TaskMooster

Unknown

ShmooCon XX (Final) · Day 1 · One Track Mind

Overview

The "TaskMooster" presentation at ShmooCon is a notable departure from the typical technical deep dives and vulnerability disclosures often found at cybersecurity conferences. Instead, it presents itself as a live, unscripted game show, hosted by Bryson Bort, featuring four prominent members of the ShmooCon community: Jesse (Mubix), Alan (Goldjacket), Heidi, and Rob. This unique format transforms a conference slot into an interactive, humorous, and community-centric event, designed to engage the audience through lighthearted competition rather than direct technical instruction.

Watch on YouTube

Visual summary for TaskMooster by Unknown
Visual summary for TaskMooster by Unknown

Key moments

  1. 0:00 Chaotic technical start and intro
  2. 2:00 Explaining rules: shmoo-balling and bribery
  3. 3:20 Contestants introduce each other with humor
  4. 6:00 Heidi introduces Rob, highlighting kindness and community
  5. 6:30 First task revealed: Best Last Minute Gift
  6. 8:00 Heidi presents her 'last minute' gift strategy

TaskMooster

Speakers: Bryson Bort (TaskMooster), Jesse (Mubix), Alan (Goldjacket), Heidi, Rob

Conference: ShmooCon

YouTube: https://www.youtube.com/watch?v=wXbnUm88IJw

Overview

The "TaskMooster" presentation at ShmooCon is a notable departure from the typical technical deep dives and vulnerability disclosures often found at cybersecurity conferences. Instead, it presents itself as a live, unscripted game show, hosted by Bryson Bort, featuring four prominent members of the ShmooCon community: Jesse (Mubix), Alan (Goldjacket), Heidi, and Rob. This unique format transforms a conference slot into an interactive, humorous, and community-centric event, designed to engage the audience through lighthearted competition rather than direct technical instruction.

The talk’s significance lies not in groundbreaking research or novel attack vectors, but in its embodiment of ShmooCon’s core values: transparency, community engagement, and a willingness to embrace unconventional content. It highlights the human element of the cybersecurity world, showcasing the personalities, wit, and camaraderie that underpin much of the industry's collaborative spirit. By turning the stage into a playful arena, "TaskMooster" serves as a refreshing counterpoint to the often-intense technical discussions, reminding attendees of the importance of connection and levity within a demanding field.

This article delves into the "TaskMooster" experience, analyzing its structure, the "challenges" presented to the contestants, and the broader implications for the security community. While traditional technical content is absent, the event offers insights into problem-solving, improvisation, and the unique culture of ShmooCon, making it a relevant study for understanding the multifaceted nature of modern security conferences.

Background

▶ Watch: Chaotic technical start and intro (0:00)

ShmooCon, known for its community-driven ethos and diverse range of talks, often features presentations that extend beyond purely technical subjects. This context is crucial for understanding the "TaskMooster" event. Bryson Bort, the self-proclaimed "TaskMooster," sets the stage by reminiscing about his own public speaking debut at ShmooCon in 2018, underscoring the conference's role in fostering talent and providing a platform for various forms of engagement. The event itself is framed as a "live bribery" and "games" session, a transparent nod to its entertainment value and a playful contrast to the "back rooms with cigars" often associated with less transparent political dealings in Washington D.C., where ShmooCon is held.

The "problem" that "TaskMooster" addresses isn't a cybersecurity vulnerability but rather the perennial challenge of maintaining audience engagement and providing diverse content at a long-running technical conference. In an industry often plagued by burnout and high-stress environments, events like "TaskMooster" offer a vital outlet for humor, community building, and a temporary respite from the relentless pace of threat intelligence and defensive strategies. It leverages the inherent competitive spirit and quick thinking often found in security professionals, redirecting it towards whimsical challenges. The format also encourages audience participation, with the "TaskMooster" inviting attendees to "shmoo ball" contestants who go over time or score poorly, further blurring the lines between presenter and participant. This inclusive approach reinforces ShmooCon's reputation as a conference deeply rooted in its community.

