This workshop will teach attendees what they need to know to pass the Technician Class amateur radio license exam and get started in amateur radio. It includes six hours of instruction, with the exam administered immediately after the workshop. It is sometimes said that radio amateurs were the original hackers, cobbling together transmitters and receivers from odds, ends, and discarded electronics. Radio amateurs continue this tradition today, and in addition to building their own gear, they’re hacking on digital communications systems, including both hardware and software. Amateur radio is a great hobby for electronics enthusiasts and, increasingly, for hardware and software hackers. Participants will increase their chances of passing the test if they download the study guide from www.kb6nu.com/study-guides/ and familiarize themselves with the material before coming to the workshop. The text for this workshop is Dan’s No Nonsense Technician Class License Study Guide. The PDF version of the study guide is available for free at the above page. EPUB and print versions are also available for a small charge. This is part 1 of 2 parts -- the 2nd part is Saturday 10am - 2pm, same room. To pass your exam, please participate in both parts.
It all starts Friday morning. Join us as we make sure everything works before another HOPE is unleashed on everyone.
Your car passes a license plate reader. Your phone connects to a cell tower. A camera identifies your face, a drone watches from above, and data brokers help connect the dots. Most people have no idea how much surveillance follows them through an ordinary day or where that information ends up. This talk pulls back the curtain on the modern police surveillance stack, from Flock cameras and cell-site simulators to drones, body cameras, facial recognition, data brokers, and regional intelligence networks. Using real-world examples and open-source tools such as EFF’s Atlas of Surveillance and RayHunter, Michael Raymond will show attendees how these systems work, how communities are mapping them, and what practical, lawful steps people can take to better understand and reduce their exposure.
Back for the third time, author and technologist Mallory Knodel will give an update on several I-star organizations, namely ICANN, IETF, IEEE, W3C, and ITU. The tensions and synergies of human rights considerations in Internet governance and standards setting across the I-star bodies is rapidly expanding. This talk will touch on the major controversies in each space as they relate to human rights, namely censorship and the right to privacy.
This workshop offers hands-on instruction using a unique, cat-shaped Wi-Fi hacking microcontroller, the Wi-Fi Nugget. Designed to engage participants in practical learning, it covers essential skills for defending against four common yet powerful Wi-Fi attacks. Students will explore topics including detecting Wi-Fi leaks, the risks of QR codes leading to hidden networks, spotting phishing networks, and defending against advanced Wi-Fi karma attacks. The Wi-Fi Nugget is a powerful tool for understanding and fighting back against Wi-Fi hacking. This class is suitable for Wi-Fi hacking experts and those just getting started.
As tech bosses fall in line with the right, tech workers have begun fighting back. Resistance has included organizing against military contracts, walkouts to protest sexism, agitation about tech’s role in the climate crisis, and even a wave of union drives. Hellbent on stamping out any and all dissent, tech executives embraced Trumpism, fired organizers, and began lashing out against the “woke” ideology they blamed for turning their once loyal employees against them. This is the rousing inside story of the tech worker movement – and the way it spawned an anti-worker backlash now reshaping the industry.
A space for anarchists, abolitionists, anti-authoritarians, other like-minded folks, with friendly faces to meet and socialize with. Where hacking and technology are tools for total liberation. We'll have freely available swag like zines and stickers, and a place to find out about related ad-hoc events like assemblies.
The RCade is a custom arcade cabinet built at the Recurse Center that runs games made by the community. It has a real CRT, a custom graphics card, spinner controllers, and a deploy pipeline where anyone can ship a game just by pushing to GitHub. It now has over 90 games. Frank Chiarulli will talk about reviving the hardware and building the deployment system, Rose Hall will cover the game engine and plugin sandbox, and Sophie Downward will walk through building a custom display adapter from scratch. They’ll close out by showing off some of the games.
Rhizomatica has been working on a completely autonomous communication system called HERMES (hermes.radio) since 2017. HERMES is a fully FLOSS stack that has been built to use HF radio to create secure and very long-range (about 500 kilometers) digital communication links. HERMES has been deployed in the Amazon to support land defenders, on boats in Bangladesh to provide critical communications to fishermen, in war zones in Africa as part of early warning systems, etc. Due to current geopolitical situations that have us all concerned, it’s clear that HERMES can be a critical tool for hackers, privacy activists, and the general public to create autonomous and secure digital communication networks that are much harder to monitor or shut down compared to corporate-controlled ISPs.
Come check out the local NYC hackerspaces at the Hackerspace Village. It is organized by
some of New York City’s local hackerspaces. You are invited to join them for lots of cool
activities throughout HOPE 26. They are all nonprofit and 100 percent volunteer-run and would
love to have you visit on their open nights!
Our mission is to deliver high-quality and innovate amateur radio related educational content,
hands-on experiences, and license testing sessions online and in-person through events. We
believe that the more people know about amateur radio, the more safe, secure, functional, and
innovative our wireless products, services, and experiments will be. Our team of dedicated
volunteers is responsible for generating all new research, giving talks and demonstrations at
events, building and testing experiments, as well as offering support to the general ham radio
community. There will be ham radio demonstrations throughout HOPE 26.
The workshop will be an open discussion and hands-on introduction to practical herbal medicine for everyday health. It will engage directly with plants to assess herbs through both sensory experience and basic phytochemistry - and discuss herbal preparations such as tinctures, oils, and teas.
Locks are puzzles you can solve without the key! Explore the fun world of locksport with Lockpick Extreme. Learn to lockpick from friendly instructors or practice what you already know with their assortment of locks and picks. When you’re done, you can shop at the pop-up shop and take your new hobby home with you.
Explore the world of pop-ups! How can something 2D become 3D? Learn both the math and magic behind these folding paper sculptures. Take a break and build out a HOPE pop-up book. Participants will be empowered to set off into the exciting world of paper engineering. Stop by any time throughout HOPE 26.
In a world increasingly shaped by secrecy, corruption, and misinformation, truth requires infrastructure. Built entirely for the public interest, both the Organized Crime and Corruption Reporting Project (OCCRP) and MuckRock provide vital, public-good resources designed to help investigators uncover what powerful actors want to keep hidden. This two-hour, hands-on workshop brings together two essential tools for transparency: OCCRP Aleph Pro and MuckRock’s DocumentCloud. Aleph Pro is a massive investigative data platform holding more than four billion documents - ranging from corporate registries to leaked datasets - designed to help users follow the money and map complex networks. DocumentCloud is a public platform with over seven million primary source documents, allowing anyone to search, analyze, and organize materials through either the user interface or the API, serving as a trusted resource for public records and research on public figures, government activities, corporate practices, and other matters of public interest. You will be walked through real-life examples of how these platforms are used in high-stakes investigations, and learn about the global impact they ’ve generated and how new users can get started. Whether your goal is to make sense of chaotic leaked data, navigate massive FOIA dumps, or map hidden assets, this workshop gives you the tools and hands-on experience to do it. What will you uncover?
Legal research is infamous for guarded access (law firms only) and high prices (monthly and per-search). This year at HOPE, see the launch of an open-source legal search engine, and a public forum for legal research. Learn how to model legal sources using vector and graph databases, how to acquire records using scrapers, and how to connect directly to the people at Congress producing and publishing these records each day. Calliope live-codes each day on YouTube to prepare for HOPE, on https://www.youtube.com/@c4lliope/streams. Their code is published on https://operand.online.
The threat landscape for journalists and whistleblowers has dramatically intensified over the last 15 years, leading to the development of robust technical evolutions in platforms from SecureDrop, Dangerzone, WhatsApp (meh), and Signal. Safely handling malicious submissions and spicy comms, newsrooms have become used to employing rigorous security models, sandboxing techniques, and myriad other tactics that have become the “meat-and-potatoes” of high-stakes public interest journalism. The baseline for secure communications is always shifting due to emerging legal, quantum, and novel AI challenges. This talk will address this and help enable you to fully understand how securing data is only half the equation; it is equally critical to protect the human risking their livelihood or liberty for the public’s right to know. This means moving beyond threat models to deeply understand the psychological toll of whistleblowing and the empathetic dimensions of the journalist-source relationship. You will get a glimpse into the modern toolbox that merges strict digital security protocols with empathetic strategies to manage the anxiety inherent in the biggest disclosures. From first contact to post-publication – you’ll learn about the life cycle reporters expect to safely and ethically get the story done.
We treat code as pure instruction, something you write so a machine will obey. Programming languages are closer to a living vernacular, riddled with idiom, accent, ambiguity, and taste, sitting somewhere between human language and musical notation. This talk covers the linguistics of computer languages: how languages were invented, argued over, and mutated; how grammar became structure; how we keep accelerating the pace at which we talk to machines in search of better ways to build. And as the history of computer linguistics will be covered, it is also worth reviewing the uncomfortable question for an age of generated code: as fewer of us write it by hand, will we still read it, understand it, and know why we write it the way we do?
Beginners can now create off-grid, encrypted mesh networks for cheap, with applications in emergency communication, sensor monitoring, and more! These mesh networks have been popping up in cities all over the world, and this workshop will go over everything a beginner needs to run or build their own nodes. If you ’ve ever wanted to legally create off-grid, encrypted mesh networks that can span over a hundred miles, you can get started with Meshtastic for around $50. This class will serve as a beginner user’s guide to Meshtastic, covering everything from hardware basics to advanced software configuration. The workshop will use custom Meshtastic nodes to see real-world results in Las Vegas and explore attacks against mesh networks. Attendees will learn to run their own Meshtastic nodes, select antenna options, and configure software!
Do you have a movie inside you? This is a writing workshop focused on the structures that can be set up in the early pages of a screenplay. Bring your script, come to write, or just come to learn. Details on the wiki. Lines like “hack the planet” are burned into most of our brains, but to get in there they had to go through a lengthy process that all started with a script. The first five pages of a script are critical for engaging the reader and setting up the rest of the story, so that is where this workshop will focus.
Throughout 2025, EFF facilitated digital privacy and security trainings for more than 2000 people. The issue spaces at hand ranged from animal rights activism, abortion access, immigration legal defense groups, and many many more. Although the particular characteristics of the various audiences differed, one thing remained true: traditional sources of information security were either inaccessible to these groups or fundamentally unable to meet their unique needs. In this talk, EFF senior staff technologist Daly Barnett will present field notes collected from the trainings conducted throughout 2025. This high-level survey will cover the types of digital privacy and security threats facing various liberation movement workers in America today, as well as the mitigation strategies they are walked through. For fellow hackers and technologists, this is not only an indispensable insight into the actual impacts of surveillance technology and digital security threats facing today’s activists, but also a blueprint for how they might be able to provide movement workers with much needed help.
