<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>DEFCON &amp;mdash; Kevin Neely&#39;s Security Notes</title>
    <link>https://infosec.press/ktneely/tag:DEFCON</link>
    <description>A place where I can post security-related long-form thoughts, notes, and articles</description>
    <pubDate>Tue, 14 Apr 2026 14:42:26 +0000</pubDate>
    <item>
      <title>DEFCON 32 in Review</title>
      <link>https://infosec.press/ktneely/defcon-32-in-review</link>
      <description>&lt;![CDATA[Critiques&#xA;The venue was too bright.  Chillout rooms and talk tracks could have used a dimmer.&#xA;Speaking of the Chillout room, it was somewhat disappointing. (I’m talking about Chillout 2, as Chillout 1 felt like a giant hospital waiting room).  I like a cavernous, dim, and ambient room for, you know, chilling out.  #SomaFM was over in the hallway, the Chillout room had a live stage, and it was overall pretty small. &#xA;&#xA;“Best-ofs”&#xA;&#xA;These are the best things I personally saw or were close to.  There’s so much going on that this just represents the best stuff I saw in my fractional DEFCON experience.&#xA;&#xA;Best thing I learned:  Gained a good bit of familiarity with InspectAI at the AI Village as a part of their CTF.&#xA;Best Talk:  “Librarian in Broad Daylight: Fighting back against ever encroaching capitalism”  by the Cyberpunk Librarian in the War Stories track.&#xA;Best Rant: Cory Doctorow on #enshittification&#xA;Best Tool or Technique: “MySQL honeypot that drops shells”&#xA;Best Research: “Watchers being watched: Exploiting the Surveillance System” in which the researchers exploited 4 different surveillance systems.&#xA;Best Real-World Impact: “Bastardo Grande: Hunting the Largest Black Market Bike Fence In The World” by Bryan Hance.  Talk not up yet, see the related Wired article&#xA;Best Contest: There’s too many, but I loved the idea of Sn4ck3r, the machine that vends real items for captured flags.&#xA;Best Party:  the 503 Party, of course!&#xA;Best Entertainment: DJ Jackalope brought an awesome set after Hacker Jeopardy.  (and Skittish and Bus did a great job warming up the crowd just before)&#xA;Biggest Drama: the badge&#xA;Best Village: The Packet Hacking village due to the supreme DEFCON-y ambience and the well-run workshops they provided to people of all skill levels&#xA;&#xA;Observations &amp; Random Points&#xA;&#xA;I probably haven’t been to a main track talk in person for over 6 years.  I decided to go to a few of them and really enjoyed the atmosphere.  I’ll have to remember to put at least 2 on the agenda each year going forward.&#xA;BlueTeam Village got a much larger space this year.  I’m happy to see that, as they were nearly impossible to get into over at the Flamingo in recent years.  BTV is doing good work and people should be able to experience it.&#xA;There were a lot of contests. &#xA;The Car-hacking village really brings it.  They had a semi truck rig, a Rivian, and they gave away a Tesla.  Well done, and my only ask is that we make it easier for people &amp; mechanics to jail break their cars when the companies John Deere-ify them.&#xA;&#xA;Next #DEFCON will be held Aug 7-10, 2025 at the LVCC.  I hope to see you there!]]&gt;</description>
      <content:encoded><![CDATA[<h2 id="critiques">Critiques</h2>
<ul><li>The venue was too bright.  Chillout rooms and talk tracks could have used a dimmer.</li>
<li>Speaking of the Chillout room, it was somewhat disappointing. (I’m talking about Chillout 2, as Chillout 1 felt like a giant hospital waiting room).  I like a cavernous, dim, and ambient room for, you know, chilling out.  <a href="/ktneely/tag:SomaFM" class="hashtag" rel="nofollow"><span>#</span><span class="p-category">SomaFM</span></a> was over in the hallway, the Chillout room had a live stage, and it was overall pretty small.</li></ul>

