The Badge Talk

compukidmike (MK Factor)

SAINTCON 2025 · Day 4 · Main Track 2

Overview

The "Badge Talk" at SAINTCON 2023, presented by compukidmike (MK Factor) and featuring contributions from Redacted Vortex and a dedicated team, offered a candid, behind-the-scenes look at the design, manufacturing, and deployment of the conference's highly anticipated interactive badge and its accompanying game. Far from a mere souvenir, the SAINTCON badge is an integral part of the conference experience, serving as a platform for engagement, learning, and community interaction. This year's badge, themed as a comically oversized wrench, was central to a complex network-patching game designed to immerse attendees in the conference's "AI war aftermath" narrative.

Watch on YouTube

Visual summary for The Badge Talk by compukidmike
Visual summary for The Badge Talk by compukidmike

Key moments

  1. 0:00 Introduction and team acknowledgments
  2. 2:00 Origin of the comically large wrench badge
  3. 4:00 Challenges of in-house PCB assembly and panel design
  4. 7:00 Total number of badges produced
  5. 8:00 Badge game physical components and initial design flaw
  6. 12:00 Detailed explanation of the badge game mechanics

The Badge Talk

Speakers: compukidmike (MK Factor), Redacted Vortex

Conference: SAINTCON

YouTube: https://www.youtube.com/watch?v=fYb-d4U15Qc

Overview

The "Badge Talk" at SAINTCON 2023, presented by compukidmike (MK Factor) and featuring contributions from Redacted Vortex and a dedicated team, offered a candid, behind-the-scenes look at the design, manufacturing, and deployment of the conference's highly anticipated interactive badge and its accompanying game. Far from a mere souvenir, the SAINTCON badge is an integral part of the conference experience, serving as a platform for engagement, learning, and community interaction. This year's badge, themed as a comically oversized wrench, was central to a complex network-patching game designed to immerse attendees in the conference's "AI war aftermath" narrative.

This talk served as a post-mortem, detailing the immense effort, innovative solutions, and unforeseen challenges encountered by the badge team. It delved into the intricacies of in-house hardware manufacturing, the complexities of game design, and the unexpected behaviors observed from a highly engaged, and at times, overly enthusiastic, attendee base. The speakers openly discussed technical hurdles, manufacturing woes, game-breaking bugs, and even instances of intentional sabotage, providing invaluable lessons for anyone involved in large-scale interactive hardware projects within a dynamic event environment.

The significance of this talk extends beyond the specifics of a single conference badge. It highlights the dedication required to create bespoke hardware experiences, the critical role of robust backend systems, and the constant balancing act between innovation, technical feasibility, and user experience. For security professionals, it underscores the importance of anticipating adversarial behavior even in a "friendly" game, the challenges of deploying and updating hardware in the field, and the potential of integrated security features like hardware-backed cryptographic chips to enhance digital interactions.

Background

▶ Watch: Introduction and team acknowledgments (0:00)

SAINTCON has a rich tradition of producing elaborate and interactive conference badges, transforming a simple access credential into a multi-faceted puzzle, game, and learning tool. This commitment to unique hardware experiences has become a hallmark of the conference, setting a high bar for the badge team each year. The inspiration for the 2023 badge, a large wrench, drew partly from a Defcon car hacking village badge from years prior, which also featured a wrench design adorned with LEDs. This year, the team decided to escalate the concept, resulting in a comically large wrench measuring 2 inches (50mm) wide, with a distinctive 10mm lanyard hole. The aesthetic design, including intricate corrosion patterns, was a collaborative effort, with particular artistic contributions from compukidmike's wife, Katie.

A critical decision made several years ago, and continued for the 2023 badge, was to undertake in-house pick-and-place assembly of the printed circuit boards (PCBs). This initiative began as a cost-saving measure but quickly evolved into a strategic choice to overcome significant challenges encountered with overseas manufacturing, particularly language barriers and quality control issues. The in-house process, while providing greater control, introduced its own set of complexities, turning each production cycle into a new learning adventure for the team. This year, the manufacturing process involved producing 2,100 badges to accommodate 2,025 attendees, allowing for spares and replacements due to breakage or errors.

