.
/v3-uk/analysis/1945499/black-hat-hacking-age
31 Jul 2010, Iain Thomson , V3
The presentations at the Black Hat briefings may make the headlines, but as important is what the show tells us about the overall state of the security industry.
In the years I've been covering the show, it has evolved from a motley collection of hackers, crackers and security wonks to something that feels more and more like RSA conferences. Black Hat is big business, and the smart IT concerns are moving in.
Purists will tell you that Black Hat went to the dogs in 2005, when founder Jeff Moss, aka The Dark Tangent, sold out the show to CMP Media. While it's true that the briefings have suffered, in some ways it's a sign that the hacking industry is getting old.
I nearly choked on my lunch at the Wednesday press conference when renowned hacker Dan Kaminsky turned up in a suit for possibly the second most historic press conference of his life.
I'm ashamed to say I gave him a little ribbing about it, as did others, but in fact it's a very positive sign. And he wasn’t alone. Moxie Marlinspike was wearing a collar, and a lot of otherwise non-conformists were looking surprisingly dapper.
I was told afterwards that the venture capitalists behind Kaminsky's new company Recursion Ventures had taken him clothes shopping and enrolled him in a gym. I'm not sure how true that is, but he's looking good and achieving some great things. DNSSec is something to be very proud of.
"You need the research and the breaking, but it can't stop there," said Kaminsky. "You have to work on a fix, get it out there, and then occasionally put on a suit."
The hacking industry is growing up. The early pioneers are now working out which side they want to go on, and all the gradations in between.
It used to be the dream of every script kiddie that they'd discover a great hack and then be hired by the National Security Agency or a security firm, and spend the rest of their life hacking around in the company of glamorous nymphomaniac spies.
Shows like Chuck perpetuate the myth, but instead the hacking community has got smart.
Just as criminals have realised that malware is much more useful for profit rather than bragging rights, the hacker industry is coming to the conclusion that there's a better life to be had at solving problems than being sarky.
But this is a two-way street. Companies that used to hoard information like politicians go after directorships are now talking to each other, and shared information offers the best shot at providing long-term security. As many have acknowledged, the criminal hackers are winning the security wars.
Cisco's chief security officer John Stewart summed it up perfectly. "We all get together and there aren't many venues in which we get to do this," he said,
"On the first-principles effort, we're largely very interested in the same thing: keeping what we use on a day-to-day basis safe enough for us to use. Research is turning into a profit model."
For a conference that used to play 'Spot the Fed', the idea that a Department of Homeland Security director (even if it was a very poor keynote) and an ex-head of the NSA would be giving presentations is a sign of real change.
Now the US Department of Defense is actively recruiting at the show, and all the major security firms are keeping an eye out on the hot new talent.
Black Hat has lost its hacker edge in the process, however. The critics are right; it's a corporate affair now. But this is no bad thing. That corporates and government are willing to talk to the experts, rather than engaging in mindless enforcement, can be seen as progress.
This was also the biggest show in Black Hat history. The lunch area hosts over 5,000 people and a second room had to be opened up. That's a lot of very dedicated people, albeit with plenty of hangers on. However, the overspill of enthusiasts doesn't stop there.
The Bsides conference, running concurrently with Black Hat, is seen by some as a sideshow, but in fact it's more a collection of the companies that weren't big enough to make it onto the main stage. Big doesn't necessarily mean smart, and the Bsides show looks very interesting.
But it is Defcon that has picked up Black Hat's mantle. Moss made a very smart move in not selling this conference along with Black Hat and, if companies and enthusiasts want to see what's really cutting edge, they should head along to that show.