DEFCON 34: Forty years of hacking on the same Saturday afternoon

DEFCON 34: Forty years of hacking on the same Saturday afternoon

I presented research at DEF CON 34's Main Track this August. An hour later, Cliff Stoll walked onto a stage down the hall and pulled out an overhead projector. Between those two talks, separated by sixty minutes and four decades of technology, I saw the entire arc of what hacking is and what it has always been.

This is about that afternoon.

Getting There

DEF CON is not a normal conference. It is thirty thousand people filling the Las Vegas Convention Center's West Hall in August, most of them carrying hardware they've modified in ways the manufacturers did not intend. There are villages dedicated to hacking cars, airplanes, voting machines, satellites, medical devices, and locks. There is a room where people try to social-engineer real companies over a live phone line from a soundproof booth. Autonomous AI agents were competing in capture-the-flag for the first time in the competition's history. Across the hall, Bill Swearingen was demonstrating adversarial fabric patterns that make surveillance cameras unable to detect you as a person, and researchers were revealing how they had taken over 36 million GPS smart watches that parents put on their children. The scale is hard to describe until you're standing in it.

I had been to DEF CON before, but never as a Main Track speaker. Getting a talk accepted is a different experience from submitting to a village or a regional conference. The CFP review board is brutal, the acceptance rate is low, and the talks that make it tend to represent months or years of original research. Dan Borgogno and I submitted "The Glass Perimeter: Systematic Bypasses in Biometric Frameworks and the Rise of Synthetic Identity" with more than six months of R&D behind it, seven authorized targets across top-tier fintech and banking applications, eight biometric liveness frameworks, and four SDK families. When we got the acceptance, the weight of it was immediate. This was the stage where the work had to land.

Saturday morning I walked through the LVCC hallways trying to find Track 3. The rooms at DEF CON are enormous, built for thousands of people, and the signage assumes you already know where you're going. I found it, checked the projector, and waited for noon.

The Glass Perimeter

The research started with a question that sounds simple and turned out to be anything but: what happens when identity verification systems make their security decisions on a device the attacker controls?

Every major bank, fintech, and financial services company in the world now uses some form of biometric authentication. You open your banking app, point the camera at your face, follow the instructions on screen, and in a few seconds the system decides you are who you claim to be. The technology behind that decision is built by vendors whose solutions are worth hundreds of millions of dollars and deployed across billions of users globally. The entire architecture rests on one assumption: the environment producing the biometric assertion is trustworthy. The device is honest. The camera feed is authentic. The SDK's verdict is final.

We spent six months proving that assumption wrong. The result was a 100% bypass rate across every framework we tested.

The talk walked through the full journey, from optical deception to kernel hijacking. On one end of the spectrum, we showed how presentation attacks still work: high-fidelity prints designed to avoid the moiré patterns that SDKs look for, silicone masks engineered to replicate the way light scatters through human skin, eye-and-mouth cutout hybrids where a real person blinks behind a printed photograph. These are not sophisticated attacks. They are the most common ones in the wild, and they succeed because vendors often lower their detection thresholds to avoid blocking legitimate users in bad lighting. The tension between user experience and security, what we called the CISO Threshold Dilemma in the talk, is where many of the real-world gaps live.

On the synthetic identity side, we demonstrated something that landed hard in the room. We showed the audience two photos of Dan and asked which one was real. Both were synthetic, generated from just two public pictures. The pipeline from public profile to liveness video is alarmingly short: a few photos scraped from social media, a face model, a cloned voice, and tools like Wav2Lip to sync audio with imagery. We produced deepfake videos that passed biometric validation with a 0.94 face match and 0.96 liveness score. For context, some of these SDKs had their AI-based deepfake detection available as a toggle, and in the deployments we tested, it was turned off.

Then we went deeper into the mobile media pipeline. The core of the research was understanding where camera frames actually live inside an Android device and finding the right point to replace them. We mapped six injection techniques across every layer of the stack, from swapping compressed images at the application level all the way down to writing raw video frames directly into the system's camera service, a process that runs outside the application entirely. Each technique targets a different depth in the pipeline, and each one matters because the biometric SDKs we tested consume camera data at different points. If you inject at the wrong layer, the SDK sees the real feed and your bypass fails.