The overarching theme for SAINTCON 2023, "rebuilding from what's left of the AI war," heavily influenced the badge game's narrative. Attendees were divided into six factions, tasked with "repatching" a network to connect their headquarters to a central core and extract data. The physical manifestation of this network game involved repurposing telecom boxes acquired from an NPS auction. These boxes, initially designed for network or cable connections, were filled with custom electronics, transforming them into interactive "nodes" where players could physically manipulate connections using their badge. The initial concept for these nodes involved a vertical-opening design with air shocks, but this was quickly abandoned due to safety concerns regarding the force required to close them, which posed a risk of smashing fingers. This iterative design process, from initial concept to practical implementation, is a recurring theme in the badge's development story.

Key Findings

▶ Watch: Challenges of in-house PCB assembly and panel design (4:00)

The development and deployment of the SAINTCON 2023 badge yielded several significant findings across manufacturing, game design, and user interaction:

  1. Manufacturing Vulnerabilities: The custom PCB panels, designed to save space during manufacturing, proved to be critically flimsy. The board house's panel design featured very small connection points to the rails, leading to panel skewing during the automated pick-and-place process and during CNC routing. This resulted in alignment issues for solder paste application and physical damage, with edges of boards being cut off or distorted. The panels also broke apart "way too easy," posing a significant problem for two-sided boards that required two passes through the pick-and-place machine and oven. The acquisition of a new, heavier, and more stable pick-and-place machine, affectionately named "Q" (replacing the less reliable "Pick and Rick"), significantly improved efficiency and quality this year.
  1. Badge Game Mechanics and Challenges: The core game involved players using their badges to interact with physical network nodes (repurposed telecom boxes) to establish connections from their faction's headquarters to a central core. Scoring was based on the length of the established path, with longer paths yielding more points. To prevent trivial exploitation and node guarding, rules mandated unique entry/exit nodes for each connection and a cooldown period between successive actions by the same team on a node. The game's backend, developed by Redacted Vortex, provided real-time dashboards and a playback feature to visualize connections and scores.
  1. Critical Software and Hardware Bugs: A major setback for the game was the failure of Over-The-Air (OTA) firmware updates for the network nodes. While initially functional, later feature additions consumed just enough RAM to prevent the necessary buffers for OTA updates from being allocated. This meant that despite having code to fix known game bugs, the team could not push updates without physically reflashing each node, an infeasible task given the time and scale. This highlights the critical importance of robust memory management and thorough OTA testing throughout the development cycle.
  1. Player Behavior and Sabotage: A disheartening but significant finding was the prevalence of intentional sabotage. While some players engaged in legitimate game strategies like locking nodes by disconnecting cables internally, others resorted to more destructive actions. This included unplugging entire nodes from the network, ripping doors open, breaking latches, and performing "nefarious things inside to the hardware." One wall jack was even broken. This underscored the need to design for resilience against both legitimate and malicious player interactions in an open, physical game environment.
  1. Hidden Features and Engagement: The badge incorporated several hidden features that fostered deeper engagement:
  • AI Inhibitor / AI Security Strip: Two physical components that, if removed (one or both), triggered a bright red warning on the badge. Removing both "disabled protections" and was used to trigger CTF flags reported to the server. 359 people cut the security strip, and 366 disabled the AI inhibitor.
  • Konami Code: Entering this sequence unlocked a hardware test mode, found by approximately 400 people.
  • NFC Tag: The badge featured a writable NFC tag, intended for quick code transfers from nodes or communities, though player interaction with this feature was surprisingly low.
  • Port 5000 Easter Egg: A humorous audio recording listing every service that has ever used port 5000, ending with a simple instruction to "just type 5,000."
  • Exercise Bikes: A returning challenge where players had to average their cadence across two bikes for 25-30 seconds to hit a target, designed to prevent brute-forcing.
  • Unused Buttons: Physical buttons on the HQ towers that lit up but had no functional purpose in the game, providing "joy" to the designers and creating player theories.
  1. Hardware-Backed Security: The badge included a dedicated crypto chip with 16 slots. Most slots were encrypted and locked, used for storing API secrets to secure communications with the backend API, preventing unauthorized requests. A few special slots were intentionally left unlocked and accessible as part of the CTF, providing a hardware-level challenge.

