ShmooFAQ

Shmoo Group

ShmooCon XX (Final) · Day 2 · Bring It On

Overview

ShmooFAQ is ShmooCon's annual, highly anticipated, and often chaotic quiz show, a cornerstone event that blends technical acumen with pop culture references and community engagement. Far from a traditional technical presentation, this talk serves as a live, interactive competition designed to test the diverse knowledge base of cybersecurity professionals and enthusiasts across a wide spectrum of topics. Hosted by the inimitable Lint Tile and featuring a rotating cast of readers, ShmooFAQ challenges teams of up to five participants through six intense "periods" of multiple-choice questions.

Watch on YouTube

Visual summary for ShmooFAQ by Shmoo Group
Visual summary for ShmooFAQ by Shmoo Group

Key moments

  1. 0:00 Talk introduction and initial banter
  2. 12:12 Final call for registration and John Valjean intro
  3. 18:00 Pre-quiz chaos and pencil shortage
  4. 20:10 Official welcome to ShmooFAQ final exam
  5. 21:20 ShmooFAQ rules and anti-cheating pledge
  6. 24:15 Critical warning about unique answer sheet indexing

ShmooFAQ

Speakers: Shmoo Group

Conference: ShmooCon

YouTube: https://www.youtube.com/watch?v=yIutY_X2FcU

Overview

ShmooFAQ is ShmooCon's annual, highly anticipated, and often chaotic quiz show, a cornerstone event that blends technical acumen with pop culture references and community engagement. Far from a traditional technical presentation, this talk serves as a live, interactive competition designed to test the diverse knowledge base of cybersecurity professionals and enthusiasts across a wide spectrum of topics. Hosted by the inimitable Lint Tile and featuring a rotating cast of readers, ShmooFAQ challenges teams of up to five participants through six intense "periods" of multiple-choice questions.

This particular iteration of ShmooFAQ, presented at ShmooCon, underscored the event's unique blend of education and entertainment. It showcased the Shmoo Group's commitment to fostering a vibrant community spirit, punctuated by humorous banter, unexpected technical glitches, and a strong emphasis on charity fundraising. The competition, culminating in the awarding of a championship belt, serves as both a demanding intellectual exercise and a celebration of the shared culture within the hacker community.

The significance of ShmooFAQ extends beyond mere trivia; it reflects the multifaceted nature of the cybersecurity field itself, where a deep understanding of core technical principles must often be complemented by historical context, awareness of industry trends, and even a touch of pop culture savviness. By engaging attendees in a fun yet challenging format, ShmooFAQ reinforces the value of continuous learning and broad knowledge, all while contributing to important causes like the Electronic Frontier Foundation (EFF).

Background

▶ Watch: Talk introduction and initial banter (0:00)

The tradition of quiz shows at hacker conferences is deeply rooted in the community's desire for interactive learning, competitive camaraderie, and a healthy dose of entertainment. Events like ShmooFAQ and the well-known Hacker Jeopardy serve as more than just games; they are cultural touchstones that celebrate the unique blend of technical expertise, historical awareness, and esoteric knowledge prevalent within the cybersecurity sphere. These competitions emerged as a natural evolution of conference programming, offering an alternative to traditional lectures and panels by engaging participants directly in a high-energy, public forum.

The problem these quiz shows solve is multifaceted: how to maintain audience engagement in a large conference setting, how to encourage continuous learning beyond specific talk topics, and how to foster a sense of community and shared identity among attendees. ShmooFAQ addresses these challenges by creating an environment where participants can publicly demonstrate their knowledge, often under playful pressure, while hosts inject humor and personality into the proceedings. Prior work in this space, primarily other conference quiz shows, established the format of multiple rounds, diverse categories, and the use of a scoring system.

At ShmooCon, ShmooFAQ has evolved into a highly anticipated event, known for its challenging questions and the "Mog Tron 9000" custom scoring system. This system, while not explicitly detailed in its technical architecture, is critical to the quiz's integrity, handling unique answer sheets, randomized question orders, and complex scoring rules. The evolution of ShmooFAQ has seen increasingly intricate question design and logistical challenges, such as handling multiple correct answers per question, which the "Mog Tron 9000" is designed to manage, albeit sometimes with "bugs" that are jokingly deferred to "next year." The underlying ethos is to provide a demanding yet accessible platform that caters to both seasoned veterans and newer entrants to the security community, while also serving as a significant fundraiser for digital rights organizations like EFF, collecting over $1,500 during this event alone.