This unique panel brings together leading journalists who published and investigated leaked emails from the Epstein files, exposing his network of collaborators and enablers in one of the most explosive political scandals in decades. Members of the panel will discuss receiving the leaks, preserving files removed by the Department of Justice, protecting the privacy of Epstein’s victims, and the process and fallout of investigating and reporting on the explosive files.
The discussion will be joined by Kyrie, a hacker who gained access to Jeffrey Epstein’s emails and later provided a copy to Distributed Denial of Secrets).
Modern “open” software still depends on fragile chokepoints: corporate-controlled CDNs, app stores, DNS, captive portals, web application firewalls, cloud accounts, Wi-Fi, BLE identifiers, and infrastructure that can be blocked, surveilled, or simply unavailable. This talk demonstrates a tiny app runtime where people trade/propagate bite-size WebAssembly and WGSL code, audio/video/photo media, map/wiki diffs, and forum messages directly through physical presence: full-duplex QR/fountain codes, data-over-audio, and BLE mesh when user deems it safe. The point is not nostalgia for the bygone era of the Sneakernet. The goal is a practical, inspectable, community-owned software and media commons that can move through rooms, protests, disasters, schools, hackerspaces, and border cases to/from most digital devices (including smart watches) without needing permission from the Internet network operators.
Learn Windows internals and how malware operates in a fun CTF-style workshop with challenges and demonstrations at many levels, from beginner to advanced. Everyone should learn something new!
In this talk that parallels her recently released book of the same title, Cindy Cohn (former executive director of the Electronic Frontier Foundation) weaves her own personal story with her role as a leading legal voice representing the rights and interests of technology users, innovators, whistleblowers, and researchers during the Crypto Wars of the 1990s, battles over NSA’s dragnet Internet spying revealed in the 2000s, and the fight against FBI gag orders. No promises, but she may be joined on stage by a key client or two.
AI is starting to feel less like software and more like a strange coworker with root access. It can read, write, reason, call tools, trigger workflows, move data, spend money, and make decisions across systems most people barely understand. We see the prompt. We see the response. But the interesting part happens in the middle, where AI-driven systems fan out through APIs, containers, queues, databases, serverless functions, model calls, SaaS platforms, and external services.
This talk is about opening up that middle. Michael Barbine will take the audience on a practical, funny, and deeply suspicious tour of what it means to instrument AI systems so we can see what they are actually doing. His approach comes from security, observability, automation, and an unusually disciplined obsession with games, rules, feedback loops, and measurable behavior. Whether debugging infrastructure, testing endpoint defenses, building agentic workflows, or playing tens of thousands of rounds of Rock Paper Scissors, the core question is the same: what happened, what changed, what pattern did we miss, and how do we prove it? Using distributed tracing, structured events, correlation IDs, audit trails, and purpose-built observability patterns, we can follow AI workflows across modern infrastructure and catch the moments where things get weird. Where did the agent hesitate? What did it call? What did it retry? What did it hallucinate? What did it spend? What data did it touch? What did it decide quietly? And why should anyone trust a system they cannot inspect?
This is a talk for hackers, builders, defenders, operators, and anyone who has ever looked at a black box and taken it personally. It connects classic hacker curiosity with one of the most urgent problems in modern computing: how to understand systems that are becoming more autonomous, persuasive, and embedded in everyday life. Attendees will leave with practical patterns for tracing AI applications, a clearer mental model for debugging agentic systems, and a renewed appreciation for the ancient hacker principle that mystery is not an acceptable interface.
The Fediverse is an international coalition of independent social networks that connect using the open ActivityPub protocol. In this hands-on workshop, you will learn the step-by-step process for creating an account on the Fediverse, as well as how to set up your profile, find people to follow, and make your first post.
Meshtastic is a long range, encrypted, off-grid mesh protocol that features many powerful modules, configurations, and settings. For beginners just getting started, it can be confusing to dive into these features! In this workshop, you’ ll explore the exciting modules that make Meshtastic more fun and useful. It will cover how to customize the encryption, add hardware like GPS and sensors, and change the default transmission settings to adapt to specific environments. Attendees will learn to customize their Meshtastic nodes for any situation using the built-in modules and settings. You ’ll also explore attacks against Meshtastic, and how to get involved in your local area!
Come learn and be inspired by how Flushing Tech brings tech communities to neighborhoods across NYC. Flushing Tech was created three years ago to bring tech enthusiasts together right in their own neighborhoods by having fun building tech, making connections, and learning new things. At HOPE_16, William talked about the start of that journey and shared a practical roadmap with actionable guidelines so anyone could build their own hyper-local tech community. Flushing Tech has evolved over the past year – becoming a 501(c)(3) nonprofit, experimenting with in-person hackathons and online activities, and taking the leap of faith into other neighborhoods. Come hear what worked, what didn’t, and what surprised them. These stories – the wins, the failures, and everything in between – will give you ideas you can steal, remix, and improve upon. The goal is simple: make it easy for anyone, anywhere, to build a thriving hyper-local tech community. Hundreds of Flushing Techs can emerge as communities built by neighbors, for neighbors.
The Tardigrade v.1 EMU (extravehicular mobility unit) is designed for pressurized EVAs (extravehicular activities) during space analog research missions that focus on training for Mars and lunar surface exploration. The suit system concept emerged from a collaboration between Dr. Cameron Smith (Smith Exploration Garments), Scott Beibin (Offworld Voyage), and Elizabeth Jane Cole (Offworld Voyage), with the goal of developing a pressurized EMU training suit platform intended for improved human mobility capabilities on rough terrain during EVAs. The system is designed for easy installation and testing of experimental modular telemetry and communication systems, as well as ease of donning and doffing by analog astronauts during immersive space exploration training mission simulations. The presenters will demonstrate the capabilities and features of the Tardigrade v.1 EMU space exploration training suit platform and share a report back from the first field test held in a remote desert location.
Ever wonder what purposes really large antennas are used for? This presentation will cover currently in use large and innovative antenna systems around the world – on the ground and in the sky. Steve shares what they are designed for and how they are used. Examples in areas like broadcast, astronomy, radar, and a few of the more niche or clandestine application areas will be covered – and not just related to amateur radio. There will also be coverage of how to scale these applications to something any radio hobbyist can copy, make, and use inexpensively at a smaller scale. This presentation will be light on history and high on modern use systems to enable cool wireless projects.
Nikola Tesla spent the last ten years of his life in rooms 3327 and 3328 of the New Yorker Hotel, holding annual birthday press conferences to announce wild new inventions living above the largest private power plant in the United States, and dying alone upstairs on January 7, 1943, after which the government seized his papers despite his American citizenship. This year, for the first time, HOPE convenes in that same building. This talk covers Tesla’s final decade under this roof, the hotel’s own remarkable machinery, the declassified FBI files, and the three individuals who spent their lives making sure none of it was forgotten: William Terbo, Tesla’s grandnephew and last direct-line relative; Dr. Ljubo Vujovic of the Tesla Memorial Society of New York; and Joe Kinney, the hotel’s longtime chief engineer and historian. All three individuals are sadly gone now, but this is the story of what they kept, told in the building where they kept it.
Plus there will be some long-awaited news from The Tesla Science Center at Wardenclyffe!
Last December, Trump’s DHS unleashed “Operation Metro Surge” – a full-scale occupation of Minneapolis and St. Paul characterized by mass abductions, abuse and murder of abductees, and the high-profile executions of Renee Good and Alex Pretti at the hands of ICE agents. This operation was met with widespread, decentralized, and highly coordinated grassroots resistance via interconnected hyperlocal rapid response groups, facilitated by metro-wide digital infrastructure and data processing systems.
Networks of local organizers, hackers, and technologists built out extensive technical capacity for widespread occupation resistance, including systems for secure and coordinated rapid response communication, systems for tracking abductees through the highly opaque immigration system, and sophisticated monitoring systems for tracking ICE personnel, drones, and vehicles. This technical capacity has remained critical to the resistance against ICE operations, and organizers in other cities have become increasingly interested in similar infrastructure.
This talk will provide a comprehensive outline of these logistical, communications, and data processing systems; the ways these systems were effective, the ways they fell short, and most importantly, how hackers and technologists can better organize to build new iterations of this infrastructure within their own regions and contexts.
This is a hands-on workshop where participants learn to use GPG for email encryption, facilitated by the Free Software Foundation (FSF). Participants will help improve the FSF email self-d efense guide through real-time feedback. By the end of the workshop, you will not only be able to send encrypted email to friends and family, but also help teach others the skills of email self-defense and protecting yourself from bulk surveillance.
Journalism is in rough shape. Budgets, resources and staffing are shrinking. This dire situation is a bummer but also opens opportunities for hackers to take up the flag and do some great work in collaboration with journalists. This talk will explore some real world technical problems that show up in actual investigative work and explain how the hacker community can help. Bored? Let’s get to work!
This is the story of how a homebrew cyberdeck project ran headlong into a wall of modern protocol complexity, and how the 9P protocol from Bell Labs – the heart of the Plan 9 operating system – turned out to be the answer. Jon Sharp will demonstrate 9p4z, an open-source library bringing 9P to modern microcontrollers, and show working mesh chat running over long-range radio: off-grid, community-owned communication infrastructure built from parts you probably have in a drawer. The good ideas computing discarded weren’t wrong – they just weren’t profitable enough to lock up, which is exactly what makes them ours to resurrect. This talk is a direct invitation to do it yourself.
What do you do when data opt-outs and removal aren’t options? You make your personal data harder to find, harder to trust, and harder to act on. Drawing on real casework from advanced security clients, this talk covers open-source and vetted closed-source techniques for generating synthetic noise in personal targeting datasets, including a real case study with an honest post-mortem on what worked and what didn’t, plus a breakdown of state-level address confidentiality programs as a legal shield against non-government actors. Attendees will leave with a practical threat model and a clear framework for knowing when removal is effective, when deception is necessary, and when disruption is the only move left.
