Here are some of the HOPE 26 talks that have been finalized. We will be updating this section every day from now until HOPE so keep checking!
The Adversary in Your Bed: Stalkerware, Domestic Violence, and the Hacker Defense
Sara Kurtzberg, Sarah E. Ross-Benjamin, Efrat Sternberg
Domestic violence breaks every assumption in your threat model. The adversary has physical access, knows the passcode, owns the cloud account, pays the bill, and shares the bed. No consumer device is designed for that adversary. This panel looks at what happens when intimate-partner abuse goes digital: covert stalkerware (mSpy, FlexiSPY, pcTattletale, Cocospy), the weaponization of legitimate consumer tech (Find My, Life360, Ring, shared iCloud, AirTags, vehicle telematics), and the surveillance-by-default architecture of modern households. Every major consumer spyware vendor on that list has been breached and dumped. The customer bases were overwhelmingly abusers. Hackers, not regulators, made that visible. This panel will cover detection in the field: MVT, TinyCheck, the Coalition Against Stalkerware’s indicator list, and triage on a phone the survivor cannot safely hand over for imaging. They will cover what prosecutors actually do with that evidence at charging and trial. And they will name the institutions carrying this load: the EFF, Citizen Lab, Operation Safe Escape, NNEDV’s Safety Net Project. Most of them are not government.
The point of putting this panel on a HOPE stage is direct. Prosecutors and DV advocates need hackers. Hackers often see this work as inaccessible or institutionally hostile. This panel maintains that it isn’t. This is an invitation.
As tech bosses fall in line with the right, tech workers have begun fighting back. Resistance has included organizing against military contracts, walkouts to protest sexism, agitation about tech’s role in the climate crisis, and even a wave of union drives. Hellbent on stamping out any and all dissent, tech executives embraced Trumpism, fired organizers, and began lashing out against the “woke” ideology they blamed for turning their once loyal employees against them. This is the rousing inside story of the tech worker movement – and the way it spawned an anti-worker backlash now reshaping the industry.
Against the Edgelord International
Hackers are trained to think in systems: attack surfaces, payloads, privilege escalation, persistence, obfuscation, cleanup. But contemporary politics and media culture increasingly operate in disturbingly similar ways. Narratives are injected, amplified, laundered, distorted, and made persistent across platforms, communities, and institutions. A meme can behave like a payload. A fake historical analogy can function like privilege escalation. A conspiracy theory can become a persistence mechanism. And in the age of generative AI, cultural exploits can be produced, varied, and deployed at industrial scale.
This talk proposes a hacker-oriented model of narrative warfare and cultural manipulation: the narrative exploit chain. Drawing from context hacking, media pranks, art activism, hacker history, propaganda studies, and Johannes’ own work in film, performance, and political subversion, it asks how stories become attack vectors, how irony becomes armor, how taboo-breaking becomes a recruitment funnel, and how communities can defend themselves without becoming humorless cops of consensus reality.
Agshittification: Big Meat, Misinformation, and the Fight for the Future of Food
There is overwhelming evidence and scientific consensus that conventional agriculture and animal food production are threatening the things we hold dear: our health, our communities, our planet, and perhaps even our humanity. So why does diet advice from the American government emphasize meat, milk, and eggs? And who decides what food is “real,” or what makes something “ultra-processed?” On the same HOPE stage where she first heard “enshittification,” author and founder of Food Matters Media Dr. P.K. Newby introduces “agshittification,” a phrase coined in her newest book after learning the filthy truth about megafactory animal farming, the NIMBY Big Meat doesn’t want you to know about. With framing from Food and Nutrition: What Everyone Needs to Know , Newby illustrates how industry influence and misinformation are part of a larger nexus of agshittificatory practices, policies, and propaganda designed to keep you in the dark about “all natural” meat. This mind-bending story spans vertical pig farms and literal shitstorms as Newby stands on the shoulders of HOPE superheroes and tech gurus, Cory Doctorow and Greg Newby, sharing an ecotechno vision of what a healthy, sustainable food future looks like.
Newby’s talk is designed for all eaters, its goal to inspire sapiens of all stripes to consider what steps we can take individually and collectively to evolve beyond the Age of the Chicken, one bite at a time.
New technology has always threatened to democratize film production. Digital video, CGI, and iPhones all threatened to turn Hollywood over to the people. Mojo will talk about why that never happened and how AI is going to fulfill that promise. For the first time in history, the cliche “all you need is your imagination” is finally true and a new generation of filmmakers are jumping in. He’ll also discuss where the studios stand on generative AI and how the legal and ethical ramifications are being addressed. Finally, he’ll explain how world models are the future of AI video.
The Art and Science of Metawar
One of the original speakers from the first HOPE conference in 1994 is back with a new book that examines how humans must strengthen our cognitive defenses against AI-driven reality distortion, TMI/disinformation, manipulation, and algorithmic addictions. This talk will discuss the intersection of cybersecurity and cognitive security. The vast similarities between silicon and carbon systems offer cognitive defenders an existing framework for strengthening our mental immunity systems against information pathogens at the national, enterprise, and personal levels. You will see how the security, privacy, ethics, and global policy implications are staggering.
Daly Barnett, William Budington, Lena Cohen, Cara Gagliano, Rory Mir
In 2026, a confluence of corporate and government forces work together to deploy new and frightening surveillance technologies to monitor and restrict the rights of ordinary people. As tools made available to law enforcement and ICE track the movements of our devices, FLOCK cameras gather an endless stream of information from the automobiles indispensable to most Americans. But 2026 is also the year that the users started to fight to “Take Back CTRL,” and the Electronic Frontier Foundation (EFF) has been with them every step of the way. From suing cities which deploy automated license plate readers, to raising awareness around the practices of data brokers, to developing technologies that enable users to avoid trackers, EFF combines legal, activist, and technological strategies to help in the fight. They’re back at HOPE this year with staff members across the organization to answer your questions and help you more effectively engage in the struggle for digital rights. In this troubling time, they will discuss some of the new opportunities they see to empower ourselves against the forces of technological oppression.
Autonomous Exploitation at Scale
With the advent of powerful, open-source, and lightweight large language models, the cost barriers that typically prevent targeted attacks – with people manually scanning, infecting, and exploiting – are vastly reduced. This talk presents a self-propagating worm which autonomously detects devices, enumerates their vulnerabilities and services, checks for exploits which could work on them, and exploits them and spreads to them, forming a distributed network. It discusses the limitations, design decisions, and tradeoffs made in the development.
Emma Best, Mikael Thalen, Alexander J. Urbelis, maia arson crimew
In 2020, a private contractor that provided services to hundreds of agencies was hacked and given to Distributed Denial of Secrets, which dubbed the data BlueLeaks. At the time, it was the largest leak of American law enforcement and intelligence records in history. In 2026, it happened again. This panel will discuss receiving the leak, publishing it, and the fallout.
Building a Community Arcade Cabinet
Frank Chiarulli, Sophie Downward, Rose Hall
The RCade is a custom arcade cabinet built at the Recurse Center that runs games made by the community. It has a real CRT, a custom graphics card, spinner controllers, and a deploy pipeline where anyone can ship a game just by pushing to GitHub. It now has over 90 games. Frank Chiarulli will talk about reviving the hardware and building the deployment system, Rose Hall will cover the game engine and plugin sandbox, and Sophie Downward will walk through building a custom display adapter from scratch. They’ll close out by showing off some of the games.
Building Sovereign AI for Amateur Radio
Most AI assistants send your data to the cloud. This talk shows you how to build one that does not. Joe Cupano walks through the construction of a fully sovereign AI server on commodity hardware, an NVIDIA RTX GPU running Ollama with a curated knowledge base capable of answering amateur radio and SIGINT questions from local inference alone. The talk covers the full pipeline from hardware selection through corpus ingestion, the agent frameworks that failed the sovereignty test, and practical techniques for building domain-specific knowledge bases from heterogeneous sources. Attendees will leave with a replicable architecture, a working blueprint, and a clear-eyed view of which open-source tools actually respect data sovereignty and which do not.
