To see our schedule with full functionality, like timezone conversion and personal scheduling, please enable JavaScript and go here.
10:00
10:00
240min
Get Your Amateur (Ham) Radio License in a Single Weekend (Part 1 of 2 parts)
Dan Romanchik, Ed Wilson, Nicole Adams, BusySignal

This workshop will teach attendees what they need to know to pass the Technician Class amateur radio license exam and get started in amateur radio. It includes six hours of instruction, with the exam administered immediately after the workshop. It is sometimes said that radio amateurs were the original hackers, cobbling together transmitters and receivers from odds, ends, and discarded electronics. Radio amateurs continue this tradition today, and in addition to building their own gear, they’re hacking on digital communications systems, including both hardware and software. Amateur radio is a great hobby for electronics enthusiasts and, increasingly, for hardware and software hackers. Participants will increase their chances of passing the test if they download the study guide from www.kb6nu.com/study-guides/ and familiarize themselves with the material before coming to the workshop. The text for this workshop is Dan’s No Nonsense Technician Class License Study Guide. The PDF version of the study guide is available for free at the above page. EPUB and print versions are also available for a small charge. This is part 1 of 2 parts -- the 2nd part is Saturday 10am - 2pm, same room. To pass your exam, please participate in both parts.

Kips Bay
10:30
10:30
30min
HOPE 26 Opening Ceremonies

It all starts Friday morning. Join us as we make sure everything works before another HOPE is unleashed on everyone.

Grand Ballroom
11:00
11:00
50min
Cameras, Cops, and Cell Towers: A Field Guide to Modern Surveillance
Michael Raymond

Your car passes a license plate reader. Your phone connects to a cell tower. A camera identifies your face, a drone watches from above, and data brokers help connect the dots. Most people have no idea how much surveillance follows them through an ordinary day or where that information ends up. This talk pulls back the curtain on the modern police surveillance stack, from Flock cameras and cell-site simulators to drones, body cameras, facial recognition, data brokers, and regional intelligence networks. Using real-world examples and open-source tools such as EFF’s Atlas of Surveillance and RayHunter, Michael Raymond will show attendees how these systems work, how communities are mapping them, and what practical, lawful steps people can take to better understand and reduce their exposure.

Grand Ballroom
11:00
50min
I-Stars: Protocols and Power
Mallory Knodel

Back for the third time, author and technologist Mallory Knodel will give an update on several I-star organizations, namely ICANN, IETF, IEEE, W3C, and ITU. The tensions and synergies of human rights considerations in Internet governance and standards setting across the I-star bodies is rapidly expanding. This talk will touch on the major controversies in each space as they relate to human rights, namely censorship and the right to privacy.

Crystal Ballroom
11:00
120min
Wi-Fi Self Defense and Hacker Hunting for Beginners (Day 1)
Kody Kinzie

This workshop offers hands-on instruction using a unique, cat-shaped Wi-Fi hacking microcontroller, the Wi-Fi Nugget. Designed to engage participants in practical learning, it covers essential skills for defending against four common yet powerful Wi-Fi attacks. Students will explore topics including detecting Wi-Fi leaks, the risks of QR codes leading to hidden networks, spotting phishing networks, and defending against advanced Wi-Fi karma attacks. The Wi-Fi Nugget is a powerful tool for understanding and fighting back against Wi-Fi hacking. This class is suitable for Wi-Fi hacking experts and those just getting started.

Herald Square / ScriptKitty Village
12:00
12:00
50min
Against Tech Oligarchy
Clarissa Redwine

As tech bosses fall in line with the right, tech workers have begun fighting back. Resistance has included organizing against military contracts, walkouts to protest sexism, agitation about tech’s role in the climate crisis, and even a wave of union drives. Hellbent on stamping out any and all dissent, tech executives embraced Trumpism, fired organizers, and began lashing out against the “woke” ideology they blamed for turning their once loyal employees against them. This is the rousing inside story of the tech worker movement – and the way it spawned an anti-worker backlash now reshaping the industry.

Crystal Ballroom
12:00
360min
Anarchist Hacker Village (Day 1)

A space for anarchists, abolitionists, anti-authoritarians, other like-minded folks, with friendly faces to meet and socialize with. Where hacking and technology are tools for total liberation. We'll have freely available swag like zines and stickers, and a place to find out about related ad-hoc events like assemblies.

Herald Square / Anarchist Hacker Village
12:00
50min
Building a Community Arcade Cabinet
Frank Chiarulli, Rose Hall, Sophie Downward

The RCade is a custom arcade cabinet built at the Recurse Center that runs games made by the community. It has a real CRT, a custom graphics card, spinner controllers, and a deploy pipeline where anyone can ship a game just by pushing to GitHub. It now has over 90 games. Frank Chiarulli will talk about reviving the hardware and building the deployment system, Rose Hall will cover the game engine and plugin sandbox, and Sophie Downward will walk through building a custom display adapter from scratch. They’ll close out by showing off some of the games.

Grand Ballroom
12:00
50min
HERMES: Secure, Long Distance Data Communication Over HF Radio
Peter Bloom

Rhizomatica has been working on a completely autonomous communication system called HERMES (hermes.radio) since 2017. HERMES is a fully FLOSS stack that has been built to use HF radio to create secure and very long-range (about 500 kilometers) digital communication links. HERMES has been deployed in the Amazon to support land defenders, on boats in Bangladesh to provide critical communications to fishermen, in war zones in Africa as part of early warning systems, etc. Due to current geopolitical situations that have us all concerned, it’s clear that HERMES can be a critical tool for hackers, privacy activists, and the general public to create autonomous and secure digital communication networks that are much harder to monitor or shut down compared to corporate-controlled ISPs.

Gramercy Park Suite
12:00
360min
Hackerspace Village (Day1)

Come check out the local NYC hackerspaces at the Hackerspace Village. It is organized by
some of New York City’s local hackerspaces. You are invited to join them for lots of cool
activities throughout HOPE 26. They are all nonprofit and 100 percent volunteer-run and would
love to have you visit on their open nights!

Herald Square / Hackerspace Village
12:00
360min
Ham Radio Village (Day 1)

Our mission is to deliver high-quality and innovate amateur radio related educational content,
hands-on experiences, and license testing sessions online and in-person through events. We
believe that the more people know about amateur radio, the more safe, secure, functional, and
innovative our wireless products, services, and experiments will be. Our team of dedicated
volunteers is responsible for generating all new research, giving talks and demonstrations at
events, building and testing experiments, as well as offering support to the general ham radio
community. There will be ham radio demonstrations throughout HOPE 26.

Herald Square / Ham Radio Village
12:00
60min
Health Sovereignty: Herbal Medicine for Everyday Care
Rev. Eon

The workshop will be an open discussion and hands-on introduction to practical herbal medicine for everyday health. It will engage directly with plants to assess herbs through both sensory experience and basic phytochemistry - and discuss herbal preparations such as tinctures, oils, and teas.

Sutton Place / Workshop B
12:00
360min
Lockpick Village With Lockpick Extreme (Day 1)
Bob Hermes, Christine Bachman, Daniel Finegold

Locks are puzzles you can solve without the key! Explore the fun world of locksport with Lockpick Extreme. Learn to lockpick from friendly instructors or practice what you already know with their assortment of locks and picks. When you’re done, you can shop at the pop-up shop and take your new hobby home with you.

Herald Square / Lockpick Village
12:00
360min
Paper Popups (Day 1)

Explore the world of pop-ups! How can something 2D become 3D? Learn both the math and magic behind these folding paper sculptures. Take a break and build out a HOPE pop-up book. Participants will be empowered to set off into the exciting world of paper engineering. Stop by any time throughout HOPE 26.

Herald Square / Paper Popup Village
12:30
12:30
120min
The Accountability Toolkit: OCCRP and MuckRock
Ezana, Sanjin

In a world increasingly shaped by secrecy, corruption, and misinformation, truth requires infrastructure. Built entirely for the public interest, both the Organized Crime and Corruption Reporting Project (OCCRP) and MuckRock provide vital, public-good resources designed to help investigators uncover what powerful actors want to keep hidden. This two-hour, hands-on workshop brings together two essential tools for transparency: OCCRP Aleph Pro and MuckRock’s DocumentCloud. Aleph Pro is a massive investigative data platform holding more than four billion documents - ranging from corporate registries to leaked datasets - designed to help users follow the money and map complex networks. DocumentCloud is a public platform with over seven million primary source documents, allowing anyone to search, analyze, and organize materials through either the user interface or the API, serving as a trusted resource for public records and research on public figures, government activities, corporate practices, and other matters of public interest. You will be walked through real-life examples of how these platforms are used in high-stakes investigations, and learn about the global impact they ’ve generated and how new users can get started. Whether your goal is to make sense of chaotic leaked data, navigate massive FOIA dumps, or map hidden assets, this workshop gives you the tools and hands-on experience to do it. What will you uncover?

Sutton Place / Workshop A
13:00
13:00
50min
An Open Forum for Legal Research
Calliope Youngblood

Legal research is infamous for guarded access (law firms only) and high prices (monthly and per-search). This year at HOPE, see the launch of an open-source legal search engine, and a public forum for legal research. Learn how to model legal sources using vector and graph databases, how to acquire records using scrapers, and how to connect directly to the people at Congress producing and publishing these records each day. Calliope live-codes each day on YouTube to prepare for HOPE, on https://www.youtube.com/@c4lliope/streams. Their code is published on https://operand.online.

Crystal Ballroom
13:00
50min
From Source to Story: Cryptography and Psychosocial Care Protects Public Interest Journalism
Jen Helsby, Harlo Holmes

The threat landscape for journalists and whistleblowers has dramatically intensified over the last 15 years, leading to the development of robust technical evolutions in platforms from SecureDrop, Dangerzone, WhatsApp (meh), and Signal. Safely handling malicious submissions and spicy comms, newsrooms have become used to employing rigorous security models, sandboxing techniques, and myriad other tactics that have become the “meat-and-potatoes” of high-stakes public interest journalism. The baseline for secure communications is always shifting due to emerging legal, quantum, and novel AI challenges. This talk will address this and help enable you to fully understand how securing data is only half the equation; it is equally critical to protect the human risking their livelihood or liberty for the public’s right to know. This means moving beyond threat models to deeply understand the psychological toll of whistleblowing and the empathetic dimensions of the journalist-source relationship. You will get a glimpse into the modern toolbox that merges strict digital security protocols with empathetic strategies to manage the anxiety inherent in the biggest disclosures. From first contact to post-publication – you’ll learn about the life cycle reporters expect to safely and ethically get the story done.

Grand Ballroom
13:00
50min
Lingua Machina: The Last Humans Who Read Code
Anna Nicanorova

We treat code as pure instruction, something you write so a machine will obey. Programming languages are closer to a living vernacular, riddled with idiom, accent, ambiguity, and taste, sitting somewhere between human language and musical notation. This talk covers the linguistics of computer languages: how languages were invented, argued over, and mutated; how grammar became structure; how we keep accelerating the pace at which we talk to machines in search of better ways to build. And as the history of computer linguistics will be covered, it is also worth reviewing the uncomfortable question for an age of generated code: as fewer of us write it by hand, will we still read it, understand it, and know why we write it the way we do?

Gramercy Park Suite
13:15
13:15
120min
Build Your Own Meshtastic Node: Off-Grid, Encrypted LoRa Meshnets for Beginners!
Kody Kinzie

Beginners can now create off-grid, encrypted mesh networks for cheap, with applications in emergency communication, sensor monitoring, and more! These mesh networks have been popping up in cities all over the world, and this workshop will go over everything a beginner needs to run or build their own nodes. If you ’ve ever wanted to legally create off-grid, encrypted mesh networks that can span over a hundred miles, you can get started with Meshtastic for around $50. This class will serve as a beginner user’s guide to Meshtastic, covering everything from hardware basics to advanced software configuration. The workshop will use custom Meshtastic nodes to see real-world results in Las Vegas and explore attacks against mesh networks. Attendees will learn to run their own Meshtastic nodes, select antenna options, and configure software!

Herald Square / ScriptKitty Village
13:30
13:30
90min
Hacking at the First Five Pages: A Screenwriting Workshop
LexIcon

Do you have a movie inside you? This is a writing workshop focused on the structures that can be set up in the early pages of a screenplay. Bring your script, come to write, or just come to learn. Details on the wiki. Lines like “hack the planet” are burned into most of our brains, but to get in there they had to go through a lengthy process that all started with a script. The first five pages of a script are critical for engaging the reader and setting up the rest of the story, so that is where this workshop will focus.

