Room inspections at Resorts World confuse, annoy DEF CON attendees
reviewjournal.com
reviewjournal.com
Yesterday, I poked another friend to see where they were at the conference. They were not at the conference. They were stuck at resorts world three hours after the conference had started. Their conference badges had been confiscated by security. The security team had tried to force them to throw them in the garbage, and for a while it appeared that security had thrown them away after they had confiscated them. It’s literally just a fancy gameboy!
This isn’t a safety issue, it’s deliberate, malicious abuse by a vendor who knowingly sold a discounted room block to defcon conference attendees and then, through persistent and abusive behavior, tried to force those customers to leave once they checked in. The issue was mentioned early in closing ceremonies as something that will be addressed with the vendor once all conference attendees have been checked out of the hotels. This wasn’t random room check for caches of weapons. It was not a safety search. It was luggage contents searches for the lulz, seemingly intended as harassment. Either they didn’t want us there in the first place, or they wanted the revenue for the rooms forfeited. This was not behavior in good faith and the specific acts that I witnessed personally and others whom I trust communicated to me that they had experienced directly, could only be intended as harassment or profoundly extreme incompetence.
For 20 years, I’ve stayed almost exclusively at Hilton properties when I travel, with the exception of Vegas for HSC. I’m almost certain to switch to another company after this, unless they issue a really, really, excellent apology.
Quit your BS excuses about how this was a legitimate safety issue. This was almost entirely limited to one hotel. Somehow another 10+ major hotels, including Caesars who non-renewed the conference contract, managed to not do any of this.
Edited for spleling.
And that’s assuming they thought about it all, instead of just forwarding a vaguely remembered email.
I'd consider calling the police in a situation like this. "Officer, these men stole my conference pass, which I paid ($$) for, and they won't give it back."
Imagine singling out a group of people who previously had no ill will towards you for targeted harassment and that this exact same group of people also had the capability to fuck with you in unpredictable ways without getting caught.
This is literally the most fundamental 101 intel / LEO thinking of: means, motive and opportunity.
If I were them I’d be doing my best to make up for this starting with some serious apologies and firing whoever came up with this idiotic idea.
Some clever hackers figured out how to use the phone system to make them think housekeeping had been there[0], so now they do inspections when BlackHat/DefCon is in town because they don't trust their own tracking systems.
[0] One of the hotels had housekeeping dial *5 on the room phone when they entered the room to clean, and then *5 again when they left. So some hackers would put out their "do not clean" sign and then just dial *5 twice 10 minutes apart so no one would get suspicious.
> Since the festival shooting Vegas hotels have a policy of entering every room every 24 hours
> so now they do inspections when BlackHat/DefCon is in town because they don't trust their own tracking systems
What's the difference between these two statements? It sounds to me like the only point is that they have a manual ledger to track inspections, which is probably for the best, given that any would-be domestic terrorist would surely know how to use Google and find this information too.
One describes the policy. Which is what they want to achieve. They want to achieve that a hotel employee checks on every room every 24 hour.
The other describes that they don't trust their usual implementation during BlackHat/DefCon.
> which is probably for the best, given that any would-be domestic terrorist would surely know how to use Google and find this information too.
The whole thing provides probabilistic protection anyway. (Also known as a security theatre, if you want to be uncharitable.) A determined attacker will appear as a model hotel guest up until the point they want to attack. Then they wait until housekeeping is done with their room and move their weapons in the room only after. Hotels are full of people moving luggage around at all hours so this won't be suspicious to anyone.
The policy will probably catch some would be attackers (the dumb ones). It will also probably uncover a lot more drug overdoses/suicides/murders/sudden heart attack victims, several days earlier than they would be uncovered otherwise.
I bet that for every Stephen Paddock found there is at least a hundred "oops this room has a dead person in it for some reason".
I find it puzzling how you (and all the other commenters here) accept this rule like sheeps. Normally, you US citizens cannot stop boasting how the USA is supposedly "the land of the free".
So don't take this personally, I'm replying to this as to all the others that appear like they find it totally normal that some security guy or hotel cleaning can enter a rented room. Every 24 hours, or at all. It's not normal. And IMHO not even needed / helpful.
No 24h check will ever hinder a mass-shooter. The criminal would just wait until room cleaning made their job, then go to his car and get the big suitcase with all the guns and ammunition one can buy entirely too easy in the US. And then he can shot from his room, minutes after this compulsory do-nothing 24h "security" check.
Here, were I am (Germany), things are completely different.
First, it's not so easy to get weapons. Not even at gun exhibitions. That in itself helps tremendously getting a less violent society.
