DEF CON Closing Ceremonies & Awards
Unknown
DEF CON 32 Main Stage · Day 1 · Main Stage
Overview
The DEF CON 32 Closing Ceremonies, delivered by an unnamed but clearly central figure in the conference's organization, served as more than just a wrap-up; it was a strategic declaration of intent and a rallying cry for the global cybersecurity community. Under the overarching theme of "Engage," the talk unveiled two ambitious new initiatives: the Def Con Franklin Initiative and the Def Con Academy, alongside reaffirming the importance of the Def Con Social Mastodon server. These projects signal a deliberate move by DEF CON to deepen its impact beyond the annual event, fostering both critical infrastructure protection and accelerated cybersecurity education.

Key moments
- 0:00 Welcome to DEF CON 32 Closing Ceremonies
- 2:00 Moment of silence for community contributors
- 2:29 Introducing DEF CON 32 theme: "Engage"
- 2:59 Launching Def Con Franklin Initiative for critical infrastructure
- 3:59 Introducing Def Con Academy to accelerate learning
- 4:29 Update on Def Con Social Mastodon server
- 5:07 Announcing the Uber Contributor Award: The Prophet
DEF CON Closing Ceremonies & Awards
Speakers: Unknown
Conference: DEF CON 32
YouTube: https://www.youtube.com/watch?v=GdeKrNlvG8g
Overview
The DEF CON 32 Closing Ceremonies, delivered by an unnamed but clearly central figure in the conference's organization, served as more than just a wrap-up; it was a strategic declaration of intent and a rallying cry for the global cybersecurity community. Under the overarching theme of "Engage," the talk unveiled two ambitious new initiatives: the Def Con Franklin Initiative and the Def Con Academy, alongside reaffirming the importance of the Def Con Social Mastodon server. These projects signal a deliberate move by DEF CON to deepen its impact beyond the annual event, fostering both critical infrastructure protection and accelerated cybersecurity education.
The speaker emphasized the foundational principle of "standing on the shoulders of giants," acknowledging the historical contributions of community members and dedicating a moment of silence to those who paved the way. This reflective tone quickly transitioned into an energetic outline of future endeavors designed to empower and mobilize the community. The initiatives represent a proactive approach to addressing pressing cybersecurity challenges, from safeguarding essential services to bridging the skills gap within the industry.
Furthermore, the ceremonies included the presentation of the third annual Uber Contributor Award to "The Prophet," recognizing decades of selfless dedication to the community. This award underscores DEF CON's commitment to celebrating and inspiring sustained, impactful contributions. The talk, while lighthearted at times, conveyed a clear message of community responsibility, continuous learning, and collective action, setting a forward-looking agenda for DEF CON and its global participants.
Background
▶ Watch: Welcome to DEF CON 32 Closing Ceremonies (0:00)
DEF CON, since its inception in 1993, has evolved from an informal gathering of hackers into the world's largest and most iconic cybersecurity conference. Its history is deeply rooted in the principles of open knowledge sharing, community building, and challenging the status quo. Over the decades, it has served as a crucible for groundbreaking research, a platform for ethical disclosure, and a vital hub for fostering talent within the often-misunderstood hacking community. The ethos of "giving back" and "contributing to others" highlighted by the speaker is a core tenet that has defined DEF CON's culture, enabling generations of security professionals to learn, collaborate, and innovate. The phrase "standing on the shoulders of giants" encapsulates this respect for the community's heritage and the collective knowledge built over time.
The problems addressed by the new initiatives are acutely relevant to the current global cybersecurity landscape. The protection of critical infrastructure, particularly water systems, has emerged as a paramount concern for national security and public safety. These systems, often built on legacy technologies and increasingly interconnected, present unique vulnerabilities that nation-state actors and sophisticated criminal groups frequently exploit. The inherent complexity and specialized nature of Operational Technology (OT) and Industrial Control Systems (ICS) environments mean that expertise is scarce, and traditional IT security approaches are often insufficient. There is a clear and urgent need for a dedicated, skilled workforce to identify and mitigate risks to these essential services. The speaker’s emphasis on creating "on-ramps" for community members to contribute directly to this protection reflects a recognition of the vast, untapped potential within the hacking community to address these critical challenges.
