Multi-Sector/Industry Hobo: Rules of Riding the Security Rails

Amélie Koran

ShmooCon XX (Final) · Day 1 · One Track Mind

Overview

Amélie Koran's ShmooCon talk, "Multi-Sector/Industry Hobo: Rules of Riding the Security Rails," offers a profound and unconventional perspective on the cybersecurity profession. Moving beyond traditional technical deep dives, Koran draws compelling parallels between the historical hobo code and the ethical, communal, and professional challenges faced by security practitioners today. The presentation reclaims the term "hobo" from its derogatory connotations, emphasizing their historical role as adaptable, self-reliant workers who traveled for employment and adhered to a strict, unwritten ethical code.

Watch on YouTube

Visual summary for Multi-Sector/Industry Hobo: Rules of Riding the Security Rails by Amélie Koran
Visual summary for Multi-Sector/Industry Hobo: Rules of Riding the Security Rails by Amélie Koran

Key moments

  1. 0:00 Introduction to 'Security Hobo' concept
  2. 2:00 Hobo ethical code and security's public image
  3. 3:20 Security professionals' hustle and career exploration
  4. 4:20 The hacker community as a 'jungle'
  5. 5:00 Challenges: diversity, zero loyalty, poor advocacy

Multi-Sector/Industry Hobo: Rules of Riding the Security Rails

Speakers: Amélie Koran

Conference: ShmooCon

YouTube: https://www.youtube.com/watch?v=wXbnUm88IJw

Overview

Amélie Koran's ShmooCon talk, "Multi-Sector/Industry Hobo: Rules of Riding the Security Rails," offers a profound and unconventional perspective on the cybersecurity profession. Moving beyond traditional technical deep dives, Koran draws compelling parallels between the historical hobo code and the ethical, communal, and professional challenges faced by security practitioners today. The presentation reclaims the term "hobo" from its derogatory connotations, emphasizing their historical role as adaptable, self-reliant workers who traveled for employment and adhered to a strict, unwritten ethical code.

Koran, a veteran of the security industry with 25 years of experience and 18 years attending ShmooCon, argues that security professionals, much like historical hobos, are often travelers across different roles, industries, and technologies, constantly seeking work and adapting to new environments. She highlights the shared experiences of being misunderstood by the public and corporate entities, the constant hustle for employment, and the paramount importance of community and mutual support. The talk is a passionate call to introspection and action, urging the security community to embrace and formalize its own ethical guidelines, foster mentorship, and actively lift one another up, thereby building a more resilient and humane profession.

The significance of this talk lies in its ability to reframe the often-isolated and highly technical world of cybersecurity within a broader sociological and ethical context. By likening security professionals to hobos, Koran underscores the fundamental human elements of the industry: the need for belonging, the value of shared knowledge, and the imperative of ethical conduct amidst constant change and uncertainty. It serves as a powerful reminder that while technology evolves rapidly, the core principles of community, integrity, and mutual aid remain timeless and essential for navigating the "security rails" of the modern world.

Background

▶ Watch: Introduction to 'Security Hobo' concept (0:00)

To understand the core message of Amélie Koran's talk, it's essential to first grasp the historical and sociological context of the hobo. As Koran meticulously explains, a hobo is distinctly different from a tramp or a bum. While all three terms refer to transient individuals, a hobo, by definition, is a traveler who works for a living, seeking employment wherever it can be found. Tramps are travelers who don't work, and bums neither travel nor work. This distinction is crucial, as it immediately aligns the hobo with the proactive, adaptable nature of a security professional.

The hobo phenomenon largely emerged in the United States after the Civil War and peaked during the Great Depression. With widespread unemployment and economic hardship, many individuals, including writers like Carl Sandburg and George Orwell, were forced to travel by freight train in search of work. During this period, an intricate, unwritten ethical system known as the hobo code developed. This code comprised a set of symbols and unwritten rules designed to guide travelers, indicate safe places, warn of dangers, and foster mutual aid among the hobo community. It was a practical and moral framework for survival and community cohesion in a harsh, transient existence.

