthew Broderick and hacking the Pentagon. These days, though, many twenty- and thirtysomething hackers have gone legit-- cashing in their knowledge of computer software and networks to become security consultants, software developers and cryptographers. Thinking about it, hiring a hacker to safeguard does make sense: Who else would better how to build the most asbestos-like firewall? Interestingly, none of these three call themselves hackers. Schear's business card bills him as an "e-cash monger," Shostack's touts him as a "firewalls and security consultant," Parekh's simply states he is president of his own company. They might look more like overgrown college students than businessmen, but don't be fooled by the baggy shorts, anti-establishment attitude (Shostack's sporting a "Resistance is Futile" T-shirt with a picture of a Borg-like Bill Gates), long hair or (in Parekh's case) the kung-fu-master style goatee. Schear's company, First ECache, is developing anonymous electronic money which should be untraceable once it's left your virtual wallet-- he reckons the Feds hate it. Shostack, from Boston, Mass., sells his services to banks, hospitals and software companies-- auditing and beefing up electronic computer systems. Parekh's Oakland, Calif.-based company, C2Net, develops encryption software. Shouting over the chorus of slot machines as they sip piņa coladas from souvenir half-yard glasses-- I'm drinking a yeoman beer-- these corporate hackers all agree Def Con is more about play than work. "It's a fun party," says Shostack, who attended Def Con Three. Likewise, Parekh, a first-timer, says he came because "I knew it would be a fun party." And Schear? For him, it's a rare chance to rub shoulders with his colleagues. Undeniably, networking-- that cornerstone of conferences-- also enters the equation. "The contacts that I have made here have led to things (consultancy work) later on," Shostack says. Parekh chimes in: "It's more networking-- hanging out with people who are in the same field. I don't expect I will pick up lots of info, but I will meet people." In that respect, Def Con's not so different from another get together being held in the Aladdin: the Tele-Sales conference. Tele-Sales? That's right. In one of life's little ironies, while the black T-shirt brigade mulls over Zen and the art of hacking in the Ricardo Room, across the hall in the Herve Villechaize Memorial Suite the perm and padded shoulder set are discussing capitalism and the art of making a buck online. The Tele-Sales crowd seem mildly perplexed by the Defheads. Neatly attired in Friday-casual wear, and with a far larger contingent of women, these salespeople gather in small groups to observe the passing parade of nose-rings and ponytails. I try to stray into one of the Tele-Sales group sessions, but am lassoed by a Tele-Sales cowboy (complete with 10-gallon hat and boots) and herded away. Back to the bar. As the mega-margaritas subside, conversation turns to the malicious hackers and, you guessed it, the FBI. Shostack says one of the reasons for hacking's roguish reputation is the public's failure to differentiate between knowledge-seeking hackers (only out to learn about and play with systems) and malicious hackers (out to crash sites, systems and maybe even the Internet). According to Shostack, there are at least six ways a malicious hacker could crash "large chunks" of the Net. Parekh agrees. "We are lucky that people who have gotten on the Net and have the ability are not sociopaths," he says, which brings us to the FBI. Personal relations between the conference's hackers and law enforcement seem relatively friendly. Feeling technically-- and possibly intellectually-- superior, some hackers, such as Se7en, from Berkeley, Calif., talk of individual G-men in an offhand, parental manner. That said, hackers still consider that the Bureau is Big Brother's lifeguard-- watching the pool that is the Internet, ready to expel any swimmer caught using an unorthodox stroke. Instead of taking it out on individual agents, though, most Defheads seem content to rail against the institution and FBI director Louis J. Freeh. "The ironic situation is that the FBI Computer Crime Squad is talking about how terrorists can shut down the Internet and do all these things, but at the same time the FBI wants to outlaw what would safeguard it," says Parekh, referring to Freeh's crusade against full-strength encryption. "Louis Freeh came up through the ranks by wiretapping the mafia," Shostack says. "He's afraid of losing it." This is Jeopardy! By the time the piņa coladas are history, it's 8:45 p.m.