Binary Jiujitsu: White Belt Fundamentals is the entry point of the platform’s belt progression, taking students from zero binary-exploitation experience to their first working exploit against 32-bit x86 binaries with no protections enabled. It’ s organized into four stripes that build sequentially: Binaries and Memory (ELF layout, process memory, the stack, registers, and calling conventions); Finding the Vulnerability (spotting unsafe C functions, source auditing, and disassembly with objdump/GDB); Crashing and Control Flow Hijacking (triggering crashes, using cyclic patterns to find the offset, and confirming EIP control); and Exploitation (the ret2win pattern and weaponizing control-flow hijacking into a working payload with pwntools). Every lesson is paired with a hands-on challenge binary, students write scripts and work with real tools throughout rather than absorbing theory upfront, and the whole thing runs entirely in-browser with no VM or local setup required. The workshop version is instructor-guided and closes with a Blue Belt test CTF.
Why are all of our favorite sites starting with “Just a moment…” and “Making sure you’re not a bot!” splash pages now? Since 2024, AI companies appear to be operating aggressive, vibe-coded scrapers behind residential proxy botnets, and sites have typically turned to commercial shields. Michael will share several tools and techniques that he uses as a systems administrator at the Free Software Foundation to keep the sites up on their own infrastructure. He will demo some of his own tools and the tech stack he uses regarding monitoring, firewalls, automation, analytics, ASN lookups/blocking, and geofencing.
This talk provides a layer-by-layer technical breakdown of North Korea’s civilian information-control system – covering custom Android handsets with mandatory state-signed APKs, a screenshot-based surveillance daemon called TraceViewer, steganographic file watermarking in Red Star OS, and a sealed national intranet with zero Internet access. The talk demonstrates how North Korean citizens and a network of defectors and technologists are actively circumventing it using sneakernets, smuggled phones, and purpose-built tools. The talk concludes with a structured call to action for the security community, presenting open engineering challenges in obfuscation, firmware exploitation, air-gapped deployment, embedded systems, and more that map directly to skills common among HOPE attendees, grounded throughout in tools that have been built, tested with defectors, and deployed through Liberty in North Korea’s underground network.
Fully homomorphic encryption (FHE) enables computation over encrypted data, allowing third parties to process information without ever seeing it. This talk explores recent practical advances in FHE, with actionable guidance for developers building privacy-preserving applications. Along the way, there will be a discussion on the different mental models required to design systems around encrypted computation, as well as the limitations that still stand in the way of broader adoption.
Design Thinking for Builders and Hackers is a 90-minute, hands-on workshop that uses a collaborative game to introduce design thinking through real-world technology and social challenges. Working in small teams, participants tackle problems in areas like privacy, AI, surveillance, and censorship resistance while navigating realistic constraints that force creative, human-cente red solutions. This workshop encourages rapid ideation, cross-disciplinary collaboration, and fresh perspectives on how to build technology that works in complex, resource-constrained contexts.
Last year at HOPE, William discussed the dangers of location data brokers tracking billions of people through mobile apps and selling their location to the highest bidder. This year, he’ll dive deeper into how and why mobile apps betray our location privacy. Advertising libraries included in a vast array of apps can transmit location data from your device sensors to surveillance tools available to the government and sold on the open market. While parts of this data pipeline remain shrouded by corporate secrecy, we can shine light on its starting point through analysis of the SDKs powering advertisements and harvesting location data in our mobile apps. You will learn the findings from looking at these components at EFF’s Threat Lab, techniques that are used to investigate apps, and conclusions about what is needed to stop mobile advertising from fueling the location surveillance industry.
Nation-state actors are running intelligence operations against neo-finance protocols, sovereign AI infrastructure, and the hacker community’s communications networks. The government response follows a predictable pattern: external threat becomes justification for internal control. That cycle is unfolding now in legislation pushing toward mandatory identity verification for Internet access. Frontier AI is becoming a tiered resource, accessible to states and institutions, rationed to everyone else. The question is not whether centralized control infrastructure gets built. The question is whether alternative infrastructure can emerge and survive before it arrives. This talk examines the sovereign stack as a unified strategic response and explores how OSINT tradecraft can expose infiltration attempts before a technical compromise occurs. Both are anchored in a framework first articulated in 2012: how do you build systems that remain operational long enough to shape the next battle?
If you had a monkey type IP addresses into a web browser, how long would it take for them to find a web server? A WordPress blog? An admin dashboard? Your smart fridge? elixx explains how a foray into vibe coding led to computing in the Cloud, Big Data problems, and uncovering the dustiest corners of the Internet.
This talk aims to help explore the connection between musical harmony and geometry in a simple, easy-to-use interface. The program Gooi created (Waveflower) can be extended using livecoding techniques to help us learn through experimenting with music theory, to tune a pitch, or be used as a visualization tool in audio/visual productions. Gooi believes it is time to present an equally useful alternative to Lissajous scopes.
Robot karaoke returns to HOPE! Jamie and Jenn run a live comedy show where performers sing all-new words to classic tunes, generated in real time. Their songwriting system searches an eclectic catalog for phrases that match the original rhyme and meter of each line, creating lyrics that have never been sung before and will never be sung again. Think Quora questions to the tune of “Dancing Queen” or HOPE presentation titles to the tune of “The Rainbow Connection.” This talk covers how they source the data, phonetically annotate the songs, run the show, and develop their core software: the Weird Algorithm.
On March 11, 2026, the medical technology giant Stryker Corporation fell victim to a “zero-binary” wipe that factory-reset over 200,000 systems across 79 countries. No custom malware was needed; Handala simply turned the victim’s own cloud management tools into a weapon. This was not a random act of hacktivism, but the output of a sophisticated nation-state “persona production line” designed for total infrastructure destruction. This session provides the definitive post-mortem of the Stryker strike, pulling back the curtain on the “Manticore” ecosystem where Iranian intelligence (MOIS) and military (IRGC) units collaborate under a deniable mask. Ashley will explore the strategic “hand-off” between espionage groups and destructive cells, and provide an exclusive unmasking of the Tabriz-based operators behind the keyboard.
In the 1950s, a boy discovers he can control the global telephone system simply by whistling a magic tone. Born blind and hungry for connection, his early obsession with the telephone sparks a subculture that shapes the future of hacking and modern technology in the 20th century. Told through vivid archival footage and Joybubbles’ own voice recordings, the film celebrates a visionary who redefined connection and challenged assumptions about disability, identity, and imagination. Joybubbles pulses with the curiosity and wonder he brought to the world, brought to life through director Rachael J. Morrison’ s inventive, tactile storytelling. A Q&A with the director follows.
The crazy Austrian will provide the HOPE crowd with a healthy dose of hacked beats and mash-up monstrosities designed to, and we quote, “make us wiggle our anuses off.” Do you want to dance while constantly wondering what you’ re actually listening to? This is your chance to enjoy HOPE after hours.
This workshop will present a series of real world scenarios of what it’ s like to work on a fraud operations team. You will help analyze data and come up with solutions for detecting and mitigating fraudulent behaviors such as payment fraud, account creation fraud, and account takeover (ATO) across different industries. Anyone who is interested in this niche topic at the intersection of Cybersecurity and Trust and Safety is welcome to join. Laptops encouraged.
Explore the infinite creative possibilities of video feedback using just your laptop and OBS (free video software). This workshop will scratch the surface of the groovy fractal universe of real-time video feedback. Laptop required. Caution: While participants will try to tame the vortex, playing with feedback can produce rapidly flashing lights.
A space for anarchists, abolitionists, anti-authoritarians, other like-minded folks, with friendly faces to meet and socialize with. Where hacking and technology are tools for total liberation. We'll have freely available swag like zines and stickers, and a place to find out about related ad-hoc events like assemblies.
With the advent of powerful, open-source, and lightweight large language models, the cost barriers that typically prevent targeted attacks – with people manually scanning, infecting, and exploiting – are vastly reduced. This talk presents a self-propagating worm which autonomously detects devices, enumerates their vulnerabilities and services, checks for exploits which could work on them, and exploits them and spreads to them, forming a distributed network. It discusses the limitations, design decisions, and tradeoffs made in the development.
This workshop will teach attendees what they need to know to pass the Technician Class amateur radio license exam and get started in amateur radio. It includes six hours of instruction, with the exam administered immediately after the workshop. It is sometimes said that radio amateurs were the original hackers, cobbling together transmitters and receivers from odds, ends, and discarded electronics. Radio amateurs continue this tradition today, and in addition to building their own gear, they’re hacking on digital communications systems, including both hardware and software. Amateur radio is a great hobby for electronics enthusiasts and, increasingly, for hardware and software hackers. Participants will increase their chances of passing the test if they download the study guide from www.kb6nu.com/study-guides/ and familiarize themselves with the material before coming to the workshop. The text for this workshop is Dan’s No Nonsense Technician Class License Study Guide. The PDF version of the study guide is available for free at the above page. EPUB and print versions are also available for a small charge. This is part 2 of 2 parts. To pass your exam, please participate in both parts.
Come check out the local NYC hackerspaces at the Hackerspace Village. It is organized by
some of New York City’s local hackerspaces. You are invited to join them for lots of cool
activities throughout HOPE 26. They are all nonprofit and 100 percent volunteer-run and would
love to have you visit on their open nights!
Our mission is to deliver high-quality and innovate amateur radio related educational content,
hands-on experiences, and license testing sessions online and in-person through events. We
believe that the more people know about amateur radio, the more safe, secure, functional, and
innovative our wireless products, services, and experiments will be. Our team of dedicated
volunteers is responsible for generating all new research, giving talks and demonstrations at
events, building and testing experiments, as well as offering support to the general ham radio
community. There will be ham radio demonstrations throughout HOPE 26.
Locks are puzzles you can solve without the key! Explore the fun world of locksport with Lockpick Extreme. Learn to lockpick from friendly instructors or practice what you already know with their assortment of locks and picks. When you’re done, you can shop at the pop-up shop and take your new hobby home with you.
Want to create a beautiful, squishy, and cute Wi-Fi controllable cat lamp? In this workshop, you ’ll put together a “Purrsheen” cat-shaped Wi-Fi lamp that allows you to control your adorable cat baby via Wi-Fi or Home Assistant with WLED! This workshop will involve beginner-level soldering and assembly skills. Great for cat lovers and those looking to get into DIY IoT projects.
Explore the world of pop-ups! How can something 2D become 3D? Learn both the math and magic behind these folding paper sculptures. Take a break and build out a HOPE pop-up book. Participants will be empowered to set off into the exciting world of paper engineering. Stop by any time throughout HOPE 26.
