The Two Types of Fool – Generations in Cybersecurity
Casey John Ellis
BSides Las Vegas 2025 · Day 1
Overview
Casey Ellis delivers a reflective keynote on generational knowledge transfer in cybersecurity, anchored by a thesis borrowed from John Brunner’s novel The Shockwave Rider: there are two kinds of fools—one who says “this is old, therefore good,” and another who says “this is new, therefore better.” Ellis argues both extremes fail; truth sits in the middle. The talk weaves personal medical trauma, community sociology, entrepreneurship, and geopolitical threat trends into a single argument: defenders succeed when wisdom and knowledge move across age cohorts and subcultures faster than attackers innovate alone.

Key moments
- 2:00 Disclose.io mission: safer good-faith hacking; CFAA/DOJ guidance mentioned.
- 4:00 Personal medical story: valve failure, ~20% heart function, surgeries, recovery months.
- 6:00 Two kinds of fools thesis; BSides bounty hunters now founders—generational handoff.
- 8:00 Hybrid conflict, post-2020 opportunistic spraying, LLMs lowering attacker skill bar.
- 12:00 Alice metaphor: humility (get small) vs leadership (get big) as complementary.
- 14:00 Community as strategic asset; diversity counters collaborative adversaries.
- 16:00 Gratitude as force multiplier; Josh quote on public-good work over long timelines.
- 22:00 Roblox/crime recruitment diversion via mentorship; BSides proving ground value.
The Two Types of Fool – Generations in Cybersecurity
Speakers: Casey Ellis, Founder, Bugcrowd; Co-founder, Disclose.io (additional roles described below)
Conference: BSides Las Vegas
YouTube: https://www.youtube.com/watch?v=TN-HewAJDgY
Overview
Casey Ellis delivers a reflective keynote on generational knowledge transfer in cybersecurity, anchored by a thesis borrowed from John Brunner’s novel The Shockwave Rider: there are two kinds of fools—one who says “this is old, therefore good,” and another who says “this is new, therefore better.” Ellis argues both extremes fail; truth sits in the middle. The talk weaves personal medical trauma, community sociology, entrepreneurship, and geopolitical threat trends into a single argument: defenders succeed when wisdom and knowledge move across age cohorts and subcultures faster than attackers innovate alone.
The session is explicitly not a tool tutorial. It is a culture-and-strategy talk aimed at BSides attendees, praising the Las Vegas community’s default norms—mentorship, curiosity, and mutual respect—while urging the same behaviors outside conference walls.
Background
▶ Watch: Disclose.io mission: safer good-faith hacking; CFAA/DOJ guidance mentioned. (2:00)
Speaker identity and work
Ellis introduces himself as best known for founding Bugcrowd and co-founding the Disclose.io project, with additional involvement in angel investing and policy. Bugcrowd is described as pioneering intermediation between security researchers and organizations needing defensive insight—positioned as scaling a market that disrupts offense/defense economics. Disclose.io is framed as improving the legal and policy environment for good-faith hacking, including influence on CFAA-related DOJ charging guidance (as claimed in talk) and international policy threads.
Personal context: Ellis identifies as Australian and living in San Francisco, California.
Medical context and vulnerability of practitioners
Ellis discloses a serious heart valve issue discovered after ignoring symptoms, with heart function described as operating at roughly 20% capacity for perhaps one to two years, leading to open-heart surgery and, about a month later (during BSides season), a complication requiring another operation—totaling roughly three and a half months of recovery. He credits community and family support, emphasizes listening to one’s body, and warns that “adrenaline is not a great diet” for security professionals prone to heroic overwork.
Key Findings
▶ Watch: Two kinds of fools thesis; BSides bounty hunters now founders—generational ha... (6:00)
Generations as a security supply chain
Ellis uses a dinner photo from Mandalay Bay with early Bugcrowd bounty hunters who later founded companies employing others—an anecdotal but concrete illustration of mentorship → entrepreneurship → re-mentorship loops. He describes younger researchers teaching him techniques that feel native to them but foreign to his generational baseline, and reciprocally sharing lessons from his entrepreneurial path.
Why cross-generational transfer is urgent
Two arguments intertwine:
- Technical permanence vs novelty: “Packet rat” knowledge still matters because the internet still runs on low-level primitives even as attention moves up-stack to business logic abstractions.
- Hybrid conflict and blended threat actors: Ellis cites a “new normal” of hybrid conflict, accelerating threats, nation-state opportunistic spraying intensifying since 2020, and LLM/agentic tools lowering the bar below traditional Metasploit-level skill for “good enough” impactful attacks.
Community as strategic defense asset
Ellis argues diversity and collaboration across tribes mirror adversary collaboration; collective creativity is positioned as a counterweight. The hashtag phrase “it takes the crowd” ties to Bugcrowd’s origin story but is presented as a broader belief about peer learning.
Practical cultural tools
Humility vs leadership framed through Alice in Wonderland resizing: know your strengths, seek help elsewhere; sometimes leadership means being the person who says “this problem should not exist” and starting momentum (Bugcrowd origin story). Curiosity vs ego: ego can drive execution but can also crush others’ ideas; balance preserves collective brilliance.
Gratitude is argued as a force multiplier—compatible with continued push for change, not apathy. A Josh quote (first name only in transcript) summarizes a career arc: on a long enough timeline, many practitioners do work for the public good. Ellis connects this to growth in policy participation (DEF CON policy village attendance exploding by 2022) and entrepreneurship support networks.
Youth recruitment and crime diversion
Ellis references companies like “the hacking games” working to divert Gen Z / Gen Alpha from cybercrime recruitment happening via Roblox, likened in metaphor to older drug mule dynamics—online analogues pulling youth toward crime. Mitigation includes mentorship from people with legal scars from hacking the wrong targets.
