Opening Remarks
Reed Loden (President and Lead organizer)
BSidesSF 2024 · Day 1
Overview
This session, delivered by Reed Loden, President and Lead Organizer for BSides San Francisco, served as the opening remarks for the 2024 conference. The address welcomed attendees, outlined the event's core philosophy, and highlighted key activities and themes. A central focus for BSidesSF 2024 is the pervasive influence of Artificial Intelligence (AI), encapsulated in the theme: "You can't spell dystopia without AI." Loden emphasized the dual nature of AI's popularity and the critical need to address concerns and hesitations surrounding its future implications for security. Notably, over 50% of the talks scheduled for the conference were stated to have an AI component, underscoring the event's commitment to exploring this rapidly evolving technological landscape.

Key moments
- 0:00 Welcome and AI Theme Introduction
- 0:40 Over 50% of Talks Feature AI
- 4:00 Capture the Flag (CTF) and AI Village
- 4:30 Introduction of Numerous Technical Villages
- 10:00 Hackable Electronic Badges Introduced
- 10:30 Badge Challenge and GitHub Documentation
- 11:00 Assistance for Bricked Badges
Opening Remarks
Speakers: Reed Loden
Conference: BSidesSF 2024
YouTube: https://www.youtube.com/watch?v=ELC31N7ViOg
Overview
This session, delivered by Reed Loden, President and Lead Organizer for BSides San Francisco, served as the opening remarks for the 2024 conference. The address welcomed attendees, outlined the event's core philosophy, and highlighted key activities and themes. A central focus for BSidesSF 2024 is the pervasive influence of Artificial Intelligence (AI), encapsulated in the theme: "You can't spell dystopia without AI." Loden emphasized the dual nature of AI's popularity and the critical need to address concerns and hesitations surrounding its future implications for security. Notably, over 50% of the talks scheduled for the conference were stated to have an AI component, underscoring the event's commitment to exploring this rapidly evolving technological landscape.
The remarks also underscored the community-driven nature of BSides events, stressing that it is organized "for and by the community" by a 100% volunteer team. This ethos translates into a unique participant model where "no attendees, everybody is a participant" is the guiding principle, encouraging active engagement in conversations and activities. Beyond the talks, the conference offers a rich array of interactive experiences, including a Capture the Flag (CTF) competition, numerous specialized Villages, workshops, and a new initiative involving hackable electronic badges designed to foster hands-on learning and engagement.
Loden also covered essential logistical and community-focused aspects, such as the Code of Conduct, photo policy, venue layout, career development opportunities, and even onsite emotional support. The overall message was one of welcoming, active participation, and a forward-looking perspective on the most pressing security challenges, particularly those introduced by AI, all within a supportive and inclusive community environment.
Background
▶ Watch: Welcome and AI Theme Introduction (0:00)
BSides conferences originated from the desire to create a more intimate, community-driven alternative to larger, more commercial security events. The "unconference" model emphasizes open discussions, hands-on learning, and direct engagement among participants. BSides San Francisco, as highlighted by Reed Loden, embodies this philosophy, being entirely volunteer-run and taking a full year of dedicated effort from a core team of 20, supported by an additional 15+ staffers and over 200 weekend volunteers. This structure ensures that the content and activities are curated by and for the cybersecurity community itself, fostering an environment where the "next big thing" in security can be openly discussed and explored.
The choice of AI as the overarching theme for BSidesSF 2024 reflects the current industry zeitgeist. The rapid advancements and widespread adoption of AI technologies across various sectors have introduced novel security challenges and opportunities. From potential misuse in offensive operations to the need for securing AI systems themselves, the intersection of AI and cybersecurity is a critical area of research and discussion. The conference aims to address these concerns head-on, providing a platform for researchers and practitioners to share insights into how AI is actively being used and what it means for the future of security. This proactive approach is consistent with BSides' mission to stay at the forefront of emerging threats and technologies.
Furthermore, the introduction of hackable electronic badges represents an evolution in conference engagement. While Loden humorously acknowledged a previous "failed miserably" attempt several years prior, the reintroduction of these badges signifies a commitment to providing tangible, interactive experiences. This initiative aligns with the hands-on learning philosophy prevalent in the security community, offering a practical way for participants to engage with hardware and software in a controlled, educational environment. Such elements are crucial for a conference that positions every attendee as a participant, encouraging active exploration and skill development rather than passive consumption of information.
