Duke Cyber students recently travelled to DEFCON 34 in Las Vegas, Nevada, one of the largest and longest-running hacker conferences in the world. Six members of the club (Peter Banyas, David Shenkerman, Alex Mages, David Jiang, Derock Xie, and Theo Prosise) spent the weekend immersed in talks, competitions, and hands-on villages covering nearly every corner of the security industry. The opportunity to attend this is event was made possible by the generous support of Professor Art Ehuan and the Cybersecurity Master’s Program and the Pratt Engineering Alumni Council.
DEFCON draws tens of thousands of hackers, researchers, government officials, and students each year, and is known as much for its technical depth as for its unconventional, hands-on approach to teaching security. The conference is built around “villages,” which are themed spaces where attendees can try attacks firsthand, ranging from physical security to AI to policy, alongside talks from leading researchers and a running slate of capture-the-flag (CTF) competitions.
Hands-On Villages
Much of the group's time was spent in DEFCON's villages, where members got to test physical and digital attacks in a legal, hands-on setting. In the Physical Security Village, students worked through hotel key card locks, shopping cart wheel locks, and handcuffs, reinforcing the concept that hacking isn't always about creating flaws, but many times about finding ones that implementation has already left behind. In the Voting Village, they examined real voting machines and explored the vulnerabilities that have made election security a national conversation, and in the Adversary Village, they built a command and control system (C2) to simulate adversary attacks.
The group also got a look at security from the hardware level up, sitting in on CPU silicon hacking demonstrations that showed how vulnerabilities can be built into a chip long before it ever runs code. In the Drone Village and Radio Frequency Village, members explored how wireless signals and unmanned systems can be intercepted, spoofed, and manipulated, while a hands-on Ethernet wiring exercise gave students a refresher on the physical networking fundamentals that underpin everything else at the conference.
Competing and Learning
Members chased their own interests by engaging in DEFCON's many competitions, several of which reward winners with an SAO, a small hardware add-on for their conference badge. A cloud-focused CTF and a drone hacking CTF each earned participating members an SAO, while others took on OSINT (open-source intelligence) challenges, searching for real missing people using only publicly available sources. Members also took part in badge hacking, a DEFCON tradition where the conference badge itself is an electronic puzzle to be reverse-engineered and modified; the group's badges ranged from displaying the Duke Cyber technical track's logo to a QR code that, when scanned by another attendee's badge, triggered a kernel panic.
Students also filled their schedules with talks spanning both the technical and policy sides of security, from prominent voices in digital rights to sessions on AI surveillance policy and zero-day vulnerabilities. Between talks, students had the chance to meet some of the most well-known names in the hacking community, providing a rare opportunity to connect the research they study in the classroom to the people actually doing it in the field.
STUDENT REFLECTIONS:
Peter Banyas (Electrical and Computer Engineering, 2026): DEFCON was an amazing experience to be immersed in the hacker community. Of course, the talks were great and spanned technical exploits, policy, culture, and geopolitics. A special piece of DEFCON is the “village” concept where communities with different interests (physical security, aerospace, AI, elections, etc.) convened. There, alongside the demos and activities, we got to have wonderful conversations with other attendees. But the best part of the conference was the enthralling discussion I had with my fellow Duke Cyber Club members who attended; we explored how AI is eliminating points of friction in the justice process and how that changes the relationship between a government and its people. Duke Cyber members are the best; join the club!
David Jiang (Mathematics/Computer Science, 2028): Attending DEFCON will be one of the highlights of my time at Duke, and I fully intend to go back. Walking into the Las Vegas Convention Center, I was struck by the sheer scale of the global hacking community gathered in one place. Over the course of the conference, I built my own botnet, attempted to hack a boat, and learned about zero-day vulnerabilities. While working through a tamper-evident device in one of the villages, I had the chance to sit down and speak with the researcher who famously stopped WannaCry. The coolest part was that the folks at DEFCON weren’t there only to watch talks but also to get their hands dirty and experiment with new technology; I’m excited to bring this spirit back home!
Theo Prosise (Computer Science, 2027): I had a great weekend. Going to DEFCON has always been on my bucket list and I have been so lucky to knock it out early and with my friends from Duke Cyber. Entering Vegas I was overwhelmed with the heat and community. Each and every person at the conference was interested in a field that I am interested in, and it was a novel look into a group of people that normally interact online. I learned from experts in the field on a variety of topics. From call center hacking, novel Windows kernel malware, to drone interception, there were an immense variety of topics from experienced speakers.
Derock Xie (Electrical and Computer Engineering/Computer Science, 2029): DEF CON was overwhelmingly fun; along with numerous interesting and engaging talks, what I enjoyed the most were the DEF CON villages. These villages gave me hands-on experience in many new topics. I successfully fault injected a computer processor, making it release data it had been designed not to, and learned that while modern security algorithms work perfectly in theory, the improper physical implementation of said theory can open the door to new attack vectors. These villages were filled with attendees from around the world, all with a similar interest in security, but each living in their own niches under this umbrella. It was an absolute delight to get to meet and converse with these humans, and I truly intend to participate again.