Shmooganography, Looking Back from Behind the Scenes and into Plain Sight
Will Newton, Mike Bowen
ShmooCon XX (Final) · Day 2 · Bring It On
Overview
The ShmooCon conference has long been a bastion for cutting-edge security research and community engagement, and for many years, a standout staple has been the Shmooganography challenge. This talk, "Shmooganography, Looking Back from Behind the Scenes and into Plain Sight," delivered by its creators, Will Newton and Mike Bowen, offers an unparalleled retrospective into the intricate world of designing, deploying, and managing this multi-stage steganography game. Far from a mere summary, the presentation provides a candid, in-depth look at the evolution of the challenge, detailing both the triumphs and tribulations encountered over its extensive run.

Key moments
- 0:00 Welcome and ShmooConography introduction
- 2:27 Defining Shmooganography: Hiding things in plain sight
- 3:20 The origin story: 1600 pens puzzle
- 4:50 Game evolution: from 3 to 5 stages
- 5:30 How contestants engage with Shmooganography challenges
Shmooganography, Looking Back from Behind the Scenes and into Plain Sight
Speakers: Will Newton, Mike Bowen
Conference: ShmooCon
YouTube: https://www.youtube.com/watch?v=yIutY_2XFcU
Overview
The ShmooCon conference has long been a bastion for cutting-edge security research and community engagement, and for many years, a standout staple has been the Shmooganography challenge. This talk, "Shmooganography, Looking Back from Behind the Scenes and into Plain Sight," delivered by its creators, Will Newton and Mike Bowen, offers an unparalleled retrospective into the intricate world of designing, deploying, and managing this multi-stage steganography game. Far from a mere summary, the presentation provides a candid, in-depth look at the evolution of the challenge, detailing both the triumphs and tribulations encountered over its extensive run.
Will Newton and Mike Bowen, the masterminds behind Shmooganography, share their journey from initial concept to a long-standing conference tradition. The talk delves into the core philosophy of the game—hiding information in plain sight without relying on traditional cryptography—and explores the diverse array of techniques employed over the years. This behind-the-scenes narrative is invaluable for anyone interested in game design, practical steganography applications, or the logistical complexities of running a community-driven technical contest within a major security conference.
The significance of this talk extends beyond the ShmooCon community. It serves as a practical guide and a cautionary tale for those considering building similar challenges, emphasizing the critical interplay between technical ingenuity, robust logistics, and community interaction. The speakers' reflections on what worked, what didn't, and the continuous learning process underscore the dynamic nature of such initiatives, making it a crucial resource for fostering engagement and education within the broader cybersecurity landscape.
Background
▶ Watch: Welcome and ShmooConography introduction (0:00)
Shmooganography originated from a desire to introduce a fun, engaging technical challenge at ShmooCon. Will Newton, hired into the industry by Bruce Potter, the founder of ShmooCon, conceived the idea after attending ShmooCon 2. Initially a solo endeavor, Will crafted a three-stage contest that incorporated elements of both cryptology and steganography. A notable early challenge involved disassembling 1,600 multi-color pens, inserting tiny slips of paper with codes between the ink cartridges, reassembling them, and distributing them in attendee bags—a testament to the early, highly physical nature of the game.
As the challenge grew, Mike Bowen joined Will, transforming it into a more collaborative and refined experience. The game evolved from its initial three stages, briefly expanding to seven, and eventually settling into a five-stage format. A deliberate pivot was made to focus exclusively on steganography, moving away from cryptology to truly embody the concept of "hiding things in plain sight." This distinction is a core tenet of Shmooganography, ensuring that the hidden information never interferes with the primary function or appearance of the medium.
The game operates with a blend of old-school and modern approaches. Teams register via email, receiving personalized, non-automated responses that foster a direct relationship with the builders. Progress is tracked on a dedicated website, which also provides hints and a scoreboard, allowing teams to gauge their standing. Each of the five stages is designed to be progressively more complex, starting with more physical, easily discoverable clues and escalating to intricate technical puzzles. Successful completion of a stage yields a code word and a new clue, guiding teams through the multi-faceted challenge. The motivation behind Shmooganography is multifaceted: to provide an outlet for technical exploration, engage the community, and offer tangible prizes, including a $500 cash prize, thanks to dedicated sponsors.
