This article may rely excessively on sources too closely associated with the subject , potentially preventing the article from being verifiable and neutral.(August 2015) |
Black Hat Briefings | |
---|---|
Status | Active |
Genre | Security Conference |
Frequency | Annual |
Venue | Varies |
Location(s) | United States, United Kingdom, Singapore |
Years active | 27 |
Inaugurated | July 9, 1997 |
Founder | Jeff Moss |
Organised by | Informa Tech |
Website | blackhat |
Part of a series on |
Computer hacking |
---|
Black Hat Briefings (commonly referred to as Black Hat) is a computer security conference that provides security consulting, training, and briefings to hackers, corporations, and government agencies around the world. Black Hat brings together a variety of people interested in information security ranging from non-technical individuals, executives, hackers, and security professionals. The conference takes place regularly in Las Vegas, Barcelona, London and Riyadh. The conference has also been hosted in Amsterdam, Tokyo, and Washington, D.C. in the past. [1] [2]
The first Black Hat was held July 7-10, 1997 in Las Vegas, immediately prior to DEF CON 5. [3] The conference was aimed at the computer industry, promising to give them privileged insight into the minds and motivations of their hacker adversaries. Its organizers stated: "While many conferences focus on information and network security, only the Black Hat Briefings will put your engineers and software programmers face-to-face with today's cutting edge computer security experts and 'hackers.'" [4] It was presented by DEF CON Communications and Cambridge Technology Partners. It was founded by Jeff Moss, who also founded DEF CON, and is currently the Conference Chair of the Black Hat Review Board. [5] Black Hat started as a single annual conference in Las Vegas, Nevada and is now held in multiple locations around the world. [6] Black Hat Briefings was acquired by CMP Media, a subsidiary of U.K.-based United Business Media (UBM) in 2005 [7] [8] which was then acquired by Informa Tech in June 2018.
The conference is composed of three major sections: the Black Hat Briefings, Black Hat Trainings, and Black Hat Arsenal.
The Briefings are composed of tracks, covering various topics including reverse engineering, identity and privacy, and hacking. The briefings also contain keynote speeches from leading voices in the information security field, including Robert Lentz, Chief Security Officer, United States Department of Defense; Michael Lynn; Amit Yoran, former Director of the National Cyber Security Division of the Department of Homeland Security; [2] [9] and General Keith B. Alexander, former Director of the National Security Agency and former commander of the United States Cyber Command. [10]
Training is offered by various computer security vendors and individual security professionals. The conference has hosted the National Security Agency's information assurance manager course, and various courses by Cisco Systems, Offensive Security, [11] and others. [12] [13]
Arsenal is a portion of the conference dedicated to giving researchers and the open source community a place to showcase their latest open-source information security tools. Arsenal primarily consists of live tool demonstrations in a setting where attendees can ask questions about the tools and sometimes use them. It was added in 2010. [14] ToolsWatch maintains an archive of all Black Hat Briefings Arsenals. [15]
Black Hat had historically been known for the antics of its hacker contingent, and the disclosures brought in its talks. In the past, companies have attempted to ban researchers from disclosing vital information about their products. At Black Hat USA in 2005, Cisco Systems tried to stop Michael Lynn from speaking about a vulnerability that he said could let hackers virtually shut down the Internet. [2] However, in recent years, researchers have worked with vendors to resolve issues, and some vendors have challenged hackers to attack their products. [16] [17] [18] [19]