<h2 id="best-ofs">“Best-ofs”</h2>

<p>These are the best things I personally saw or were close to.  There’s so much going on that this just represents the best stuff I saw in <em>my fractional</em> DEFCON experience.</p>
<ul><li><strong>Best thing I learned:</strong>  Gained a good bit of familiarity with <a href="https://github.com/UKGovernmentBEIS/inspect_ai" rel="nofollow">InspectAI</a> at the <a href="https://aivillage.org/" rel="nofollow">AI Village</a> as a part of their CTF.</li>
<li><strong>Best Talk:</strong>  “Librarian in Broad Daylight: Fighting back against ever encroaching capitalism”  by the <a href="https://hackers.town/@CyberpunkLibrarian" rel="nofollow">Cyberpunk Librarian</a> in the War Stories track.</li>
<li><strong>Best Rant:</strong> Cory Doctorow on <a href="/ktneely/tag:enshittification" class="hashtag" rel="nofollow"><span>#</span><span class="p-category">enshittification</span></a></li>
<li><strong>Best Tool or Technique:</strong> <a href="https://media.defcon.org/DEF%20CON%2032/DEF%20CON%2032%20presentations/DEF%20CON%2032%20-%20Alexander%20Rubin%20Martin%20Rakhmanov%20-%20Atomic%20Honeypot%20A%20MySQL%20Honeypot%20That%20Drops%20Shells.pdf" rel="nofollow">“MySQL honeypot that drops shells”</a></li>
<li><strong>Best Research:</strong> <a href="https://media.defcon.org/DEF%20CON%2032/DEF%20CON%2032%20presentations/DEF%20CON%2032%20-%20Chanin%20Kim%20Myeonghun%20Pak%20Myeongjin%20Shin%20-%20Watchers%20being%20watched%20Exploiting%20the%20Surveillance%20System%20and%20its%20supply%20chain%20-%20DEMO%204.mp4" title="DEF CON 32 - Chanin Kim Myeonghun Pak Myeongjin Shin - Watchers being watched Exploiting the Surveillance System and its supply chain - DEMO 4.mp4" rel="nofollow">“Watchers being watched: Exploiting the Surveillance System”</a> in which the researchers exploited 4 different surveillance systems.</li>
<li><strong>Best Real-World Impact:</strong> “Bastardo Grande: Hunting the Largest Black Market Bike Fence In The World” by Bryan Hance.  Talk not up yet, see the related <a href="https://www.wired.com/story/silicon-valleys-fanciest-stolen-bikes-trafficked-mastermind-jalisco-mexico/" rel="nofollow">Wired article</a></li>
<li><strong>Best Contest:</strong> There’s too many, but I loved the idea of Sn4ck3r, the machine that vends real items for captured flags.</li>
<li><strong>Best Party:</strong>  the 503 Party, of course!</li>
<li><strong>Best Entertainment:</strong> DJ Jackalope brought an awesome set after Hacker Jeopardy.  (and Skittish and Bus did a great job warming up the crowd just before)</li>
<li><strong>Biggest Drama:</strong> the <a href="https://www.theregister.com/2024/08/13/defcon_badge_disagreement_gets_physical/?td=rt-3a" rel="nofollow">badge</a></li>
<li><strong>Best Village:</strong> The Packet Hacking village due to the supreme DEFCON-y ambience and the well-run workshops they provided to people of all skill levels</li></ul>

<h2 id="observations-random-points">Observations &amp; Random Points</h2>
<ol><li>I probably haven’t been to a main track talk in person for over 6 years.  I decided to go to a few of them and really enjoyed the atmosphere.  I’ll have to remember to put at least 2 on the agenda each year going forward.</li>
<li>BlueTeam Village got a much larger space this year.  I’m happy to see that, as they were nearly impossible to get into over at the Flamingo in recent years.  BTV is doing good work and people should be able to experience it.</li>
<li>There were <em>a lot</em> of contests.</li>
<li>The Car-hacking village really brings it.  They had a semi truck rig, a Rivian, and they gave away a Tesla.  Well done, and my only ask is that we make it easier for people &amp; mechanics to jail break their cars when the companies <a href="https://www.wired.com/story/john-deere-tractor-jailbreak-defcon-2022/" rel="nofollow">John Deere-ify</a> them.</li></ol>

