The Scene is Dead
Allison Nixon (Chief Research Officer · Unit 221B)
BSides Las Vegas 2025 · Day 1
Overview
Allison opens her BSides Las Vegas keynote with a deliberate contradiction: she declares the scene is dead, then insists it is more alive than it has ever been—just no longer underground, still full of people she respects. The talk blends autobiography with a researcher’s longitudinal view. She traces dial-up CompuServe, Hunt the Wumpus, breaking SimPark, a high school programming class that taught her how rules work on machines, and a career studying patterns of how humans interact with computers while working the criminal underground since 2011.

Key moments
- 2:00 Ground rules: limited bad-actor naming, no company names, content warning; contrast ‘scene is dead’ vs scene more public than ever.
- 8:00 Structural shifts: Bitcoin wealth incentives and pandemic-driven online population changes in criminal underground communities.
- 10:00 Critique of the ‘get arrested to get hired’ myth; real career penalties; hiring should consider offense nature.
- 12:00 Industry mimicry: ‘security researcher’ labels on harmful actors; OSINT tools abused; ‘CEST’ criminal slang discussion.
- 16:00 Warning on dangerous ‘research’ lurkers; legal surprise around material-support class risks in criminal chats.
- 18:00 Case narrative tying extreme offending to infosec employment themes; CSAM offenders hear the same hiring narratives.
- 24:00 Call to action: trust positions, vetting, talent pipeline ethics before today’s youth offenders enter the workforce.
- 30:00 Interview montage begins: com participants describe OSINT/social-engineering targeting and anti-extortion community dynamics.
The Scene is Dead
Speakers: Allison (full name not stated in the recording), cybersecurity / criminal underground research (employer not named)
Conference: BSides Las Vegas
YouTube: https://www.youtube.com/watch?v=jzMzluaPCEM
Overview
Allison opens her BSides Las Vegas keynote with a deliberate contradiction: she declares the scene is dead, then insists it is more alive than it has ever been—just no longer underground, still full of people she respects. The talk blends autobiography with a researcher’s longitudinal view. She traces dial-up CompuServe, Hunt the Wumpus, breaking SimPark, a high school programming class that taught her how rules work on machines, and a career studying patterns of how humans interact with computers while working the criminal underground since 2011.
Her core claim is escalation: every year the underground has gotten more severe; the crimes are more depraved. She allows that it is probably always been this way to some degree, yet highlights two shifts she treats as significant. The Bitcoin price explosion turned hacking and fraud into a path to retirement money real quick, attracting people who want money velocity more than love of technology. The pandemic brought a massive influx of people not previously deep online, shifting community composition; she says certain lines of activity were absent before the pandemic and appeared after it began—offered as her observation, not in-session proof.
Ground rules: minimal bad actor names (often forgettable groups, not only an “attention” ethics point); no company names, because discourse on platform abuse resembles data breaches discourse ten years ago—blame falls on those who admit problems instead of those who hide them. Content warning; leave without explanation if needed; she avoids shock value.
She closes with a video montage on com entry, victim targeting, ages, feelings, and anti-extortion responses, then Q&A on generations, parents, university ethics, hiring myths, and intervention.
Before that footage she stresses we cannot save everybody: some entrants’ first draw was violent videos—animals and women being harmed—and those people are still entering the talent pool, demanding different thinking about certain offenses. She also notes the industry cannot expel bad actors entirely—they may be fired or bounced from a conference, then hop elsewhere—so structural responses must go beyond single-org fixes.
Background
▶ Watch: Ground rules: limited bad-actor naming, no company names, content warning; co... (2:00)
At nine she watched her father dial CompuServe on a 56k modem—better than 28k, even if she did not know what 56k meant. Hunt the Wumpus was her first game; SimPark was the first she broke, rerouting a slide to dump people in water, then discovering a concession-stand loop that became an infinite money dystopia—hacking is cool. Her programming teacher’s lesson: violate the spirit while following the letter—how computers work—illustrated by importing PHP libraries to satisfy assignments while the teacher smiled and accepted. Teen years: love breaking computers because it was fun; adult work: organizations as breakable systems.
A teenage-era document about finding truth with computers and fixing your own mistakes—not malice from the machine—still resonates; she notes it is one year older than she is. Since 2011 she has worked the underground, drawn to fraud, botnets, and breaking organizations, while watching crime types worsen.
Off-ramps matured: bug bounties, hiring reformed hackers, people aging into families. She calls that noble—then targets a harmful meme: the best way to get a job in security is to get arrested. Factually untrue for a long time, yet it survives as movie and TV plot fuel. Even those who recover face years of career and pay setback. She spoke with people who rebuilt lives after justice involvement; they do not play victim, but she suspects such jokes influenced them—and others—at vulnerable ages.
Key Findings
▶ Watch: Critique of the ‘get arrested to get hired’ myth; real career penalties; hiri... (10:00)
Offense typing and hiring ethics. She has hired convicted hackers and will again, but urges weighing offense nature: some histories rehabilitate more readily; there is some predictive power, though choice stays with the person. She says she would rather hire someone who hacked the Pentagon than someone who targeted a girl, credit cards, or an old person—different mentality—as a hiring ethics point, not legal doctrine.
Identity mimicry and tooling blur. Swatters and other high-harm actors sometimes call themselves security researcher; she jokes about euphemism-treadmilling the title. Com overlaps OSINT: tools learned via fraud turn out to be real companies—hard to separate abused legitimate services from straight-up criminal tools sold with industry terms.
