troll.fan:~$ cat expo-floor.map
EXPO FLOOR -- HALL C
[VENDOR] [VENDOR] [VENDOR] [VENDOR]
[VENDOR] [VENDOR] [VENDOR] [VENDOR]
[VENDOR] [VENDOR] [VENDOR] [......]
^
"ACTUAL SECURITY"
(nobody at this booth)
Conference Capture
The conferences, the capture, the intelligence agencies in the room.
#SecurityCharlatans
Security conferences are where the industry performs self-awareness. DEF CON started as 100 hackers in a hotel room. Now the NSA recruits there. Black Hat charges $2,600 and lets vendors buy talk slots. RSA took $10M from the NSA to backdoor its own product, then hosted a conference about trust. The compliance circuit sells certifications, runs the conferences, writes the standards, and mandates the continuing education. The loop is closed.
Every entry below is sourced. The pattern is the point.
DEF CON and Intelligence Agencies
From "Spot the Fed" to keynote speaker in one generation
-
Keith Alexander keynote (2012)
NSA director wore a t-shirt to DEF CON, told hackers "we don't hold dossiers on millions of Americans." Snowden proved otherwise 11 months later.
[SecurityWeek] [NSA.gov]
-
"Spot the Fed" game
DEF CON tradition since the 1990s: identify undercover federal agents, win a t-shirt. FBI FOIA files show the Bureau was not amused. By the 2020s, feds were on the program.
[Vice] [DEF CON archives]
-
2013 federal "time-out"
After Snowden, Jeff Moss asked feds to skip DEF CON 21 so the community could "have an honest conversation about the role of the government." They mostly complied. Temporarily.
[NPR] [HuffPost]
-
NSA recruitment table
NSA set up a recruitment booth at DEF CON. Told attendees: "If you have indiscretions in your past, don't be alarmed." The agency that surveils everyone wants to hire the people it surveils.
[CNN Money]
-
Chris Hadnagy ban
DEF CON social engineering trainer. Banned 2022 based on 700+ pages of evidence. Sued DEF CON for defamation. Case dismissed with prejudice.
[The Register] [→ full dossier]
-
Dmitry Sklyarov arrest (2001)
Russian researcher presented on Adobe eBook encryption at DEF CON 9. FBI arrested him at the airport. First criminal DMCA prosecution. Jury acquitted ElcomSoft on all counts.
[EFF]
-
Marcus Hutchins arrest (2017)
Stopped the WannaCry pandemic at 22 by registering a kill-switch domain. FBI arrested him leaving DEF CON 25 — for code he wrote as a teenager. Message received.
[TechCrunch]
RSA Conference — Vendor Capture
The company that took $10M from the NSA hosts an annual conference about trust
-
RSA's $10M NSA deal
RSA Security accepted $10M from the NSA to make Dual_EC_DRBG — a backdoored random number generator — the default in its products. Left the backdoor in place for six years after the flaw was publicly demonstrated.
[The Register] [Cloudflare]
-
2014 boycott / TrustyCon
After the NSA deal surfaced, 9 speakers pulled out of RSA Conference. The EFF organized TrustyCon as an alternative event across the street. RSA's response: "we categorically deny" — while the math proved otherwise.
[EFF] [The Register]
-
Exhibition pricing
RSAC booth space: $14K to $126K. Juniper Networks spent $405K+ on a single booth. The conference is a trade show with talks attached, not a research conference with vendors present.
[RSAC PDF] [CSO Online]
Black Hat — Pay-to-Play
Peer-reviewed talks in front, sponsored slots in back, lawsuits when the audience notices
-
Crown Sterling ($115K sponsored talk)
Robert Grant paid $115K for a Black Hat sponsored talk, claimed to break RSA encryption. Audience heckled. Crown Sterling sued the organizers, Schneier, and individual hecklers for defamation. Case went nowhere.
[The Register] [Techdirt] [Schneier]
-
Dual track system
Black Hat runs two parallel tracks: peer-reviewed Briefings and sponsored sessions. The sponsored slots are purchased, not vetted. Crown Sterling proved what happens when a company buys a stage it hasn't earned.
[Black Hat about page]
-
Jeff Moss split: DEF CON vs. Black Hat
Moss founded DEF CON (1993, hackers, cash only) then Black Hat (1997, corporate, $2,600). Black Hat was acquired by Informa. Moss kept DEF CON independent. Same founder, opposite cultures, and the money went where you'd expect.