Second, here we have the right, upheld by courts, that a hotel tenant can make the hotel not enter his room. A "do not disturb" sign is everything that is needed. If you want, you can look it up under "Frankfurter Landgerichts aus dem Jahr 2009 (AZ 2-19 O 153/08)".
Sure, there are other rulings that landlords (including hoteliers) have under some circumstances the right to enter a property they rented out. Like fire, or water pipe broken. Actual, imminent danger. Not hypothetical danger! But they even cannot get a general "you can always enter" term signed, that would be null and void over here.
The more free private entities are from government oversight, the more carefully they have to read contracts. For example, even the US is not quite so free as to allow people to sell their organs. If it were, citizens would have to carefully read room rental contracts at hotels, to make sure there were no conditions which included forfeiture of a kidney.
(FWIW, I'm now living in Germany, and it's significantly more relaxing with a bit less freedom. There's definitely different tradeoffs which make more sense for different people).
Here in Germany, I'm not magically immune to crime, but the base rates of gun crime are so low that I never worry about loud bangs. That comes at the cost of the freedom granted by the Second Amendment in America.
Another, slightly less salient & serious example: Germany has strict laws about public photography. Take a look at any "embarrassing pratfalls" or "annoying Karens" video reel: They may be US-weighted, but they come from all over the world--but not Germany. The lack of freedom to document the people around you on video trades off with the security of knowing you can slip on a banana peel without being known worldwide as "the banana peel guy."
What do you mean "accept this rule like sheeps"? Do you expect violent resistance? Do you want to sue someone because a security guy poked their head in the room for 30s? How would "I do not accept this rule like sheeps" look like in your opinion? How far would you go resisting it?
> you US citizens
Wrong assumption.
> So don't take this personally,
I won't. Clearly you don't know anything about me.
> appear like they find it totally normal
I can explain what is a fact of life (they have this policy) without expressing my opinion about it.
> No 24h check will ever hinder a mass-shooter.
As clearly stated in my comment.
> The criminal would just wait until room cleaning made their job, then go to his car and get the big suitcase with all the guns and ammunition one can buy entirely too easy in the US. And then he can shot from his room, minutes after this compulsory do-nothing 24h "security" check.
Yes. Exactly this is described in my comment.
> that would be null and void over here.
Thank you. Interesting addition to the conversation about how it is in Germany. Different places have wildly different legal norms and expectations.
For me it is hard o get upset about this either way. A hotel is a different type of arrangement than renting.
The protocol for non-DefCon rooms:
* Housekeeping services the room.
* If housekeeping was unable to service the room, security will come take a look.
The protocol for DefCon rooms:
* Security comes and takes a look no matter what, and is, from reports, particularly invasive.
* They have to visually inspect upwards of 1000 rooms every day looking for vaguely electronic looking things
* They have to use Microsoft Teams
Poor Hilton employees...
That’s the explanation for the behavior not the behavior itself.
Last time I traveled the concierge looked at me as if I was some horrible person because I requested daily housekeeping, not this "on demand" nonsense which has sadly become pervasive.
They don't change sheets or towels ("for the environment")... just inspect the room, then leave.
Thanks for clarification
Washing your towel after every use is incredibly wasteful, and unnecessary. If the towel is "dirty" after you've bathed and used it to dry yourself off, then you probably should do a better job cleaning yourself while bathing.
What I suspect is that people here have massive washer/dryer combos that slurp oodles of energy, and use them only infrequently?
We can only fit one day of the clothes for the entire family in a single wash, therefore washing happens every day.
But on the other hand: If you didn't have to wash everyone's towels every night, would you still have to do laundry daily?
Bigger washer/dryers are not necessarily more wasteful, for what it's worth... it really depends on their efficiency (both for water and dryer heat). Sometimes doing it in bulk all at once can save water/energy per item even if it uses more overall. And newer machines tend to be a lot more efficient than older ones, especially if they are load-sensing front-loaders. Anyway, that's not really the point.
It's just interesting that your laundry patterns are different than anyone I've ever known. Thanks for explaining, that's all :)
Sure we could wash less if we really wanted to, but it just doesn’t signify. The washer uses like 40L of water over 30m of runtime and then it’s done. We hang the clothes (and towels) outside, and by evening everything is fresh.
The shower runs at about 10L a minute. I think you can see how the washing quickly becomes irrelevant, and the shower needs to be heated too, unlike the washer.
Do you really wash your towels after each use? Why? How?
Presumably the same as everyone else, by putting them in the washer.
Hell, a lot of hotels were doing that before the pandemic. I thought it was a really good thing. I certainly don't need my towels replaced every day; that's just pointless and wasteful.
Haven't been to the US though...where is the connection to COVID?