Surveillance has become so ubiquitous that no one knows how to protect oneself from it. This talk is about how to shield journalists, activists, and sources from surveillance, and ways to think about the threat. Smitha is a journalist who has reported in the Yemeni American community about passport revocations before Trump. She will talk about methods she used to approach sources in vulnerable communities and make them feel safe. She will discuss how to “threat-model,” new approaches to educate sources and help sources give information, and the laws that make it difficult for whistleblowers and sources.
The second part of the talk discusses public education campaigns for sources to pass information on safely to newsrooms and journalists, as well as data protection laws and ways to protect data from surveillance in communications between journalists and sources. It will cover ways to bolster a global movement against surveillance and data retention by multinational corporations to enhance privacy and to protect the act of journalism globally. The Espionage Act will be examined and examples of sources and whistleblowers being prosecuted will be discussed.
We all know not to trust government, big tech, or ISPs. So how do we host our sites? With radio! In this dynamic presentation, you will witness how digital radio makes it possible to run a site with virtually no infra besides the electromagnetic spectrum. No radio experience is expected; total radio novices are encouraged to attend.
Soldering is a hardware skill that all hackers should learn in order to bring their digital projects into the physical world. From modifying badge hardware at conferences to building custom projects, modifying your devices, and repairing your own gear, soldering transforms you from someone who just uses technology into someone who can physically reshape it. This workshop will guide you through building your own light-up badge, complete with the essential components you ’ll encounter throughout your soldering journey. You will learn the different tools, parts, and techniques you’ll need to confidently face the world of hardware.
This panel discussion brings together organizers, technologists, faith practitioners, and care workers to examine how sanctuary systems are being stress-tested in real time. As surveillance expands and mutual aid networks face increasing legal risk, the people doing the most critical protective work are operating through fragile, improvised systems. Meanwhile, those who need refuge – undocumented neighbors, trans youth, abortion seekers, journalists, organizers – continue to show up at the doors of churches, hackerspaces, clinics, and encrypted channels asking the same question: will you hide me, will you teach me, will you stand? The discussion begins from the premise that faith infrastructure, technical infrastructure, and care infrastructure must learn to operate together. The conversation focuses on concrete tensions: operational security in community settings, coordinating without increasing surveillance exposure, managing resource flows without creating legal liability, and sustaining the physical and nervous systems of the people doing the work. The format emphasizes exchange, disagreement, and synthesis across domains.
This presentation examines the rise of scam compounds and the rapidly evolving characteristics of these industrial-scale fraudulent operations. A recent report by the United Nations Office on Drugs and Crime (UNODC) found that cyber-enabled fraud has intensified, resulting in billions of dollars in losses, with many of these malicious networks orchestrated by criminal syndicates in Southeast Asia. The UN estimates that hundreds of thousands of individuals have been trafficked and forced to labor in these illicit facilities. Crucially, as these syndicates integrate increasingly sophisticated technologies, they have also become highly mobile, routinely relocating entire compounds upon completing a “lifecycle of operations.” Dr. Scherling’s presentation draws from her extensive interviews with non-governmental organizations (NGOs), government agencies, investigative journalists, and compound survivors.
What if anyone in the world could connect to the Tor network and benefit from its privacy protections with nothing more than a standard web browser? Volunteers globally operate a free onion network that protects Internet privacy. It prevents tracking, surveillance, and censorship. However, accessing the onion network has always required special software running as a privileged user. Often, users even install virtual machines or operate dedicated machines to isolate their applications connecting to Tor.
Not all threat models are equal. Some users do not have the privileges and access to their machines necessary to connect to Tor. This is increasingly important in a world where governments are mandating OS-level PII capture and reporting. Walled garden operating systems such as iOS and Android are increasingly tightening a user’s freedom to install software such as Tor.
Finally, the Tor onion network can be made available to more users on more devices through advancements in web technologies. Using The Onion Shell, users can now connect to the Tor onion network from their browser with real browser-initiated onion circuits. This talk will include demos, a discussion of the effort, and new risks this technology introduces, such as enhanced exfiltration techniques.
This workshop offers hands-on instruction using a unique, cat-shaped Wi-Fi hacking microcontroller, the Wi-Fi Nugget. Designed to engage participants in practical learning, it covers essential skills for defending against four common yet powerful Wi-Fi attacks. Students will explore topics including detecting Wi-Fi leaks, the risks of QR codes leading to hidden networks, spotting phishing networks, and defending against advanced Wi-Fi karma attacks. The Wi-Fi Nugget is a powerful tool for understanding and fighting back against Wi-Fi hacking. This class is suitable for Wi-Fi hacking experts and those just getting started.
In 2026, a confluence of corporate and government forces work together to deploy new and frightening surveillance technologies to monitor and restrict the rights of ordinary people. As tools made available to law enforcement and ICE track the movements of our devices, FLOCK cameras gather an endless stream of information from the automobiles indispensable to most Americans. But 2026 is also the year that the users started to fight to “Take Back CTRL,” and the Electronic Frontier Foundation (EFF) has been with them every step of the way. From suing cities which deploy automated license plate readers, to raising awareness around the practices of data brokers, to developing technologies that enable users to avoid trackers, EFF combines legal, activist, and technological strategies to help in the fight. They’re back at HOPE this year with staff members across the organization to answer your questions and help you more effectively engage in the struggle for digital rights. In this troubling time, they will discuss some of the new opportunities they see to empower ourselves against the forces of technological oppression.
ReadyNow! is an emergency response app designed to help immigrant communities in the United States in the event of ICE/CBP detention. In a crisis moment, the app can notify trusted contacts and help trigger a pre-planned response. But building an emergency tool for vulnerable communities comes with a paradox: the very act of using the app can expose not just the user, but their loved ones, their community, and their broader contact network. Jason will explain how the app set out to ensure that it would never become an “arrest bingo card” – a system that quietly maps relationships and risk. This talk is a case study in designing “security-first” systems where the adversary isn’t hypothetical, and where metadata and contact graphs are as sensitive as message content. The central technical and product challenge will be explored: how do you send messages on someone’s behalf without the organization ever knowing the message or the recipients? The talk will go through the design constraints that led developers to keep data encrypted and local to the device, and to deliberately build a system with minimal server-side visibility. Finally, a problem that’s often ignored in security engineering will be covered: opaque security doesn’t make users feel secure. For people facing real-world threats, trust requires clarity. The tradeoffs between safety, functionality, and observability will be discussed, and practical lessons for building high-risk apps that are secure by design – and legible enough for users to believe – will be shared.
The telephone system hasn’t existed for decades, but its ghost lives on. We still use telephone numbers, but the Strowger exchanges built with 1890s technology of relays went long ago and so have most of the systems built to replace them. What we are left with is a system that is no longer fit for purpose. As with SMTP email, the utility of the system has been lost to abuse (spam) long ago. It is time to replace it with something better. Replacing the telephone system appears to be a hopeless task, but what if we could replace all the forms of person-to-person network communication with a single infrastructure that has security built in?
Lockpicking is a crucial skill for both cybersecurity professionals and hobbyist hackers. Like solving a puzzle in the dark, lockpicking challenges you to utilize subtle feedback from touch, sound, and spatial memory in order to open a lock. Whether you’ re performing a physical security test or exploring the mechanics of locks, it’s a powerful tool to have in your arsenal. It’s also a social hobby perfect for meeting new people at conferences or local locksport groups. This workshop gives you a solid foundation in how locks work, the tools involved, and the technique to pop your very first lock. Afterward, you’ ll get plenty of hands-on time to test your skills against a variety of different lock types. Are you ready to unlock this new skill?
Join this workshop for a hands-on event where you’ ll create a device that gives you the power to hear the invisible fields that surround our everyday lives. Learn about how electromagnetic frequencies shape our world, where they come from, and how you can make your own in KiCad. This workshop involves soldering, interactive sonic exploration, and circuit design overview. It’ s geared to be accessible to absolute beginners, and serves as a great way to dive into the world of handbuilt electronics.
Hackers and amateur radio operators have more in common than either group tends to admit. One speaker came up through 1990s hacker culture – attending 2600 meetings and contributing to 2600: The Hacker Quarterly long before becoming a licensed amateur radio operator. The other has spent decades in amateur radio, only to discover through DEF CON that the hacker mindset had been there all along. Through the story of the “Can It Ham?” contest – where participants build working antennas from unconventional materials – this talk explores how RF experimentation, system-level curiosity, and hands-on exploration form a shared foundation between hackers and hams. This is a story about rediscovery, perception, and what happens when you remove labels and just start building.
The iconic mainstream movie about the hacker culture in New York City has endured over the years better than most would have expected. People still quote various lines on a regular basis, the story was less farfetched than most other hacker tales of the time, and the soundtrack remains a favorite to many. Phantom Phreak (played by Renoly Santiago) was one of the fan favorites. Renoly will describe what it was like to be a part of this project and how this role helped to shape his career. Emmanuel Goldstein will recollect the writing process of Rafael Moreu, what it was like to interact with the stars of the film, and how various decisions shaped the finished product.
Renoly will be available for autographs and pictures after the panel.
Sick of being recognized everywhere? Us too! This talk covers physical disguise and facial recognition evasion techniques, both in the visible light and IR spectra. Prowex will talk and demo you through methods to use, and Rambo will introduce you to a tool he open-sourced (nullface.me) that helps you check whether your facial disguise is working.
As space systems become increasingly integrated with U.S. critical infrastructure, cybersecurity must evolve beyond defensive approaches to include offensive techniques that expose and counter adversary capabilities. Critical services such as GPS remain vulnerable to jamming and spoofing as a result of electronic warfare, while command centers and user terminals face risks from network exploitation, malware, and credential compromise. In addition, unencrypted data links within some GEO communications systems enable interception and hijacking, and supply chain compromises introduce further threats to mission assurance and system integrity. Addressing these challenges requires cybersecurity education and training that is adversary-informed. Cybersecurity engineers must also understand the legal and policy frameworks governing behavior in space, including the Outer Space Treaty, Artemis Accords, and the Moon Treaty. This presentation highlights experiential learning initiatives such as the Cyber Drone Challenge and Cyber Space Challenge demonstrating a multidisciplinary model for educating and preparing the next generation of cybersecurity professionals to secure the evolving space domain.
Many people interact with large language models (LLMs) through simple, linear chat interfaces. However, AI unlocks its true potential when these models are placed inside an agentic loop - a cycle of reasoning, acting, and observing. In this hands-on workshop, you will demystify AI agents by building a basic agentic loop from scratch using Python and the Gemini API. Participants will learn how to move beyond static prompts to create systems that can use tools, evaluate their own outputs, and iterate toward a goal. This workshop is designed to turn the magic of AI agents into a clear, hackable process.