-- time to head back to the Ricardo Room. I've been up since 5 this morning-- a hellish hour for a nocturnal type-- and, with a belly full of mega-margarita and beer, am beginning to fade. Still, I troop into the Ricardo Room with all the Defheads, many of whom are already wearing their Def Con caps and T-shirts. Inside the Ricardo Room, the night's first event-- the drinking game-- is underway. As the name suggests, the drinking game is all about getting drunk. A panel of hackers, armed with cocktails in half-yard glasses, sit on the stage. The host, Mudge, roams around with a microphone, fielding questions from the audience. What sort of questions? The more technically arcane the better. In fact, the more technical the question, the more the panel of contestants has to drink. Needless to say, the more celebrated questions sounded like people speaking in tongues to this technical luddite. The crowd is well-oiled by the time the night's big event-- Hacker Jeopardy-- rolls around. An Alex Trebek look-alike (well, maybe not a look-alike, but the host did wear a suit and mustache) took over the stage, along with four teams of contestants. The format was much like the TV show-- only here the categories were Hacking, We Still Hate Cyberflicks, Busts, Some Net Security, Aliens Among Us and This Is Jeopardy. With prizes ranging from free software to motherboards up for grabs, the contestants and crowd got into the swing of the occasion-- climbing over each other to provide the correct answer to questions like "The day, month and year the aliens visited Roswell." I bet some Tele-Sales types are asking themselves similar questions about extraterrestrials in the Aladdin right about now. Part Three: Saturday Something is seriously amiss. I've been in Las Vegas more than 24 hours and I haven't spent a dime gambling. Last night, after Hacker Jeopardy, I walked the Las Vegas strip-- up as far as Treasure Island, down as far as Excalibur. I didn't bother with the Luxor, not this time. I stayed in that glass pyramid during my previous Vegas excursion: visiting the genuine recreation of Tutankhamen's tomb, buried deep beneath the gaming room floor; riding up and down the inclinator (a backwards elevator) until I thought I was going to throw up. It was fun, sure, but that was 1995-- before New York New York, before Monte Carlo, before the Stratosphere. Get the picture? The Luxor is last summer's attraction. So far as being box office draws, these extravaganzas of casinos have the shelf life of Speed 2. As soon as the newest, latest, hottest casino opens, it falls under the shadow of another construction site; its days numbered as the hot ticket in town. You like New York New York? Then wait until you caste your eyes upon Paris! Dazzled by the replica Statue of Liberty? Then you'll be thrilled by our fiberglass Eiffel Tower! Coming soon! Oh, dear.... What is it with Vegas? The town used to be the home of wise guys, of practitioners of martini-cool like Sinatra and Co. Now it's a theme park-- Disneyland with topless dancers. Walking Las Vegas Boulevard. last night, the strip had no sense of danger. It was all families and couples and tourists and footloose convention-goers. People were meandering past the Mirage waiting for the volcano to erupt or for the sea battle on the sidewalk outside Treasure Island; bathing in the lights of the giant Siegfried and Roy sign. Everything is disarmingly surreal. And that's Vegas: The way it calls to you with its gaudy fluorescence, $4.95 buffet meals and cheap rooms; sings siren songs-- i.e., classic rock covers-- via all those upholstered, blow-dried lounge acts; slowly unbuckles your money-belt until you lose all sense of gravity; then dashes you against the rocks of that free scotch you're drinking. Quite the seductress. Some place for a hacker convention. Jeff Moss, the event's organizer, has held every Def Con in Las Vegas. Why? Simple, he says. In War Games, when Matthew Broderick and the other teen hackers break into the Pentagon, the first place they try to nuke is Sin City. There's also a more pragmatic reason. Back in 1993, when the first conference was held, Moss wanted a warm, dry venue. That way, if no one turned up, he and his friends could at least sit around the pool and drink cocktails. In case you were wondering, Moss hails from a cool, wet part of these United States-- Seattle, Wash. Up until now Def Con's enjoyed an underground existence in Vegas. It was small, not big-spending and largely anonymous-- at least until all the dudes with the laptops started parachuting in. Finding a venue has often been difficult for Moss. None of the hotels that have hosted Def Con have asked the Defheads back. Moss, who has taken out loans to finance Def Con Five, insists those closed doors are not due to illegal activities undertaken during any conferences, but the casinos' hacker phobia. "I tend to play down the whole hacker thing when I'm looking for a hotel," he says, which partly explains the splendor of the Aladdin. By the time I take the lift from my room on the 23rd floor to the ground floor (a quicker trip than expected, since the hotel skips floors one through 11), it's approaching 10 a.m. I just have time for a quick breakfast-- Belgian waffles-- before an eternal lineup of speakers. Saturday at Def Con is D-Day. Now's when most of the action takes place. The next eight hours are a welter of speeches, tech sessions and shenanigans. The heavy-hitting speeches are in the Ricardo Room. There's the cyberpunk philosophy of Richard Thieme ("The smaller the ego and more manageable the ego, the more powerful [a hacker] you are")-- who sees humanity evolving by interacting with technology. Or the in-your-face approach ("There are 50,000 to 70,000 clueless hackers out there") of Ira Winkler, security expert and author of Corporate Espionage. Or the riveting sermon on the mount delivered by Bruce Schneier, revered author of Applied Cryptography: "The problem with bad cryptography is it