DEF CON 33 - Unmasking the Snitch Puck: IoT surveillance tech in the school bathroom - Reynaldo, nyx

With the commoditization of IoT surveillance technology, private and public entities alike have been rushing to put every facet of our lives under surveillance. Unfortunately, schools are no exception in the ongoing privacy race to the bottom. In this talk, we present our analysis of a popular line of IoT vape detectors marketed primarily to schools. Rey first learned of the existence of this device while he was a student in high school, scanning the local network during his lunch break. He became obsessed with the idea of reverse-engineering it, and a couple of years later he got an opportunity when a specimen appeared on eBay. This talk will cover our journey of acquiring the device and doing a hardware teardown. Then, we'll talk about dumping the firmware, examining its behavior, and doing some light reverse-engineering to uncover some fun appsec vulnerabilities. We'll discuss implications of our findings on this particular series of devices, as well as on the ed-tech surveillance industry as a whole. We will release a copy of the device filesystem, as well as our scripts for decrypting OEM firmware and packing custom firmware updates.

DEF CON 34 - ESP32 as counter-surveillance platform - Cybertiger, Colonel Panic, The Wrew
▶︎

DEF CON 34 - ESP32 as counter-surveillance platform - Cybertiger, Colonel Panic, The Wrew

DEF CON 33 - Kill List: Hacking an Assassination Site on the Dark Web - Carl Miller, Chris Monteiro
▶︎

DEF CON 33 - Kill List: Hacking an Assassination Site on the Dark Web - Carl Miller, Chris Monteiro

Stony Brook Southampton Dialogues - A Conversation with New York Climate Exchange CEO, M. Sanjayan
▶︎

Stony Brook Southampton Dialogues - A Conversation with New York Climate Exchange CEO, M. Sanjayan

There Are Files Stored in This Video
▶︎

There Are Files Stored in This Video

DEF CON 33 - Recording PCAPs from Stingrays With a $20 Hotspot - Cooper Quintin, oopsbagel
▶︎

DEF CON 33 - Recording PCAPs from Stingrays With a $20 Hotspot - Cooper Quintin, oopsbagel

From ML Potentials to Agents That Write the Paper: AI for Computational Chemistry
▶︎

From ML Potentials to Agents That Write the Paper: AI for Computational Chemistry

I Built an AI Virus To Destroy This Scammer
▶︎

I Built an AI Virus To Destroy This Scammer

How to Track the People Tracking YOU
▶︎

How to Track the People Tracking YOU

DEF CON 33 - Exploiting Shadow Data from AI Models and Embeddings - Patrick Walsh
▶︎

DEF CON 33 - Exploiting Shadow Data from AI Models and Embeddings - Patrick Walsh

An Israeli surveillance company is HACKING phones globally | Cellebrite EXPOSED | EP01
▶︎

An Israeli surveillance company is HACKING phones globally | Cellebrite EXPOSED | EP01

DEF CON 32 - Hacking Millions of Modems and Investigating Who Hacked My Modem - Sam Curry
▶︎

DEF CON 32 - Hacking Millions of Modems and Investigating Who Hacked My Modem - Sam Curry

7 Concerning Levels Of Acoustic Spying Techniques
▶︎

7 Concerning Levels Of Acoustic Spying Techniques

Attacking AI - Jason Haddix - NDC Security 2026
▶︎

Attacking AI - Jason Haddix - NDC Security 2026

How to Become Your Own ISP
▶︎

How to Become Your Own ISP

Bill Swearingen - HAKC THE POLICE - DEF CON 27 Conference
▶︎

Bill Swearingen - HAKC THE POLICE - DEF CON 27 Conference

DEF CON - noRecognition: Could a pattern on  clothing fool Facial Recognition? - Bill Swearingen
▶︎

DEF CON - noRecognition: Could a pattern on clothing fool Facial Recognition? - Bill Swearingen

U.S. Empire in Decline: Richard Wolff on Iran War, Rising Inequality, $40T National Debt & More
▶︎

U.S. Empire in Decline: Richard Wolff on Iran War, Rising Inequality, $40T National Debt & More

EVERYTHING Is Backdoored. By Default.
▶︎

EVERYTHING Is Backdoored. By Default.

The coolest anti-surveillance tools at Defcon
▶︎

The coolest anti-surveillance tools at Defcon

DEF CON 33 - China's 5+ year campaign to penetrate perimeter network defenses - Andrew  Brandt
▶︎

DEF CON 33 - China's 5+ year campaign to penetrate perimeter network defenses - Andrew Brandt