Key Findings

▶ Watch: Pre-quiz chaos and pencil shortage (18:00)

While ShmooFAQ is a quiz show rather than a research presentation, the "key findings" can be interpreted as the core elements that define its structure, challenges, and overall impact on participants. The event revealed several critical aspects regarding the design of engaging educational competitions and the breadth of knowledge expected within the cybersecurity community.

First, the quiz structure itself is a significant finding. It comprised six distinct "periods" or rounds, each focusing on a broad category:

  1. Kindergarten: General cybersecurity and fundamental computing knowledge.
  2. Math: Network protocols, port numbers, binary, hexadecimal, and subnetting.
  3. Arts & Literature: References from hacker culture in movies, books, and video games.
  4. History: Key dates and events in computing and cybersecurity.
  5. Science: Electronics, physics, and an unexpected "me moose or mises" section on plurals, along with alarm sound identification.
  6. CISSP: Enterprise-level information security concepts, often presented in scenarios.

Second, the sophistication of the question design was a notable finding. Questions were predominantly multiple-choice, but with several unique twists:

  • Randomized Answer Sheets: Each team's answer sheet featured a unique layout with randomized question and answer orders, preventing easy collaboration or looking at neighbors' papers. This was managed by a "test ID per round" system, with a humorous "shot of Malort" penalty for selecting the wrong ID.
  • Multiple Correct Answers: Several questions, particularly in the Math and CISSP rounds, explicitly stated that "some questions do have multiple answers" and required all correct options to be filled for credit, adding a layer of complexity beyond typical multiple-choice.
  • Tricky Wording: The questions were often phrased to challenge critical reading skills, a trait exemplified by the CISSP round, which hosts advised answering "like your manager would" rather than with pure technical precision.

Third, the central role of the "Mog Tron 9000" scoring system was a key finding. This custom-built system was responsible for processing the Scantron-style answer sheets. Despite some playful jabs about its "bugs," its ability to handle unique sheet layouts, randomized questions, and multiple-bubble answers was crucial to the competition's integrity. The system's decisions were declared "final," with any issues deferred to "next year at ShmooCon."

Finally, the dynamic and interactive nature of the event itself was a significant takeaway. The hosts, particularly Lint Tile, maintained a high-energy, humorous, and often self-deprecating demeanor, engaging in constant banter with the audience and each other. Audience participation, including shouting out answers (to the hosts' mock consternation) and actively bribing the judges (with proceeds going to EFF), highlighted the community-driven and charitable spirit of ShmooCon. The grand prize – a real championship belt – added a tangible and coveted reward to the intellectual challenge.

Technical Deep Dive

▶ Watch: Official welcome to ShmooFAQ final exam (20:10)

The "technical deep dive" into ShmooFAQ primarily concerns the mechanics and underlying system that facilitates this complex quiz, rather than a traditional security vulnerability or protocol analysis. The core of the competition's technical infrastructure revolves around the "Mog Tron 9000," a custom-developed scoring system designed to process physically submitted answer sheets.

The "Mog Tron 9000" is a critical component, handling several intricate requirements:

  • Unique Answer Sheets: To prevent cheating and ensure fairness, each team received an answer sheet with a randomized order of questions and answer options. This necessitated a robust backend system capable of mapping the selected bubbles on a physical sheet back to the correct answers for that specific sheet's layout. The hosts explicitly warned, "each answer sheet is unique to you," and "A1 is not in the upper left-hand corner."
  • Indexing Marks: Participants were instructed to "fill in your circles completely" and warned against "screwing up the indexing mark," indicating that the system relies on precise optical character recognition (OCR) or similar scanning technology to correctly align and read the submitted answers. Errors in these marks would lead to the "Mog Tron 9000" failing to read the sheet.
  • Multiple Correct Answers: A challenging feature for any automated scoring system, some questions required participants to select multiple correct bubbles to receive full credit. The hosts clarified, "multiple bubbles are okay and the code accepts it. In fact, if you don't get all the correct multiple bubbles, you're screwed and you get zero." This implies the "Mog Tron 9000" performs a logical AND operation across potential correct answers for specific questions.
  • Test IDs: Each round was assigned a specific test ID (e.g., 248 for Kindergarten, 37 for Math, 137 for Arts & Literature, 1985 for History, 69 for Science, 42 for CISSP). Participants had to correctly mark this ID on their sheet, with failure resulting in a "shot of Malort" to get a fresh sheet, highlighting the system's reliance on accurate metadata for processing.