Key Findings
▶ Watch: Capture the Flag (CTF) and AI Village (4:00)
The opening remarks for BSidesSF 2024, while not presenting traditional research findings, laid out several key programmatic and thematic elements that define the conference's contributions to the cybersecurity community:
- AI as the Dominant Theme: The most significant finding is the conference's explicit and extensive focus on Artificial Intelligence. With over 50% of the talks incorporating an AI component, BSidesSF 2024 positions itself as a critical forum for understanding the security implications, challenges, and opportunities presented by AI. This reflects a community-wide recognition of AI's transformative, and potentially disruptive, impact on the cybersecurity landscape.
- Emphasis on Active Participation: The core philosophy of "no attendees, everybody is a participant" is a foundational element. This encourages a highly interactive environment where networking, discussion, and hands-on engagement are prioritized. This model fosters a stronger sense of community and collective learning, moving beyond traditional lecture-style conferences.
- Diverse Hands-on Learning Opportunities: The conference offers a wide array of practical learning experiences beyond formal talks. This includes a robust Capture the Flag (CTF) competition, numerous specialized Villages (e.g., AI, Adversarial, APS Security, Bug Bounty, Cloud, Crypto & Privacy, Embedded Systems, Hardware Challenge, Lockpick, Personal Security), and dedicated workshops. These elements provide invaluable opportunities for skill development and exploration of niche technical areas.
- Introduction of Hackable Electronic Badges: A notable innovation for this year is the re-introduction of hackable electronic badges. These badges, which function as USB-C flash drives running Python, are designed to be modified and experimented with by participants. A dedicated challenge associated with the badges, with a prize of a free badge for next year, further incentivizes technical engagement and problem-solving.
- Commitment to Inclusivity and Support: The conference demonstrates a strong commitment to fostering a safe and supportive environment. This is evidenced by a clear Code of Conduct, a unique photo/video policy requiring consent, the provision of onsite emotional support services (via Dr. Sarah), and a career village to assist those impacted by recent industry layoffs. These initiatives underscore the importance of human well-being and professional development within the technical community.
Technical Deep Dive
▶ Watch: Introduction of Numerous Technical Villages (4:30)
While the opening remarks themselves did not delve into specific technical exploits or research, they served as a gateway to the extensive technical content and interactive opportunities available throughout BSidesSF 2024. The underlying technical currents of the conference are primarily driven by its overarching theme and the hands-on activities it provides.
Artificial Intelligence (AI) as a Security Vector: The declaration that over 50% of talks feature an AI component signals a deep exploration of AI's technical facets in security. This implies discussions ranging from AI/ML model security (e.g., adversarial attacks on models, data poisoning, model inversion attacks) to the use of AI in threat intelligence and automated defense systems. The presence of a dedicated Def Con AI Village at BSidesSF further suggests hands-on technical engagement with AI, potentially involving challenges related to prompt injection, AI red teaming, or securing AI-powered applications. The technical deep dive within the conference would likely cover topics such as large language model (LLM) security, machine learning pipeline vulnerabilities, and the ethical implications of AI in offensive and defensive operations.
Capture the Flag (CTF) Competition: The annual CTF, sponsored by Google, is a cornerstone of technical skill development. CTFs typically involve a series of challenges across various cybersecurity domains, including reverse engineering, cryptography, web exploitation, binary exploitation, forensics, and network security. Participants engage with real-world or simulated technical problems, requiring them to apply advanced analytical and problem-solving skills. The technical depth of a CTF lies in its ability to test participants' understanding of low-level system internals, protocol vulnerabilities, and sophisticated attack techniques, often involving custom tools and scripting.
Specialized Technical Villages: The wide array of Villages offers focused technical deep dives into specific domains:
- Adversarial Village: Likely focuses on advanced offensive techniques, red teaming, and simulating real-world adversary tactics.
- APS Security Village: Implies technical exploration of Application Programming Interface (API) security, including authentication bypasses, data exfiltration through APIs, and API gateway vulnerabilities.
