Welcome to DEF CON 33 - The Dark Tangent
The Dark Tangent
DEF CON 33 · Day 1 · Main Stage
Overview
The "Welcome to DEF CON 33" address by The Dark Tangent (DT), the founder of DEF CON, is a quintessential opening keynote that transcends a mere greeting to encapsulate the ethos, history, and future trajectory of the world's longest-running and largest hacker convention. Delivered at DEF CON 33, this talk serves as both an origin story and a philosophical manifesto, articulating the core values that differentiate DEF CON from traditional information security (infosec) conferences. DT emphasizes the "joy of discovery," the inherent drive to understand and push technology beyond its intended limits, and the crucial role of community in fostering innovation and accountability within the hacker space.

Key moments
- 0:00 Welcome to DEF CON 33 and first-timers
- 1:30 Defining DEF CON as a hacker conference
- 2:40 The origin story: meeting online friends
- 3:50 Dispelling myths and seeking experts face-to-face
- 5:50 Early content: first cyber prosecutor and network scanning tool
- 6:30 The spirit: 50% social, 50% learning/hacking
- 7:30 Community accountability and transparency report
Welcome to DEF CON 33 - The Dark Tangent
Speakers: The Dark Tangent
Conference: DEF CON
YouTube: https://www.youtube.com/watch?v=Eo5lwnTft8U
Overview
The "Welcome to DEF CON 33" address by The Dark Tangent (DT), the founder of DEF CON, is a quintessential opening keynote that transcends a mere greeting to encapsulate the ethos, history, and future trajectory of the world's longest-running and largest hacker convention. Delivered at DEF CON 33, this talk serves as both an origin story and a philosophical manifesto, articulating the core values that differentiate DEF CON from traditional information security (infosec) conferences. DT emphasizes the "joy of discovery," the inherent drive to understand and push technology beyond its intended limits, and the crucial role of community in fostering innovation and accountability within the hacker space.
This address is particularly significant as it marks a moment of both reflection and forward-looking vision. DT not only recounts the humble beginnings of DEF CON, born out of a need for face-to-face interaction and the debunking of widespread misinformation in the early days of online communities, but also highlights its evolution into a "meta-conference" – a sprawling ecosystem of villages, contests, and diverse content. The talk underscores the increasing global relevance of the hacker community, revealing how governments and corporations now view DEF CON as a "crystal ball" for future threats and technological trends, a dramatic shift from its initial underground reputation.
Ultimately, The Dark Tangent’s welcome speech is a powerful reminder of DEF CON's enduring mission: to provide a safe, vibrant space for hackers of all levels to connect, learn, and challenge the status quo. It champions constant renewal, encouraging new generations to engage while challenging the community to uphold standards of conduct and embrace the ever-changing landscape of technology, from Wi-Fi to AI. The address is a call to action for collective awareness and education, positioning the hacker community as a vital force in navigating an unpredictable technological future.
Background
▶ Watch: Welcome to DEF CON 33 and first-timers (0:00)
DEF CON emerged from the nascent digital underground of the early 1990s, a period characterized by bulletin board systems (BBS) and a nascent online culture largely devoid of face-to-face interaction. The Dark Tangent, frustrated by the lack of physical community and the rampant spread of misinformation regarding hacking and phone phreaking, conceived DEF CON as a gathering where individuals could meet their online counterparts and learn directly from experts. This foundational premise directly addressed the challenges of a pre-internet information landscape, where "mythologies" and "nonsense" — such as the belief in untraceable phone calls via specific dial-up sequences – propagated unchecked. DT's vision was to bring "the experts in front of the rest of us" to demystify technology and provide accurate, actionable knowledge.
The early DEF CON was a stark contrast to today's corporate-backed infosec conferences. Indeed, as DT points out, "infosec conferences didn't exist when we started," forcing DEF CON to forge its own identity as a pure "hacker conference." This distinction is crucial: while infosec often focuses on defending existing systems, the hacker ethos, as championed by DEF CON, prioritizes the "joy of discovery," the act of "breaking things, fixing things, understanding what the technology can really do," and pushing boundaries. This mentality resonated with early pioneers like Dan Farmer from Sun Microsystems, who presented his groundbreaking network scanning tool, Satan (Security Administrator Tool for Analyzing Networks), at DEF CON 1, subsequently landing on the cover of Time magazine. This historical context illustrates DEF CON's role as a crucible for groundbreaking research and its immediate impact on the broader technology and security landscape.