After covid, many hotels never fully returned to daily housekeeping, often opting for every other day or so. Some still don't offer it until you check out. Guess they rode the covid coattails for the cost savings.
I use my imagination. The most likely answer is that there was a check and they haven't noticed because they were out and about.
On a balance of probabilities without hearing more on how they specifically verified it I will still assume the alternate hypothesis. Which is that someone on the internet is very sure about something and they are wrong.
It is not due to a lack of imagination. Or because I haven't heard some cool spy trick you have heard about. It's because I find it (in the absence of other information) the most likely explanation given a lifetime of observations about human nature.
C’mon.
These are the same people that started to not change linens or provide new clean towels unless you ask (or infrequently) for ‘environmental reasons’. (Aka profit margins)
And yes, back in the day it was normal for housekeeping to clean every occupied room every day, unless you told them not to. Unless you were in a roach motel or something.
I don't understand why you would not want them to clean your room as it's included in the price.
Most hotels stock at least two rolls of toilet paper too. I’ve personally never run out of toilet paper this quickly.
Most hotels I've stayed at give you at least 2 or 3 rolls of TP, and while the soap bars they give you are small, they last more than a week, easy.
answering for myself, having been in too many hotel rooms in my lifetime:
it's easier to ask for towels and toiletries than deal with binding arbitration after having things stolen from your room. I can make my own bed.
It's all in the small print too which nobody reads (these hotels have legal advisors).
Room service counted as a room check so security only did it if you refused room service.
Seems like whoever drafted this policy has no idea what they're talking about given USB drives and empty breadboards are on here
DEFCON attendees having mandatory daily room searches by conference block hotels - https://news.ycombinator.com/item?id=41222930
You need to remember that America is stupid enough that working on calculus problems on a plane, is enough to delay the plane and get searched because the person next to you thinks you're a terrorist: https://www.washingtonpost.com/news/rampage/wp/2016/05/07/iv...
I expect privacy in any home where I live, whether it's for a decade or for a day.
When the door closes, it's "my personal space" for the duration I paid for.
Of course, now Vegas begs to differ.
And they can’t come do inspections day after day.
In the UK. The law requires notice.
Yes, a property you rent is your home. It's not your property, though.
The safe is there because they acknowledge that quite a few people have access to the room and they can't be 100% sure that all their employees are good people who wouldn't steal, even if they expect them not to. Not because they intend to send randos into your room at all hours of the day.
(And it's not clear how many employees have access to override the locks on the in-room safes... I've always thought of those safes as borderline security theater.)
I wouldn't call a hotel stay "home" either, but I expect the privacy situation to be only slightly weaker than an apartment rental.
Hell, I own a unit in a condo building, and our building insurance requires annual inspections of the sprinklers and fire alarm horns. I know someone who owns a condo in another city, and the building does (required) quarterly spraying for cockroaches, and replacements of the air conditioning filters. None of us feel like we don't own these spaces.
The other obvious question is, did the people who "cyberattack" them do so from _inside_ their own hotel? Is there some reason to think simple visual room inspections are going to help prevent their networks from being attacked?
None of these are logical responses to the stated problems. They're just ways to reduce privacy with a very thin corporate liability excuse tacked onto the end of it. I don't trust that they can people safe, and I don't trust their motivations in deploying these "techniques."
I'd rather sleep in the tunnels with the homeless at this point.
He claims they implemented policies in 2015 to enter and inspect all rooms after more than 12 hours of DnD. In other interviews he admits they "profile" everyone that enters their hotel.
https://nypost.com/2017/10/08/vegas-shooting-wouldnt-have-ha...
Eh, I guess I'd trip flags there. I typically put up the DnD on checking in at a hotel and leave it up until I check out. It's not a principled stance or anything, I'm just never staying for an amount of time (i.e. more than a week) where I'd need housekeeping services so figure I can save the housekeeping staff some effort and save some water.
If they really have "more cameras than anywhere else" and if that even mattered, then its already covered.
It would be orders of magnitude cheaper to put cameras in every single room, with a big sign saying this camera turns on every 4 hours with a big red light, and then if you cover it up a physical presence will occur.
Instead they go with: SHOW ME ALL YOUR USB DRIVES. Same shit as covid, if you make it normal for "officials" to touch and make copies of everything all the time everywhere, then there is no such thing as crime anymore yay
Also I think the average hotel guest is completely fine with maids entering during the day when the room's unoccupied, but would not appreciate a camera in the bedroom, with or without a big sign and a big red light.
The objective is not “make sure nobody in Vegas has a gun” the objective is “prevent a mass casualty event like the previous one”
Obviously the “tool” makes a difference, otherwise the tool wouldn’t have been used.