Conference attendees had been known to hijack wireless connections of the hotels, hack hotel television billing systems, and in one instance, deploy a fake automated teller machine in a hotel lobby. [20] In 2009, web sites belonging to a handful of security researchers and groups were hacked and passwords, private e-mails, instant messaging chats, and sensitive documents were exposed on the vandalized site of Dan Kaminsky, days before the conference. During Black Hat USA in 2009, a USB thumb drive that was passed around among attendees was found to be infected with the Conficker virus, and in 2008, three men were expelled for packet sniffing the press room local area network. [21]
Black Hat had initially started within the United States but expanded over the years across USA, Europe, Asia, Middle East, Africa, Washington DC, and Abu Dhabi: [22]
Conference Name | Location | Venue | Duration | Year |
---|---|---|---|---|
Black Hat Asia 2024 [23] | Singapore | Marina Bay Sands | April 16 - April 19 | 2024 |
Black Hat Spring Trainings 2024 [24] | United States, Washington DC | Walter E Washington Convention Center | March 12 - March 15 | 2024 |
Black Hat Europe 2023 [25] | United Kingdom, London | Excel London | December 4 - December 7 | 2023 |
Black Hat USA 2023 [26] | United States, Las Vegas, Virtual | Mandalay Bay | August 5 - August 10 | 2023 |
Black Hat Asia 2023 [27] | Singapore, Virtual | Marina Bay Sands | May 9 - May 12 | 2023 |
Black Hat Spring Trainings 2023 [28] | Virtual | N/A | March 13 - March 16 | 2023 |
Black Hat Europe 2022 [29] | United Kingdom, London | Excel London | December 5 - December 8 | 2022 |
Black Hat USA 2022 [30] | United States, Las Vegas, Virtual | Mandalay Bay | August 6 - August 11 | 2022 |
Black Hat Spring Trainings 2022 [31] | Virtual | N/A | June 13 - June 16 | 2022 |
Black Hat Asia 2022 [32] | Singapore, Virtual | Marina Bay Sands | May 10 - May 13 | 2022 |
Black Hat Europe 2021 [33] | United Kingdom, London | Excel London | November 8 - November 11 | 2021 |
Black Hat USA 2021 [34] | United States, Las Vegas, Virtual | Mandalay Bay | July 31 - August 5 | 2021 |
Black Hat Asia 2021 [35] | Virtual | N/A | May 4 - May 7 | 2021 |
Black Hat Spring Trainings 2021 [36] | Virtual | N/A | March 15 - March 18 | 2021 |
Black Hat Europe 2020 [37] | Virtual | N/A | December 7 - December 10 | 2020 |
Black Hat Asia 2020 [38] | Virtual | N/A | September 29 - October 2 | 2020 |
Black Hat USA 2020 [39] | Virtual | N/A | August 1 - August 6 | 2020 |
Black Hat Europe 2019 [40] | United Kingdom, London | Excel London | December 2 - December 5 | 2019 |
Black Hat Trainings 2019 [41] | United States, Alexandria | Hilton Alexandria | October 17 - October 18 | 2019 |
Black Hat USA 2019 [42] | United States, Las Vegas | Mandalay Bay | August 3 - August 8 | 2019 |
Black Hat Asia 2019 [43] | Singapore | Marina Bay Sands | March 26 - March 29 | 2019 |
Black Hat Europe 2018 [44] | United Kingdom, London | Excel London | December 3 - December 6 | 2018 |
Black Hat Trainings 2018 [45] | United States, Chicago | Sheraton Grand Chicago | October 22 - October 23 | 2018 |
Black Hat USA 2018 [46] | United States, Las Vegas | Mandalay Bay | August 4 - August 9 | 2018 |
Black Hat Asia 2018 [47] | Singapore | Marina Bay Sands | March 20 - March 23 | 2018 |
Black Hat Europe 2017 [48] | United Kingdom, London | Excel London | December 4 - December 7 | 2017 |
Black Hat USA 2017 [49] | United States, Las Vegas | Mandalay Bay | July 22 - July 27 | 2017 |
Black Hat Asia 2017 [50] | Singapore | Marina Bay Sands | March 28 - March 31 | 2017 |
Black Hat Europe 2016 [51] | United Kingdom, London | Business Design Centre | November 1 - November 4 | 2016 |
Black Hat USA 2016 [52] | United States, Las Vegas | Mandalay Bay | July 3 - August 4 | 2016 |
Black Hat Asia 2016 [53] | Singapore | Marina Bay Sands | March 29 - April 1 | 2016 |
Black Hat Europe 2015 [54] | Netherlands, Amsterdam | Amsterdam RAI | November 10 - November 13 | 2015 |
Black Hat USA 2015 [55] | United States, Las Vegas | Mandalay Bay | August 1 - August 6 | 2015 |
Black Hat Asia 2015 [56] | Singapore | Marina Bay Sands | March 24 - March 27 | 2015 |
