Security Conferences: DEF CON, Black Hat, and BSides Explained

Security Conferences: DEF CON, Black Hat, and BSides Explained

Every August, roughly 30,000 hackers descend on Las Vegas for what the security community calls "hacker summer camp" - a week that includes DEF CON, Black Hat USA, and BSides Las Vegas back to back. These three conferences represent different philosophies about security research, community, and knowledge sharing, and together they form the most important week on the cybersecurity calendar.

But security conferences happen year-round, all over the world, and they are one of the most underutilized resources for career development, skill building, and networking in the field. This guide explains what each major conference offers, what to expect, and how to maximize the experience whether you attend in person or follow along remotely.

The Security Conference Ecosystem

graph TD
    subgraph LasVegas["Las Vegas - August (Hacker Summer Camp)"]
        BH[Black Hat USA\nResearch + Corporate\n$2,500-$3,500]
        DC[DEF CON\nHacker Culture\n$440 cash]
        BSV[BSides Las Vegas\nCommunity\nFree/Low Cost]
    end
    subgraph Global["Global Events"]
        BHE[Black Hat Europe\nLondon - December]
        BHA[Black Hat Asia\nSingapore - April]
        RSA[RSA Conference\nSan Francisco - May]
        CCCDE[CCC\nHamburg - December]
        HITB[HITB\nAmsterdam + Other]
    end
    subgraph Regional["Regional BSides (100+ Cities)"]
        BSF[BSides SF]
        BSL[BSides London]
        BSM[BSides Munich]
        BSD[BSides Delhi]
        BSO[BSides + 100 more...]
    end
    subgraph Specialized["Specialized Conferences"]
        SP1[ShmooCon - DC]
        SP2[GrrCon - Midwest]
        SP3[DerbyCon - Louisville]
        SP4[Wild West Hackin' Fest]
        SP5[Hardwear.io - Hardware]
    end
    BH --> BHE
    BH --> BHA
    BSV --> BSF
    BSV --> BSL
    BSV --> BSM
    BSV --> BSD

The security conference landscape - from massive corporate events to intimate community gatherings

Security conferences roughly fall into three categories:

Industry conferences (Black Hat, RSA) cater to security professionals, vendors, and corporate buyers. They feature cutting-edge research presentations, vendor exhibition halls, and professional training courses. Attendance costs are high, and many attendees are sponsored by their employers.

Hacker conferences (DEF CON, CCC, ShmooCon) prioritize the hacker community, hands-on activities, and independent research. They tend to be cheaper, more chaotic, and more fun. The culture is distinct - talks are recorded for free distribution, badges are collectible hardware projects, and the social dynamic is very different from corporate events.

Community conferences (BSides events) are local, volunteer-organized events that bring security conversations to cities worldwide. They are the most accessible entry point for newcomers and often the best for making genuine connections.

DEF CON: The Hacker Summer Camp

DEF CON started in 1993 when Jeff Moss (aka The Dark Tangent) invited friends to a party in Las Vegas. It has grown into the largest hacker convention in the world, attracting around 30,000 attendees. But despite its size, DEF CON retains a distinctly countercultural atmosphere that sets it apart from every other security event.

The Culture

DEF CON is cash only for badge purchases ($440 in recent years). There is no pre-registration - you show up, pay cash, and get a badge. This anonymity is intentional and philosophical. The conference values privacy, open knowledge sharing, and the hacker ethic of curiosity-driven exploration.

The badge itself is a tradition. DEF CON badges are custom electronic hardware with embedded challenges. Attendees spend the entire conference trying to solve badge puzzles, which sometimes lead to hidden parties or secret content. Badge design and the surrounding "badge life" subculture have spawned their own cottage industry of independent electronic badges.

The social norms are different from corporate conferences. Mohawks and business suits coexist. Conversations happen easily because the shared passion for security breaks down social barriers. But the "hacker" label carries weight here - people expect substance. Name-dropping and marketing speak are not welcome.