“CEST.” In criminal chatter, CEST means closed source intelligence; she is not aware of legal variants and opines C should mean criminal—her stance in the talk.
Non-reformed black hats and drama. Non-reformed black hats exist; veterans can each name different examples. Much industry drama, she claims, centers a non-reformed black hat.
Public-source sketches (as she describes them). A court doc (not on PACER; via a journalist on X covering 764-adjacent violence) shows someone facing decades who worked at an infosec startup on anti-scam tools—CSAM-category offenders hear hire-for-defense narratives too. An SEC hack participant blamed others, cited college and cyber security major—training repurposed for fraud. An early sexortion figure studied computer science before arrest—skills that aid targeting.
Skill migration. Com, fraud, and sex crimes overlap: extortion and OSINT against minors can pivot to companies; doxing a child is harder (smaller footprint), so honed skills can exceed hers—very hirable, in her grim framing.
Trust versus daycare rules. Jobs touch personal data on adults and minors, including victimization material where abuse could kill. Daycare for five kids implies government-mandated checks; cybersecurity may reach millions of children with unclear minima—expect government imposition if the field ignores trust.
Generational layer (Q&A). Old pattern: stupid youthful mistakes; new layer: initial pull from gore, violence, death videos, viewing hacking as control and coercion—qualitative and quantitative shift, plus self-selection among participants.
Ethics curriculum gap (Q&A). She asked universities for cybersecurity ethics syllabi/textbooks; answers were no dedicated material on scope-of-testing harm—contributing to bull-in-china-shop newcomers.
Fewer “normal” learners underground (Q&A). More legit paths (degrees, practice platforms) may mean fewer mediators stumbling into undergrounds for knowledge—a factor in severity tipping.
Technical Deep Dive
▶ Watch: Warning on dangerous ‘research’ lurkers; legal surprise around material-suppo... (16:00)
Not exploits—sociotechnics: community pathways, platform dynamics, identity labels, and moving tradecraft between contexts.
She stresses compartmentalization: she lurks fraud chats without socializing; she worries about cybersecurity students treating fraud rooms as hangouts without guidance. No proper public playbook for legal and safety boundaries—dangerous. She once warned someone that helping a given actor risked material support to terrorism; the person was surprised, which alarmed her. Incident work shows TTPs “straight out of textbooks” from formally trained offenders.
Demo / Proof of Concept
▶ Watch: Case narrative tying extreme offending to infosec employment themes; CSAM off... (18:00)
No exploit demo. The closing video has young people describe joining com via cybersecurity and doxing interest (one wanted to seem scary around 12). They find people through socials, run open source intelligence, and use social engineering and OSINT tools—sometimes preferring social engineering over deep cybersecurity skill. Ages discussed land 13–17; one cites youngest 11, average ~13. Feelings include satisfaction without pride; communities feel friendly; deterrent sentences draw answers like nothing or life sentence. Anti-extortion groups offer support pathways; clips show tangled loyalties between AE and extortion scenes. Allison wants their words, not shock, to carry the weight.
Defensive Implications
▶ Watch: Interview montage begins: com participants describe OSINT/social-engineering ... (30:00)
Trust, not just skills: match background checks, references, and insider risk to sensitivity—especially minors and victimization data.
Recruiting culture: drop arrest-as-career-plan jokes; add ethics training and honest talk about records and setbacks.
Research safety: teach legal and personal guardrails for criminal-space study. Blocking all comms backfires—kids prioritize regaining access; internet blocks “never going to work” alone.
Parenting: morality taught at home (e.g., don’t steal, don’t be cruel) is the biggest off-ramp; younger kids are still forming ethics—talk about contacts and groups without only shutting everything down.
Framing the problem: treat parts of this as youth gang violence spanning third-party sites, not a single platform story—avoid punishing only transparent companies.
Society/Q&A: partner efforts include arresting those who need it (easier to stomach after the video), while many can still have futures. Surface discovery risk: a 12-year-old’s search once landed a criminal forum first—she is unsure if that persists, but on-ramps matter.
Key Takeaways
- The scene is bigger, visible, not underground—and in her view more severe yearly.
- Bitcoin money and pandemic onboarding changed who enters and why; some violent lines post-date the pandemic onset in her observations.
- Arrest-to-job jokes are false and costly; records cost years of pay and trajectory.
- Offense typing should inform rehabilitation and hiring—not all crimes imply the same mindset.
- Security researcher / OSINT language is mimicked by high-harm actors; CEST in crime contexts reads as criminal closed-source intelligence to her.
- Jobs are trust positions over millions of sensitive records—expect regulation if the industry stalls.
- Generations differ: classic youthful mischief plus entrants pulled by gore/coercion who see hacking as control.
- She offers questions, not a single fix—especially as 764-era youth near employment age.
About the Speaker(s)
Allison (surname not stated). BSides Proving Ground hosted her first talk; keynoting BSides is an honor she names. She studies human–computer interaction patterns and cybercrime since 2011, thanks colleagues “keeping the dream alive,” and does not name an employer. In Q&A she prefers cybercrime research to APT work she caricatures as dull—pairing that drive with duties around arrest, off-ramps, and harm reduction.
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
Uncomfortable, necessary sociotechnical keynote: long-view crime ecosystem analysis, sharp critique of industry myths, and a trust-and-vetting challenge that security culture avoids in favor of skill fetishization.
Heather Calloway (CISO) — MUST SEE
A governance earthquake disguised as a keynote: it reframes insider risk, hiring ethics, and child-safety data stewardship as executive problems—not ‘culture’ talking points—while naming how industry language and myths can accelerate harm.