Defcon stiffs badge HW vendor, drags FW author offstage during talk
twitter.com
twitter.com
But even so, dragging a presenter off stage is sus. And doesn't seem smart because even if the other claims are not true, I'm tempted to never attend Defcon if that's what they do.
Approx:
Entropic is engaged to make hw. I am asked (unofficially) to do sw.
Entropic works for free but does charge for parts and subcontracted stuff . Eventually defcon stops paying. Entropic is uninvited from badge talk. Their logo is ground out of plastic case. Their logo hidden in publicity photos of pcb.
Tempers are high. I implement the Easter egg. This is months ago cause thats how long one needs to pre-flash chips.
Time passed. Defcon still working on their game last moment. They had volunteers reflash badges cause they didn’t make the real pre flashing deadline. I forgot about the screen entirely more or less.
Day of con. I spend all day helping debug badge issues. Push updates. Help people. Even pushed an update from plane on way to con to fix some things.
Badge talk time. Half an hour before defcon tells me no talk for me cause someone found the Easter egg screen and they are pissed. I show up anyways since it was promised.
I get dragged off stage.
I hold talk outside answering questions.
Next steps: I have no contact with defcon. They never bothered to. Normally: who cares? I get to talk, people get to play with badges. Nobody cares.
But… I got kicked out, and… they have no license to my firmware they are distributing. Likely DMCA notice.
(“Had to” means a friend offered me one, laughed, and said “aw, c’mon”. I could’ve easily said no.)
First, I literally saw them do shots during a talk yesterday for some first-time presenters. Secondly that WASN'T the "old defcon" either! Drinking is a relatively new tradition in the history of the con. I've spoken twice. Once at DC 17 (no shot offered) and once at DC 23 (shots were offered). There's video proof:
No drinking, DC 17: https://www.youtube.com/watch?v=okPWY0FeUoU Asked to drink, opted for a coin instead (we were asked beforehand): https://youtu.be/6dmvtbrM6hs?feature=shared&t=1153
And recently I've had a string of bad, unalterable, and irrevocably-permanent events occur in my life. And yet, I'm very pleased to say that your write-up on your experiences with the RP2350[1] presented a small but meaningfully-positive thing for me to look forward to.
Please be well -- and don't take any guff from these swine[2].
[0] https://media.defcon.org/DEF%20CON%201/DEF%20CON%201%20annou...
[1] https://dmitry.gr/?r=06.%20Thoughts&proj=11.%20RP2350
[2] https://www.barnesandnoble.com/w/fear-and-loathing-in-las-ve...
Defcon has a lot more grassroots stuff, but it's grown to a size that it cannot avoid the corporate BS anymore. It's probably one of the biggest and most disruptive conferences in Vegas, venues don't like having 1000s of hackers hanging around slot machines.
Any one of those things sounds unpleasant to me, let alone all 3 at once.
And most corp trips are to black hat, not def con.
I've been offered a trip to black hat before and asked if I could go to def con as well but no. I was thinking of just staying longer on my own dime but we got a travel ban for cost cutting reasons so the whole thing never happened. I wasn't really interested in black hat anyway so I didn't care, I hate corporate PR.
But Vegas to me is a detractor. I hate gambling. I'd love it if it were in NYC or something. Much easier from Europe too.
not true in the vulnerability research space.
Actual engineers are sent to defcon because blackhat talks are advertisements, not educational presentations.
I worked in a "blue team" and we would only get travel approvals for black hat. Even though I've never been as I didn't want to and I was hesitant to visit the US. Black Hat doesn't interest me precisely for the reason you mentioned. I don't want sales pitches, I want unrestricted flow of technical information without marketing motives.
The only problem is it's in an extremely expensive period of the year for hotel stays. For that reason I've never actually been.
In 2024 not sure I’d really see the point, there are other conferences I’d likely enjoy more and mostly that itch is scratched by YT.
The on I’d still like to visit in person is fosdem and given I’m in the UK that one would be much easier.
With blackjack. And...
If you are in contact with any of the Entropic folks, maybe point them to this or the r/ thread so that they can provide more context.
I'd love to hear their sides of that story. (Both Def Con and Entropic). I'm curious now.
I'm sorry you got roped into this conflict too though. I have great respect for your work.
I just don’t see how they lose anything there (or rather, don’t see how they lose anything there that they lose a hundred times more of by their actual actions, namely reputation).