The Villages

DEF CON's villages are themed areas focused on specific security topics. Each village is essentially a mini-conference with its own talks, workshops, and hands-on activities. Notable villages include:

  • Wireless Village: WiFi, Bluetooth, RFID, and RF security. Hands-on workshops, wireless CTF, and research presentations. Bring your own hardware - the BLEShark Nano fits right in for BLE and WiFi analysis alongside the village's activities.
  • IoT Village: Internet of Things security. Researchers demonstrate vulnerabilities in real consumer devices, and attendees can try hacking IoT devices at the soldering and hacking stations.
  • Car Hacking Village: Automotive security research with actual vehicles to test on.
  • Lockpick Village: Physical security. Learn to pick locks, bypass physical access controls, and understand physical security from experts.
  • Social Engineering Village: Social engineering competitions where participants cold-call real companies (with prior arrangement) to extract information using social skills alone.
  • Voting Village: Election security research on real voting machines. This village has produced significant findings about voting system vulnerabilities.
  • Aerospace Village: Aviation and space security. Satellite hacking, avionics, and aerospace system security.
  • Red Team Village, Blue Team Village, AppSec Village: Focused on their respective disciplines with talks and workshops.
Get the BLEShark Nano - $49.99

The CTF

The DEF CON CTF is the most prestigious hacking competition in the world. Qualifying teams compete throughout the year in online qualifiers, with the top teams earning a spot in the finals held during the conference. The finals use an attack-defense format, and winning teams earn legendary status in the security community.

The Talks

DEF CON talks cover everything from zero-day vulnerability disclosures to hardware hacking to policy discussions. Major talks have included demonstrations of car hacking, voting machine exploitation, medical device vulnerabilities, and satellite system compromises. All DEF CON talks are recorded and posted online for free - the conference believes in open access to knowledge.

Black Hat: The Research Conference

Black Hat was founded in 1997 by the same Jeff Moss who created DEF CON, but it serves a very different purpose. While DEF CON is a hacker gathering, Black Hat is a professional security conference focused on cutting-edge research and corporate training.

Briefings

Black Hat briefings are peer-reviewed research presentations. The review board is composed of respected security researchers, and acceptance rates are competitive. Presentations at Black Hat often represent months or years of research and frequently result in significant industry impact - major vulnerability disclosures, new attack techniques, and novel defense strategies debut here.

Notable historical Black Hat presentations include the demonstration of DNS cache poisoning (Dan Kaminsky, 2008), the Stuxnet analysis, and numerous zero-day disclosures that prompted emergency patches from major vendors.

Trainings

Black Hat offers multi-day training courses taught by leading practitioners. These are intensive, hands-on courses covering topics from web application security to malware analysis to cloud penetration testing. Courses cost $2,500-$5,000 on top of the conference registration, making them expensive but highly regarded.

Many security professionals consider Black Hat training the most efficient way to learn a new specialization. The instructors are often the people who literally wrote the tools or discovered the techniques being taught.

The Business Hall

Black Hat's exhibition hall is where security vendors show their products. For buyers, it is an efficient way to evaluate multiple solutions in one place. For job seekers, many companies recruit actively at their booths. For researchers, the vendor parties (especially in the evenings) are networking opportunities.

The vendor presence at Black Hat is a frequent point of criticism. The conference has become increasingly commercialized, with some attendees feeling that vendor marketing overshadows research. The tension between academic/research purity and commercial reality is an ongoing conversation.

Cost

Black Hat USA registration runs $2,500-$3,500 for briefings access. Training courses are additional. Add Las Vegas hotel costs during peak season and meals, and a full Black Hat experience easily costs $5,000-$8,000. Most attendees are employer-sponsored.

BSides: The Community Conferences

BSides started in 2009 when two talks rejected from Black Hat were presented in a bar across the street. The "B-side" concept - like the flip side of a vinyl record - resonated, and the format exploded. There are now over 100 BSides events annually across every continent.

The Format

BSides events are volunteer-organized, often free or very low cost ($10-$50), and focused on community over commerce. Typical BSides features:

  • Single or dual-track talks (more intimate than Black Hat's massive sessions)
  • Open discussion panels and unconference sessions
  • CTF competitions
  • Workshop rooms for hands-on learning
  • Career villages with resume reviews and mock interviews
  • Strong emphasis on including newcomers

The quality of BSides talks varies by city and year, but the best BSides events rival Black Hat for content quality at a fraction of the cost. BSides Las Vegas, BSides San Francisco, and BSides London are particularly well-regarded.

Why BSides Matters

BSides events are the most accessible entry point into the security conference world. The community is welcoming to newcomers, the cost barrier is minimal, and the smaller scale makes it easier to meet people and have real conversations.

For speakers, BSides is where many security professionals give their first public talk. The review process is less competitive than Black Hat, the audience is supportive, and the experience of presenting at BSides builds confidence for larger venues.

For local communities, BSides events create a recurring gathering point for security professionals who might otherwise never meet. The networking value of local BSides events is enormous - many job referrals, mentorships, and collaborations start at BSides.

