More on the topic...
Generating detailed summary...
Failed to generate summary. Please try again.
Defcon 34’s badges break from tradition by spotlighting their brains instead of their puzzles. Hardware hacker Andrew “bunnie” Huang built the Baochip-1x, a mostly open-source microcontroller whose entire stack—from processor core to cryptographic engines—is on GitHub. The silicon is packaged under an infrared-transparent substrate, so anyone with an IR light can verify the actual transistors match the published design. That level of transparency tackles the trust problem in chips, where backdoors can be introduced during manufacturing.
Huang didn’t foot the full bill for fabrication. Three years ago Crossbar invited him to piggyback his RISC-V core onto their 22-nanometer wafer run, sharing costs and splitting the die. Crossbar’s proprietary ARM core sits side by side; Huang simply disables it for his ballot. Some low-level process details remain closed, but by open-sourcing nearly everything else, Baochip-1x outpaces other security-oriented silicon in verifiability.
Defcon’s founder Jeff Moss saw a match with this year’s theme of agency and asked Huang to use the chip in 27,000 badges. Each badge carries a detachable module that doubles as a FIDO-compliant hardware token. It supports time-based one-time passwords, stores secrets inside resistive RAM to resist data extraction, and even includes a low-res camera for QR-code logins. Huang claims it’s the first token whose bootloader and transistors you can fully inspect.
Beyond authentication, the badge keeps the social spirit of Defcon alive. Colored LEDs flash in patterns tied to attendee roles—general, speaker, goon or the coveted black Uber badge. When badges talk, they unlock new color combinations and flashing sequences, encouraging people to mingle. The badge’s life extends well past the conference, with open-source software updates and a hardware token you’ll still use months later.
Questions about this article
No questions yet.