They've not really shrunk or significantly grown and are really opposed to corporate and government interests (as Fox-IT found out in 2013)
I just don't really like going to the UK anymore since Brexit. It just puts me off because the main driver of it was xenophobia. I've avoided it, I have not been there at all since Brexit. I probably won't ever go there again unless there's a serious change. Of course none of this is on the EMF community which is great, I've met many of them at other things.
As for the hacker camps I only really go to the Netherlands ones. The Congress is too expensive for me with the hotels around Christmas and with my lack of car it's hard to go camping in Germany so I've never been to the chaos camp either. Within Holland it's been easier because they've recently been at locations near me.
It parallels what Ivan Illich said about revolutions, namely that if a revolution survives it will turn into a system that stifles the same freedoms it supported.
Aka, either you die the hero, or see yourself become the corporate stooge/villain.
The DMCA criminalises breaking DRM, or providing tools to do so, such as distributing a tool to remove the DRM from an e-book.
This is textbook copyright infringement. $150k statutory damages plus, at the court's discretion, legal costs and fees. And that is just the result of civil action. You could probably find a prosecutor who would love pursue criminal action against the conference to appear strong on cybersecurity.
There is a reason why even large corporations, which often play chicken with lesser laws, are extremely careful about copyright infringement. The law has real teeth if the infringer has significant wealth.
Reading about rePalm has changed my definition of what monumental effort looks like.
(You should absolutely add that you managed to get PalmOS running on the badges in question!)
Demand the minimum for every badge distributed — as even if you later provided licenses to holders, DC had no license when distributing the copies as merchandise at their for-pay event.
Not saying they were morally or ethically right, or smart to do this at all - but legally there usually is a right to remove a unwanted person from your stage with the help of your own security.
The police does not want to be called, for every bouncer action.
It can get into a grey area, if violence will happen, the security may not simply beat someone out - but grabbing and forcefully moving or carrying out is legal. But if there is serious resistance and the security unable to handle it in a nonescalating way, then they would need to call the police. But usually, the bouncers would just get brutal, then. Attacking security gives them some freedom to act.
If other people are endangered by someone, very different scenario, anyone can (and must if possible) stop violence.
Source: short stunt as a professional security
They have committed assault against you.
This serves two purposes. The first is, a crime has been committed. The second is, you may now defend yourself.
I'm sure there is something similar in common law for other buildings. EG control of a space.
(I know nothing of this incident, just speaking generically.)
How do you think bouncers work?
Though I'm sure you can find them on eBay.
https://www.reddit.com/r/Defcon/comments/1eoe4u7/comment/lhe...
>I show up anyways since it was promised.
-you get asked to leave the stage
-you refused to leave the stage
-you told them they'd have to drag you off stage to get you to leave
>I get dragged off stage.
When people get SWATed, usually a fake call is made, were the police are told that a murder was already committed by the caller and that we will kill everyone on sight. Thus the police expect real danger, brings the big guns and their trigger happy attitude, kick the door in and are more likely to kill the victim.
It's not SWATing if the police come to handle a disturbance. The SWAT team need to be deployed for a SWATing.
Anyone could have called the cops too. A gathering of 100 people can make people nervous. But I wouldn't be surprised if Defcon called them too.
Calling the police is not SWATing someone.
Bullshit.
Swatting is:
> the action or practice of making a prank call to emergency services in an attempt to bring about the dispatch of a large number of armed police officers to a particular address.
The cops response for like, someone disturbing the peace or someone playing loud music in the middle of the night, is nothing like when the SWAT team comes with automatic weapon, full body armor and flash bangs, expecting to be shot at, as promised by the phrank call.
Claiming the calling the police on someone is swatting, even though US police routinely execute people unprovoked attacks, is not swatting. The difference is the intent - the intent of swatting is terrorism and murder.
I do wish I had more context from the video, but at this point, it's getting hard to imagine any good reason for Defcon to do what they did. Assuming that you weren't threatening someone in the audience or something like that. Doubtful, from the way you've been talking.
Anyway, it looks like good stuff. Wish I had some Game Boy games to try it.
Anyways, just seemed odd.
One cannot lay even a finger on another person, ever, let alone jostle someone just because they don’t like what they are saying.
It doesn’t matter if they are “security”. It’s assault and battery just the same as if I shove grandma out the way to get to the bus!
