Keynote - Jeff Moss
Jeff Moss (Keynote Speaker)
SAINTCON 2025 · Day 2 · Keynote
Overview
In a candid and insightful keynote address at SAINTCON, Jeff Moss, widely known as "The Dark Tangent" and the visionary founder of both Defcon and Black Hat, offered a sweeping retrospective on the evolution of hacking, the cybersecurity industry, and the challenges facing digital security today. Delivered as an intimate conversation rather than a traditional slide-based presentation, Moss's talk delved into the origins of the hacker community, the changing legal landscape, and the complex geopolitical forces shaping our interconnected world. His unique perspective, born from three decades at the forefront of the hacker movement, provides invaluable context for understanding the present state of cyber defense and offers a provocative outlook on its future.

Key moments
- 0:50 Jeff Moss: Founder of Defcon and Black Hat
- 2:15 How Defcon unexpectedly started from a farewell party
- 4:30 Defcon's purpose: Experts debunking hacker misinformation
- 5:00 Dan Farmer, Satan, and early network scanning tools
- 6:30 The 'magical formula' of Defcon: Experts engaging everyone
- 7:00 Dumpster diving reveals real-world security vulnerabilities
Keynote - Jeff Moss
Speakers: Jeff Moss (Keynote Speaker)
Conference: SAINTCON
YouTube: https://www.youtube.com/watch?v=rNXTezTrvJ4
Overview
In a candid and insightful keynote address at SAINTCON, Jeff Moss, widely known as "The Dark Tangent" and the visionary founder of both Defcon and Black Hat, offered a sweeping retrospective on the evolution of hacking, the cybersecurity industry, and the challenges facing digital security today. Delivered as an intimate conversation rather than a traditional slide-based presentation, Moss's talk delved into the origins of the hacker community, the changing legal landscape, and the complex geopolitical forces shaping our interconnected world. His unique perspective, born from three decades at the forefront of the hacker movement, provides invaluable context for understanding the present state of cyber defense and offers a provocative outlook on its future.
Moss’s discussion highlighted the fundamental shift from an era of "unfettered exploratory freedom" for early hackers to today's environment of "unlimited risk and unlimited harm." He explored the inherent tensions between fostering curiosity and navigating stringent legal frameworks, the commercialization of cybersecurity, and the strategic dilemmas faced by organizations of all sizes. The keynote served as a critical reflection on the industry's progress, its persistent failures, and the philosophical underpinnings of what it means to be a "hacker" in the age of nation-state threats and artificial intelligence.
The talk underscored the importance of community, the surprising benefits of inviting adversaries into shared spaces, and the growing chasm between the capabilities of hyperscale cloud providers and the defensive struggles of small to medium businesses. Moss's insights are particularly relevant for anyone seeking to understand the historical trajectory of cybersecurity, the cultural dynamics of the hacker community, and the strategic imperatives for navigating an increasingly complex and adversarial digital landscape.
Background
▶ Watch: Jeff Moss: Founder of Defcon and Black Hat (0:50)
Jeff Moss's journey into founding Defcon began from a place of exclusion and a desire to connect. In the early 1990s, the hacking scene was largely underground and invite-only, with conferences like HoHoCon, PumpCon, and SummerCon dictating who could participate. Frustrated by his inability to secure an invitation, Moss found himself inadvertently organizing a "going away party" for a disappearing Canadian hacking network, Platinum Net, whose users were primarily in the US. What started as a small gathering in Las Vegas for around 100 people, invited through IRC channels like Pound Hack and Pound Freak, and Usenet groups, quickly grew into something far larger. His initial motivation was simple: to get experts to speak to non-experts, countering the "inordinate amount of nonsense" and misinformation prevalent on early bulletin boards – from fake call tracing disable codes to erroneous legal advice about entrapment.
The first Defcon featured seminal figures like Dan Farmer, then at Sun Microsystems, who spoke about the need for network management and scanning tools, an idea that later led to his creation of Satan (Security Administrator Tool for Analyzing Networks) and a Time magazine cover. Even a prosecutor from Operation Sundevil, Gail Factory, was invited, creating an "awkward" but pivotal dialogue where hackers presented evidence of dumpster-dived telco documents to her face. This blend of technical expertise, legal reality, and raw community interaction defined Defcon's early magic, distinguishing it from the insular "hackers talking to hackers" model.
The early hacking landscape was characterized by an "unfettered exploratory freedom." Activities like software piracy, while common, were not inherently illegal if no money was exchanged. Exploring the telco network was the primary frontier, a complex system with no manuals or Google, fostering a culture of discovery and shared knowledge. As Moss recounts, the "stuff we used to do as kids, there's like federal sentencing minimum guidelines" today, a stark contrast to a time when there were "no bank online, no medical records to wreck, nothing to ransom." This shift in legality and risk fundamentally changed the environment for aspiring hackers, making pure exploration a dangerous endeavor.