Concurrently, the cybersecurity industry faces a persistent and widening skills gap. The rapid pace of technological change, the constant evolution of threats, and the sheer volume of new vulnerabilities mean that continuous learning is not just beneficial, but essential. Traditional educational pathways often struggle to keep pace, leaving many aspiring professionals without the practical, hands-on experience demanded by the industry. Initiatives aimed at accelerating learning and providing practical, real-world skill development are therefore crucial for equipping the next generation of defenders. The mention of lessons learned from Pone College suggests an intent to leverage proven, practical pedagogical methods that prioritize rapid skill acquisition over theoretical knowledge alone.
Finally, the discussion around social media fragmentation and the continued operation of the Def Con Social Mastodon server speaks to broader trends in digital communication and community engagement. As traditional social media platforms grapple with issues of moderation, content control, and user trust, there's a growing movement towards decentralized and community-governed alternatives. Providing a "safe harbor" moderated by DEF CON's established code of conduct reflects a desire to maintain a principled, secure, and respectful online space for its community, mirroring the values upheld at the physical conference. This commitment underscores the understanding that a robust, supportive community is vital for collaborative progress in cybersecurity.
Key Findings
▶ Watch: Introducing DEF CON 32 theme: "Engage" (2:29)
The DEF CON 32 Closing Ceremonies served as a platform for significant announcements and strategic shifts, rather than presenting traditional research findings. The "key findings" of this event are the concrete initiatives launched under the theme "Engage," which represent DEF CON's evolving commitment to community and global security.
- The Def Con Franklin Initiative: This is a pioneering effort to establish a "Rolodex matchmaking system" designed to connect cybersecurity professionals willing to volunteer their expertise with critical infrastructure entities that require assistance. The initial focus is on water systems, recognizing their vital importance and inherent vulnerabilities. The objective is to create structured "on-ramps" for community members to contribute directly to the protection of these essential services. The initiative is experimental, with DEF CON acknowledging the possibility of both spectacular success and failure, but committing to documenting and sharing lessons learned regardless of the outcome. If successful, there are plans to expand the initiative to education and school systems, demonstrating a broad vision for leveraging community talent for societal good.
- The Def Con Academy: Spearheaded by the Pone College crew (specifically mentioning "Shellfish"), this initiative aims to accelerate learning for cybersecurity practitioners. The core idea is to drastically reduce the time it takes for individuals to achieve a high level of skill, potentially cutting a seven-year learning curve down to four or five years. The Academy will integrate "lessons learned from Pone College and other things," suggesting a curriculum heavy on practical, hands-on training and real-world scenarios. It is launching in a beta phase this year, with a full public launch anticipated next year. The call for community involvement in testing indicates a collaborative, iterative development process.
- Continued Support for Def Con Social (Mastodon Server): In response to observed "fragmentation in social media" and "reduced activity across all platforms," DEF CON reaffirmed its commitment to its Mastodon server. Positioned as a "safe harbor," this platform is moderated according to DEF CON's established code of conduct, providing a trusted online space for community interaction. This initiative reflects a broader trend towards decentralized social media and a commitment to fostering a respectful and secure digital environment for its members in a "post-Covid long haul" era.
- The Uber Contributor Award: This annual award, now in its third year, recognizes individuals who have made years or decades of selfless contributions to the DEF CON community and the broader hacking world. The recipient at DEF CON 32 was "The Prophet," celebrated for being a long-time writer for 2600 magazine, an educator, a DJ, and his involvement in projects like Telefreak Challenge and Queer Con. This award serves as an important mechanism for DEF CON to highlight exemplary community members, set a standard for selfless contribution, and inspire future generations of hackers.
