Opening Remarks, Rumblings, Ruminations, and Rants
Bruce Potter (Founder · Shmoo Group)
ShmooCon XX (Final) · Day 1 · One Track Mind
Overview
This article delves into the opening remarks of ShmooCon's 20th anniversary, delivered by co-founder Bruce Potter, with significant contributions from Heidi (uncredited in the official speaker list but a driving force behind the event and its narrative). Far from a traditional technical presentation, this session served as a comprehensive welcome, a historical retrospective, and a candid look behind the scenes of one of the cybersecurity community's most beloved and unique conferences. The talk is less about specific security vulnerabilities or tools and more about the ethos, operational challenges, and community spirit that define ShmooCon, especially as it marks two decades of existence.

Key moments
- 0:00 Welcome to ShmooCon, audience participation
- 2:00 Overview of the talk and ShmooCon survival tips
- 3:00 Speaker accidentally deletes presentation slides pre-keynote
- 4:30 Humorous take on Google Slides vs. Keynote
- 5:00 Using ChatGPT and DALL-E for presentation images
- 6:00 Identifying ShmooCon staff and volunteers
- 7:00 ShmooCon speaker statistics, new talent
- 7:40 What is the Shmoo Ball? (Schmotor Board Cap)
Opening Remarks, Rumblings, Ruminations, and Rants
Speakers: Bruce Potter (Founder, Shmoo Group)
Conference: ShmooCon
YouTube: https://www.youtube.com/watch?v=wXbnUm88IJw
Overview
This article delves into the opening remarks of ShmooCon's 20th anniversary, delivered by co-founder Bruce Potter, with significant contributions from Heidi (uncredited in the official speaker list but a driving force behind the event and its narrative). Far from a traditional technical presentation, this session served as a comprehensive welcome, a historical retrospective, and a candid look behind the scenes of one of the cybersecurity community's most beloved and unique conferences. The talk is less about specific security vulnerabilities or tools and more about the ethos, operational challenges, and community spirit that define ShmooCon, especially as it marks two decades of existence.
The importance of this talk lies in its profound insight into the culture of ShmooCon. It articulates the conference's foundational principles, such as fostering speaker accountability and audience engagement, prioritizing attendee privacy and safety, and maintaining a distinctly DIY, community-driven approach. Through a blend of humor, personal anecdotes, and logistical transparency, the speakers illuminate the immense effort and passion required to orchestrate such an event, all while celebrating the unique community it has cultivated. This presentation is crucial for anyone seeking to understand the heart and soul of ShmooCon, offering a rare glimpse into the philosophy and practical realities of running a large-scale, community-focused cybersecurity conference.
Background
▶ Watch: Welcome to ShmooCon, audience participation (0:00)
ShmooCon's origins are famously recounted as a "drunk Vegas talk" between Bruce Potter and Beetle (the first con organizer), born from a desire to address the perceived lack of accountability and engagement at other major security conferences. This foundational impulse led to one of ShmooCon's most iconic traditions: the Schmoo Ball. Initially conceived as a means for the audience to "hold the speaker accountable" without the intimidation of a public microphone, the Schmoo Ball has evolved significantly over the years. The first iteration was a soft, yellow foam ball that barely flew, quickly followed by a disastrous experiment with ping-pong balls that were too small for their intended guns, leading to attendees throwing the guns themselves. Subsequent attempts included whiteboards (unreadable from stage, prone to inappropriate drawings) and an "interactive moose," before settling into its current form. For the 20th anniversary, the traditional Schmoo Ball was replaced by a Schmortar Board cap, a nod to the conference's milestone, with a gentle lob encouraged rather than a forceful throw.
Beyond the Schmoo Ball, the talk touches on other historical elements that underscore ShmooCon's unique identity. The infamous "razor blade badges" from year one, which were metal pieces designed as a puzzle set with jagged edges, literally risked cutting attendees and ripping shirts, prompting the need for "a box of Band-Aids in everybody's bag." This anecdote highlights an early, perhaps overzealous, commitment to unique physical elements that has since been tempered by practicality and safety. The conference also boasts a robust Schmoozer Student Program, bringing 82 students to the event, with 58 "Schmoozers" (sponsors) facilitating their attendance. Furthermore, ShmooCon emphasizes a different relationship with its sponsors, challenging them to "bring something really different" and "engage with the audience" rather than merely promoting products, a testament to the conference's community-first approach. The recurring theme is a conference built on passion, problem-solving, and a deep engagement with its audience, even if it means navigating unexpected challenges and learning from past "mistakes."
