— burner hardware, — one-time network connections, — one-time user accounts, — one-time identifiers, — read-only OS builds, — physically disabling sensors, — (insert suggestions)
What else might be options for securely accessing the event?
— burner hardware, — one-time network connections, — one-time user accounts, — one-time identifiers, — read-only OS builds, — physically disabling sensors, — (insert suggestions)
What else might be options for securely accessing the event?
I generally recommend ensuring that your security posture for DEFCON is the same baseline security posture you should have at all times, and for all websites, and then adjusting your habits accordingly months in advance... and then just chilling out because you've adopted a more secure normal (and DEFCON isn't particularly risky compared to everyday life).
Pantomiming paranoid-level security during hacker summer camp is silly. This is true for both in-person events and this year's virtual event.
If you're worried about getting hacked at DEFCON, don't wait until DEFCON to become secure, and don't become lax after DEFCON is over.
If memory serves, the "open" network has seen novel attacks used in years past. But not many.
For example, I might choose not to bring a laptop and just use my phone + take paper notes.
But that's more about not wanting to have to keep track of my laptop than fear of evil maids. Unplugging for a bit can be rewarding mentally and if it's not with you it's one less thing that can be lost or stolen.
The bigger risk is IMHO to end up on someone's watchlist, especially if the country you live in isn't particularly respectful of your individual freedom.
Hacker con sec can be boiled down to 2 simple principles: Update yo shit, and if you have access turned on (ssh, etc) to know their threat model.