- Bug Bounty Village: Provides insights into methodologies for discovering and reporting software vulnerabilities, often involving web application penetration testing techniques and understanding common vulnerability classes (e.g., XSS, SQLi, RCE).
- Cloud Village: Concentrates on the unique security challenges of cloud environments, covering topics like misconfigurations in IaaS/PaaS/SaaS, container security, serverless function vulnerabilities, and cloud identity and access management (IAM) issues.
- Crypto and Privacy Village: Explores the technical underpinnings of cryptographic systems, privacy-enhancing technologies, and potential weaknesses in their implementation. This could include discussions on post-quantum cryptography, zero-knowledge proofs, or privacy-preserving machine learning.
- Embedded Systems and Hardware Challenge Villages: These are inherently hands-on, focusing on the security of physical devices. Technical activities might involve firmware analysis, side-channel attacks, JTAG/SWD debugging, reverse engineering hardware components, and exploiting vulnerabilities in IoT devices or industrial control systems.
- Lockpick Village: While seemingly non-digital, lockpicking involves a deep understanding of mechanical systems, tolerances, and manipulation, which parallels the analytical mindset required for digital exploitation.
Hackable Electronic Badges: The most direct technical offering mentioned in the opening remarks is the hackable electronic badges. These badges are described as functioning like a USB-C flash drive and running Python code. This design immediately suggests several technical avenues for participants:
- Firmware Modification: The ability to plug the badge into a laptop and have it appear as a flash drive implies direct access to the badge's filesystem and potentially its firmware. Participants can modify the Python code, experiment with custom functionalities, or even attempt to flash alternative firmware.
- Embedded Python Development: The use of Python makes the badges accessible for a wide range of developers, allowing for rapid prototyping of small applications, custom displays, or interactions with other badge features (if any, like LEDs, buttons, or sensors).
- Hardware Exploration: While the extent of exposed hardware was not detailed, the "hackable" nature suggests potential for interacting with GPIO pins, I2C/SPI buses, or other on-board components, offering a basic platform for embedded systems development and hardware hacking.
- Security Challenges: The associated badge challenge, where participants solve puzzles, likely involves exploiting aspects of the badge's software or hardware, requiring technical skills in reverse engineering, code analysis, or creative problem-solving. The provision of full documentation on a GitHub repository (
github.com/bssf/badge2024) further supports a deep technical engagement, allowing participants to review schematics, source code, and development guides.
In summary, while the opening remarks were high-level, they effectively signposted a conference rich in diverse and deep technical content, catering to a wide spectrum of cybersecurity interests from cutting-edge AI research to hands-on hardware and software exploitation.
Demo / Proof of Concept
▶ Watch: Badge Challenge and GitHub Documentation (10:30)
The opening remarks themselves did not include a live demonstration or a proof of concept of any specific exploit or technical finding. As an introductory address, its purpose was to set the stage for the conference, outline its themes, and highlight the various activities available to participants. Therefore, no direct technical demo was presented by Reed Loden.
However, the spirit of demonstration and proof of concept is deeply embedded within the fabric of BSidesSF 2024, as indicated by the activities mentioned. The Capture the Flag (CTF) competition inherently involves participants demonstrating their ability to exploit vulnerabilities and solve technical puzzles. Similarly, the various Villages, particularly those focused on hardware, embedded systems, and adversarial techniques, are designed to provide hands-on opportunities for participants to engage with and demonstrate technical concepts. The hackable electronic badges also serve as a personal proof-of-concept platform, allowing attendees to modify and experiment with the device's Python code and hardware, effectively creating their own small-scale demonstrations of custom functionality or exploitation.
Defensive Implications
▶ Watch: Assistance for Bricked Badges (11:00)
The themes and activities highlighted in the BSidesSF 2024 opening remarks carry significant defensive implications for individuals, organizations, and the broader cybersecurity community:
- Proactive AI Security Posture: The overwhelming focus on AI throughout the conference signals an urgent need for defenders to develop a proactive AI security posture. Organizations must understand the unique attack vectors associated with AI systems (e.g., data poisoning, model evasion, prompt injection), integrate AI-specific threat modeling into their development lifecycles, and implement robust controls for AI-powered applications. The conference provides a crucial platform for learning about these emerging risks and sharing defensive strategies.