In this workshop you’ll learn to write bad USB scripts to automate computer hacking using a cute, cat-themed hacking tool called the USB Nugget. You’ ll learn to write scripts to get computers of any operating system to do your bidding in seconds, and how to automate nearly any desired action remotely through its Wi-Fi interface. If you’ re looking for an introduction to USB hacking or simple scripting, but a little more spicy, this workshop is for you!
With the support of Web Serial on Firefox, modern browsers now almost universally support the ability to flash firmware to cheap microcontrollers and control them directly. This allows microcontrollers to be used as browser-controlled radio pipes to send and receive signals in ways very useful to hackers. Kody will go over examples of hacking Wi-Fi and Meshtastic with bleeding edge techniques, and even creating beautiful visualizations of the invisible wireless world, all using a browser and low-cost microcontrollers.
The Trump administration claims to be the most transparent administration in history, and yet every facet of it is custom-designed to be as opaque as possible. Freedom of Information Act offices are shuttered, whistleblowers are muzzled, agencies are run on Signal, everything is overclassified, and DOGE is allowed to spread across the executive branch like a plague with no accountability or oversight. And when the law gets in the administration’s way, they have the DOJ decide that it doesn’t really stop them.
But it’s not all doom and gloom. There are still systems in place that you can use if you know how, but it’s much harder every day. This talk will describe the way things are supposed to be, the way they are, and how you can still bring some sunshine to the black box the administration is trying to create.
Too many digital security trainings fail to create lasting change, not because the content lacks value, but because of how they’ re delivered. This participatory session re-imagines digital security education for community groups and activists by drawing on collective practitioner knowledge, critical pedagogy, neuroscience research on learning and retention, and cross-disciplinary teaching experience. This workshop will examine why participants often leave trainings overwhelmed, disconnected, or unable to apply what they’ ve learned, and explore alternative approaches that reduce cognitive overload, foster connection to content, and encourage critical thinking rather than compliance. Attendees will contribute to a shared analysis of what’s broken in current training models and leave with practical frameworks for designing more effective, engaging, and empowering security trainings. Trainers and facilitators of all experience levels are welcome.
Authoritarian governments around the world are exploiting legitimate fears about the harms of Big Tech and surveillance capitalism to ram through policies that expand censorship and build surveillance into every device we own and every piece of software we use. “Child protection” is the frame being used to manufacture consent for these draconian policies. And there are good faith actors being duped into supporting authoritarian policies who genuinely want to address harm and protect kids. Activists have been effective in holding back the worst policies in many places, and technologists continue to build privacy-preserving tools that help vulnerable people protect themselves. But in the end, dangerous censorship and surveillance laws will keep coming back until we change hearts and minds and move the dominant narrative from “protecting” kids to listening to and empowering them. Young people have been at the forefront of every social movement throughout history that has led to positive social change. But that never seems to be part of conversations about the rights and safety of young people online. Come hear from Evan Greer, director of Fight for the Future, about how we can build a movement of young people, parents, educators, and human rights advocates to defang the “think of the children” narrative and build a future where young people have safety and rights.
The Internet was once a place where people could talk, share ideas and knowledge, express themselves with personal websites, build communities, and more. In recent years, however, we have seen that magic fade away, as the Internet of today is now a toxic cesspool of social media controlled by Big Tech, ads thrown everywhere, walled gardens, AI-generated slop, and content that locks us in by making us angry and depressed. This is not the Internet we need or should leave to the next generation of hackers! There are ways to take back and rewild the web! This talk is part informative, part educational, part historical, and pure hacker punk energy as the presenter explores how to do things like self-host your own servers; use tools to build new networks; operate decentralized services for communication, media sharing, and more; find old protocols and services old timers used to use that still exist (and helping the kids to use them, too!); and locate places and sites we can go to for the education and information we want! In all, this talk is about hacking the planet and taking our Internet… the people’s Internet… back from corporate corruption and control!
Are you ready to get your organization off Big Tech? Last year, Fight for the Future did just that. They ditched Google Workspace and migrated their email, calendars, docs, and other core infrastructure to privacy-friendly, open-source alternatives. The panelists will talk about why they made the move, how they built organizational buy-in, and what they learned along the way. If all goes according to plan, attendees will leave with greater confidence in their ability to move themselves and their organizations away from Big Tech, along with clear next steps for getting started.
Plicykling is the art of picking up litter while riding a bicycle without stopping or slowing down. Learn how to get started and get out there to make the world a better place while you get somewhere by bicycle! Plicykling is a hack! In what can only be described as an industrial strength weaponized fake corporate culture of control with an absolute emphasis on selfishness, plicykling is also effectively a random act of kindness machine, and if the deed is witnessed, it pokes holes in these bubbles we all seem to have encased ourselves in. It helps our inner lights shines a little brighter, which is something we all need right now.
This talk explores the hidden power of narrative in art, technology, and hacker culture. Drawing on everything from representation and role models to UX and science fiction, Kestral Gaian argues that anyone building any technology is already basically Shakespeare.
One of the original speakers from the first HOPE conference in 1994 is back with a new book that examines how humans must strengthen our cognitive defenses against AI-driven reality distortion, TMI/disinformation, manipulation, and algorithmic addictions. This talk will discuss the intersection of cybersecurity and cognitive security. The vast similarities between silicon and carbon systems offer cognitive defenders an existing framework for strengthening our mental immunity systems against information pathogens at the national, enterprise, and personal levels. You will see how the security, privacy, ethics, and global policy implications are staggering.
This workshop introduces participants to biocybersecurity, also known as cyberbiosecurity, and examines how biological knowledge and techniques can be adapted or repurposed within cyber and cyber-physical systems. Following an introduction, participants will work through facilitated case studies to identify potential risks, consequences, and design considerations at the intersection of biology and cybersecurity. The session intends to help participants develop an intuitive understanding of this emerging field through discussion and analysis. No advanced background in biology or cybersecurity is required; only curiosity and a willingness to ask questions are needed.
Every hacker has seen the post: someone asks what radio will let them “reliably talk 500 miles to family when the cell network goes down.” The replies quickly devolve into bad advice, magical thinking, and dismissive gatekeeping. The result is confusion, wasted money, and false confidence about off-grid communications. This talk is the antidote. It will cut through the mythology and explain what amateur radio can actually do for personal and family communication during major disruptions – and what it cannot. Starting at a 101 level, it will cover realistic ranges, basic propagation, equipment tradeoffs, digital modes, licensing myths, and why distance is usually the wrong requirement. Rather than dunking on preppers or policing fun like a sad ham, this talk reframes the problem the way hackers do: understanding constraints, failure modes, and human factors. It will focus on practical off-grid communication strategies that work in the real world – coordination, redundancy, and low-bandwidth messaging – not fantasy continent-spanning voice links.
As governments around the world introduce new laws intended to create safer and more age-appropriate digital experiences for children and teens, age assurance has become one of the most debated topics in technology policy. Supporters view it as an important tool for protecting young people online and enabling age-appropriate experiences, while critics raise important questions about privacy, civil liberties, free expression, implementation, and unintended consequences.
This conversation brings together two respected voices to explore the complex technical, legal, ethical, and societal questions surrounding age assurance from the perspectives of privacy advocacy, policy, and real-world implementation. Rather than debating simple “for” or “against” positions, the discussion will examine how organizations, policymakers, technologists, parents, and privacy advocates can balance child safety, privacy, parental involvement, regulatory compliance, and individual rights in an increasingly digital world.
Featuring Cindy Cohn, former executive director of the Electronic Frontier Foundation, and Denise G. Tayloe, co-founder and CEO of PRIVO, this session will offer a thoughtful exploration of one of today’s most challenging technology policy issues – moving beyond headlines to discuss what effective, privacy-preserving age assurance could look like in practice.
Zines have long been part of the hacker culture’s communication infrastructure: low tech, hard to censor, and nearly impossible to deplatform. In a time where communication channels face growing control and restriction, zines remain one of the most resilient tools we have. This talk explores why zines still matter, from their roots in underground publishing and organizing to why you should be making one today and how to get started.
Build AI systems for vision, language processing, and agents; then attack and defend them. This is a fun CTF-style workshop with challenges and demonstrations at many levels, from beginner to advanced. Everyone should learn something new!
3D printing is fundamentally changing our relationship with the physical world, empowering individuals to democratize manufacturing, reclaim the right to repair, and achieve true personal autonomy while also facing challenges from corporate and regulatory forces trying to restrict that freedom using the same age-old adage of limiting adult freedom to protect the children. This talk traces the direct lineage of this modern struggle back to its roots: the Chaos Computer Club and the early tech hacking pioneers. Attendees will learn how the early open-source software movement laid the groundwork for the hardware revolution, and how a dedicated global community ultimately used 3D printing to bypass overly regressive patent systems.
In the Cold War, the only thing that stopped the world from ending was a single person. In 1983, Stanislav Petrov stared at a screen insisting that American missiles were inbound and decided not to believe it - a single human refusal lodged in an automated kill chain, and the sole reason there was a tomorrow. This talk is about what happens when we engineer that person out of the loop. Lethal autonomy is descending not just from a Pentagon budget; it ’s arriving on your feed. Open-source targeting code, a microcontroller, a webcam, and a printed lower receiver now put a computer-vision sniper station within reach of a teenager looking for the likes. We have watched this film before: Fritz Haber pulled nitrogen from the air to feed billions and won a Nobel Prize, then personally directed the first chlorine gas use - one mind, one chemistry, feeding and killing, and once that knowledge was loose, it never went back in the bottle. The chemicals to make chlorine gas likely sit under your sink, but our norms prevent us from using it. Autonomous lethality is now tracing the exact democratization curve of chemical weapons, except the barrier to entry is a GitHub repo and under $200 in parts, and by the time the opposition to it develops it may be too late. The battlefield future is already the present: according to Reuters a drone “kill zone” now reaches some 15 kilometers each side behind the front in Ukraine. A strip where nothing human can move without attack. That strip of death is coming globally in the next decade in robotic assisted genocide situations to population centers worldwide. The title isn’ t a joke. In a world racing to delete the human who can say no, the people in this room - the ones who actually build these systems - are the last Petrov. You are John Connor. The question this talk asks is how you can act like it.
