Building on the Foundation of our Shared Hacker History

Robert Weiss (Principal Security Engineer · Warer)

ShmooCon XX (Final) · Day 2 · Build It

Overview

Robert Weiss’s ShmooCon talk, "Building on the Foundation of our Shared Hacker History," serves as a profound reflection on the enduring principles and rich cultural heritage that define the hacker community. Timed to align with ShmooCon’s "Commencement: A New Beginning" theme, Weiss guides the audience through a historical journey, illustrating how the core tenets of hacking – curiosity, tenacity, collaboration, and a relentless pursuit of understanding complex systems – have manifested across centuries, long before the advent of computers. The talk is a passionate call to recognize, cherish, and actively participate in the community that embodies these values.

Watch on YouTube

Visual summary for Building on the Foundation of our Shared Hacker History by Robert Weiss
Visual summary for Building on the Foundation of our Shared Hacker History by Robert Weiss

Key moments

  1. 0:00 Introduction and speaker's professional background
  2. 1:17 Starting the Enigma decryption software project
  3. 3:57 How hacker community involvement shaped career path
  4. 4:19 Introducing Michael Faraday as a hacker ethic embodiment
  5. 6:04 Faraday's key discoveries: motor, induction, Faraday cage
  6. 6:44 Faraday's persistence and the value of iterative failure

Building on the Foundation of our Shared Hacker History

Speakers: Robert Weiss, Principal Security Engineer at Warer

Conference: ShmooCon

YouTube: https://www.youtube.com/watch?v=-_jUZBMeU5w

Overview

Robert Weiss’s ShmooCon talk, "Building on the Foundation of our Shared Hacker History," serves as a profound reflection on the enduring principles and rich cultural heritage that define the hacker community. Timed to align with ShmooCon’s "Commencement: A New Beginning" theme, Weiss guides the audience through a historical journey, illustrating how the core tenets of hacking – curiosity, tenacity, collaboration, and a relentless pursuit of understanding complex systems – have manifested across centuries, long before the advent of computers. The talk is a passionate call to recognize, cherish, and actively participate in the community that embodies these values.

Weiss, a Principal Security Engineer at Warer and deeply embedded in the hacker community through roles at Defcon, OpenVPN, and various hacker spaces, leverages his personal experiences and historical anecdotes to articulate why this heritage matters. He argues that understanding these roots is crucial for appreciating what makes the community special and for guiding its future evolution. By highlighting figures like Michael Faraday and Alfred C. Hobbs, Weiss reframes the popular perception of "hacking" from a pejorative term associated with criminality to a fundamental mindset of critical inquiry and innovative problem-solving, emphasizing its ethical underpinnings and societal contributions.

The significance of this talk extends beyond mere historical recounting; it’s a foundational piece for current and aspiring security professionals. It provides a moral and philosophical compass for navigating the complexities of the digital age, stressing the importance of learning from failure, fostering inclusivity, and engaging in collaborative efforts. Weiss’s message is clear: the hacker ethos is not just about technical prowess, but about a unique way of engaging with the world, challenging assumptions, and collectively building a more secure and informed future.

Background

▶ Watch: Introduction and speaker's professional background (0:00)

The talk begins with an acknowledgment of ShmooCon's theme of "Commencement," prompting a reflection on the origins and evolution of the hacker community. Robert Weiss posits that the hacker ethos predates modern computing, tracing its roots through a series of historical figures and movements that embody key hacker traits. This background provides crucial context for understanding why the hacker community operates as it does today and why certain values are so deeply ingrained.

One of the earliest examples cited is Michael Faraday, an apprentice bookbinder in 1812 who, despite limited formal education, possessed an insatiable curiosity for science and electricity. Faraday’s meticulous note-taking, self-training, and relentless experimentation—documented in over 30,000 experiments—demonstrate the tenacity and dedication to empirical discovery that characterizes the hacker mindset. His ability to persist through four years of "tedious" and "ultimately a failure" research on optical glass, while still uncovering "anything of consequence," highlights the crucial role of failure in scientific and hacking progress. Weiss draws a direct parallel to the daily experience of penetration testers, who "fail every day, sometimes for months at a time, to get a particular exploit to work" before eventual success. Faraday’s initiation of the Royal Institution Christmas lectures also positions him as an early innovator in knowledge sharing, akin to modern "TED Talks."

