0wn the Con / Growing Up ShmooCon
Shmoo Group
ShmooCon XX (Final) · Day 3 · Bring It On
Overview
The "0wn the Con" talk is a long-standing tradition at ShmooCon, offering attendees an unprecedented look behind the curtain of running a major hacker conference. Unlike typical security presentations focusing on vulnerabilities or exploits, this session, delivered by members of the Shmoo Group (primarily AR and Mr. Potter), delves into the intricate logistics, philosophical underpinnings, and sheer human effort required to bring ShmooCon to life year after year. This particular installment, titled "Growing Up ShmooCon," carried significant emotional weight as it marked the final iteration of the conference, providing a retrospective on two decades of operation and a unique forward look from the perspective of the organizers' children.

Key moments
- 0:00 Introduction and purpose of "0wn the Con"
- 2:00 ShmooCon's operational structure and community mission
- 5:00 The decision to end ShmooCon after 20 years
- 6:40 Looking forward: New beginnings after ShmooCon
- 7:00 The immense volunteer hours behind ShmooCon
0wn the Con / Growing Up ShmooCon
Speakers: Shmoo Group (AR, Mr. Potter, Taran, Bobby, Dax)
Conference: ShmooCon
YouTube: https://www.youtube.com/watch?v=tPbbMPjFKjA
Overview
The "0wn the Con" talk is a long-standing tradition at ShmooCon, offering attendees an unprecedented look behind the curtain of running a major hacker conference. Unlike typical security presentations focusing on vulnerabilities or exploits, this session, delivered by members of the Shmoo Group (primarily AR and Mr. Potter), delves into the intricate logistics, philosophical underpinnings, and sheer human effort required to bring ShmooCon to life year after year. This particular installment, titled "Growing Up ShmooCon," carried significant emotional weight as it marked the final iteration of the conference, providing a retrospective on two decades of operation and a unique forward look from the perspective of the organizers' children.
This talk serves as a masterclass in event management, community building, and the unique challenges faced by independent hacker conferences. It dissects everything from volunteer hours and financial transparency to the intricacies of the Call for Papers (CFP) process and ticket sales. Beyond the operational mechanics, the speakers share their core philosophy of fostering a community, maintaining personal privacy, and leading with kindness. The inclusion of Taran, Bobby, and Dax (AR and Mr. Potter's children) offered a poignant and often humorous account of growing up alongside ShmooCon, highlighting the profound personal impact of such a sustained community endeavor. This blend of practical advice, candid financial disclosure, and personal reflection makes "0wn the Con" an invaluable resource for anyone interested in the lifecycle of a community-driven event.
Background
▶ Watch: Introduction and purpose of "0wn the Con" (0:00)
ShmooCon was founded with a clear mission: to create a hacker conference on the East Coast, filling a void that existed at the time. The organizers, led by the initial vision of Beetle, aimed to give back to the community that had nurtured their interests. From its inception, a core tenet of ShmooCon has been transparency, a commitment exemplified by the "0wn the Con" sessions themselves. These talks were designed to demystify the process of running a conference, sharing the "why" and "how" with the community, and inviting accountability. This openness was also a strategic decision, especially during challenging periods like the early "Moose Cluster" days of ticket sales, which fostered goodwill and trust among attendees.
The decision to operate as an LLC, ShmooCon Logistics, rather than a non-profit, was a deliberate choice to avoid the bureaucratic overhead and administrative complexities often associated with non-profit organizations. This structure allowed the organizers greater agility and control, albeit with the trade-off of tax obligations. Over two decades, ShmooCon grew into a significant event, but the organizers always envisioned an exit strategy. The 20-year mark, coinciding with personal milestones, was deemed the appropriate time to conclude the conference while it was still at its peak, avoiding a slow decline in quality or interest. This philosophy of ending on a high note underscores the care and dedication poured into the event from its very beginning, ensuring its legacy remained one of positive impact and cherished memories.