Over the decades, DEF CON has not only retained its core hacker identity but also evolved significantly. It pioneered the concept of Capture The Flag (CTF) contests, initially as an organic response to network chaos at early conferences, which then formalized into full-contact combat CTFs. This innovation became a global standard for cybersecurity skill assessment and training. The conference also grew from a small gathering where DT knew "everything that happened" to a "meta-conference" by DEF CON 3 or 4, now involving thousands of contributors and tens of thousands of attendees. This growth necessitated the development of robust community structures, including a comprehensive Code of Conduct and an annual Transparency Report (initiated around 2016-2018), reflecting a commitment to safety and accountability that DT actively encourages other conferences to adopt. The background thus paints a picture of DEF CON as a dynamic, community-driven entity that has consistently adapted while remaining true to its hacker roots.
Key Findings
▶ Watch: The origin story: meeting online friends (2:40)
While The Dark Tangent's address is not a technical research paper, it presents several profound "findings" regarding the nature and evolution of the hacker community and its increasing global significance.
Firstly, a core finding is the enduring and evolving definition of "hacker". DT clearly distinguishes a hacker conference from an infosec conference, defining the hacker mentality as a drive for "the joy of discovery, breaking things, fixing things, understanding what the technology can really do." This isn't just about vulnerability research but a deeper exploration of technology, often pushing devices like cars or Xboxes beyond their manufacturer-intended limits. This intrinsic curiosity, often bordering on masochism in its pursuit, is highlighted as the fundamental spirit of the community.
Secondly, DT reveals the unforeseen strategic value of the hacker community to governments and corporations. What began as "showing off for each other" has transformed into a "crystal ball" for anticipating future threats and technological trajectories. DT recounts anecdotes, such as a Defense Intelligence Agency (DIA) operative attending DEF CON to "watch for other watchers" and identify potential recruitment by nation-states or crime groups. More significantly, he cites the DARPA Cyber Grand Challenge and the US Air Force's Hackasat initiative, where millions were invested to leverage the hacker community's skills to identify vulnerabilities in critical infrastructure like satellites and aviation systems. This demonstrates a paradigm shift where nation-states actively solicit and fund hacker innovation, not just to patch existing systems, but to build a robust "ecosystem of people who can hack aviation and satellite stuff so it all gets better for everybody."
Thirdly, the talk underscores the importance of community accountability and safety. Recognizing the challenges that come with growth, DEF CON has actively developed structures like a comprehensive Code of Conduct, a dedicated "goon" team for enforcement, a hotline for complaints, and a separate investigation team for goon misconduct. The annual Transparency Report, started in 2016-2018, publicly details incidents at the conference, setting a precedent for other conferences to follow. This commitment to fostering a "safe space environment" is presented as crucial for attracting and retaining new talent, ensuring the community's constant renewal.
Finally, DT highlights the global expansion and influence of the hacker ethos. After previous forays into China (which were curtailed by the pandemic), DEF CON is actively pursuing new international events, with upcoming conferences planned in Bahrain and Singapore. This global outreach aims to "inspire this kind of hacking community around the world," recognizing that the challenges posed by emerging technologies like Artificial Intelligence (AI) demand a globally informed and interconnected community. The finding here is that the principles of hacker inquiry and community-driven education are increasingly vital for navigating a complex, unpredictable global future.
Technical Deep Dive
▶ Watch: Dispelling myths and seeking experts face-to-face (3:50)
While The Dark Tangent's keynote does not delve into specific code or protocol vulnerabilities, it offers a deep dive into the underlying technical philosophy and historical development of key concepts within the hacker community that have profoundly influenced the broader cybersecurity landscape. The talk frames the hacker mindset not as a mere technical skill, but as an intrinsic drive to understand and manipulate technology at its most fundamental levels.
One of the earliest "technical deep dives" highlighted by DT is the debunking of prevalent misinformation in the pre-internet era. He recalls the pervasive belief that dialing a specific sequence like "pound star, this phone number" would render a call untraceable by law enforcement. DT explains that this "special magic" was, in fact, a simple telco test line whose "beep just means that the line is working." This anecdote illustrates the early community's struggle with accurate technical information and the critical role DEF CON played in bringing "experts" to explain the true workings of systems, a foundational principle for technical integrity.
The evolution of Capture The Flag (CTF) contests is another area of historical technical significance. DT recounts its accidental genesis around DEF CON 3 or 4: initially, the conference's open network became "unusable" due to attendees "messing with each other." This organic chaos led to the creation of a separate "CTF network" where participants could "destroy everybody else on the network and they tried to destroy you." This evolved into a formalized, "offensive defensive," "full contact combat CTF" model, distinct from "Jeopardy style" competitions. This "technical deep dive" into CTF's origins reveals how a practical problem of network hygiene spontaneously generated a powerful, hands-on learning and skill-testing environment that has become a cornerstone of cybersecurity education globally. The CTF model itself is a technical architecture, involving complex networks, vulnerable systems, and scoring mechanisms designed to simulate real-world attack and defense scenarios.