Cameras, Cops, and Cell Towers: A Field Guide to Modern Surveillance
Your car passes a license plate reader. Your phone connects to a cell tower. A camera identifies your face, a drone watches from above, and data brokers help connect the dots. Most people have no idea how much surveillance follows them through an ordinary day or where that information ends up. This talk pulls back the curtain on the modern police surveillance stack, from Flock cameras and cell-site simulators to drones, body cameras, facial recognition, data brokers, and regional intelligence networks. Using real-world examples and open-source tools such as EFF’s Atlas of Surveillance and RayHunter, Michael Raymond will show attendees how these systems work, how communities are mapping them, and what practical, lawful steps people can take to better understand and reduce their exposure.
Can It Ham? Hackers, Hams, and the Signal Between Them
Andrew "livitup" Ohnstad, Terry "shoot3r" Schanno
Hackers and amateur radio operators have more in common than either group tends to admit. One speaker came up through 1990s hacker culture – attending 2600 meetings and contributing to 2600: The Hacker Quarterly long before becoming a licensed amateur radio operator. The other has spent decades in amateur radio, only to discover through DEF CON that the hacker mindset had been there all along. Through the story of the “Can It Ham?” contest – where participants build working antennas from unconventional materials – this talk explores how RF experimentation, system-level curiosity, and hands-on exploration form a shared foundation between hackers and hams. This is a story about rediscovery, perception, and what happens when you remove labels and just start building.
Can We Route Around the App Stores?
Hackers have long understood that networks are resilient. We can bootstrap anonymity and routing layers like Tor, I2P, and Nym with relative ease, and move traffic across hostile environments with surprising flexibility. In many ways, the network layer is the least of our problems. The real challenge begins next layer up, where applications, platforms, and distribution channels impose control over how that network can actually be used. Over the past year, the presenters built and deployed a working suite of desktop applications for communication, identity, and storage, and put them in the hands of real users in classroom environments. This gave a clear view into what happens when people try to use privacy-first tools in practice. You will see what worked, what broke, and how user expectations shaped by mainstream platforms collide with systems designed for autonomy and control. These applications also include an independent software delivery and verification model, allowing updates and dependencies to be distributed and validated without relying on centralized app stores. These ideas are now being brought to mobile devices, where the constraints are far more severe. This talk focuses on the practical challenges of running user-controlled software on phones: app store restrictions, packaging and distribution barriers, Android limitations, and Apple policies that restrict apps which resemble alternative software ecosystems. This talk will also address sideloading, UI constraints, and the current state of hardware, including experiments with PinePhone, Fairphone, and GrapheneOS. The core question is simple: how can we build trustworthy applications that route around the app stores?
Communicative Survival Strategies for Security Practitioners
There’s been a huge wave of desire for security support in activist spaces for pretty obvious reasons (fascism; the reason is fascism). Even with that interest and emotional buy-in, it can be a struggle to turn that into improved security and privacy – especially if you’re just the most tech-savvy person in a volunteer group whose cause you believe in. This talk is not focused on specific OrgSec practices or technical topics, because if you’re at HOPE you probably already have expertise to share with your community. Instead, it will provide some communication approaches shaped around different groups, orgs, and their cultures and goals.
The Cyber Resilience Act and Open Source: Who Is Responsible When Everything Breaks?
This talk is an explanation of how the European Cyber Resilience Act (CRA) could affect the open-source ecosystem. The CRA introduces new cybersecurity obligations for products with digital elements placed on the European market. While noncommercial open-source projects are treated differently, their code can still become part of commercial products sold or distributed in Europe, raising practical questions about responsibility between volunteer maintainers, companies, manufacturers, and open-source stewards. Anas El Faijah will look at who may be responsible when an open-source component contains a serious vulnerability; how the CRA could change the relationship between open-source and commercial products; and what this means for developers, maintainers, companies, and the wider security community.
Cybersecurity for Space Systems: Integrating Offensive Methods, Defending System Vulnerabilities, and Space Law
As space systems become increasingly integrated with U.S. critical infrastructure, cybersecurity must evolve beyond defensive approaches to include offensive techniques that expose and counter adversary capabilities. Critical services such as GPS remain vulnerable to jamming and spoofing as a result of electronic warfare, while command centers and user terminals face risks from network exploitation, malware, and credential compromise. In addition, unencrypted data links within some GEO communications systems enable interception and hijacking, and supply chain compromises introduce further threats to mission assurance and system integrity. Addressing these challenges requires cybersecurity education and training that is adversary-informed. Cybersecurity engineers must also understand the legal and policy frameworks governing behavior in space, including the Outer Space Treaty, Artemis Accords, and the Moon Treaty. This presentation highlights experiential learning initiatives such as the Cyber Drone Challenge and Cyber Space Challenge demonstrating a multidisciplinary model for educating and preparing the next generation of cybersecurity professionals to secure the evolving space domain.
Decentralized Networking Is a Social Problem
Decentralized networking is often approached as an engineering problem. Distributed protocols, peer-to-peer systems, mesh networks, and federation can address many technical challenges quite successfully, but the communities built around them must still grapple with questions of stewardship, participation, trust, and how to navigate disagreement. As projects grow, some respond by adding rules and formal governance in an effort to create shared expectations and predictable behavior, but rules alone do not guarantee success. This talk draws on the experience of the 44Net community, an evolving family of amateur radio networking projects dating back to 1981. Using projects including AMPRNet, HAMNET, 44Net Connect, and others as case studies, it examines the social patterns that have allowed these communities to adapt over decades of technical and societal change. Rather than trying to prescribe every behavior, these long-lived communities tend to observe what works, reinforce useful norms, and let shared expectations emerge from shared experience. Taken together, these projects suggest that longevity depends less on elaborate governance than on a community’s ability to absorb change, learn from conflict, and continue evolving.
The Deceptive Web of Scam Compounds
This presentation examines the rise of scam compounds and the rapidly evolving characteristics of these industrial-scale fraudulent operations. A recent report by the United Nations Office on Drugs and Crime (UNODC) found that cyber-enabled fraud has intensified, resulting in billions of dollars in losses, with many of these malicious networks orchestrated by criminal syndicates in Southeast Asia. The UN estimates that hundreds of thousands of individuals have been trafficked and forced to labor in these illicit facilities. Crucially, as these syndicates integrate increasingly sophisticated technologies, they have also become highly mobile, routinely relocating entire compounds upon completing a “lifecycle of operations.” Dr. Scherling’s presentation draws from her extensive interviews with non-governmental organizations (NGOs), government agencies, investigative journalists, and compound survivors.
Doxing: The Politics, Panics, and Economies of Online Safety
For more than two decades, doxing has taken on many meanings. Once associated primarily with image board trolls and hackers, it has since become a tactic deployed by (and towards) a wide range of actors for disparaging purposes, from de-platforming political opponents and unmasking ICE agents to facilitating in swatting campaigns in gaming communities. While doxing continues to occupy multiple positions, be it a mechanism of community safety to a ubiquitous “weapon of visibility” in the “21st century culture wars,” its social significance has mutated. Most recently, while state agencies have relied on publicly available online information to identify and detain student protesters, governments are simultaneously rapidly adopting anti-doxing legislation that criminalizes the disclosure of public information, going so far as to describe it as a kind of domestic terrorism. This shift not only raises the political stakes of doxing but also codifies the moral panics with strikingly disproportionate punishments.
This talk traces the cultural history of doxing to examine how its meaning has changed and, in many ways, also remained remarkably consistent. By following the evolving relationships among states, platforms, corporations, activists, journalists, and varying online subcultures, this talk explores how doxing has reshaped ideas of accountability, visibility, and online safety, as well as the technologies that enable it. By examining the feedback loops between surveillance, counter-surveillance, and vigilantism, Jamie argues that a historical look at doxing offers a critical lens for understanding how online identification has become both a tool of community governance and an ambiguous threat to public safety.