Key Findings
▶ Watch: ShmooCon's operational structure and community mission (2:00)
The talk revealed several key findings and insights from two decades of running ShmooCon, emphasizing the immense effort and thoughtful philosophy behind the event:
- Volunteer Effort is Monumental: The conference relies heavily on volunteer power. Heidi, a key organizer, dedicates approximately 1,000 hours annually, effectively making it a full-time job from September to February. AR contributes around 400 hours, with thousands more hours collectively invested by other volunteers. This equates to "several man-years of effort" to make the event function, a critical metric for anyone considering organizing similar-scale events.
- CFP Process Requires Nuance Beyond Scoring: For the final ShmooCon, there were 249 total CFP submissions, with a notable 100 submissions received in the last 24 hours. The organizers stressed that talk acceptance is not solely based on numerical scores from reviewers. The process involves meticulous track building, avoiding topic collisions, and accounting for reviewer biases (e.g., overly enthusiastic "sixes" or overly critical "ones"). The most crucial advice for submitters is to follow directions precisely, adhere to word limits, and provide detailed descriptions, as program committees lack time for poorly formatted or incomplete submissions. Referencing prior art is also paramount to demonstrate awareness of existing research.
- Financial Transparency Builds Trust: The Shmoo Group maintains an open-book approach to ShmooCon's finances, providing approximate "money in" and "money out" figures. While acknowledging these are "back of the napkin" estimates, the willingness to share this information, including categories like hotel costs, AV, network, and security, is a cornerstone of their relationship with attendees. This transparency, particularly regarding ticket sales and expenses, fostered significant goodwill, especially during times when ticket acquisition was notoriously difficult.
- Ticket Sales Prioritize Privacy and Community: ShmooCon actively runs its own ticket sales process rather than relying on external platforms like Eventbrite. This decision was initially driven by cost savings but evolved into a commitment to personal privacy, minimizing attendee data shared with third parties. While external platforms have become more cost-effective, ShmooCon maintained its internal system to shoulder the data responsibility. The organizers also noted a positive shift in the community's behavior regarding secondary ticket sales, with attendees largely ceasing to profit off reselling tickets after the organizers requested it.
- Sponsorship is Curated for Value: ShmooCon limits its sponsorships to 39 sponsors across six levels, ensuring value for both sponsors and attendees. This approach prevents dilution of sponsor visibility and encourages sponsors to bring "something different, something fun," moving away from purely corporate pitches. The high demand means sponsorship slots often sell out in days, leading to situations where even large companies are turned away, reinforcing the conference's unique value proposition.
- Technology Management is a Constant Challenge: The talk highlighted the ongoing struggle with event technology, citing the use of G3 Mac minis for registration boxes "far longer than we should have." This illustrates the cost and effort involved in maintaining and upgrading hardware and software for a large-scale event, especially when operating on a tight budget.
- Community and Personal Growth are Core Outcomes: Beyond the technical and logistical aspects, the talk, particularly through the segment with the children, underscored the profound impact of ShmooCon on its community and the organizers' families. The children shared lessons learned, from practical skills like box Tetris and t-shirt folding to invaluable life lessons such as leading with kindness and the importance of a strong support network. This highlights that the "product" of ShmooCon extends far beyond the talks and badges to include personal development and lasting community bonds.
Technical Deep Dive
▶ Watch: The decision to end ShmooCon after 20 years (5:00)
While "0wn the Con" isn't a traditional technical security talk, it offers a fascinating look into the technical infrastructure and operational processes required to run a major hacker conference. The "technical deep dive" here refers to the actual systems and challenges involved in orchestrating ShmooCon:
- Call for Papers (CFP) System: ShmooCon utilizes OpenConf for managing talk submissions. While an open-source version exists, the organizers pay for a managed instance. The process involves a committee of reviewers who score and comment on submissions. AR then performs a "first draft" selection, refined with a small group of key individuals (John, Ben, Bruce, and others). This multi-stage review ensures a balanced program, considering not just scores but also track alignment and avoiding topic overlap. The program committee's challenge is sifting through hundreds of submissions, with a significant crunch often occurring in the final 24 hours. The emphasis on adhering to submission guidelines (word limits, detailed descriptions) is a direct reflection of the technical challenge of processing and evaluating a large volume of diverse content efficiently.