Sutton Place / Workshop B
14:00
14:00
50min
Field Notes From a Year of OPSEC for Liberation Movements
Daly Barnett

Throughout 2025, EFF facilitated digital privacy and security trainings for more than 2000 people. The issue spaces at hand ranged from animal rights activism, abortion access, immigration legal defense groups, and many many more. Although the particular characteristics of the various audiences differed, one thing remained true: traditional sources of information security were either inaccessible to these groups or fundamentally unable to meet their unique needs. In this talk, EFF senior staff technologist Daly Barnett will present field notes collected from the trainings conducted throughout 2025. This high-level survey will cover the types of digital privacy and security threats facing various liberation movement workers in America today, as well as the mitigation strategies they are walked through. For fellow hackers and technologists, this is not only an indispensable insight into the actual impacts of surveillance technology and digital security threats facing today’s activists, but also a blueprint for how they might be able to provide movement workers with much needed help.

Crystal Ballroom
14:00
50min
Leaking and Investigating the Epstein Files
Emma Best, Mikael Thalen, Alexander J. Urbelis, Raphael Satter, Kyrie

This unique panel brings together leading journalists who published and investigated leaked emails from the Epstein files, exposing his network of collaborators and enablers in one of the most explosive political scandals in decades. Members of the panel will discuss receiving the leaks, preserving files removed by the Department of Justice, protecting the privacy of Epstein’s victims, and the process and fallout of investigating and reporting on the explosive files.
The discussion will be joined by Kyrie, a hacker who gained access to Jeffrey Epstein’s emails and later provided a copy to Distributed Denial of Secrets).

Grand Ballroom
15:00
15:00
50min
Against Chokepoints: Optical, Audio, and Wireless Mesh as a Community Software Bus
Matt Hargett

Modern “open” software still depends on fragile chokepoints: corporate-controlled CDNs, app stores, DNS, captive portals, web application firewalls, cloud accounts, Wi-Fi, BLE identifiers, and infrastructure that can be blocked, surveilled, or simply unavailable. This talk demonstrates a tiny app runtime where people trade/propagate bite-size WebAssembly and WGSL code, audio/video/photo media, map/wiki diffs, and forum messages directly through physical presence: full-duplex QR/fountain codes, data-over-audio, and BLE mesh when user deems it safe. The point is not nostalgia for the bygone era of the Sneakernet. The goal is a practical, inspectable, community-owned software and media commons that can move through rooms, protests, disasters, schools, hackerspaces, and border cases to/from most digital devices (including smart watches) without needing permission from the Internet network operators.

Gramercy Park Suite
15:00
180min
Introduction to Malware Analysis
Sam Bowne, Elizabeth Biddlecome

Learn Windows internals and how malware operates in a fun CTF-style workshop with challenges and demonstrations at many levels, from beginner to advanced. Everyone should learn something new!

Sutton Place / Workshop A
15:00
90min
Privacy’s Defender: My 30 Year Fight Against Digital Surveillance
Cindy Cohn

In this talk that parallels her recently released book of the same title, Cindy Cohn (former executive director of the Electronic Frontier Foundation) weaves her own personal story with her role as a leading legal voice representing the rights and interests of technology users, innovators, whistleblowers, and researchers during the Crypto Wars of the 1990s, battles over NSA’s dragnet Internet spying revealed in the 2000s, and the fight against FBI gag orders. No promises, but she may be joined on stage by a key client or two.

Grand Ballroom
15:00
50min
Seeing Inside the Mind of AI: Tracing Agents, Tools, and Weird Decisions
Michael Barbine

AI is starting to feel less like software and more like a strange coworker with root access. It can read, write, reason, call tools, trigger workflows, move data, spend money, and make decisions across systems most people barely understand. We see the prompt. We see the response. But the interesting part happens in the middle, where AI-driven systems fan out through APIs, containers, queues, databases, serverless functions, model calls, SaaS platforms, and external services.

This talk is about opening up that middle. Michael Barbine will take the audience on a practical, funny, and deeply suspicious tour of what it means to instrument AI systems so we can see what they are actually doing. His approach comes from security, observability, automation, and an unusually disciplined obsession with games, rules, feedback loops, and measurable behavior. Whether debugging infrastructure, testing endpoint defenses, building agentic workflows, or playing tens of thousands of rounds of Rock Paper Scissors, the core question is the same: what happened, what changed, what pattern did we miss, and how do we prove it? Using distributed tracing, structured events, correlation IDs, audit trails, and purpose-built observability patterns, we can follow AI workflows across modern infrastructure and catch the moments where things get weird. Where did the agent hesitate? What did it call? What did it retry? What did it hallucinate? What did it spend? What data did it touch? What did it decide quietly? And why should anyone trust a system they cannot inspect?

This is a talk for hackers, builders, defenders, operators, and anyone who has ever looked at a black box and taken it personally. It connects classic hacker curiosity with one of the most urgent problems in modern computing: how to understand systems that are becoming more autonomous, persuasive, and embedded in everyday life. Attendees will leave with practical patterns for tracing AI applications, a clearer mental model for debugging agentic systems, and a renewed appreciation for the ancient hacker principle that mystery is not an acceptable interface.

Crystal Ballroom
15:30
15:30
90min
Get On the Fediverse Already
Evan Prodromou

The Fediverse is an international coalition of independent social networks that connect using the open ActivityPub protocol. In this hands-on workshop, you will learn the step-by-step process for creating an account on the Fediverse, as well as how to set up your profile, find people to follow, and make your first post.

Sutton Place / Workshop B
15:30
120min
Mesh Nets for Hackers: How (And When) to Use Meshtastic, Meshcore, and Reticulum (Day 1)
Kody Kinzie

Meshtastic is a long range, encrypted, off-grid mesh protocol that features many powerful modules, configurations, and settings. For beginners just getting started, it can be confusing to dive into these features! In this workshop, you’ ll explore the exciting modules that make Meshtastic more fun and useful. It will cover how to customize the encryption, add hardware like GPS and sensors, and change the default transmission settings to adapt to specific environments. Attendees will learn to customize their Meshtastic nodes for any situation using the built-in modules and settings. You ’ll also explore attacks against Meshtastic, and how to get involved in your local area!

Herald Square / ScriptKitty Village
16:00
16:00
50min
Flushing Tech: Three Years of Building Hyper-Local Tech Communities
William Hutson

Come learn and be inspired by how Flushing Tech brings tech communities to neighborhoods across NYC. Flushing Tech was created three years ago to bring tech enthusiasts together right in their own neighborhoods by having fun building tech, making connections, and learning new things. At HOPE_16, William talked about the start of that journey and shared a practical roadmap with actionable guidelines so anyone could build their own hyper-local tech community. Flushing Tech has evolved over the past year – becoming a 501(c)(3) nonprofit, experimenting with in-person hackathons and online activities, and taking the leap of faith into other neighborhoods. Come hear what worked, what didn’t, and what surprised them. These stories – the wins, the failures, and everything in between – will give you ideas you can steal, remix, and improve upon. The goal is simple: make it easy for anyone, anywhere, to build a thriving hyper-local tech community. Hundreds of Flushing Techs can emerge as communities built by neighbors, for neighbors.

Gramercy Park Suite
16:00
50min
Spacesuits, Mars Boots and Vegan Roots in the Desert Regolith: Field Testing the Tardigrade v.1 EMU Under Pressure in the Badlands
Scott Beibin, Elizabeth Jane Cole

The Tardigrade v.1 EMU (extravehicular mobility unit) is designed for pressurized EVAs (extravehicular activities) during space analog research missions that focus on training for Mars and lunar surface exploration. The suit system concept emerged from a collaboration between Dr. Cameron Smith (Smith Exploration Garments), Scott Beibin (Offworld Voyage), and Elizabeth Jane Cole (Offworld Voyage), with the goal of developing a pressurized EMU training suit platform intended for improved human mobility capabilities on rough terrain during EVAs. The system is designed for easy installation and testing of experimental modular telemetry and communication systems, as well as ease of donning and doffing by analog astronauts during immersive space exploration training mission simulations. The presenters will demonstrate the capabilities and features of the Tardigrade v.1 EMU space exploration training suit platform and share a report back from the first field test held in a remote desert location.

Crystal Ballroom
17:00
17:00
50min
Huge Antennas: Death Rays to Aliens
Steve Bossert

Ever wonder what purposes really large antennas are used for? This presentation will cover currently in use large and innovative antenna systems around the world – on the ground and in the sky. Steve shares what they are designed for and how they are used. Examples in areas like broadcast, astronomy, radar, and a few of the more niche or clandestine application areas will be covered – and not just related to amateur radio. There will also be coverage of how to scale these applications to something any radio hobbyist can copy, make, and use inexpensively at a smaller scale. This presentation will be light on history and high on modern use systems to enable cool wireless projects.

Gramercy Park Suite
17:00
50min
Nikola Tesla’s Time at the New Yorker Hotel
Jeffrey Velez

Nikola Tesla spent the last ten years of his life in rooms 3327 and 3328 of the New Yorker Hotel, holding annual birthday press conferences to announce wild new inventions living above the largest private power plant in the United States, and dying alone upstairs on January 7, 1943, after which the government seized his papers despite his American citizenship. This year, for the first time, HOPE convenes in that same building. This talk covers Tesla’s final decade under this roof, the hotel’s own remarkable machinery, the declassified FBI files, and the three individuals who spent their lives making sure none of it was forgotten: William Terbo, Tesla’s grandnephew and last direct-line relative; Dr. Ljubo Vujovic of the Tesla Memorial Society of New York; and Joe Kinney, the hotel’s longtime chief engineer and historian. All three individuals are sadly gone now, but this is the story of what they kept, told in the building where they kept it.

Plus there will be some long-awaited news from The Tesla Science Center at Wardenclyffe!

Crystal Ballroom
17:00
50min
Rapid Response Tech – The Role of Tech Infrastructure in the Twin Cities Anti-ICE Resistance
Eyes

Last December, Trump’s DHS unleashed “Operation Metro Surge” – a full-scale occupation of Minneapolis and St. Paul characterized by mass abductions, abuse and murder of abductees, and the high-profile executions of Renee Good and Alex Pretti at the hands of ICE agents. This operation was met with widespread, decentralized, and highly coordinated grassroots resistance via interconnected hyperlocal rapid response groups, facilitated by metro-wide digital infrastructure and data processing systems.

Networks of local organizers, hackers, and technologists built out extensive technical capacity for widespread occupation resistance, including systems for secure and coordinated rapid response communication, systems for tracking abductees through the highly opaque immigration system, and sophisticated monitoring systems for tracking ICE personnel, drones, and vehicles. This technical capacity has remained critical to the resistance against ICE operations, and organizers in other cities have become increasingly interested in similar infrastructure.

This talk will provide a comprehensive outline of these logistical, communications, and data processing systems; the ways these systems were effective, the ways they fell short, and most importantly, how hackers and technologists can better organize to build new iterations of this infrastructure within their own regions and contexts.

Grand Ballroom
17:30
17:30
120min
Learn Email Self-Defense: Hands-On GPG With GNU/Linux
Heshan de Silva-Weeramuni, Greg Farough

This is a hands-on workshop where participants learn to use GPG for email encryption, facilitated by the Free Software Foundation (FSF). Participants will help improve the FSF email self-d efense guide through real-time feedback. By the end of the workshop, you will not only be able to send encrypted email to friends and family, but also help teach others the skills of email self-defense and protecting yourself from bulk surveillance.

Sutton Place / Workshop B
18:00
18:00
50min
Hackers: Journalism Needs Your Help
Brandon Roberts

Journalism is in rough shape. Budgets, resources and staffing are shrinking. This dire situation is a bummer but also opens opportunities for hackers to take up the flag and do some great work in collaboration with journalists. This talk will explore some real world technical problems that show up in actual investigative work and explain how the hacker community can help. Bored? Let’s get to work!

Grand Ballroom
18:00
50min
Nobody Owns This: 9P CyberDecks and Community-Owned Mesh Computing
Jon Sharp

This is the story of how a homebrew cyberdeck project ran headlong into a wall of modern protocol complexity, and how the 9P protocol from Bell Labs – the heart of the Plan 9 operating system – turned out to be the answer. Jon Sharp will demonstrate 9p4z, an open-source library bringing 9P to modern microcontrollers, and show working mesh chat running over long-range radio: off-grid, community-owned communication infrastructure built from parts you probably have in a drawer. The good ideas computing discarded weren’t wrong – they just weren’t profitable enough to lock up, which is exactly what makes them ours to resurrect. This talk is a direct invitation to do it yourself.

Crystal Ballroom
18:00
50min
Poisoning the Well: How Decoys and Misdirection Protect Privacy When Opting Out Isn’t Enough
Rachel Vrabec

What do you do when data opt-outs and removal aren’t options? You make your personal data harder to find, harder to trust, and harder to act on. Drawing on real casework from advanced security clients, this talk covers open-source and vetted closed-source techniques for generating synthetic noise in personal targeting datasets, including a real case study with an honest post-mortem on what worked and what didn’t, plus a breakdown of state-level address confidentiality programs as a legal shield against non-government actors. Attendees will leave with a practical threat model and a clear framework for knowing when removal is effective, when deception is necessary, and when disruption is the only move left.