The concept of assessing security by demonstrating weaknesses is introduced through Alfred C. Hobbs, a 19th-century American locksmith. At the Great Exhibition of 1851 in London, Hobbs famously picked the seemingly "unpickable" Brahma Precision and Chubb Detector locks, earning a 200-guinea bounty and fundamentally altering Britain's image of lock-making supremacy. This act of "breaking into something as a means to assess its security" is presented as a direct analogy to computer security and software exploitation, where "leveraging very small manufacturing defects" in physical locks mirrors how "extremely small defects, errors or bugs" in "complex software with millions of lines of code" can lead to "complete system ownership." The widespread presence of lockpick villages at hacker conferences today underscores the enduring relevance of Hobbs’s contribution.

Another historical antecedent to modern hacking is Neville Maskelyne, a British magician who, in 1903, publicly disrupted Guglielmo Marconi’s demonstration of secure wireless Morse code. Marconi had claimed his instruments could be tuned to prevent tapping, but Maskelyne broadcast rude messages, including "rats" and a limerick, moments before the official demonstration. This act, which Fleming, Marconi's assistant, called "scientific hooliganism," served as an early proof of concept for wireless interception and interference, fundamentally challenging claims of "secure by design" and highlighting critical security flaws. Maskelyne's motive, "he did it for the lulls," resonates with the playful yet impactful nature of early hacker activities.

The importance of collaboration and community is illustrated by the enigmatic Nicholas Bourbaki collective. Starting in 1934, this group of French mathematicians, initially formed to update outdated textbooks, adopted a collective pseudonym and operated under a strict rule of unanimous consent for publications. Their "frequently heated and confrontational" in-person meetings, fueled by "humor" and a shared belief in their "collective work," enabled them to be "incredibly prolific" for decades. This example underscores the power of sustained, in-person collaboration in generating impactful work, a principle that continues to define the hacker community's reliance on conferences and hacker spaces.

Finally, Weiss delves into the origins of the term and culture of "hacking" at the Massachusetts Institute of Technology (MIT). Early MIT "hacks" were clever pranks or practical jokes demonstrating technical ability, governed by an informal code of conduct emphasizing subtlety, non-damage, and the return of borrowed items. This evolved in the early 1960s with the Building 26 hackers—undergraduates and professors coalescing around early computers like the TX-0, PDP-1, PDP-6, and PDP-10. These pioneers developed the hacker ethic, an unwritten code advocating universal and unlimited access to computers, free information, mistrust of authority, decentralization, and judgment based on hacking skill rather than "bogus criteria." Their practice of lock hacking became a statement against administrative control, a challenge to "administrators who tried to control access to the computers." This historical trajectory establishes a clear lineage for the core values and practices that define contemporary hacker culture.

Key Findings

▶ Watch: How hacker community involvement shaped career path (3:57)

Robert Weiss's talk distills several fundamental insights into the nature of hacking and the hacker community, revealing its enduring ethos and practical applications:

  • Hacking is a Mindset, Not Just a Skill Set: The most overarching finding is that hacking is primarily a way of thinking – characterized by curiosity, critical thinking, and problem-solving in ways not previously anticipated. It's about understanding and questioning complex systems, rather than merely possessing technical skills or adhering to a particular aesthetic. This mindset, rooted in figures like Faraday, is what drives innovation and discovery.
  • Failure is a Normal and Necessary Part of Progress: The talk emphatically normalizes failure as an inherent and valuable component of the hacking process. Weiss highlights that successful exploitation often follows "failing every day, sometimes for months at a time." The key skill, he emphasizes, is "the ability to know when your failures are creating progress and when your failures are just wasting time." This perspective encourages tenacity and resilience, transforming setbacks into learning opportunities.
  • Collaboration and In-Person Interaction are Foundational: From the Bourbaki collective to the "never hack alone" code of MIT and the social dynamics of modern conferences, the talk underscores the critical importance of collaboration and in-person meetings. Sharing, debating, challenging, and supporting each other in physical spaces are identified as essential for the community to "continue to be prolific and generate impactful work together."
  • The Hacker Community is a Meritocracy Built on Inclusivity: The historical development of the hacker community, particularly through early BBS culture and the MIT hacker ethic, fostered an environment where individuals were judged by their contributions ("hacking") rather than superficial attributes like "degrees, age, race or position." The community's evolution, embracing growth from "7,000 attendees" at Defcon 15 to "25,000 attendees," demonstrates a commitment to inclusivity over elitism, even as it necessitates "creative destruction" and adaptation.
  • Ethical Hacking Plays a Vital Societal Role: Through historical examples like Hobbs and Maskelyne, the talk illustrates how exposing security flaws, even through disruptive means, serves a crucial function in assessing and improving security. Weiss acknowledges the negative connotations of the word "hacker" but champions the work of ethical security communities, citing groups like the EFF, Citizen Lab, and I Am The Cavalry for their efforts to "highlight the valuable contributions," "reform bad laws," and "decriminalize ethical activities."
  • Modern Tools Empower Safe and Rapid Experimentation: For newcomers looking to engage with hacking, Weiss identifies virtualization, Linux, and a scripting language like Python as the essential "on-ramp" technologies. These tools enable individuals to "hack safely and fail fast," creating "thousands or millions of inputs" to find "optimal outcomes" without incurring significant cost or risk, mirroring the scientific experimentation on computers seen with Conway's Game of Life.