Key Findings

▶ Watch: Contestants introduce each other with humor (3:20)

The "Key Findings" of the TaskMooster event are less about technical discoveries and more about the outcomes of the challenges and the subjective, often humorous, judging process. The competition unfolded over two distinct tasks, with a promise of a conclusion on Sunday, indicating a multi-part series of events.

Task 1: The Best Last-Minute Gift

Contestants were challenged to present the "best last-minute gift." This task tested their creativity, resourcefulness, and ability to "hack" the brief.

  • Heidi: Presented a ShmooCon-branded watch, playing on the literal interpretation of "last minute" (the minute hand of a watch). She emphasized it was something she already owned, pulled from her "gift closet" at the last minute. She scored one point.
  • Alan (Goldjacket): Interpreted "last-minute" as "I'll worry about that later." He showcased items from his "con bag," including a Cliff Bar, deodorant, non-steroidal anti-inflammatories, and an open bag of cough drops. His standout item was a shoulder-mounted 10-ounce holster with rye, which he humorously claimed transformed him into an "instant leather daddy." Alan received two points.
  • Jesse (Mubix): Demonstrated a highly personalized approach, tailoring her gifts specifically for Bryson Bort after observing photos of him on airplanes. Her collection from a recent trip to Seattle included:
  • A plane spotting guide.
  • A guide to the mountains visible from Seattle.
  • A geographical marker for Mount St. Helens, showing its revised elevation post-1980 eruption.
  • A foraging book for Mount St. Helens.
  • A limited edition M.C. Escher tie in West Point colors, acquired from a math conference where she spoke on "applications of knowledge graphs to cyberspace."

Jesse's personalized, multi-faceted bribe was highly effective, earning her four points and first place in this round.

  • Rob: Presented a re-gifted, re-re-gifted item: a "1920s wagon" converted into a "spacecraft" by a neighbor, then acquired by his mother at a garage sale. He openly admitted he didn't want it and hoped the winner would take it home. Rob's unique, somewhat absurd offering earned him three points and second place.

Task 2: Carnival Games (Can Toss & Darts)

This physical challenge involved contestants attempting to knock over cans and pop balloons. The "findings" here revolved around athletic prowess, problem-solving, and a bit of rule-bending.

  • Alan (Goldjacket) & Jesse (Mubix): Their performance was described as "embarrassing" and not "gifted athlete" material. Alan resorted to "engineering or desperation," eventually throwing the entire tennis ball holder at the cans to achieve results, a move the TaskMooster noted as a "lasso model." Alan scored 105 points but was placed third in the round due to his methods. Jesse scored 95 points and was placed fourth.
  • Rob & Heidi: Faced their own challenges, with Heidi having a "frozen shoulder" limiting her physical ability. Rob, however, exhibited clever "hacking" of the game rules. While throwing darts, he intentionally "did not touch the rope" but instead "touched the pylon" to steady himself, a loophole that the TaskMooster acknowledged as "in scope" for a hacker. Rob was the only contestant to explicitly declare himself "done" after hitting exactly 100 points, a key criterion for winning this round. Rob won this round, earning four points. Heidi, despite her adversity, scored 105 points and was awarded second place with three points.

Overall Standings After Two Rounds:

Rob was in first place with seven points, leading into the final round scheduled for Sunday. The "findings" collectively underscore that success in "TaskMooster" is a blend of creativity, strategic thinking, humor, and an understanding of how to exploit or interpret rules, much like in the broader security domain.

Technical Deep Dive

▶ Watch: Heidi introduces Rob, highlighting kindness and community (6:00)

In the traditional sense of a security conference talk, "TaskMooster" does not offer a technical deep dive into cybersecurity vulnerabilities, protocols, or architectures. The core content is a game show, not a research presentation. However, to fulfill the requirements of this section, we can analyze the meta-technical aspects of the event itself and the subtle technical references embedded within the non-technical narrative.