Gramercy Park Suite
18:30
18:30
210min
Binary Jiujitsu: White Belt Fundamentals
Nyt3jmp

Binary Jiujitsu: White Belt Fundamentals is the entry point of the platform’s belt progression, taking students from zero binary-exploitation experience to their first working exploit against 32-bit x86 binaries with no protections enabled. It’ s organized into four stripes that build sequentially: Binaries and Memory (ELF layout, process memory, the stack, registers, and calling conventions); Finding the Vulnerability (spotting unsafe C functions, source auditing, and disassembly with objdump/GDB); Crashing and Control Flow Hijacking (triggering crashes, using cyclic patterns to find the offset, and confirming EIP control); and Exploitation (the ret2win pattern and weaponizing control-flow hijacking into a working payload with pwntools). Every lesson is paired with a hands-on challenge binary, students write scripts and work with real tools throughout rather than absorbing theory upfront, and the whole thing runs entirely in-browser with no VM or local setup required. The workshop version is instructor-guided and closes with a Blue Belt test CTF.

Sutton Place / Workshop A
19:00
19:00
50min
How to Fight DDoS Attacks From the Command Line
Michael McMahon

Why are all of our favorite sites starting with “Just a moment…” and “Making sure you’re not a bot!” splash pages now? Since 2024, AI companies appear to be operating aggressive, vibe-coded scrapers behind residential proxy botnets, and sites have typically turned to commercial shields. Michael will share several tools and techniques that he uses as a systems administrator at the Free Software Foundation to keep the sites up on their own infrastructure. He will demo some of his own tools and the tech stack he uses regarding monitoring, firewalls, automation, analytics, ASN lookups/blocking, and geofencing.

Crystal Ballroom
19:00
50min
Inside North Korea’s Underground Tech Resistance: How Smugglers, Defectors, and Technologists Are Outmaneuvering the World’s Most Locked-Down Information System
Jon Thompson

This talk provides a layer-by-layer technical breakdown of North Korea’s civilian information-control system – covering custom Android handsets with mandatory state-signed APKs, a screenshot-based surveillance daemon called TraceViewer, steganographic file watermarking in Red Star OS, and a sealed national intranet with zero Internet access. The talk demonstrates how North Korean citizens and a network of defectors and technologists are actively circumventing it using sneakernets, smuggled phones, and purpose-built tools. The talk concludes with a structured call to action for the security community, presenting open engineering challenges in obfuscation, firmware exploitation, air-gapped deployment, embedded systems, and more that map directly to skills common among HOPE attendees, grounded throughout in tools that have been built, tested with defectors, and deployed through Liberty in North Korea’s underground network.

Grand Ballroom
19:00
50min
Using Fully Homomorphic Encryption to Build Real-World Software
Vishakh

Fully homomorphic encryption (FHE) enables computation over encrypted data, allowing third parties to process information without ever seeing it. This talk explores recent practical advances in FHE, with actionable guidance for developers building privacy-preserving applications. Along the way, there will be a discussion on the different mental models required to design systems around encrypted computation, as well as the limitations that still stand in the way of broader adoption.

Gramercy Park Suite
20:00
20:00
90min
DEZINE for Builders and Hackers
ModupeOreoluwa (Mo) Alabi

Design Thinking for Builders and Hackers is a 90-minute, hands-on workshop that uses a collaborative game to introduce design thinking through real-world technology and social challenges. Working in small teams, participants tackle problems in areas like privacy, AI, surveillance, and censorship resistance while navigating realistic constraints that force creative, human-cente red solutions. This workshop encourages rapid ideation, cross-disciplinary collaboration, and fresh perspectives on how to build technology that works in complex, resource-constrained contexts.

Sutton Place / Workshop B
20:00
50min
How Advertising Libraries in Mobile Apps Enable a Massive Location Surveillance Apparatus
William Budington, Lena Cohen

Last year at HOPE, William discussed the dangers of location data brokers tracking billions of people through mobile apps and selling their location to the highest bidder. This year, he’ll dive deeper into how and why mobile apps betray our location privacy. Advertising libraries included in a vast array of apps can transmit location data from your device sensors to surveillance tools available to the government and sold on the open market. While parts of this data pipeline remain shrouded by corporate secrecy, we can shine light on its starting point through analysis of the SDKs powering advertisements and harvesting location data in our mobile apps. You will learn the findings from looking at these components at EFF’s Threat Lab, techniques that are used to investigate apps, and conclusions about what is needed to stop mobile advertising from fueling the location surveillance industry.

Crystal Ballroom
20:00
50min
The New Cold War Has No Borders: Building the Sovereign Stack
Daniel Nowak

Nation-state actors are running intelligence operations against neo-finance protocols, sovereign AI infrastructure, and the hacker community’s communications networks. The government response follows a predictable pattern: external threat becomes justification for internal control. That cycle is unfolding now in legislation pushing toward mandatory identity verification for Internet access. Frontier AI is becoming a tiered resource, accessible to states and institutions, rationed to everyone else. The question is not whether centralized control infrastructure gets built. The question is whether alternative infrastructure can emerge and survive before it arrives. This talk examines the sovereign stack as a unified strategic response and explores how OSINT tradecraft can expose infiltration attempts before a technical compromise occurs. Both are anchored in a framework first articulated in 2012: how do you build systems that remain operational long enough to shape the next battle?

Grand Ballroom
20:00
50min
Wardialing IPv4
elixx

If you had a monkey type IP addresses into a web browser, how long would it take for them to find a web server? A WordPress blog? An admin dashboard? Your smart fridge? elixx explains how a foray into vibe coding led to computing in the Cloud, Big Data problems, and uncovering the dustiest corners of the Internet.

Gramercy Park Suite
21:00
21:00
50min
Engineering Waveflower - A Radial Oscilloscope for Visualizing Livecoding Music
Ying Chyi Gooi

This talk aims to help explore the connection between musical harmony and geometry in a simple, easy-to-use interface. The program Gooi created (Waveflower) can be extended using livecoding techniques to help us learn through experimenting with music theory, to tune a pitch, or be used as a visualization tool in audio/visual productions. Gooi believes it is time to present an equally useful alternative to Lissajous scopes.

Gramercy Park Suite
21:00
50min
More Computational Techniques for Making Karaoke Harder
Jamie Brew, Jenn Schiffer

Robot karaoke returns to HOPE! Jamie and Jenn run a live comedy show where performers sing all-new words to classic tunes, generated in real time. Their songwriting system searches an eclectic catalog for phrases that match the original rhyme and meter of each line, creating lyrics that have never been sung before and will never be sung again. Think Quora questions to the tune of “Dancing Queen” or HOPE presentation titles to the tune of “The Rainbow Connection.” This talk covers how they source the data, phonetically annotate the songs, run the show, and develop their core software: the Weird Algorithm.

Crystal Ballroom
21:00
50min
Nation-State Machinery: Inside the Persona Production Line Behind the Stryker Strike
Ashley Rose

On March 11, 2026, the medical technology giant Stryker Corporation fell victim to a “zero-binary” wipe that factory-reset over 200,000 systems across 79 countries. No custom malware was needed; Handala simply turned the victim’s own cloud management tools into a weapon. This was not a random act of hacktivism, but the output of a sophisticated nation-state “persona production line” designed for total infrastructure destruction. This session provides the definitive post-mortem of the Stryker strike, pulling back the curtain on the “Manticore” ecosystem where Iranian intelligence (MOIS) and military (IRGC) units collaborate under a deniable mask. Ashley will explore the strategic “hand-off” between espionage groups and destructive cells, and provide an exclusive unmasking of the Tabriz-based operators behind the keyboard.

Grand Ballroom
22:00
22:00
50min
Joybubbles Screening
Rachael J. Morrison

In the 1950s, a boy discovers he can control the global telephone system simply by whistling a magic tone. Born blind and hungry for connection, his early obsession with the telephone sparks a subculture that shapes the future of hacking and modern technology in the 20th century. Told through vivid archival footage and Joybubbles’ own voice recordings, the film celebrates a visionary who redefined connection and challenged assumptions about disability, identity, and imagination. Joybubbles pulses with the curiosity and wonder he brought to the world, brought to life through director Rachael J. Morrison’ s inventive, tactile storytelling. A Q&A with the director follows.

Crystal Ballroom
22:00
50min
Please Wiggle Responsibly - A Dance Extravaganza
Johannes Grenzfurthner

The crazy Austrian will provide the HOPE crowd with a healthy dose of hacked beats and mash-up monstrosities designed to, and we quote, “make us wiggle our anuses off.” Do you want to dance while constantly wondering what you’ re actually listening to? This is your chance to enjoy HOPE after hours.

Grand Ballroom
22:00
90min
True Crime: A Day in the Life of a Fraud Analyst!
Edie Ismene Nicolaou

This workshop will present a series of real world scenarios of what it’ s like to work on a fraud operations team. You will help analyze data and come up with solutions for detecting and mitigating fraudulent behaviors such as payment fraud, account creation fraud, and account takeover (ATO) across different industries. Anyone who is interested in this niche topic at the intersection of Cybersecurity and Trust and Safety is welcome to join. Laptops encouraged.

Sutton Place / Workshop B
22:30
22:30
60min
Far-Out Video Feedback With Stuff You Already Have
Sam Boling

Explore the infinite creative possibilities of video feedback using just your laptop and OBS (free video software). This workshop will scratch the surface of the groovy fractal universe of real-time video feedback. Laptop required. Caution: While participants will try to tame the vortex, playing with feedback can produce rapidly flashing lights.

Sutton Place / Workshop A
10:00
10:00
480min
Anarchist Hacker Village (Day 2)

A space for anarchists, abolitionists, anti-authoritarians, other like-minded folks, with friendly faces to meet and socialize with. Where hacking and technology are tools for total liberation. We'll have freely available swag like zines and stickers, and a place to find out about related ad-hoc events like assemblies.

Herald Square / Anarchist Hacker Village
10:00
50min
Autonomous Exploitation at Scale
Carter Pfaff

With the advent of powerful, open-source, and lightweight large language models, the cost barriers that typically prevent targeted attacks – with people manually scanning, infecting, and exploiting – are vastly reduced. This talk presents a self-propagating worm which autonomously detects devices, enumerates their vulnerabilities and services, checks for exploits which could work on them, and exploits them and spreads to them, forming a distributed network. It discusses the limitations, design decisions, and tradeoffs made in the development.

Gramercy Park Suite
10:00
240min
Get Your Amateur (Ham) Radio License in a Single Weekend (Part 2 of 2 parts)
Dan Romanchik

This workshop will teach attendees what they need to know to pass the Technician Class amateur radio license exam and get started in amateur radio. It includes six hours of instruction, with the exam administered immediately after the workshop. It is sometimes said that radio amateurs were the original hackers, cobbling together transmitters and receivers from odds, ends, and discarded electronics. Radio amateurs continue this tradition today, and in addition to building their own gear, they’re hacking on digital communications systems, including both hardware and software. Amateur radio is a great hobby for electronics enthusiasts and, increasingly, for hardware and software hackers. Participants will increase their chances of passing the test if they download the study guide from www.kb6nu.com/study-guides/ and familiarize themselves with the material before coming to the workshop. The text for this workshop is Dan’s No Nonsense Technician Class License Study Guide. The PDF version of the study guide is available for free at the above page. EPUB and print versions are also available for a small charge. This is part 2 of 2 parts. To pass your exam, please participate in both parts.

Kips Bay
10:00
480min
Hackerspace Village (Day2)

Come check out the local NYC hackerspaces at the Hackerspace Village. It is organized by
some of New York City’s local hackerspaces. You are invited to join them for lots of cool
activities throughout HOPE 26. They are all nonprofit and 100 percent volunteer-run and would
love to have you visit on their open nights!

Herald Square / Hackerspace Village
10:00
480min
Ham Radio Village (Day 2)

Our mission is to deliver high-quality and innovate amateur radio related educational content,
hands-on experiences, and license testing sessions online and in-person through events. We
believe that the more people know about amateur radio, the more safe, secure, functional, and
innovative our wireless products, services, and experiments will be. Our team of dedicated
volunteers is responsible for generating all new research, giving talks and demonstrations at
events, building and testing experiments, as well as offering support to the general ham radio
community. There will be ham radio demonstrations throughout HOPE 26.

Herald Square / Ham Radio Village
10:00
480min
Lockpick Village With Lockpick Extreme (Day 2)
Bob Hermes, Christine Bachman, Daniel Finegold

Locks are puzzles you can solve without the key! Explore the fun world of locksport with Lockpick Extreme. Learn to lockpick from friendly instructors or practice what you already know with their assortment of locks and picks. When you’re done, you can shop at the pop-up shop and take your new hobby home with you.