Technical Deep Dive

▶ Watch: Total number of badges produced (7:00)

The SAINTCON 2023 badge and its interactive game represent a complex interplay of custom hardware, embedded firmware, and a robust backend infrastructure.

At the heart of the badge's intelligence is likely an ESP32 microcontroller (implied by the mention of the necessary jumper for reprogramming, a common requirement for ESP32s). This powerful, low-cost Wi-Fi and Bluetooth-enabled chip provides the processing power and connectivity for the badge's interactive features. The badge also features a crucial crypto chip, which provides hardware-backed security. This chip contains 16 distinct slots, which can be used to store data, cryptographic keys, or perform cryptographic operations. For the SAINTCON badge, most of these slots were encrypted and locked, securely storing API secrets. These secrets were essential for authenticating and encrypting API calls made by the badge to the backend server, preventing players from simply replaying or forging requests. A few specific slots were left intentionally unlocked, forming a key component of the conference's Capture The Flag (CTF) challenge, requiring participants to interact directly with the hardware's cryptographic capabilities.

The manufacturing process for the 2,100 badges was entirely in-house, leveraging a specialized pick-and-place machine named "Q." This machine, a significant upgrade from its predecessor ("Pick and Rick"), is described as much faster, more stable, and heavier (1,800 lbs), greatly improving the efficiency and reliability of component placement. The process involved applying solder paste using a stainless steel stencil, followed by component placement and reflow soldering. A key challenge this year stemmed from the PCB panel design provided by the board house. The panels, which contained multiple wrench-shaped badges, had excessively small connection points to the rails. This structural weakness caused the panels to be flimsy and prone to skewing during both solder paste application (where the stencil remained rigid) and during the CNC routing process used to cut out the individual badges. The result was alignment errors and physically damaged boards, highlighting the critical importance of robust panelization in PCB manufacturing. The badges were also two-sided boards, requiring two passes through the pick-and-place machine and oven, further exacerbating issues with flimsy panels that could easily break.

The badge game's physical network nodes were ingeniously constructed from repurposed telecom boxes. These boxes were fitted with custom electronics and multiple RJ11 ports, chosen after initial consideration of RJ45s, which were deemed too large and unwieldy for the badge's form factor. The selection of RJ11 connectors itself was an adventure: after initial samples from Amazon didn't fit correctly, the team ordered "one of every different kind" until they found a batch that provided the "just right amount of pressure" to hold the cable securely. Each node contained internal patching mechanisms that players could reconfigure. These nodes communicated with a backend server, developed by Redacted Vortex, which tracked connections, managed game state, and calculated scores. The server also provided rich dashboards and a playback feature that allowed the team to visualize the game's progression, showing established, partial, and previously scored connections in different colors (green, yellow, red).

The game also featured HQ nodes with a "wireless port 4," intended to connect to rotating towers that would provide additional entry points into the network for different teams. While only three towers were operational, their rotation was reduced to 10 minutes to give all teams an opportunity to capture them.

A significant technical hurdle was the failure of Over-The-Air (OTA) firmware updates for the nodes. After adding various features post-initial development, the node firmware consumed just enough RAM that it could no longer allocate the necessary buffers for OTA updates. This meant that despite having working code to address game bugs, the team was unable to push fixes remotely, necessitating a laborious and time-consuming manual reflashing process for each node – a task deemed infeasible during the conference.