Other Notable Conferences

RSA Conference (San Francisco, May): The largest security industry conference, heavily focused on enterprise security and vendor exhibitions. Less research-oriented than Black Hat, more business-oriented. The keynotes feature industry leaders and occasionally government officials. Attendance costs around $2,500.

Chaos Communication Congress (CCC) (Hamburg, December): Europe's premier hacker conference, organized by the Chaos Computer Club. CCC has a stronger political dimension than DEF CON, with significant focus on privacy, surveillance, and digital rights. The technical talks are world-class.

ShmooCon (Washington DC, January): A well-curated, mid-sized conference with excellent talks and a strong community feel. Tickets sell out quickly. The DC location attracts significant government and policy participation.

Wild West Hackin' Fest (Deadwood, SD): Founded by John Strand and the BHIS team. Known for high-quality training, a relaxed atmosphere, and being genuinely fun. Smaller and more personal than the Las Vegas conferences.

Hardwear.io (multiple locations): Focused specifically on hardware security. If you work with embedded systems, IoT, or physical security, this is the specialized conference for your field.

Getting the Most From a Conference

Prioritize hallway conversations over talks. This sounds counterintuitive, but talks are recorded and posted online. The conversations you have between sessions - with speakers, other attendees, and vendors - cannot be replicated. Go to talks that interest you, but do not treat your schedule as rigid.

Prepare specific questions. Before the conference, identify people you want to meet and topics you want to discuss. "I am working on wireless security and trying to understand BLE GATT exploitation" is a better conversation starter than "so, what do you do?"

Attend villages and workshops. Hands-on activities teach more than passive listening. At DEF CON, the villages are often more valuable than the main track talks. At BSides, workshop sessions provide direct instruction on practical skills.

Take notes immediately. After each talk or conversation, write down key points, tool names, and action items while they are fresh. Conference information overload is real - without notes, you will forget 90% of what you learned within a week.

Follow up within a week. If you exchanged contact information with someone, reach out within a week of the conference. "Great talking about X at DEF CON - I looked into Y that you mentioned and found it really useful" converts a brief encounter into a professional relationship.

First-Timer Survival Guide

Start with BSides. If you have never attended a security conference, BSides is the best starting point. The community is welcoming, the scale is manageable, and you can test whether the conference experience works for you without significant cost.

Bring a burner phone. At DEF CON especially, assume the WiFi and cell networks are hostile. Experienced attendees bring dedicated devices with no personal data, use VPNs, and disable Bluetooth and WiFi when not actively using them. This is not paranoia - DEF CON's "Wall of Sheep" publicly displays credentials captured on the conference network.

Pace yourself. Las Vegas in August is exhausting. The conferences run from morning to late night, and the temptation to attend everything leads to burnout by day two. Pick your priorities, take breaks, stay hydrated, and sleep. The best conversations often happen at meals and evening events, so conserve energy for those.

Do not be afraid to talk to people. Security conferences are full of introverts who are all slightly awkward at networking. Most people are happy to talk about their work and answer questions from newcomers. The community rewards curiosity and genuine interest.

Bring business cards or a way to share contact info. Despite the hacker aesthetic, networking is a major purpose of conferences. Have a simple way to share your contact information - a business card, a QR code on your phone, or even just your LinkedIn URL.

Budget for the social events. The best networking happens at after-parties, dinners, and informal gatherings. Budget for meals and drinks beyond the conference itself. Many vendor parties offer free food and drinks - check social media for announcements during the conference.

Participating Remotely

Not everyone can travel to conferences. Here is how to get value remotely:

Watch talks online. DEF CON posts all talks on YouTube. Black Hat posts briefings. Many BSides events livestream or post recordings. You get the content without the travel cost.

Follow conference Twitter/X hashtags. During conferences, the security community live-tweets highlights, key findings, and tool releases. Following the hashtag (#defcon, #bhusa, #bsideslv) gives you a curated feed of the most interesting content.

Attend virtual conferences. Several conferences offer virtual attendance options. NahamCon and GrrCon have virtual components. SANS runs fully virtual conferences. These provide structured content with some networking capability.

Join local BSides. With over 100 BSides events worldwide, there is likely one within driving distance. Check bsides.org for a list of upcoming events in your region.

Participate in conference CTFs remotely. Many conference CTFs allow remote participation. This gives you the competitive experience without the travel.

Security conferences are about community as much as content. The people you meet, the conversations you have, and the sense of belonging to a global community of practitioners are what make conferences worth attending. Whether you start with a local BSides or jump straight into the chaos of DEF CON, getting involved in the conference scene is one of the best investments you can make in your security career.

Back to blog

Leave a comment