Key Findings
▶ Watch: Defining Shmooganography: Hiding things in plain sight (2:27)
Over its many years, Shmooganography has yielded significant insights into effective game design, community engagement, and the practical application of steganography. A primary finding is the critical role of strong logistics and planning, which often overshadow the technical challenge itself. The speakers highlighted the importance of early and consistent interaction with conference organizers, securing sponsorships to cover costs (such as hotel rooms, which often exceeded prize money), and gaining visibility through posters and other advertising. Being co-located at the conference venue also proved essential for direct interaction with participants and real-time feedback.
From a game design perspective, the creators learned several crucial lessons. Fairness is paramount, especially with cash prizes, necessitating clear clues and equitable hint distribution. They discovered the pitfalls of creating bottlenecks, where a single physical resource (like their custom-built Legend of Zelda console) became a choke point for all teams, leading to frustration. Consequently, they often provided digital alternatives or distributed resources. Another key lesson was to avoid overlapping techniques or media across different stages, as this frequently confused players and detracted from the intended challenge. Each stage's hidden information needed to be distinct to maintain clarity and prevent accidental premature solves.
The choice of theming proved vital for engagement and differentiation. Rotating themes annually, ranging from Super Mario to Magic the Gathering, helped tie challenges together logically and distinguish Shmooganography from other conference contests. However, the themes also had to be adaptable, as some ambitious ideas (like a full video advertisement) proved too labor-intensive for recurring use. Ultimately, the continuous loop of feedback, adaptation, and a deep-seated passion for the craft, despite personal and professional time constraints, were identified as the core drivers for the longevity and success of Shmooganography. The educational value for both participants and creators, fostering a unique way of thinking about hidden information, remains a central takeaway.
Technical Deep Dive
▶ Watch: The origin story: 1600 pens puzzle (3:20)
Shmooganography distinguishes itself by strictly adhering to steganography – the art of concealing information within other non-secret data or messages, avoiding traditional encryption. This core principle dictates that the modified medium must still function as intended, making the hidden message truly "in plain sight." Over the years, Will Newton and Mike Bowen have developed and employed a diverse arsenal of techniques, ranging from low-tech physical modifications to complex digital manipulations.
Successful Steganography Techniques:
- Polarization Film Manipulation:
- One notable technique involved removing the polarization film from a monitor display (e.g., a Twitter feed display). When viewed normally, only a seemingly incomplete image or text was visible. However, by using a polarized set of sunglasses or a provided piece of polarization film, the hidden message would become fully legible. This exploited the optical properties of LCD screens and light.
- UV Ink Printing:
- The team utilized UV ink for physical challenges. This involved purchasing UV-sensitive ink compatible with older HP or Epson printers, cleaning cartridges, and printing messages. These UV prints were then layered with overt black-and-white laser prints. Under normal light, only the overt print was visible, but when illuminated with a black light, the hidden UV message would pop out, often integrated into game controllers or other themed elements.
- Packet Steganography (EG4 Streams):
- For more advanced stages, particularly Stage 5, packet steganography was a recurring theme. One specific implementation involved manipulating EG4 streams, which are concatenations of JPEG images. By leveraging overflow areas within these streams, additional data could be hidden without degrading the quality or functionality of the original images. Will Newton often delved into RFCs (Request for Comments) to identify obscure header fields or unused data spaces within network protocols where information could be covertly embedded. The rule was strict: the original medium (e.g., the image stream) had to remain functional after modification.
- USB Containment Unit:
- This interactive physical challenge involved a custom-built unit with a USB port. When a contestant plugged in their USB drive, the system would perform several actions: it would format the drive (a "dirty" trick), capture a picture of the contestant, embed another picture (containing the clue) within that captured image, write the modified image back to the contestant's drive, and return it. The challenge then lay in the contestant's ability to extract the hidden image from the seemingly innocent photo.
- Wormhole (Raspberry Pi & Ethernet over Power):
- During a Stargate-themed year, the "Wormhole" challenge involved two wooden boxes, each containing a hidden Raspberry Pi and black lights mounted upside down. The Pis communicated using Ethernet over Power (EoP), a technique that allows network data to be transmitted over existing electrical wiring. Players had to identify a specific box and knock on it three distinct times. This action would trigger a message to be sent via EoP to the other box, which would then play an audible message. This message was octo-encoded in the upper registers of the audio spectrum, making it difficult to hear normally but causing "clicking noises" that alerted teams to record and analyze it. This complex setup required careful pre-testing and a stroke of luck for the EoP to work reliably in the conference environment.
- Low-Tech Steganography:
- Not all techniques were digital or hardware-intensive. Low-tech methods included:
- Bidirectional Poems: Poems designed to convey different meanings when read forward or backward.