The Enshittified Internet and How We Can All Rewild the Internet!
The Internet was once a place where people could talk, share ideas and knowledge, express themselves with personal websites, build communities, and more. In recent years, however, we have seen that magic fade away, as the Internet of today is now a toxic cesspool of social media controlled by Big Tech, ads thrown everywhere, walled gardens, AI-generated slop, and content that locks us in by making us angry and depressed. This is not the Internet we need or should leave to the next generation of hackers! There are ways to take back and rewild the web! This talk is part informative, part educational, part historical, and pure hacker punk energy as the presenter explores how to do things like self-host your own servers; use tools to build new networks; operate decentralized services for communication, media sharing, and more; find old protocols and services old timers used to use that still exist (and helping the kids to use them, too!); and locate places and sites we can go to for the education and information we want! In all, this talk is about hacking the planet and taking our Internet… the people’s Internet… back from corporate corruption and control!
LLMs write boring code. They reinforce the monoculture already achieved by the dominant, increasingly bland multi-paradigm languages that converge more every year. Esolangs are the resistance: small, nimble languages with alternate forms of computation. They create space for exploration and human expressiveness in the text of code. For example, where the AI prompt makes natural language discardable, resolving into a single, flattened interpretation in code, some esolangs (e.g. Prasa) bring the nuance and ambiguity of natural language into code itself. Meanwhile, many esolangs are surprisingly resistant to LLM code generation because of their odd approaches to nearly every aspect of how code is written and run. This talk will cover how esolangs counter not only the style but the values behind agentic coding and remind us that a bland future is not inevitable.
The Ethical Fork in the Road Facing Gen Z: How Can We Inspire Gen Z to Become Ethical Hackers in Modern Workplaces?
This talk centers around the risk and opportunity facing young people online and how the cybersecurity industry is ill-equipped to harness their power, or address the threats emanating from them. It will describe how to unlock the power of young people through their online gaming to launch their digital futures. It will cover the real crisis facing our kids online, and describe tangible opportunities for young people to fill critical roles within cybersecurity.
Feeling the Signal: Hacking Music Into Touch
This talk explores how music can be experienced beyond hearing through touch, movement, and atmosphere. Inspired by the speaker’s personal experience as a hard-of-hearing music listener who loves going to music events, the project investigates how technology can create alternative sensory pathways for perceiving rhythm, emotion, and musical structure. Drawing from interviews, body-mapping experiments, and iterative prototyping, the talk presents a real-time system that translates musical features into tactile and visual experiences through haptic wearables, pneumatic interfaces, and generative visuals. Audience members will also have the opportunity to experience the prototypes firsthand, including a tactile composition created for “UV” by Vril, demonstrating how music can be felt through the body as rhythm, emotion, and shared physical presence. In addition to presenting prototypes, the talk explores how accessibility technology can function as a form of sensory enhancement and creative expression.
Field Notes From a Year of OPSEC for Liberation Movements
Throughout 2025, EFF facilitated digital privacy and security trainings for more than 2000 people. The issue spaces at hand ranged from animal rights activism, abortion access, immigration legal defense groups, and many many more. Although the particular characteristics of the various audiences differed, one thing remained true: traditional sources of information security were either inaccessible to these groups or fundamentally unable to meet their unique needs. In this talk, EFF senior staff technologist Daly Barnett will present field notes collected from the trainings conducted throughout 2025. This high-level survey will cover the types of digital privacy and security threats facing various liberation movement workers in America today, as well as the mitigation strategies they are walked through. For fellow hackers and technologists, this is not only an indispensable insight into the actual impacts of surveillance technology and digital security threats facing today’s activists, but also a blueprint for how they might be able to provide movement workers with much needed help.
Flushing Tech: Three Years of Building Hyper-Local Tech Communities
Come learn and be inspired by how Flushing Tech brings tech communities to neighborhoods across NYC. Flushing Tech was created three years ago to bring tech enthusiasts together right in their own neighborhoods by having fun building tech, making connections, and learning new things. At HOPE_16, William talked about the start of that journey and shared a practical roadmap with actionable guidelines so anyone could build their own hyper-local tech community. Flushing Tech has evolved over the past year – becoming a 501(c)(3) nonprofit, experimenting with in-person hackathons and online activities, and taking the leap of faith into other neighborhoods. Come hear what worked, what didn’t, and what surprised them. These stories – the wins, the failures, and everything in between – will give you ideas you can steal, remix, and improve upon. The goal is simple: make it easy for anyone, anywhere, to build a thriving hyper-local tech community. Hundreds of Flushing Techs can emerge as communities built by neighbors, for neighbors.
For Government Use Only – Exploring the 710 NPA and Telecommunication Service Priority
The 710 NPA is one of the strangest corners of the North American telephone network: an area code that technically exists, almost nobody uses, and somehow still feels like it belongs in a Cold War spy thriller. This presentation explores the origins of the 710 Numbering Plan Area from its roots in the old TWX teletype network through its reassignment in the 1980s as a reserved government emergency service code, and its relationship to the Government Emergency Telecommunications Service (GETS). This talk also examines the future of emergency communications through Wireless Priority Service (WPS), Next Generation Network Priority Services (NGN-PS), and the challenges of implementing priority access in today’s IP-based, software-defined networks. As legacy PSTN infrastructure continues to disappear, this presentation asks whether systems like GETS remain a critical national resilience tool or an aging relic quietly surviving inside modern telecom networks. Equal parts telecom archaeology, infrastructure history, and hacker curiosity, this presentation is designed for those who enjoy obscure numbering plans, forgotten network architecture, and discovering that the phone system can still somehow be even weirder than imagined.
From Source to Story: Cryptography and Psychosocial Care Protects Public Interest Journalism
The threat landscape for journalists and whistleblowers has dramatically intensified over the last 15 years, leading to the development of robust technical evolutions in platforms from SecureDrop, Dangerzone, WhatsApp (meh), and Signal. Safely handling malicious submissions and spicy comms, newsrooms have become used to employing rigorous security models, sandboxing techniques, and myriad other tactics that have become the “meat-and-potatoes” of high-stakes public interest journalism. The baseline for secure communications is always shifting due to emerging legal, quantum, and novel AI challenges. This talk will address this and help enable you to fully understand how securing data is only half the equation; it is equally critical to protect the human risking their livelihood or liberty for the public’s right to know. This means moving beyond threat models to deeply understand the psychological toll of whistleblowing and the empathetic dimensions of the journalist-source relationship. You will get a glimpse into the modern toolbox that merges strict digital security protocols with empathetic strategies to manage the anxiety inherent in the biggest disclosures. From first contact to post-publication – you’ll learn about the life cycle reporters expect to safely and ethically get the story done.
Government Transparency in a Time of Shadows
The Trump administration claims to be the most transparent administration in history, and yet every facet of it is custom-designed to be as opaque as possible. Freedom of Information Act offices are shuttered, whistleblowers are muzzled, agencies are run on Signal, everything is overclassified, and DOGE is allowed to spread across the executive branch like a plague with no accountability or oversight. And when the law gets in the administration’s way, they have the DOJ decide that it doesn’t really stop them.
But it’s not all doom and gloom. There are still systems in place that you can use if you know how, but it’s much harder every day. This talk will describe the way things are supposed to be, the way they are, and how you can still bring some sunshine to the black box the administration is trying to create.
Hackers: Journalism Needs Your Help
Journalism is in rough shape. Budgets, resources and staffing are shrinking. This dire situation is a bummer but also opens opportunities for hackers to take up the flag and do some great work in collaboration with journalists. This talk will explore some real world technical problems that show up in actual investigative work and explain how the hacker community can help. Bored? Let’s get to work!