- Registration and Ticketing Infrastructure: Rather than outsourcing to platforms like Eventbrite, ShmooCon developed and maintained its own registration system. This decision, initially driven by cost, became a core tenet of their commitment to personal privacy. By handling attendee data internally, they minimized exposure to potential breaches at third-party vendors. The system also allowed for specific "hacker shenanigans" with credit cards, as one speaker noted with Amex, which offers flexibility not found with other card providers. The historical "Moose Cluster" issues with ticket sales point to the inherent technical complexities of handling high-demand online transactions, a challenge they eventually overcame through iterative improvements.
- On-site Hardware and Network: The conference's physical infrastructure includes what they humorously referred to as G3 Mac minis used as "regge boxes" for registration, highlighting the longevity and sometimes outdated nature of their equipment. The mention of "cost of replacing hardware/software" underscores the continuous investment required to keep event technology functional. The network infrastructure, while not detailed, is a critical component of any hacker conference, supporting attendees, speakers, and staff. The speakers acknowledged that they "sometimes we keep up, sometimes we are behind" on technology, reflecting the dynamic nature of managing IT for a temporary, high-density event.
- Media and Streaming Operations: Bobby, one of the younger speakers, played a crucial role in modernizing ShmooCon's media operations. He transitioned the streaming setup from an older, unspecified system to OBS (Open Broadcaster Software) and leveraged Twitch for live broadcasts. This involved significant work in video editing, audio engineering, and graphic design. The "Task Booster" initiative, which Bobby managed, focused on creating and editing videos, demonstrating a practical application of media production skills within the conference's technical ecosystem. The children also mentioned skills like "building computers" and "designing cutouts for laser cutters" for badge creation, pointing to diverse technical crafts involved.
- Badge Production and Physical Logistics: The creation of ShmooCon's iconic badges involved specific technical processes. The children spoke about "poking out badges from wood" and "designing cutouts for laser cutters." Previous years included projects like the "bicycle badge" and the Stargate element, which involved "inhale fumes to put the Stargate in plastic" and "curing resin wood." These details illustrate the hands-on, often custom, technical fabrication required for unique conference swag, contrasting with mass-produced items. The eventual "shredding" of a Stargate component also highlights the lifecycle of these custom technical elements.
This "technical deep dive" showcases that running a conference like ShmooCon is a complex engineering feat, requiring expertise across various domains, from software development and network administration to media production and physical fabrication. The organizers' candidness about their choices, challenges, and solutions provides valuable lessons for anyone involved in large-scale event technology.
Demo / Proof of Concept
▶ Watch: Looking forward: New beginnings after ShmooCon (6:40)
This "0wn the Con" talk did not feature a traditional security demonstration or proof of concept in the sense of an exploit or a technical vulnerability. Instead, the entire presentation served as a proof of concept for ShmooCon's unique operational philosophy and its impact.
The "demo" was the transparent disclosure of the conference's inner workings:
- Operational Transparency: The detailed breakdown of volunteer hours (1000 hours for Heidi, 400 for AR), the CFP statistics (249 submissions, 100 in the last 24 hours), and the "back of the napkin" financial figures for "money in" and "money out" were a direct demonstration of their commitment to openness. This transparency, a core value of ShmooCon, proved that a large-scale event could be run with integrity and accountability to its community.
- Community Impact: The most compelling "proof" was the segment featuring AR and Mr. Potter's children – Taran, Bobby, and Dax. Their presence on stage, sharing their personal experiences of growing up with the conference, demonstrated the profound, multi-generational impact of ShmooCon. Their stories, from stuffing swag bags and rolling t-shirts to learning video editing with OBS and stream maintenance on Twitch via the "Task Booster," provided tangible evidence of how the conference fostered practical skills and life lessons. The discussion about the unique, often custom-made badges (like the "bicycle badge" or the Stargate components) also served as a physical manifestation of the creative and technical efforts that went into the event.