Technical Deep Dive

▶ Watch: Introducing Michael Faraday as a hacker ethic embodiment (4:19)

While Robert Weiss's talk primarily focuses on the cultural and historical aspects of hacking, it interweaves several compelling technical examples that underscore the practical application of the hacker mindset. These instances serve as historical "proofs of concept" for principles still relevant in modern cybersecurity.

One of the most intriguing technical mentions is Weiss’s personal involvement in developing software to decrypt Enigma messages without the key. Working with Ben in 2012, Weiss describes how they tackled a problem that had been "broken 70 years ago" by cryptographers like Rejewski and Turing, yet lacked readily available software for a personal laptop. The Enigma machine itself was a complex electro-mechanical device involving multiple rotors, a reflector, rings, notches, a plugboard, and starting positions. The sheer number of possible settings made brute-forcing computationally infeasible for the time. Weiss and Ben's solution involved a "really innovative technique" that Ben devised, breaking the Enigma in a "completely different way" that worked "brilliantly." Although the specific algorithmic details are not disclosed in the talk, the project exemplifies the hacker's drive to re-examine solved problems, find novel approaches, and leverage deep understanding of a system's mechanics and weaknesses to bypass its intended security. It highlights the ingenuity required to bypass cryptographic systems, a challenge that persists today with modern encryption.

The historical account of Alfred C. Hobbs at the Great Exhibition of 1851 provides a powerful analogy for vulnerability assessment and exploitation. Hobbs's target locks, the Brahma Precision and the Chubb Detector, were considered the pinnacle of security. His method was not brute force but a meticulous understanding of their internal mechanisms and "leveraging very small manufacturing defects." By using specialized tools and spending "some 50 hours of work" on the Brahma lock, Hobbs systematically exploited these minute imperfections to gain access. Weiss explicitly connects this to modern software exploitation, stating that "more impactful software exploits work leveraging extremely small defects into complete system ownership." These "defects, errors or bugs are almost always are almost impossible to avoid in very complex software with millions of lines of code," making exploitation a persistent reality. This demonstrates that deep technical understanding of a system's design and implementation, coupled with patience, is paramount to uncovering and exploiting vulnerabilities, whether in physical locks or digital code.

Neville Maskelyne's wireless hack against Marconi in 1903 is an early example of radio frequency (RF) exploitation and denial of service (DoS). Marconi's claim of "tuning my instruments so that no other instrument that is not similarly tuned can tap my messages" implied a secure, private communication channel. Maskelyne's ability to broadcast messages that interfered with Marconi's demonstration directly disproved this claim. This act technically showcased the fundamental vulnerabilities of early wireless communication: interception (reading messages not intended for you) and interference (disrupting legitimate transmissions). It's a foundational lesson in wireless security: broadcast mediums are inherently susceptible to eavesdropping and jamming unless robust cryptographic and transmission security measures are in place, a challenge that continues to evolve with modern wireless technologies like Wi-Fi, Bluetooth, and cellular networks.

The talk also touches upon Conway's Game of Life, a zero-player, zero-move cellular automaton programmed by the MIT Building 26 hackers, notably Bill Gosper, into the PDP-6 computer. This simulation operates on a simple set of rules for each cell in a grid:

  1. A populated cell with fewer than two populated neighbors dies (underpopulation).
  2. A populated cell with two or three populated neighbors survives to the next generation.
  3. A populated cell with more than three populated neighbors dies (overpopulation).
  4. An empty cell with exactly three populated neighbors becomes a populated cell (reproduction).