I found an interview where he just mentions "devices" amongst other extreme security measures.
- "Devices" at every entrance that the public can't see
- 40 Plain clothed, armed, former Marines trained specifically for guarding US embassy's at each entrance.
- Seal team and CIA agents that form private counter terrorism that have direct communication with FBI etc.
Is it not possible to create new policies that are effective while not compromising the privacy of your guests?
If they are looking through everyone’s rooms I would hope they find this now as he took days to get all of the guns and ammo up to his suite. I am not law enforcement and can’t say for sure though. The US has done a lot worse in the name of terrorism (I believe this was a terrorist act).
If he leaves the guns in the cases it just looks like he has a lot of luggage. He had a huge suite. If it didn't look odd to them in the first place I can't imagine how it would in retrospect:
Hotel staff certainly wouldn't find that with room inspections; they'd just see three or four pieces of luggage, which shouldn't raise any eyebrows. Then when the shooter decides to get started, they take everything out of the cases and set things up.
Like... this isn't rocket science. The only kind of room inspection that would actually stop these kinds of attacks would be if they do room searches, including opening and going through people's luggage. But I hope we can all agree that would be a huge invasion of privacy that no one should accept.
Of, course the actual way to stop -- or at least drastically reduce -- these sorts of attacks would be much stronger gun, ammo, and accessory controls. But of course the mouth-breathing 2A crowd (including most of SCOTUS) think guns are more important than people's lives.
For instance, he had bell desk bring 22 large suitcases to his room over a few days. That's a huge red flag that would not go unnoticed now (and there's likely some procedure about logging/reporting since then). Prior to that event, nobody logged or even paid attention to such things. When you work with whales in Vegas, you just get used to eccentric rich people being eccentric rich people. Now you're at least aware of threats from people posing as them.
I would go straight to the front desk, demand my money back for that day and then never stay with hotel again along with making sure the corporate office got a nice email about their bullshit policy.
Maybe over priced Vegas hotels can do this but any hotel I have ever stayed at needs to make the customer happy because the competition is so fierce. Most hotels will go out of their way to make sure you are happy. Not randomly inspect your room like you are a child.
Any longer than 7 days for inspecting and cleaning every room is asking for pest infestations, or worse.
As a hotel customer, I would not want to stay in one that does not a policy of frequent room inspections.
Yeah I can't imagine ever willingly going there (eg unless my work forces me to). It's a very curious choice for a community with so many privacy activists. The shooting excuse for the inspections is stupid. Anyone could walk in and set up in 10 minutes.
what motive would they have that is so important that they insist on spending money on low skill headcount to enter thousands of rooms per day?
honestly i'm struggling to sort out what scheme they're running that makes this headcount investment worthwhile.
95% of these rooms are being cleaned anyway by low-wage staff. The added 5% is such a small percentage.
But the shooting excuse is an excuse because they're not even liable for this. Any idiot can do the same from their private apartment. A mass shooter has no survival expectancy anyway. They can just rent a private flat and do it. Or they can just rent a room, bring their guns in and start shooting during the first day. It doesn't actually solve the problem at all. Only 24/7 video surveillance would do that which is obviously untenable in a hotel. Or strict gun controls which is why this isn't a problem in Europe but the US just can't get that into their heads.
The other reason I consider it an excuse is that in this case they are not causing hassle about firearms but about technical devices. Nothing to do with shootings at all. If the motive was purely looking for guns they wouldn't be harrassing unarmed defcon visitors.
I don't think they actually care about shootings but that it's dumb security theater to make customers feel safer which they probably see as a monetary benefit.
Knowing this now I definitely will refuse to visit Vegas even if my company tries to send me there on a business trip. Although to be fair I kinda have this policy already for the entire US because I'm not willing to give up my devices or my social media accounts to border patrol either.
https://www.nbcnews.com/news/us-news/court-approves-800m-set...
> A court on Wednesday approved a settlement totaling $800 million from casino company MGM Resorts International and its insurers to more than 4,400 relatives and victims of the Las Vegas Strip shooting that was the deadliest in recent U.S. history.
The liability in this context is money leaving the business’s pocket due to performing or not performing X action, regardless of who the money goes to.
The motivation could merely be a desire to capriciously wield power over others. You see this in physical security careers from mall security up to actual law enforcement. Plenty of people get into these security-related roles simply for the ability to unaccountably bully and intimidate others, and will eagerly do so if given the chance, regardless of monetary cost or reward. I wouldn't be surprised if a hotel security apparatus were in favor of being allowed to enter rooms at will just because they want to.
While this is happening, the person on the inside can totally thwart the attack by just blocking the tool physically - it's hard enough to do this while you're not being interfered with.