Security features were embedded both physically and logically. The AI inhibitor and AI security strip were physical components on the badge that, when removed, triggered visual warnings and reported events to the backend server. These events were integrated into the CTF, allowing players to earn flags by demonstrating physical interaction with the badge's tamper-detection mechanisms. The crypto chip provided a more sophisticated layer of security, safeguarding API communications against tampering and unauthorized access, a critical component for maintaining the integrity of the game's scoring and credit system. The NFC tag on the badge was designed to be writable, allowing for quick transfer of one-time use, five-digit codes (generated by the backend API with a limited 32-character set) from communities or nodes, simplifying credit acquisition or node interaction.

Demo / Proof of Concept

▶ Watch: Badge game physical components and initial design flaw (8:00)

While "The Badge Talk" itself was a post-mortem discussion rather than a live demonstration of a new exploit or technology, the entire SAINTCON badge and its interactive game served as a large-scale, distributed proof of concept for the team's ambitious design. The talk effectively "demonstrated" the results of their work and the challenges encountered.

The speakers utilized dashboards and a game map created by Redacted Vortex to visually demonstrate the game's state and progression. They showed how different factions (represented by colors like blue, green, dream coil, vern, pack) established connections across the network of nodes. The playback feature allowed attendees to see a chronological history of connections being made, scored, and then marked as "used" (turning red), illustrating the dynamic nature of the game. This visualization was crucial for understanding the complex network patching game that players engaged with physically.

The physical badges themselves, with their integrated AI inhibitor and AI security strip, acted as a direct proof of concept for hardware-based tamper detection linked to a backend system. The demonstration of these components, which would flash red upon removal and report to the server for CTF flags, showcased a tangible security mechanism. Similarly, the Konami code for the hardware test, found by hundreds of attendees, demonstrated an intentional, hidden feature designed to reward exploration and interaction with the badge's firmware.

The physical interaction with the telecom box nodes and the RJ11 patching cables was the core "demo" of the game's mechanics. Although not shown live during the talk, the detailed explanation of how players would physically reconfigure connections within the nodes, combined with the visual representation on the map, painted a clear picture of the interactive experience. The anecdote about the initial vertical-opening node design with air shocks, and its rejection due to safety concerns, served as a "negative proof of concept," highlighting a design that didn't work and the iterative process of hardware development.

Furthermore, the integration of the crypto chip for securing API calls, even though its internal workings weren't visually "demoed" in the main talk (but were elaborated on in a subsequent CTF talk), served as a proof of concept for hardware-backed security in an interactive game environment. It demonstrated a practical application for protecting backend communications from manipulation, a critical aspect for the integrity of the credit and scoring system. The existence and functionality of these diverse interactive elements, despite the operational challenges, collectively served as a powerful demonstration of what a dedicated team can achieve with custom hardware and software in a conference setting.

Defensive Implications

▶ Watch: Detailed explanation of the badge game mechanics (12:00)

The SAINTCON badge experience, particularly its post-mortem analysis, offers several crucial defensive implications for hardware designers, game developers, and security professionals:

  1. Anticipate Adversarial Behavior (Even in Friendly Games): The most striking defensive implication is the necessity to design systems that account for intentional misuse and sabotage, even in a "friendly" conference game. Players unplugging nodes, breaking hardware, and performing "nefarious things" inside the boxes highlight that any interactive system, especially one with physical components, will be targeted. Future designs must incorporate physical tamper-resistance, robust error handling for unexpected disconnections, and possibly even a reputation system or punitive measures for destructive behavior.
  1. Robust Manufacturing and Supply Chain QA: The issues with flimsy PCB panels and CNC cutting errors underscore the critical need for rigorous quality assurance throughout the hardware manufacturing process. This includes detailed specifications for panelization, thorough testing of prototypes, and clear communication with board houses. In-house manufacturing, while offering control, still requires strict internal QA to prevent widespread issues.
  1. Criticality of OTA Updates and Resource Management: The failure of OTA updates due to RAM allocation issues is a significant lesson. For any deployed hardware, especially at scale, reliable OTA functionality is paramount for bug fixes and feature enhancements. Developers must meticulously manage memory, especially on resource-constrained microcontrollers like the ESP32, and rigorously test OTA mechanisms throughout the development lifecycle, particularly after adding new features, to ensure sufficient resources remain available.
  1. Hardware-Backed Security for API Integrity: The integration of a crypto chip for securing API calls is a strong defensive measure. Using hardware to store and manage API secrets significantly raises the bar for attackers attempting to spoof or manipulate backend communications. This approach is superior to purely software-based key storage, which can be more easily extracted. For critical systems, hardware security modules (HSMs) or crypto chips should be considered to protect sensitive operations and data.
  1. Physical Tamper Detection: The AI inhibitor and security strip serve as a practical example of physical tamper detection. While simple, integrating physical triggers that report to a backend system can be valuable for forensic analysis, triggering alerts, or, as demonstrated, as part of a CTF. This concept can be extended to more sophisticated tamper-evident seals or sensors in critical infrastructure.
  1. Clear Rules and Communication: While not strictly technical, the confusion and sabotage around the game rules highlight the importance of clear, unambiguous instructions and effective communication channels. When designing complex interactive systems, especially those with competitive elements, explicit rules and mechanisms to clarify ambiguities can reduce frustration and malicious behavior.
  1. Documentation and API Schemas: Redacted Vortex's lesson about "spending extra time documenting request and response schemas" is crucial. Clear and consistent API documentation is vital for firmware developers, backend engineers, and even CTF participants. It reduces errors, streamlines development, and facilitates debugging.
  1. Designing for Maintainability: The decision not to manually reflash 2,100 nodes due to time constraints illustrates the importance of designing for easy maintainability and repair. Future badge designs might consider modular components, easier access for physical reflashing, or more robust OTA mechanisms to ensure that fixes can be deployed efficiently.

Key Takeaways

  • Custom hardware development is inherently complex: Even with in-house manufacturing, unforeseen challenges like flimsy PCB panels and specific component compatibility (RJ11 connectors) can significantly impact production and quality.
  • Robust OTA update mechanisms are non-negotiable: The failure of OTA updates due to subtle RAM allocation issues can cripple the ability to deploy fixes, underscoring the need for rigorous testing and resource management throughout development.
  • Anticipate and mitigate player sabotage: Designing interactive games in an open environment requires expecting and planning for both legitimate strategic play and malicious attempts to break the system or hardware.
  • Hardware-backed security enhances trust and integrity: The crypto chip effectively protected API communications and provided a secure foundation for CTF challenges, demonstrating the value of dedicated hardware for cryptographic operations.
  • Hidden features and Easter eggs drive engagement: Elements like the Konami code, the AI inhibitor, and even non-functional "joy" buttons foster exploration and a deeper, more personalized interaction with the badge.
  • Community interaction is a double-edged sword: While fostering camaraderie and unique playstyles, open interaction also introduces vulnerabilities to deliberate misuse, requiring careful game design and monitoring.

About the Speaker(s)

compukidmike (MK Factor) served as the lead and primary speaker for "The Badge Talk." He is the driving force behind the SAINTCON badge team, responsible for the overall concept, design, and manufacturing process of the conference badges. His talk provided candid insights into the challenges and triumphs of creating such an ambitious hardware project, from initial design inspiration to the intricacies of in-house assembly and game deployment.

Redacted Vortex was a key technical contributor to the SAINTCON badge project, specifically in the areas of backend development and API security. He was responsible for developing the server infrastructure that tracked the badge game, provided interactive dashboards, and managed the complex scoring system. Crucially, Redacted Vortex also spearheaded the implementation of the crypto chip on the badge, ensuring secure communications with the backend API and integrating hardware-backed security into the CTF challenges.

All talks from SAINTCON 2025