The logistical "technical deep dive" involves the rapid collection and processing of these physical sheets. After each round, teams were instructed to pass their sheets to the center aisles for collection. The "Mog Tron 9000" then rapidly scanned and scored these, with the hosts often providing real-time updates on the processing status, including moments of "technical difficulty" and "no signal shift to standby," which added to the live, unrehearsed charm of the event.

The questions themselves provided a "technical deep dive" into the collective knowledge base of the security community. Examples across categories illustrate the breadth:

  • Kindergarten: Covered foundational concepts like "how many Twisted cable pairs are in a standard ethernet cable" (4), "how many pins are in a USB-A connector" (4), "what does the acronym DOS stand for" (Distributed Denial of Service), types of malware (Trojan, rootkit, worm, ransomware, but not hypervisor), SQL, Wi-Fi cracking tools (Aircrack-ng), hash functions (verifying data integrity), and open-source penetration testing frameworks (Metasploit).
  • Math: Delved into specifics such as hexadecimal conversions (8*8 = 0x40), common port numbers (Telnet on TCP 23, Mail on TCP 25, 587, 465, 2525, encrypted LDAP on TCP 636 and 389, DNS on TCP 53 and UDP 53, BGP on TCP 179), two's complement representation, Hamming distance, subnetting (/29 having 6 usable hosts), and octal permissions (420 for 644).
  • Science: Explored electronics (cold solder joints, thermal paste with silver, Ohm's law R=V/I, resistor color banding for resistance value and tolerance, 555 timer chip with 8 pins) and basic physics (water boiling at 373.15 K, 60/40 tin-lead solder melting at 190°C, diesel autoignition at 210°C).
  • CISSP: Focused on enterprise security architecture and governance, including cabling ratings (plenum), authentication systems combining symmetric and asymmetric crypto (Kerberos), physical security (passive infrared sensor least effective in a gymnasium), compliance recognition (certification), reporting structures (CISO reporting to CEO), access control models (Bell-LaPadula for confidentiality), fire classifications (Class C for electrical), frameworks (COBIT for financial reporting), mandatory access control (MAC), insider threat indicators (Motive, Opportunity, Means), routing protocols (link state routing protocol), smart card policies, intrusion detection techniques (least useful for a safe: CO2 detector), SDLC processes (regression testing for bugs), ring protocols (Isis, RIPv6, OSPF, EIGRP, BGP), risk management strategies (risk acceptance for high cost/low impact), password attack differentiation (dictionary vs. rainbow table), network segmentation devices (router), IP addressing (100.64.0.0/16 for carrier-grade NAT, not private or public internet use), and intellectual property protection (patent laws for algorithms).

The "Mog Tron 9000," while a black box in terms of its internal code, represents a sophisticated, bespoke solution for managing the logistics and scoring of a large-scale, dynamic, and intentionally complex quiz show. Its design considerations directly reflect the unique challenges presented by a live, interactive, and often irreverent hacker conference event.

Demo / Proof of Concept

▶ Watch: ShmooFAQ rules and anti-cheating pledge (21:20)

The entirety of ShmooFAQ serves as its own "demo" or "proof of concept" – a live, interactive demonstration of a large-scale, community-driven quiz show at a major cybersecurity conference. The "demo" showcased the seamless (mostly) execution of a complex, multi-round competition involving hundreds of participants.

The core of the demonstration was the live quiz experience. Teams, armed with unique Scantron-style answer sheets, engaged with questions projected on a large screen while various hosts read them aloud. The dynamic between the primary host, Lint Tile, and the rotating cast of readers (Silly C, Rando, Strafe, Bruce Potter, Danny) was central to the demo's success. Their unrehearsed banter, humorous asides, and engagement with the audience created an atmosphere that was both competitive and highly entertaining. For instance, Bruce Potter's reading of the CISSP questions, complete with his personal commentary and advice ("answer like your manager would"), provided an authentic and relatable experience for many security professionals.