The goal is then to establish identity, purpose, and ultimately deescalate. And then if need-be call the police and/or chargeback your credit card later.
Until otherwise verified, this intruder is no different than a random burglar breaking-and-entering in the middle of the night.
Mass shootings happen because the US has one of the most-armed citizenry in the developed world, and because we have ridiculously backward views about how easy it should be to put deadly weapons in the hands of anyone who wants one.
Daily room inspections are not going to stop any mass shooting where the shooter is aware of the inspections. The 2017 case was egregiously bad, certainly, with the shooter able to bring an insane amount of weaponry up to his room. But he could have been just as deadly with the contents of two or three regular-looking suitcases, something that wouldn't have raised any red flags during daily room inspections.
It's security theater, plain and simple.
Our government is currently trying to use the recent riots as an excuse for even more surveillance and censorship.
The arguments include "the rioters used social media". That is one reason its going to be easy to catch them. They themselves were posting photos and videos - self-surveillance.
It is very much what the media are doing: one local news website compared what happened in their town to Kristalnacht when what happened was 12 houses had windows broken and some cars were vandalised. Nasty, but hardly a fascist takeover.
On the other hand, the media do not balance it with equally wide reporting of things such as local builders doing free repairs on mosque in Southport, or the far larger crowds that turned out for counter protests.
Crime IS a normal occurrence. Riots will happen. You should not compromise human rights to deal with it.
There are blatantly racist social media posts - FB is infested, and I agree showing such posts so widely (no doubt because they get high engagement because people feel impelled to disagree with them) shows FB in a bad light.
One alternative is using the huge footprint people have left on social media (to say nothing of phone location data) to catch the people involved.
As a brown British person the riots have not caused me any great concern (contrary to what some posturing politicians may claim). Yes, it might be different if I lived in an area very close to where a riot occurred, but most people do not. I still think the UK is a lot less racist than the other countries I have lived or worked in, or no anything about, and a lot less racist than if was when I was young.
Remember that you're also free to open a hotel that doesn't have this policy and there's plenty of cheap land to be had very near Vegas. If you're right that this is something people want then it should be quite successful, maybe it can host the next DefCon. That's the American way to solve the problem.
Additional regulation generally yields less overall freedom.
The protocol for non-DefCon rooms:
* Housekeeping services the room.
* If housekeeping was unable to service the room, security will come take a look.
The protocol for DefCon rooms:
* Security comes and takes a look no matter what, and is, from reports, particularly invasive. E.g. asked to look for USB sticks as evidence of "hacking tools": https://x.com/d0rkph0enix/status/1822879409126162779
Housekeeping is neither trained nor spending time to performing a deep search of anyone’s room. But they do know what a pile of guns look like, and they’re instructed to escalate the situation to their superiors if they discover it.
* Housekeeping is optional, and not preferred. Housekeeping never shows up. * Security is never seen once on any floor above the ground level.
This has been my experience in Las Vegas in 5 different hotel rooms in the same hotel this year. These were 3 to 4 day stays. If the stay is longer than that then maybe a visit from security is more likely, but I didn't see them at all in the afternoons, evenings, mornings, any time. There was a security guard at the elevators on 1 day out of all the days I stayed.
The "protocol" probably depends on the hotel, where it's located, the events going on around Las Vegas at the time, and probably what the budget for security is.
The reports of mandatory security coming from "locals" and others in the comments here seem pretty wild to me, and far outside of what I've experienced in Las Vegas in the last year.
Because it's part of the United States, where personal freedoms are supposedly respected. Reading so many comments describing daily room searches at hotels as just the new normal state of affairs makes me sick. I hadn't been aware that the terrorizing mass media had ruined hotels even harder than they ruined air travel.
Hotel rooms are a different matter, though. People should and do expect levels of privacy similar to that of a rented apartment. (Lower levels, but similar.)
I expect privacy in any hotel room, regardless of where I am. Certainly not the same level of privacy I'd expect in my own home, whether purchased or rented. But daily security checks? No way, that's unreasonable. If I've put up the "do not disturb" sign, I expect no one to enter my room, at all, except in an emergency, or in a non-emergency where I'm present and have agreed to let someone in. That seems to me... entirely normal and reasonable to expect.
> there are more cameras and technology watching you here than anywhere else in the US
What does that have to do with it? Just because casinos want to watch what's going on to prevent cheating (or just too-good play), that doesn't mean the hotel-room privacy situation should go to shit.
My last few trips to Vegas I stayed in Airbnbs; I guess I will continue doing that for the foreseeable future when I visit.
Are there any huge advantages to staying in Vegas? Why not another city, perhaps with negotiated privacy for rooms at choice hotels?
