‘Legacy system’ exposed Black Hat 2018 attendees’ contact information
techcrunch.com
techcrunch.com
Is that something people get warned when buying a ticket?
edit: https://www.blackhat.com/us-18/registration-terms.html#priva... links to https://legal.us.ubm.com/privacy-policy/#Choices which someone smarter than me should interpret.
Also, if you're at a show, presumably you're interested in at least of the vendors so may want to be on their lists. I get a huge amount of email from vendors because I attend so many events but it's not really that big a deal to just unsubscribe from anything I genuinely have zero interest in.
Maybe there are less black hats at these conferences than the numbers suggest.
You may be thinking of DEFCON?
It's possible that some might suggest that Black Hat Briefings might be easily googled.
Defcon has become this enormous nerd Burning Man event, filling Caesars armpit-to-elbow with attendees trying to fight their way to various different "villages". But as it's become that, it has become less and less "black hat", and more and more just security's Comic Con.
But in the days before the two conferences diverged, it certainly was not the case that BH was more "white hat" than Defcon; BH was a way to pay offensive security people out of the expense accounts of defensive security people. And these days I have sort of a hard time believing any "real" black hat takes Defcon seriously.
BlackHat - the Burning Man and Comic Con of information security for serious professionals.
Needs to be fleshed out with a bit of Renfaire, SXSW and Anthrocon, perhaps.
Everyone working in offensive security is still a white hat. That's a legitimate profession. Black hats hack things without permission. That used to be big at Defcon, but I don't think it was ever really a Black Hat thing.
Unless they run out of those, then they just give you a paper card that you wear on some string or something.
There are, so far as I know, no pay-to-play Black Hat talks; all the listed briefings were picked by the review board.
It's been several years, but I remember the RSA conf held in early Spring usually had it's CFP deadline something like a 6 months before. So if you were speaking at BH, then around July/August you had everything ready to present, which was perfect timing to submit for the following year's RSA.
I’m now imagining a place full of sharks with smaller fish swimming around waiting for their credit cards to get caught in a net.
It's not great to just dump contact info --- that happened to RSA Security a couple years back and it was a story then --- but it's mostly an optics problem, I think.
I can confirm that it is possible to go to big conferences and be unaware that my contact information is being flung about! For proof of existence, I provide myself.
(And I'm someone who gives out custom email addresses for all signups anyway, so I'm not totally naïve.)
It's one thing to attend a "free" event that makes a return by monetizing attendee data, and another to have an expensive event that does it.
One of the reasons I'm such a fan of BSides events which, generally, aren't expensive to attend and don't sell your data on.
(disclaimer - I've organized a couple of BSides events)
I say this as someone who participates in all this regularly. I much prefer smaller and less overtly commercial events in general.
Which makes swag sorta problematic. On the one hand, it drives booth traffic and some of those people may be exposed to your company or a product who hadn't been previously. On the other hand, I've seen lines of people clogging up booths and the vast bulk of them just want a T-shirt or to be entered in a drawing for a drone or whatever. You end up with scans that are 90% just people who wanted a freebie and have zero interest in your product.
/s
If I had to go to prison for 13 months - even if it was for something as silly as this example -, I'd most likely be out of a job and have a prior on my record, which would probably make it very hard to find a new job equivalent to the one I hold now.
13 months in prison can easily destroy somebody's professional existence, not to mention, if applicable, marriage/relationship and family.
[0] Read the fine print: https://media.defcon.org/DEF%20CON%2026/DEF%20CON%2026%20rec...