DEF CON 32 Was Canceled. We Un-Canceled it
forum.defcon.org
forum.defcon.org
Since the pandemic Vegas has had a pretty strong resurgence in general and this may be a sign that Caesar's is doing well enough they've decided there are higher-revenue guests they can put in those rooms — even in the doldrums of August (a traditionally slow month for Vegas tourism).
I happen to regularly attend an unrelated, non-tech conference that's always right around the same week as DEF CON. That conference also happens to attract attendees who don't gamble or spend much at the hotel other than room costs. The reason the conference organizer chooses August is they get better discounts on their costs from the hotel in exchange for filling up rooms that would otherwise be empty (except this hotel is lower-end and cheaper than Caesar's). This works out because unlike Caesar's this hotel is far off the strip and doesn't have nearly as much dining or gambling revenue potential anyway.
Not renew the contract - sure. But canceling an already scheduled event because of low revenue per guest doesn't seem very likely to me?
Or maybe it was some sort of ongoing agreement and canceling it was effectively "not renewing".
Not to be TOO snarky, but given how quickly corporate cancels employee labor despite rising revenue, it would not surprise me for other corporate to also cancel "low paying customers" for "high paying customers". Loyalty is beyond dead so cancelling a contract is just a cost of business if they feel the alternative gives more money.
At least going by all the entrepreneurship articles I've read over the decade, "firing your customers" is a term of art, and a recommended approach for dealing with unprofitable and/or annoying customers - so I guess this shouldn't be surprising.
> Loyalty is beyond dead so cancelling a contract is just a cost of business if they feel the alternative gives more money.
Not to be TOO snarky, but that's kind of the point of contracts - contract cancellation terms aren't an "or else..." threat, but rather an agreed upon exit strategy. Termination fines aren't punishment, they're compensation for inconvenience.
Repeating this verbatim in your reply means you are trying to be pretty snarky, fyi.
The idea is to diffuse siutations like this before it comes about, but I guess nothing is perfect.
If they canceled a year or so before the con, I could see that. But to cancel seven month before the conference? There's no way they will get a decent-sized substitute in the space before then, so I don't see how this would be anything but a money-loser. Not to mention other conferences might be less willing to commit to long-term deals if they see that the contract can be canceled on a whim.
The announcement effectively calls it "no-notice cancellation" and overall it reads like they were already deep in the planning phase when it happened, which seems unlikely if a renewal was pending.
In all likelihood they ran the math and figured it was worth it to yank the rug out from under Defcon, penalties be damned.
A large company has probably decided to move a conference to Caesar's during that period, and that got Defcon bumped. Especially because DefCon has become massive, so the RoI has shrunk due to staffing overhead.
1. https://www.freep.com/story/entertainment/nightlife/2016/04/...
The problem with card counting generally is that the casino has infinite money and never runs out, thereby they can sustain large expected value swings... whereas you need an enormous bankroll to handle those swings, assuming they don't throw you out before that happens.
There’s a huge difference between: “if you do X, you will be asked to leave” and “if you do X, the police will arrest you”
Like, when I invite someone over to a dinner party, it is against my policy to insult my dog. If you do that I will kick you out (not actually, he’s a dumb klutz, you can insult him all you want), but that doesn’t make it illegal to insult my dog.
Regardless of the year I think you might want to reconsider your overly confident notions about fiction/reality or at least the condescending tone. I don't know what is institutionalized in what places, but have been threatened by casino security. Fuck around and find out I guess
From where I stand, you'd need to show it's systematic. One single instance is not enough for me. Because your claims are general, as if they applied to many casinos.
To be clear, if they tell you to stop playing, and you don’t, then they absolutely can call the police for trespassing, which is a crime.
I don’t think most casinos have private security that will beat you any more, since they can tell you to stop playing and enforce that with police.
Nevermind casinos, do people think every bouncer at every bar is merely for show? Since "management reserves the right", trespassing, threats and assault are not really a huge due-process kind of thing, and local establishments/insiders rank higher than outsiders. Within reason they know what is allowed and that isn't always going to be exactly and only whatever the law technically says.
Edit for even more context. For people that don't know already, not every casino or bar is owned by some megacorp who gives a shit about PR, has tons of cameras, has some HR department to educate staff on doctrine, etc. Many casinos are literally in sovereign territory of indigenous peoples also. Not that summary execution for offenders will be status quo there, but come on folks. The world is large and complicated, so simple stories about it are usually incomplete
I mean, I think you're making up blanket assertions where there are none. I haven't made a blanket assertion. I specified the difference between policy and legality.