These initiatives collectively represent a strategic evolution for DEF CON, moving beyond simply hosting a conference to actively facilitating solutions to real-world security challenges and nurturing the next generation of talent through structured programs.
Technical Deep Dive
▶ Watch: Launching Def Con Franklin Initiative for critical infrastructure (2:59)
While the closing ceremonies did not present a traditional "technical deep dive" into a specific vulnerability or exploit, the initiatives announced carry significant technical implications and will necessitate deep technical understanding in their execution. The "technical deep dive" in this context refers to the underlying technical challenges and the types of expertise required to make these initiatives successful.
The Def Con Franklin Initiative, focused on protecting critical infrastructure (starting with water systems), implicitly demands a profound technical understanding of Operational Technology (OT) and Industrial Control Systems (ICS). Unlike conventional IT environments, OT systems often involve specialized hardware, proprietary protocols (e.g., Modbus, DNP3, IEC 61850), and real-time operational constraints where downtime can have severe physical consequences. A technical deep dive into this area would involve:
- Vulnerability Assessment in OT/ICS: This requires knowledge of specific OT device vulnerabilities, common misconfigurations in SCADA (Supervisory Control and Data Acquisition) systems, and the ability to safely conduct penetration testing without disrupting operational processes. Techniques might include passive network monitoring to map industrial networks, protocol analysis for unusual traffic, and identifying insecure remote access mechanisms.
- Secure Architecture Design: Expertise in designing segmented networks for OT environments (e.g., using Purdue Model or IEC 62443 standards), implementing secure gateways, and deploying specialized intrusion detection systems tailored for industrial protocols.
- Incident Response in OT: Understanding the unique challenges of responding to incidents in a live industrial environment, including forensic analysis of embedded systems, safe mitigation strategies, and recovery plans that prioritize operational continuity.
- Legacy System Hardening: Many critical infrastructure systems rely on outdated hardware and software. Technical contributions would involve identifying upgrade paths, implementing compensating controls, and developing custom solutions to secure systems that cannot be easily patched or replaced.
The "Rolodex matchmaking system" itself, while conceptually simple, would require a robust technical platform. This could involve secure user authentication, robust data privacy measures for sensitive infrastructure information, and potentially sophisticated algorithms for skill matching and project management, ensuring that volunteers possess the specific technical expertise required by a given critical infrastructure entity.
The Def Con Academy, aiming to accelerate learning, will necessitate a technically rigorous and innovative pedagogical approach. A technical deep dive into its design would consider:
- Curriculum Development: Crafting focused, hands-on curricula that rapidly build competence in areas like reverse engineering, exploit development, network forensics, cloud security, or secure coding. This would involve identifying core concepts and practical skills that typically take years to master and distilling them into an accelerated format.
- Learning Environments: Designing and implementing robust virtual lab environments that mimic real-world systems and networks, allowing students to practice offensive and defensive techniques safely. This often involves orchestrating virtual machines, containers, and specialized tools (e.g., Metasploit, Wireshark, IDA Pro) in a scalable and accessible manner.
- Automated Assessment and Feedback: Developing systems for automated grading of practical exercises, providing immediate feedback, and tracking student progress. This could involve CTF (Capture The Flag)-style challenges, automated code analysis, or simulated incident response scenarios.
- Integration of Open-Source Tools and Methodologies: Leveraging the vast array of open-source security tools and community-developed methodologies to provide cost-effective and up-to-date training.
Finally, the continued operation of Def Con Social on Mastodon highlights technical considerations related to decentralized social media. A technical deep dive here would involve:
- Federated Network Architecture: Understanding the ActivityPub protocol and how Mastodon instances communicate across a decentralized network. This includes managing server-to-server interactions, data synchronization, and content distribution across independent nodes.
- Instance Security and Moderation: Implementing robust security configurations for the Mastodon server itself, including hardening the underlying operating system, web server, and database. Developing and enforcing moderation policies requires technical tools for content filtering, user reporting, and managing user access in a decentralized environment.