Koran draws direct parallels between this historical context and the modern cybersecurity landscape. She highlights that both groups share a distorted public image. Just as "hobo" became a pejorative, the term "hacker" was once, and often still is, misunderstood or viewed negatively by the general public and business professionals. Explaining one's role as a security professional, especially one engaged in "hacking" activities for good, often requires significant effort to demystify and educate. This shared experience of being "misunderstood" forms a foundational commonality.

Furthermore, Koran points to the shared experience of constant hustle for work. Hobos faced economic uncertainty, always needing to find their next job. Today, security professionals often navigate a job market with "zero loyalty now with employers," leading to frequent transitions and the need to constantly be "on your toes." This transient nature, coupled with the imperative to constantly learn and adapt, echoes the hobo's journey. The "dark times" of economic downturns or rapid technological shifts can leave security professionals feeling "lost and wistful," much like hobos confronting an unforgiving landscape. The talk frames the security community as a modern "jungle," the hobo term for their gathering places, where mutual support, care, and protection are paramount. This background sets the stage for understanding why the hobo code, with its emphasis on ethics, community, and resilience, offers such a potent framework for the cybersecurity industry.

Key Findings

▶ Watch: Hobo ethical code and security's public image (2:00)

The central "key findings" of Amélie Koran's talk are not technical vulnerabilities or exploits, but rather a profound set of analogies and ethical principles derived from the hobo code, which she argues are directly applicable, and indeed vital, to the cybersecurity profession. These findings challenge the community to reflect on its shared identity, responsibilities, and future direction.

Firstly, Koran establishes that security professionals are, in essence, travelers – "multi-sector/industry hobos." They navigate diverse technologies, organizational cultures, and threat landscapes, rarely staying in one static role or environment for their entire career. This constant movement necessitates adaptability, continuous learning, and a broad perspective, much like a hobo moving from town to town.

Secondly, the talk identifies a shared experience of being misunderstood and having a distorted public image. Just as "hobo" was once a derogatory term, "hacker" has historically carried negative connotations. This requires security professionals to be constant advocates for their work, explaining its value and ethical underpinnings to a skeptical or uninformed public and corporate leadership. Koran underscores the frustration of being "poor advocates about what we are" and the need for better communication strategies.

Thirdly, Koran highlights the lack of employer loyalty as a defining characteristic of the modern professional landscape, mirroring the precarious employment of historical hobos. This necessitates that individuals constantly build their skills, expand their networks, and be prepared for transitions, reinforcing the idea of self-reliance within a supportive community.

Perhaps the most significant finding is the direct application of the hobo code's ethical tenets to the security community. While the historical hobo code comprised numerous specific signs and rules, Koran extracts the overarching principles:

  • Mutual Aid and Community Support: Hobos formed "jungles" where they shared resources, cooked together, and protected one another. Similarly, security conferences like ShmooCon serve as "jungles" where professionals reconnect, share knowledge, and offer mentorship. Koran emphasizes the importance of helping others find work, offering free training, and providing references, even if it means deflecting opportunities for oneself.
  • Ethical Conduct and Responsibility: The hobo code mandated respect for the environment and avoiding troublesome behavior. Koran translates this into the "don't shit where you sleep" principle, emphasizing professionalism, cleaning up, and being a good community member (e.g., Defcon's 3-2-1 rule: 3 hours sleep, 2 meals, 1 shower). This extends to addressing issues like alcohol and drug problems within the community, offering help rather than shunning.
  • Volunteerism and Contribution: Hobos actively contributed to their temporary communities. Koran champions volunteerism within the security space, whether formal roles at conferences or simply "dropping into some of these villages or other areas and you're just willing to kind of help."
  • Sharing Knowledge and Lore: Hobos passed down their code and experiences through oral tradition. For security professionals, this means actively "sharing your knowledge and experiences and tell our lore, our stories." This includes writing books, contributing to community notes, and documenting practices, even if they become outdated.
  • Lifting Others Up: A powerful theme is the imperative to "lift others up," not just as one climbs, but at all times. This involves mentorship, connecting people, recognizing accomplishments, and actively supporting those in need. The speaker identifies her "superpower" as connecting people, encouraging others to find and leverage their own unique abilities to help the community.
  • Avoiding Being a "Jerk": A simple yet profound rule, "don't be a jerk," underscores the importance of basic respect, introspection, and fostering a positive, inclusive environment.