In essence, the talk itself was a living demonstration of the "own the con" ethos – proving that a successful, beloved hacker conference could be built and sustained through dedication, transparency, and a deep commitment to community, even to the point of involving and shaping the next generation.
Defensive Implications
▶ Watch: The immense volunteer hours behind ShmooCon (7:00)
For security professionals and aspiring event organizers, the "0wn the Con" talk offers unique defensive implications, not against cyber threats, but against the challenges that can undermine the integrity, sustainability, and community spirit of an event. These are "defenses" for conference organizers:
- Defending Against Burnout: The immense volunteer hours (over a "man-year of effort") highlight the risk of organizer burnout. A key defense is structured volunteer management and recognizing the limits of dedicated individuals. The Shmoo Group's decision to end ShmooCon while it was still good, rather than letting it "peter out," is a testament to proactively defending against burnout and ensuring a positive legacy. Organizers must be realistic about effort and set clear boundaries.
- Defending Financial Stability and Trust: Transparency in financial operations, even with "back of the napkin" estimates, is a powerful defense against rumors, mistrust, and financial mismanagement. By openly discussing "money in" and "money out," ShmooCon built a foundation of trust that allowed them to navigate challenging periods. Maintaining an independent financial system (like their own ticket sales) also defends against the financial overhead and data privacy risks associated with third-party vendors.
- Defending Program Quality and Fairness: The detailed CFP process, which goes beyond simple scoring to include track building, collision avoidance, and reviewer bias mitigation, defends against a weak or unbalanced program. Furthermore, the strong emphasis on submitters "following directions" and referencing prior art helps maintain a high standard of submissions, acting as a filter against low-effort or unoriginal content. Providing clear rubrics or examples of successful submissions (which ShmooCon did in the past) can "defend" first-time speakers by guiding them to meet expectations.
- Defending Attendee Privacy: ShmooCon's deliberate choice to run its own ticketing system, rather than using platforms like Eventbrite, is a direct defensive posture against potential data breaches and the commodification of attendee information. This self-reliance ensures that sensitive personal data remains within the direct control of the organizers, demonstrating a commitment to attendee privacy often lacking in larger, corporatized events.
- Defending Community Ethos: Actively curating sponsors to ensure they bring "something different, something fun" and limiting their numbers defends against the commercialization and potential "suitification" of the conference. This maintains the unique hacker ethos and prevents the event from becoming solely a corporate marketing platform. Furthermore, the call for attendees to stop profiting from secondary ticket sales, and the community's positive response, shows how cultivating a strong ethical culture can "defend" against exploitative practices.
- Defending Against Technological Obsolescence: The candid admission of using G3 Mac minis for "far longer than we should have" highlights the constant battle against technological obsolescence and the associated costs. A proactive defense involves budgeting for regular hardware and software upgrades, while a reactive defense involves clever workarounds and leveraging open-source solutions (like OBS for streaming) when resources are limited. This is a practical lesson in resilience for event technical staff.
- Defending Against Loss of Purpose: The "lead with kindness" philosophy, instilled in the children and emphasized throughout the talk, is a defense against negativity, conflict, and a loss of the event's core humanistic purpose. Fostering a supportive environment for volunteers and attendees ensures the community remains vibrant and positive, which is crucial for long-term sustainability.
In summary, the defensive implications from "0wn the Con" are holistic strategies for ensuring the longevity, integrity, and positive impact of community-driven events, addressing challenges from human capital and financial health to technological resilience and ethical conduct.
Key Takeaways
- Running a large-scale conference requires immense volunteer effort and proactive planning to prevent burnout. ShmooCon's operation involved thousands of hours from dedicated individuals, underscoring the need for sustainable models and clear exit strategies.