Herald Square / Lockpick Village
10:00
90min
Make Your Very Own IoT Cat Lamp With WLED (Day 2)
Michael Raymond

Want to create a beautiful, squishy, and cute Wi-Fi controllable cat lamp? In this workshop, you ’ll put together a “Purrsheen” cat-shaped Wi-Fi lamp that allows you to control your adorable cat baby via Wi-Fi or Home Assistant with WLED! This workshop will involve beginner-level soldering and assembly skills. Great for cat lovers and those looking to get into DIY IoT projects.

Herald Square / ScriptKitty Village
10:00
480min
Paper Popups (Day 2)

Explore the world of pop-ups! How can something 2D become 3D? Learn both the math and magic behind these folding paper sculptures. Take a break and build out a HOPE pop-up book. Participants will be empowered to set off into the exciting world of paper engineering. Stop by any time throughout HOPE 26.

Herald Square / Paper Popup Village
10:00
50min
Source Protection and Digital Security Techniques Under Surveillance
Smitha Khorana

Surveillance has become so ubiquitous that no one knows how to protect oneself from it. This talk is about how to shield journalists, activists, and sources from surveillance, and ways to think about the threat. Smitha is a journalist who has reported in the Yemeni American community about passport revocations before Trump. She will talk about methods she used to approach sources in vulnerable communities and make them feel safe. She will discuss how to “threat-model,” new approaches to educate sources and help sources give information, and the laws that make it difficult for whistleblowers and sources.

The second part of the talk discusses public education campaigns for sources to pass information on safely to newsrooms and journalists, as well as data protection laws and ways to protect data from surveillance in communications between journalists and sources. It will cover ways to bolster a global movement against surveillance and data retention by multinational corporations to enhance privacy and to protect the act of journalism globally. The Espionage Act will be examined and examples of sources and whistleblowers being prosecuted will be discussed.

Crystal Ballroom
11:00
11:00
60min
Resist Internet Censorship by Running Your Site Over the Radio
Dan Tennery-Spalding

We all know not to trust government, big tech, or ISPs. So how do we host our sites? With radio! In this dynamic presentation, you will witness how digital radio makes it possible to run a site with virtually no infra besides the electromagnetic spectrum. No radio experience is expected; total radio novices are encouraged to attend.

Sutton Place / Workshop A
11:00
60min
Soldering 101
Bianca "BiaSciLab" Lewis

Soldering is a hardware skill that all hackers should learn in order to bring their digital projects into the physical world. From modifying badge hardware at conferences to building custom projects, modifying your devices, and repairing your own gear, soldering transforms you from someone who just uses technology into someone who can physically reshape it. This workshop will guide you through building your own light-up badge, complete with the essential components you ’ll encounter throughout your soldering journey. You will learn the different tools, parts, and techniques you’ll need to confidently face the world of hardware.

Sutton Place / Workshop B
11:00
50min
Speculative Solidarities: Sanctuary Cell Division – A Call to Action
Jorge Luis, Rev. Eon, Camille Acey, Rev. Elæ Moss Benedetto

This panel discussion brings together organizers, technologists, faith practitioners, and care workers to examine how sanctuary systems are being stress-tested in real time. As surveillance expands and mutual aid networks face increasing legal risk, the people doing the most critical protective work are operating through fragile, improvised systems. Meanwhile, those who need refuge – undocumented neighbors, trans youth, abortion seekers, journalists, organizers – continue to show up at the doors of churches, hackerspaces, clinics, and encrypted channels asking the same question: will you hide me, will you teach me, will you stand? The discussion begins from the premise that faith infrastructure, technical infrastructure, and care infrastructure must learn to operate together. The conversation focuses on concrete tensions: operational security in community settings, coordinating without increasing surveillance exposure, managing resource flows without creating legal liability, and sustaining the physical and nervous systems of the people doing the work. The format emphasizes exchange, disagreement, and synthesis across domains.

Crystal Ballroom
11:00
50min
The Deceptive Web of Scam Compounds
Laura Sang Hee Scherling EdD

This presentation examines the rise of scam compounds and the rapidly evolving characteristics of these industrial-scale fraudulent operations. A recent report by the United Nations Office on Drugs and Crime (UNODC) found that cyber-enabled fraud has intensified, resulting in billions of dollars in losses, with many of these malicious networks orchestrated by criminal syndicates in Southeast Asia. The UN estimates that hundreds of thousands of individuals have been trafficked and forced to labor in these illicit facilities. Crucially, as these syndicates integrate increasingly sophisticated technologies, they have also become highly mobile, routinely relocating entire compounds upon completing a “lifecycle of operations.” Dr. Scherling’s presentation draws from her extensive interviews with non-governmental organizations (NGOs), government agencies, investigative journalists, and compound survivors.

Gramercy Park Suite
11:00
50min
The Onion Shell: Zero-Install Tor From the Browser
Erica Windisch

What if anyone in the world could connect to the Tor network and benefit from its privacy protections with nothing more than a standard web browser? Volunteers globally operate a free onion network that protects Internet privacy. It prevents tracking, surveillance, and censorship. However, accessing the onion network has always required special software running as a privileged user. Often, users even install virtual machines or operate dedicated machines to isolate their applications connecting to Tor.

Not all threat models are equal. Some users do not have the privileges and access to their machines necessary to connect to Tor. This is increasingly important in a world where governments are mandating OS-level PII capture and reporting. Walled garden operating systems such as iOS and Android are increasingly tightening a user’s freedom to install software such as Tor.

Finally, the Tor onion network can be made available to more users on more devices through advancements in web technologies. Using The Onion Shell, users can now connect to the Tor onion network from their browser with real browser-initiated onion circuits. This talk will include demos, a discussion of the effort, and new risks this technology introduces, such as enhanced exfiltration techniques.

Grand Ballroom
11:45
11:45
120min
Wi-Fi Self Defense and Hacker Hunting for Beginners (Day 2)
Kody Kinzie

This workshop offers hands-on instruction using a unique, cat-shaped Wi-Fi hacking microcontroller, the Wi-Fi Nugget. Designed to engage participants in practical learning, it covers essential skills for defending against four common yet powerful Wi-Fi attacks. Students will explore topics including detecting Wi-Fi leaks, the risks of QR codes leading to hidden networks, spotting phishing networks, and defending against advanced Wi-Fi karma attacks. The Wi-Fi Nugget is a powerful tool for understanding and fighting back against Wi-Fi hacking. This class is suitable for Wi-Fi hacking experts and those just getting started.

Herald Square / ScriptKitty Village
12:00
12:00
110min
Ask EFF, 2026 Edition
Daly Barnett, William Budington, Lena Cohen, Cara Gagliano, Rory Mir

In 2026, a confluence of corporate and government forces work together to deploy new and frightening surveillance technologies to monitor and restrict the rights of ordinary people. As tools made available to law enforcement and ICE track the movements of our devices, FLOCK cameras gather an endless stream of information from the automobiles indispensable to most Americans. But 2026 is also the year that the users started to fight to “Take Back CTRL,” and the Electronic Frontier Foundation (EFF) has been with them every step of the way. From suing cities which deploy automated license plate readers, to raising awareness around the practices of data brokers, to developing technologies that enable users to avoid trackers, EFF combines legal, activist, and technological strategies to help in the fight. They’re back at HOPE this year with staff members across the organization to answer your questions and help you more effectively engage in the struggle for digital rights. In this troubling time, they will discuss some of the new opportunities they see to empower ourselves against the forces of technological oppression.

Grand Ballroom
12:00
50min
The Server Knows Nothing: Designing Emergency Apps With Nothing to Subpoena
Jason Long

ReadyNow! is an emergency response app designed to help immigrant communities in the United States in the event of ICE/CBP detention. In a crisis moment, the app can notify trusted contacts and help trigger a pre-planned response. But building an emergency tool for vulnerable communities comes with a paradox: the very act of using the app can expose not just the user, but their loved ones, their community, and their broader contact network. Jason will explain how the app set out to ensure that it would never become an “arrest bingo card” – a system that quietly maps relationships and risk. This talk is a case study in designing “security-first” systems where the adversary isn’t hypothetical, and where metadata and contact graphs are as sensitive as message content. The central technical and product challenge will be explored: how do you send messages on someone’s behalf without the organization ever knowing the message or the recipients? The talk will go through the design constraints that led developers to keep data encrypted and local to the device, and to deliberately build a system with minimal server-side visibility. Finally, a problem that’s often ignored in security engineering will be covered: opaque security doesn’t make users feel secure. For people facing real-world threats, trust requires clarity. The tradeoffs between safety, functionality, and observability will be discussed, and practical lessons for building high-risk apps that are secure by design – and legible enough for users to believe – will be shared.

Gramercy Park Suite
12:00
50min
To Kill the Telephone System’s Ghost
Phillip Hallam-Baker

The telephone system hasn’t existed for decades, but its ghost lives on. We still use telephone numbers, but the Strowger exchanges built with 1890s technology of relays went long ago and so have most of the systems built to replace them. What we are left with is a system that is no longer fit for purpose. As with SMTP email, the utility of the system has been lost to abuse (spam) long ago. It is time to replace it with something better. Replacing the telephone system appears to be a hopeless task, but what if we could replace all the forms of person-to-person network communication with a single infrastructure that has security built in?

Crystal Ballroom
12:30
12:30
60min
Lockpicking 101: A Puzzle in the Dark
Bianca "BiaSciLab" Lewis

Lockpicking is a crucial skill for both cybersecurity professionals and hobbyist hackers. Like solving a puzzle in the dark, lockpicking challenges you to utilize subtle feedback from touch, sound, and spatial memory in order to open a lock. Whether you’ re performing a physical security test or exploring the mechanics of locks, it’s a powerful tool to have in your arsenal. It’s also a social hobby perfect for meeting new people at conferences or local locksport groups. This workshop gives you a solid foundation in how locks work, the tools involved, and the technique to pop your very first lock. Afterward, you’ ll get plenty of hands-on time to test your skills against a variety of different lock types. Are you ready to unlock this new skill?

Sutton Place / Workshop A
12:30
120min
Sensing the Hidden World of EMF
Darcy Neal

Join this workshop for a hands-on event where you’ ll create a device that gives you the power to hear the invisible fields that surround our everyday lives. Learn about how electromagnetic frequencies shape our world, where they come from, and how you can make your own in KiCad. This workshop involves soldering, interactive sonic exploration, and circuit design overview. It’ s geared to be accessible to absolute beginners, and serves as a great way to dive into the world of handbuilt electronics.

Sutton Place / Workshop B
13:00
13:00
50min
Can It Ham? Hackers, Hams, and the Signal Between Them
Terry "shoot3r" Schanno, Andrew "livitup" Ohnstad

Hackers and amateur radio operators have more in common than either group tends to admit. One speaker came up through 1990s hacker culture – attending 2600 meetings and contributing to 2600: The Hacker Quarterly long before becoming a licensed amateur radio operator. The other has spent decades in amateur radio, only to discover through DEF CON that the hacker mindset had been there all along. Through the story of the “Can It Ham?” contest – where participants build working antennas from unconventional materials – this talk explores how RF experimentation, system-level curiosity, and hands-on exploration form a shared foundation between hackers and hams. This is a story about rediscovery, perception, and what happens when you remove labels and just start building.

Gramercy Park Suite
13:00
50min
Remembering Hackers 31 Years Later
Renoly Santiago, Emmanuel Goldstein

The iconic mainstream movie about the hacker culture in New York City has endured over the years better than most would have expected. People still quote various lines on a regular basis, the story was less farfetched than most other hacker tales of the time, and the soundtrack remains a favorite to many. Phantom Phreak (played by Renoly Santiago) was one of the fan favorites. Renoly will describe what it was like to be a part of this project and how this role helped to shape his career. Emmanuel Goldstein will recollect the writing process of Rafael Moreu, what it was like to interact with the stars of the film, and how various decisions shaped the finished product.

Renoly will be available for autographs and pictures after the panel.

Crystal Ballroom
14:00
14:00
50min
A Practical Guide to Facial Recognition Evasion
Prowex, Rambo Anderson-You

Sick of being recognized everywhere? Us too! This talk covers physical disguise and facial recognition evasion techniques, both in the visible light and IR spectra. Prowex will talk and demo you through methods to use, and Rambo will introduce you to a tool he open-sourced (nullface.me) that helps you check whether your facial disguise is working.

Crystal Ballroom
14:00
50min
Cybersecurity for Space Systems: Integrating Offensive Methods, Defending System Vulnerabilities, and Space Law
Tiffany Strauchs Rad

As space systems become increasingly integrated with U.S. critical infrastructure, cybersecurity must evolve beyond defensive approaches to include offensive techniques that expose and counter adversary capabilities. Critical services such as GPS remain vulnerable to jamming and spoofing as a result of electronic warfare, while command centers and user terminals face risks from network exploitation, malware, and credential compromise. In addition, unencrypted data links within some GEO communications systems enable interception and hijacking, and supply chain compromises introduce further threats to mission assurance and system integrity. Addressing these challenges requires cybersecurity education and training that is adversary-informed. Cybersecurity engineers must also understand the legal and policy frameworks governing behavior in space, including the Outer Space Treaty, Artemis Accords, and the Moon Treaty. This presentation highlights experiential learning initiatives such as the Cyber Drone Challenge and Cyber Space Challenge demonstrating a multidisciplinary model for educating and preparing the next generation of cybersecurity professionals to secure the evolving space domain.