I then said "I don’t think most casinos have private security that will beat you any more" That's not a blanket assertion. It specifically says "most casinos".
I have never asserted that it NEVER happens and can NEVER happen.
So, I think your confusion is a product of your own assumptions.
Statistically, it is not effective. Your card counting needs to be (basically) perfect, and you need very deep pockets to handle extended drawdowns.
Taken with a grain of salt, as my only knowledge of this is via Hollywood movies. It does make sense from a game theory perspective though.
The only reason to kick you out would be if they believed you somehow have an edge on them.
The customer who got lucky at first and is willing to try to be lucky again and again is the best customer for the casinos.
Even if you do get thrown out it is already after you have won some money thanks to your edge and therefore 'outsmarted' them.
…because it’s actually extremely difficult to do with the countermeasures casinos now use, more decks and random cutoffs. Letting you try is very profitable though.
The whole environment part is of course not useful. None of the monitoring happening where you can see.
I think the only ones who can make money are those playing poker and are really good at it. That's because they are playing against other players and not the bank. They still have to beat the rake.
I'm not even sure comp players, that is those who play to get non-cash rewards like travels, restaurant and hotel stays while minimizing their losses can still have an advantage. I heard that casinos calculate comps by expected losses, making sure they stay on top (statistically).
And they are cheaters, but it is like saying thieves can make money.
Absolutely not. Using your brains to keep track of cards is not cheating in any way, shape or form. They are simply using all the available information and some pretty basic math to them to gain an advantage.
Calling card counters cheaters is like calling chess players with better knowledge of patterns than their opponents cheaters. They are not cheaters.
The cheating it mentions at the bottom is not card counting (technically legal), but genuine cheating.
https://www.theatlantic.com/magazine/archive/2012/04/the-man...
Also a couple of video poker variants have actual positive (!) returns with perfect play. https://wizardofodds.com/games/video-poker/basics/#playing-s...
You make it sound like it's entirely about money and the bottom line.
I have a hard time believing gaming doesn't provide _huge_ contributions to favorable politicians. I feel like you've got something to say, and maybe something really interesting. But what you've got if awfully vague.
If you've got the time or inclination, I'd definitely read an elaboration of your meaning.
Financially the strips have massive amounts of money flowing into it from every angle. Construction is booming and housing cannot keep up with the demand. If you view LV from the surface then it seems like the economy is trashed - lower travel rates, millennials are not into gaming as much, and the virtualization of gaming is competing. But the reality is business for "living" is doing better than ever before.
Because recent politics has changed ideologies with modern corporations several things have changed. For example skids were never part of LV ever, but that has changed in the last 10 years directly because of these ideologies. https://www.cbsnews.com/news/u-s-first-public-needle-vending...
Do you think these same Corporations look fondly upon DEFCON? They would push it out eventually as it's not safe-hacking.
> We don’t know why Caesars canceled us, they won’t say beyond it being a strategy change and it is not related to anything that DEF CON or our community has done.
https://www.reddit.com/r/Defcon/comments/1aj6ixn/def_con_was...
To avoid any legal liability. Stating a specific reason would open them to possible "breach of contract" depending on whether the act(s) were significant enough or justifiable, based on the contract terms. Just say nothing, part amicably, everyone moves on without drama.
With that said, they probably weren't lying. Most likely, months after ponying up $10 million to a sophisticated international hacking group, Caesars Entertainment probably doesn't want to invite some of the world's best hackers to stay and meet at its flagship resort.
This is how it works for at-will employment, but it would be a very weird contract that allows backing out only if you don't say why you're backing out.
How does making this statement this benefit Caesars in any way? Now DEF CON can demand some proof of this claim, or sue for defamation, or state that without proof, Caesars isn't acting in good faith, whatever.
Most Def con visitors would be white hats so that would be a bit disingenious. I would expect most attendees to behave (reporting issues after finding one)
Especially considering they just got hacked, a few pentests would be good for their business.
But in such a large group, there's always going to be some people who'll decide to muck around with their hotel room's locks or something like that.
https://www.bloomberg.com/news/articles/2023-09-13/caesars-e...
https://www.vox.com/technology/2023/9/15/23875113/mgm-hack-c...
About a month after the conference would be enough time to discredit an obvious connection to the conference, while still making use of security breaches that might have been found during the conference. Most security experts know you have to abandon security hopes if you give the hardware to the user with direct access. And with a conference of DEF CON's size, you only need 1% malicious actors for 300 tragedy of the commons results.