A key part of the demonstration was the "Mog Tron 9000" in action. While its internal workings were not revealed, its function was clearly demonstrated. Answer sheets were collected after each round, transported to the scoring station, and processed. The system’s ability to handle randomized question orders, unique sheets, and questions requiring multiple correct answers was implicitly proven by its continuous operation, despite playful acknowledgements of "bugs" and "technical difficulties" (such as a brief "no signal shift to standby" during the Math round). The final scoring process, leading to the announcement of the top three teams and the ultimate champion, visibly demonstrated the system's ability to aggregate scores and declare a winner.

Another crucial element of the demo was the community engagement and charitable aspect. The hosts actively encouraged "bribes" – donations to the Electronic Frontier Foundation (EFF). These donations, which reached over $1,500 during the event, were a tangible demonstration of how a fun, competitive event could also serve a significant philanthropic purpose. The awarding of a physical championship belt to the winning team, "Hat Heaven St Puking Monty serbo poke and G collector priz," served as the ultimate proof of concept for the competition's design and execution. The demo successfully showcased that ShmooFAQ is not just a quiz, but a vibrant, interactive, and impactful community event that blends intellectual challenge with entertainment and charity.

Defensive Implications

▶ Watch: Critical warning about unique answer sheet indexing (24:15)

While ShmooFAQ is an entertainment and knowledge-testing event, its comprehensive scope implicitly provides several "defensive implications" for cybersecurity professionals. The sheer breadth of topics covered in the quiz underscores the vast and interdisciplinary knowledge base required for effective defense in modern cyber environments.

  1. Broad Knowledge is Essential: The quiz's categories, ranging from "Kindergarten" (basic security principles) to "CISSP" (enterprise governance and architecture), demonstrate that defenders cannot specialize too narrowly. A strong foundation in network protocols (ports, subnetting, routing), operating system internals (file systems, memory), historical context (Morris Worm, CFAA, major breaches), and even physical security is crucial. The ability to answer questions across these domains reflects a well-rounded security professional, better equipped to identify and mitigate diverse threats.
  2. Attention to Detail and Critical Thinking: The randomized answer sheets, questions with multiple correct options, and intentionally tricky wording (especially in the CISSP section) implicitly train participants in critical thinking and meticulous attention to detail. Defenders constantly face ambiguous situations, misleading information, and complex systems. The quiz format, by forcing careful reading and precise selection, hones skills vital for incident response, vulnerability analysis, and policy interpretation.
  3. Understanding the Adversary's Mindset (and Culture): The "Arts & Literature" and "History" sections, filled with hacker movie references, historical events, and pop culture memes, highlight the importance of understanding the cultural context and historical evolution of hacking. Knowing the origins of terms like "script kiddie" or references from WarGames or Neuromancer provides insight into the hacker ethos, which can sometimes aid in anticipating adversary tactics, techniques, and procedures (TTPs).
  4. Network and System Hardening: The "Math" and "Science" categories, with their focus on port numbers, subnetting, and hardware components, directly relate to fundamental network and system hardening. Knowing default ports (e.g., TCP 23 for Telnet, TCP 179 for BGP) is critical for configuring firewalls, intrusion detection systems, and secure network segmentation. Understanding basic electronics (solder joints, thermal paste) can inform physical security assessments and hardware tampering detection.
  5. Enterprise Security Governance and Risk Management: The "CISSP" round directly addresses the strategic and governance aspects of cybersecurity. Questions about access control models (Bell-LaPadula), compliance (certification), risk management strategies (risk acceptance), and insider threat indicators (Motive, Opportunity, Means) are directly applicable to building resilient security programs. Defenders need to understand not just the technical controls but also the policies, frameworks, and legal implications (like the CFAA, which was referenced in the history section) that govern their security posture.
  6. Community and Information Sharing: The event itself, by fostering community and collaboration (even if within teams), reinforces the importance of collective defense. In the real world, sharing threat intelligence, collaborating on defensive strategies, and learning from peers are invaluable. ShmooFAQ, as a community-building exercise, indirectly promotes these essential defensive practices.