Grand Ballroom
14:00
90min
Grokking the Agentic Loop: From Chatbots to Autonomous Agents
Kwame Wright, Jarone Wright

Many people interact with large language models (LLMs) through simple, linear chat interfaces. However, AI unlocks its true potential when these models are placed inside an agentic loop - a cycle of reasoning, acting, and observing. In this hands-on workshop, you will demystify AI agents by building a basic agentic loop from scratch using Python and the Gemini API. Participants will learn how to move beyond static prompts to create systems that can use tools, evaluate their own outputs, and iterate toward a goal. This workshop is designed to turn the magic of AI agents into a clear, hackable process.

Sutton Place / Workshop A
14:00
90min
Learn BadUSB Hacking With the USB Nugget
Michael Raymond

In this workshop you’ll learn to write bad USB scripts to automate computer hacking using a cute, cat-themed hacking tool called the USB Nugget. You’ ll learn to write scripts to get computers of any operating system to do your bidding in seconds, and how to automate nearly any desired action remotely through its Wi-Fi interface. If you’ re looking for an introduction to USB hacking or simple scripting, but a little more spicy, this workshop is for you!

Herald Square / ScriptKitty Village
14:00
50min
Riding the Pipe: Hack Wi-Fi and Meshtastic via Browser With Cheap Microcontrollers
Kody Kinzie

With the support of Web Serial on Firefox, modern browsers now almost universally support the ability to flash firmware to cheap microcontrollers and control them directly. This allows microcontrollers to be used as browser-controlled radio pipes to send and receive signals in ways very useful to hackers. Kody will go over examples of hacking Wi-Fi and Meshtastic with bleeding edge techniques, and even creating beautiful visualizations of the invisible wireless world, all using a browser and low-cost microcontrollers.

Gramercy Park Suite
15:00
15:00
50min
Government Transparency in a Time of Shadows
Kel McClanahan Esq.

The Trump administration claims to be the most transparent administration in history, and yet every facet of it is custom-designed to be as opaque as possible. Freedom of Information Act offices are shuttered, whistleblowers are muzzled, agencies are run on Signal, everything is overclassified, and DOGE is allowed to spread across the executive branch like a plague with no accountability or oversight. And when the law gets in the administration’s way, they have the DOJ decide that it doesn’t really stop them.

But it’s not all doom and gloom. There are still systems in place that you can use if you know how, but it’s much harder every day. This talk will describe the way things are supposed to be, the way they are, and how you can still bring some sunshine to the black box the administration is trying to create.

Crystal Ballroom
15:00
90min
Re-imagining Digital Security Training
Izebel

Too many digital security trainings fail to create lasting change, not because the content lacks value, but because of how they’ re delivered. This participatory session re-imagines digital security education for community groups and activists by drawing on collective practitioner knowledge, critical pedagogy, neuroscience research on learning and retention, and cross-disciplinary teaching experience. This workshop will examine why participants often leave trainings overwhelmed, disconnected, or unable to apply what they’ ve learned, and explore alternative approaches that reduce cognitive overload, foster connection to content, and encourage critical thinking rather than compliance. Attendees will contribute to a shared analysis of what’s broken in current training models and leave with practical frameworks for designing more effective, engaging, and empowering security trainings. Trainers and facilitators of all experience levels are welcome.

Sutton Place / Workshop B
15:00
50min
Stop “Thinking Of” the Children. Start Listening to Them.
Evan Greer

Authoritarian governments around the world are exploiting legitimate fears about the harms of Big Tech and surveillance capitalism to ram through policies that expand censorship and build surveillance into every device we own and every piece of software we use. “Child protection” is the frame being used to manufacture consent for these draconian policies. And there are good faith actors being duped into supporting authoritarian policies who genuinely want to address harm and protect kids. Activists have been effective in holding back the worst policies in many places, and technologists continue to build privacy-preserving tools that help vulnerable people protect themselves. But in the end, dangerous censorship and surveillance laws will keep coming back until we change hearts and minds and move the dominant narrative from “protecting” kids to listening to and empowering them. Young people have been at the forefront of every social movement throughout history that has led to positive social change. But that never seems to be part of conversations about the rights and safety of young people online. Come hear from Evan Greer, director of Fight for the Future, about how we can build a movement of young people, parents, educators, and human rights advocates to defang the “think of the children” narrative and build a future where young people have safety and rights.

Grand Ballroom
15:00
50min
The Enshittified Internet and How We Can All Rewild the Internet!
LambdaCalculus

The Internet was once a place where people could talk, share ideas and knowledge, express themselves with personal websites, build communities, and more. In recent years, however, we have seen that magic fade away, as the Internet of today is now a toxic cesspool of social media controlled by Big Tech, ads thrown everywhere, walled gardens, AI-generated slop, and content that locks us in by making us angry and depressed. This is not the Internet we need or should leave to the next generation of hackers! There are ways to take back and rewild the web! This talk is part informative, part educational, part historical, and pure hacker punk energy as the presenter explores how to do things like self-host your own servers; use tools to build new networks; operate decentralized services for communication, media sharing, and more; find old protocols and services old timers used to use that still exist (and helping the kids to use them, too!); and locate places and sites we can go to for the education and information we want! In all, this talk is about hacking the planet and taking our Internet… the people’s Internet… back from corporate corruption and control!

Gramercy Park Suite
16:00
16:00
50min
How to De-Google Your Org: Practical Advice From People Who’ve Done It
Meredith Laverty, Jibran Ludwig, Sarah E. Philips

Are you ready to get your organization off Big Tech? Last year, Fight for the Future did just that. They ditched Google Workspace and migrated their email, calendars, docs, and other core infrastructure to privacy-friendly, open-source alternatives. The panelists will talk about why they made the move, how they built organizational buy-in, and what they learned along the way. If all goes according to plan, attendees will leave with greater confidence in their ability to move themselves and their organizations away from Big Tech, along with clear next steps for getting started.

Grand Ballroom
16:00
90min
Plicykling - Make the World a Better Place
Craig Topham

Plicykling is the art of picking up litter while riding a bicycle without stopping or slowing down. Learn how to get started and get out there to make the world a better place while you get somewhere by bicycle! Plicykling is a hack! In what can only be described as an industrial strength weaponized fake corporate culture of control with an absolute emphasis on selfishness, plicykling is also effectively a random act of kindness machine, and if the deed is witnessed, it pokes holes in these bubbles we all seem to have encased ourselves in. It helps our inner lights shines a little brighter, which is something we all need right now.

Sutton Place / Workshop A
16:00
50min
Tell Stories, Save the World: How Hackers Are Basically Shakespeare
Kestral Gaian

This talk explores the hidden power of narrative in art, technology, and hacker culture. Drawing on everything from representation and role models to UX and science fiction, Kestral Gaian argues that anyone building any technology is already basically Shakespeare.

Gramercy Park Suite
16:00
50min
The Art and Science of Metawar
Winn Schwartau

One of the original speakers from the first HOPE conference in 1994 is back with a new book that examines how humans must strengthen our cognitive defenses against AI-driven reality distortion, TMI/disinformation, manipulation, and algorithmic addictions. This talk will discuss the intersection of cybersecurity and cognitive security. The vast similarities between silicon and carbon systems offer cognitive defenders an existing framework for strengthening our mental immunity systems against information pathogens at the national, enterprise, and personal levels. You will see how the security, privacy, ethics, and global policy implications are staggering.

Crystal Ballroom
17:00
17:00
120min
Exploring Security in the Bio-Digital Stack
Xavier Palmer

This workshop introduces participants to biocybersecurity, also known as cyberbiosecurity, and examines how biological knowledge and techniques can be adapted or repurposed within cyber and cyber-physical systems. Following an introduction, participants will work through facilitated case studies to identify potential risks, consequences, and design considerations at the intersection of biology and cybersecurity. The session intends to help participants develop an intuitive understanding of this emerging field through discussion and analysis. No advanced background in biology or cybersecurity is required; only curiosity and a willingness to ask questions are needed.

Sutton Place / Workshop B
17:00
50min
Ham Radio Isn’t Magic: Preppers, Sad Hams, and Practical Off-Grid Communications
Andrew "livitup" Ohnstad

Every hacker has seen the post: someone asks what radio will let them “reliably talk 500 miles to family when the cell network goes down.” The replies quickly devolve into bad advice, magical thinking, and dismissive gatekeeping. The result is confusion, wasted money, and false confidence about off-grid communications. This talk is the antidote. It will cut through the mythology and explain what amateur radio can actually do for personal and family communication during major disruptions – and what it cannot. Starting at a 101 level, it will cover realistic ranges, basic propagation, equipment tradeoffs, digital modes, licensing myths, and why distance is usually the wrong requirement. Rather than dunking on preppers or policing fun like a sad ham, this talk reframes the problem the way hackers do: understanding constraints, failure modes, and human factors. It will focus on practical off-grid communication strategies that work in the real world – coordination, redundancy, and low-bandwidth messaging – not fantasy continent-spanning voice links.

Crystal Ballroom
17:00
110min
What’s Your Age Again? The Future of Online Age Assurance
Cindy Cohn, Denise G. Tayloe

As governments around the world introduce new laws intended to create safer and more age-appropriate digital experiences for children and teens, age assurance has become one of the most debated topics in technology policy. Supporters view it as an important tool for protecting young people online and enabling age-appropriate experiences, while critics raise important questions about privacy, civil liberties, free expression, implementation, and unintended consequences.

This conversation brings together two respected voices to explore the complex technical, legal, ethical, and societal questions surrounding age assurance from the perspectives of privacy advocacy, policy, and real-world implementation. Rather than debating simple “for” or “against” positions, the discussion will examine how organizations, policymakers, technologists, parents, and privacy advocates can balance child safety, privacy, parental involvement, regulatory compliance, and individual rights in an increasingly digital world.

Featuring Cindy Cohn, former executive director of the Electronic Frontier Foundation, and Denise G. Tayloe, co-founder and CEO of PRIVO, this session will offer a thoughtful exploration of one of today’s most challenging technology policy issues – moving beyond headlines to discuss what effective, privacy-preserving age assurance could look like in practice.

Grand Ballroom
17:00
50min
Zines Against the Machine: Analog Communication for a Digital Dystopia
Jack Gangi

Zines have long been part of the hacker culture’s communication infrastructure: low tech, hard to censor, and nearly impossible to deplatform. In a time where communication channels face growing control and restriction, zines remain one of the most resilient tools we have. This talk explores why zines still matter, from their roots in underground publishing and organizing to why you should be making one today and how to get started.

Gramercy Park Suite
18:00
18:00
180min
Build and Secure AI Systems
Sam Bowne, Elizabeth Biddlecome

Build AI systems for vision, language processing, and agents; then attack and defend them. This is a fun CTF-style workshop with challenges and demonstrations at many levels, from beginner to advanced. Everyone should learn something new!

Sutton Place / Workshop A
18:00
50min
Hacking the Layers, Hackers, Open Source and the 3D Printing World – And Why You Should Care About It
Jim Griffin

3D printing is fundamentally changing our relationship with the physical world, empowering individuals to democratize manufacturing, reclaim the right to repair, and achieve true personal autonomy while also facing challenges from corporate and regulatory forces trying to restrict that freedom using the same age-old adage of limiting adult freedom to protect the children. This talk traces the direct lineage of this modern struggle back to its roots: the Chaos Computer Club and the early tech hacking pioneers. Attendees will learn how the early open-source software movement laid the groundwork for the hardware revolution, and how a dedicated global community ultimately used 3D printing to bypass overly regressive patent systems.

Gramercy Park Suite
18:00
50min
You Are John Connor... The Rise of Lethal Autonomous Weapon Systems
Peter Haas

In the Cold War, the only thing that stopped the world from ending was a single person. In 1983, Stanislav Petrov stared at a screen insisting that American missiles were inbound and decided not to believe it - a single human refusal lodged in an automated kill chain, and the sole reason there was a tomorrow. This talk is about what happens when we engineer that person out of the loop. Lethal autonomy is descending not just from a Pentagon budget; it ’s arriving on your feed. Open-source targeting code, a microcontroller, a webcam, and a printed lower receiver now put a computer-vision sniper station within reach of a teenager looking for the likes. We have watched this film before: Fritz Haber pulled nitrogen from the air to feed billions and won a Nobel Prize, then personally directed the first chlorine gas use - one mind, one chemistry, feeding and killing, and once that knowledge was loose, it never went back in the bottle. The chemicals to make chlorine gas likely sit under your sink, but our norms prevent us from using it. Autonomous lethality is now tracing the exact democratization curve of chemical weapons, except the barrier to entry is a GitHub repo and under $200 in parts, and by the time the opposition to it develops it may be too late. The battlefield future is already the present: according to Reuters a drone “kill zone” now reaches some 15 kilometers each side behind the front in Ukraine. A strip where nothing human can move without attack. That strip of death is coming globally in the next decade in robotic assisted genocide situations to population centers worldwide. The title isn’ t a joke. In a world racing to delete the human who can say no, the people in this room - the ones who actually build these systems - are the last Petrov. You are John Connor. The question this talk asks is how you can act like it.