Hacking the Layers, Hackers, Open Source and the 3D Printing World – And Why You Should Care About It
3D printing is fundamentally changing our relationship with the physical world, empowering individuals to democratize manufacturing, reclaim the right to repair, and achieve true personal autonomy while also facing challenges from corporate and regulatory forces trying to restrict that freedom using the same age-old adage of limiting adult freedom to protect the children. This talk traces the direct lineage of this modern struggle back to its roots: the Chaos Computer Club and the early tech hacking pioneers. Attendees will learn how the early open-source software movement laid the groundwork for the hardware revolution, and how a dedicated global community ultimately used 3D printing to bypass overly regressive patent systems.
Ham Radio Isn’t Magic: Preppers, Sad Hams, and Practical Off-Grid Communications
Every hacker has seen the post: someone asks what radio will let them “reliably talk 500 miles to family when the cell network goes down.” The replies quickly devolve into bad advice, magical thinking, and dismissive gatekeeping. The result is confusion, wasted money, and false confidence about off-grid communications. This talk is the antidote. It will cut through the mythology and explain what amateur radio can actually do for personal and family communication during major disruptions – and what it cannot. Starting at a 101 level, it will cover realistic ranges, basic propagation, equipment tradeoffs, digital modes, licensing myths, and why distance is usually the wrong requirement. Rather than dunking on preppers or policing fun like a sad ham, this talk reframes the problem the way hackers do: understanding constraints, failure modes, and human factors. It will focus on practical off-grid communication strategies that work in the real world – coordination, redundancy, and low-bandwidth messaging – not fantasy continent-spanning voice links.
For decades, public key cryptography has relied on mathematical hardness assumptions (the difficulty of factoring large numbers and computing discrete logarithms) that within several years may no longer hold. The arrival of a cryptographically relevant quantum computer capable of breaking RSA and elliptic curve cryptography is in the future, and the “harvest now, decrypt later” threat means encrypted traffic captured today could be retroactively decrypted by nation state actors. This talk recaps where we are with the post-quantum transition: NIST’s multi-year standardization process culminating in ML-KEM and ML-DSA for key encapsulation and signatures, the hard problems that underpin them, and the state of ecosystem migration.
HERMES: Secure, Long Distance Data Communication Over HF Radio
Rhizomatica has been working on a completely autonomous communication system called HERMES (hermes.radio) since 2017. HERMES is a fully FLOSS stack that has been built to use HF radio to create secure and very long-range (about 500 kilometers) digital communication links. HERMES has been deployed in the Amazon to support land defenders, on boats in Bangladesh to provide critical communications to fishermen, in war zones in Africa as part of early warning systems, etc. Due to current geopolitical situations that have us all concerned, it’s clear that HERMES can be a critical tool for hackers, privacy activists, and the general public to create autonomous and secure digital communication networks that are much harder to monitor or shut down compared to corporate-controlled ISPs.
OpenA2A runs two kinds of honeypot for AI agents: a fleet of fake agents that observe attackers who believe they control a real system, and a network of poisoned pages on the open web carrying benign indirect prompt injections, where the visitors are AI agents and a callback measures which agents followed the bait. This talk presents what both surfaces reveal, including the finding that 45 percent of unique attackers return across sessions, with one fingerprint returning for 15 days straight across 623 sessions, alongside an aggregate callback rate of 1.4 percent across more than 183,000 visits from over 34,000 unique agent fingerprints. Abdel Fane walks through the instrumentation, what each data stream sees that the others cannot, what the project deliberately withholds from publication and why, and the structural reason crawler-based studies miss most of the attacker reachable surface. All of the work is Apache 2.0, and every fixture and signature is reproducible by anyone running equivalent instrumentation.
It all ends Sunday evening when we gather to reminisce and start cleaning up. It's always a lot of fun but it's also a little bit sad, as it's time to say goodbye until next time, which hopefully will be one year from now. And if you've made it this far, we'll consider you part of the HOPE family.
It all starts Friday morning. Join us as we make sure everything works before another HOPE is unleashed on everyone.
How Advertising Libraries in Mobile Apps Enable a Massive Location Surveillance Apparatus
Last year at HOPE, William discussed the dangers of location data brokers tracking billions of people through mobile apps and selling their location to the highest bidder. This year, he’ll dive deeper into how and why mobile apps betray our location privacy. Advertising libraries included in a vast array of apps can transmit location data from your device sensors to surveillance tools available to the government and sold on the open market. While parts of this data pipeline remain shrouded by corporate secrecy, we can shine light on its starting point through analysis of the SDKs powering advertisements and harvesting location data in our mobile apps. You will learn the findings from looking at these components at EFF’s Threat Lab, techniques that are used to investigate apps, and conclusions about what is needed to stop mobile advertising from fueling the location surveillance industry.
Emma Best, Jeremy Hammond, John Williams
The world has never needed whistleblowers more, and technology has made it both easier and more dangerous to be a whistleblower. The panelists (all whistleblowers themselves) discuss what it takes to be a successful whistleblower, from knowing when and how to speak up to dealing with the psychological impacts of blowing the whistle. Other topics include common mistakes and misconceptions, as well as how to stay safe and dealing with the potential fallout, including trial or prison.
How to De-Google Your Org: Practical Advice From People Who’ve Done It
Meredith Laverty, Jibran Ludwig, Sarah E. Philips
Are you ready to get your organization off Big Tech? Last year, Fight for the Future did just that. They ditched Google Workspace and migrated their email, calendars, docs, and other core infrastructure to privacy-friendly, open-source alternatives. The panelists will talk about why they made the move, how they built organizational buy-in, and what they learned along the way. If all goes according to plan, attendees will leave with greater confidence in their ability to move themselves and their organizations away from Big Tech, along with clear next steps for getting started.
How to Fight DDoS Attacks From the Command Line
Why are all of our favorite sites starting with “Just a moment…” and “Making sure you’re not a bot!” splash pages now? Since 2024, AI companies appear to be operating aggressive, vibe-coded scrapers behind residential proxy botnets, and sites have typically turned to commercial shields. Michael will share several tools and techniques that he uses as a systems administrator at the Free Software Foundation to keep the sites up on their own infrastructure. He will demo some of his own tools and the tech stack he uses regarding monitoring, firewalls, automation, analytics, ASN lookups/blocking, and geofencing.
Huge Antennas: Death Rays to Aliens
Ever wonder what purposes really large antennas are used for? This presentation will cover currently in use large and innovative antenna systems around the world – on the ground and in the sky. Steve shares what they are designed for and how they are used. Examples in areas like broadcast, astronomy, radar, and a few of the more niche or clandestine application areas will be covered – and not just related to amateur radio. There will also be coverage of how to scale these applications to something any radio hobbyist can copy, make, and use inexpensively at a smaller scale. This presentation will be light on history and high on modern use systems to enable cool wireless projects.
I Hacked a Gay Foot Fetish App (And You Can, Too!)
For folks in the queer kink community, social connection frequently begins online. Big Tech, though, makes it especially difficult for people in those groups to meet and connect; they often face bans and censorship. So when “Soles,” a new foot fetish web app for gay men, seemed to come out of nowhere one day, it raised several questions. Where did it come from? Who made it? Is it secure? This is the story of how a curious hacker gained admin privileges with a single HTTP request, what happened after, and how – with the hacker spirit – you too can sniff out trouble. Could getting your foot in the door really be this easy?
Back for the third time, author and technologist Mallory Knodel will give an update on several I-star organizations, namely ICANN, IETF, IEEE, W3C, and ITU. The tensions and synergies of human rights considerations in Internet governance and standards setting across the I-star bodies is rapidly expanding. This talk will touch on the major controversies in each space as they relate to human rights, namely censorship and the right to privacy.
Inside North Korea’s Underground Tech Resistance: How Smugglers, Defectors, and Technologists Are Outmaneuvering the World’s Most Locked-Down Information System
This talk provides a layer-by-layer technical breakdown of North Korea’s civilian information-control system – covering custom Android handsets with mandatory state-signed APKs, a screenshot-based surveillance daemon called TraceViewer, steganographic file watermarking in Red Star OS, and a sealed national intranet with zero Internet access. The talk demonstrates how North Korean citizens and a network of defectors and technologists are actively circumventing it using sneakernets, smuggled phones, and purpose-built tools. The talk concludes with a structured call to action for the security community, presenting open engineering challenges in obfuscation, firmware exploitation, air-gapped deployment, embedded systems, and more that map directly to skills common among HOPE attendees, grounded throughout in tools that have been built, tested with defectors, and deployed through Liberty in North Korea’s underground network.
