Why BSidesLV Felt Like Old-School DEF CON
I’m a veteran of security conferences, but this year I stumbled into something I didn’t expect: BSidesLV reminded me of some of the best parts of old-school DEF CON and made me want to go back.
My first DEF CON was DEF CON 14, back in 2006. It was unlike any conference I had been to before, and it blew me away.
The first thing that jumped out at me was the overt FBI presence: they had video cameras on tripods at every entrance and exit from the Riviera. Then, once inside, there was a “spot the fed” game where people would point and shout “Fed! Fed!” at people with military-style haircuts. Mind you, the Feds were also invited in and gave talks and panels, so the game was just for fun.
The next thing that caught my attention was the Wall of Sheep, where credentials sent over unencrypted HTTP on the local Wi-Fi were sniffed and displayed on a projector. HTTPS was far less common at the time, many apps were lazy about encryption, and cellular data connections were painfully slow, so the Wall of Sheep was full of unredacted credentials. It was a vivid testament to the importance of encryption.
Unlike most conferences, which are structured solely around talks, networking opportunities, and vendors, DEF CON was intensely interactive and non-commercial. Networking happened everywhere, not just during stilted happy hours. In fact, much of the networking happened in the lines.
They didn’t cap the number of attendees, so the whole thing was a fire marshal’s nightmare. There were lines for every talk, and you often had to get in line early or risk not getting in at all. The lines became the primary place to meet people, but also to open your laptops, sit down at the edges of the hallways, and show off or learn things from your neighbors.
At one point, I stumbled into a small room with tables covered in locks, handcuffs, and lock picks. It was quieter and less crowded than the rest of the conference and had people who were eager to help teach you locksport. It quickly became a favorite escape hatch of mine when the lines and the crowds became too much. Locksport areas are common at security conferences now, but at the time, this was unique.
Old-school DEF CON was crowded, but it was still relatively small. Curiosity, sharing, and teaching between attendees were part of the fabric of the conference. When I was lucky enough to go, I always left with a ton more knowledge, and only a fraction of it came from the talks.
Today’s DEF CON preserves a lot of that, but on a much larger scale that can be overwhelming. There are around 40,000 people who attend, and the conference now includes around three dozen sub-conferences, each with their own interactive areas, demos, talk tracks, and competitions. The lockpicking room is now a village with its own talk tracks. It has spun out at least two other villages: one on alarm systems and one on tamper-evident seals.
It’s so big that I didn’t even notice when Skytalks stopped happening.
Skytalks were one of the original unofficial events within DEF CON. They were held in rooms rented on the top floor and were strictly off-the-record, with masked anonymous speakers talking about real-world security incidents. The speaker could be a hacker, a defender, or just someone ranting. Some of the insider information on real-world events discussed in those talks was eye opening.
When I wasn’t looking a few years ago, Skytalks moved to BSides.
BSides started in 2009 as a venue for people who couldn’t get into Black Hat. Black Hat is another security conference focused on enterprise IT attendees, but it’s expensive to attend and has a much stronger commercial and sponsor presence, including in some of the talks. Black Hat and DEF CON used to be run by the same people and to this day are scheduled back-to-back during the same week in Vegas. BSides is set up for the couple of days before Black Hat to take advantage of the influx of security folks already in Vegas. BSides became popular in an underground-cult way and has since spread to hundreds of cities around the world.
Until this year, I’d never attended the original BSides, BSidesLV. Though it’s well known and popular, it’s an order of magnitude smaller than DEF CON, with around 3,000 attendees. It’s also far less expensive than other conferences that week, costing $100 to attend versus DEF CON’s $500 and Black Hat’s $3,000.
I really liked BSidesLV. For one thing, it wasn’t overcrowded. It felt calmer. I talked to people more. There were some lines, but they were manageable: more like 10 minutes than an hour. It had great talks, good people, a nice space, and I didn’t leave feeling overwhelmed and overstimulated, as I sometimes do after modern DEF CON.
I don’t miss the lines and masses of people of old DEF CON. I miss the collisions. I miss the surprising discoveries and deep learnings. Those can be found in modern DEF CON, but the scale gets in the way. BSidesLV gave me some of that back.
I was fortunate enough to go there as a speaker, but I will absolutely go again even if I don’t have a talk. And if you’re someone who heads to Vegas at peak heat and misery to attend hacker summer camp, you should give it a shot, too.