Crystal Ballroom
19:00
19:00
50min
How to Be a Whistleblower
Emma Best, John Williams, Jeremy Hammond

The world has never needed whistleblowers more, and technology has made it both easier and more dangerous to be a whistleblower. The panelists (all whistleblowers themselves) discuss what it takes to be a successful whistleblower, from knowing when and how to speak up to dealing with the psychological impacts of blowing the whistle. Other topics include common mistakes and misconceptions, as well as how to stay safe and dealing with the potential fallout, including trial or prison.

Grand Ballroom
19:00
50min
It’s 10 PM. Do You Know What Your AI Agents Are Doing?
Alexander Rodriguez

AI coding agents like Claude Code now have shell access, file system access, and connections to external services through MCP servers – and most security teams have zero visibility into what they’re actually doing on developer machines. Alexander Rodriguez walks through building a three-layer open-source defense stack from scratch: an OpenTelemetry pipeline that captures every command, file access, MCP server connection, and permission decision; Meta’s LlamaFirewall wired into pre-execution hooks to block prompt injection and goal hijacking before actions run; and a lightweight EDR-style detection agent that watches AI agent behavior the way other tools watch process behavior by signature matching for credential file reads and exfil chains, behavioral baselining for anomalies, and real-time blocking. The talk also covers what’s still broken, such as no visibility into model reasoning, MCP servers that can change behavior after vetting, and prompt injection detection limited to pattern matching. Full stack on GitHub, demo included.

Gramercy Park Suite
19:00
50min
Not Your Boy Genius: Feminist and Queer Hackers in Film and Pop Culture
Jasmin Hagendorfer

From cyberpunk fantasies to contemporary screen culture, hackers are often imagined as brilliant, antisocial, male-coded figures in hoodies, basements, and command lines. But what happens when the hacker is female, queer, trans, femme, monstrous, seductive, collective, or politically disobedient?

This talk explores the representation of female, female-read, and queer hacker figures in film, fiction, and pop culture. Taking cinema as its main entry point, it will look at how women and queer characters have been portrayed as coders, engineers, system-breakers, information smugglers, digital witches, cyberpunks, whistleblowers, and technological tricksters. The talk will move through iconic and lesser-known examples – from mainstream hacker films and cyberpunk narratives to queer, feminist, and speculative media and ask what these figures reveal about power, gender, surveillance, desire, and technological agency.

Crystal Ballroom
19:30
19:30
90min
Evaluating a Program’s Free Software Licensing
Craig Topham

Being able to take a random program from the Internet and be confident whether it is free software or not, solely based on the available documentation within the program’ s source code, is a useful skill. (This is not legal advice and Craig is not a lawyer.) This workshop involves walking the participants through the evaluation process of a computer program’ s licensing in order to determine if it is eligible for entry in the Free Software Foundation’s Free Software Directory.

Sutton Place / Workshop B
20:00
20:00
50min
No Laptop or Wi-Fi? No Problem: Democratizing Coding for the Mobile-Only World
David Schachter, Hal Eisen, Elissa Miller

For too long, access to programming resources has been limited by access to infrastructure. Nonprofit App Dev for All is challenging tech’s pay-to-play nature with Code on the Go, a powerful, free and open-source IDE that turns a budget Android smartphone into a professional workstation, even in regions without reliable Internet access. The presenters will demonstrate that even the most resource-constrained coders can build, compile, debug, and deploy full Android apps entirely offline on almost any Android phone.

Grand Ballroom
20:00
50min
Studying the Quotidian Web
Ryan McGrady

There are about 20 billion videos on YouTube, with a median view count of just 41. 800 million have never been seen by even one person. For all the press and politics about Internet platforms, basic statistics like these are hard to come by. We typically don’t know how large platforms are, what languages their content is in, and what regular people use them for because – especially in the “post-API age” – most of what we do know is filtered through opaque, attention-optimized recommendation systems. But it’s a project worth doing, not just for the sake of transparency and auditing, but because they are also rich, global repositories of everyday life and culture that are deprioritized in favor of MrBeast.

This presentation will explain the research program that has been built at the University of Massachusetts Amherst dedicated to the production and study of representative samples of social video sites. More important than what’s already been done is what’s still left to do. The purpose of this talk is to get people excited about solving the technical challenges associated with random sampling. YouTube and TikTok have been figured out, but, absent meaningful legislation to mandate platform transparency in the public interest, there are big open questions about most sites, especially smaller platforms and those that are less popular here in the U.S.

Crystal Ballroom
20:00
50min
Take This Job and Pwn It
`Lex Pendragon

Lex is a one-person managed services provider – the outsourced IT department. This presentation is the answer to all the questions thatLex-from-20-years-ago would have had. This talk will tell why he went into business for himself and include day-to-day operations, how he got clients, how he figured out how much to charge, and the actual methods used, including each of the tools (remote management software, help desk software, etc.) and costs.

Gramercy Park Suite
21:00
21:00
50min
Does Self-Sovereign Identity Imply Decentralized Identity?
Wes Kussmaul

This presentation will demonstrate that human accountability via x.509 digital identity certificates is at the core of any real solution to phishing, software supply chain contamination, botnets, AI-agent driven fraud, breaches, etc. Identity certificates imply a certification authority, which raises legitimate concerns in the decentralized identity community. However, if any of us is to trust the identity claims of another person, we must both agree on an authority ’s attestation that the identity claims are valid. And so, the point is not to dispense with authority, but to do it right. That calls for a “license plate” identity which, like your car’s license plate, makes you accountable on the public (information) highway, but which does not disclose your identity; a protocol that makes it impossible to directly discern identity from “license plate” information; an identity certification authority database with no identity information in it, so that if a dictator demands at gunpoint the identity of the person who’s been critical of his regime, no sysadmin or d atabase administrator has any way of providing that information; a certification authority using “optimocracy governance,” where any certificate holder may participate in its governance; a recourse system by which an injured party (fraud, defamation, other injury) obtains a court order deemed legitimate by the member’ s attestation officer and may cause the disclosure of an identity if they and the management of the council of attestation officers deems the court order to represent a valid reason for disclosure of identity.

Grand Ballroom
21:00
50min
Feeling the Signal: Hacking Music Into Touch
Yi Wang

This talk explores how music can be experienced beyond hearing through touch, movement, and atmosphere. Inspired by the speaker’s personal experience as a hard-of-hearing music listener who loves going to music events, the project investigates how technology can create alternative sensory pathways for perceiving rhythm, emotion, and musical structure. Drawing from interviews, body-mapping experiments, and iterative prototyping, the talk presents a real-time system that translates musical features into tactile and visual experiences through haptic wearables, pneumatic interfaces, and generative visuals. Audience members will also have the opportunity to experience the prototypes firsthand, including a tactile composition created for “UV” by Vril, demonstrating how music can be felt through the body as rhythm, emotion, and shared physical presence. In addition to presenting prototypes, the talk explores how accessibility technology can function as a form of sensory enhancement and creative expression.

Crystal Ballroom
21:00
50min
What It’s Like in a Worker-Owned Creative Technology Cooperative
Gwendolyn Pasquarello

The Emma Technology Co-op is a five-year-old worker-owned and democratically run creative technology consultancy. They do software consulting in the new media and interactive technology industries. In this talk, you will hear why they chose to start a co-op specifically and how they felt that it could provide a fairer and more stable career path than either a traditional “tech job” or continuing their individual freelancing practices. With that established, the talk will go on to cover how they built our business to address their needs and reflect their politics and sensibilities. If you’ve ever wondered what a day job without bosses or shareholders could look like, this talk can show you their vision for that.

Gramercy Park Suite
21:30
21:30
120min
Breaking Walled Gardens: An iOS Jailbreaking Workshop
Sam Heckle

Dedicate some time to try hacking existing devices to extend their longevity and limit our own production of e-waste. This is a workshop to jailbreak old Apple devices for reusability in modern livelihoods. Non iOS devices are also possible to explore. Each participant will be requested to bring an old i-device (ideally with the original charger) to go through the process of “jailbreaking.” If participants do not have old Apple devices, they are welcome to bring other specific hardware and use the workshop time to experiment with modifications and tooling to get them up and running again (think old phones, media players, game consoles). In this workshop, you will be looking for ways to play around with the existing hardware and re-incorporating them back into serviceable devices. Potential avenues could include: extra screens for an art installation, modded gaming consoles to play lost media, or simply using your old iPod as a music player again. This workshop will also have a discussion on the philosophy of perma-computing, or ways we can hack existing devices to extend their longevity and limit our own production of e-waste. Devices are planned to become obsolete, and it is our job as soft(ware) custodians to maintain, cultivate, and care for these old and forgotten tools.

Sutton Place / Workshop B
21:30
120min
Build and Use a Still-Air Box for Aseptic Handling of (Bacterial) Sample
Danny Chan

Tiny particles can have all sorts of living things attached or may even be alive themselves! One basic method when working with biology is keeping the organisms you want away from the organisms you don’ t. To this end, a still-air box can help you prevent contamination if you are manipulating materials fo r plant tissue culture, mycology, microbiology, or other fields requiring a reduction of airborne contaminants. In addition to keeping contaminants “out,” ensuring that you don’t grow anything you don’t intend, proper use of a still-air box can also help with keeping your sample “in,” ensuring that the risk of exposure to anything unknown is mitigated. Come to this workshop to make a simple and extensible still-air box and/or to learn about how to operate one safely by separating mixtures of commercially available bacteria using the streak-plate method.

Sutton Place / Workshop A
22:00
22:00
110min
Hackers Got Talent
Rob T Firefly, Gila

Since 2016, Hackers Got Talent has given HOPE attendees the opportunity to strut their stuff on the main stage. This year will be no exception - you can showcase your talents, hacking-related or not! Sign up at the Info Desk, or find one of your intrepid hosts around the con. Onstage presentations will be judged by a combination of panelists and audience members.

Grand Ballroom
22:00
110min
Maxx Klaxon Show
Maxx Klaxon

A medley of retrofuturist electropop and 3D multimedia with tracks that serve up an ironic perspective on authoritarian politics and technological dysfunction, with a groove you can move to. Prepare to don red/blue glasses and get down to the beat.

Crystal Ballroom
10:00
10:00
360min
Anarchist Hacker Village (Day 3)

A space for anarchists, abolitionists, anti-authoritarians, other like-minded folks, with friendly faces to meet and socialize with. Where hacking and technology are tools for total liberation. We'll have freely available swag like zines and stickers, and a place to find out about related ad-hoc events like assemblies.

Herald Square / Anarchist Hacker Village
10:00
120min
Certified Vibe Hacker
Robert Wagner, Jaime Urteaga

Most security professionals are overloaded with tools, but what they really need is more focus and leverage. This workshop introduces “vibe hacking,” a practical, hands-on approach to using agentic AI for red, blue, and purple team workflows. It will focus on amplifying human capability by reducing cognitive overhead and helping attendees steer AI toward real-world security tasks like threat identification and remediation. The goal is to augment human judgment and decision-making rather than simply automating it.

Sutton Place / Workshop A
10:00
180min
Community Scale Cloud Infrastructure: Deploying and Managing Autonomous Services With Co-op Cloud
Marlon Kautz, Silk, Brooke

Co-op Cloud is an open-source software stack that lubricates the process of protecting against digital surveillance through self-hosting and realizing data autonomy on a community scale. This workshop will cover the essentials of hosting software using Co-op Cloud - installing Abra (the flagship CLI client) and using Abra to deploy and configure services. Participants will also learn why data autonomy is important, how it prevents government repression and corporate surveillance, and how to take concrete steps to protect and secure their data through self-hosting. Experience with the Linux command line recommended, but not required.

Sutton Place / Workshop B
10:00
360min
Hackerspace Village (Day3)

Come check out the local NYC hackerspaces at the Hackerspace Village. It is organized by
some of New York City’s local hackerspaces. You are invited to join them for lots of cool
activities throughout HOPE 26. They are all nonprofit and 100 percent volunteer-run and would
love to have you visit on their open nights!

Herald Square / Hackerspace Village
10:00
360min
Ham Radio Village (Day 3)

Our mission is to deliver high-quality and innovate amateur radio related educational content,
hands-on experiences, and license testing sessions online and in-person through events. We
believe that the more people know about amateur radio, the more safe, secure, functional, and
innovative our wireless products, services, and experiments will be. Our team of dedicated
volunteers is responsible for generating all new research, giving talks and demonstrations at
events, building and testing experiments, as well as offering support to the general ham radio
community. There will be ham radio demonstrations throughout HOPE 26.