Black Hat Trainings 2014 [57] | United States, Potomoc | The Bolger Center | December 8 - December 11 | 2014 |
Black Hat Europe 2014 [58] | Netherlands, Amsterdam | Amsterdam RAI | October 14 - October 17 | 2014 |
Black Hat USA 2014 [59] | United States, Las Vegas | Mandalay Bay | August 2 - August 7 | 2014 |
Black Hat Asia 2014 [60] | Singapore | Marina Bay Sands | March 25 - March 28 | 2014 |
Black Hat USA 2013 [61] | United States, Las Vegas | Caesars Palace | July 27 - August 1 | 2013 |
Black Hat Europe 2013 [62] | Netherlands, Amsterdam | Grand Hotel Krasnapolsky | March 12 - March 15 | 2013 |
Black Hat USA 2012 [63] | United States, Las Vegas | Caesars Palace | July 21 - July 26 | 2012 |
Black Hat Europe 2012 [64] | Netherlands, Amsterdam | Grand Krasnapolsky | March 14 - March 16 | 2012 |
Black Hat USA 2011 [65] | United States, Las Vegas | Caesars Palace | July 30 - August 2 | 2011 |
Black Hat DC 2011 [66] | United States, Crystal City | Hyatt Regency | January 16 - January 19 | 2011 |
Black Hat USA 2010 [67] | United States, Las Vegas | Caesars Palace | July 24 - July 29 | 2010 |
Black Hat DC 2010 [68] | United States, Crystal City | Hyatt Regency | January 31 - February 3 | 2010 |
Black Hat USA 2009 [69] | United States, Las Vegas | Caesars Palace | July 25 - July 30 | 2009 |
Black Hat DC 2009 [70] | United States, Crystal City | Hyatt Regency | February 16 - February 17 | 2009 |
Black Hat USA 2008 [71] | United States, Las Vegas | Caesars Palace | August 2 - August 7 | 2008 |
Black Hat DC 2008 [72] | United States, Crystal City | Westin Washington DC City Center | February 18 - February 21 | 2008 |
Black Hat USA 2007 [73] | United States, Las Vegas | Caesars Palace | July 28 - August 2 | 2007 |
Black Hat USA 2006 [74] | United States, Las Vegas | Caesars Palace | July 29 - August 3 | 2006 |
Black Hat Federal 2006 [75] | United States, Crystal City | Sheraton Crystal City | January 23 - January 26 | 2006 |
Black Hat USA 2005 [76] | United States, Las Vegas | Caesars Palace | July 23 - July 28 | 2005 |
Black Hat USA 2004 [77] | United States, Las Vegas | Caesars Palace | July 24 - July 29 | 2004 |
Black Hat Federal 2003 [78] | United States, Tysons Corner | Sheraton Premiere | September 29 - October 2 | 2003 |
Black Hat USA 2003 [79] | United States, Las Vegas | Caesars Palace | July 28 - July 31 | 2003 |
Black Hat USA 2002 [80] | United States, Las Vegas | Caesars Palace | July 29 - August 1 | 2002 |
The Black Hat Briefings '01 [81] | United States, Las Vegas | Caesars Palace | July 11 - July 12 | 2001 |
The Black Hat Briefings '00 [82] | United States, Las Vegas | Caesars Palace | July 26 - July 27 | 2000 |
The Black Hat Briefings '99 [83] | United States, Las Vegas | The Venetian | July 7 - July 8 | 1999 |
The Black Hat Briefings '98 [84] | United States, Las Vegas | Caesars Palace | July 29 - July 30 | 1998 |
The Black Hat Briefings [85] | United States, Las Vegas | Unknown | July 9 - July 10 | 1997 |
DEF CON is a hacker convention held annually in Las Vegas, Nevada. The first DEF CON took place in June 1993 and today many attendees at DEF CON include computer security professionals, journalists, lawyers, federal government employees, security researchers, students, and hackers with a general interest in software, computer architecture, hardware modification, conference badges, and anything else that can be "hacked". The event consists of several tracks of speakers about computer and hacking-related subjects, as well as cyber-security challenges and competitions. Contests held during the event are extremely varied and can range from creating the longest Wi-Fi connection to finding the most effective way to cool a beer in the Nevada heat.
A grey hat is a computer hacker or computer security expert who may sometimes violate laws or typical ethical standards, but usually does not have the malicious intent typical of a black hat hacker.
A black hat is a computer hacker who violates laws or ethical standards for nefarious purposes, such as cybercrime, cyberwarfare, or malice. These acts can range from piracy to identity theft. A Black hat is often referred to as a "cracker".