The hackers’ obsession with this game led to the discovery of a "broad range of patterns" such as gliders, guns, spaceships, shuttles, oscillators, eaters, beehives, blinkers, and traffic lights. The Gosper Glider Gun, in particular, is highlighted, generating a recurring pattern that appears to "glide or walk over the grid" and has become a symbol of hacker culture. This technical pursuit demonstrates the power of computation for scientific experimentation and modeling. It allowed the hackers to "vary the inputs," "experiment and fail fast," and "try thousands or millions of inputs and find optimal outcomes" – a precursor to modern simulation, fuzzing, and machine learning techniques used in security research.

Finally, Weiss provides a practical technical "on-ramp" for aspiring hackers: virtualization, Linux, and a scripting language like Python. These three technologies combine to offer a safe, isolated, and rapidly iterative environment for learning. Virtualization (e.g., VirtualBox, VMware) allows users to run multiple operating systems on a single physical machine, creating sandboxed environments for experimentation. Linux, with its open-source nature, command-line interface, and vast array of security tools, serves as the de facto operating system for many security professionals. A scripting language like Python provides the means to automate tasks, parse data, develop custom tools, and rapidly prototype exploits or defensive measures. Together, these tools enable individuals to "run hacking experiments, create prototypes, destroy them and start over rapidly re-iterating with almost no cost," embodying the spirit of discovery and rapid iteration found in the historical examples.

Demo / Proof of Concept

▶ Watch: Faraday's key discoveries: motor, induction, Faraday cage (6:04)

While Robert Weiss's talk was rich with historical examples of demonstrations and proofs of concept, it did not feature a live, interactive technical demonstration during the ShmooCon presentation itself. Instead, the talk highlighted several historical instances where individuals effectively "demonstrated" security flaws or innovative solutions, serving as conceptual proofs of concept that shaped the hacker ethos.

For instance, the speaker recounted his own project with Ben to decrypt Enigma messages without the key, which resulted in a working software solution and a talk at 44Con in London. This past project, though not live on stage, was a significant demonstration of their innovative technique. Similarly, Alfred C. Hobbs's public lockpicking exploits at the Great Exhibition of 1851 were literal demonstrations, proving the vulnerability of supposedly unpickable locks. Neville Maskelyne's disruption of Marconi's wireless telegraphy demonstration in 1903 was a public proof of concept for wireless interference and interception. Even the MIT hacks, like the balloon emerging from the Harvard-Yale game turf, were elaborate demonstrations of cleverness and technical execution.

These historical narratives collectively serve to illustrate how the hacker mindset manifests in tangible, demonstrable ways, whether through breaking systems, building novel solutions, or creatively exposing flaws. The absence of a live demo in Weiss's ShmooCon talk does not diminish its technical depth, as the examples discussed vividly convey the spirit of practical demonstration inherent to hacking.

Defensive Implications

▶ Watch: Faraday's persistence and the value of iterative failure (6:44)

Robert Weiss's talk, while primarily historical and cultural, offers several crucial implications for cybersecurity defenders, encouraging a paradigm shift in how security is approached and practiced.

First, the emphasis on normalizing failure is paramount. Defenders often operate in environments where mistakes are heavily penalized. Weiss's anecdote about the "Blue screw" award and CrowdStrike's acceptance of the Pony Award for "most epic fail" highlights that acknowledging and taking responsibility for errors is essential for learning and moving forward. Security teams should foster a culture where experimentation, even if it leads to temporary setbacks, is encouraged as long as it contributes to progress. This allows for more aggressive testing of defenses and a willingness to admit and fix vulnerabilities without fear of reprisal.

Second, the historical examples of Hobbs and Maskelyne underscore the importance of proactive vulnerability assessment. Hobbs didn't wait for a thief to pick a lock; he actively sought to demonstrate its weaknesses. Similarly, Maskelyne exposed Marconi's false claims of security. For defenders, this translates to embracing offensive security practices like penetration testing, red teaming, and bug bounty programs. Rather than passively waiting for attacks, organizations should actively seek out "small manufacturing defects" or "extremely small defects, errors, or bugs" in their systems before adversaries exploit them. This requires adopting the hacker's mindset of curiosity and relentless questioning of system security.

Third, the talk implicitly advocates for a deeper understanding of fundamental security principles rather than relying solely on vendor claims or surface-level solutions. Marconi's "secure" wireless was easily compromised because its underlying physics had not been fully considered for adversarial scenarios. Defenders must look beyond marketing and critically evaluate the foundational security of protocols, architectures, and implementations. This includes understanding the inherent limitations of technologies and anticipating how they might be misused or circumvented.