- Continuous Skill Development and Adaptability: The extensive offerings like the CTF, numerous Villages (e.g., Cloud, APS Security, Embedded Systems), and workshops underscore the critical importance of continuous learning and skill development for cybersecurity professionals. Defenders must constantly update their technical expertise to counter evolving threats. These hands-on environments provide invaluable practical experience that directly translates to improved defensive capabilities in real-world scenarios.
- Community-Driven Threat Intelligence and Collaboration: The BSides philosophy of "no attendees, only participants" fosters a strong sense of community and collaboration. For defenders, this means access to a peer network for sharing threat intelligence, discussing best practices, and collectively addressing complex security challenges. This collaborative environment is vital for building collective resilience against sophisticated adversaries.
- Secure Development and Hardware Awareness: The hackable electronic badges, with their Python-based, USB-C flash drive architecture, encourage an understanding of basic hardware and software security principles. For developers and security engineers, this reinforces the importance of secure coding practices, understanding embedded system vulnerabilities, and the potential for physical access attacks. It provides a low-stakes environment to experiment with and understand the implications of insecure design choices.
- Importance of Governance and Inclusivity: The emphasis on a clear Code of Conduct, a respectful environment, and the provision of emotional support services highlights that effective defense is not solely technical. A diverse, inclusive, and mentally healthy workforce is more resilient, innovative, and effective. Security leaders must prioritize strong governance, ethical considerations, and the well-being of their teams to build sustainable and high-performing security programs.
- Feedback Loops for Program Improvement: The explicit request for feedback on talks and the overall conference mirrors the need for continuous improvement in defensive operations. Security programs must regularly solicit and act upon feedback from incident response, vulnerability assessments, and internal audits to adapt and strengthen their defenses against an ever-changing threat landscape.
Key Takeaways
- AI Dominates the Security Conversation: BSidesSF 2024's theme and talk distribution confirm AI as a paramount concern in cybersecurity, necessitating focused research and defensive strategies.
- Active Participation is Key to Learning: The conference's "no attendees, only participants" model emphasizes hands-on engagement, fostering deeper learning and community building through CTFs, Villages, and workshops.
- Hackable Badges Promote Practical Exploration: The introduction of Python-based, USB-C hackable electronic badges offers a unique, interactive platform for attendees to experiment with hardware and software security concepts.
- Diverse Learning Paths for All Skill Levels: A wide array of specialized Villages (e.g., Cloud, Embedded Systems, Bug Bounty) caters to various technical interests and skill levels, promoting continuous professional development.
- Community and Well-being are Foundational: A strong Code of Conduct, consent-based photo policy, and onsite emotional support highlight the conference's commitment to an inclusive and supportive environment, crucial for effective collaboration in defense.
- Feedback Drives Improvement: The robust feedback mechanisms for talks and the overall conference underscore the importance of continuous evaluation and adaptation, a principle vital for any successful security program.
About the Speaker(s)
Reed Loden is the President and Lead Organizer for BSides San Francisco. In this role, he is responsible for overseeing the planning, execution, and overall success of the annual conference. He leads a dedicated team of volunteers who work year-round to bring the event to fruition, coordinating everything from call for presentations and Capture the Flag challenges to managing logistics and ensuring a positive experience for all participants. His leadership is central to maintaining BSidesSF's community-driven ethos and its reputation as a key event in the cybersecurity calendar.
Reviews
Dr. Zero (Offensive Security Researcher) — WEAK
This is an opening remark, not a technical talk. While it sets the stage for a conference with some potentially interesting technical elements like hackable badges and an AI theme, the presentation itself offers zero technical depth or novel research. It's a logistical overview, not a session for a technical audience seeking real knowledge.
Heather Calloway (CISO) — STRONG ACCEPT
These opening remarks effectively set the strategic direction for BSidesSF 2024, emphasizing critical emerging risks like AI and fostering a strong, inclusive community. The focus on participant engagement, skill development, and a supportive environment provides a solid foundation for a valuable conference experience, directly impacting the capabilities of security professionals and leaders.