Herald Square / Ham Radio Village
10:00
50min
Harvest Now, Decrypt Later
redshiftzero

For decades, public key cryptography has relied on mathematical hardness assumptions (the difficulty of factoring large numbers and computing discrete logarithms) that within several years may no longer hold. The arrival of a cryptographically relevant quantum computer capable of breaking RSA and elliptic curve cryptography is in the future, and the “harvest now, decrypt later” threat means encrypted traffic captured today could be retroactively decrypted by nation state actors. This talk recaps where we are with the post-quantum transition: NIST’s multi-year standardization process culminating in ML-KEM and ML-DSA for key encapsulation and signatures, the hard problems that underpin them, and the state of ecosystem migration.

Gramercy Park Suite
10:00
360min
Lockpick Village With Lockpick Extreme (Day 3)
Bob Hermes, Christine Bachman, Daniel Finegold

Locks are puzzles you can solve without the key! Explore the fun world of locksport with Lockpick Extreme. Learn to lockpick from friendly instructors or practice what you already know with their assortment of locks and picks. When you’re done, you can shop at the pop-up shop and take your new hobby home with you.

Herald Square / Lockpick Village
10:00
50min
No, I’d Rather Stay Manipulated: How the Apps in Our Lives Hijack Our Behavioral Programming
Nasir Barday

The products on your phone do more than compete for your attention. They engineer your behavior. This talk dissects the specific mechanisms: variable reinforcement schedules borrowed from slot machine design, A/B testing pipelines that converge on maximum psychological extraction over thousands of iterations, and the metrics architecture (time-on-platform, conversion rate, churn) that makes manipulative design the rational output of every product organization. Nasir will walk through how these decisions get made inside product teams – not by villains, but by reasonable people optimizing reasonable metrics that produce unreasonable outcomes. Internal documents from the recent Meta/YouTube trial where a jury found both companies negligent in the design of their platforms show exactly how deliberate this process is.

The more urgent territory is what happens when dark patterns move from static interfaces into AI. Recent research shows that every major LLM exhibits sycophancy, systematically validating user beliefs over providing honest guidance. And that users prefer and trust the sycophantic version more, creating a perverse incentive loop where the model that’s worse for you is the model that wins on engagement metrics. A separate line of research found that AI agents navigating interfaces on behalf of users are more susceptible to dark patterns as they become more capable. And smarter agents get tricked more . When the interface itself is an optimization target driven by AI personalization, the dark pattern becomes invisible: two people see the same app, but experience entirely different levels of manipulation, and neither can document what happened to them.

Crystal Ballroom
10:00
360min
Paper Popups (Day 3)

Explore the world of pop-ups! How can something 2D become 3D? Learn both the math and magic behind these folding paper sculptures. Take a break and build out a HOPE pop-up book. Participants will be empowered to set off into the exciting world of paper engineering. Stop by any time throughout HOPE 26.

Herald Square / Paper Popup Village
10:00
50min
The Ethical Fork in the Road Facing Gen Z: How Can We Inspire Gen Z to Become Ethical Hackers in Modern Workplaces?
Will McKeen

This talk centers around the risk and opportunity facing young people online and how the cybersecurity industry is ill-equipped to harness their power, or address the threats emanating from them. It will describe how to unlock the power of young people through their online gaming to launch their digital futures. It will cover the real crisis facing our kids online, and describe tangible opportunities for young people to fill critical roles within cybersecurity.

Grand Ballroom
11:00
11:00
50min
Building Sovereign AI for Amateur Radio
Joe Cupano

Most AI assistants send your data to the cloud. This talk shows you how to build one that does not. Joe Cupano walks through the construction of a fully sovereign AI server on commodity hardware, an NVIDIA RTX GPU running Ollama with a curated knowledge base capable of answering amateur radio and SIGINT questions from local inference alone. The talk covers the full pipeline from hardware selection through corpus ingestion, the agent frameworks that failed the sovereignty test, and practical techniques for building domain-specific knowledge bases from heterogeneous sources. Attendees will leave with a replicable architecture, a working blueprint, and a clear-eyed view of which open-source tools actually respect data sovereignty and which do not.

Crystal Ballroom
11:00
120min
Mesh Nets for Hackers: How (And When) to Use Meshtastic, Meshcore, and Reticulum (Day 3)
Kody Kinzie

Meshtastic is a long range, encrypted, off-grid mesh protocol that features many powerful modules, configurations, and settings. For beginners just getting started, it can be confusing to dive into these features! In this workshop, you’ ll explore the exciting modules that make Meshtastic more fun and useful. It will cover how to customize the encryption, add hardware like GPS and sensors, and change the default transmission settings to adapt to specific environments. Attendees will learn to customize their Meshtastic nodes for any situation using the built-in modules and settings. You ’ll also explore attacks against Meshtastic, and how to get involved in your local area!

Herald Square / ScriptKitty Village
11:00
50min
Modern OSINT Tradecraft: Attribution, Analysis, and OPSEC
Lex Tungkasiri

Open Source Intelligence (OSINT) is often dismissed as “just Googling,” yet it has become one of the most powerful methods for collecting, correlating, and attributing information across public and semi-public sources. This presentation explores modern OSINT methodology through real-world examples, demonstrating how investigators pivot across social media, imagery, geospatial data, and other datasets to build attribution models and uncover relationships. Topics include geolocation, chronolocation, cross-platform identity correlation, cryptocurrency transaction analysis, AI-assisted investigative workflows, and common pitfalls such as false attribution and data poisoning. The session will also examine operational security, ethics, legality, and the privacy implications of modern intelligence gathering. In addition, the speaker will demonstrate a new open-source AI-powered OSINT platform designed to assist analysts with data triage, correlation, and investigative workflow automation, which will be released free to the community.

Gramercy Park Suite
11:00
50min
The Adversary in Your Bed: Stalkerware, Domestic Violence, and the Hacker Defense
Efrat Sternberg, Sarah E. Ross-Benjamin, Sara Kurtzberg

Domestic violence breaks every assumption in your threat model. The adversary has physical access, knows the passcode, owns the cloud account, pays the bill, and shares the bed. No consumer device is designed for that adversary. This panel looks at what happens when intimate-partner abuse goes digital: covert stalkerware (mSpy, FlexiSPY, pcTattletale, Cocospy), the weaponization of legitimate consumer tech (Find My, Life360, Ring, shared iCloud, AirTags, vehicle telematics), and the surveillance-by-default architecture of modern households. Every major consumer spyware vendor on that list has been breached and dumped. The customer bases were overwhelmingly abusers. Hackers, not regulators, made that visible. This panel will cover detection in the field: MVT, TinyCheck, the Coalition Against Stalkerware’s indicator list, and triage on a phone the survivor cannot safely hand over for imaging. They will cover what prosecutors actually do with that evidence at charging and trial. And they will name the institutions carrying this load: the EFF, Citizen Lab, Operation Safe Escape, NNEDV’s Safety Net Project. Most of them are not government.

The point of putting this panel on a HOPE stage is direct. Prosecutors and DV advocates need hackers. Hackers often see this work as inaccessible or institutionally hostile. This panel maintains that it isn’t. This is an invitation.

Grand Ballroom
12:00
12:00
50min
BlueLeaks 2.0
Emma Best, maia arson crimew, Mikael Thalen, Alexander J. Urbelis

In 2020, a private contractor that provided services to hundreds of agencies was hacked and given to Distributed Denial of Secrets, which dubbed the data BlueLeaks. At the time, it was the largest leak of American law enforcement and intelligence records in history. In 2026, it happened again. This panel will discuss receiving the leak, publishing it, and the fallout.

Grand Ballroom
12:00
50min
Non-Human Identity – The Gaping Security Hole That Agents Are Making Worse!
Michael Morgenstern

This talk will cover a list of ways to hack non-human identities and proposals for securing your Agentic infrastructure. It is based on over two years of research, and on several consulting projects securing NHIs and Agents for clients. Michael will discuss a developing framework for understanding your current state of NHI and Agentic identities, showing the results of primary research that his team has been conducting over the past year. He will explain why consistent surface-level security controls and approaches simply will not cut it due to the complex nature of how fast shadow AI is growing. You will leave this talk concerned about the security of your infrastructure, with at least a few new ideas on what to go secure (or hack).

Gramercy Park Suite
12:00
50min
Organizing in Layer 8 – Building Tech in Democratic Socialists of America
Colin Mahns

The Democratic Socialists of America (DSA) is the largest socialist organization in the country, swelling in the past ten years from just a few thousand to over 110,000 dues-paying members. They believe that working people should run the economy and society democratically to meet their needs, not to make profits for a few, and so they prioritize mass campaigns that center the working class, like labor and tenant organizing and class struggle elections – including winning the mayor’s office here in New York City. Using technology to build DSA’s political independence and their membership’s organizing capacity has been key to helping them grow and succeed. This talk aims to provide an overview of DSA’s technology use, address real world problems with adopting closed and open-source tools, and outline their efforts to create a politically independent tech stack, as well as discuss other challenges organizing on Layer 8 – the Political Layer.

Crystal Ballroom
12:30
12:30
180min
Pegasus Detection and Analysis
Stephen Boriotti, Matthew Hopard, Gabriel Ruiz

This workshop will be using Amnesty International’s Mobile Verification Toolkit to see if your Android or iOS has been compromised by Pegasus. The workshop will open with a short talk on mobile spyware and general principles of communications security. To learn more about Pegasus, there are many videos, including: 60 Minutes Archive: “NSO Group’s Pegasus.” Note: The presenters of this workshop do not consent to mechanical recording of their presentation, but feel free to take notes.

Sutton Place / Workshop A
13:00
13:00
50min
Against the Edgelord International
Johannes Grenzfurthner

Hackers are trained to think in systems: attack surfaces, payloads, privilege escalation, persistence, obfuscation, cleanup. But contemporary politics and media culture increasingly operate in disturbingly similar ways. Narratives are injected, amplified, laundered, distorted, and made persistent across platforms, communities, and institutions. A meme can behave like a payload. A fake historical analogy can function like privilege escalation. A conspiracy theory can become a persistence mechanism. And in the age of generative AI, cultural exploits can be produced, varied, and deployed at industrial scale.

This talk proposes a hacker-oriented model of narrative warfare and cultural manipulation: the narrative exploit chain. Drawing from context hacking, media pranks, art activism, hacker history, propaganda studies, and Johannes’ own work in film, performance, and political subversion, it asks how stories become attack vectors, how irony becomes armor, how taboo-breaking becomes a recruitment funnel, and how communities can defend themselves without becoming humorless cops of consensus reality.

Grand Ballroom
13:00
50min
Nobody Meant to Build a Surveillance Machine: The Modern Corporate Panopticon
Steven Irurueta

Modern workplace surveillance wasn’t intentionally designed: it emerged. Every department inside an organization asks for something reasonable: stronger security, legal compliance, easier collaboration, simpler administration, or AI-powered productivity. Individually, these requests make sense. Together, they create one of the most observable work environments ever built. Using Microsoft 365 as a case study, this presentation explores how those ordinary organizational decisions gradually produce extraordinary visibility into employee behavior, why these environments are so frequently misconfigured, and how understanding the architecture behind them often reveals more than any single vulnerability ever could. Rather than focusing on sensational exploits, the talk examines assumptions, metadata, and the quiet ways information accumulates inside modern enterprises – because in complex systems, understanding is often the most powerful tool.

Crystal Ballroom
13:00
50min
Non-Stop BioDigital Attack Surfaces: Reviewing AI-Augmented Biocybersecurity and Cyberbiosecurity
bueller, Xavier Palmer

Information lies at the center of biology and computation - systems and networks, similarly, undergird both domains. This cyber-native similarity has introduced digital and biophysical security considerations to one another: DNA-based exploits for remote code execution, wastewater public health infrastructure ransomware, and medical image artificial tumor removal and addition have all been demonstrated as viable attack vectors within the past decade. Concerns about hardening vaccine supply, agriculture, and bioproduct manufacturing have already been raised. Artificial intelligence (AI) has enabled some of these attack vectors, particularly in improved obfuscation, as well as demonstrated use in identifying potential attackers. This talk will discuss integration of AI into cyberbiosecurity (CBS) and biocybersecurity (BCS) frameworks, discussing its positioning as a fundamental driver of risk across discovery, automation, and adversarial thinking in biocyber workflows. It will also cover recent biocyber attack vectors, with an emphasis on those made possible through AI. It is imperative that our defenses evolve as quickly as the algorithms designing the next attack.

Gramercy Park Suite
13:15
13:15
90min
Make Your Very Own IoT Cat Lamp With WLED (Day 3)
Michael Raymond

Want to create a beautiful, squishy, and cute Wi-Fi controllable cat lamp? In this workshop, you ’ll put together a “Purrsheen” cat-shaped Wi-Fi lamp that allows you to control your adorable cat baby via Wi-Fi or Home Assistant with WLED! This workshop will involve beginner-level soldering and assembly skills. Great for cat lovers and those looking to get into DIY IoT projects.

