Live data from Hacker News

Entropic Engineering DEFCON 32 Statement

entropicengineering.com

131–140 of 187 posts

Re: Entropic Engineering DEFCON 32 Statement

#131
post #54

Earlier quoted context omitted.

[flagged]

> undisclosed malware in the FW Lol, its literally just an easter-egg screen. If you see something that benign as malware, you may actually have some in your brain.

Calling something that’s trying to fool people into tipping into a crypto wallet controlled by the person who inserted it an Easter-egg is really stretching it.

It’s obviously trying to insert the potential for financial fai into the software which falls well within the definition of malware. Just because the author calls it a joke doesn’t mean it’s suddenly not a serious breach of the confidence placed on them.

Re: Entropic Engineering DEFCON 32 Statement

#132
post #72

As per usual nobody comes out of these things looking good. To really understand who is right and who is wrong here we would need to read the letter of the agreements between these entities, and cross reference them with facts. Of course neither the contracts, nor the facts are available to us. As is, the best I can do here is to put all participants on my personal “do not work with” list. Who needs the drama. In par…

The firmware author themselves write[1]: > I was not anybody’s contractor or subcontractor. I’m not employed by entropic nor by you [DEFCON]. I did this in my free time so attendees could have a fun badge. [1] https://old.reddit.com/r/Defcon/comments/1ep00ln/def_cons_re...

It seems quintessentially DEFCON to infiltrate both organizations by exploiting the breakdown of communication between them.

Re: Entropic Engineering DEFCON 32 Statement

#133
post #79

Earlier quoted context omitted.

> undisclosed malware in the FW Lol, its literally just an easter-egg screen. If you see something that benign as malware, you may actually have some in your brain.

At DEFCON of all places. I mean, they steal your password and post it on a board as a joke. Didn't someone set up fake charging devices a few years ago to hack people's phone and gave a talk about it?

There’s a clear difference between highlighting security concerns and doing things for financial gain. If they’d have used the passwords to drain peoples bank accounts then we’d also be talking about it as a serious issue.

Re: Entropic Engineering DEFCON 32 Statement

#134
post #93

Earlier quoted context omitted.

I think this is a very balanced take and probably one that most people should follow. However, I do slightly favour defcon in this mess - why did Entropic take on a project that was nearly "impossible". Why did the firmware engineer add a crypto beg for a "joke".

> I do slightly favour defcon in this mess I do favour Entropic slightly. Simply because DEFCON being the larger entity has more power in the situation to dictate terms, and also because the end result favours DEFCON. They have their badges using the work Entropic put into them. But I recognise that this is entirely feel and vibe based. Which is not the proper basis to decide anything. > Why did the firmware engineer…

> I do favour Entropic slightly. Simply because DEFCON being the larger entity has more power in the situation to dictate terms […]

If the terms were clarified before the contract was signed, i don’t really see this point. If you sign a contract to do something, it doesn’t matter how much power the other party has. If you don’t like the terms they dictate, don’t take them as a customer. And once there is a contract, the terms should be locked in.

Re: Entropic Engineering DEFCON 32 Statement

#135
post #3

I regret that I have only two eyes to roll at this: We are especially grateful that Dmitry was not hurt in the physical removal he was subjected to as a result of his demonstration of solidarity. We want to extend our thanks to all attendees who have been asking questions, reaching out, attending surprise side-walk cons, displaying the about page badge on the con floor, and, especially, keeping a community eye on law…

Omg, someone didn't follow the rules at a hacker convention!

That's what's kind of interesting about this entire drama. The entire conference is based on people that break systems, bend the rules, bask in pseudo outlaw rider cache, and an amorphous alternate shadow moral code.

And yet here we have Internet lawyers arguing formal contracts between contractors and suppliers. There's obviously greed involved here somewhere, and someone is being non-hacker-code compliant.

To me the public actions with the most scumminess is defcon: using security guards. Reforming molds. Using the produced badges rather than just paper badges. Thin accusations of malware at a hacker conference.

C'mon, man!

Re: Entropic Engineering DEFCON 32 Statement

#136
post #54

Earlier quoted context omitted.