- Transparency in operations, especially finances, builds strong trust and goodwill within the community. ShmooCon's open-book approach to its budget and processes fostered attendee loyalty, even through challenging logistical periods.
- The CFP process demands more than just numerical scoring; it requires careful curation, track building, and attention to reviewer biases. Submitting talks that strictly follow guidelines and acknowledge prior art significantly increases acceptance chances.
- Prioritizing attendee privacy by controlling ticketing and data management is a core value that distinguishes community-driven events. ShmooCon's decision to run its own ticket sales, despite complexities, protected attendee information.
- Curating sponsors and encouraging unique contributions maintains the event's ethos and value for all stakeholders. Limiting sponsorship to avoid over-commercialization ensures the conference remains authentic and engaging.
- Conferences are powerful platforms for personal growth, skill development, and community building across generations. The experiences shared by the organizers' children highlighted the lasting impact of ShmooCon beyond its official programming, fostering practical skills and life lessons.
About the Speaker(s)
The "0wn the Con / Growing Up ShmooCon" talk was presented by members of the Shmoo Group, primarily AR and Mr. Potter, the core organizers of ShmooCon, along with their children Taran, Bobby, and Dax.
AR and Mr. Potter (collectively the Shmoo Group) are the driving force behind ShmooCon, having conceptualized and executed the conference for two decades. AR, who delivered much of the initial presentation, is deeply involved in the strategic planning, volunteer management, and program selection (CFP) for the event, dedicating hundreds of hours annually. Mr. Potter contributes significantly to the logistical and operational aspects, working closely with AR. Their philosophy centers on transparency, community building, and giving back to the hacker community, a commitment evident in their candid discussions about finances, challenges, and lessons learned. They initiated the "0wn the Con" talks to share their experiences and demystify conference organization.
Their children, who joined them on stage for the latter half of the talk, offered a unique perspective on growing up with ShmooCon:
- Taran is the eldest, 26 years old, and has attended every ShmooCon, remembering key incidents and changes over the years. He shared humorous anecdotes about the "busy work" involved and the importance of a supportive community, and is currently "looking to get hired."
- Bobby is 22 years old, the "eldest youngest" due to an age gap. He is about the same age as ShmooCon itself and has contributed significantly to the conference's media and streaming efforts, modernizing the setup with OBS and Twitch. He's skilled in video editing, audio engineering, and graphic design, and is currently pursuing a Master of Arts in Teaching (MAT).
- Dax is the youngest, 14 years old. He's been involved in the more recent years of the conference, helping with tasks like bag stuffing and t-shirt folding. He shared his perspective on the immense work involved and the skills he's learned, including leadership and public speaking, despite his youth. He's currently in middle school and involved in extracurriculars like orchestra and leatherwork.
Together, the Shmoo Group and their children provided a holistic and deeply personal account of the two-decade journey of ShmooCon, embodying its spirit of community, learning, and shared experience.
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
This is not a zero-day talk, but it's a deep dive into the guts of running a decades-long, community-focused conference. The Shmoo Group, along with their children, lay bare the monumental effort, the financial realities, and the personal sacrifices involved in building and sustaining a vital hacker gathering. Their brutal honesty about logistics, CFP reviews, and the decision to end the con, coupled with the unique multi-generational perspective, offers invaluable lessons for anyone serious about community building and event management. It's a masterclass in transparent operations and the human cost of dedication.
Heather Calloway (CISO) — STRONG ACCEPT
This talk, while not a traditional cybersecurity presentation, offers a masterclass in operational governance, accountability, and the strategic management of risk for any complex endeavor. The Shmoo Group's candid financial transparency, privacy-first decision-making regarding ticketing, and the deliberate choice to conclude the conference on a high note exemplify leadership that prioritizes institutional integrity and community trust. It's a compelling demonstration of how to build and sustain a resilient operation, providing highly transferable lessons for CISOs and executive leaders on managing resources, reputation, and an eventual strategic exit.