In essence, Koran's key findings reveal that the informal, ethical framework of historical hobos provides a robust, human-centric blueprint for building a more resilient, supportive, and principled cybersecurity profession capable of navigating its unique challenges.

Technical Deep Dive

▶ Watch: Security professionals' hustle and career exploration (3:20)

While Amélie Koran's talk is fundamentally philosophical and ethical rather than a traditional technical deep dive into code or vulnerabilities, it implicitly addresses the "technical" aspects of the security profession through the lens of community, knowledge transfer, and adaptive skill development. The "code" she refers to is not programming code, but rather the hobo code of ethics, which, when applied to cybersecurity, forms a framework for technical excellence and resilience.

The technical deep dive in this context involves understanding how the hobo code's principles foster a robust technical community capable of tackling complex security challenges.

  1. Continuous Learning and Exploration: Hobos were perpetual learners, adapting to new environments and skills required for temporary work. Koran highlights that the security field "allows us to explore," with professionals coming from diverse backgrounds (e.g., pharmacists, retail workers). This inherent drive to learn and build knowledge is a core technical attribute. The "hustle to find work" in "dark times" also implies a constant need to update technical skills, understand emerging threats, and master new tools or methodologies.
  2. Diverse Skill Sets: The "diversity is our greatest strength" point directly relates to the technical breadth of the security industry. Unlike a single, monolithic technical discipline, cybersecurity encompasses a vast array of specializations, from cryptology (Koran mentions cryptologists from NSA in the audience) to penetration testing, incident response, forensics, security architecture, and policy development. The hobo analogy supports the idea that this diverse skill set, much like the varied talents hobos brought to different jobs, makes the community stronger and more adaptable to a broad spectrum of technical problems.
  3. Knowledge Sharing and "Lore": The hobo code was an oral tradition, later written down. Koran explicitly calls for the security community to "share our knowledge and experiences and tell our lore, our stories." This is the technical deep dive for the community:
  • Documentation: "We put it in github. We put it in community notes. We write books about it." This highlights the importance of open-source contributions, collaborative documentation, and publishing research – all critical mechanisms for technical knowledge transfer in security. Even if books become "useless after a while" due to rapid technological change, they capture a moment in time and contribute to the collective technical memory.
  • Mentorship: The hobo tradition of bringing "new folks who were along" mirrors the critical role of mentorship in cybersecurity. Experienced professionals guide newcomers, sharing practical technical wisdom that cannot be gleaned solely from textbooks or certifications. This directly contributes to raising the overall technical proficiency of the field.
  • Community Forums and Conferences: Events like ShmooCon are central to this "lore" sharing. While specific tools or CVEs might not be discussed in this particular talk, the very act of gathering and networking facilitates the informal exchange of technical insights, war stories, and best practices that are vital for staying current.
  1. Ethical Application of Technical Skills: The hobo code's emphasis on "do good and be better" and "don't be a jerk" directly impacts the application of technical skills. It promotes responsible disclosure, ethical hacking practices, and the use of technical knowledge for defensive rather than malicious purposes. It implicitly guides professionals away from misusing their technical prowess, ensuring that the community's collective "superpower" is used for positive impact.
  2. Adapting to Threat Landscapes and Budget Challenges: Koran mentions that "you never know where the next threat is going to come from, where the next budget challenge is going to be." This directly speaks to the technical challenges of developing flexible, cost-effective security solutions and strategies. The creativity inherent in the hobo's resourcefulness becomes a technical asset in designing resilient architectures or implementing security controls under constraints.