MGM's not that far away on the strip for somebody to find a security exploit, and then start checking every nearby casino to see if it works at those casinos. Found a $1 million exploit? Might walk a few blocks to see if it can turn into a $10 million exploit. Non-negligible risk from a casino perspective.
Average casino-win per customer is usually ~$100/admission. [1] Three days [2] gambling for 30,000 = 9,000,000. Hotel stay revenue helps, yet it's usually only 25% of revenue per guest. [3] Casino visitation and attendance has also rebounded significantly in the last few years. [4]
So, higher than normal costs per attendee, attendees who believe they all spend less than normal conference participants, anecdotal stories of repeated high cost issues each year to resolve (ex: concrete poured in sinks on purpose, rooms broken into, satellite dishes stolen), increasing attendance numbers in Vegas, and a multi-$10 million slap a month afterward based on social engineering.
[1] https://www.americangaming.org/wp-content/uploads/2021/02/CG...
[2] https://forum.defcon.org/node/248358
[3] https://www.playusa.com/las-vegas-casino-hotel-revenue-numbe...
[4] https://gaming.library.unlv.edu/reports/national_monthly.pdf
If there's any place in the private sector where I'd expect security (including digital security) to be literally top notch, a casino would be it.
And casinos don't fuck around. If they catch some "uber haxor" laying a finger on their networks, you can bet they'd have him arrested in a heartbeat, regardless of whether he is a conference attendee or not.
I know why you'd expect that, regardless, you'd be very wrong
Most casinos rent their gaming equipment from IGT, who directly manage most of these systems. IGT also has a fairly robust security team, having worked with them back when I was still a PM in the space.
Organizations like Caesar's aren't the greatest security wise, but that's largely because they have low margins because they are primarily property holding companies that are operating Casino/Gaming that they rent out from vendors like IGT.
This has been changing after MGM, but I don't think I can discuss it deeply.
In practice the biggest abuse from Defcon to the venues is in the form of a subset of people constantly defacing casino property which no one reports because no one has sympathy for casinos.
My favorite trolling of casinos at Defcon is the people dumping prop money everywhere. Casinos do not -like- that and spend a lot of resources running around picking them up which is funny to watch.
I'm not so sure. There's a _lot_ of drinking at DEF CON
I'm sure their insurers might not be too happy about them hosting hacker conventions these days.
I accidentally bumped into a random guy there before the con started, and we ended up chatting and he bought me a beer. I saw him there the next morning. And that evening. And at 2AM. Almost every time I walked past, the same guy was in the same seat, enthusiastically laughing and drinking with his buddies.
Dios mio, amigo.
The magnitude of entropy casinos require you inject into the system each round is quite low in practice.
Profiting off of that is all skill.
But even so we’re actually all net-positive on the city, thanks to a couple “lucky” craps runs.
And same. A couple of roulette results has us “positive”.
[1] https://investor.caesars.com/news-releases/news-release-deta...
The requirement is that the expected value for a play on a machine is >75%. And most are >90%. But that’s not a cap on profit margin, as 25% of the expense for a play may be more than the cost of that play.
Eg, having a machine that costs $1 with $0.75 expected return (and $0.25 revenue for the casino) may only cost the casino $0.10 a play — which would be a 60% profit margin.
Gaming does have expenses -- labor (mostly dealers and slot attendants & mechanics), costs of purchasing and leasing the machines, and some other miscellaneous stuff... but profit margins on pure gaming are very high (and not limited in any way by the 25% maximum hold percentage that you reference)
Now the casino has your dollar and it's "costs" were four cents in electricity/maintenance. A much higher profit tham 25%.
Other businesses are treated like this too. If you are a high frequency trading firm and you buy 1000 shares stock for $99.99 each and sell for $100, you didn't have $100k of revenue - you had $10, and your profit is what's left after paying for staff and computers.
Yes, if your business was a supermarket, it would indeed work the other way, and it's not obvious to the literal- minded where one treatment should stop and the other should start.
And perhaps is more obvious when you consider what happens when there’s only players, eg, poker. The pot is held in trust, until the game ends and the losers forfeit their money to the winner. At no point does it belong to the casino.
That doesn’t change when the casino is also a player.
So no, profit is more like gross revenue minus expenses and taxes.
You could easily have a machine with positive EV for the house that has negative profit.
There is the story that the American Physical Society was not allowed back after in 1986 Vegas supposedly suffered its worst week in history.
First of all there is no real evidence that this story is true and secondly it doesn't make sense to me that they would cancel DEF CON after so many years for that reason. They would have done so much earlier, probably.
https://skeptics.stackexchange.com/questions/39668/did-a-cas...