Summercon is one of the oldest hacker conventions, and America's oldest and longest-running information security conference. It helped set a precedent for more modern "cons" such as H.O.P.E. and DEF CON, although it has remained smaller and more personal. Summercon has been hosted in cities such as Pittsburgh, St. Louis, Atlanta, Washington, D.C., New York City, Austin, Las Vegas, and Amsterdam. Originally run by Phrack, the underground ezine, and held annually in St. Louis, the organizational responsibilities of running Summercon were transferred to clovis in 1998 and the convention took place in Atlanta, dubbed 'Summercon X'.
Black hat, blackhats, or black-hat refers to:
Joanna Rutkowska is a Polish computer security researcher, primarily known for her research on low-level security and stealth malware, and as founder of the Qubes OS security-focused desktop operating system.
Jeff Moss, also known as Dark Tangent, is an American hacker, computer and internet security expert who founded the Black Hat and DEF CON computer security conferences.
A computer security conference is a convention for individuals involved in computer security. They generally serve as meeting places for system and network administrators, hackers, and computer security experts. Common activities at hacker conventions may include:
Elie Bursztein, is a French computer scientist and software engineer. He is Google and DeepMind AI cybersecurity technical and research lead.
In computer security, virtual machine (VM) escape is the process of a program breaking out of the virtual machine on which it is running and interacting with the host operating system. In theory, a virtual machine is a "completely isolated guest operating system installation within a normal host operating system", but this isn't always the case in practice.
Matthieu Suiche, also known as Matt and under the username msuiche, is a French hacker and entrepreneur. He is widely known as the founder of MoonSols and co-founder of CloudVolumes, which was acquired by VMWare in 2014. In March 2014, Suiche was highlighted as one of the 100 key French developers in a report for French minister Fleur Pellerin.
Juice jacking is a theoretical type of compromise of devices like smartphones and tablets which use the same cable for charging and data transfer, typically a USB cable. The goal of the attack is to either install malware on the device, or to surreptitiously copy potentially sensitive data. As of April 2023 there have been no credible reported cases of juice jacking outside of research efforts.
Offensive Security is an American international company working in information security, penetration testing and digital forensics. Operating from around 2007, the company created open source projects, advanced security courses, the ExploitDB vulnerability database, and the Kali Linux distribution. The company was started by Mati Aharoni, and employs security professionals with experience in security penetration testing and system security evaluation. The company has provided security counseling and training to many technology companies.
Iftach Ian Amit is an Israeli Hacker/computer security researcher and practitioner. He is one of the co-founders of the Tel Aviv DEF CON Group DC9723, the Penetration Testing Execution Standard, and presented at hacker conventions such as DEF CON, Black Hat, BlueHat, RSA Conference. He has been named SC Magazine's top experts and featured at Narratively's cover piece on Attack of the Superhackers and is frequently quoted and interviewed
Security BSides is a series of loosely affiliated information security conferences. It was co-founded by Mike Dahn, Jack Daniel, and Chris Nickerson in 2009. Due to an overwhelming number of presentation submissions to Black Hat USA in 2009, the rejected presentations were presented to a smaller group of individuals. The event was named after the "B-side" of a vinyl record.
HackRF One is a wide band software defined radio (SDR) half-duplex transceiver created and manufactured by Great Scott Gadgets. It is able to send and receive signals. Its principal designer, Michael Ossmann, launched a successful Kickstarter campaign in 2014 with a first run of the project called HackRF. The hardware and software's open source nature has attracted hackers, amateur radio enthusiasts, and information security practitioners.
Election cybersecurity or election security refers to the protection of elections and voting infrastructure from cyberattack or cyber threat – including the tampering with or infiltration of voting machines and equipment, election office networks and practices, and voter registration databases.
Ang Cui is an American cybersecurity researcher and entrepreneur. He is the founder and CEO of Red Balloon Security in New York City, a cybersecurity firm that develops new technologies to defend embedded systems against exploitation.
Ciscogate, also known as the Black Hat Bug, is the name given to a legal incident that occurred at the Black Hat Briefings security conference in Las Vegas, Nevada, on July 27, 2005.
Capture the Flag (CTF) in computer security is an exercise in which participants attempt to find text strings, called "flags", which are secretly hidden in purposefully-vulnerable programs or websites. They can be used for both competitive or educational purposes. In two main variations of CTFs, participants either steal flags from other participants or from organizers. A mixed competition combines these two styles. Competitions can include hiding flags in hardware devices, they can be both online or in-person, and can be advanced or entry-level. The game is inspired by the traditional outdoor sport of the same name. CTFs are used as a tool for developing and refining cybersecurity skills, making them popular in both professional and academic settings.