- Program Manipulation: Hiding code words as the first character of each line in the conference program, or embedding purposeful spelling errors in specific paragraphs that, when decoded, revealed clues.
- Whitespace Steganography: Using spaces and tabs in text files to represent binary data (e.g., space = 0, tab = 1). An anecdote shared involved Tesla allegedly using varied spacing in company-wide emails in 2009 to create unique signatures for each recipient, enabling them to identify the source of a leak.
Techniques That Didn't Work Well:
- Wi-Fi Packet Steganography (Live Deployment):
- An ambitious attempt involved hiding messages within Wi-Fi management or control frames and replaying a pcap capture live as a fake access point. While this worked in a controlled home environment, the highly contested Wi-Fi spectrum at ShmooCon, coupled with hardware limitations of the time (pre-robust Wi-Fi), made live deployment impossible. The backup plan was to simply provide the pcap file to teams.
- IR LED Shadow Box:
- A sign featuring steganography icons in a shadow box with IR LEDs was designed to reveal a message when photographed. However, the IR lights were not powerful enough to clearly display the message in the conference setting, despite a frantic search for more LEDs in local electronics stores.
- Stargate Event Horizon (Vixen Light Control):
- Part of the Stargate theme, this involved using a Vixen-type light control system to manipulate blue and white lights in the "event horizon" of a Stargate prop, intending to encode 1s and 0s. The technique was deemed too complicated for teams to decipher and suffered from poor visual contrast due to an un-planned light background, which was partially mitigated by a hotel-provided black tablecloth.
- Overlapping Techniques/Media:
- A recurring issue was trying to use the same file or physical item to convey multiple distinct steganographic techniques for different stages. This invariably led to confusion and frustration among teams, prompting the creators to ensure distinct media or clearly demarcated techniques for each challenge.
- Blue Man Group Poster:
- A poster designed to play a specific musical sequence (three notes from the Intel Blue Man Group commercials) was themed for the game but proved too difficult to integrate into an actionable challenge, remaining an unused design element.
These detailed examples highlight the experimental nature of Shmooganography, showcasing the continuous learning and adaptation required to create novel and engaging steganographic challenges.
Demo / Proof of Concept
▶ Watch: Game evolution: from 3 to 5 stages (4:50)
While the talk itself was a retrospective rather than a live demonstration of a new hack, Will Newton and Mike Bowen effectively "demonstrated" their past challenges through a rich array of visual aids and anecdotes. They presented numerous slides featuring photographs and screenshots of deployed techniques and props from previous ShmooCon events.
A notable "demo" within the presentation was the playback of their Blue Man Group-themed advertising video. This video, created for a past conference, was not just an advertisement for Shmooganography but itself contained hidden elements, such as a fabricated talk title within a series of genuine ShmooCon presentation slides. The speakers pointed out a subtle oversight in the video where the "refresh" action for getting conference tickets was shown incorrectly, adding a touch of humor to their past efforts.
Furthermore, Will Newton explicitly mentioned having one of the Magic the Gathering-themed posters on stage with him. He invited attendees to examine it after the talk, explaining how tilting the poster at an extreme angle would reveal a hidden message printed on the back, exploiting a visual steganography technique. This provided a tangible example of a low-tech, yet highly effective, method they had deployed.
The entire presentation served as a comprehensive "proof of concept" for their game design philosophy, illustrating how diverse steganographic techniques, from physical object manipulation to digital packet embedding, could be successfully integrated into a multi-stage, engaging, and educational contest.
Defensive Implications
▶ Watch: How contestants engage with Shmooganography challenges (5:30)
The detailed exploration of steganography techniques in Shmooganography carries significant defensive implications for cybersecurity professionals. The core idea of hiding information in plain sight is a powerful concept that can be leveraged by both attackers for data exfiltration and defenders for tracking or protection.
The speakers provided a compelling real-world example of steganography being used for internal corporate security. They recounted an alleged incident at Tesla in 2009 where the company reportedly used subtle variations in whitespace (spaces vs. tabs) within emails sent to employees. While the content of the emails appeared identical, each employee received a uniquely formatted version. If a proprietary document was leaked, and that specific email's formatting was found embedded within the leak, it could trace back to the individual who received that unique email. This illustrates how even seemingly innocuous elements can be used as a covert channel for tracking and identifying insider threats, a concept directly applicable to defensive strategies.