My suspicion is that Caesars is trying to do something like play with headcount. Late summer is not just a weak time for conferences but DEF CON needs a ton more space and a ton more human babysitting across that space than any other conference. You don't see EVO or BlackHat getting cancelled (same exactly time window) because they're pretty contained in one place.
My guess is that Caesars needs to staff up a little for DEF CON or that they may even be considering reducing staffing in late summer. Con attendees are going to stay at their properties and use their bars/restaurants/tables anyway.
...although now that I think about it, EVO was moved up 2 weeks and has a new unannounced venue this year, so maybe this isn't isolated to DEF CON. ...and also the Venetian is having its convention space renovated until 2026...
I very much doubt there's any conspiracy here.
I never heard of this. Can you tell us more?
It's basically "a no harm, no faul" termination of an existing contract, and is fairly common in competitive markets where there is no long term strategic partnership to develop an unique product.
If it's the buyer terminating it's either because the product is either no longer needed or an cheaper supplier was found, and if it's the seller it's caused by all sorts of resource optimization reasons(aka someone being willing to pay more for the same limited resources, or an increase in cost making unprofitable).
https://qz.com/work/1249513/was-a-convention-of-physicists-r... (2018)
1) Hacked the in-circuit TV system and broadcast their own pirate show
2) Gained roof access and removed the satellite dish
3) Spilled hookah coals onto the bed starting a fire
4) drove the janitor's golf cart into the pool
and that is only what I witnessed firsthand. I can only imagine what else went on. Maybe the attendees low spend was only part of the equation?For example, the ATMs on casino floors are probably some of the most secure in the nation during the con. Harassment is also taken actually seriously.
I quit going after 7. It seemed like they partying had vastly I overtaken any actual technical content. I don't drink and I'm not super social, so it just seemed like it wasn't "for me" anymore.
Edit: It has probably changed in the intervening years but every time I looked into it it seemed like more spectacle than tech. DerbyCon filled the niche for me for a few years but then it got impossible to get tickets for and imploded. (I know there's a lot of backstory about DerbyCon that I don't know, too. For me it was just a fun way to feel a little of the DefCon 3 vibes again.)
DEF CON is a hell of a party, and I hope to go this year, but the attendees are a force to be reckoned with. Even I ended up fucking up a homemade badge, and tossing a failing lithium battery into the trash in the middle of a casino, only to learn later I created a trash fire, so I know firsthand that we're a problematic bunch.
I've seen bottles of alcohol passed around doing talks and heard more than a few really off color jokes about criminal sex acts and such. Vegas waitresses have seen it all also but there was over the top behavior.
We're in a victim dominant culture now, "it's not you or what you've done, you're just a victim of evil or something" but at more than a few Def Cons and more than a few times, it was really uncomfortable to be there and see some of the stuff that was happening.
Worst case scenario is usually they tell people to disperse, but otherwise, they always seemed to laugh when they saw shenanigans (except for people fucking with Casino machines, thats a fast way to make them mad)
Also, I was a 17 year old girl at the time, and I felt sexually threatened several times during the event. That is the only place I have visited where I would make a statement of that nature.
The whole damn strip is air conditioned and misted so it's not really a problem. A few years back I participated in a scavenger hunt during DEF CON and it was taxing but I would do it again.
New Orleans is hell on earth that time of year though -- never again.
I thought the same until visiting Kyoto and Rome in August.
Cheap flights too.
Others have said August is off-peak for Vegas (perhaps because of the weather), which means its a good time for a conference as space should be less expensive.
I'm sure the other places suggested would have been nice, but you turn one flight into 2, maybe even 3, have to search for a venue and accommodation for 100s/1000s persons (even if they self book), etc
Conference tourism is big business and the big conferences want friendly places that fit their budget and make it possible for people to attend it
The heat sucks but it’s not like it’s that hard to avoid on a conference trip. It’s when you live here and have to hop in your plasma generating car that makes you wonder what the fuck is wrong with you
A high of 40C / 104F is not generally considered "nice".
But that is beside the point; is it "generally considered nice" ? - emphasis added to the words that I chose with care above.
It is not.
Checking climate for Barbados, I rate that as factually incorrect. And of little relevance.
It’s very relevant because that’s what qualifies my “considered generally nice” statement.
Your useless pedantry about beaches is becoming boring now.
The average high in Kodiak Alaska is 60F.
(But your parent was mostly being silly.)
Yes, it's hot, but you can still walk outside without becoming a sweaty mess because it's so dry. And you're probably not going to be walking outside very far, it's a very unfriendly place to walk outside of the prescribed separated paths on the strip.