The hardest target we faced used an integrated anti-tamper engine that killed our instrumentation every nine seconds. We went through over seventy script iterations trying to survive inside the application process. The breakthrough came when we stopped fighting the protection and stepped outside its reach. Android's process isolation meant the SDK's forensic checks could audit everything inside their own process and find nothing wrong, while our injected frames arrived through the normal camera path from a system service the SDK could not inspect. We sustained a ninety-second synthetic video injection, over 2,600 frames, with zero crashes and zero detections.

The implication is architectural, not just technical. These SDKs are multi-million dollar solutions deployed by the largest companies in the world, and they share a structural blind spot: they can only see inside their own process. The moment the attack moves one boundary away, the fortress becomes a glass wall.

We closed the talk with what this means at scale. Synthetic identity fraud is projected to exceed twenty billion dollars annually by 2026. The OSINT-to-deepfake pipeline we demonstrated, five minutes of reconnaissance producing a liveness video that passes KYC, means the cost of creating a verified mule account has collapsed. The economics are brutal: Fraud-as-a-Service subscriptions for biometric bypass tooling run ten to thirty thousand dollars a month, and a single automated tool can produce over a hundred verified accounts per day.

The problem is not facial recognition as an isolated technology. It is the degree of trust that banks and fintech companies place in controls that run entirely on the user's device. When biometrics become the sole barrier, a technology designed to simplify access becomes what we called in the talk a Single Point of Failure. A password can be stolen, but so, it turns out, can a face.

The Transition

After Q&A I walked from Track 3 into Track 5.

Cliff Stoll was about to speak. I knew the name. Anyone who has read The Cuckoo's Egg knows the name. I did not fully know what to expect from the presentation itself.

The room was filling up fast. People who had been in the hallways between talks were flowing in, finding seats, standing along the walls. By the time Stoll started, the room was packed.

And then he pulled out transparencies. Actual transparencies, the kind you put on an overhead projector. He had brought the originals he used to brief the NSA decades ago. He had a slide rule. He had physical objects he held up and waved around while he talked. There was no slide deck in the modern sense. No Keynote, no Figma, no embedded videos, no animated transitions. Just a seventy-six-year-old man, a projector from another era, and one of the most important hacking stories ever told.

The contrast with what Dan and I had just presented, sixty minutes earlier and a hundred meters down the hall, was almost absurd.

Stalking the Wily Hacker, Forty Years Later

In August 1986, Cliff Stoll was an astronomer who had been reassigned to manage computers at the Lawrence Berkeley National Laboratory. He was not a security professional. He was not even particularly interested in computer administration. He was a scientist who had been given a job maintaining UNIX workstations because the lab needed someone and he was available.

One morning he found a bookkeeping discrepancy. A new account had been created without a corresponding billing address. The accounting system was off by seventy-five cents. Most people would have shrugged and moved on. Stoll did not. He started pulling the thread.

What he found was not a student prank or an accounting glitch. An intruder was using LBL as a hub to reach military and defense contractor systems across ARPANET and MILNET. Over the next ten months, Stoll watched this individual attack approximately 450 computers and successfully penetrate more than thirty. The intruder was searching for keywords related to nuclear weapons, SDI, and classified military programs. The trail led through Tymnet X.25 networks, defense contractor modem pools in McLean, Virginia, transatlantic links, and eventually to universities in Bremen and Karlsruhe in West Germany.

The investigation methods were astonishing in their simplicity. Stoll set up printers on serial lines to capture every keystroke in real time. He built crude alarms using pocket pagers triggered by modem calls. He created honeypot files, fake memos about the Strategic Defense Initiative, planted on an obscure LBL computer and alarmed so he would know when someone read them. When the intruder found those files and spent over an hour reading them, the extended connection gave telephone technicians enough time to complete the trace. The intruder was eventually identified as Markus Hess, connected to the KGB through circles in the Chaos Computer Club.

Zack Whittaker, writing up the conference highlights for "This Week in Security," described the experience of watching Stoll's talk as a genuine treat, calling it a joy to see someone with so much love, excitement, and energy about something they care deeply about. From my seat in the audience, that was exactly right. He was waving transparencies around, explaining how he convinced the FBI and the German Bundespost and Pacific Bell and the NSA to cooperate on a trace that none of them individually wanted to own, and the room was completely locked in. In a conference full of AI agents autonomously hacking systems and researchers demonstrating zero-days in Claude and Chrome and Nvidia GPUs, the most captivating talk of the day was a man telling a story about printers and phone lines and patience.

What Changed, What Didn't

I sat there watching Stoll's talk and thinking about the sixty minutes between his presentation and ours.