<p>Next <a href="/ktneely/tag:DEFCON" class="hashtag" rel="nofollow"><span>#</span><span class="p-category">DEFCON</span></a> will be held Aug 7-10, 2025 at the LVCC.  I hope to see you there!</p>
]]></content:encoded>
      <guid>https://infosec.press/ktneely/defcon-32-in-review</guid>
      <pubDate>Tue, 13 Aug 2024 21:38:53 +0000</pubDate>
    </item>
    <item>
      <title>Creating Tech &#34;Go Bags&#34; for travel and conferences</title>
      <link>https://infosec.press/ktneely/creating-tech-go-bags-for-travel-and-conferences</link>
      <description>&lt;![CDATA[I always loved Lesley Carhart&#39;s blog post on packing for hacker conferences and referred to it many times while prepping for #DEFCON , #BSides, other cons, and even general travel.  As time has gone by, I&#39;ve developed a three-tier system that kind of builds on itself for longer and more involved travel.  The general ideaidea is that&#xA;&#xA;Tier 1 Go Bag - The Weekender&#xA; &#xA;The most basic level of the tech travel stack I&#39;ve created is what I call &#34;The Weekender&#34;.  it&#39;s meant for being out and about all day long or for short weekend getaways.  As such, the requirements are basically:&#xA;Take up little room, being able to fit in any backpack or even a sling bag.&#xA;be able to charge the devices I&#39;m likely to carry, from ear buds to a laptop.&#xA;Plan for extended periods away from a power source.&#xA;&#xA;img src=&#34;https://pixel.infosec.exchange/storage/m/v2/540237025755407403/062ac74bd-fb82c6/ae7jd5nwgaQi/WpFmxPWk8IwRW3i16yhHVb5frmToFYP4VisYdkFn.jpg&#34; alt=&#34;image&#34; style=&#34;width:480px;height:auto;&#34;&#xA;image 1: Tier 1 go bag - The Weekender with a backup battery, USB-C to USB-C cable, USB-A to micro-USB cable, and USB-C adapter.  Small, ready to go, and easy to drop into any bag.&#xA;&#xA;Bag Contents&#xA;&#xA;In order to address these simple requirements, I realized I needed to be able to provide power to USB-C and micro-USB devices, for a laptop, I need a bit more oomph, so the adapter can deliver enough power to charge a laptop battery.  Limited by the space requirements, I went with a 33W charger that can absolutely charge a laptop, but it will not keep up with power consumption under load.  This means that if I&#39;m going to be working all day on the laptop, I&#39;m going to need to move up to the next tier. &#xA;&#xA;Power sources &amp; adapters&#xA;&#xA;1x multi-adapter (USB-A for devices, USB-C for laptops) like the Anker 323 at 33W it won’t fully power a laptop, however, it will greatly extend the battery life and will change the laptop when it’s off or in standby&#xA;1 5000mAh battery pack with dual USB-C ports - thin and light is key here&#xA;&#xA;USB&#xA;&#xA;Cables&#xA;Note that all cables can transfer data.  For versatility, I don’t mess with power-only cables.&#xA;1x USB-A to microUSB cable - 3ft.&#xA;1x 5ft. USB-C to USB-C cable - This is the minimum length you want to ensure your phone can reach the bed when charging&#xA;&#xA;Converters&#xA;Converters extend the utility and versatility of the other equipment&#xA;USB micro female to USB-C male.  This gives me a third USB-C cable&#xA;&#xA;img src=&#34;https://pixel.infosec.exchange/storage/m/v2/540237025755407403/062ac74bd-fb82c6/L8F0wgK3TJpv/icuPwzvpqxg9lxP0lnCqSv2uNRLIlxxA8YbwO2gy.jpg&#34; alt=&#34;image&#34; style=&#34;width:640px;height:auto;&#34;&#xA;Image 2: Zipped Weekender Go-bag and its contents in detail]]&gt;</description>
      <content:encoded><![CDATA[<p>I always loved Lesley Carhart&#39;s <a href="https://tisiphone.net/2017/04/28/whats-in-my-hacking-con-bag/" rel="nofollow">blog post on packing for hacker conferences</a> and referred to it many times while prepping for <a href="/ktneely/tag:DEFCON" class="hashtag" rel="nofollow"><span>#</span><span class="p-category">DEFCON</span></a> , <a href="/ktneely/tag:BSides" class="hashtag" rel="nofollow"><span>#</span><span class="p-category">BSides</span></a>, other cons, and even general travel.  As time has gone by, I&#39;ve developed a three-tier system that kind of builds on itself for longer and more involved travel.  The general ideaidea is that</p>