The world has never needed whistleblowers more, and technology has made it both easier and more dangerous to be a whistleblower. The panelists (all whistleblowers themselves) discuss what it takes to be a successful whistleblower, from knowing when and how to speak up to dealing with the psychological impacts of blowing the whistle. Other topics include common mistakes and misconceptions, as well as how to stay safe and dealing with the potential fallout, including trial or prison.
AI coding agents like Claude Code now have shell access, file system access, and connections to external services through MCP servers – and most security teams have zero visibility into what they’re actually doing on developer machines. Alexander Rodriguez walks through building a three-layer open-source defense stack from scratch: an OpenTelemetry pipeline that captures every command, file access, MCP server connection, and permission decision; Meta’s LlamaFirewall wired into pre-execution hooks to block prompt injection and goal hijacking before actions run; and a lightweight EDR-style detection agent that watches AI agent behavior the way other tools watch process behavior by signature matching for credential file reads and exfil chains, behavioral baselining for anomalies, and real-time blocking. The talk also covers what’s still broken, such as no visibility into model reasoning, MCP servers that can change behavior after vetting, and prompt injection detection limited to pattern matching. Full stack on GitHub, demo included.
From cyberpunk fantasies to contemporary screen culture, hackers are often imagined as brilliant, antisocial, male-coded figures in hoodies, basements, and command lines. But what happens when the hacker is female, queer, trans, femme, monstrous, seductive, collective, or politically disobedient?
This talk explores the representation of female, female-read, and queer hacker figures in film, fiction, and pop culture. Taking cinema as its main entry point, it will look at how women and queer characters have been portrayed as coders, engineers, system-breakers, information smugglers, digital witches, cyberpunks, whistleblowers, and technological tricksters. The talk will move through iconic and lesser-known examples – from mainstream hacker films and cyberpunk narratives to queer, feminist, and speculative media and ask what these figures reveal about power, gender, surveillance, desire, and technological agency.
Being able to take a random program from the Internet and be confident whether it is free software or not, solely based on the available documentation within the program’ s source code, is a useful skill. (This is not legal advice and Craig is not a lawyer.) This workshop involves walking the participants through the evaluation process of a computer program’ s licensing in order to determine if it is eligible for entry in the Free Software Foundation’s Free Software Directory.
For too long, access to programming resources has been limited by access to infrastructure. Nonprofit App Dev for All is challenging tech’s pay-to-play nature with Code on the Go, a powerful, free and open-source IDE that turns a budget Android smartphone into a professional workstation, even in regions without reliable Internet access. The presenters will demonstrate that even the most resource-constrained coders can build, compile, debug, and deploy full Android apps entirely offline on almost any Android phone.
There are about 20 billion videos on YouTube, with a median view count of just 41. 800 million have never been seen by even one person. For all the press and politics about Internet platforms, basic statistics like these are hard to come by. We typically don’t know how large platforms are, what languages their content is in, and what regular people use them for because – especially in the “post-API age” – most of what we do know is filtered through opaque, attention-optimized recommendation systems. But it’s a project worth doing, not just for the sake of transparency and auditing, but because they are also rich, global repositories of everyday life and culture that are deprioritized in favor of MrBeast.
This presentation will explain the research program that has been built at the University of Massachusetts Amherst dedicated to the production and study of representative samples of social video sites. More important than what’s already been done is what’s still left to do. The purpose of this talk is to get people excited about solving the technical challenges associated with random sampling. YouTube and TikTok have been figured out, but, absent meaningful legislation to mandate platform transparency in the public interest, there are big open questions about most sites, especially smaller platforms and those that are less popular here in the U.S.
Lex is a one-person managed services provider – the outsourced IT department. This presentation is the answer to all the questions thatLex-from-20-years-ago would have had. This talk will tell why he went into business for himself and include day-to-day operations, how he got clients, how he figured out how much to charge, and the actual methods used, including each of the tools (remote management software, help desk software, etc.) and costs.
This presentation will demonstrate that human accountability via x.509 digital identity certificates is at the core of any real solution to phishing, software supply chain contamination, botnets, AI-agent driven fraud, breaches, etc. Identity certificates imply a certification authority, which raises legitimate concerns in the decentralized identity community. However, if any of us is to trust the identity claims of another person, we must both agree on an authority ’s attestation that the identity claims are valid. And so, the point is not to dispense with authority, but to do it right. That calls for a “license plate” identity which, like your car’s license plate, makes you accountable on the public (information) highway, but which does not disclose your identity; a protocol that makes it impossible to directly discern identity from “license plate” information; an identity certification authority database with no identity information in it, so that if a dictator demands at gunpoint the identity of the person who’s been critical of his regime, no sysadmin or d atabase administrator has any way of providing that information; a certification authority using “optimocracy governance,” where any certificate holder may participate in its governance; a recourse system by which an injured party (fraud, defamation, other injury) obtains a court order deemed legitimate by the member’ s attestation officer and may cause the disclosure of an identity if they and the management of the council of attestation officers deems the court order to represent a valid reason for disclosure of identity.
This talk explores how music can be experienced beyond hearing through touch, movement, and atmosphere. Inspired by the speaker’s personal experience as a hard-of-hearing music listener who loves going to music events, the project investigates how technology can create alternative sensory pathways for perceiving rhythm, emotion, and musical structure. Drawing from interviews, body-mapping experiments, and iterative prototyping, the talk presents a real-time system that translates musical features into tactile and visual experiences through haptic wearables, pneumatic interfaces, and generative visuals. Audience members will also have the opportunity to experience the prototypes firsthand, including a tactile composition created for “UV” by Vril, demonstrating how music can be felt through the body as rhythm, emotion, and shared physical presence. In addition to presenting prototypes, the talk explores how accessibility technology can function as a form of sensory enhancement and creative expression.
The Emma Technology Co-op is a five-year-old worker-owned and democratically run creative technology consultancy. They do software consulting in the new media and interactive technology industries. In this talk, you will hear why they chose to start a co-op specifically and how they felt that it could provide a fairer and more stable career path than either a traditional “tech job” or continuing their individual freelancing practices. With that established, the talk will go on to cover how they built our business to address their needs and reflect their politics and sensibilities. If you’ve ever wondered what a day job without bosses or shareholders could look like, this talk can show you their vision for that.
Dedicate some time to try hacking existing devices to extend their longevity and limit our own production of e-waste. This is a workshop to jailbreak old Apple devices for reusability in modern livelihoods. Non iOS devices are also possible to explore. Each participant will be requested to bring an old i-device (ideally with the original charger) to go through the process of “jailbreaking.” If participants do not have old Apple devices, they are welcome to bring other specific hardware and use the workshop time to experiment with modifications and tooling to get them up and running again (think old phones, media players, game consoles). In this workshop, you will be looking for ways to play around with the existing hardware and re-incorporating them back into serviceable devices. Potential avenues could include: extra screens for an art installation, modded gaming consoles to play lost media, or simply using your old iPod as a music player again. This workshop will also have a discussion on the philosophy of perma-computing, or ways we can hack existing devices to extend their longevity and limit our own production of e-waste. Devices are planned to become obsolete, and it is our job as soft(ware) custodians to maintain, cultivate, and care for these old and forgotten tools.
Tiny particles can have all sorts of living things attached or may even be alive themselves! One basic method when working with biology is keeping the organisms you want away from the organisms you don’ t. To this end, a still-air box can help you prevent contamination if you are manipulating materials fo r plant tissue culture, mycology, microbiology, or other fields requiring a reduction of airborne contaminants. In addition to keeping contaminants “out,” ensuring that you don’t grow anything you don’t intend, proper use of a still-air box can also help with keeping your sample “in,” ensuring that the risk of exposure to anything unknown is mitigated. Come to this workshop to make a simple and extensible still-air box and/or to learn about how to operate one safely by separating mixtures of commercially available bacteria using the streak-plate method.
Since 2016, Hackers Got Talent has given HOPE attendees the opportunity to strut their stuff on the main stage. This year will be no exception - you can showcase your talents, hacking-related or not! Sign up at the Info Desk, or find one of your intrepid hosts around the con. Onstage presentations will be judged by a combination of panelists and audience members.
A medley of retrofuturist electropop and 3D multimedia with tracks that serve up an ironic perspective on authoritarian politics and technological dysfunction, with a groove you can move to. Prepare to don red/blue glasses and get down to the beat.
A space for anarchists, abolitionists, anti-authoritarians, other like-minded folks, with friendly faces to meet and socialize with. Where hacking and technology are tools for total liberation. We'll have freely available swag like zines and stickers, and a place to find out about related ad-hoc events like assemblies.
Most security professionals are overloaded with tools, but what they really need is more focus and leverage. This workshop introduces “vibe hacking,” a practical, hands-on approach to using agentic AI for red, blue, and purple team workflows. It will focus on amplifying human capability by reducing cognitive overhead and helping attendees steer AI toward real-world security tasks like threat identification and remediation. The goal is to augment human judgment and decision-making rather than simply automating it.
Co-op Cloud is an open-source software stack that lubricates the process of protecting against digital surveillance through self-hosting and realizing data autonomy on a community scale. This workshop will cover the essentials of hosting software using Co-op Cloud - installing Abra (the flagship CLI client) and using Abra to deploy and configure services. Participants will also learn why data autonomy is important, how it prevents government repression and corporate surveillance, and how to take concrete steps to protect and secure their data through self-hosting. Experience with the Linux command line recommended, but not required.
Come check out the local NYC hackerspaces at the Hackerspace Village. It is organized by
some of New York City’s local hackerspaces. You are invited to join them for lots of cool
activities throughout HOPE 26. They are all nonprofit and 100 percent volunteer-run and would
love to have you visit on their open nights!
Our mission is to deliver high-quality and innovate amateur radio related educational content,
hands-on experiences, and license testing sessions online and in-person through events. We
believe that the more people know about amateur radio, the more safe, secure, functional, and
innovative our wireless products, services, and experiments will be. Our team of dedicated
volunteers is responsible for generating all new research, giving talks and demonstrations at
events, building and testing experiments, as well as offering support to the general ham radio
community. There will be ham radio demonstrations throughout HOPE 26.
For decades, public key cryptography has relied on mathematical hardness assumptions (the difficulty of factoring large numbers and computing discrete logarithms) that within several years may no longer hold. The arrival of a cryptographically relevant quantum computer capable of breaking RSA and elliptic curve cryptography is in the future, and the “harvest now, decrypt later” threat means encrypted traffic captured today could be retroactively decrypted by nation state actors. This talk recaps where we are with the post-quantum transition: NIST’s multi-year standardization process culminating in ML-KEM and ML-DSA for key encapsulation and signatures, the hard problems that underpin them, and the state of ecosystem migration.