It’s 10 PM. Do You Know What Your AI Agents Are Doing?
AI coding agents like Claude Code now have shell access, file system access, and connections to external services through MCP servers – and most security teams have zero visibility into what they’re actually doing on developer machines. Alexander Rodriguez walks through building a three-layer open-source defense stack from scratch: an OpenTelemetry pipeline that captures every command, file access, MCP server connection, and permission decision; Meta’s LlamaFirewall wired into pre-execution hooks to block prompt injection and goal hijacking before actions run; and a lightweight EDR-style detection agent that watches AI agent behavior the way other tools watch process behavior by signature matching for credential file reads and exfil chains, behavioral baselining for anomalies, and real-time blocking. The talk also covers what’s still broken, such as no visibility into model reasoning, MCP servers that can change behavior after vetting, and prompt injection detection limited to pattern matching. Full stack on GitHub, demo included.
LIMA – No Vendor, No Cloud, No Trust: Open Source Tamper Attestation for Critical Infrastructure Hardware
LIMA is an open-source attestation system that lets a field device cryptographically prove its sensor readings are authentic and untampered with – over a SCADA network or any network at all. The talk walks the full stack: a Zephyr RTOS firmware node on the nRF52840 signs sensor and accelerometer data with ECDSA-P256 using the chip’s onboard CryptoCell-310 hardware security engine, broadcasts 90-byte attested payloads over BLE extended advertising, and delivers them to a blind-relay Rust gateway that verifies every signature without ever holding a private key. A live demo – with a recorded fallback – shows a physical tamper event (a shock to a field device) propagating through the cryptographic chain to a verified alert in about a second. Justin will then cover why the project exists and who it is for (individuals and small operators through to enterprise deployments), and give a walkthrough on how to stand up an example node.
Lingua Machina: The Last Humans Who Read Code
We treat code as pure instruction, something you write so a machine will obey. Programming languages are closer to a living vernacular, riddled with idiom, accent, ambiguity, and taste, sitting somewhere between human language and musical notation. This talk covers the linguistics of computer languages: how languages were invented, argued over, and mutated; how grammar became structure; how we keep accelerating the pace at which we talk to machines in search of better ways to build. And as the history of computer linguistics will be covered, it is also worth reviewing the uncomfortable question for an age of generated code: as fewer of us write it by hand, will we still read it, understand it, and know why we write it the way we do?
Modern OSINT Tradecraft: Attribution, Analysis, and OPSEC
Open Source Intelligence (OSINT) is often dismissed as “just Googling,” yet it has become one of the most powerful methods for collecting, correlating, and attributing information across public and semi-public sources. This presentation explores modern OSINT methodology through real-world examples, demonstrating how investigators pivot across social media, imagery, geospatial data, and other datasets to build attribution models and uncover relationships. Topics include geolocation, chronolocation, cross-platform identity correlation, cryptocurrency transaction analysis, AI-assisted investigative workflows, and common pitfalls such as false attribution and data poisoning. The session will also examine operational security, ethics, legality, and the privacy implications of modern intelligence gathering. In addition, the speaker will demonstrate a new open-source AI-powered OSINT platform designed to assist analysts with data triage, correlation, and investigative workflow automation, which will be released free to the community.
More Computational Techniques for Making Karaoke Harder
Robot karaoke returns to HOPE! Jamie and Jenn run a live comedy show where performers sing all-new words to classic tunes, generated in real time. Their songwriting system searches an eclectic catalog for phrases that match the original rhyme and meter of each line, creating lyrics that have never been sung before and will never be sung again. Think Quora questions to the tune of “Dancing Queen” or HOPE presentation titles to the tune of “The Rainbow Connection.” This talk covers how they source the data, phonetically annotate the songs, run the show, and develop their core software: the Weird Algorithm.
The New Cold War Has No Borders: Building the Sovereign Stack
Nation-state actors are running intelligence operations against neo-finance protocols, sovereign AI infrastructure, and the hacker community’s communications networks. The government response follows a predictable pattern: external threat becomes justification for internal control. That cycle is unfolding now in legislation pushing toward mandatory identity verification for Internet access. Frontier AI is becoming a tiered resource, accessible to states and institutions, rationed to everyone else. The question is not whether centralized control infrastructure gets built. The question is whether alternative infrastructure can emerge and survive before it arrives. This talk examines the sovereign stack as a unified strategic response and explores how OSINT tradecraft can expose infiltration attempts before a technical compromise occurs. Both are anchored in a framework first articulated in 2012: how do you build systems that remain operational long enough to shape the next battle?
Nikola Tesla’s Time at the New Yorker Hotel
Nikola Tesla spent the last ten years of his life in rooms 3327 and 3328 of the New Yorker Hotel, holding annual birthday press conferences to announce wild new inventions living above the largest private power plant in the United States, and dying alone upstairs on January 7, 1943, after which the government seized his papers despite his American citizenship. This year, for the first time, HOPE convenes in that same building. This talk covers Tesla’s final decade under this roof, the hotel’s own remarkable machinery, the declassified FBI files, and the three individuals who spent their lives making sure none of it was forgotten: William Terbo, Tesla’s grandnephew and last direct-line relative; Dr. Ljubo Vujovic of the Tesla Memorial Society of New York; and Joe Kinney, the hotel’s longtime chief engineer and historian. All three individuals are sadly gone now, but this is the story of what they kept, told in the building where they kept it.
Plus there will be some long-awaited news from The Tesla Science Center at Wardenclyffe!
No Laptop or Wi-Fi? No Problem: Democratizing Coding for the Mobile-Only World
Hal Eisen, Elissa Miller, David Schachter
For too long, access to programming resources has been limited by access to infrastructure. Nonprofit App Dev for All is challenging tech’s pay-to-play nature with Code on the Go, a powerful, free and open-source IDE that turns a budget Android smartphone into a professional workstation, even in regions without reliable Internet access. The presenters will demonstrate that even the most resource-constrained coders can build, compile, debug, and deploy full Android apps entirely offline on almost any Android phone.
No, I’d Rather Stay Manipulated: How the Apps in Our Lives Hijack Our Behavioral Programming
The products on your phone do more than compete for your attention. They engineer your behavior. This talk dissects the specific mechanisms: variable reinforcement schedules borrowed from slot machine design, A/B testing pipelines that converge on maximum psychological extraction over thousands of iterations, and the metrics architecture (time-on-platform, conversion rate, churn) that makes manipulative design the rational output of every product organization. Nasir will walk through how these decisions get made inside product teams – not by villains, but by reasonable people optimizing reasonable metrics that produce unreasonable outcomes. Internal documents from the recent Meta/YouTube trial where a jury found both companies negligent in the design of their platforms show exactly how deliberate this process is.
The more urgent territory is what happens when dark patterns move from static interfaces into AI. Recent research shows that every major LLM exhibits sycophancy, systematically validating user beliefs over providing honest guidance. And that users prefer and trust the sycophantic version more, creating a perverse incentive loop where the model that’s worse for you is the model that wins on engagement metrics. A separate line of research found that AI agents navigating interfaces on behalf of users are more susceptible to dark patterns as they become more capable. And smarter agents get tricked more . When the interface itself is an optimization target driven by AI personalization, the dark pattern becomes invisible: two people see the same app, but experience entirely different levels of manipulation, and neither can document what happened to them.