The fact that it js now at the convention center and likely all under one roof is an improvement, IMO
Frankfurt also has the most international destinations (just not volume).
(Probably not Dubai, considering a few speakers would be thrown out at the border - or worse if they get though. It's also artificially inflated because it's almost all transit traffic).
https://en.wikipedia.org/wiki/List_of_busiest_airports_by_in...
Dubai is a center for large conferences and Expos.
The row of High rise hotels along Sheik Zayed Road across from Dubai World Trade Center (the largest exhibition hall in Dubai) is astounding.
Gitex, Gulfood and Arab Health are all conference that are largest in their class world wide.
And while A lot of DXBs traffic is transfers, the city does see 15 million international visitors a year, putting it in the top 5 most visited cities.
They can easily accommodate Def Con.
There’s a lot to criticize Dubai for, but they literally built the city to be a center for international conferences.
Well, they literally enslaved foreign men to work as indentured workers, stripping their human rights, in order to build the city...
Aimed largely at the MENA, SAARC, and a bit of the APJ market.
Most DefCon attendees are in North America, which makes the flight to the UAE hellishly long and expensive.
Most attendees are also expensing the trip, so a $700-900 round trip ticket plus an additional $500-700 for hotels makes Managers balk, as that's a major expense coming out of your yearly budget.
Also, DefCon sponsors largely showed up because it was occuring around the same time and same location as BlackHat
Source: travelled a lot for corporate tech conferences in my PM days.
Terrible location for any conference that cares about everyone being able to attend. While one could argue about "hiding the gay" (I'd still say that's hard to impossible), I would never be able to attend as visibly trans.
No other city in North America has a similar amount of space or options for low cost block booking.
Also, plenty of DefCon attendees and sponsors are also attending BlackHat at around the same time, so it makes it easier to justify expensing most of the cost as an employee.
Not even in Mexico? You know, the country that's part of North America? Why not just say America?
Yep. Not even in Mexico. The largest expo center in Mexico is Expo Guadalajara, which is smaller than Salt Lake City's Salt Palace Expo Center.
> You know, the country that's part of North America
Ik it is. I'm usually the one who reminds people about that on HN
And that is precisely why DEFCON is there in August - demand is weak so prices are low. They even state as much in their FAQ.
DEF CON is listed as a "hacker convention held annually in Las Vegas, Nevada." where Blackhat is "Black Hat is an internationally recognized cybersecurity event series providing the most technical and relevant information security..."
I imagine places like the convention center cant afford or care about insurance at this level.
It doesn't provide information, it just provides sales suits a chance to blow their hot air :P
If I'd ever go there it would just be an excuse to go to vegas to see DEF CON as well :P I work in security but I have no time for corporatism and sales bullshit.
Edit: I know it's a bit of a hot take but I've been to so many conferences where sales goons spew all the pretty pictures and then later when we actually got our hands on the product it turned out that it couldn't do half the stuff that was promised. Or there were other weaknesses like excruciatingly bad support. I've become very cynical due to this.
Just read it as showmanship. They're trying to be over the top for the sake of performance.
Black Hat is peer reviewed and accepts a tiny fraction of submissions (tracks will accept 3-5 talks out of a typical pool of 20-50). Reviewers --- all of them vulnerability researchers --- barely have time to read outlines and look for any possible excuse to DQ a submission and move on to the next one, and the single most common DQ is "the presenter has a commercial interest in this topic, vendor talk, 1.0 rating".
There is also a giant vendor expo that runs alongside Black Hat, and vendors do whatever they can to stage events that look like Black Hat talks but are not. I submit that you have probably confused those for actual talks. Or: you watched the keynote? I don't understand what the keynote is for.
Here are the actual 2023 talks:
https://www.blackhat.com/us-23/briefings/schedule/index.html
> No I haven't been there
The first sentence is not true. Many good talks are give, often breaking ground. Yes, you can find sales pitches, but there are good fundamentally technology talks.
Anyone that takes this scene seriously knows Defcon is the place to be. Blackhat is a overpriced vendor circle jerk. The only way to make Blackhat relevant again is to kick out all of the vendors and if you can't do that, forbid them from collecting peoples information.
This is going to be my 11th year at Defcon this year. I snuck into a couple of blackhats and didn't get any value from them. I've been around the block a few times.
You think insurance providers are capable of doing this level of analysis? They see "hacker conference" in which Defcon may still hold some notoriety in and decide it's a risk.
I don't think this was done because of cyber insurance
They most likely got bumped to make space for a better paying corporate conference.