While the talk doesn't present a specific vulnerability or a new tool, it provides a powerful meta-framework for how a technically proficient and ethically grounded security community can sustain itself, evolve its skills, and effectively address the ever-changing technical demands of the field. The "rules of riding the security rails" are, in this sense, the guidelines for a sustainable and impactful technical journey.

Demo / Proof of Concept

▶ Watch: The hacker community as a 'jungle' (4:20)

Amélie Koran's talk did not include a traditional technical demonstration or a security proof of concept (PoC) in the sense of exploiting a vulnerability or showcasing a new tool. The nature of the talk was primarily philosophical and ethical, focusing on analogies and community principles rather than hands-on technical execution.

However, a creative "demonstration" was mentioned during the Q&A portion of the talk. Koran revealed that the AI-generated artwork used in her slides, particularly the images of the judges, was created by inputting photos of each judge into "a couple different AI photo generators." This showcased a contemporary application of artificial intelligence for creative purposes, rather than a security-specific PoC. While not a direct security demonstration, it subtly underscored the ongoing integration of new technologies into various aspects of professional life, including presentations. The core message of the talk remained centered on human ethics and community, rather than technical exploits.

Defensive Implications

▶ Watch: Challenges: diversity, zero loyalty, poor advocacy (5:00)

The "Multi-Sector/Industry Hobo" talk, while not technical, carries significant defensive implications for the cybersecurity community. By fostering the principles of the hobo code, security professionals can build a more resilient, adaptive, and effective defensive posture against evolving threats.

  1. Enhanced Threat Intelligence and Knowledge Sharing: The hobo code's emphasis on "sharing your knowledge and experiences and tell our lore" is a direct call for improved threat intelligence sharing. A community that openly discusses attack techniques, defensive strategies, and lessons learned from incidents is better equipped to anticipate and mitigate future threats. This informal and formal exchange, whether through "community notes," GitHub repositories, or conference talks, strengthens the collective defense by distributing crucial information beyond individual organizations.
  2. Stronger Community Resilience and Mutual Aid: Adversaries often target isolated entities. A strong, interconnected security community, akin to the hobo "jungle," provides a critical layer of defense. When individuals or organizations face severe breaches or challenges, the community's readiness to "help each other out" through mentorship, job references, or even direct assistance (e.g., incident response support) can significantly reduce recovery times and mitigate damage. This mutual aid creates a collective resilience that individual organizations cannot achieve alone.
  3. Ethical Conduct as a Foundation for Trust: The "don't be a jerk" and "do good and be better" principles are fundamental for building trust within the security ecosystem. Ethical conduct among security professionals (e.g., responsible disclosure, avoiding black-hat activities) fosters collaboration with vendors, researchers, and even law enforcement. This trust is crucial for effective information sharing, coordinated defense efforts, and maintaining the integrity of the profession itself. A community known for its ethical standards is more likely to be trusted with sensitive information and granted access to critical resources.
  4. Adaptability and Continuous Skill Development: The hobo's constant "hustle to find work" and the necessity to "explore" new paths translates into a defensive imperative for continuous skill development. The threat landscape is dynamic, with new CVEs, attack vectors, and technologies emerging constantly. A professional who embraces lifelong learning, seeks out "free training," and mentors others ensures that the defensive capabilities of the entire community remain cutting-edge. This adaptability is key to countering sophisticated and rapidly evolving threats.
  5. Effective Advocacy and Policy Influence: Koran notes that security professionals are "really poor advocates about what we are." The hobo code, with its clear ethical framework, provides a strong basis for advocating for better security policies, budgets, and public understanding. By speaking with a unified, ethical voice, the community can more effectively influence decision-makers, leading to better security investments, regulations, and public awareness campaigns that strengthen national and global cyber defenses. Events like "Hackers on the Hill" are examples of this advocacy in action.
  6. Addressing Internal Vulnerabilities (Human Element): The talk's candid discussion of internal community issues like "alcohol and drug problem[s]" and the importance of looking out for one another directly addresses the human element of security. A community that supports its members through personal struggles ensures that highly skilled individuals remain productive and engaged, preventing burnout and potential insider threats that can arise from personal distress. Caring for the well-being of practitioners is a defensive strategy for maintaining a healthy and vigilant workforce.