Fourth, the sustained success of the Bourbaki collective and the "never hack alone" tenet of MIT hacks highlight the critical role of collaboration and community engagement for defenders. Security is not a solo endeavor. Participating in conferences like ShmooCon, joining local hacker spaces (e.g., Nova Hackers, Unallocated Space), and engaging with online communities allows defenders to share knowledge, learn from diverse perspectives, and build professional networks. This collective intelligence is invaluable for staying ahead of evolving threats and developing more robust defenses.

Fifth, the discussion on the evolution of the term "hacker" and the advocacy work of groups like the EFF, Citizen Lab, and I Am The Cavalry has direct implications for ethical hacking advocacy within organizations and policy. Defenders should champion the value of ethical security research, protect whistleblowers, and advocate for laws that enable responsible vulnerability disclosure rather than criminalizing it. By supporting the ethical hacker community, organizations help ensure a continuous supply of talent and insights necessary for improving global cybersecurity.

Finally, Weiss's practical "on-ramp" of virtualization, Linux, and scripting (Python) provides a clear directive for skill development and safe experimentation. Defenders should leverage these tools to build isolated labs for:

  • Malware analysis: Safely execute and study malicious code.
  • Vulnerability research: Replicate and understand exploits without risk to production systems.
  • Tool development: Prototype custom scripts and utilities for defensive operations.
  • Security control testing: Evaluate the effectiveness of new security products or configurations in a controlled environment.

This "fail fast" approach allows security professionals to rapidly iterate on defensive strategies, gain practical experience, and develop a deep understanding of adversarial techniques.

In essence, Weiss encourages defenders to embrace the core values of the hacker mindset – curiosity, tenacity, and collaborative problem-solving – to build more resilient and adaptable security postures.

Key Takeaways

  • Hacking is a Mindset: At its core, hacking is a mindset characterized by curiosity, critical thinking, and tenacious problem-solving, not merely a set of technical skills or a subculture.
  • Embrace Failure as Progress: Successful hacking, whether historical or modern, often involves numerous failures. The ability to discern productive failure from wasted effort is a crucial skill that fosters tenacity and continuous learning.
  • Collaboration is Key: The hacker community thrives on in-person meetings, sharing, and collective effort. "Never hack alone" is a foundational principle for generating impactful work and fostering innovation.
  • Inclusivity and Meritocracy Define the Community: From early BBS culture to modern conferences, the hacker community values individuals based on their contributions and ideas, transcending traditional biases and actively welcoming newcomers.
  • Ethical Disclosure Drives Security: Historical examples demonstrate that publicly exposing security flaws, even disruptively, is vital for assessing and improving security, highlighting the critical role of ethical hacking and advocacy.
  • Modern On-Ramps for Learning: Virtualization, Linux, and scripting languages like Python provide an accessible, safe, and cost-effective environment for aspiring hackers to experiment, learn, and rapidly prototype solutions.

About the Speaker(s)

Robert Weiss is a highly experienced and deeply integrated member of the cybersecurity community. He currently serves as a Principal Security Engineer at Warer. Prior to this, he held the position of Head of Information Security for OpenVPN, a role he secured through connections forged within the hacker community. Weiss is a long-standing contributor to major security conferences, notably serving as the Speaker Operations and CFP Lead Goon for Defcon. His commitment to fostering local hacker communities is evident through his long-time membership in Nova Hackers and Unallocated Space, and his former co-chairmanship of BSides DC. Throughout his talk, Weiss emphasizes his passion for hacker culture and his belief in its foundational principles, actively encouraging engagement and collaboration among its members.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

This session provides a well-researched and engaging historical account of hacker culture, tracing its roots from pre-computer figures to modern communities. While lacking the bleeding-edge technical depth I typically demand, the speaker's deep knowledge and the talk's clear narrative effectively convey the foundational mindset and values of hacking. It serves as an important cultural touchstone and an excellent call to action for fostering community and continuous learning, making it a valuable, if not strictly technical, contribution.

Heather Calloway (CISO) — STRONG ACCEPT

Robert Weiss's ShmooCon talk offers a compelling historical and philosophical foundation for the hacker ethos, emphasizing curiosity, tenacity, collaboration, and ethical disclosure. While not a direct exposition on governance frameworks, it profoundly informs the cultural bedrock necessary for effective security programs. For any CISO, understanding and fostering this mindset within their teams is critical for proactive risk assessment, resilient incident response, and institutional accountability. The talk serves as a vital reminder that true security leadership begins with embracing the core principles of inquiry and a willingness to confront systemic flaws.

→ Top-rated talks at ShmooCon XX (Final)

All talks from ShmooCon XX (Final)