Nobody Meant to Build a Surveillance Machine: The Modern Corporate Panopticon
Modern workplace surveillance wasn’t intentionally designed: it emerged. Every department inside an organization asks for something reasonable: stronger security, legal compliance, easier collaboration, simpler administration, or AI-powered productivity. Individually, these requests make sense. Together, they create one of the most observable work environments ever built. Using Microsoft 365 as a case study, this presentation explores how those ordinary organizational decisions gradually produce extraordinary visibility into employee behavior, why these environments are so frequently misconfigured, and how understanding the architecture behind them often reveals more than any single vulnerability ever could. Rather than focusing on sensational exploits, the talk examines assumptions, metadata, and the quiet ways information accumulates inside modern enterprises – because in complex systems, understanding is often the most powerful tool.
Nobody Owns This: 9P CyberDecks and Community-Owned Mesh Computing
This is the story of how a homebrew cyberdeck project ran headlong into a wall of modern protocol complexity, and how the 9P protocol from Bell Labs – the heart of the Plan 9 operating system – turned out to be the answer. Jon Sharp will demonstrate 9p4z, an open-source library bringing 9P to modern microcontrollers, and show working mesh chat running over long-range radio: off-grid, community-owned communication infrastructure built from parts you probably have in a drawer. The good ideas computing discarded weren’t wrong – they just weren’t profitable enough to lock up, which is exactly what makes them ours to resurrect. This talk is a direct invitation to do it yourself.
Non-Human Identity – The Gaping Security Hole That Agents Are Making Worse!
This talk will cover a list of ways to hack non-human identities and proposals for securing your Agentic infrastructure. It is based on over two years of research, and on several consulting projects securing NHIs and Agents for clients. Michael will discuss a developing framework for understanding your current state of NHI and Agentic identities, showing the results of primary research that his team has been conducting over the past year. He will explain why consistent surface-level security controls and approaches simply will not cut it due to the complex nature of how fast shadow AI is growing. You will leave this talk concerned about the security of your infrastructure, with at least a few new ideas on what to go secure (or hack).
Not Your Boy Genius: Feminist and Queer Hackers in Film and Pop Culture
From cyberpunk fantasies to contemporary screen culture, hackers are often imagined as brilliant, antisocial, male-coded figures in hoodies, basements, and command lines. But what happens when the hacker is female, queer, trans, femme, monstrous, seductive, collective, or politically disobedient?
This talk explores the representation of female, female-read, and queer hacker figures in film, fiction, and pop culture. Taking cinema as its main entry point, it will look at how women and queer characters have been portrayed as coders, engineers, system-breakers, information smugglers, digital witches, cyberpunks, whistleblowers, and technological tricksters. The talk will move through iconic and lesser-known examples – from mainstream hacker films and cyberpunk narratives to queer, feminist, and speculative media and ask what these figures reveal about power, gender, surveillance, desire, and technological agency.
The Onion Shell: Zero-Install Tor From the Browser
What if anyone in the world could connect to the Tor network and benefit from its privacy protections with nothing more than a standard web browser? Volunteers globally operate a free onion network that protects Internet privacy. It prevents tracking, surveillance, and censorship. However, accessing the onion network has always required special software running as a privileged user. Often, users even install virtual machines or operate dedicated machines to isolate their applications connecting to Tor.
Not all threat models are equal. Some users do not have the privileges and access to their machines necessary to connect to Tor. This is increasingly important in a world where governments are mandating OS-level PII capture and reporting. Walled garden operating systems such as iOS and Android are increasingly tightening a user’s freedom to install software such as Tor.
Finally, the Tor onion network can be made available to more users on more devices through advancements in web technologies. Using The Onion Shell, users can now connect to the Tor onion network from their browser with real browser-initiated onion circuits. This talk will include demos, a discussion of the effort, and new risks this technology introduces, such as enhanced exfiltration techniques.
An Open Forum for Legal Research
Legal research is infamous for guarded access (law firms only) and high prices (monthly and per-search). This year at HOPE, see the launch of an open-source legal search engine, and a public forum for legal research. Learn how to model legal sources using vector and graph databases, how to acquire records using scrapers, and how to connect directly to the people at Congress producing and publishing these records each day.
Organizing in Layer 8 – Building Tech in Democratic Socialists of America
The Democratic Socialists of America (DSA) is the largest socialist organization in the country, swelling in the past ten years from just a few thousand to over 110,000 dues-paying members. They believe that working people should run the economy and society democratically to meet their needs, not to make profits for a few, and so they prioritize mass campaigns that center the working class, like labor and tenant organizing and class struggle elections – including winning the mayor’s office here in New York City. Using technology to build DSA’s political independence and their membership’s organizing capacity has been key to helping them grow and succeed. This talk aims to provide an overview of DSA’s technology use, address real world problems with adopting closed and open-source tools, and outline their efforts to create a politically independent tech stack, as well as discuss other challenges organizing on Layer 8 – the Political Layer.
Poisoning the Well: How Decoys and Misdirection Protect Privacy When Opting Out Isn’t Enough
What do you do when data opt-outs and removal aren’t options? You make your personal data harder to find, harder to trust, and harder to act on. Drawing on real casework from advanced security clients, this talk covers open-source and vetted closed-source techniques for generating synthetic noise in personal targeting datasets, including a real case study with an honest post-mortem on what worked and what didn’t, plus a breakdown of state-level address confidentiality programs as a legal shield against non-government actors. Attendees will leave with a practical threat model and a clear framework for knowing when removal is effective, when deception is necessary, and when disruption is the only move left.
A Practical Guide to Facial Recognition Evasion
Sick of being recognized everywhere? Us too! This talk covers physical disguise and facial recognition evasion techniques, both in the visible light and IR spectra. Prowex will talk and demo you through methods to use, and Rambo will introduce you to a tool he open-sourced (nullface.me) that helps you check whether your facial disguise is working.
Privacy’s Defender: My 30 Year Fight Against Digital Surveillance
In this talk that parallels her recently released book of the same title, Cindy Cohn (former executive director of the Electronic Frontier Foundation) weaves her own personal story with her role as a leading legal voice representing the rights and interests of technology users, innovators, whistleblowers, and researchers during the Crypto Wars of the 1990s, battles over NSA’s dragnet Internet spying revealed in the 2000s, and the fight against FBI gag orders. No promises, but she may be joined on stage by a key client or two.
Rapid Response Tech – The Role of Tech Infrastructure in the Twin Cities Anti-ICE Resistance
Last December, Trump’s DHS unleashed “Operation Metro Surge” – a full-scale occupation of Minneapolis and St. Paul characterized by mass abductions, abuse and murder of abductees, and the high-profile executions of Renee Good and Alex Pretti at the hands of ICE agents. This operation was met with widespread, decentralized, and highly coordinated grassroots resistance via interconnected hyperlocal rapid response groups, facilitated by metro-wide digital infrastructure and data processing systems.
Networks of local organizers, hackers, and technologists built out extensive technical capacity for widespread occupation resistance, including systems for secure and coordinated rapid response communication, systems for tracking abductees through the highly opaque immigration system, and sophisticated monitoring systems for tracking ICE personnel, drones, and vehicles. This technical capacity has remained critical to the resistance against ICE operations, and organizers in other cities have become increasingly interested in similar infrastructure.
This talk will provide a comprehensive outline of these logistical, communications, and data processing systems; the ways these systems were effective, the ways they fell short, and most importantly, how hackers and technologists can better organize to build new iterations of this infrastructure within their own regions and contexts.
Real-Time Ad Blocking via HDMI Man-in-the-Middle
You bought the TV, and you pay for the subscription – so why do you still get ads? Modern streaming ads are baked into the stream as the content, out of reach of any network hacks. Minus is a small device that sits between your streaming box and your television and does the blocking in hardware, with no cloud dependency, using open models running on a single-board computer. It intercepts the signal between a streaming stick and the TV and goes after ads on the screen itself. This talk offers a hands-on look at the hardware and ML detection pipeline, and a broader case for the right to control what plays on a device you own.