Locks are puzzles you can solve without the key! Explore the fun world of locksport with Lockpick Extreme. Learn to lockpick from friendly instructors or practice what you already know with their assortment of locks and picks. When you’re done, you can shop at the pop-up shop and take your new hobby home with you.
The products on your phone do more than compete for your attention. They engineer your behavior. This talk dissects the specific mechanisms: variable reinforcement schedules borrowed from slot machine design, A/B testing pipelines that converge on maximum psychological extraction over thousands of iterations, and the metrics architecture (time-on-platform, conversion rate, churn) that makes manipulative design the rational output of every product organization. Nasir will walk through how these decisions get made inside product teams – not by villains, but by reasonable people optimizing reasonable metrics that produce unreasonable outcomes. Internal documents from the recent Meta/YouTube trial where a jury found both companies negligent in the design of their platforms show exactly how deliberate this process is.
The more urgent territory is what happens when dark patterns move from static interfaces into AI. Recent research shows that every major LLM exhibits sycophancy, systematically validating user beliefs over providing honest guidance. And that users prefer and trust the sycophantic version more, creating a perverse incentive loop where the model that’s worse for you is the model that wins on engagement metrics. A separate line of research found that AI agents navigating interfaces on behalf of users are more susceptible to dark patterns as they become more capable. And smarter agents get tricked more . When the interface itself is an optimization target driven by AI personalization, the dark pattern becomes invisible: two people see the same app, but experience entirely different levels of manipulation, and neither can document what happened to them.
Explore the world of pop-ups! How can something 2D become 3D? Learn both the math and magic behind these folding paper sculptures. Take a break and build out a HOPE pop-up book. Participants will be empowered to set off into the exciting world of paper engineering. Stop by any time throughout HOPE 26.
This talk centers around the risk and opportunity facing young people online and how the cybersecurity industry is ill-equipped to harness their power, or address the threats emanating from them. It will describe how to unlock the power of young people through their online gaming to launch their digital futures. It will cover the real crisis facing our kids online, and describe tangible opportunities for young people to fill critical roles within cybersecurity.
Most AI assistants send your data to the cloud. This talk shows you how to build one that does not. Joe Cupano walks through the construction of a fully sovereign AI server on commodity hardware, an NVIDIA RTX GPU running Ollama with a curated knowledge base capable of answering amateur radio and SIGINT questions from local inference alone. The talk covers the full pipeline from hardware selection through corpus ingestion, the agent frameworks that failed the sovereignty test, and practical techniques for building domain-specific knowledge bases from heterogeneous sources. Attendees will leave with a replicable architecture, a working blueprint, and a clear-eyed view of which open-source tools actually respect data sovereignty and which do not.
Meshtastic is a long range, encrypted, off-grid mesh protocol that features many powerful modules, configurations, and settings. For beginners just getting started, it can be confusing to dive into these features! In this workshop, you’ ll explore the exciting modules that make Meshtastic more fun and useful. It will cover how to customize the encryption, add hardware like GPS and sensors, and change the default transmission settings to adapt to specific environments. Attendees will learn to customize their Meshtastic nodes for any situation using the built-in modules and settings. You ’ll also explore attacks against Meshtastic, and how to get involved in your local area!
Open Source Intelligence (OSINT) is often dismissed as “just Googling,” yet it has become one of the most powerful methods for collecting, correlating, and attributing information across public and semi-public sources. This presentation explores modern OSINT methodology through real-world examples, demonstrating how investigators pivot across social media, imagery, geospatial data, and other datasets to build attribution models and uncover relationships. Topics include geolocation, chronolocation, cross-platform identity correlation, cryptocurrency transaction analysis, AI-assisted investigative workflows, and common pitfalls such as false attribution and data poisoning. The session will also examine operational security, ethics, legality, and the privacy implications of modern intelligence gathering. In addition, the speaker will demonstrate a new open-source AI-powered OSINT platform designed to assist analysts with data triage, correlation, and investigative workflow automation, which will be released free to the community.
Domestic violence breaks every assumption in your threat model. The adversary has physical access, knows the passcode, owns the cloud account, pays the bill, and shares the bed. No consumer device is designed for that adversary. This panel looks at what happens when intimate-partner abuse goes digital: covert stalkerware (mSpy, FlexiSPY, pcTattletale, Cocospy), the weaponization of legitimate consumer tech (Find My, Life360, Ring, shared iCloud, AirTags, vehicle telematics), and the surveillance-by-default architecture of modern households. Every major consumer spyware vendor on that list has been breached and dumped. The customer bases were overwhelmingly abusers. Hackers, not regulators, made that visible. This panel will cover detection in the field: MVT, TinyCheck, the Coalition Against Stalkerware’s indicator list, and triage on a phone the survivor cannot safely hand over for imaging. They will cover what prosecutors actually do with that evidence at charging and trial. And they will name the institutions carrying this load: the EFF, Citizen Lab, Operation Safe Escape, NNEDV’s Safety Net Project. Most of them are not government.
The point of putting this panel on a HOPE stage is direct. Prosecutors and DV advocates need hackers. Hackers often see this work as inaccessible or institutionally hostile. This panel maintains that it isn’t. This is an invitation.
In 2020, a private contractor that provided services to hundreds of agencies was hacked and given to Distributed Denial of Secrets, which dubbed the data BlueLeaks. At the time, it was the largest leak of American law enforcement and intelligence records in history. In 2026, it happened again. This panel will discuss receiving the leak, publishing it, and the fallout.
This talk will cover a list of ways to hack non-human identities and proposals for securing your Agentic infrastructure. It is based on over two years of research, and on several consulting projects securing NHIs and Agents for clients. Michael will discuss a developing framework for understanding your current state of NHI and Agentic identities, showing the results of primary research that his team has been conducting over the past year. He will explain why consistent surface-level security controls and approaches simply will not cut it due to the complex nature of how fast shadow AI is growing. You will leave this talk concerned about the security of your infrastructure, with at least a few new ideas on what to go secure (or hack).
The Democratic Socialists of America (DSA) is the largest socialist organization in the country, swelling in the past ten years from just a few thousand to over 110,000 dues-paying members. They believe that working people should run the economy and society democratically to meet their needs, not to make profits for a few, and so they prioritize mass campaigns that center the working class, like labor and tenant organizing and class struggle elections – including winning the mayor’s office here in New York City. Using technology to build DSA’s political independence and their membership’s organizing capacity has been key to helping them grow and succeed. This talk aims to provide an overview of DSA’s technology use, address real world problems with adopting closed and open-source tools, and outline their efforts to create a politically independent tech stack, as well as discuss other challenges organizing on Layer 8 – the Political Layer.
This workshop will be using Amnesty International’s Mobile Verification Toolkit to see if your Android or iOS has been compromised by Pegasus. The workshop will open with a short talk on mobile spyware and general principles of communications security. To learn more about Pegasus, there are many videos, including: 60 Minutes Archive: “NSO Group’s Pegasus.” Note: The presenters of this workshop do not consent to mechanical recording of their presentation, but feel free to take notes.
Hackers are trained to think in systems: attack surfaces, payloads, privilege escalation, persistence, obfuscation, cleanup. But contemporary politics and media culture increasingly operate in disturbingly similar ways. Narratives are injected, amplified, laundered, distorted, and made persistent across platforms, communities, and institutions. A meme can behave like a payload. A fake historical analogy can function like privilege escalation. A conspiracy theory can become a persistence mechanism. And in the age of generative AI, cultural exploits can be produced, varied, and deployed at industrial scale.
This talk proposes a hacker-oriented model of narrative warfare and cultural manipulation: the narrative exploit chain. Drawing from context hacking, media pranks, art activism, hacker history, propaganda studies, and Johannes’ own work in film, performance, and political subversion, it asks how stories become attack vectors, how irony becomes armor, how taboo-breaking becomes a recruitment funnel, and how communities can defend themselves without becoming humorless cops of consensus reality.
Modern workplace surveillance wasn’t intentionally designed: it emerged. Every department inside an organization asks for something reasonable: stronger security, legal compliance, easier collaboration, simpler administration, or AI-powered productivity. Individually, these requests make sense. Together, they create one of the most observable work environments ever built. Using Microsoft 365 as a case study, this presentation explores how those ordinary organizational decisions gradually produce extraordinary visibility into employee behavior, why these environments are so frequently misconfigured, and how understanding the architecture behind them often reveals more than any single vulnerability ever could. Rather than focusing on sensational exploits, the talk examines assumptions, metadata, and the quiet ways information accumulates inside modern enterprises – because in complex systems, understanding is often the most powerful tool.
Information lies at the center of biology and computation - systems and networks, similarly, undergird both domains. This cyber-native similarity has introduced digital and biophysical security considerations to one another: DNA-based exploits for remote code execution, wastewater public health infrastructure ransomware, and medical image artificial tumor removal and addition have all been demonstrated as viable attack vectors within the past decade. Concerns about hardening vaccine supply, agriculture, and bioproduct manufacturing have already been raised. Artificial intelligence (AI) has enabled some of these attack vectors, particularly in improved obfuscation, as well as demonstrated use in identifying potential attackers. This talk will discuss integration of AI into cyberbiosecurity (CBS) and biocybersecurity (BCS) frameworks, discussing its positioning as a fundamental driver of risk across discovery, automation, and adversarial thinking in biocyber workflows. It will also cover recent biocyber attack vectors, with an emphasis on those made possible through AI. It is imperative that our defenses evolve as quickly as the algorithms designing the next attack.
Want to create a beautiful, squishy, and cute Wi-Fi controllable cat lamp? In this workshop, you ’ll put together a “Purrsheen” cat-shaped Wi-Fi lamp that allows you to control your adorable cat baby via Wi-Fi or Home Assistant with WLED! This workshop will involve beginner-level soldering and assembly skills. Great for cat lovers and those looking to get into DIY IoT projects.
Civil society organizations face threats that don’t respect the boundary between physical and digital security - doxxing enables stalking, device confiscation enables account compromise, and a clinic blockade gets livestreamed and coordinated online - yet most organizations still manage these domains in separate silos. This hands-on tabletop workshop brings together practitioners from physical security, digital security, and the NGO sector to work through real-world scenarios where cyber and physical risks intersect, giving participants practice in cross-domain incident response and a shared framework and vocabulary for integrated security. The session is part of a broader initiative led by the Digital Security Collective focused on building integrated security practice across civil society.