- Scalability and Performance: Ensuring the Mastodon instance can handle a potentially large user base, managing database load, and optimizing media storage and delivery, especially given the influx of users seeking alternatives to centralized platforms.
- Data Privacy and User Control: Implementing features that give users granular control over their data, privacy settings, and interactions within the federated network, aligning with the principles of user empowerment often associated with decentralized platforms.
In essence, while the talk was an organizational update, the initiatives themselves are deeply technical in their conceptualization and execution, requiring the very expertise that DEF CON strives to cultivate and mobilize.
Demo / Proof of Concept
▶ Watch: Update on Def Con Social Mastodon server (4:29)
As the event was the closing ceremonies for DEF CON 32, it did not feature a traditional technical demonstration or proof of concept in the manner of a research presentation. Instead, the focus was on outlining future initiatives and community directions.
The initiatives themselves, particularly the Def Con Franklin Initiative and the Def Con Academy, are in their nascent stages, with the Franklin Initiative described as experimental and the Academy launching in a beta phase. Therefore, there were no live demonstrations of a "Rolodex matchmaking system" in action for critical infrastructure protection, nor were there any showcases of accelerated learning modules from the Def Con Academy. However, the very nature of these projects implies that future DEF CON events or community updates could very well include demonstrations of their progress, such as successful pairings facilitated by the Franklin Initiative or the practical outcomes achieved by Academy participants. These future demonstrations would serve as proof points for the effectiveness and impact of these ambitious community-driven efforts.
Defensive Implications
▶ Watch: Announcing the Uber Contributor Award: The Prophet (5:07)
The announcements made at the DEF CON 32 Closing Ceremonies carry significant defensive implications for the cybersecurity community and critical infrastructure sectors. The strategic focus on "Engage" and the launch of the Def Con Franklin Initiative directly address one of the most pressing defensive challenges: the protection of critical infrastructure.
The Franklin Initiative aims to bridge a crucial gap between the vast talent pool within the cybersecurity community and the often under-resourced and vulnerable operators of essential services, starting with water systems. The defensive implications are profound:
- Enhanced Critical Infrastructure Resilience: By connecting volunteer security experts with water utilities, the initiative can facilitate proactive vulnerability assessments, penetration testing, and the implementation of robust security controls that these entities might otherwise lack the internal expertise or budget to acquire. This direct injection of specialized knowledge can significantly improve the defensive posture of critical infrastructure, making it more resilient against cyberattacks.
- Proactive Threat Mitigation: Community experts can help identify and mitigate specific threats unique to Operational Technology (OT) environments, such as insecure network configurations, exploitable legacy systems, and vulnerabilities in industrial control protocols. This proactive approach moves beyond reactive incident response to prevent attacks before they succeed.
- Knowledge Transfer and Capacity Building: Beyond immediate fixes, the initiative fosters knowledge transfer. Volunteers can educate critical infrastructure staff on best practices, threat intelligence, and defensive strategies, building long-term internal capacity for cybersecurity within these organizations. This is crucial for sustainable defense.
- Community-Driven Intelligence Sharing: As the Franklin Initiative matures, it could naturally lead to a more formalized mechanism for sharing anonymized threat intelligence and defensive lessons learned across critical infrastructure sectors, further bolstering collective defense.
- Accelerated Workforce Development for Defenders: The Def Con Academy directly contributes to strengthening overall defensive capabilities by accelerating the development of highly skilled cybersecurity professionals. A shorter learning curve means more qualified defenders entering the workforce sooner, equipped with practical skills in areas like incident response, threat hunting, and secure system design. This directly addresses the global cybersecurity skills gap, which is a significant impediment to effective defense across all sectors.