The eventual emergence of Black Hat, founded by Moss, represented a parallel but distinct evolution. While Defcon remained committed to its hacker roots, releasing all content for free and resisting corporate sponsorship to avoid compromising its ethos, Black Hat embraced the burgeoning info-sec industry. Moss deliberately carved out a distinction: Defcon focuses on the "hacker mindset"—the joy of discovery, freedom to fail, and learning to think—while info-sec caters to professional tasks, career advancement, and corporate tools. This separation was a strategic decision to preserve Defcon's unique identity amidst the increasing commercialization of cybersecurity.
Key Findings
▶ Watch: Defcon's purpose: Experts debunking hacker misinformation (4:30)
Jeff Moss's keynote offered several profound insights into the cybersecurity landscape, spanning its history, present challenges, and future trajectory.
Firstly, he articulated a clear distinction between the "hacker mindset" and the "info-sec" industry. For Moss, hacking is fundamentally about the joy of discovery, embracing unexpected outcomes, speaking truth to power, and the freedom to fail. He cited a conversation with Facebook's first CISO, who sent his team to Defcon "to learn how to think," not just to sharpen existing skills, which was the domain of Black Hat training. This highlights hacking as a cognitive approach to problem-solving, distinct from the task-oriented, career-driven nature of corporate information security.
Secondly, Moss emphasized the "bigger fish" principle in the realm of cyber adversaries. Through anecdotes like "Grock"—a hacker operating deeper within AT&T's systems, observing other hackers like MOD and LOD—he illustrated that there is "always a bigger fish." This principle, he noted, is now manifest at the nation-state level, with multiple state actors potentially "time-sharing" access to critical infrastructure, a problem hackers faced 30 years ago.
Thirdly, the keynote underlined the global nature of cyber problems and the necessity of international engagement. Moss explained his rationale for expanding Defcon into countries like China and Bahrain: "internet problems are global problems... you're not going to solve global problems from one position." Building relationships with hackers in diverse regions, like the "hundreds of Chinese hackers" who excelled at Defcon CTFs, provided invaluable alternative perspectives and intelligence, often contradicting Western narratives. He shared a fascinating story of how Chinese offensive capabilities were honed through fierce, government-sanctioned corporate cyber warfare between giants like Alibaba, Tencent, and Chihu 360, leading to their dominance in international competitions like Pwn2Own.
Fourthly, Moss painted a bleak picture for small to medium businesses (SMBs) facing nation-state threats, stating, "you're doomed if they come after you." This stark assessment underscores a significant power imbalance. He argued that hyperscalers like Microsoft, Amazon, and Google are becoming the de facto battlegrounds for cyber conflict, with Microsoft's Azure serving as the "terrain" where Russia and Ukraine clash. These giants, constantly under pressure, are "light years ahead" in defense, capable of "changing reality" (e.g., routing) to disrupt adversaries. This trend suggests a future where SMBs must either outsource extensively or rely on the inherent defenses of these dominant platforms, potentially increasing their centralizing power.
Finally, Moss critically examined the industry's persistent failures and its self-deceptions. He asserted that the cybersecurity industry often tells itself it "can solve the problem," when in reality, it hasn't solved fundamental issues like secure email or DNS security. He introduced the "fighting cancer" analogy: "you're here fighting cancer. You're not here to solve cancer." This perspective encourages focusing on "better patient outcomes" and "quality of life" rather than the unrealistic goal of complete eradication, which can lead to frustration and burnout. He attributed many persistent security gaps to a lack of economic incentive, where "low profitability, high security returns" projects, like creating secure email by default, fail to attract venture capital.
Technical Deep Dive
▶ Watch: Dan Farmer, Satan, and early network scanning tools (5:00)
Jeff Moss's keynote, while conversational, touched upon several key technical concepts and historical exploits that shaped the early hacking landscape and continue to resonate today.
One of the earliest technical shifts he highlighted was the advent of network automation scanning tools. He credited Dan Farmer with recognizing the need for automated network management at Sun Microsystems, leading to the development of Satan (Security Administrator Tool for Analyzing Networks). Satan, an early vulnerability scanner, became a significant milestone, allowing administrators to identify potential weaknesses across large networks, a concept now foundational to modern vulnerability management.
The discussion also revisited early phreaking and social engineering. Moss recounted common myths from bulletin boards, such as typing specific numbers to "disable call tracing" or believing disclaimers like "no police allowed" constituted entrapment. These anecdotes illustrate the blend of technical curiosity and often naive understanding of telecommunications infrastructure and legal frameworks among early hackers.