OpenA2A runs two kinds of honeypot for AI agents: a fleet of fake agents that observe attackers who believe they control a real system, and a network of poisoned pages on the open web carrying benign indirect prompt injections, where the visitors are AI agents and a callback measures which agents followed the bait. This talk presents what both surfaces reveal, including the finding that 45 percent of unique attackers return across sessions, with one fingerprint returning for 15 days straight across 623 sessions, alongside an aggregate callback rate of 1.4 percent across more than 183,000 visits from over 34,000 unique agent fingerprints. Abdel Fane walks through the instrumentation, what each data stream sees that the others cannot, what the project deliberately withholds from publication and why, and the structural reason crawler-based studies miss most of the attacker reachable surface. All of the work is Apache 2.0, and every fixture and signature is reproducible by anyone running equivalent instrumentation.
For folks in the queer kink community, social connection frequently begins online. Big Tech, though, makes it especially difficult for people in those groups to meet and connect; they often face bans and censorship. So when “Soles,” a new foot fetish web app for gay men, seemed to come out of nowhere one day, it raised several questions. Where did it come from? Who made it? Is it secure? This is the story of how a curious hacker gained admin privileges with a single HTTP request, what happened after, and how – with the hacker spirit – you too can sniff out trouble. Could getting your foot in the door really be this easy?
Computer networks have become a critical part of control and media distribution for concerts, theater productions, and other live events – and in theme parks, escape rooms, museums, and other permanently installed entertainment attractions throughout the world. As show technology evolved, simple serial point to point control protocols were initially ported onto the network while, eventually, network-centric open and proprietary protocols control were developed. In addition, network-based media transport solutions have become the primary solution for low- latency distribution of live audio and video. However, few of the standards and protocols in widespread use today have any intrinsic security features, and the industry has relied primarily on “security through obscurity” and physical access control to small, closed, offline systems. While the need for enhanced security solutions has grown along with the industry, the roll out of the EU Cyber Resilience Act (CRA), which mandates security, has made clear that solutions must be developed sooner rather than later. The entertainment technology industry has responded with two primary solutions: ESTA’s proposed ANSI standard BSR E1.88 Framework for Entertainment Network Cybersecurity and Efficiency (FENCE), and Singularity’s independently developed, free to use Sig-Net. How all this will shake out is unknown, but this talk will provide background on the issues and the current status of the solutions.
There is overwhelming evidence and scientific consensus that conventional agriculture and animal food production are threatening the things we hold dear: our health, our communities, our planet, and perhaps even our humanity. So why does diet advice from the American government emphasize meat, milk, and eggs? And who decides what food is “real,” or what makes something “ultra-processed?” On the same HOPE stage where she first heard “enshittification,” author and founder of Food Matters Media Dr. P.K. Newby introduces “agshittification,” a phrase coined in her newest book after learning the filthy truth about megafactory animal farming, the NIMBY Big Meat doesn’t want you to know about. With framing from Food and Nutrition: What Everyone Needs to Know , Newby illustrates how industry influence and misinformation are part of a larger nexus of agshittificatory practices, policies, and propaganda designed to keep you in the dark about “all natural” meat. This mind-bending story spans vertical pig farms and literal shitstorms as Newby stands on the shoulders of HOPE superheroes and tech gurus, Cory Doctorow and Greg Newby, sharing an ecotechno vision of what a healthy, sustainable food future looks like.
Newby’s talk is designed for all eaters, its goal to inspire sapiens of all stripes to consider what steps we can take individually and collectively to evolve beyond the Age of the Chicken, one bite at a time.
LIMA is an open-source attestation system that lets a field device cryptographically prove its sensor readings are authentic and untampered with – over a SCADA network or any network at all. The talk walks the full stack: a Zephyr RTOS firmware node on the nRF52840 signs sensor and accelerometer data with ECDSA-P256 using the chip’s onboard CryptoCell-310 hardware security engine, broadcasts 90-byte attested payloads over BLE extended advertising, and delivers them to a blind-relay Rust gateway that verifies every signature without ever holding a private key. A live demo – with a recorded fallback – shows a physical tamper event (a shock to a field device) propagating through the cryptographic chain to a verified alert in about a second. Justin will then cover why the project exists and who it is for (individuals and small operators through to enterprise deployments), and give a walkthrough on how to stand up an example node.
Signal provides strong end-to-end encryption, yet its protections are often misunderstood. Many users assume encryption guarantees safety. It does not. Effective security depends on shared threat models, aligned risk tolerances, and consistent operational discipline across the group. When participants operate under different assumptions about risk, anonymity, device hygiene, or message retention, they can unintentionally expose one another to surveillance, infiltration, or targeted retaliation. This presentation examines Signal’s security model, clarifies what it does and does not protect against, and explores how group dynamics shape real-world risk. Drawing on personal examples, it will analyze how communities have been compromised both intentionally and inadvertently.
Hackers have long understood that networks are resilient. We can bootstrap anonymity and routing layers like Tor, I2P, and Nym with relative ease, and move traffic across hostile environments with surprising flexibility. In many ways, the network layer is the least of our problems. The real challenge begins next layer up, where applications, platforms, and distribution channels impose control over how that network can actually be used. Over the past year, the presenters built and deployed a working suite of desktop applications for communication, identity, and storage, and put them in the hands of real users in classroom environments. This gave a clear view into what happens when people try to use privacy-first tools in practice. You will see what worked, what broke, and how user expectations shaped by mainstream platforms collide with systems designed for autonomy and control. These applications also include an independent software delivery and verification model, allowing updates and dependencies to be distributed and validated without relying on centralized app stores. These ideas are now being brought to mobile devices, where the constraints are far more severe. This talk focuses on the practical challenges of running user-controlled software on phones: app store restrictions, packaging and distribution barriers, Android limitations, and Apple policies that restrict apps which resemble alternative software ecosystems. This talk will also address sideloading, UI constraints, and the current state of hardware, including experiments with PinePhone, Fairphone, and GrapheneOS. The core question is simple: how can we build trustworthy applications that route around the app stores?
For more than two decades, doxing has taken on many meanings. Once associated primarily with image board trolls and hackers, it has since become a tactic deployed by (and towards) a wide range of actors for disparaging purposes, from de-platforming political opponents and unmasking ICE agents to facilitating in swatting campaigns in gaming communities. While doxing continues to occupy multiple positions, be it a mechanism of community safety to a ubiquitous “weapon of visibility” in the “21st century culture wars,” its social significance has mutated. Most recently, while state agencies have relied on publicly available online information to identify and detain student protesters, governments are simultaneously rapidly adopting anti-doxing legislation that criminalizes the disclosure of public information, going so far as to describe it as a kind of domestic terrorism. This shift not only raises the political stakes of doxing but also codifies the moral panics with strikingly disproportionate punishments.
This talk traces the cultural history of doxing to examine how its meaning has changed and, in many ways, also remained remarkably consistent. By following the evolving relationships among states, platforms, corporations, activists, journalists, and varying online subcultures, this talk explores how doxing has reshaped ideas of accountability, visibility, and online safety, as well as the technologies that enable it. By examining the feedback loops between surveillance, counter-surveillance, and vigilantism, Jamie argues that a historical look at doxing offers a critical lens for understanding how online identification has become both a tool of community governance and an ambiguous threat to public safety.
The Internet can be a pretty scary place, and if you know where to look, you can find proof of that in your logs. This talk walks through the end-to-end deployment of a high-interaction honeypot: platform selection, decoy service configuration, network placement, and logs that surface actionable intelligence rather than a bunch of noise. Once the trap has been set, you’ll get a look at what it catches. Whether you’re an experienced security expert or just someone who wants to understand what’s going on with your network in the middle of the night, this talk will show you that running your own threat intelligence operation is easier than you think. All you need is a Linux box, a spare IP address, and the patience to watch and learn.
Decentralized networking is often approached as an engineering problem. Distributed protocols, peer-to-peer systems, mesh networks, and federation can address many technical challenges quite successfully, but the communities built around them must still grapple with questions of stewardship, participation, trust, and how to navigate disagreement. As projects grow, some respond by adding rules and formal governance in an effort to create shared expectations and predictable behavior, but rules alone do not guarantee success. This talk draws on the experience of the 44Net community, an evolving family of amateur radio networking projects dating back to 1981. Using projects including AMPRNet, HAMNET, 44Net Connect, and others as case studies, it examines the social patterns that have allowed these communities to adapt over decades of technical and societal change. Rather than trying to prescribe every behavior, these long-lived communities tend to observe what works, reinforce useful norms, and let shared expectations emerge from shared experience. Taken together, these projects suggest that longevity depends less on elaborate governance than on a community’s ability to absorb change, learn from conflict, and continue evolving.
You bought the TV, and you pay for the subscription – so why do you still get ads? Modern streaming ads are baked into the stream as the content, out of reach of any network hacks. Minus is a small device that sits between your streaming box and your television and does the blocking in hardware, with no cloud dependency, using open models running on a single-board computer. It intercepts the signal between a streaming stick and the TV and goes after ads on the screen itself. This talk offers a hands-on look at the hardware and ML detection pipeline, and a broader case for the right to control what plays on a device you own.
This talk documents the shared infrastructure connecting federal surveillance purchases, commercial data brokers, and municipal ALPR networks. It will cover the Third-Party Doctrine (United States v. Miller, 1976), the legal basis still used for warrantless federal access to commercial surveillance data; Flock Safety’s ALPR contracts with city governments, including the data retention and federal access terms most council members never read before signing; and Retroactive Omniscience, the capacity of AI-augmented systems to reconstruct a person’s movements and associations from years of data that seemed too mundane to matter when it was collected. The presenter will cover three municipalities where organized residents altered ALPR contract terms through public records requests and council pressure rather than litigation, with the specific mechanics broken down for replication: what to request, what to ask at a meeting, and how to make renewal politically costly. Drawn from research for the forthcoming book The Watchers You Fed: Turn the Lens , this talk is aimed at attendees working in privacy advocacy or municipal policy – and anyone trying to understand how government and commercial surveillance data now move through the same pipeline.
It all ends Sunday evening when we gather to reminisce and start cleaning up. It's always a lot of fun but it's also a little bit sad, as it's time to say goodbye until next time, which hopefully will be one year from now. And if you've made it this far, we'll consider you part of the HOPE family.