Key Findings
▶ Watch: Speaker accidentally deletes presentation slides pre-keynote (3:00)
The "Key Findings" of this ShmooCon opening talk are not research outcomes but rather profound insights into the operational philosophy and cultural fabric that have sustained the conference for two decades. First, audience engagement and speaker accountability are paramount. The evolution of the Schmoo Ball, from its initial concept to its varied (and sometimes problematic) iterations, demonstrates a persistent commitment to enabling audience participation and providing a mechanism for feedback, however unconventional. The current Schmortar Board cap serves as both a commemorative item and a symbolic tool for gentle discourse.
Second, a strong emphasis on community and inclusivity underpins ShmooCon. This is evident in the dedication to nurturing new talent, with 36 new speakers on stage this year, and approximately 10 individuals making their major conference debut. The Schmoozer Student Program further exemplifies this, supporting 82 students' attendance. The explicit photography rules, requiring consent from everyone in frame and prohibiting crowd shots, along with the mandatory mask policy, underscore a deep commitment to attendee privacy and physical safety—principles the organizers feel "pretty strongly about" and are "unbending on."
Third, the conference thrives on a DIY spirit and creative problem-solving, often born out of necessity and unexpected challenges. The elaborate process of creating the Stargate mementos, from custom molds to deconstructing the original prop with household tools and industrial shears, illustrates a willingness to undertake complex, hands-on projects to deliver unique experiences. Even logistical nightmares, like the bag printing fiasco where 402 bags were defective due to manufacturing errors, were met with ingenuity (e.g., cleaning bags with acetone in freezing temperatures, repurposing old conference bags). These instances highlight the resilience and resourcefulness of the ShmooCon team.
Finally, the talk reveals the immense personal dedication and effort invested by the organizers. The anecdotes about deleting an entire keynote presentation minutes before a talk, the "stabby stab, stab, stab" dad jokes, and the detailed recounting of the bag and badge production issues paint a vivid picture of the human element behind the conference. The "Potter kids" spending their winter break making Stargates or painstakingly punching out 10,000 tiny axles for past badges further underscores the family-like, all-hands-on-deck approach that defines ShmooCon's operations. This collective effort ensures that despite the challenges, the conference continues to deliver a memorable and meaningful experience for its 2270 attendees.
Technical Deep Dive
▶ Watch: Using ChatGPT and DALL-E for presentation images (5:00)
While ShmooCon is a technical security conference, the opening remarks themselves do not feature a traditional "technical deep dive" into cybersecurity vulnerabilities or protocols. Instead, the "technical deep dive" aspects emerge from the elaborate, often improvised, engineering and logistical challenges involved in creating unique physical elements for the conference. The most significant "technical" undertaking discussed is the deconstruction of the original Stargate prop and the production of 2,400 miniature Stargate resin pieces for the 20th-anniversary Schmortar Board caps.
The process began with designing custom silicone molds, outsourced to a Vermont-based company specializing in molds, often for edibles. This required translating the original Stargate design into a 3D model, a task handled by an unexpected Stargate fan engineer at the mold company after initial "crappy art" attempts. The subsequent challenge was reducing the original, corrugated plastic Stargate prop into small, embeddable pieces. Initial thoughts of a wood chipper were dismissed due to safety concerns. A household blender was attempted, resulting in a "lightning storm" of atomized plastic and static cling, producing inconsistent piece sizes. The ultimate solution involved a multi-stage shredding party. The Stargate was first cut into thin strips using an "old school... 70s paper cutter" (a large, dangerous hatchet-style cutter), then further reduced using scissors, followed by tin snips, and finally sheet metal shears to achieve appropriately sized fragments. Despite expectations, only a section of the original Stargate was needed, leaving much of the prop intact.
The resin pour process for the 2,400 individual Stargate pieces involved extensive research by the "Potter kids" into various resin types, drying times, and curing conditions. To expedite the process, Bruce Potter constructed a "drying oven" using stair balusters and cookie sheets, heated by germination heaters to warm the resin and accelerate curing without combustion. Each cycle produced 225 pieces, requiring 11 cycles over several weeks, with each batch curing for approximately 24 hours. The team encountered issues with rapid cured resin, where some batches partially cured, leading to sticky, unusable pieces and resin getting onto bare hands, highlighting a lapse in safety protocols (should-a-worn gloves).