Dumpster diving was presented as a crucial, albeit physical, "technical" exploit. Moss and his peers, including those from Hectic and ZZQ, would raid dumpsters of organizations like the Department of Workforce Services, retrieving documents containing personally identifiable information (PII), including social security numbers. This demonstrated a fundamental flaw in information disposal that, while seemingly low-tech, yielded sensitive data and underscored the importance of physical security long before digital breaches became commonplace.
The talk delved into the intricacies of early wide-area networks, specifically the X.25 network. This packet-switched network was the backbone for many early digital communications, including ATM machines. Moss described two competing X.25 operators, TimeNet and MCI (or GTE), each with their own supervisory systems like TDD2 and X-ray. He recounted the legend of Parmmaster, a hacker who gained X-ray access, allowing him to control and monitor the entire X.25 network. Parmmaster could observe all ATM transactions on the East Coast and, critically, "change account numbers in real time" as they passed through a packet assembler/disassembler (PAD), though he never criminally exploited this capability. This story highlights the profound control early hackers could exert over core infrastructure due to unencrypted, circuit-switched protocols.
Moss also referenced the legendary battles between hackers like MOD and LOD across AT&T infrastructure, often involving systems like thumper.bellcore.com. This era saw hackers deep within the telco's internal networks. The "bigger fish" concept was exemplified by Grock, another hacker who operated even deeper, "keeping the system stable" while watching MOD and LOD, taking their exploits and learning from them. This multi-layered access to critical systems foreshadowed today's complex nation-state intrusions.
A persistent, foundational vulnerability discussed was SS7 (Signaling System No. 7). Moss revealed that this vulnerability, which allows for global geolocation tracking and intercepting communications, has been "intentionally been left in the SS7 system for decades" by certain law enforcement agencies. This highlights a deliberate trade-off between surveillance capabilities and widespread security, leaving critical infrastructure vulnerable for strategic advantage.
The talk also touched upon the deprecation of DANE (DNS-based Authentication of Named Entities). DANE allowed website owners to publish their TLS fingerprint in DNS, enabling browsers to validate self-signed certificates without relying on potentially compromised Certificate Authorities (CAs). This gave website owners control over their cryptographic destiny. However, Chrome's performance engineers removed DANE support because the DNS lookups added "some milliseconds" to page load times, sacrificing a critical security and decentralization feature for marginal speed gains.
Finally, Moss discussed the emerging role of Artificial Intelligence (AI) in hacking and Capture The Flag (CTF) competitions. He described a Defcon Live CTF scenario where an agentic AI system autonomously solved a challenge, autosubmitted the flag, and won, leaving the human competitor unaware of his victory. This illustrates AI's potential to automate complex hacking tasks and its transformative impact on offensive security. He drew an analogy to Garry Kasparov's experience with chess, predicting that the future of CTFs and hacking will involve a "hybrid synthesis" of human intuition and machine speed for optimal results.
Demo / Proof of Concept
▶ Watch: The 'magical formula' of Defcon: Experts engaging everyone (6:30)
As a keynote interview, this talk did not feature a live technical demonstration or proof of concept in the traditional sense. Instead, Jeff Moss's narrative was rich with historical anecdotes that served as vivid "proofs of concept" of early hacking capabilities and vulnerabilities.
For instance, the story of Defcon attendees bringing back "bags of telco documents" from the Department of Workforce Services dumpsters, some containing "people's social security numbers," served as a real-world demonstration of physical security vulnerabilities and the efficacy of dumpster diving in obtaining sensitive information. This informal "demo" directly informed a prosecutor about real-world data disposal failures.
Similarly, the detailed account of Parmmaster's access to the X.25 network's X-ray supervisory system illustrated a profound, albeit unexploited, proof of concept. Parmmaster's ability to "change account numbers in real time" for ATM transactions, even if he didn't use it for criminal gain, demonstrated a critical vulnerability in the financial infrastructure of the era. These historical narratives, while not live demonstrations, provided concrete examples of the technical prowess and impact of early hackers.
Defensive Implications
▶ Watch: Dumpster diving reveals real-world security vulnerabilities (7:00)
Jeff Moss's keynote provides several critical defensive implications for organizations and the cybersecurity industry as a whole, highlighting the need for strategic shifts in how we approach security.
For Small to Medium Businesses (SMBs): Moss's stark declaration that SMBs are "doomed" if targeted by nation-state actors is a crucial defensive takeaway. It implies that traditional, self-sufficient security models are insufficient. The defensive strategy for SMBs must shift towards:
- Simplification and Focus on Basics: Avoid getting "caught up in every trend" or adopting "hyperscaler mentality" with unnecessarily complex solutions like Kubernetes for simple services.
- Strategic Outsourcing: Leverage specialized security providers for advanced defense capabilities that are otherwise unattainable.
