Black Hat alternatives: Hackers flock to Las Vegas for security conference season

DefCon, Security B-Sides, Toxic BBQ all in one city in one week

  • Email to a friend
  • Print this article
  • Bookmark this page
  • RSS feed

Two premier security conferences - Black Hat and DefCon - run back-to-back in Las Vegas this week, each with their own distinct flavour. But even these events don't meet the needs of all computer security pros, setting the stage for a widening set of satellite events.

Some of these alternatives are corporate sponsored and some are grassroots, but all contribute to making Las Vegas the place to be this week for anyone hoping to raise their security know-how.

Jack Daniel, who is community development manager for Astaro, says he's getting to town a day early specifically for a four-and-a-half hour conference run by security vendor Codenomicon, then sitting on a panel at Security B-Sides - which directly competes with Black Hat - then speaking at DefCon. That wealth of content in one city at one time is a big draw. "It's a reason to get to Vegas this week if you can afford it," Daniel says.

Black Hat speaker looks at hacker fingerprint analysis | China Google hack starts debate at Black Hat 2010 | Black Hat promises news of major security flaw

DefCon (the oldest of the bunch) and Black Hat were both founded by security consultant Jeff Moss and each have their own appeal. "It's the dark side of the force and the light side of the force," says Josh Corman, an analyst with The 451 Group. DefCon is "a visceral, personal confrontation with what the adversarial community really is. It's more raw, more intense," whereas Black Hat is the more corporate side of the coin with briefings by white-hat researchers.

Inevitably some quality talks proposed for these conferences get rejected, which led to the formation last year of Security B-Sides, a much smaller but more populist conference where attendees can directly engage speakers rather than being talked to from the lectern. Talks aimed at niche sections of the security community can find a home here, Daniel says. The largest talk last year was attended by 60 people; Black Hat and DefCon meeting rooms can hold hundreds.

And the larger shows drift toward presentations by big names that don't necessarily have pure security credentials. For example, last year Adam Savage, the host of the TV show "MythBusters," spoke about carrying on through failure, not a security talk but nevertheless popular. "You couldn't get down that hall to the room," says Daniel. It's difficult, he notes, to maintain the feel of an elite hacker conference when it has more than 10,000 attendees.

Hence the rise of the anti-conference, Security B-Sides, Corman says. "It's almost parasitic; ideally it would be symbiotic," he says. B-Sides -- young, healthy and vibrant -- could actually help keep the larger conferences more focused and relevant.

Last year B-Sides was held in a rented home that had a large meeting room often used as a wedding chapel. This year the group has rented a larger mansion with more and larger rooms and has hired shuttle buses to run continuously between it and Caesar's Palace, where Black Hat is held.

Despite B-Sides running the same days as Black Hat, Daniel says he sees the two as complementary. "Black Hat is a very corporate feel. Vendors are vendors at Black Hat," he says. "At B-Sides our sponsors are not acting like vendors. It's not about lead generation."

That corporate tone at Black Hat is reflected by vendor booths that line the corridors, product announcements released there and even corporate launches. This year, for instance, start-up SlimWare is coming out of stealth mode and announcing availability of its PC-optimising software that relies on crowdsourcing to direct product development.

Black Hat offers a knowledgeable body of technology users as part of the community SlimWAre taps to help guide its product roadmaps, says Chris Cope, CEO and founder of the company. He sought out Black Hat because he sees it as being attended by security enthusiasts who don't necessarily work for vendors.

"That's just what we really want to populate our community," he says.

Black Hat's corporate feel also stems from a set of special events ranging from an awards show (the Pwnies) to a demo area (Black Hat Arsenal) to the Cloud Security Alliance Summit, each of which has its own set of vendor sponsors whose names are affiliated with the events. Those not sponsoring official events often host parties instead, with more than 25 after-conference affairs, most corporate-backed, being scheduled. Some, such as the DefCon-related Toxic BBQ, rely on food contributions from those who attend.

By contrast, B-Sides has more of a frat house feel, Daniel says, with attendees able to collar speakers and sit down in a living room setting or by the pool to talk over a beer. "There's spaces for side conversations without having to stand in the hall," he says. "You can sit in an air-conditioned room and have a burger or some chicken. The spirit of B-Sides is engagement."

Another upside for B-Sides is it's free, which makes it fit better into a lot of training budgets, Daniel says.

Corman sees B-Sides as a place where the security digerati -- analysts and influential bloggers -- can float ideas and get immediate and knowledgeable feedback, which serves to hasten the development of their ideas about where threats lie and what to do about them.

Success could lead to yet another conference, he says. "When an anti-conference gets big enough, it necessitates its own anti-conference," he says.


Contact Us

For editorial queries:
Max Cooter max_cooter@techworld.com

For website issues:
Email webmaster@techworld.com

For commercial queries
Russell Kearney russell_kearney@idg.co.uk


For more contact details click here.

Comment

What are your views on this subject? Use the form below to post a comment on this article up to 500 characters.

Characters remaining: 500

Related Security news

Black hole discovery could boost quantum computers

String theory of gravity connected to entanglement

Onapsis to launch ERP vulnerability testing suite

The software searches for vulnerabilities, looks for compliance problems and creates reports

Women are better at protecting corporate secrets

Defcon social engineering contest finds most people give up secrets to strangers

Facebook introduces new security measures to kick out spammers

Users will be able to use IP info to confirm if their account has been hacked in to and reset passwords



Send to a friend

Email this article to a friend or colleague:

PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

IT Manager's guide to buying an anti-spam solution

With these ten critical questions as your guide, you can cut through the marketing hype and zero in on the key features and benefits that should guide your decision.

Download Whitepaper

Unleashing cloud performance

While cloud services aim to eliminate cost and complexity from the world of enterprise IT, the unintended consequences of these services may do exactly the opposite if not carefully planned for.

Download Whitepaper

Online PC backup

This paper looks at the need for laptop and desktop data protection and, based upon recent IDC research, the key requirements firms should consider in evaluating enterprise-level online PC backup solutions.

Download Whitepaper

Protecting your business, customers, and the bottom line

Download this whitepaper to find out more about how you can protect your business from malware.

Download Whitepaper

Techworld UK - Technology - Business

Oracle Video

Enabling agile and intelligent businesses

 Changing markets, competitive pressures and evolving customer needs are placing increasing pressure on IT to deliver greater flexibility and speed. Explore truly flexible SOA foundations with this Oracle video.

Watch
AMD LGF

AMD Opteron™ Resource Centre

Set the foundations for higher speed processing, low energy consumption whilst delivering flexibility and value to your organisation.

Learn More

Win an iPad

How do you view and share technology related content and information? Tell us in our 2010 Media Usage Survey and you could win an iPad.

Complete the survey here

Site Map

IDG Network

* *