looks just like good cryptography... The Internet is different because these (hacking) tools can be automated and propagated... Someone can have a website-- 'Click here to destroy the Internet.' That's possible to do. That's scary... It's going to get worse before it gets better... We are going to see voting on the Net within our lifetime..." And what is the upshot of all these speakers? Methinks the hackers are not as countercultural as they are perceived. Granted, many of these folks are libertarians-- believers in the mythology of the American frontier, that place where men (and only men) were allowed to carve out a new world for themselves, free from regulation and governmental constraints. And, like many netizens, hackers see the Internet as an electronic frontier, a brave new world, a virtual Plymouth Rock-- a wilderness that should be kept from the hands of Big Brother. But, as the evolution of corporatus hackerexus attests, these Defheads are also, by and large, quintessentially American. Again and again, in speeches and conversations, many Defheads exhibited: a) an acute awareness of the United States' dominance in the information technology field, b) a concern that that dominance not be lost through digital theft or corporate espionage and c) generally, a grudging acceptance that someone (so why not the FBI?) needs to safeguard the United States from computer terrorists. That doesn't mean these characters won't indulge in the occasional "hack Netscape" competition or debate the FBI's methods or merrily pirate, say, Microsoft's Office 97. As Bruce Schneier says, he's not worried if someone hacks a computer system, but he is worried if someone destroys the economy. What irks many Defheads is that the broader community confuses hacking-- as in the kind that is basically a pursuit of knowledge-- with digital criminals. Far from outlaws, these hackers see themselves as part of Richard Thieme's techno-evolution. By finding holes in computer and phone networks, they are improving those systems, making them stronger. When you look at it that way, the hackers finding faults in the system's monolithic, yet fragile, information infrastructure are agents of progress, and thus thoroughly American. While the speeches continue, there's fun to be had in the auxiliary rooms. More books, such as Secrets of a Superhacker, are for sale, and, after some technical hiccups, the Capture the Flag contest is well underway. Packed around fold-up tables, camped on the carpet with their laptops, teams of hackers are beavering away-- trying to either capture or defend one of five operating systems. Spot the Fed has to be the game of the day, though, especially since Defheads who ID any law enforcement or military personnel win a "I Spotted the Fed" T-shirt. By the end of the day, though, I'm brain dead. After sitting through all those speeches, I feel like a clubbed seal-- and there's still another late-night round of Hacker Jeopardy to go. Hoping for a bit of R&R, I dash upstairs, change into my bathers and scoot back down to the 12th floor-- hoping to cram in a quick swim before this evening's activities. Outside, on the roof, the concrete feels like a Teflon frying pan beneath my bare feet. I run through the shimmering heat, already sweating, reach the pool-- but stop dead. Despite the heat, despite daylight savings, despite my blistering feet, The Aladdin, in its wisdom, has decreed the pool closed as of 6 pm. It's 6:05 pm. Disgruntled, I trudge back upstairs, stand under a feeble shower and change into a black double-breasted suit and dark shirt. Tonight's supposed to be black evening wear night, but I doubt many Defheads will get out of their T-shirts. Standing in front of the hall mirror, I look like some white trash grifter. That's OK. Whatever else happens tonight, I'm going to play me some blackjack. Part Four: Saturday Night So much for dressing up. I swan into the Ricardo Room in my double-breasted black suit, look around, and-- yep, you guessed it-- the vast majority of Defheads are still slopping around in T-shirts. At least they're clean T-shirts. There are a few fashion try-hards. One gent walks into Def Con's main room, resplendent in jacket and tie; why, he even has on a pair of those two-tone gangster shoes. A few Defheadettes are gliding around in (mostly black) dresses, usually set off with combat boots. But over there, laced into a crushed velvet tuxedo, which, in concert with his long locks and pale complexion, gives him the air of an Interview With the Vampire extra, has to be the winner: The best-dressed hacker in town. Def Con attendees are milling around, talking in small groups; some are sitting in ones and twos amid the room's chaotic seating. The Ricardo Room's neat rows and tidy, if not tasteful, carpet is now littered with the debris of empty half-yard cocktail glasses, soft drink containers, day-old newspapers and assorted fast food wrappers. The atmosphere is decidedly low key. Suddenly, there's a commotion. A clutch of Defheads are gathered around a half-open door, peering waif-like into another room. Not wanting to miss a scoop, I head over-- needling my way to the front of the pack. As I get closer to the door, I hear music. But not just any music. This is 1980s dance music-- the nostalgia music of late