Read your blog/article about the badge project yesterday and it was such a good read, even for a not-much-of-a-hardware-guy like me.
select "ABOUT" and press "A" to enter about screen
Press "SELECT" button there despite that not being listed as a valid input.
(In particular, he managed to get Palm OS running on the badges in question).
If there's one person whose credibility I wouldn't doubt on those matters, it's him.
DEF CON's response to the badge controversy - https://news.ycombinator.com/item?id=41211519 - Aug 2024 (41 comments)
Option A: let the dude have his talk. Nobody hears about it beyond the walls of defcon. Move along.
Option B: uninvite and call security. Guy becomes instant personality on reddit and hn. I didn't know that defcon had become a shitty, small minded operation that abuses volunteer time and can't take an Easter egg, well now I do!
Well played...
It's always kind of frustrating to see programmers and other software people participating/defending that kind of thing considering logic is our whole game to begin with.
Defcon will probably argue that including the easter egg was some kind breach of duty of Dmitry's part, and gave them the right to remove him from the talk, and modify the firmware to remove the easter egg. My expectation is that courts would decide that Defcon has the right to use the firmware, but will require them to pay some kind of compensation for not living up to their side of the bargain.
The incentive to not do it is because it makes them look like power-tripping maniacs, which is what happened.
I've never been to the conference but now I think I'll never want to go.
DEFCON may well have many reasons and legal recourses to stop a talk from occurring. But if they do not meet the terms of the contract for the IP, then the author/developer/manufacturer is entirely free to pursue action against them.
Now it’s possible the developers had not watched Mike Monteiro’s “fuck you pay me” talk (https://creativemornings.com/talks/mike-monteiro--2/1), but assuming that the claims in this tweet are remotely accurate you can bet that - assuming they can get someone to do it at all - next years defcon badge will be produce by someone with a contract that has the only sane language: “no transfer of any IP or right to distribute occurs until receipt of full payment”
The “um,” start to this was unnecessarily shitty/passive aggressive and I just noticed it when I was checking for replies, so apologies for that attitude.
The issue I was wanting to address is that the reply was talking about removing the speaker as if that is relevant to the OP’s comment about IP, etc and in hindsight I guess I assumed a bad faith argument and responded to that assumed intent rather than the actual comment.
The creator didn't revoke the license until after the badges were distributed.
Did Defcon contract with Entropic Engineering for hardware and software? Or did Defcon contract with EE for Hardware and non-contract it from Dmitry?
If it is the former, Defcon could say "you need to work that out with EE and if it turns out that EE wants to revoke the license for the software, we'll have our lawyers talk with your lawyers about what is in the contract."
If its the later, then things get trickier and more difficult in many different directions.
Based on https://old.reddit.com/r/Defcon/comments/1eoe4u7/so_the_guy_... "/u/dmitrygr wrote the firmware for the badges as well at the behest of Entropic" - its the former. And so if anyone is in trouble with the licensing, it's Entropic for not having a contract with Dmitry and providing the software to Defcon." Defcon used it, with the understanding that they had a license to the firmware.
Until constructive notice as to otherwise.
It may turn out that Entropic would be the one paying the penalty and footing the bill if one of the people they worked with decided to change the license.
Revoking or changing that license afterwards may fall on the vendor rather than the distributor to make things right.
While this isn't likely to be something anyone is going to come out smelling like roses out of... my crystal ball says that Entropic is going to come out the worse for it.
Having a "volunteer" working for a for profit company has hints of FLSA violations ( https://www.reddit.com/r/Defcon/comments/1ep00ln/comment/lhj... ). Having a person that Entropic is working with for embedded software put in easter eggs that went counter to the SOW becomes difficult. Entropic relying on software that has a license of "as long as the software author is ok with it" may complicate future business relationships with other clients.
That's an unmitigated PR disaster for Defcon. It doesn't matter to this who was right or wrong or what laws were broken, even if somehow all legally ended up in Defcon's favour, the damage to the brand is huge, enduring and set aside from those issues.
To address this, whoever at Defcon ultimately actioned this series of events should be held to account, for this PR aspect, and the matter immediately and publicly handed to someone with an appropriate understanding of Defcon's culture & reputation.
https://x.com/dmitrygr/status/1822124650547257637
It's definitely somewhat aggressive. Way to burn bridges.
[1] https://www.dexerto.com/tech/hacking-convention-uses-fully-w...
I'm confused by the rationale of questioning the OP about someone else's motivations.