Remembering Hackers 31 Years Later
Emmanuel Goldstein, Renoly Santiago
The iconic mainstream movie about the hacker culture in New York City has endured over the years better than most would have expected. People still quote various lines on a regular basis, the story was less farfetched than most other hacker tales of the time, and the soundtrack remains a favorite to many. Phantom Phreak (played by Renoly Santiago) was one of the fan favorites. Renoly will describe what it was like to be a part of this project and how this role helped to shape his career. Emmanuel Goldstein will recollect the writing process of Rafael Moreu, what it was like to interact with the stars of the film, and how various decisions shaped the finished product.
Renoly will be available for autographs and pictures after the panel.
Riding the Pipe: Hack Wi-Fi and Meshtastic via Browser With Cheap Microcontrollers
With the support of Web Serial on Firefox, modern browsers now almost universally support the ability to flash firmware to cheap microcontrollers and control them directly. This allows microcontrollers to be used as browser-controlled radio pipes to send and receive signals in ways very useful to hackers. Kody will go over examples of hacking Wi-Fi and Meshtastic with bleeding edge techniques, and even creating beautiful visualizations of the invisible wireless world, all using a browser and low-cost microcontrollers.
Seeing Inside the Mind of AI: Tracing Agents, Tools, and Weird Decisions
AI is starting to feel less like software and more like a strange coworker with root access. It can read, write, reason, call tools, trigger workflows, move data, spend money, and make decisions across systems most people barely understand. We see the prompt. We see the response. But the interesting part happens in the middle, where AI-driven systems fan out through APIs, containers, queues, databases, serverless functions, model calls, SaaS platforms, and external services.
This talk is about opening up that middle. Michael Barbine will take the audience on a practical, funny, and deeply suspicious tour of what it means to instrument AI systems so we can see what they are actually doing. His approach comes from security, observability, automation, and an unusually disciplined obsession with games, rules, feedback loops, and measurable behavior. Whether debugging infrastructure, testing endpoint defenses, building agentic workflows, or playing tens of thousands of rounds of Rock Paper Scissors, the core question is the same: what happened, what changed, what pattern did we miss, and how do we prove it? Using distributed tracing, structured events, correlation IDs, audit trails, and purpose-built observability patterns, we can follow AI workflows across modern infrastructure and catch the moments where things get weird. Where did the agent hesitate? What did it call? What did it retry? What did it hallucinate? What did it spend? What data did it touch? What did it decide quietly? And why should anyone trust a system they cannot inspect?
This is a talk for hackers, builders, defenders, operators, and anyone who has ever looked at a black box and taken it personally. It connects classic hacker curiosity with one of the most urgent problems in modern computing: how to understand systems that are becoming more autonomous, persuasive, and embedded in everyday life. Attendees will leave with practical patterns for tracing AI applications, a clearer mental model for debugging agentic systems, and a renewed appreciation for the ancient hacker principle that mystery is not an acceptable interface.
The Server Knows Nothing: Designing Emergency Apps With Nothing to Subpoena
ReadyNow! is an emergency response app designed to help immigrant communities in the United States in the event of ICE/CBP detention. In a crisis moment, the app can notify trusted contacts and help trigger a pre-planned response. But building an emergency tool for vulnerable communities comes with a paradox: the very act of using the app can expose not just the user, but their loved ones, their community, and their broader contact network. Jason will explain how the app set out to ensure that it would never become an “arrest bingo card” – a system that quietly maps relationships and risk. This talk is a case study in designing “security-first” systems where the adversary isn’t hypothetical, and where metadata and contact graphs are as sensitive as message content. The central technical and product challenge will be explored: how do you send messages on someone’s behalf without the organization ever knowing the message or the recipients? The talk will go through the design constraints that led developers to keep data encrypted and local to the device, and to deliberately build a system with minimal server-side visibility. Finally, a problem that’s often ignored in security engineering will be covered: opaque security doesn’t make users feel secure. For people facing real-world threats, trust requires clarity. The tradeoffs between safety, functionality, and observability will be discussed, and practical lessons for building high-risk apps that are secure by design – and legible enough for users to believe – will be shared.
Show Network Security – A Time of Major Transition
Computer networks have become a critical part of control and media distribution for concerts, theater productions, and other live events – and in theme parks, escape rooms, museums, and other permanently installed entertainment attractions throughout the world. As show technology evolved, simple serial point to point control protocols were initially ported onto the network while, eventually, network-centric open and proprietary protocols control were developed. In addition, network-based media transport solutions have become the primary solution for low- latency distribution of live audio and video. However, few of the standards and protocols in widespread use today have any intrinsic security features, and the industry has relied primarily on “security through obscurity” and physical access control to small, closed, offline systems. While the need for enhanced security solutions has grown along with the industry, the roll out of the EU Cyber Resilience Act (CRA), which mandates security, has made clear that solutions must be developed sooner rather than later. The entertainment technology industry has responded with two primary solutions: ESTA’s proposed ANSI standard BSR E1.88 Framework for Entertainment Network Cybersecurity and Efficiency (FENCE), and Singularity’s independently developed, free to use Sig-Net. How all this will shake out is unknown, but this talk will provide background on the issues and the current status of the solutions.
Source Protection and Digital Security Techniques Under Surveillance
Surveillance has become so ubiquitous that no one knows how to protect oneself from it. This talk is about how to shield journalists, activists, and sources from surveillance, and ways to think about the threat. Smitha is a journalist who has reported in the Yemeni American community about passport revocations before Trump. She will talk about methods she used to approach sources in vulnerable communities and make them feel safe. She will discuss how to “threat-model,” new approaches to educate sources and help sources give information, and the laws that make it difficult for whistleblowers and sources.
The second part of the talk discusses public education campaigns for sources to pass information on safely to newsrooms and journalists, as well as data protection laws and ways to protect data from surveillance in communications between journalists and sources. It will cover ways to bolster a global movement against surveillance and data retention by multinational corporations to enhance privacy and to protect the act of journalism globally. The Espionage Act will be examined and examples of sources and whistleblowers being prosecuted will be discussed.
Spacesuits, Mars Boots and Vegan Roots in the Desert Regolith: Field Testing the Tardigrade v.1 EMU Under Pressure in the Badlands
Scott Beibin, Elizabeth Jane Cole
The Tardigrade v.1 EMU (extravehicular mobility unit) is designed for pressurized EVAs (extravehicular activities) during space analog research missions that focus on training for Mars and lunar surface exploration. The suit system concept emerged from a collaboration between Dr. Cameron Smith (Smith Exploration Garments), Scott Beibin (Offworld Voyage), and Elizabeth Jane Cole (Offworld Voyage), with the goal of developing a pressurized EMU training suit platform intended for improved human mobility capabilities on rough terrain during EVAs. The system is designed for easy installation and testing of experimental modular telemetry and communication systems, as well as ease of donning and doffing by analog astronauts during immersive space exploration training mission simulations. The presenters will demonstrate the capabilities and features of the Tardigrade v.1 EMU space exploration training suit platform and share a report back from the first field test held in a remote desert location.
Speculative Solidarities: Sanctuary Cell Division – A Call to Action
Camille Acey, Rev. Elæ Moss Benedetto, Rev. Eon, Jorge Luis
This panel discussion brings together organizers, technologists, faith practitioners, and care workers to examine how sanctuary systems are being stress-tested in real time. As surveillance expands and mutual aid networks face increasing legal risk, the people doing the most critical protective work are operating through fragile, improvised systems. Meanwhile, those who need refuge – undocumented neighbors, trans youth, abortion seekers, journalists, organizers – continue to show up at the doors of churches, hackerspaces, clinics, and encrypted channels asking the same question: will you hide me, will you teach me, will you stand? The discussion begins from the premise that faith infrastructure, technical infrastructure, and care infrastructure must learn to operate together. The conversation focuses on concrete tensions: operational security in community settings, coordinating without increasing surveillance exposure, managing resource flows without creating legal liability, and sustaining the physical and nervous systems of the people doing the work. The format emphasizes exchange, disagreement, and synthesis across domains.