In essence, ShmooFAQ, through its diverse and challenging curriculum, serves as a simulated, high-pressure environment that tests and implicitly reinforces the comprehensive skill set necessary for robust cybersecurity defense, from the lowest-level technical details to the highest-level strategic thinking.

Key Takeaways

  • Comprehensive Knowledge is Paramount: ShmooFAQ rigorously tests a vast array of topics, from fundamental computing and network protocols to advanced enterprise security concepts (CISSP) and the cultural history of hacking, underscoring the interdisciplinary expertise required for effective cybersecurity.
  • Sophisticated Quiz Mechanics: The competition utilizes a custom "Mog Tron 9000" scoring system to manage unique, randomized answer sheets, enforce strict indexing requirements, and accurately score questions with multiple correct answers, showcasing a complex logistical and technical setup.
  • Engaging and Humorous Delivery: Hosted by Lint Tile and a rotating cast of readers, the event maintains a high level of audience engagement through witty banter, self-deprecating humor, and direct interaction, making learning and competition entertaining.
  • Community and Charity Focused: Beyond the competition, ShmooFAQ is a significant community-building event, fostering camaraderie and successfully raising over $1,500 in "bribes" (donations) for the Electronic Frontier Foundation (EFF), highlighting the philanthropic spirit of ShmooCon.
  • Practical Defensive Skill Reinforcement: The quiz's challenging format, particularly with tricky wording and specific technical details, implicitly hones critical thinking, attention to detail, and a broad understanding of defensive strategies, from network hardening to enterprise governance.
  • Pop Culture and History Matter: Integration of questions from hacker movies, books, and historical events emphasizes that understanding the cultural and historical context of cybersecurity is as important as technical knowledge.

About the Speaker(s)

The "Shmoo Group" is credited as the speaker for ShmooFAQ, representing the collective effort of the organizers and hosts of ShmooCon, the renowned hacker conference. The primary host and driving force behind ShmooFAQ is Lint Tile, who orchestrates the entire event. Lint Tile is known for his distinctive voice, quick wit, and ability to manage the chaotic yet engaging atmosphere of the quiz show. He is also responsible for the "Mog Tron 9000" scoring system and its underlying question generation, often joking about the "alcohol involved in the writing of this program." Beyond ShmooFAQ, Lint Tile teaches an all-day course through ISACA, focusing on tradecraft and offering CPEs for various certifications, including CISSP and SANS.

Throughout the event, Lint Tile is joined by several individuals from the Shmoo Group who take on the role of question readers, adding their own personalities and humor to the proceedings. Notable readers in this session included:

  • Silly C: Read the "Kindergarten" round.
  • Rando: Read the "Math" round, bringing his own style to the technical questions.
  • Strafe: Read the "Arts & Literature" round, navigating its pop culture references.
  • Bruce Potter: A prominent figure in the security community, Bruce Potter read the challenging "CISSP" round. He is famously known as a "Hacker Jeopardy champion" and has taught numerous CISSP classes, despite, as the hosts humorously pointed out, not holding the certification himself. His commentary and advice during his segment were highly entertaining and insightful.
  • Danny: Contributed to the "Science" round and assisted with various logistical aspects.

Collectively, the Shmoo Group, led by Lint Tile, creates an engaging, challenging, and memorable experience that is a highlight of ShmooCon.

Reviews

Dr. Zero (Offensive Security Researcher) — HARD PASS

This 'session,' if one can even call it that, is nothing more than a poorly disguised pub quiz. While I appreciate the effort to entertain, a conference slot is for actual research, not a chaotic trivia game filled with basic, rehashed facts from 'Kindergarten' to 'SISP' certification prep. There is zero technical depth, zero novel contribution, and absolutely zero actionable intelligence for any attendee worth their salt. This is an insult to the intellectual rigor expected at a serious security conference.

Heather Calloway (CISO) — STRONG ACCEPT

This ShmooFAQ quiz, while an entertainment event, powerfully underscores the foundational requirement for broad, interdisciplinary knowledge across all levels of a security organization. It implicitly challenges security leaders to ensure their teams possess a comprehensive understanding of technical fundamentals, operational nuances, and enterprise governance principles, demonstrating that effective defense and risk management hinge on continuous, wide-ranging education rather than narrow specialization.

→ Top-rated talks at ShmooCon XX (Final)

All talks from ShmooCon XX (Final)