[Wikipedia] [CNN]
-
Mike Lynn / Cisco (2005)
Lynn demonstrated a critical Cisco IOS vulnerability at Black Hat 2005. Cisco and ISS ripped 30 pages from the conference booklet, obtained a restraining order, and forced Lynn to sign an NDA. He resigned from ISS on stage rather than stay silent.
[Wikipedia] [Schneier]
TrustCon / TSPA — Content Moderation Capture
Platforms fund the association that defines "best practices" that regulators defer to
-
TSPA founding supporters
Trust & Safety Professional Association founded with support from Meta, Google, Twitter, Microsoft, TikTok, and Omidyar Network. The companies being regulated created the professional body that defines how regulation should work.
[TSPA website]
-
Origins: COMO 2018 / Santa Clara Principles
TSPA grew out of the 2018 Content Moderation conference and the Santa Clara Principles on transparency. Academic origin, industry capture.
[Eric Goldman]
-
Omidyar Network: $100M for "trust deficit"
Pierre Omidyar's network committed $100M to address a "trust deficit" in technology. Funded TSPA and adjacent grants. The eBay founder funding content moderation infrastructure that covers platforms competing with eBay's ecosystem.
[Citizens and Technology Lab]
-
The closed loop
Platforms fund the association. The association defines "best practices." Regulators defer to those practices. The regulated parties wrote the rules the regulators enforce. This is not a conspiracy. It is a business model.
[Citizens and Technology Lab]
[tee] [tee] [tee] [KHAKIS] [tee] [tee] [tee]
^
SPOT THE FED
Intelligence Agency Conference Presence
The agencies in the room, the money on the table, and the research they chilled
-
In-Q-Tel
CIA's venture capital arm. 800+ investments, $1.2B in taxpayer money. Invested in Keyhole Inc., which became Google Earth. The intelligence community doesn't just attend conferences — it funds the companies exhibiting there.
[Wikipedia] [Fortune]
-
NOBUS doctrine
"Nobody But Us" — NSA policy of hoarding zero-days for offensive use. $25.1M annual zero-day budget. The Shadow Brokers leak dumped NSA's exploit toolkit online, proving the hoarding strategy fails catastrophically when the hoard is stolen.
[Wikipedia] [Schneier]
-
Wassenaar Arrangement
Export control regime expanded to cover "intrusion software." Chilling effect on legitimate security research: researchers couldn't share tools or findings across borders without risking prosecution.
[Lawfare] [CyberScoop]
-
Palantir conference ecosystem
Runs its own conference circuit (AIPCon). $570M in government revenue. Built on CIA seed funding via In-Q-Tel. The surveillance company that grew up to host its own trade shows.
[Palantir.com] [Investing.com]
-
DCSA conference targeting warning
The Defense Counterintelligence and Security Agency formally warns that foreign intelligence services target security conferences for recruitment. The conferences where you learn about threats are themselves threat vectors.
[DCSA PDF]
The Compliance Conference Circuit
Write the standard, certify the standard, run the conference, mandate continuing ed, repeat
-
ISC2 / CISSP
$58M revenue. $135/yr maintenance fee per holder. The certification industrial complex: ISC2 defines what security professionals should know, certifies them, charges annual rent, and runs conferences to collect CPE credits it also requires.
[Wikipedia] [CPA to Cybersecurity]
-
EC-Council / CEH
Decade of plagiarism in courseware. Sexist "survey" asking women about hacking in bikinis. Blog documenting it was pressured offline. Still required by DoD 8570. No executive consequences.
[Attrition.org] [Alyssa Miller]
-
ISACA
"Pure money making machine" per Trustpilot reviews. Writes governance frameworks, certifies practitioners against them, runs conferences to deliver CPE credits it mandates. Vertical integration of compliance revenue.
[ISACA] [Trustpilot]
-
PCI Security Standards Council
Founded by Visa, Mastercard, Amex, Discover, JCB. QSA audits cost $30K–$500K. The card brands who created the fraud problem created the compliance body that charges merchants to prove they're addressing it. Regulated parties have no vote.
[Wikipedia] [Spreedly]
-
THE PATTERN
Write the standard. Certify against the standard. Run the conference. Mandate continuing education. Charge for the continuing education. Repeat. The compliance circuit is a subscription service disguised as a profession.
The Standard: Every entry on this page is sourced to court records, news reporting, government documents, or archived watchdog pages. Opinions are commentary; facts are cited. The burden of proof is on us, not the subject. If it can't survive a defamation challenge, it doesn't belong here.
To contribute: Post under #SecurityCharlatans on X. Bring receipts.