6 ms·
After the impact of the MGM hack this year Cesars probably revisited their insurance on getting compromised. After the auditors and lawyers looked at all the ri
by dash488 3y ago
After the impact of the MGM hack this year Cesars probably revisited their insurance on getting compromised. After the auditors and lawyers looked at all the risks they came across DEF CON and said no because of the wording of how DEF CON is marketed. Their choice was probably to drop them or loose coverage.
DEF CON is listed as a "hacker convention held annually in Las Vegas, Nevada." where Blackhat is "Black Hat is an internationally recognized cybersecurity event series providing the most technical and relevant information security..."
I imagine places like the convention center cant afford or care about insurance at this level.
- wkat4242 3y agoBlack hat is just one giant bunch of sales pitches. No I haven't been there but I've had to sift through recordings that my boss (who did attend) wanted me to look at because he was too drunk himself to do a proper evaluation. It doesn't provide information, it just provides sales suits a chance to blow their hot air :P If I'd ever go there it would just be an excuse to go to vegas to see DEF CON as well :P I work in security but I have no time for corporatism and sales bullshit. Edit: I know it's a bit of a hot take but I've been to so many conferences where sales goons spew all the pretty pictures and then later when we actually got our hands on the product it turned out that it couldn't do half the stuff that was promised. Or there were other weaknesses like excruciatingly bad support. I've become very cynical due to this.
- nopeYouAreWrong 3y agoif we're going with hot takes, I've watched a lot of DefCon vids and many presenters come off as outlandish arrogant. not simply smug, more "I am levitating above the normies."
- jstarfish 3y agoThat's not specific to presenters; there's a lot of insecurity (no pun intended) on parade in this industry. The sort of people who can bridge air-gapped networks using bubblegum and popsicle sticks tend not to minor in human relations. Just read it as showmanship. They're trying to be over the top for the sake of performance.
- tptacek 3y agoThis isn't a hot take. It's just wrong. Black Hat is peer reviewed and accepts a tiny fraction of submissions (tracks will accept 3-5 talks out of a typical pool of 20-50). Reviewers --- all of them vulnerability researchers --- barely have time to read outlines and look for any possible excuse to DQ a submission and move on to the next one, and the single most common DQ is "the presenter has a commercial interest in this topic, vendor talk, 1.0 rating". There is also a giant vendor expo that runs alongside Black Hat, and vendors do whatever they can to stage events that look like Black Hat talks but are not. I submit that you have probably confused those for actual talks. Or: you watched the keynote? I don't understand what the keynote is for. Here are the actual 2023 talks: https://www.blackhat.com/us-23/briefings/schedule/index.html https://www.blackhat.com/us-23/briefings/schedule/index.html
- jeltz 3y agoKeynotes are terrible at almost all conferences I have been to. They mostly seem to be there to stroke the egos of management of major sponsors.
- wglb 3y ago>Black hat is just one giant bunch of sales pitches. > No I haven't been there The first sentence is not true. Many good talks are give, often breaking ground. Yes, you can find sales pitches, but there are good fundamentally technology talks.
- technick 3y agoCaesars was hacked by the same attackers that pwned Okta, and used the stolen keys and tokens to get into Caesars. It was nothing carried out by Defcon in any way. Anyone that takes this scene seriously knows Defcon is the place to be. Blackhat is a overpriced vendor circle jerk. The only way to make Blackhat relevant again is to kick out all of the vendors and if you can't do that, forbid them from collecting peoples information. This is going to be my 11th year at Defcon this year. I snuck into a couple of blackhats and didn't get any value from them. I've been around the block a few times.
- waihtis 3y ago> It was nothing carried out by Defcon in any way. You think insurance providers are capable of doing this level of analysis? They see "hacker conference" in which Defcon may still hold some notoriety in and decide it's a risk.
- alephnerd 3y agoThey are able to. I've worked with AXA and Chubbs before in this space. I don't think this was done because of cyber insurance They most likely got bumped to make space for a better paying corporate conference. Most vendors are now running a Cisco Live/AWS Re:invent type conference, and they've increasingly consolidated on Las Vegas because venue booking and block room booking is much easier there than in any other city in North America. Also, DefCon has become massive, so the RoI has most likely shrunk due to staffing overhead.
- waihtis 3y ago> They most likely got bumped to make space for a better paying corporate conference This is the occams razor explanation
- busterarm 3y agoBlackHat isn't a con you attend. You go there for the training sessions that are required to obtain/upkeep your certifications. The infosec industry sorta runs separately from the rest of tech in that it's entirely a status economy. Name recognition, certification and publication are the most important things to maintain stable employment. On the other hand none of the planned programming at DEFCON has any professional value whatsoever and it's merely a metacon for connecting with people in varying niches in the space.
- passwordoops 3y agoThis explanation makes the most sense. A team of lawyers/risk analysts saw "hacker conference", superficially dug in and noted previous incidents that coincided with the "hacker conference" in previous years (bomb threat, the shooter) and decided it wasn't worth it
- dash488 3y agoThe bomb threat last year is a funny story that I cant share here. It was very much a nothing burger but their security doing what they are paid to do.
- exadeci 3y agoCancelling it sounds like best way to get DEF CON attendees to try and hack your hotels