DT also touches upon the ever-shifting technical landscape that captures the community's attention. He notes that while today "people are really obsessed about" AI, in the past, it was equally fervent obsessions with Wi-Fi, cloud computing, aviation systems, physical access controls, implantable medical devices, and lock systems, and smart cars. This catalog of past and present technical fascinations underscores the hacker community's role as an early adopter and explorer of emerging technologies. The community's collective "technical deep dive" into these areas often precedes mainstream security concerns, identifying vulnerabilities and pushing design limits long before they become critical issues for industry or government.
Furthermore, the mention of the DARPA Cyber Grand Challenge and the US Air Force's Hackasat initiative provides insight into government-sponsored technical deep dives. The Cyber Grand Challenge involved "AI machines," or "automated reasoning systems, attacking automated reasoning systems," a cutting-edge exploration of autonomous cybersecurity. Hackasat, where the Air Force asked hackers to "teach hackers or have hackers learn how to hack satellites," explicitly sought to leverage the community's technical prowess to expose vendor insecurities in critical space infrastructure. The successful hacking of a satellite in orbit by the Italian team, M Hackaroni, demonstrates the profound technical capabilities fostered by these initiatives and the DEF CON environment. These examples illustrate how the hacker community, nurtured by DEF CON, has become a critical resource for understanding, testing, and improving the security posture of complex, high-stakes technical systems on a global scale.
Demo / Proof of Concept
▶ Watch: The spirit: 50% social, 50% learning/hacking (6:30)
The Dark Tangent's welcome address, as a keynote presentation, did not feature a live technical demonstration or a traditional proof of concept of a specific vulnerability or exploit. The talk's purpose was to set the stage for DEF CON 33, reflecting on its history, philosophy, and future.
However, the speech itself serves as a powerful "proof of concept" for the value of the hacker community and the DEF CON experience. DT recounts several illustrative anecdotes that function as conceptual demonstrations of the conference's impact:
- The "Fed Watcher" Story (14:00): DT describes observing a person at a CTF table meticulously taking notes on yellow Post-it notes about a hacking team's actions. Later, at the "I spotted the Fed" event, an individual from the Defense Intelligence Agency (DIA) revealed himself, explaining his role was to "figure out if other nation states or crime groups are here trying to recruit hackers" by "stand[ing] at the edge of the room and you watch for other watchers." This anecdote serves as a proof of concept that DEF CON is a significant hub for intelligence gathering and strategic observation, demonstrating its real-world geopolitical relevance beyond just technical talks.
- The DARPA Cyber Grand Challenge (18:00): DT mentions this event, held at DEF CON, where "AI machines" or "automated reasoning systems" were pitted against each other. While not a live demo during this talk, the fact that DARPA chose DEF CON to host a multi-million-dollar competition showcasing the "current state-of-the-art" in automated cyber defense and offense serves as a historical proof of concept for the conference's standing as a premier venue for cutting-edge security research and demonstration.
- The US Air Force Hackasat (18:00): DT highlights the Air Force's initiative to "teach hackers or have hackers learn how to hack satellites" at DEF CON. The ultimate success, culminating in the "winning team was from Italy, M Hackaroni," hacking a satellite in orbit, is a profound proof of concept. It demonstrates that the skills fostered within the DEF CON community are directly applicable to critical national security infrastructure and can drive significant improvements in vendor accountability and overall system security. This "demo" of collective hacker power validated the Air Force's hypothesis that "insecure equipment" could be exposed by "random people," not just nation-states.
These examples, while narrative, function as compelling proofs of concept for the conference's unique environment, its ability to attract diverse participants, and its tangible impact on both the technical landscape and the geopolitical stage. They demonstrate that DEF CON is not just a collection of talks and workshops but a dynamic ecosystem where significant real-world implications unfold.
Defensive Implications
▶ Watch: Community accountability and transparency report (7:30)
The Dark Tangent's address, while not offering specific defensive tools or patches, provides crucial overarching defensive implications for individuals, organizations, and governments. These implications stem from the core philosophy and evolution of the hacker community itself.
Firstly, a primary defensive implication is the imperative for continuous learning and adaptation. DT explicitly states that "the world moves on" and that the community cannot "freeze the universe in carbonite." This underscores that defensive strategies must constantly evolve to counter new threats and technologies. Defenders cannot rely on static solutions; they must emulate the hacker's "joy of discovery" to understand new attack vectors, whether they relate to Wi-Fi, cloud, aviation, or the current obsession, AI. Organizations should foster internal "hacker" mindsets that encourage employees to "break things" safely to understand and proactively fix vulnerabilities.