The very opening of the talk highlights the operational challenges of live event production, a significant technical undertaking often overlooked by attendees. The "TaskMooster" Bryson Bort, alongside "Bobby" running the video, immediately grapples with issues like "make sure everything's hot on him," "that's not full screen. Hit the green one," and the crucial "we'll see if we have audio." This impromptu "jit filmmaking" (just-in-time filmmaking) provides a candid glimpse into the complexities of AV setup, screen sharing, and sound engineering in a live conference environment. The humorous self-reflection, "This is why we're in security," underscores that even seasoned technical professionals face unexpected technical glitches when operating outside their primary domain. This segment, while brief, serves as a mini "technical deep dive" into the logistics of a live conference presentation, showcasing the constant need for troubleshooting and improvisation.

The talk also provides a fleeting but significant technical reference when Jesse (Mubix) describes her recent speaking engagement at a math conference. She presented on "applications of knowledge graphs to cyberspace." This is the sole direct mention of a highly technical, current area of cybersecurity research. Knowledge graphs are structured representations of information that describe entities and their relationships, often used in fields like artificial intelligence, data analytics, and semantic web technologies. Their application to cyberspace implies using these graph structures to model complex relationships within networks, security incidents, threat intelligence, or even attack paths. While the talk does not elaborate on Jesse's work, this brief mention points to a sophisticated area of research that involves advanced data science, graph theory, and potentially machine learning for security applications. This serves as a reminder of the technical depth and diverse expertise present even among contestants in a lighthearted game show.

Furthermore, the contestants' approaches to the tasks, particularly in the carnival games, can be viewed through a "hacker mindset" lens. Rob's deliberate act of touching the "pylon" instead of the "rope" while dart-throwing is a classic example of rule exploitation or scope manipulation. He identified a boundary condition ("don't touch the rope") and found an adjacent, unstated permissible action ("touch the pylon") that provided an advantage. This mirrors how security researchers identify and exploit vulnerabilities by finding edge cases, misconfigurations, or unintended behaviors within system rules or protocols. Alan's "engineering or desperation" in throwing the entire tennis ball holder at the cans also demonstrates a form of creative problem-solving or resourcefulness under pressure, akin to lateral thinking in security operations when conventional methods fail. These interactions, while playful, showcase the inherent analytical and problem-solving skills valued in the cybersecurity domain, translated into a game context.

In essence, while "TaskMooster" avoids a traditional technical deep dive into security topics, it inadvertently provides a "deep dive" into the technical realities of live event production, offers a glimpse into advanced research areas through a speaker's background, and subtly illustrates the pervasive "hacker mindset" in problem-solving.

Demo / Proof of Concept

▶ Watch: First task revealed: Best Last Minute Gift (6:30)

The entirety of the "TaskMooster" event can be considered a live demonstration or proof of concept for an engaging, non-traditional conference segment. Rather than showcasing a specific tool or exploit, the demo was the real-time execution of the game show itself, with all its unscripted challenges and humorous outcomes.

Demo of Task 1: Best Last-Minute Gift

The first "demo" involved the contestants physically presenting and explaining their "best last-minute gifts."

  • Heidi presented a ShmooCon-branded watch, showcasing its relevance to the "last minute" theme.
  • Alan (Goldjacket) pulled items directly from his "con bag," including a Cliff Bar, deodorant, and his signature shoulder-mounted 10-ounce holster with rye. The visual of the holster and the description of its "leather daddy" transformation served as a humorous physical demonstration.
  • Jesse (Mubix) laid out a collection of gifts from Seattle, including a plane spotting guide, mountain guide, a Mount St. Helens geographical marker showing its post-eruption elevation, a foraging book, and a distinctive M.C. Escher tie. The diverse, personalized nature of these items was the core of her demonstration.
  • Rob brought a peculiar, re-gifted item: a "1920s wagon" converted into a "spacecraft" that he openly confessed he didn't want. The physical presence of this unusual object was central to his presentation.