Herald Square / ScriptKitty Village
13:30
13:30
120min
Security Without Silos: Bridging Physical and Cyber Defense for Civil Society
Kristin Antin, Tara Arthur, Davis Erin Anderson

Civil society organizations face threats that don’t respect the boundary between physical and digital security - doxxing enables stalking, device confiscation enables account compromise, and a clinic blockade gets livestreamed and coordinated online - yet most organizations still manage these domains in separate silos. This hands-on tabletop workshop brings together practitioners from physical security, digital security, and the NGO sector to work through real-world scenarios where cyber and physical risks intersect, giving participants practice in cross-domain incident response and a shared framework and vocabulary for integrated security. The session is part of a broader initiative led by the Digital Security Collective focused on building integrated security practice across civil society.

Sutton Place / Workshop B
14:00
14:00
50min
Honeypotting AI Agents
Abdel Fane

OpenA2A runs two kinds of honeypot for AI agents: a fleet of fake agents that observe attackers who believe they control a real system, and a network of poisoned pages on the open web carrying benign indirect prompt injections, where the visitors are AI agents and a callback measures which agents followed the bait. This talk presents what both surfaces reveal, including the finding that 45 percent of unique attackers return across sessions, with one fingerprint returning for 15 days straight across 623 sessions, alongside an aggregate callback rate of 1.4 percent across more than 183,000 visits from over 34,000 unique agent fingerprints. Abdel Fane walks through the instrumentation, what each data stream sees that the others cannot, what the project deliberately withholds from publication and why, and the structural reason crawler-based studies miss most of the attacker reachable surface. All of the work is Apache 2.0, and every fixture and signature is reproducible by anyone running equivalent instrumentation.

Gramercy Park Suite
14:00
50min
I Hacked a Gay Foot Fetish App (And You Can, Too!)
Altair

For folks in the queer kink community, social connection frequently begins online. Big Tech, though, makes it especially difficult for people in those groups to meet and connect; they often face bans and censorship. So when “Soles,” a new foot fetish web app for gay men, seemed to come out of nowhere one day, it raised several questions. Where did it come from? Who made it? Is it secure? This is the story of how a curious hacker gained admin privileges with a single HTTP request, what happened after, and how – with the hacker spirit – you too can sniff out trouble. Could getting your foot in the door really be this easy?

Crystal Ballroom
14:00
50min
Show Network Security – A Time of Major Transition
John Huntington

Computer networks have become a critical part of control and media distribution for concerts, theater productions, and other live events – and in theme parks, escape rooms, museums, and other permanently installed entertainment attractions throughout the world. As show technology evolved, simple serial point to point control protocols were initially ported onto the network while, eventually, network-centric open and proprietary protocols control were developed. In addition, network-based media transport solutions have become the primary solution for low- latency distribution of live audio and video. However, few of the standards and protocols in widespread use today have any intrinsic security features, and the industry has relied primarily on “security through obscurity” and physical access control to small, closed, offline systems. While the need for enhanced security solutions has grown along with the industry, the roll out of the EU Cyber Resilience Act (CRA), which mandates security, has made clear that solutions must be developed sooner rather than later. The entertainment technology industry has responded with two primary solutions: ESTA’s proposed ANSI standard BSR E1.88 Framework for Entertainment Network Cybersecurity and Efficiency (FENCE), and Singularity’s independently developed, free to use Sig-Net. How all this will shake out is unknown, but this talk will provide background on the issues and the current status of the solutions.

Grand Ballroom
15:00
15:00
50min
Agshittification: Big Meat, Misinformation, and the Fight for the Future of Food
P.K. Newby

There is overwhelming evidence and scientific consensus that conventional agriculture and animal food production are threatening the things we hold dear: our health, our communities, our planet, and perhaps even our humanity. So why does diet advice from the American government emphasize meat, milk, and eggs? And who decides what food is “real,” or what makes something “ultra-processed?” On the same HOPE stage where she first heard “enshittification,” author and founder of Food Matters Media Dr. P.K. Newby introduces “agshittification,” a phrase coined in her newest book after learning the filthy truth about megafactory animal farming, the NIMBY Big Meat doesn’t want you to know about. With framing from Food and Nutrition: What Everyone Needs to Know , Newby illustrates how industry influence and misinformation are part of a larger nexus of agshittificatory practices, policies, and propaganda designed to keep you in the dark about “all natural” meat. This mind-bending story spans vertical pig farms and literal shitstorms as Newby stands on the shoulders of HOPE superheroes and tech gurus, Cory Doctorow and Greg Newby, sharing an ecotechno vision of what a healthy, sustainable food future looks like.

Newby’s talk is designed for all eaters, its goal to inspire sapiens of all stripes to consider what steps we can take individually and collectively to evolve beyond the Age of the Chicken, one bite at a time.

Crystal Ballroom
15:00
50min
LIMA – No Vendor, No Cloud, No Trust: Open Source Tamper Attestation for Critical Infrastructure Hardware
Justin T. Knox

LIMA is an open-source attestation system that lets a field device cryptographically prove its sensor readings are authentic and untampered with – over a SCADA network or any network at all. The talk walks the full stack: a Zephyr RTOS firmware node on the nRF52840 signs sensor and accelerometer data with ECDSA-P256 using the chip’s onboard CryptoCell-310 hardware security engine, broadcasts 90-byte attested payloads over BLE extended advertising, and delivers them to a blind-relay Rust gateway that verifies every signature without ever holding a private key. A live demo – with a recorded fallback – shows a physical tamper event (a shock to a field device) propagating through the cryptographic chain to a verified alert in about a second. Justin will then cover why the project exists and who it is for (individuals and small operators through to enterprise deployments), and give a walkthrough on how to stand up an example node.

Gramercy Park Suite
15:00
50min
We Need to Talk About Signal: Security Assumptions, Threat Models, and Activist Community Risk
HelpMeRob

Signal provides strong end-to-end encryption, yet its protections are often misunderstood. Many users assume encryption guarantees safety. It does not. Effective security depends on shared threat models, aligned risk tolerances, and consistent operational discipline across the group. When participants operate under different assumptions about risk, anonymity, device hygiene, or message retention, they can unintentionally expose one another to surveillance, infiltration, or targeted retaliation. This presentation examines Signal’s security model, clarifies what it does and does not protect against, and explores how group dynamics shape real-world risk. Drawing on personal examples, it will analyze how communities have been compromised both intentionally and inadvertently.

Grand Ballroom
16:00
16:00
50min
Can We Route Around the App Stores?
Mikalai Birukou, Sean O'Brien

Hackers have long understood that networks are resilient. We can bootstrap anonymity and routing layers like Tor, I2P, and Nym with relative ease, and move traffic across hostile environments with surprising flexibility. In many ways, the network layer is the least of our problems. The real challenge begins next layer up, where applications, platforms, and distribution channels impose control over how that network can actually be used. Over the past year, the presenters built and deployed a working suite of desktop applications for communication, identity, and storage, and put them in the hands of real users in classroom environments. This gave a clear view into what happens when people try to use privacy-first tools in practice. You will see what worked, what broke, and how user expectations shaped by mainstream platforms collide with systems designed for autonomy and control. These applications also include an independent software delivery and verification model, allowing updates and dependencies to be distributed and validated without relying on centralized app stores. These ideas are now being brought to mobile devices, where the constraints are far more severe. This talk focuses on the practical challenges of running user-controlled software on phones: app store restrictions, packaging and distribution barriers, Android limitations, and Apple policies that restrict apps which resemble alternative software ecosystems. This talk will also address sideloading, UI constraints, and the current state of hardware, including experiments with PinePhone, Fairphone, and GrapheneOS. The core question is simple: how can we build trustworthy applications that route around the app stores?

Crystal Ballroom
16:00
50min
Doxing: The Politics, Panics, and Economies of Online Safety
Jamie Theophilos

For more than two decades, doxing has taken on many meanings. Once associated primarily with image board trolls and hackers, it has since become a tactic deployed by (and towards) a wide range of actors for disparaging purposes, from de-platforming political opponents and unmasking ICE agents to facilitating in swatting campaigns in gaming communities. While doxing continues to occupy multiple positions, be it a mechanism of community safety to a ubiquitous “weapon of visibility” in the “21st century culture wars,” its social significance has mutated. Most recently, while state agencies have relied on publicly available online information to identify and detain student protesters, governments are simultaneously rapidly adopting anti-doxing legislation that criminalizes the disclosure of public information, going so far as to describe it as a kind of domestic terrorism. This shift not only raises the political stakes of doxing but also codifies the moral panics with strikingly disproportionate punishments.

This talk traces the cultural history of doxing to examine how its meaning has changed and, in many ways, also remained remarkably consistent. By following the evolving relationships among states, platforms, corporations, activists, journalists, and varying online subcultures, this talk explores how doxing has reshaped ideas of accountability, visibility, and online safety, as well as the technologies that enable it. By examining the feedback loops between surveillance, counter-surveillance, and vigilantism, Jamie argues that a historical look at doxing offers a critical lens for understanding how online identification has become both a tool of community governance and an ambiguous threat to public safety.

Grand Ballroom
16:00
50min
They’re Already Knocking: High-Interaction Honeypots for the Rest of Us
Aaron Levitt

The Internet can be a pretty scary place, and if you know where to look, you can find proof of that in your logs. This talk walks through the end-to-end deployment of a high-interaction honeypot: platform selection, decoy service configuration, network placement, and logs that surface actionable intelligence rather than a bunch of noise. Once the trap has been set, you’ll get a look at what it catches. Whether you’re an experienced security expert or just someone who wants to understand what’s going on with your network in the middle of the night, this talk will show you that running your own threat intelligence operation is easier than you think. All you need is a Linux box, a spare IP address, and the patience to watch and learn.

Gramercy Park Suite
17:00
17:00
50min
Decentralized Networking Is a Social Problem
John Burwell

Decentralized networking is often approached as an engineering problem. Distributed protocols, peer-to-peer systems, mesh networks, and federation can address many technical challenges quite successfully, but the communities built around them must still grapple with questions of stewardship, participation, trust, and how to navigate disagreement. As projects grow, some respond by adding rules and formal governance in an effort to create shared expectations and predictable behavior, but rules alone do not guarantee success. This talk draws on the experience of the 44Net community, an evolving family of amateur radio networking projects dating back to 1981. Using projects including AMPRNet, HAMNET, 44Net Connect, and others as case studies, it examines the social patterns that have allowed these communities to adapt over decades of technical and societal change. Rather than trying to prescribe every behavior, these long-lived communities tend to observe what works, reinforce useful norms, and let shared expectations emerge from shared experience. Taken together, these projects suggest that longevity depends less on elaborate governance than on a community’s ability to absorb change, learn from conflict, and continue evolving.

Grand Ballroom
17:00
50min
Real-Time Ad Blocking via HDMI Man-in-the-Middle
Cyril Engmann

You bought the TV, and you pay for the subscription – so why do you still get ads? Modern streaming ads are baked into the stream as the content, out of reach of any network hacks. Minus is a small device that sits between your streaming box and your television and does the blocking in hardware, with no cloud dependency, using open models running on a single-board computer. It intercepts the signal between a streaming stick and the TV and goes after ads on the screen itself. This talk offers a hands-on look at the hardware and ML detection pipeline, and a broader case for the right to control what plays on a device you own.

Gramercy Park Suite
17:00
50min
The Watchers You Fed: Feds, Extractors, Data-Brokers
Tony Spencer

This talk documents the shared infrastructure connecting federal surveillance purchases, commercial data brokers, and municipal ALPR networks. It will cover the Third-Party Doctrine (United States v. Miller, 1976), the legal basis still used for warrantless federal access to commercial surveillance data; Flock Safety’s ALPR contracts with city governments, including the data retention and federal access terms most council members never read before signing; and Retroactive Omniscience, the capacity of AI-augmented systems to reconstruct a person’s movements and associations from years of data that seemed too mundane to matter when it was collected. The presenter will cover three municipalities where organized residents altered ALPR contract terms through public records requests and council pressure rather than litigation, with the specific mechanics broken down for replication: what to request, what to ask at a meeting, and how to make renewal politically costly. Drawn from research for the forthcoming book The Watchers You Fed: Turn the Lens , this talk is aimed at attendees working in privacy advocacy or municipal policy – and anyone trying to understand how government and commercial surveillance data now move through the same pipeline.

Crystal Ballroom
18:00
18:00
50min
HOPE 26 Closing Ceremonies

It all ends Sunday evening when we gather to reminisce and start cleaning up. It's always a lot of fun but it's also a little bit sad, as it's time to say goodbye until next time, which hopefully will be one year from now. And if you've made it this far, we'll consider you part of the HOPE family.

Grand Ballroom