Other "technical" details mentioned include the conference network, run by the "labs" team, which is noted for being "up and running" and offering a WPA3 network for secure connectivity, managed by "world-class folks with some world-class gear." The historical "laser-cut bike badges" from a previous year also involved intricate engineering, requiring attendees to assemble a Caesar cipher-like device from multiple laser-cut parts. The most notorious aspect was the 10,000 tiny axles, "less than an eighth of an inch" in size, that had to be manually punched out of sheets by the oldest Potter child in a freezing garage, a testament to the labor-intensive nature of these custom creations. These details, while not directly related to cybersecurity exploits, reveal the technical ingenuity and hands-on effort that are deeply embedded in ShmooCon's operational DNA.
Demo / Proof of Concept
▶ Watch: Identifying ShmooCon staff and volunteers (6:00)
In the context of this ShmooCon opening talk, the "Demo / Proof of Concept" section takes on a unique interpretation, as the presentation itself is not demonstrating a new technical tool or vulnerability. Instead, the primary "demo" is the physical Schmortar Board cap given to each attendee, which contains a piece of the original Stargate prop embedded in resin. This serves as a tangible proof of concept for ShmooCon's commitment to delivering unique, commemorative, and deeply personal experiences to its community.
The entire narrative surrounding the creation of these Stargate pieces acts as the demonstration. The speakers detail the elaborate process: from commissioning custom silicone molds from a company that typically produces molds for edibles, to the meticulous and unexpectedly challenging task of deconstructing the large, corrugated plastic Stargate prop. This involved experimental attempts with a blender (which created a "lightning storm" of static and atomized plastic) before settling on a multi-stage shredding party using a vintage paper cutter, then scissors, tin snips, and finally sheet metal shears to achieve appropriately sized fragments.
Further demonstrating the hands-on, DIY ethos, the "Potter kids" conducted extensive research on different resin types and curing processes. To accelerate the production of 2,400 individual pieces, Bruce Potter engineered a custom "drying oven" from stair balusters and cookie sheets, heated by germination heaters. This process, involving 11 cycles of 225 pieces each, with 24-hour curing times, was a massive undertaking, occasionally resulting in "rapid cured resin" batches that were partially unusable and sticky.
The presentation of these Schmortar Board caps with their embedded Stargate fragments is a powerful demonstration of ShmooCon's dedication to its legacy and its attendees. It's a physical artifact that embodies the conference's history, its community-driven spirit, and the extraordinary effort of its organizers. It's also a "black spot" of sorts, as the original Stargate was often auctioned off and passed around, making every recipient a temporary custodian. Now, everyone has a piece, a direct connection to ShmooCon's unique past. This "demo" showcases not a technical exploit, but the technical and logistical ingenuity applied to foster community and create memorable physical tokens that reinforce the conference's distinctive identity.
Defensive Implications
▶ Watch: What is the Shmoo Ball? (Schmotor Board Cap) (7:40)
Given that this talk is an opening remarks and not a technical security presentation, the "Defensive Implications" are not about protecting systems from exploits, but rather about the defensive strategies for running a successful, safe, and community-oriented conference, and how attendees can "defend" their well-being and privacy.
For conference organizers, the talk highlights several crucial defensive postures:
- Prioritizing Attendee Safety and Privacy: ShmooCon's strict policies on mandatory masking and photography rules (requiring consent from everyone in frame, no crowd shots) are "relatively unique" and "unbending." These measures are explicitly stated as being for "personal privacy and physical safety," which are increasingly important in today's environment. This serves as a model for other conferences to implement robust privacy and safety protocols.
- Operational Resilience and Contingency Planning: The candid stories of the bag printing fiasco (402 defective bags out of 2160 ordered) and the last-minute badge production challenges underscore the need for robust contingency plans, flexible teams, and creative problem-solving under pressure. The team's ability to pivot, clean bags with acetone in the cold, and pull "vintage" bags from storage demonstrates a high degree of operational resilience.
- Fostering Community and Engagement: The continuous evolution of the Schmoo Ball and the commitment to supporting new speakers and students are defensive strategies against audience apathy and stagnation. An engaged, invested community is more resilient and self-sustaining.
- Maintaining Secure Infrastructure: The mention of the WPA3 network provided by the "labs" team, run by "world-class folks with some world-class gear," is a subtle but important defensive implication for attendees. It advises them to use the most secure network available, protecting their own data during the event.