<h1 id="tier-1-go-bag-the-weekender">Tier 1 Go Bag – The Weekender</h1>

<p>The most basic level of the tech travel stack I&#39;ve created is what I call “The Weekender”.  it&#39;s meant for being out and about all day long or for short weekend getaways.  As such, the requirements are basically:
1. Take up little room, being able to fit in any backpack or even a sling bag.
2. be able to charge the devices I&#39;m likely to carry, from ear buds to a laptop.
3. Plan for extended periods away from a power source.</p>

<p><img src="https://pixel.infosec.exchange/storage/m/_v2/540237025755407403/062ac74bd-fb82c6/ae7jd5nwgaQi/WpFmxPWk8IwRW3i16yhHVb5frmToFYP4VisYdkFn.jpg" alt="image" style="width:480px;height:auto;">
<strong>image 1:</strong> Tier 1 go bag – The Weekender with a backup battery, USB-C to USB-C cable, USB-A to micro-USB cable, and USB-C adapter.  Small, ready to go, and easy to drop into any bag.</p>

<h2 id="bag-contents">Bag Contents</h2>

<p>In order to address these simple requirements, I realized I needed to be able to provide power to USB-C and micro-USB devices, for a laptop, I need a bit more <em>oomph</em>, so the adapter can deliver enough power to charge a laptop battery.  Limited by the space requirements, I went with a 33W charger that can absolutely charge a laptop, but it will not keep up with power consumption under load.  This means that if I&#39;m going to be working all day on the laptop, I&#39;m going to need to move up to the next tier.</p>

<h3 id="power-sources-adapters">Power sources &amp; adapters</h3>
<ul><li>1x multi-adapter (USB-A for devices, USB-C for laptops) like the <a href="https://www.anker.com/products/a2331?variant=42282830725270" rel="nofollow">Anker 323</a> at 33W it won’t fully power a laptop, however, it will greatly extend the battery life and will change the laptop when it’s off or in standby</li>
<li>1 5000mAh battery pack with dual USB-C ports – thin and light is key here</li></ul>

<h3 id="usb">USB</h3>

<h4 id="cables">Cables</h4>

<p>Note that all cables can transfer data.  For versatility, I don’t mess with power-only cables.
– 1x USB-A to microUSB cable – 3ft.
– 1x 5ft. USB-C to USB-C cable – This is the minimum length you want to ensure your phone can reach the bed when charging</p>

<h4 id="converters">Converters</h4>

<p>Converters extend the utility and versatility of the other equipment
– USB micro female to USB-C male.  This gives me a third USB-C cable</p>

<p><img src="https://pixel.infosec.exchange/storage/m/_v2/540237025755407403/062ac74bd-fb82c6/L8F0wgK3TJpv/icuPwzvpqxg9lxP0lnCqSv2uNRLIlxxA8YbwO2gy.jpg" alt="image" style="width:640px;height:auto;">
<strong>Image 2:</strong> Zipped Weekender Go-bag and its contents in detail</p>
]]></content:encoded>
      <guid>https://infosec.press/ktneely/creating-tech-go-bags-for-travel-and-conferences</guid>
      <pubDate>Wed, 27 Mar 2024 22:37:03 +0000</pubDate>
    </item>
  </channel>
</rss>