Most vendors are now running a Cisco Live/AWS Re:invent type conference, and they've increasingly consolidated on Las Vegas because venue booking and block room booking is much easier there than in any other city in North America.
Also, DefCon has become massive, so the RoI has most likely shrunk due to staffing overhead.
This is the occams razor explanation
The infosec industry sorta runs separately from the rest of tech in that it's entirely a status economy. Name recognition, certification and publication are the most important things to maintain stable employment.
On the other hand none of the planned programming at DEFCON has any professional value whatsoever and it's merely a metacon for connecting with people in varying niches in the space.
I don't care if you go or not. I'm not trying to sell anybody on Black Hat. If you work in this field, you know what Black Hat is, and if you care about Security Summer Camp you're in the lobby bar at Mandalay. My only nit here is people claiming that the actual Black Hat conference is a vendor event (like RSA). It is not. Almost every good Defcon talk was a Black Hat submission (as you'd expect; it's the highest-status mainstream security conference, and it pays honoraria and travel expenses for speakers). There's a whole other conference, BSides, that started just to soak up the talks Black Hat doesn't accept.
e.g., the only reason I would go is if I needed to for industry certifications. Talks aren't a reason for me to go to anything (they'll be streamed eventually and I can filter them better). I'll agree the talks are better here than most other events
I guess if your employer is footing the bill, sure, fine, whatever.
Talks having no attendance value to me might be a personal thing, but you can blame Netflix and re:Invent 2017 for that. I sat through 4 different talks given by 4 different people that were supposed to talk about different parts of their architecture but were basically the same slides and staff engineers from 4 different departments claiming responsibility for the same parts of the system. Sure that has nothing to do with Infosec, but talks can be an epic waste of time and I'm much more suspicious of them these days.
I can see not wanting to sit through a bunch of vulnerability research talks! Defcon is certainly the more "fun" event.
There are higher-status (non-academic) research conferences, but they're not mainstream. Of the events everybody knows about and that employers at pentest firms will pay to have people develop talks for and employers at F500 security teams will pay to have engineers attend, Black Hat is basically the most important event of the year.
I find this aspect intriguing, and seems to contribute to the buzz around the event? Used to be true in some other areas of computer science too, but outside of security I can't think of an academic conference where it still happens. Nowadays you can almost always expect talks at top conferences to have preprints posted on arXiv (or openreview.net) ahead of the talk, often weeks or months ahead. I mean not that somewhere like NeurIPS lacks buzz either, but you're not normally expecting major surprises in the talks.
I'm a longtime reviewer for Black Hat, and I've reviewed (shadow) for ACM and (publicly) for Usenix (I was a PC for WOOT a few years ago). It's a different vibe. Nobody's WOOT submission got dinged for having been disclosed in advance, but Black Hat submissions will get dinged for having been presented at regional conferences prior to BH.
Again though: the single easiest way to make sure a talk has no chance at BH is to make it vendor-y. Reviewers will LinkedIn-stalk the names on the presentation to make sure nobody's connected to marketing or sales. If you're submitting something that's even tangential to your product (smart toaster firewalls), even if it's good research (elite-level zero-day vulnerabilities in smart toasters), you have to go way out of your way to assure reviewers you won't pitch on stage.
Black Hat is pretty sensitive to making sure the talks themselves aren't commercial, even though the conference trappings are extremely commercial. "This would make a better RSA talk" is an extremely common epithet.
And that makes sense. Talks aren't really the point of Defcon, and they are (besides the lobby conf) the sole point of Black Hat. Black Hat is also a vendor circlejerk, but that fact confuses people who don't actually practice in the field.
I have personally worried after seeing Cesars transform after the events at the Mandalay Bay with the new addition of their own paramilitary group (the SRTs) and their actions during DEF CON. Just check out their job descriptions: https://www.linkedin.com/jobs/view/security-officer-srt-i-fu...
Before the SRTs, I personally know from knowing the staff who run the conference that they have helped Cesars Entertainment in previous years strengthen and work with them hand-in-hand to secure their networks and train their staff. Even work with the goons to make sure people didn't get trespassed over shenanigans. I honestly think the mid level management is sad we are gone.
The other side is the Okta was just a taste of what could go wrong. Seeing MGM totally shut down and loosing millions was scary for upper management. Auditors weren't comparing Blackhat to DEF CON but that the listing on the spreadsheet was not "boat show" but "hacking con" and they deemed that was too much risk for the level of coverage Cesars Entertainment wanted.
Never the less, we all hated Cesars and I am personally excited to see what this next year will look like.