Search results are saying that defcon sees some 30k people. The 2023 Chicago Auto Show had 300k. Major city with all the amenities.
https://www.chicagoautoshow.com/the-2023-chicago-auto-show-c...
It's very capable to handle large conferences and does throughout the year.
Historically, Vegas had a cost advantage. I don't know if that's still the case.
Let's look at San Francisco. A city that is not as well-suited for conventions as Las Vegas. Dreamforce (Salesforce's annual conference) draws 40,000 people. DEFCON drew 30,000 this year. DEFCON could easily be held in SF. I'm not suggesting they'd want to or should move to SF, but it would be... fine.
As someone who (very) occasionally goes to conferences, Vegas is fun! I get that. I enjoy Vegas, at least for a few days before I get sick of it. There are good restaurants and shows, and virtually no puritanical laws around alcohol consumption like you find in nearly all other places in the US. It's a 24/7 city, the only one in the US. I see the appeal. (And also get why many people dislike it, largely for the same reasons many people like it.)
But c'mon, there are plenty of other US cities that have the infrastructure to support a conference like DEFCON. Conference organizers pick Vegas because they like it, not because other cities can't support them.
I would be happy if the location or date of all 3 changed. The peak temperature outside was around 110° all week this year.
Also, it’s always been in Vegas, so there’s inertia, and part of the draw is the attendance synergy with the rest of the hacker summer camp events like black hat, bsides, and others. There’s no good reason to change, and a lot of good reasons to stay.
Also understand that, the conference, no matter which conference mind, is half the draw, the other half is being in vegas itself. Move it elsewhere and it'll be much, much smaller for that reason alone.
Why can't they just move these conferences out of the US? Dmitry Sklyarov was arrested at one of these Vegas hacker conventions, in case people have forgotten after all these years. There are many other countries where these conferences could be held, and where all this security BS isn't much of a factor.
You mention Dmitry Sklyarov but more recently Marcus Hutchins (MalwareTech) has been also arrested by the FBI following its appearance at Blackhat or Defcon
If you're going to make such a wild statement where the laws are against you any any Google search of hours is against you, you've got to give a much longer and in depth explanation.
The argument for this in the comments below seems to be justifying this saying that the hotel is doing safety checks because of a prior mass shooting, which was unrelated to DEFCON, or that they’re looking for “suspicious networking equipment” which none of the staff is trained on how to go find let alone even identify.
Moral implication of do not disturb aside, this seems very poorly executed and meaningless. If the management of the hotel for some reason is paranoid and doesn’t like these guests, then don’t accept their business.
Legal obligations aside, how would a provider of public accommodation figure out who to refuse the business to? Do they size up guests at checkin to see if they look hacker-ish?
Is that more fair than a bumbling effort at deterrence by advertising your existing security policy, of casting eyes in every room every day—a policy you apply uniformly to every member of the public who wants to rent a room?
The DA should prosecute the "security staff" for their illegal acts and make an example out of them. This is not the first time a hotel has done this, and they will continue to act outside the law until those responsible face felonies and prison time.
Ha ha. In _Vegas_? Not in this timeline. The DA is _not_ on your side in this fight.
(When Spotting the Fed may actually also be useful.)
So the real goal must simply be intimidation. Of course, given the audience, that tactic is unlikely to have the desired effect.
https://www.toool.us/lockpicking-laws.php
> 1. Every person who makes or mends or causes to be made or mended, or has in his possession in the day or nighttime, any engine, machine, tool, false key, picklock, bit, nippers or implement adapted, designed or commonly used for the commission of burglary, invasion of the home, larceny or other crime, under circumstances evincing an intent to use or employ, or allow the same to be used or employed in the commission of a crime, or knowing that the same is intended to be so used, shall be guilty of a gross misdemeanor.
Having lock picks in your possession coupled with the circumstances that suggest you intend to use them would be a crime.
It wouldn't be a stretch to find someone with a flipper poking at things could run afoul of this law.
It is in the "a flipper is legal, but be very cautious having it... and if you were some place where you shouldn't be and had a flipper, it could make things worse."
Having them with the intent of drumming up sales, or teaching use, is not a crime (based on the wording of the law you supplied).
The thing that you don't want to do is go walking down a hallway in a hotel (which are of course under video surveillance) and have a utility room door pop open.
Teaching people how to pick locks in Vegas isn't a problem ( https://youtu.be/J5t9uPnXemU ).
If you have a legitimate use - go for it. If its "I brought mine because I'm going to a hacking convention in Vegas" it is now a "think about if you really want to be carrying it around" - its more likely to borrow trouble and if you "accidentally" open up some place you shouldn't have access to, it makes things worse.