DEFCON themselves is likely to not state a reason publicly, so getting a "here's what I was told by DEFCON" is likely the closest thing that we're going to get for an answer.
Not sure why the dragging off the stage happened.
I even live in Vegas now and I don’t go anymore.
There are some good people there but also a lot of people who do not care what happens with what they build and look away when it would be time to speak up.
It's a clear reference to the movie WARGAMES more than a direct reference to the real world US military itself.
Some of them are people who have also clearly been hackers before and after their work there.
Was it weird? Absolutely. But let’s not pretend the government doesn’t hire hackers. It’s our biggest employer.
Summary of the events unfolding by Sargonas on Reddit:
Maybe this will help with a listed summary of the known facts from first hands accounts. I am leaving gaps where there has just been speculation or second hand unverifiable information, and welcome anyone with first-hand knowledge of those aspects to comment below me to fill in the gaps. I'm merely presenting the facts as we have them from first-hand accounts (mostly from reddit and discord), without personal opinion or bias (hopefully, human nature is a tricky thing.)
Entropic Engineering designed and built the circuitry of the badges, physically. They were either only partially, or not at all, paid by DEFCON for this work, contrary to whatever formal agreement they had in place. (Other amazingly talented individuals create the silk screen design, the shells, and the game, but are totally removed from this drama so I'm leaving them out of it.) Subsequently, all references to them have been removed in various materials, and even one of their logos was removed from the silk screen. (apparently small one may be left under the battery? but I can't check because I affixed mine to the board to stop it's shifting.)
dmitrygr wrote the firmware for the badges as well
Somewhere along the way, Entropic was cut out of the process and left to the side by DEFCON in a way that left Entropic feeling burned and under/un paid for their non-trivial work (according to some comments below it is 6 figure sum, but this is second hand info).
Dmitry felt this was unfair, and put an easter egg into the badge code. This easter egg simply comments that Entropic engineered the badges, and had their credits removed everywhere, with an address for donations if you wish to support them. This was entirely Dmitrys doing as a gesture of thanks to the Entropic team.
This easter egg more or less flew under the radar until EoD friday.
Friday evening, after spending most of his day traveling to DEFCON and writing a 1.5 update in his spare time on his flight to fix some issues, Dmitry was up on stage with the other badge creators about to present the usual badge talk, when word of the Easter egg went around (likely due to him including some slides on his portion of the presentation about it.)
DEFCON staff had Goons escort Dmitry off stage shortly before the talk started, delaying the talk some.
during the talk, a comment was made about “unauthorized code“ being on the badges.
Dmitry setup himself on the sidewalk outside the hall, and basically held his own mini talk about the work he did and Entropics contributions.
At some point, LVMPD showed up. It is unclear to me personally who issued the call but second hand info says it was DEFCON staff. They noted Dmitry was simply talking to people (albiet nearly 100 of them) on a public sidewalk, outside a building owned by the county, and nothing was really amiss, and left shortly after.
Dmitry, in his (likely valid) opinion feels this whole situation has not been handled well, and since his code was written free of charge, without any signed agreements with DEFCON or consequently any rights assignments, has announced that he intends to assert his legal ownership of the code (which is his right under us copyright law). As a result, he will gladly issue a non-transferable right to the code to any attendee who asks him for one, but is no longer going to "turn a blind eye" to the fact DEFCON does not have a legal license to his code, and instead look into taking actions that are within his power to take to clarify their lack of ownership of the code on the badges. (I believe in discord he may have gone so far as to say DMCA, but I need to double-check.)
bearing this in mind this does add a curious wrinkle to the statement about “unauthorized code” from DEFCON given… The obvious.
He also rescued the Bowser pinmux that I had screwed up. And stepped in when the display IP didn’t work. And a ton of other heroic engineering.
The early Fire Phone engineering team was really talented and Dmitry was the best.
https://archive.is/dtRg2 https://archive.is/8HK5y https://archive.is/yk5uU
Is there any transparency that could tell us why this change was made?
Frankly… i’m not surprised. The whole industry is filled with this kind of fascistoid attitude now. Every organization takes any chance they can to silence opinions they don’t like (and this happens both left and right).
I see from the link above that the POLICE was called on dmitrygr for… speaking to people in a public space?
Really?
Defcon has gone from outcast meeting to full mainstream and interest-preserving. Kinda lost all of its hacker attitude, and this is proof.