In essence, the hobo code provides a blueprint for building a robust, ethical, and collaborative security culture. Such a culture is inherently more resilient, better informed, and more capable of mounting a collective defense against the multifaceted and ever-present threats in the digital realm. Defenders should internalize these principles to transform their individual efforts into a powerful, unified front.

Key Takeaways

  • Embrace the "Hobo" Ethos: Security professionals are modern "hobos" – adaptable travelers constantly seeking work, learning new skills, and navigating diverse environments. This identity underscores the need for resilience and community.
  • Reclaim and Advocate: Like "hacker," the term "hobo" needs reclamation. Security professionals must actively advocate for their roles, demystifying their work and communicating its ethical value to the public and corporate leadership.
  • Build Strong Community "Jungles": Conferences and online forums are our "jungles." Foster mutual aid, mentorship, knowledge sharing, and support networks to help fellow professionals find work, learn, and overcome challenges.
  • Adhere to an Ethical Code: Implement a clear, shared ethical framework (like the hobo code) that emphasizes respect, responsibility, professionalism, and the "don't be a jerk" principle, ensuring collective integrity and trust.
  • Lift Others Up & Share Your Lore: Actively mentor new talent, connect people, and contribute to the collective "lore" of the industry through documentation, talks, and sharing experiences. Your "superpower" can be connecting others.
  • Volunteerism and Continuous Contribution: Actively participate and volunteer within the community, whether formally or informally, to contribute to its growth and sustainability. Give back to the career that has given to you.

About the Speaker(s)

Amélie Koran is a highly experienced and respected veteran in the cybersecurity industry, with a professional career spanning approximately 25 years. Known by her handle "webjedi," she has been a dedicated attendee of ShmooCon for 18 years, highlighting her deep engagement and commitment to the community. Throughout her career, Koran has navigated various roles, demonstrating the "hobo" ethos of adaptability across different sectors and industries. She identifies herself as a "goon" at ShmooCon, indicating an active role in the conference's operations and community support. Her talk reflects a profound understanding of the industry's challenges, not just from a technical standpoint, but also from a human, ethical, and sociological perspective. Koran's passion for fostering community, advocating for ethical conduct, and lifting up fellow professionals is a hallmark of her contributions to the field.

Reviews

Dr. Zero (Offensive Security Researcher) — WEAK

This session attempts to draw parallels between the historical hobo code and the modern cybersecurity community, advocating for ethical behavior, mutual support, and knowledge sharing. While delivered with clear passion and personal commitment, the talk fundamentally lacks the technical depth and novel research expected at a conference of this caliber. Its core message, though positive, would be better suited for a blog post or a dedicated community-building event rather than a technical track.

Heather Calloway (CISO) — STRONG ACCEPT

Amélie Koran's "Multi-Sector/Industry Hobo" offers a critical lens on the cybersecurity profession, reframing our community through the historical hobo code. This isn't a technical brief, but a profound examination of the ethical, communal, and human dimensions that underpin our collective ability to manage risk and build resilience. Koran effectively argues that the health of our professional ecosystem – characterized by mutual aid, ethical conduct, and knowledge sharing – is a fundamental institutional concern, directly impacting business exposure and the efficacy of any security program.

→ Top-rated talks at ShmooCon XX (Final)

All talks from ShmooCon XX (Final)