Demo of Task 2: Carnival Games

The second "demo" was a pre-recorded video segment showing the contestants participating in physical carnival games, specifically a can toss and dart throwing. This segment served as a proof of performance for their athletic (or un-athletic) capabilities and their problem-solving under pressure.

  • The video highlighted Alan's "engineering or desperation" as he resorted to throwing the entire tennis ball holder at the cans, a creative but unconventional approach to the task. This was a clear demonstration of out-of-the-box thinking.
  • Rob's strategic "hack" of touching the pylon instead of the rope while throwing darts was visually evident and explicitly called out by the TaskMooster. This demonstrated a deliberate exploitation of a ruleset, a "proof of concept" for finding and leveraging loopholes within a defined system.
  • The segment also subtly highlighted Heidi's "adversity" with a frozen shoulder, showcasing her resilience and determination despite physical limitations.

The entire event, with its live banter, physical challenges, and the subjective judging process, served as a compelling demonstration of how a conference can foster community and provide entertainment alongside its technical offerings. It proved that a "talk" can be an interactive, unscripted experience that showcases different facets of the participants' personalities and problem-solving styles.

Defensive Implications

▶ Watch: Heidi presents her 'last minute' gift strategy (8:00)

Given that "TaskMooster" is a game show and not a traditional technical security talk, it does not present direct defensive implications in terms of specific vulnerabilities, mitigation strategies, or security tools. However, the event offers several valuable indirect defensive implications that are crucial for the well-being and effectiveness of cybersecurity professionals and the broader community.

  1. Cultivating a Hacker Mindset for Defense: The contestants' approaches to the game, particularly Rob's rule-bending (touching the pylon) and Alan's creative "engineering or desperation" (throwing the tennis ball holder), are direct analogies to the adversarial thinking essential for effective defense. Defenders must constantly think like attackers, identifying edge cases, overlooked details, and creative ways to bypass controls. This game provides a playful, low-stakes environment to practice such a mindset.
  2. Importance of Community and Networking: ShmooCon, and "TaskMooster" within it, heavily emphasizes community. For defenders, strong community ties are invaluable for threat intelligence sharing, collaborative problem-solving, and peer support. The camaraderie and playful jabs among contestants reflect the informal networks that often prove critical in responding to real-world incidents. Building these relationships at events like "TaskMooster" indirectly strengthens the collective defensive posture.
  3. Stress Relief and Preventing Burnout: The cybersecurity field is notoriously high-stress, leading to significant burnout rates. Events like "TaskMooster" offer a vital outlet for stress relief and mental rejuvenation. A well-rested and engaged security team is a more effective defensive force. Conference organizers and team leads should recognize the importance of providing opportunities for lighthearted engagement and community building alongside intense technical training.
  4. Valuing Diverse Skill Sets: The contestants represent diverse backgrounds—a mathematician with a PhD (Alan), someone working with knowledge graphs in cyberspace (Jesse), and community leaders (Heidi, Rob). This highlights that effective defense requires a multidisciplinary approach. Technical skills are paramount, but soft skills like creativity, improvisation, leadership, and even a sense of humor are equally important for building resilient teams and robust defensive strategies.
  5. Transparency and Openness: Bryson Bort's explicit mention of "transparency" at ShmooCon, contrasting it with political "bribery," subtly reinforces a critical principle for defenders. Openness about security incidents, sharing lessons learned, and transparent communication within organizations and with the wider community can significantly enhance defensive capabilities by fostering trust and collective improvement.
  6. Adaptability and Improvisation: The "jit filmmaking" at the start and the unscripted nature of the game itself underscore the need for adaptability and improvisation. In cybersecurity, incidents rarely follow a playbook perfectly. Defenders must be prepared to think on their feet, adapt to unexpected situations, and improvise solutions under pressure—skills implicitly honed through such dynamic, live events.

While "TaskMooster" is not a direct defensive blueprint, its underlying themes and the skills it indirectly showcases are profoundly relevant to building a robust, resilient, and human-centered defensive strategy in cybersecurity.