Closing generational “job roles”
Ellis summarizes:
- Younger generations: inherit the mess; capable of solving hard problems; do not let cynics diminish that.
- Middle generations: “connectors” who integrate practices across cohorts (Ellis self-identifies here loosely).
- Older generations: “not done yet”; two ears, one mouth; remain available to mentor while learning upward.
“Old man’s strength” and embodied credibility
Ellis uses Lewis Carroll’s Father William (prompted by audience) as a metaphor for older practitioners demonstrating continued vitality—standing on one’s head to prove the body still works. He ties this to roughhousing with his growing son and recovering from surgery: physical frailty and determined capability can coexist. The practical message for teams is that seniority should not be confused with obsolescence—experienced engineers may need different workflows, but can still anchor incidents, architecture reviews, and crisis leadership.
For younger practitioners, the same section is framed as encouragement: your seniors may look tired, but they can still “get it done” when it matters—and you will inherit both their strengths and their blind spots.
Policy participation as a scaling mechanism
Beyond Bugcrowd’s commercial lane, Ellis celebrates the expansion of policy engagement—walking into a DEF CON policy room in 2022 and not recognizing most attendees, which he interprets as healthy growth. The talk positions hackers on the hill-style participation as a force multiplier that converts individual bug findings into durable rule changes. Organizations that support employee civic time (within ethics rules) may see indirect benefits: clearer disclosure norms reduce ad hoc crisis lawyering after each bug drama.
Technical Deep Dive
▶ Watch: Alice metaphor: humility (get small) vs leadership (get big) as complementary. (12:00)
This talk does not propose a new exploit class or defensive control stack. Its closest “technical” content is strategic: acknowledging low-level internet mechanics remain relevant while AI tools compress attacker skill prerequisites. That framing matters for workforce planning—teams that only hire “full-stack app hackers” may still need infrastructure and protocol depth for certain threat models.
The policy thread references CFAA charging guidance changes at DOJ—listeners should verify current legal context independently; the talk is advocacy-flavored summary, not legal advice.
Translating culture talk into staffing and capability models
If you squint, Ellis is arguing for an S-curve of skills across tenure: junior talent brings velocity and comfort with new platforms; mid-level staff integrate controls with delivery pressure; senior staff supply judgment under uncertainty. Security organizations that optimize only for certifications or toolchains may accidentally delete the middle connective tissue—precisely the cohort he names as most responsible for glue work between generations.
For SOC and IR, the implication is documentation and playbooks must be mentorship-aware: not only “what to run,” but “why we ever thought this was normal,” because incident reasoning often depends on institutional memory that is not captured in tickets.
Demo / Proof of Concept
▶ Watch: Community as strategic asset; diversity counters collaborative adversaries. (14:00)
No technical demo; the “proof” is narrative—photos, community examples, personal medical story, and references to conference culture moments.
Defensive Implications
▶ Watch: Roblox/crime recruitment diversion via mentorship; BSides proving ground value. (22:00)
- Mentorship programs: formalize cross-level pairing inside enterprises, not only at cons.
- Hiring: value baseline infrastructure literacy even as AI copilots rise; packet-era knowledge still pays rent.
- Threat modeling: assume lower-skill high-impact attacks because LLM tooling commoditizes scaffolding for campaigns.
- Community investment: sponsor BSides, CTFs, and safe harbor disclosure ecosystems—Ellis argues these are strategic, not charitable.
- Wellbeing: operationalize checks for burnout and medical neglect; resilience is a security variable when key people drop offline.
- Public-good pathways: channel skilled folks toward policy and entrepreneurship support structures to scale fixes beyond single-company boundaries.
Organizational design notes (inferred carefully from the talk’s claims)
Ellis does not prescribe an HR policy, but his Roblox/crime diversion example supports internship and early-career pipelines that compete on excitement with criminal gigs—capture-the-flag leagues, paid research apprenticeships, and mentor access. For vendor ecosystems, bug bounty platforms implicitly appear as market infrastructure that converts gray-hat energy into accountable work—whether or not one uses Bugcrowd specifically, the economic point stands: make legitimate paths fast, fair, and lucid legally.
Gratitude as a cultural norm is framed as compatible with demanding improvement. For managers, that suggests recognition systems and post-incident reviews that credit trying as well as winning—not to lower standards, but to prevent learned helplessness when defenses fail under advanced adversaries.
Key Takeaways
- Reject false dichotomies: neither uncritical traditionalism nor uncritical novelty serves defense.
- Knowledge transfer across generations reduces wheel reinvention—a luxury defenders no longer have.
- Hybrid threats and AI-lowered attacker floors increase pressure to collaborate across tribes.
- Humility and leadership are complementary postures for starting and scaling change.
- Gratitude and public-good engagement are presented as multipliers, not soft distractions.
- Health and community care are framed as existential enablers for sustained defensive work.
About the Speaker(s)
Casey Ellis describes himself as founder of Bugcrowd, co-founder of Disclose.io, involved in angel investing and policy, Australian-born and residing in San Francisco. He references standing in for Carl at prior talks during medical recovery. Additional titles or current corporate roles beyond those stated in the talk are unknown from the transcript excerpt.
Reviews
Dr. Zero (Offensive Security Researcher) — SOLID
A heartfelt community keynote with sharp cultural diagnosis (generational arrogance traps, hybrid threats, AI lowering bars) wrapped in personal stakes. Light on technical novelty—this is morale, sociology, and strategy—not new payloads.
Heather Calloway (CISO) — SOLID
Useful for leadership culture and workforce resilience: mentorship, knowledge continuity, and wellbeing are operational inputs to security outcomes. Light on institutional controls, metrics, or program design—pair with HR and talent strategy rather than treating it as a VM playbook.