In 2018 we had aggressive room searches post the Vegas shooting that caused a lot of friction: https://arstechnica.com/tech-policy/2018/08/security-theater...
Point being that it’s been a rough ride over the last few years. Combine that with corporate events probably being far more lucrative for Caesars I.e suits drink and gamble harder than geeks - I’m not surprised by this.
TBH my team and I skipped DEF CON last year and threw our own event in Banff instead because DEF CON has become quite boring with long lines and a Groundhog Day feel to it. If you’re looking for a proper con check out a local B-sides or a smaller legit con like Shmoocon.
I heard it both from Dark Tangent and several high level Goons.
When I'm at DEFCON, I bring a fun little device. It's an ESP8266 that constantly listens for WiFi probes coming from people's mobile devices. It then displays the SSID (the network name) on a scrolling LED text display. I keep it plugged into one of those Anker battery banks. 10,000 mAh will power it for ~16 hours, so it lasts the entire day.
<tinfoil hat> I wonder if the ransomware incident last year played a role in this decision? [0] I'm guessing they wouldn't announce it for fear of boycott, but who knows. </tinfoil hat>
[0] https://www.cnbc.com/2023/09/14/caesars-paid-millions-in-ran...
This makes more sense to me than the other explanations. Probably coupled with an underinformed general manager or company president.
I’d wager a bet that the perpetrators of the hack had visited Cesar’s during defcon
Too many "security researchers", "staff engineers" and people playing politics.
But I suspect they will have no problem finding another venue, sponsor money has been flowing quite well, so I wish them well.
And AP was tolerant of people treating their property like garbage. Caesars' certainly doesn't.
It's nice that it has continued to grow and reach more people but it has also changed a lot from what it used to be to what it is now.
Socialising, learning hacking history, and getting to know the traditions is always a great side effect that the DC crowd's been good at passing on to new generations. Goons still give people shit for misbehaving, speakers still take shots, TOOOL still has some of the best workshops and tutorials on the conference floor and usually has some people who'll talk about breaking open Medecos or Fichets to anyone who'll listen.
I'd venture to say it's against the spirit of the con to try and gatekeep it.
Having said all that (and the irony not being lost on me) -- linecon's definitely getting worse, and I'm worried that DC's becoming a victim of its own success, with its accessible pricing and subject matter being counterbalanced by having to manage a 20-30k person crowd. I don't have a solution for this outside of decentralization, but I don't know if that's a good solution.
While you're over there look around for the Tamper Evident Village and we'll happily demonstrate and allow you to try removing Tamper Evident Seals of various kinds.
I forgot these when I wrote my original post at 1AM :)
Here's at least one source corroborating that[0]:
> "I think it's from around DC6 and is a reference to our only near brush with cancellation at the Monte Carlo for DC4," Def Con spokesperson Darington Forbes wrote me in an email. "I wish I had more to tell you—since it happened seventeen or so years ago my info is murky. Something about a casino mogul preferring we not use the Monte Carlo, threats of legal action."
> @ivydigital DEF CON - cancelled annually for over 20 years
> — Rich Trouton (@rtrouton) July 31, 2015
[0] https://www.vice.com/en/article/ezvez4/def-con-is-cancelled-...
It is absolutely related to DEF CON. Remember that Caesars suffered a massively embarrassing hack in September, and it is highly likely the top brass and investors don't want any association with hackers from an image and security standpoint, especially in the form of hosting a conference that brings tens of thousands of them to the hotel.
Perhaps they no longer want to be known for being the place where the "weirdos" are bouncing around the hallways. A la the poor normies staying at a hotel during a fur convention, or trying to get into the bar during a meet (though the whole place is often hired out by us; we _definitely_ provide enough alcohol revenue)
Honestly though, if your venue gets turned upside down by a Flipper, you should probably change a few things...
After a great 25 year relationship Caesars abruptly terminated their contract with DEF CON, leaving us with no venue for DC 32, and just about seven months to Con!
We don’t know why Caesars canceled us, they won’t say beyond it being a strategy change and it is not related to anything that DEF CON or our community has done. This kind of no-notice cancellation of a contract is unheard of in the conference business. The parting is confusing, but amicable.
TL;DR - DEF CON 32 will still be August 8-11 2024, but now held at the Las Vegas Convention Center (LVCC) with workshops and training at the Sahara.
Not sure on transfers. They have negotiated with Sahara on a rate and are looking to add more.