twentysomethings like myself. I push closer, then, over someone's T-shirt-clad shoulder, see it. It's like some mirage (and I don't mean the casino). Through that door is another, darkened, conference room. Only this conference room is not a Fantasy Island affair. No. In this room, the lights are low. Streamers and balloons drip from the ceiling. Instead of a seating arrangement that resembles a riot, there are neat tables and chairs. The men wear jackets and neat trousers; the women, ladylike frocks. "It's the Tele-Sales dudes," somebody says. He's right. I recognize the Tele-Sales cowboy who booted me away from the sales conference the day before. He's standing on the perimeter of the lit dance floor, where couples circle round and round-- the centerpieces of a parallel universe. Sunday I eat a slap-up, celebratory breakfast this morning. Eggs benedict with coffee and orange juice and fresh grapefruit-- a breakfast of champions. I've only slept three hours, but feel sharp. Perhaps that's due to my blackjack foray. Last night, after sticking around for most of the Hacker Jeopardy, I couldn't wait any longer. I slipped out of the Ricardo Room, strolled through the Aladdin's gaming area-- past the Barbara Eden lookalike, who was engaged in a heated discussion with an Andre the Giant of a security guard-- and onto The Strip. First, I wasted some time shopping for tacky Vegas souvenirs. The Vegas snow bubble was tempting, but I opted for the $1.49 souvenir shot glass. Now it was blackjack time. Crossing the boulevard, I tried out New York New York, but couldn't buy a seat at anything less than a $25 minimum-bet table. After a pit stop in the Motown Cafe, I head for Monte Carlo, which has a football field for a gaming area. Without too much trouble, I find a chair at a $5 minimum-bet table, and settle in for the night. I don't know how long I sat at that table. I don't recall how many free margaritas I drank. I don't remember the name of the dealer who stood in front of me for all that time, yawning between hands, then snapping "Don't touch that card!" All I want to remember are two things: After being behind most of the night, I ended up with a respectable $40 profit; and the ace and king of hearts I netted on a $25 bet. It's a good thing there are no casinos in San Francisco. After breakfast, I head back to the Ricardo Room. The speeches are decidedly techie on this the last day of Def Con. Sameer Parekh gives a cryptography talk, but I already went into that with him over beer and piņa coladas on Friday. Se7en, a Berkeley, Calif.-based hacker who frequents the corporate speaking circuit, gives his spin about what the Feds think of hacking. (His basic premise: The FBI are nice enough, albeit technically retarded, folks who wish digital crime would just go away.) "Managers don't understand the nature of computers, let alone the computer crime," he tells me afterwards. "The Dilbert principle is in extreme effect in government." Carolyn Meinel heads a panel set to discuss whether rookie hackers should be left to fend for themselves. Dan Veeneman delivers an overview on the wonders of low-earth-orbit satellites. Breaking free from the speeches, I step into the hallway. People are standing in groups, drinking cocktails and beer; sitting around, leaning against the walls. Walking down the hall, I notice a flier pasted to a wall. It reads: "John Sieh, 16. $500 cash for proof that he is alive." I dial 1-800-355-6569 and find myself speaking to John's mother, Susan, in Iowa. Susan says her husband, Greg, is in Vegas looking for their son, who's been missing since June 30. John, a teenage hacker who spends "24 hours a day almost" on his computer, planned to attend Def Con Five, Susan says, but hasn't accessed his computer account since going missing with the family's 1986 Cadillac Seville. "We don't know what to think," she says. I hang up and walk back down the hall. There are teenagers everywhere; some look younger than 16. Much younger. Next, I corner Bruce Schneier, who reprises yesterday's speech for me-- the part about how the Net's infrastructure is too fragile and can be trashed at the click of a button, leaving Web enterprises like Amazon.com extremely vulnerable. For the most part, though, Schneier, who's rushing to catch an early afternoon flight, seems distracted. Admittedly, after three days casino-crawling, my attention span's not what it used to be, either. Gradually, as each speaker punches the clock and, in the adjoining room, the same musty hacking crews play Capture the Flag, it dawns on me that the conference is over. Sure, there are still a few hours' worth of workshops, speeches, motherboard and T-shirt giveaways to be had, and maybe I could go out to the hall and place a free call to-- where? Australia?-- but, really, it's all over, bar the shouting. I catch the elevator back to room 2308, pack, check out, leave my bags with three middle-aged bell boys, then step out into the heat. Out here, away from the air-conditioning, it's well over 100 degrees; an embracing, dry baked heat. The sun, reflecting off the bleached-white concrete, is so bright my head hurts. I start to sweat, which is a good thing. I want to sweat. I want to walk The Strip up as far as New York New York. I want to see the Statue of Liberty one more time.