Key Takeaways

  • ShmooCon's Unique Culture: The "TaskMooster" event exemplifies ShmooCon's commitment to community, humor, and non-traditional content, offering a refreshing break from purely technical presentations.
  • Challenges of Live Production: The talk's opening highlighted the real-world technical difficulties of live "jit filmmaking," including AV setup and screen control, emphasizing the complexities behind seemingly seamless conference presentations.
  • Creative Problem-Solving (Hacker Mindset): Contestants demonstrated ingenuity in interpreting and "hacking" the game rules, from personalized "bribes" (Jesse) to exploiting loopholes (Rob's pylon touch) and unconventional approaches (Alan's "engineering or desperation").
  • Value of Community Engagement: The event fostered camaraderie and audience interaction, underscoring the importance of networking, peer support, and lighthearted engagement for cybersecurity professionals' well-being and collective strength.
  • Diverse Skill Sets are Essential: The brief bios of contestants, including Jesse's work with "knowledge graphs in cyberspace" and Alan's PhD, implicitly highlighted the diverse technical and non-technical expertise present within the security community.
  • The Power of Personalization: Jesse's success in the "last-minute gift" task demonstrated the effectiveness of deeply understanding and tailoring interactions to the recipient, a principle applicable to communication and influence in any field, including security advocacy.

About the Speaker(s)

Bryson Bort (TaskMooster): Bryson Bort served as the energetic and humorous host of the "TaskMooster" event. He has a special connection to ShmooCon, noting that his first public speaking engagement in 2018 at the conference launched his career. He frames the event within ShmooCon's values of transparency, contrasting it with traditional political maneuvering.

Heidi: A key figure in the ShmooCon community, Heidi is described by fellow contestant Alan as "absolutely fantastic" and an aspirational figure. Rob further elaborates that Heidi "exemplifies the phrase lead with kindness" and is an "amazing contributor to this community," particularly highlighting her involvement in the hiring aspects of ShmooCon and other conferences. She also faced the challenge of competing with a "frozen shoulder."

Rob: Rob is highly praised by Heidi as an "amazing contributor to this community" who "does so many amazing things" and "really exemplify[ies] kindness and leadership." Like Heidi, he is also noted for his involvement in managing the hiring board for conferences, connecting job seekers with opportunities. Rob demonstrated a clever "hacker mindset" during the carnival games, exploiting a loophole in the rules.

Jesse (Mubix): Introduced as "Mubix," Jesse's background includes speaking at a math conference on "applications of knowledge graphs to cyberspace," indicating a strong technical and academic background in advanced data science and security. She demonstrated exceptional creativity and personalization in the "last-minute gift" task, tailoring her offerings specifically for the host.

Alan (Goldjacket): Known as "Goldjacket," Alan holds a PhD, suggesting a background in rigorous academic or scientific fields. He is described as highly improvisational in his work. During the "TaskMooster" challenges, Alan showcased a blend of resourcefulness and "engineering or desperation" in his approach to tasks.

Reviews

Dr. Zero (Offensive Security Researcher) — HARD PASS

This "session" is a complete waste of time for anyone expecting a technical talk at a security conference. It's a disorganized carnival game and gift exchange, masquerading as content. While it might serve as light entertainment for some, it offers zero technical depth, practical impact, or novel research, making it entirely inappropriate for a serious technical track.

Heather Calloway (CISO) — STRONG ACCEPT

TaskMooster" at ShmooCon, while not a technical presentation, offers critical insights for security leaders. It effectively demonstrates the institutional value of community, creative problem-solving, and mental well-being in a high-stress field. For CISOs grappling with burnout and talent retention, this event serves as a valuable proof of concept for fostering resilience and a pragmatic "hacker mindset" within their teams, underscoring that effective defense relies as much on human capital as it does on technology.

→ Top-rated talks at ShmooCon XX (Final)

All talks from ShmooCon XX (Final)