Secondly, the talk strongly implies the need for vendor accountability and secure by design principles. DT recounts the Air Force's motivation for Hackasat: to "bust them" – meaning vendors – for "selling me insecure equipment." This highlights a critical defensive strategy: demanding higher security standards from suppliers. Defenders should actively engage in security testing, vulnerability disclosure programs, and insist on evidence of robust security engineering from their vendors, rather than blindly trusting claims. The success of Hackasat demonstrated that an ecosystem of skilled hackers can force this accountability, leading to "better for everybody" security outcomes.
Thirdly, the emphasis on community and knowledge sharing is a vital defensive implication. DT's original motivation for DEF CON was to dispel misinformation and connect people with "experts." In today's complex threat landscape, no single entity possesses all the answers. Defenders must actively participate in communities, share threat intelligence, and learn from diverse perspectives. DEF CON itself, with its "1,700 people providing content, contests, events," and "25,000-26,000" attendees, acts as a massive knowledge transfer engine. Organizations should encourage their security teams to attend such conferences, contribute to open-source projects, and engage in peer-to-peer learning to enhance collective defense capabilities.
Fourthly, the establishment of codes of conduct and transparency reports within the community (like DEF CON's own initiated around 2016-2018) carries defensive implications for fostering a healthy and inclusive talent pipeline. A safe and welcoming environment encourages new people to enter and stay in the cybersecurity field. This directly addresses the global talent shortage in defense. By holding each other "accountable for bad behavior, toxic behavior," the community strengthens itself, ensuring a broader and more diverse pool of individuals dedicated to understanding and solving security challenges. This is a long-term defensive strategy for the entire industry.
Finally, DT's closing remarks about DEF CON going global and the importance of "awareness and education" in the face of AI highlight the defensive need for proactive global engagement and policy influence. As technologies like AI introduce "uncertainties, the chaos, the unpredictable future," the hacker community's insights become critical for informing governments and shaping policy. Defenders, therefore, have a role beyond technical implementation; they must contribute to the broader discourse, educate policymakers, and ensure that security considerations are embedded in the development and regulation of emerging technologies on an international scale. This global awareness is presented as the only way to manage future challenges effectively.
Key Takeaways
- Hacker Ethos vs. Infosec: DEF CON is fundamentally a hacker conference, prioritizing the "joy of discovery," breaking things, and understanding technology beyond its intended use, distinct from traditional infosec's focus on defense.
- Community as a Knowledge Hub: Born from a need to dispel misinformation and foster face-to-face interaction, DEF CON remains a critical platform for experts to share accurate technical knowledge and mentor new generations.
- Strategic Value to Governments & Industry: What began as community "showing off" has evolved into a "crystal ball" for governments (e.g., DIA, DARPA Cyber Grand Challenge, Air Force Hackasat) and companies to anticipate threats and drive vendor accountability.
- Evolution of Community Standards: DEF CON actively promotes a safe and accountable environment through its Code of Conduct, dedicated "goons," and annual Transparency Reports, setting a standard for other conferences.
- Constant Renewal and Adaptation: The conference thrives on its continuous evolution, embracing new technological fascinations (from Wi-Fi to AI) and encouraging attendees to adapt, as "the world moves on."
- Global Reach and Future Impact: DEF CON is expanding globally (e.g., Bahrain, Singapore) to inspire hacking communities worldwide, recognizing that collective awareness and education are crucial for navigating the unpredictable future of technologies like AI.
About the Speaker(s)
The Dark Tangent is the enigmatic founder of DEF CON, the world's largest and longest-running hacker convention. His address at DEF CON 33 reflects his deep historical perspective on the hacker community, having initiated the conference over three decades prior. He is the visionary behind DEF CON's unique identity, emphasizing the "joy of discovery" and a hands-on approach to technology over traditional information security paradigms. As the driving force behind the conference's evolution, he has overseen its growth from a small gathering of online friends to a "meta-conference" involving thousands of contributors and tens of thousands of attendees. The Dark Tangent is also a proponent of community accountability, having implemented a Code of Conduct and transparency reporting at DEF CON to foster a safe and inclusive environment. His leadership extends to global outreach, aiming to inspire hacker communities worldwide and position DEF CON as a critical forum for addressing future technological challenges.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
This is DT doing what DT does at every DEF CON opening — origin story, community philosophy, hacker-vs-infosec distinction, a few good anecdotes, call to renewal. It's a competent, warm welcome from the person who has more right than anyone to give it. Nothing here will surprise a DEF CON regular, but it's not trying to.
Heather Calloway (CISO) — WEAK
A welcome address from a founder who has earned the right to give one — but earning the right and making it count are different things. There is real history here, genuine institutional pride, and a few moments of strategic honesty about how governments now use this community. None of it lands with enough precision to move a decision-maker or a defender.