- Reliance on Hyperscalers: Acknowledge and strategically utilize the robust defensive capabilities of cloud providers like Microsoft, Amazon, and Google. These platforms, being the "terrain" of modern cyber conflict, offer a level of resilience and threat intelligence that individual SMBs cannot match.
For Hyperscale Cloud Providers: These entities are in the "crucible" of nation-state conflict, making them uniquely advanced in defense. Their defensive implications include:
- Continuous Learning and Adaptation: Their constant engagement with sophisticated adversaries pushes them to evolve defenses "light years ahead" of others.
- "Changing Reality" Capabilities: The ability to dynamically alter network routing and environments provides a powerful, if temporary, defensive measure against persistent threats.
- Shifting Geopolitical Relevance: As the US government "steps back" from certain cyber roles, hyperscalers are forging new international relationships and becoming more independent in their threat intelligence and defense strategies, potentially making them less reliant on national governments.
For Governments and Policymakers: Moss critically pointed out the government's role in persistent vulnerabilities and lack of accountability:
- Software Liability: The absence of software liability in the US (in contrast to Europe's upcoming Cyber Resiliency Act (CRA)) allows for rapid, but often insecure, innovation. Governments must consider mechanisms—like capped liability or exemptions for open source—to incentivize secure development without stifling innovation.
- Addressing Legacy Vulnerabilities: The intentional preservation of vulnerabilities like SS7 for intelligence purposes creates systemic risks that impact global privacy and security. Policymakers must weigh these trade-offs and potentially mandate fixes.
- Fulfilling Mandates: Governments need to actively engage in regulating permissible behavior in cyberspace and addressing critical issues like AI's copyright implications, rather than "punting" on complex problems.
For the Cybersecurity Industry and Practitioners:
- Embrace the "Fighting Cancer" Mindset: Recognize that complete eradication of cyber problems is unlikely. Focus efforts on achieving "better patient outcomes," improving quality of life, and increasing longevity through incremental, impactful defenses. This helps manage expectations and prevent burnout.
- Fund Foundational Security: Address the "critical gap" where low-profit, high-security return solutions (e.g., secure email by default) are underfunded. This may require new funding models or public-private partnerships.
- Accept and Manage Complexity: Acknowledge that systems will become "more complex forever" and will "fail in unpredictable ways." Defenders must develop resilience strategies, be comfortable with uncertainty regarding root causes, and prioritize rapid recovery over exhaustive post-mortems for every incident.
- Leverage AI for Defense: While AI can be an offensive tool, its "hybrid synthesis" with human intuition will be crucial for defensive operations, enhancing speed and analysis capabilities.
Overall, the defensive implications underscore a future where security is increasingly centralized within hyperscalers, governments grapple with their regulatory roles, and individual organizations must adopt pragmatic, resilient strategies in the face of inevitable, complex threats.
Key Takeaways
- The "Hacker Mindset" is a Foundation for Critical Thinking: Beyond technical skills, hacking cultivates curiosity, problem-solving, and the freedom to challenge norms, which is essential for innovation and adaptation in cybersecurity.
- Global Collaboration is Imperative for Cyber Resilience: Internet problems transcend national borders, necessitating international connections and diverse perspectives to understand and effectively counter global threats.
- Small Businesses Face Dire Odds Against Nation-States: Without significant resources, SMBs are inherently vulnerable to sophisticated state-sponsored attacks, highlighting the growing reliance on hyperscale cloud providers for baseline defense and the need for strategic outsourcing.
- Fundamental Security Gaps Persist Due to Economic Disincentives: Critical infrastructure problems like secure email and persistent vulnerabilities (e.g., SS7) remain unaddressed because they lack high-profitability models, leading to a "fighting cancer" rather than "solving cancer" paradigm in the industry.
- AI Will Transform Cyber Conflict into Human-Machine Symbiosis: AI's ability to autonomously solve complex challenges will shift offensive and defensive strategies towards a hybrid model where human intuition orchestrates machine speed and analytical power.
- Complexity is the Inevitable Future, Demanding Adaptability to Uncertainty: As systems become infinitely more complex, unpredictable failures will be common, requiring organizations and practitioners to prioritize resilience and accept that definitive root causes may often remain elusive.
About the Speaker(s)
Jeff Moss, famously known as "The Dark Tangent," is a seminal figure in the global cybersecurity community. He is the founder of Defcon, the world's largest and longest-running hacker convention, which he started in 1993, and Black Hat, a premier information security conference. Moss's vision created essential forums for hackers, researchers, and security professionals to share knowledge and push the boundaries of technology. His influence extends beyond the conference circuit, as he consults world governments on cybersecurity matters, offering a unique bridge between the underground hacking culture and national security policy. His keynote at SAINTCON offered a rare, unscripted look into the mind of a leader who has shaped the very definition of the hacker community for over three decades.