The right policy would be to always respect customer privacy and if they can't be trusted to behave, refuse them.
Also why aren't they targeting laptops? That's probably the #1 "hacking tool" in anyone's arsenal.
But, hey, I bet this looks great on a Powerpoint presentation to the board of directors.
Hopefully nothing!
But there was a 2017 mass shooting so they're looking out for travellers carrying fourteen AR-15 rifles, 1600 rounds of ammunition and 50 pounds of explosives.
IDK what the mentions of "hacking tools" are. But if I was running a hotel and I was hosting defcon, I'd give all staff refresher training on "don't plug in that USB stick you found dropped in the parking lot" and suchlike.
All of which can be fit into a handful of suitcases that staff are not opening to inspect. 1600 rounds of ammunition is not very much.
I'm sure someone could perform a mass shooting without twenty suitcases.
But I can see how it would be embarrassing, from the hotel's point of view, that this guy set up the attack right under the noses of security, with bellhops taking twenty suitcases of guns and ammo up to his hotel room.
This is all just security theater. And like most security theater, it infringes on what should be legally-mandated privacy rights. But of course we don't have those here in the US.
Linux=Evil Hacker.
Windows=Harmless Muggle.
Hope nobody tells them about WSL...
What was new this year were many reports of aggressive, confrontational behavior by security at Resorts World specifically. In particular, there are quite a few stories of Resorts World security staff actively escalating confrontations and of calling over armed colleagues over resistance as minor as asking to see ID. This kind of thing is extremely worrying from a licensed security force with armed members, and suggests a serious defect in the training and security leadership at Resorts World. The problem was not room checks per se, it was the incompetence the people doing the checks repeatedly demonstrated.
I think the press may have been reticent to level accusations at specific resort operators, but I hope journalists will put some pressure on Resorts World. Do they normally mount this type of response to high-risk events? Who planned their handling of DEFCON? Are their security staff trained in deescalation? What is their policy on when and how trespass threats should be issued?
The overall feeling was that the Resorts World security department was exceptionally unprofessional and, through their confrontational behavior, made this into far more of a scandal than it should ever have been. Caesars security, by contrast, is downright militarized, but seems to have been far better trained and more graceful in their handling of similar situations.
I feel like the attendees these days are much less dangerous, but these searches seem ridiculous and over the top compared to any past year I can remember.
Vegas + hacker cons, everything one might expect.
Even this year, you will be trespassed from the con for putting up _googly eyes_ and there are 4-6 different villages dedicates to "break-times" and inclusivity.
Probably for the best, no way a truly "edgy" and zany hacker con would've been able to find venues to host at nowadays anyway.
Best for business, perhaps. I stopped going several years ago when the conference got too soft. Yes, the antics were sometimes too much and it's understandable why SOME THINGS would need to be reigned in. For example, concrete in the toilets, flares in the elevators, windows getting broken, ATMs being hacked etc. 100% understandable.
The defcon today is completely sterilized. It's an extension of corporate culture in it's truest sense. There's no interesting things going on anymore. The noted "inclusivity" breakouts and villages are growing, the goons are more serious, the "hackers" are mostly Joe's From Accounting, etc. Part of the allure of old defcon was everyone was just a hacker. It never, ever mattered who you identified as or what you were. Can you hack? Great, you're in. Everyone serious never gave names and cameras were very seriously frowned upon. Oh, how the mighty have fallen.
If I'm being honest it's gone from the high point of my year to something I'm glad is just a memory for me. I went for ~15 years. It's sad to watch it turn into this sterilized "dont offend anyone or anything" after being counter-culture for decades. But, you either die a hero or live long enough to see yourself become the villain. I'm once again glad I didn't spend the money to go.
1. https://en.wikipedia.org/wiki/Politician's_syllogism(I wonder if the NSA collected a bunch of zero days by copying every usb drive their undercover operatives found in rooms while "employed" as hotel security?)
They outright don't trust this group. Property damage?
Though I also really don't want to be the one reviewing reports from housekeeping. "Yes, that's a laptop running hacky stuff, because it's a speaker rehearsing slides. Not a visually identical laptop running visually identical tools against slightly different numbers."
I’ve had “room checks” at many hotels since then and they said it was for security purposes.
The hotel owners have presumably decided that the high-probability-minor-damage risk to their business from a few paranoid types avoiding their hotel is not as great as the very-low-probability-enormous-damage risk from a copycat mass shooting.
And so, ignoring the do-not-disturb sign and snooping on guests' rooms is the norm in Vegas these days.
And if they happen to have a large block booking of particularly privacy-conscious people and so a noticeable fraction of the rooms are declining maid service, I can understand why they'd want to be ready to carry out some supplemental checks.