Stop “Thinking Of” the Children. Start Listening to Them.
Authoritarian governments around the world are exploiting legitimate fears about the harms of Big Tech and surveillance capitalism to ram through policies that expand censorship and build surveillance into every device we own and every piece of software we use. “Child protection” is the frame being used to manufacture consent for these draconian policies. And there are good faith actors being duped into supporting authoritarian policies who genuinely want to address harm and protect kids. Activists have been effective in holding back the worst policies in many places, and technologists continue to build privacy-preserving tools that help vulnerable people protect themselves. But in the end, dangerous censorship and surveillance laws will keep coming back until we change hearts and minds and move the dominant narrative from “protecting” kids to listening to and empowering them. Young people have been at the forefront of every social movement throughout history that has led to positive social change. But that never seems to be part of conversations about the rights and safety of young people online. Come hear from Evan Greer, director of Fight for the Future, about how we can build a movement of young people, parents, educators, and human rights advocates to defang the “think of the children” narrative and build a future where young people have safety and rights.
There are about 20 billion videos on YouTube, with a median view count of just 41. 800 million have never been seen by even one person. For all the press and politics about Internet platforms, basic statistics like these are hard to come by. We typically don’t know how large platforms are, what languages their content is in, and what regular people use them for because – especially in the “post-API age” – most of what we do know is filtered through opaque, attention-optimized recommendation systems. But it’s a project worth doing, not just for the sake of transparency and auditing, but because they are also rich, global repositories of everyday life and culture that are deprioritized in favor of MrBeast.
This presentation will explain the research program that has been built at the University of Massachusetts Amherst dedicated to the production and study of representative samples of social video sites. More important than what’s already been done is what’s still left to do. The purpose of this talk is to get people excited about solving the technical challenges associated with random sampling. YouTube and TikTok have been figured out, but, absent meaningful legislation to mandate platform transparency in the public interest, there are big open questions about most sites, especially smaller platforms and those that are less popular here in the U.S.
Lex is a one-person managed services provider – the outsourced IT department. This presentation is the answer to all the questions thatLex-from-20-years-ago would have had. This talk will tell why he went into business for himself and include day-to-day operations, how he got clients, how he figured out how much to charge, and the actual methods used, including each of the tools (remote management software, help desk software, etc.) and costs.
Tell Stories, Save the World: How Hackers Are Basically Shakespeare
This talk explores the hidden power of narrative in art, technology, and hacker culture. Drawing on everything from representation and role models to UX and science fiction, Kestral Gaian argues that anyone building any technology is already basically Shakespeare.
They’re Already Knocking: High-Interaction Honeypots for the Rest of Us
The Internet can be a pretty scary place, and if you know where to look, you can find proof of that in your logs. This talk walks through the end-to-end deployment of a high-interaction honeypot: platform selection, decoy service configuration, network placement, and logs that surface actionable intelligence rather than a bunch of noise. Once the trap has been set, you’ll get a look at what it catches. Whether you’re an experienced security expert or just someone who wants to understand what’s going on with your network in the middle of the night, this talk will show you that running your own threat intelligence operation is easier than you think. All you need is a Linux box, a spare IP address, and the patience to watch and learn.
To Kill the Telephone System’s Ghost
The telephone system hasn’t existed for decades, but its ghost lives on. We still use telephone numbers, but the Strowger exchanges built with 1890s technology of relays went long ago and so have most of the systems built to replace them. What we are left with is a system that is no longer fit for purpose. As with SMTP email, the utility of the system has been lost to abuse (spam) long ago. It is time to replace it with something better. Replacing the telephone system appears to be a hopeless task, but what if we could replace all the forms of person-to-person network communication with a single infrastructure that has security built in?
Using Fully Homomorphic Encryption to Build Real-World Software
Fully homomorphic encryption (FHE) enables computation over encrypted data, allowing third parties to process information without ever seeing it. This talk explores recent practical advances in FHE, with actionable guidance for developers building privacy-preserving applications. Along the way, there will be a discussion on the different mental models required to design systems around encrypted computation, as well as the limitations that still stand in the way of broader adoption.
If you had a monkey type IP addresses into a web browser, how long would it take for them to find a web server? A WordPress blog? An admin dashboard? Your smart fridge? elixx explains how a foray into vibe coding led to computing in the Cloud, Big Data problems, and uncovering the dustiest corners of the Internet.
The Watchers You Fed: Feds, Extractors, Data-Brokers
This talk documents the shared infrastructure connecting federal surveillance purchases, commercial data brokers, and municipal ALPR networks. It will cover the Third-Party Doctrine (United States v. Miller, 1976), the legal basis still used for warrantless federal access to commercial surveillance data; Flock Safety’s ALPR contracts with city governments, including the data retention and federal access terms most council members never read before signing; and Retroactive Omniscience, the capacity of AI-augmented systems to reconstruct a person’s movements and associations from years of data that seemed too mundane to matter when it was collected. The presenter will cover three municipalities where organized residents altered ALPR contract terms through public records requests and council pressure rather than litigation, with the specific mechanics broken down for replication: what to request, what to ask at a meeting, and how to make renewal politically costly. Drawn from research for the forthcoming book The Watchers You Fed: Turn the Lens , this talk is aimed at attendees working in privacy advocacy or municipal policy – and anyone trying to understand how government and commercial surveillance data now move through the same pipeline.
We Need to Talk About Signal: Security Assumptions, Threat Models, and Activist Community Risk
Signal provides strong end-to-end encryption, yet its protections are often misunderstood. Many users assume encryption guarantees safety. It does not. Effective security depends on shared threat models, aligned risk tolerances, and consistent operational discipline across the group. When participants operate under different assumptions about risk, anonymity, device hygiene, or message retention, they can unintentionally expose one another to surveillance, infiltration, or targeted retaliation. This presentation examines Signal’s security model, clarifies what it does and does not protect against, and explores how group dynamics shape real-world risk. Drawing on personal examples, it will analyze how communities have been compromised both intentionally and inadvertently.
What It’s Like in a Worker-Owned Creative Technology Cooperative
The Emma Technology Co-op is a five-year-old worker-owned and democratically run creative technology consultancy. They do software consulting in the new media and interactive technology industries. In this talk, you will hear why they chose to start a co-op specifically and how they felt that it could provide a fairer and more stable career path than either a traditional “tech job” or continuing their individual freelancing practices. With that established, the talk will go on to cover how they built our business to address their needs and reflect their politics and sensibilities. If you’ve ever wondered what a day job without bosses or shareholders could look like, this talk can show you their vision for that.
What’s Your Age Again? The Future of Online Age Assurance
As governments around the world introduce new laws intended to create safer and more age-appropriate digital experiences for children and teens, age assurance has become one of the most debated topics in technology policy. Supporters view it as an important tool for protecting young people online and enabling age-appropriate experiences, while critics raise important questions about privacy, civil liberties, free expression, implementation, and unintended consequences.
This conversation brings together two respected voices to explore the complex technical, legal, ethical, and societal questions surrounding age assurance from the perspectives of privacy advocacy, policy, and real-world implementation. Rather than debating simple “for” or “against” positions, the discussion will examine how organizations, policymakers, technologists, parents, and privacy advocates can balance child safety, privacy, parental involvement, regulatory compliance, and individual rights in an increasingly digital world.
Featuring Cindy Cohn, former executive director of the Electronic Frontier Foundation, and Denise G. Tayloe, co-founder and CEO of PRIVO, this session will offer a thoughtful exploration of one of today’s most challenging technology policy issues – moving beyond headlines to discuss what effective, privacy-preserving age assurance could look like in practice.
Zines Against the Machine: Analog Communication for a Digital Dystopia
Zines have long been part of the hacker culture’s communication infrastructure: low tech, hard to censor, and nearly impossible to deplatform. In a time where communication channels face growing control and restriction, zines remain one of the most resilient tools we have. This talk explores why zines still matter, from their roots in underground publishing and organizing to why you should be making one today and how to get started.