- Establishing Clear Communication Channels: The [email protected] email, monitored 24/7, provides a critical communication channel for emergencies, ensuring that attendees have a reliable way to report issues and that the organizing team can respond quickly.
For attendees, the defensive implications revolve around personal well-being and adherence to community norms:
- Personal Health and Hydration: The repeated emphasis on "eat and hydrate," "sleep and shower," and the personal anecdotes about dehydration at conferences serve as a crucial defense against burnout and illness, especially in a high-energy environment.
- Respecting Privacy and Consent: Adhering to the "no crowd shots" and "everyone in frame is consenting" photography rules is essential for defending the privacy of fellow attendees.
- Network Security Awareness: Utilizing the secure WPA3 network is a personal defensive measure against potential network-based attacks.
- Awareness of Conference Logistics: Knowing where to find schedules, event locations, and emergency contacts helps attendees navigate the conference safely and efficiently.
In essence, the "defensive implications" from this talk are a holistic approach to creating and participating in a secure, respectful, and sustainable conference environment, extending beyond purely technical cybersecurity to encompass physical safety, privacy, and community health.
Key Takeaways
- ShmooCon's Unique Culture: The conference prioritizes audience engagement and speaker accountability, exemplified by the evolution of the Schmoo Ball into the Schmortar Board cap for its 20th anniversary.
- Commitment to Community & Inclusivity: ShmooCon actively supports new talent, with 36 new speakers and approximately 10 first-time major conference speakers this year, alongside a robust Schmoozer Student Program benefiting 82 students.
- Emphasis on Safety & Privacy: Strict policies like mandatory masking and consent-based photography (no crowd shots) are non-negotiable, reflecting a deep commitment to attendee well-being and personal privacy.
- Ingenious Problem-Solving: The conference organizers demonstrate remarkable resilience and creativity in overcoming logistical challenges, from deconstructing the Stargate prop with household tools and industrial shears to resolving a bag printing fiasco involving 402 defective items.
- Hands-On, DIY Ethos: The production of 2,400 Stargate resin pieces, involving custom molds, a makeshift "drying oven," and extensive material research by the "Potter kids," highlights the profound personal investment and hands-on approach of the ShmooCon team.
- Importance of Basic Well-being: Attendees are strongly encouraged to "eat and hydrate," "sleep and shower," and "learn," emphasizing that personal care is fundamental to a positive conference experience.
About the Speaker(s)
The talk was primarily delivered by Bruce Potter, identified as the Founder of the Shmoo Group and ShmooCon. He is a well-known figure in the cybersecurity community, providing high-level context, historical anecdotes, and humorous interjections. Bruce's speaking style is characterized by a confident, often dry, wit and a deep understanding of the conference's origins and operational philosophies.
Heidi, Bruce's wife, though not formally listed as a speaker in the metadata, was a dominant voice throughout the presentation, driving much of the narrative, detailing the logistical challenges, and sharing personal stories behind the conference's unique elements. She is clearly a co-organizer and an integral part of the ShmooCon team, demonstrating an intimate knowledge of the event's inner workings, from speaker lineups to bag production mishaps. Her passion and candid storytelling provide a vital human element to the ShmooCon experience. Together, Bruce and Heidi embody the spirit and dedication that have shaped ShmooCon into a beloved and enduring fixture in the cybersecurity conference landscape.
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
This is not a technical session, and it makes no pretense to be. However, as opening remarks for a major conference, it delivers a genuinely engaging and insightful look into the operational realities and unique culture of ShmooCon. The founders, Bruce Potter and Heidi, bring a rare level of transparency to the logistical challenges of running such an event, from managing speaker submissions to the literal shredding of a Stargate prop. While lacking the deep technical dives I typically seek, the talk's authenticity, practical advice for attendees, and commitment to community engagement resonate with the core values of what a good conference should be.
Heather Calloway (CISO) — STRONG ACCEPT
While not a technical security presentation, Bruce Potter and Heidi's opening remarks at ShmooCon's 20th anniversary are a masterclass in institutional realism, operational resilience, and principled community governance. It lays bare the immense effort, transparent accountability, and unwavering commitment to attendee privacy and safety required to build and sustain a valued institution. This talk offers profound insights into leadership, risk ownership, and the human element of complex operations, making it highly valuable for any executive navigating organizational challenges, even if it doesn't detail specific cybersecurity vulnerabilities.