- Secure Communication Channels: The continued operation of Def Con Social as a moderated "safe harbor" provides a secure and trusted platform for defenders to communicate, collaborate, and share information without the concerns of privacy breaches, harassment, or platform instability often associated with mainstream social media. This secure environment is vital for coordinating defensive efforts and sharing sensitive, non-classified intelligence within the community.
In essence, DEF CON is leveraging its unique position and community ethos to directly contribute to a more robust, skilled, and collaborative global cyber defense ecosystem. These initiatives are not merely academic exercises; they are practical, community-driven solutions designed to enhance the security posture of vital systems and the preparedness of the cybersecurity workforce.
Key Takeaways
- Community Engagement as a Strategic Imperative: DEF CON 32's theme "Engage" signals a proactive shift towards mobilizing the cybersecurity community for direct impact on real-world challenges, moving beyond just information sharing.
- Critical Infrastructure Protection is a Priority: The Def Con Franklin Initiative specifically targets safeguarding essential services, beginning with water systems, by matching volunteer cybersecurity expertise with entities in need.
- Accelerated Learning to Bridge the Skills Gap: The Def Con Academy, building on Pone College methodologies, aims to significantly reduce the time required to achieve high-level cybersecurity skills, addressing a critical industry shortage.
- Commitment to Secure Community Platforms: Def Con Social (Mastodon) continues to provide a moderated, "safe harbor" online environment, emphasizing trusted communication and adherence to community values amidst social media fragmentation.
- Celebrating Selfless Contribution: The Uber Contributor Award highlights and honors individuals like "The Prophet" who have dedicated decades to advancing the community, fostering a culture of generosity and long-term impact.
- Embracing Experimentation and Learning from Failure: DEF CON acknowledges that these new initiatives are experimental and may "fail spectacularly," but commits to documenting and sharing lessons learned regardless, promoting a culture of continuous improvement.
About the Speaker(s)
The speaker for the DEF CON 32 Closing Ceremonies is identified as Unknown in the provided metadata. However, based on the nature of the address, the speaker is clearly a central figure in the DEF CON organization, likely one of its primary organizers or a key leader. Their tone is authoritative yet personable, demonstrating a deep understanding of the conference's values, history, and future direction. The speaker engages with the audience, makes lighthearted jokes about hydration and "pee cups," and expresses genuine relief and pride in the successful execution of the event. Their role involves setting the strategic vision for DEF CON's community initiatives, acknowledging past contributions, and rallying attendees around the conference's core mission.
It is important to clarify that "The Prophet," mentioned in the transcript, is not a speaker for this talk but rather the recipient of the third annual Uber Contributor Award. "The Prophet" was honored for decades of selfless contributions to the community, including being a long-time writer for 2600 magazine, an educator, a DJ, and his involvement in projects such as the Telefreak Challenge and Queer Con. This award recognizes individuals who serve as exemplary figures within the hacking community through sustained and impactful efforts.
Reviews
Dr. Zero (Offensive Security Researcher) — MUST SEE
This wasn't a technical talk, it was a strategic declaration from the heart of the community, and it delivered. The launch of the Def Con Franklin Initiative and Def Con Academy represents a significant, proactive pivot for the conference, moving beyond information sharing to direct community mobilization for critical infrastructure protection and accelerated skill development. This isn't marketing fluff; it's a concrete commitment to addressing real-world problems with the community's unique expertise. It's the kind of bold move that defines the conversation and sets a new standard for what a security conference can achieve.
Heather Calloway (CISO) — MUST SEE
The DEF CON 32 Closing Ceremonies, under the banner of "Engage," delivered a powerful strategic declaration rather than a mere recap. The unveiling of the Def Con Franklin Initiative, aimed at connecting volunteer cybersecurity expertise with critical infrastructure like water systems, and the Def Con Academy, designed to accelerate professional learning, represents a profound institutional commitment. This presentation directly addresses systemic issues of governance, accountability for vital assets, and the persistent skills gap, offering concrete, actionable pathways for the community to contribute to real-world security challenges. It’s an unsentimental, direct call to action…