The Defcon conference has long been known for providing attendees with intricate and unique badges, each year featuring electronic marvels filled with challenges and exercises in hacking. This year’s badges take a bold leap forward in both functionality and purpose by incorporating an innovative piece of technology designed to enhance security and transparency. Created by renowned hardware hacker Andrew "bunnie" Huang, the new badges feature a removable core module that serves as an open-source hardware security token.
The chip, named Baochip-1x, is a product of three years of development, designed to fulfill Huang’s vision of creating a microcontroller with verifiable security. The source code for the Baochip’s operating system, firmware, and cryptographic engines has been made publicly available on GitHub, allowing for rigorous inspection. Unlike traditional chips, the Baochip boasts transparent packaging that allows researchers to visually examine its internal structures and confirm that they align with the published designs.
The affordability of chip manufacturing posed a challenge, but Huang partnered with Crossbar, a company looking to develop a secure open-source chip. By integrating his design into Crossbar’s manufacturing run, Huang optimized production costs while achieving a shared goal of enhanced security.
Past Defcon badges typically utilized commercially available chips, but Huang’s Baochip promises significant advancements. Since its release is tied to the theme of “agency” at this year’s conference—focusing on the intersection of technology and the choices that foster self-determination—Moss saw the badges as an opportunity to promote widespread adoption of the Baochip. He mandated that the badges must have a functional afterlife, avoiding the fate of being discarded post-conference.
The detachable module not only acts as a FIDO hardware security token but also supports time-based password systems and includes a low-resolution camera for QR code scanning. Designed for minimalism to ensure privacy, the camera features basic functionality to facilitate badge interactions without overriding Defcon’s privacy protocols. Each badge glows in distinctive LED patterns, tailored for different attendee categories, fostering engagement among conference-goers.
Huang ensures that the chip adheres to strict security standards, employing a Rust-based operating system and hardware features to prevent attacks. While he asserts that the chip can withstand certain threats, he acknowledges its limitations against sophisticated and resource-rich adversaries.
This collaboration with Defcon offers Huang both a testing ground for potential vulnerabilities and creative input from participants. The hope is that the Baochip serves not only as a functional tool for its users but also sparks a community of experimentation and innovation. The potential applications of the chip extend beyond mere use as a security token, hinting at a future where it could run more complex software or enhance its own security features as the user community engages with the technology.