Notes from DEF CON 33
I have been to nine DEF CONs. This was a good one. Crowded, predictably; the new venue helps but not enough. The hallway track is back to where it was pre-2020, which is the metric that actually matters.
Talks worth catching when video drops
- Faults in the silicon supply chain — a sober look at what “trusted foundry” actually means in 2025. Not breathless. Worth the watch.
- Twenty years of the same SQL injection — exactly what it sounds like. Mostly funny, occasionally bleak.
- Recovering keys from sleep-mode DRAM — beautiful work. The hardware setup was fifty dollars and a hot plate.
Villages
Hardware Hacking Village had the best signal-to-noise ratio. Lockpick Village remains the best place to take a friend who has never been. Skip the AI Village this year — it is going through a phase.
The thing I think we’re getting wrong
Defensive talks are a small minority of the schedule, and they always have been, but the ratio is getting worse. “Here is a creative new attack” is a much easier talk to give than “here is what we changed in our SOC and why it took eighteen months,” but the second talk is more useful to almost everyone in the room.
If you ran a defensive program this year and have something to say about it: submit. Please.