In the normal operation of a hotel, such guests are uncommon - but I expect defcon attracts several orders of magnitude more such people.
Do you have evidence of that happening?
https://www.nytimes.com/2018/10/07/travel/when-guests-want-t...
https://storage.courtlistener.com/recap/gov.uscourts.dcd.187...
Update: I just found that his license to practice medicine in Pennsylvania was reinstated in 2022. Interesting. I hope he is doing better.
Caesar's Palace and the MGM got hacked.
start with learning what hacking is, and talk about "living off the land" using field expedient improvised tools and materials.
[1] https://www.firearmsnews.com/editorial/2nd-amendment-nightma...
Then again, you won't be able to gamble and get prostitutes elsewhere as easily..
Find one with a convenient label on it that says Evil Plan?
Someone in management is trying to look like they're getting shit done.
Been using a little fake phone charger that's actually a hidden camera in Hotels for years now, and didn't see anyone come in.
Sure, its possible the maids are secretly 31337 h4xx0rs and noticed the device, pulled it, plugged it into their computers, deleted the video, and replaced it, but I somehow doubt it.
He says seems as good idea as any.
Guess this too.
The excuse I got is that they are trying to prevent another Las Vegas shooter situation.
The solution, as always, is to vote with your wallet.
and that year, the goons were searching for attendees without the silver wristband more closely than even attendees without a badge, they weren't joking around.
https://www.csoonline.com/article/566069/vegas-hotel-room-ch...
Disney also started a "Room Check" after the shootings - https://touringplans.com/blog/disney-in-a-minute-what-is-a-r...
The sooner we have "The Raven Hotel" the better, but until then I'm not totally sure what you can do? Know it will happen and keep guns and laptops in locked bags when you are not there I guess?
The man-children of HN are the first to cry when big corporations don't protect them, there's some irony this site is crying about it.
2. The policy is for the cleaning staff to scrupulously applies the usual policy with more attention than usual and reports out of the ordinary things to a support group with IT and security, which seems, well, fine? They are hosting a large group of people specialising in hacking. It is indeed more likely that something fishy with their IT will happen then than at any other point in time.
The whole thing is just pretty much asking staff to be extra vigilant. There are plenty of precedents allowing me to suggest it’s a very reasonable and good idea.
The Twitter thread then quickly goes into crazy conspiratorial territory when they somehow think that the pictures shared imply search and seizure. Hotels never seize things and they don’t rummage through your stuff. The whole thing is about security getting involved proactively if they see things in the open especially if they are plugged where they shouldn’t be.
Still amusing to see people who spent their whole careers arguing about extra invasive provisions to shield against potential sometime fairly remote security risk extremely spooked by room checking - a fairly standard procedure in every hotel.
Edit: Downvoting me to death because you dislike what I say is not going to make it stop being common sense. At least, if you disagree, please have the courage to engage in honest discussion. Also please read the thread, 90% of the reply at the time of my edit are completely pointless because they didn’t bother checking what the hotel is looking for and prefer trying (and predictably failing) to look smug.
That’s not what these checks are for. These started in response to the mass shooting at Mandalay Bay, and they’re looking for an arsenal.
After the Mandalay Bay shooting MGM settlesd an $800 million case. They were sued for negligence because had any employee just gone in the guys room they would have stopped the whole thing.
After that daily checks have been the policy in a whole lot of places.
Apparently you need to be logged into X to see this. I did not see any thread under the post (a good reminder to use proper language when pointing such things out, the other person might not have seen there there is a thread).
Regardless, I am not a user of X so I won't be able to see the thread. Thanks for inlightening with some examples!
In the US? There are several countries where that would be illegal.
> Please don't comment on whether someone read an article. "Did you even read the article? It mentions that" can be shortened to "The article mentions that".
Yeah, and a daily room check will help with that how exactly? Are they going to take laptops away from guest? Flipper zeros? SDRs?
This absolutely happens today, although it is rare. Hotels have turned over a client's property from rooms or valet to police without a warrant. Some hotels will actually search your bags if you use their luggage room service. This started happening after the Vegas shooting and seems to be only a Vegas practice (or at least I haven't read articles on it happening elsewhere).
2018, so as part of the same new security since the mass shooting.
> Hotel security are also confiscating attendees lock picks, although we can kind of see why they would do that. The sight of a hacker with lock picks in your five star hotel must scare the bejeesus out of any security guard. But still, lockpicks are part of hacker culture and organizers are trying to get them back for you.
> Its not just confiscating items that they can see in rooms, there are reports of hotel security going through attendees personal belongings too, they have very clearly been searching through suitcases, an unnaceptable violation of their guests privacy.