You can cancel up to 72 hours before the reservation. New room blocks are still being negotiated and will be posted at (link) as they become available. Please help us negotiate rates by booking rooms in our reserved blocks.
https://www.securityweek.com/caesars-confirms-ransomware-hac...
Hope this allows them to really spread their wings a bit more.
I started going to DEFCON in 2017 (DEFCON 25). After last year's event, I had decided I wasn't going to go anymore. The villages were always extremely crowded, so trying to actually participate would be a huge wait. The talks were nice, but I can just watch them on YouTube a month or so later. Hacker Jeopardy is always a blast, but I'm not going to spend $2,500 to fly and stay in Vegas just for that.
The fact that Red Team village would only be given this tiny conference room with only like 50 chairs to listen to talks was just bullshit.
If the new venue has more room and solves all my complaints, maybe I'll still go.
Someone probably convinced them their new fancy XDR is hacker proof and they are playing for skins now.
Def con was something I would be looking forward to and if my work paid for black hat I could have stayed the extra days to go there.
If nothing else, you might join the newsletter to see if it's your cup of tea later in the year.
Boston might be an option if it just happens to be around a time I might visit for work (but again I've never been there in my life so it's not all that likely even though we have a major office there).
In any case, thank you for entertaining the idea :)
It's the enterprise sales hookup thing that attracts most visitors though. The people from our company that go there go mainly for that. They're all VPs and other suits that have no interest in specific vulnerabilities. They just want the free wine and dine and to feel important.
I couldn't imagine going to that kind of thing. I'd only put up with it if it would give me a chance to go to Def Con :)
And it's really the Def Con social scene I'd be interested in. I'm not a vulnerability researcher either, I'm just very informal, I'm not comfortable socialising with business people even though I work in enterprise security. So I think for me black hat would be pretty boring.
What I love about the grassroots hacker conferences is the free sharing of information without commercial strings attached (in fact here in Europe people get booed off stage when they pull out the sales pitch) The presentations not vetted by PR departments. The tongue in cheek remarks against big tech. The activism. Drunkenly running into other makers and making good friends. Exchanging business cards and finding a new vendor is definitely not on the list. I don't normally go to too many of the talks either, especially not the huge ones.
To be fair, I don't think they crashed; I saw a "sorry too much traffic try later" type message. Still amuses me.
... if you're willing to trust another company with your data.
1999.
That’s exactly why it should be resilient. A fully static text-heavy site can serve basically unlimited traffic on a free host or a $5 VPS these days.
That's a big claim to make. Can someone with relevant experience confirm whether this is true?
Count me out. LVCC is even less cool than Caesars and it's a mile from the strip. It's only selling point is the Loop.[0] In the past, it was convenient to book at Caesars, or nearby at the Bellagio or Venetian-Palazzo.
0. https://en.wikipedia.org/wiki/Las_Vegas_Convention_Center_Lo...
Looking on the bright side, having a better option for a snack or meal on site would be nice. It was slim pickings in 2023.
I love this sounds like a pun about loading/executing a payload.
Pretty sure there was no vax check in 2022 and 2023, and I do know some people who got COVID in those years, but people who took decent precautions were generally able to dodge it.
And as the other commenter said, the information wasn't recorded.
Also, the majority of DEFCON attendees no longer care about being anonymous. It's not this secret underground thing. Many employers pay for their security staff to go to DEFCON. For a few years now, you can even pre-pay for your ticket online with a credit card which makes getting reimbursed for your ticket a fuckton easier. Also means you don't have to carry $500 in cash.
I go to a lot of European hacker parties/camps and I can certainly recognise the mindset you mention (and I identify with that mindset as well even though I work in a corporate job). For this reason Las Vegas made no sense to me but in light of your comment it does now.
And yeah getting ridiculously drunk is definitely part of the experience :D
Since we are talking about stuff that we don't think should be associated with hacking this is my own pet peeve. What does "getting drunk" have to do with hacking? And why is it always "absolutely smashed" or "ridiculously drunk". I get that most hacker types are shy introverts and couple drinks makes things more fun and socially fluid, but why does it need to go to hangover(s)? 9
This is primary reason which keeps me away from many "hacking camps", they are cool for couple hours, but as the sun goes down things just get sketchy and boring when I have to take care of bunch of drunk strangers.
Then comes the cost. August in Las Vegas is off-peak season which helps keep the cost down. Anywhere in Silicon Valley (or really anywhere in California) would be insanely expensive.
There's also convenience of travel. Las Vegas is such a huge tourist city that it makes getting flights there cheap and easy no matter where in the world you're coming from. My first time going to DEFCON was in 2017 and my flight from Portland OR was only a hair over $200.