HeadlinesBriefing favicon HeadlinesBriefing.com

Defcon Badge Doubles as Open-Source Security Key

Ars Technica •
×

This year's Defcon badges feature a removable open-source chip called the Baochip-1x, designed by legendary hardware hacker Andrew "Bunnie" Huang. Unlike traditional opaque chips, the Baochip uses transparent packaging that allows infrared inspection of its internal silicon, enabling researchers to verify its physical structure against published designs. The chip's source code for its operating system, firmware, and cryptographic engines is available on GitHub, making it one of the most transparent security-oriented chips ever created.

The removable core module functions as a standalone hardware security token that attendees can continue using after the conference. It supports FIDO authentication, time-based one-time passwords, and password management, with a low-resolution camera for QR code scanning that prioritizes privacy. The badge also includes LED lights that flash different patterns based on badge type—attendee, speaker, volunteer, or VIP.

The Baochip was manufactured through a partnership with Crossbar, sharing a production run to reduce costs. While some low-level manufacturing elements remain proprietary due to TSMC's 22-nanometer process, Huang emphasizes that the chip represents a significant leap toward verifiable hardware security. The 27,000 badges mark the chip's first major distribution beyond limited development releases.

Defcon founder Jeff Moss selected the badge design to align with this year's theme of 'agency,' emphasizing self-determination through technology. The badges are manufactured on panels nearly a meter on a side, representing a fusion of hacker culture and cutting-edge silicon innovation.