Conversely, the same principles highlight the challenge of detecting data exfiltration. If attackers employ sophisticated steganographic techniques—embedding malicious payloads or sensitive data within images, audio files, network packets, or even printer metadata—traditional security tools might miss them. The talk implicitly emphasizes the need for security analysts to think beyond overt indicators of compromise and develop a "steganography-aware" mindset.
The speakers also briefly touched upon existing defensive measures. They mentioned that some corporate solutions already aim to defend against steganographic techniques for leaking information, such as email servers that automatically reformat images, thereby destroying any embedded steganography. This points to an ongoing arms race between steganography techniques and detection methods.
Ultimately, the educational value of Shmooganography is a defensive asset. By exposing participants to various methods of hiding and finding information, it trains individuals to look for the subtle anomalies that could indicate malicious activity. For organizations, it underscores the importance of:
- Deep Packet Inspection (DPI) capabilities that can analyze beyond standard header fields.
- Content analysis tools that can detect subtle alterations in file formats or media.
- User behavior analytics that might flag unusual file transfers or communications.
- Awareness training for employees about the potential for hidden data.
- Continuous research into new steganographic methods to develop corresponding detection techniques.
The call for more dedicated steganography research teams echoes this need, suggesting that this domain, while often overlooked, is crucial for comprehensive cybersecurity defense.
Key Takeaways
- Logistics are paramount for long-term success: Running a multi-year, community-driven technical contest like Shmooganography requires extensive planning, coordination with conference organizers, and securing sponsorships to cover costs and ensure smooth execution.
- Steganography is distinct from cryptography: The core principle is "hiding in plain sight," where the hidden information does not alter the intended functionality or appearance of the cover medium, offering unique challenges for both creation and detection.
- Effective game design avoids player bottlenecks: Challenges must be designed to prevent single points of failure or resource contention that could frustrate teams, often requiring backup plans or distributed access to resources.
- Diverse techniques enhance engagement: Successful steganography can range from low-tech physical manipulations (UV ink, spatial text formatting) to complex digital methods (packet steganography, custom hardware with Raspberry Pis), keeping the game fresh and challenging.
- Learning from failures is crucial: Not all ideas work as intended, especially in dynamic conference environments. Identifying and adapting to deployment challenges, wonky clues, or overly complex stages is essential for continuous improvement and player satisfaction.
- Community and education are primary drivers: Despite significant time investment and personal sacrifices, the positive feedback, educational impact, and opportunity for technical engagement within the community are the key motivations for sustaining such initiatives.
About the Speaker(s)
Will Newton is a long-standing member of the ShmooCon community, having been hired into the industry by Bruce Potter, the founder of ShmooCon. He initiated the Shmooganography challenge as a solo endeavor at ShmooCon 2, driven by a desire to contribute a fun, technical game to the conference. Over the years, Will's career has evolved, moving into more leadership-oriented roles. However, Shmooganography remains a crucial outlet for him to stay technical, engage with the community, and indulge in the "fun stuff" of cybersecurity. He is deeply involved in the technical design and deployment of the challenges, often delving into RFCs to discover new steganographic opportunities.
Mike Bowen has been working with Will Newton for approximately 20 years, with their paths frequently overlapping, particularly through ShmooCon. He joined Will in building and evolving the Shmooganography game, bringing his own technical expertise and collaborative spirit to the challenge. Mike shares Will's passion for the game, contributing to technique development, logistics, and the overall management of the contest. Beyond their professional and conference-related collaborations, they maintain a close friendship, even engaging in activities like camping together. Mike is also featured as one of the voices in Will's elaborate light shows, highlighting their shared interests beyond cybersecurity. Together, they are the dedicated "builders" who have shaped Shmooganography into a beloved ShmooCon tradition.
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
Newton and Bowen deliver a brutally honest, no-bullshit retrospective on building and running the Shmooganography challenge for nearly two decades. This isn't theoretical fluff; it's a deep dive into the practicalities, the triumphs, and the painful failures of deploying diverse steganography techniques in a live conference environment. For anyone considering building a real-world CTF or simply wanting to understand the operational challenges of data hiding, this talk provides invaluable, hard-earned lessons. They clearly put in the work, and it shows.
Heather Calloway (CISO) — STRONG ACCEPT
This retrospective on Shmooganography offers a surprisingly valuable look into the often-underestimated threat of steganography. While framed as a game design journey, the speakers effectively translate the intricate art of 'hiding in plain sight' into tangible risks for data exfiltration and insider threats. The talk provides clear examples of how information can be concealed across various mediums, from physical objects to network packets, compelling security leaders to rethink their detection strategies and consider the subtle ways sensitive data might leave their organizations.