avatar
Barry Dorrans @blowdart.me

A big round of applause to Ars. I really want to see what the submission was to Defcon that got accepted, because this was bad.

sep 1, 2025, 1:38 am • 85 20

Replies

avatar
Ian Coldwater 📦💥 @lookitup.baby

“This research was presented on the DEFCON Main Stage, which means it went through peer review by technical experts before selection.” Oh. Well then!

sep 1, 2025, 3:21 am • 15 1 • view
avatar
Barry Dorrans @blowdart.me

That statement just makes me wonder about their submission truthfulness even more.

sep 1, 2025, 3:28 am • 5 0 • view
avatar
Ian Coldwater 📦💥 @lookitup.baby

Also like… program committees are made up of humans and sometimes humans fuck up

sep 1, 2025, 3:32 am • 7 0 • view
avatar
Barry Dorrans @blowdart.me

My second defcon I was sitting in a .net session getting more and more annoyed but someone else stood up and pointed out all the flaws and it amused me so much.

sep 1, 2025, 3:34 am • 10 1 • view
avatar
amye @amye.org

My advice for people who are applying to big conference for abstracts are: imagine that your reviewer is under a deadline of less than twelve hours and they are deeply deeply angry. Write to impress that person, but write the talk you'd be proud to give.

sep 1, 2025, 3:41 am • 39 7 • view
avatar
Natanael, Tech janitor @natanael.bsky.social

Clown Sterling www.schneier.com/blog/archive...

sep 1, 2025, 7:06 pm • 0 0 • view
avatar
Nicolás Alvarez @nicolas17.xyz

Oh is this separate from the two AI-slop talks that made it to the DEFCON main stage?

sep 1, 2025, 5:11 pm • 5 0 • view
avatar
Ian Coldwater 📦💥 @lookitup.baby

oh no

sep 1, 2025, 6:10 pm • 3 0 • view
avatar
Nicolás Alvarez @nicolas17.xyz

bsky.app/profile/redt...

sep 1, 2025, 8:50 pm • 1 0 • view
avatar
Joe Uchill @joeuchill.bsky.social

Crown Sterling will have its revenge on Las Vegas.

sep 1, 2025, 7:01 pm • 1 0 • view
avatar
ryokimball @ryokimball.memsec.info

"we didn't have tomatoes thrown at us, I'll call that a win!"

sep 1, 2025, 3:48 am • 0 0 • view
avatar
Brownieboy @mdlfcrss.bsky.social

I'm sorry I'm new to this stuff. Didn't we used to call this theft or fraud? Sure reads like it. Everything is just a game?

sep 1, 2025, 3:23 am • 1 0 • view
avatar
DJ Ir0ngruve @dj-ir0ngruve.bsky.social

The game is don’t get caught until after major funding preferably after going public. A common startup theme basically involves fraud on at least one level. And quite a few people believe more in the faking it and less in the making it.

sep 1, 2025, 3:44 am • 0 0 • view
avatar
thebigbadme @thebigbadme.bsky.social

at least for transactionalists

sep 1, 2025, 3:47 am • 0 0 • view
avatar
Larry Osterman @larryosterman.github.io

I mean, when I spotted the flaw in the first two or three sentences describing the attack, it says something. I'm not really a security expert (I just play one on TV), but I can't understand how this was accepted as a mainstage presentation at blackhat

sep 1, 2025, 1:59 am • 6 0 • view
avatar
Heath Stewart @heaths.dev

"It rather involved being on the other side of the airtight hatchway"

sep 1, 2025, 7:43 am • 8 0 • view
avatar
Mary Branscombe @marypcbuk.bsky.social

'if I have physical access to your machine and it's logged in'...

sep 1, 2025, 6:49 pm • 5 0 • view
avatar
Joe Uchill @joeuchill.bsky.social

If I am you I have access to all of your stufff

sep 1, 2025, 6:57 pm • 5 0 • view
avatar
Mary Branscombe @marypcbuk.bsky.social

reaches into pocket: I can take out my OWN WALLET!

sep 1, 2025, 7:06 pm • 5 0 • view
avatar
Joe Uchill @joeuchill.bsky.social

Somehow DEFCON rejected my talk on the illusion of free will.

sep 1, 2025, 7:10 pm • 3 1 • view
avatar
Lou @loustella.com

Black Hat could have scheduled right after the update on Time Crystals

sep 1, 2025, 7:20 pm • 2 0 • view
avatar
Ren @r3nt.bsky.social

If anything, they proved the effectiveness of passkeys because it is a SUPER red flag to have your passkey suddenly stop working and the best they can do is stop it from working.

sep 1, 2025, 1:48 am • 1 0 • view
avatar
Barry Dorrans @blowdart.me

To be fair most users won’t notice

sep 1, 2025, 1:49 am • 2 0 • view
avatar
Ren @r3nt.bsky.social

True. They did just get social engineered into installing malware.

sep 1, 2025, 1:52 am • 2 0 • view
avatar
ÜberBrãdy @uberbrady.com

I saw *three* talks that were all the same type of thing - "but if I totally compromise your machine and have your root password - LOOK WHAT HORRIBLE THINGS I CAN DO!" I skipped this one, but if I had seen it that would've been four.

sep 1, 2025, 11:13 am • 4 0 • view