[flagged]

A hidden screen soliciting donations is certainly in poor taste when you're building a product meant to represent another entity, but "malware"? What is the attack surface on a conference badge that runs a Game Boy emulator?

It’s like someone walking into a random restaurant seeing your food on the counter, taking it to your table then pocketing your tip. You’re “just doing the waiters job for free” and “just soliciting donations” but in reality you are abusing the situation to make the costumer think you’re taking money on behalf of the restaurant when there is no contracted affiliation.

And it’s software injected for financial gain, I can’t why anyone would take issue with calling it malware. A .txt file in the source folder of a game on steam stating “donate to the devs” with a crypto address is also malware. It doesn’t have to be sophisticated to fall under the category.

Re: Entropic Engineering DEFCON 32 Statement

#137
post #72

As per usual nobody comes out of these things looking good. To really understand who is right and who is wrong here we would need to read the letter of the agreements between these entities, and cross reference them with facts. Of course neither the contracts, nor the facts are available to us. As is, the best I can do here is to put all participants on my personal “do not work with” list. Who needs the drama. In par…

The firmware author themselves write[1]: > I was not anybody’s contractor or subcontractor. I’m not employed by entropic nor by you [DEFCON]. I did this in my free time so attendees could have a fun badge. [1] https://old.reddit.com/r/Defcon/comments/1ep00ln/def_cons_re...

This statement seems to be intentionally inaccurate to me. He’s not someone’s contractor, subcontractor or employee, but he still has to have someone he’s communicating with about the project, either at EE, DC or both. Why not state what the situation was? Was he working with EEs team, DC directly or did he switch at some point?

Re: Entropic Engineering DEFCON 32 Statement

#138
post #115
post #110

Who starts an article, especially one questioning responsibility with the lines in the sort of "woman-owned, queer- and POC-driven ... " ?? It's impossible to try to remove the sense of entitlement one gets from this company after that, given the rest of the situation seems to weight in to that way especially given I've heard of procurement of these badges having no such problems before. EDIT: That said, Defcon doesn…

> Who starts an article, especially one questioning responsibility with the lines in the sort of "woman-owned, queer- and POC-driven ... " ?? It's impossible to try to remove the sense of entitlement one gets from this company after that, [...] FWIW, I noticed that line as I read it, but it didn't make me prejudge the situation. I mostly noted it as a potential interesting bit of info that might reflect well on DEFCO…

>that they should know that progressive references can both help and hurt them, due to political polarization?

Why is it "political polarization"?

DC hired an engineering firm based on, at least in part, reasons that have nothing to do with engineering. The project fell apart. Should the procurement process not be questioned, along with selection criteria?

Re: Entropic Engineering DEFCON 32 Statement

#139
post #131

Earlier quoted context omitted.

> undisclosed malware in the FW Lol, its literally just an easter-egg screen. If you see something that benign as malware, you may actually have some in your brain.

Calling something that’s trying to fool people into tipping into a crypto wallet controlled by the person who inserted it an Easter-egg is really stretching it. It’s obviously trying to insert the potential for financial fai into the software which falls well within the definition of malware. Just because the author calls it a joke doesn’t mean it’s suddenly not a serious breach of the confidence placed on them.

How is it trying to fool people? Unless the address on the screen doesn’t belong to EE, it’s not dishonest in any way right? It says the badge was designed by EE and has a donation address, how would that fool anyone? Isn’t it correct?

Re: Entropic Engineering DEFCON 32 Statement

#140
post #136

Earlier quoted context omitted.

A hidden screen soliciting donations is certainly in poor taste when you're building a product meant to represent another entity, but "malware"? What is the attack surface on a conference badge that runs a Game Boy emulator?

It’s like someone walking into a random restaurant seeing your food on the counter, taking it to your table then pocketing your tip. You’re “just doing the waiters job for free” and “just soliciting donations” but in reality you are abusing the situation to make the costumer think you’re taking money on behalf of the restaurant when there is no contracted affiliation. And it’s software injected for financial gain, I…

You think people seeing the screen and donating weren’t aware they weren’t donating to DEFCON but to some other party? Even though it states that on top of the screen?

Also, a non-executable text file can’t be malware because the “ware” stands for software. That’s not malware, that might be social engineering.

Post reply on HN