We had just spent our session talking about synthetic identities generated from two public photos, liveness videos produced by AI that fool the algorithms trained specifically to detect them, and an injection technique that exploits shared memory between system services to become invisible to multi-million-dollar forensic protections. The attack surface we described exists because the identity infrastructure of the modern financial system runs on devices that fit in your pocket, through software stacks so complex that the vendors building them cannot fully audit their own trust boundaries.

Then Cliff Stoll told a story about printers, pagers, phone lines, a seventy-five-cent accounting error, and ten months of patience.

The temptation is to draw a clean line: the world was simpler then, hacking was more romantic, everything is different now. That would make a tidy narrative but it would be wrong.

What struck me, sitting in that room, was how much of what Stoll described mapped directly onto what we had done. Not the tools. The tools could not be more different. But the method, the way of thinking, the actual cognitive work of the thing.

Stoll noticed an anomaly that everyone else dismissed. A seventy-five-cent discrepancy. A billing address that didn't match. His instinct was not to fix it and move on but to understand why it existed. We started our research the same way: the biometric industry's trust model has an assumption embedded in it that nobody seemed to be questioning. The device is trusted. The camera feed is authentic. The SDK's verdict is final. It felt wrong. We decided to find out if it was.

Stoll mapped the intruder's behavior empirically. He watched what the hacker did across dozens of sessions, catalogued the commands, the targets, the timing, the login patterns. He built a profile not by reverse-engineering the intruder's tools but by observing what the intruder actually did and inferring what he was looking for. We did something structurally identical against the anti-tamper SDKs we tested. Instead of trying to disassemble obfuscated protection libraries, we ran a series of graduated experiments: attach and observe, hook one layer and measure how long until the process dies, tighten the screw by one notch, repeat. The result was a behavioral map of what the protection watches and what it doesn't. Not a disassembly. An empirical truth table. The same approach Stoll used with his printers and serial line analyzers, translated into a different instrument forty years later.

Stoll exploited trust assumptions. The intruder assumed nobody was watching. LBL's management assumed security was not their problem. The defense contractor in Virginia assumed their outbound modem pool was safe. Stoll exploited all of those assumptions, keeping the system open to monitor the intruder rather than closing the hole, letting the attacker feel secure while recording everything. Our research exploited the biometric SDK's trust assumption that its own process boundary was the universe. Everything inside the process was audited. Everything outside was invisible. We moved outside and won.

And both investigations required patience that most people would not tolerate. Stoll's took ten months. Ours took six. In both cases, the hardest part was not the final technique but the long series of failures that preceded it, the weeks of work that produced nothing except a clearer understanding of what did not work and why.

The Core of It

If I had to distill what connects these two stories, separated by forty years of technology, it would be this: hacking is not about tools. It is about the willingness to look at a system, notice that something about it does not match the way it is supposed to work, and refuse to let go until you understand why.

The tools have changed beyond recognition. Stoll was tracing connections through X.25 packet-switched networks and coordinating with the German Bundespost over telephone lines. We were injecting synthetic video frames into Android system services to bypass liveness detection SDKs trusted by billions. The scale has changed. The economic impact has changed. The entire landscape of what identity means has changed.

But the underlying act is the same. You find a trust boundary. You test whether the system enforces it or merely assumes it. You discover the gap between the specification and the implementation. You operate in that gap.

Curiosity. Persistence. Hypotheses formed and tested. Anomalies followed instead of dismissed. Trust boundaries questioned instead of accepted. That is the thing that does not change.

Leaving DEF CON

The schedule at DEF CON 34 put our talk and Cliff Stoll's talk on the same Saturday afternoon, one hour apart. I don't know if whoever arranged the program thought about the juxtaposition, but it was perfect.

We presented research about the emerging attack surface around digital identity: synthetic faces, biometric bypasses, the collapse of the trust model that billions of financial transactions depend on. It was a modern problem investigated with modern techniques against vendors protecting modern infrastructure. And then, in the next hour, one of the people who helped define what hacking means stood up with an overhead projector and told a story about chasing a spy through telephone networks with printers and patience.

Both talks were separated by decades of technology. Both were connected by the same impulse. Something about the system did not make sense. Let's find out why.

That impulse existed before we had AI agents competing in capture-the-flag. It existed before biometric SDKs and anti-tamper engines and synthetic identity forges. It existed in 1986, when an astronomer in Berkeley noticed that his accounting was off by seventy-five cents and decided that was worth investigating. It will exist after whatever comes next. The tools will keep changing. The question won't.