Counter Deception: Defending Yourself in a World Full of Lies
Tom Cross, Greg Conti
DEF CON 32 Main Stage · Day 1 · Main Stage
Overview
In "Counter Deception: Defending Yourself in a World Full of Lies," Tom Cross and Greg Conti tackle the pervasive and increasingly sophisticated nature of deception in the digital age, particularly within the context of the internet. The talk posits that the internet, initially envisioned as a tool for universal knowledge and human advancement, has instead evolved into a "massive deception engine." This transformation is attributed to fundamental human desires for validation rather than pure knowledge, leading to a "fun house mirror business" where individuals are presented with narratives that reinforce their existing beliefs and biases, often at the expense of truth.

Key moments
- 0:00 Introduction: Internet's promise vs. current deception reality
- 2:00 Users seek validation, not knowledge, on the internet
- 2:30 The internet has become a massive deception engine
- 3:20 Tom Cross introduces himself and his background
- 4:00 Greg Conti introduces himself and his background
- 4:30 Talk agenda: crafting effective deceptions from military doctrine
- 5:00 Talk agenda: deriving counter-deception defense principles
Counter Deception: Defending Yourself in a World Full of Lies
Speakers: Tom Cross, Greg Conti
Conference: DEF CON 32
YouTube: https://www.youtube.com/watch?v=gHqDEMrqTjE
Overview
In "Counter Deception: Defending Yourself in a World Full of Lies," Tom Cross and Greg Conti tackle the pervasive and increasingly sophisticated nature of deception in the digital age, particularly within the context of the internet. The talk posits that the internet, initially envisioned as a tool for universal knowledge and human advancement, has instead evolved into a "massive deception engine." This transformation is attributed to fundamental human desires for validation rather than pure knowledge, leading to a "fun house mirror business" where individuals are presented with narratives that reinforce their existing beliefs and biases, often at the expense of truth.
The speakers, both seasoned experts in information security and operations, frame their discussion by drawing parallels between age-old military deception strategies and contemporary cyber and information warfare tactics. Greg Conti, with his extensive background in military doctrine from West Point, NSA, and US Cyber Command, provides the historical and strategic context for understanding deception. Tom Cross, a long-time Defcon attendee and infosec professional, connects these historical maxims to the modern internet's challenges, from social media narratives to sophisticated malware. The core objective of the talk is to first understand the principles of effective deception, and then, by flipping the coin, derive actionable counter-deception strategies that empower individuals and organizations to navigate this untrustworthy digital landscape.
This talk is particularly relevant in an era defined by information overload, deepfakes, sophisticated phishing campaigns, and state-sponsored disinformation. It underscores the critical need for a robust framework to identify, analyze, and mitigate deceptive practices that permeate every layer of digital interaction, from user-level social media engagement to expert-level malware analysis. By deconstructing the mechanisms of deception, Cross and Conti aim to equip the audience with the intellectual tools necessary to build resilience against the constant barrage of false narratives and malicious manipulations that characterize the modern internet.
Background
▶ Watch: Introduction: Internet's promise vs. current deception reality (0:00)
The genesis of this talk lies in a retrospective reflection on the early days of the internet and Defcon itself. Speakers recall the nascent internet's promise: a world where universal knowledge would be at everyone's fingertips, potentially "upleveling humanity" and fostering greater understanding. Simultaneously, they recognized the inherent perils, such as the creation of extensive behavioral models from electronic payments and data collection, raising concerns about how such information could be exploited. The current reality, however, has diverged significantly from this utopian vision, leaning heavily into the perils.
The fundamental problem, as articulated by the speakers, is that people don't primarily seek knowledge or intellectual growth online; instead, they seek validation. The internet has become a platform where individuals crave confirmation of their existing intelligence, beliefs, and self-worth. This human vulnerability has given rise to what Cross describes as the "fun house mirror business," an industry that crafts personalized narratives showing individuals as "good people," deserving of their desires, and presenting their adversaries in the most negative light possible. This ego-centric worldview is profoundly compelling, making individuals susceptible to manipulation.
Deception itself is not a new phenomenon; it has been a cornerstone of conflict and strategy for millennia. Greg Conti highlights numerous historical examples:
- The Trojan Horse, a classic tale of concealed intent leading to decisive victory.
- The Cuban Missile Crisis, where medium-range ballistic missiles were cunningly concealed within ships, demonstrating strategic camouflage.
- The Persian Gulf War, where Iraqi forces, anticipating a marine attack by sea, were instead surprised by a land invasion from an unexpected direction, a masterful feint.
- The more recent Russia-Ukraine conflict, which saw the emergence of the "Ghost of Kyiv," a mythical ace fighter pilot whose heroic but fabricated exploits served as a powerful morale booster and a successful deception operation.
These historical precedents illustrate that deception's core purpose is consistent: "the act of hiding the truth to get yourself an advantage," influencing a target to make an incorrect decision, or to take (or fail to take) a desired action, all to the deceiver's benefit. What has changed is the scale, speed, and sophistication with which deception can be deployed across the internet, making it an "engine" for propagating false narratives at every level of abstraction. This includes not only social media and political discourse but also the deeply technical domains of cybersecurity, where trust in digital information is paramount.
Key Findings
▶ Watch: The internet has become a massive deception engine (2:30)
The central premise and key finding of the talk, as outlined in the provided transcript, is that an in-depth understanding of offensive deception principles, particularly those honed over centuries in military doctrine, can be directly translated and applied to develop effective counter-deception strategies in the cybersecurity and information warfare domains. The speakers assert that by mastering how to craft effective deceptions, defenders can gain critical insights into how to identify, analyze, and ultimately fight against them.
While the provided transcript primarily sets the stage and outlines this analytical framework, it emphasizes that deception targets are not limited to naive users. It explicitly states that deception can effectively target:
- Humans (Users): Through familiar tactics like phishing, typo squatting, domain mimicry, and spoofed login pages. These methods prey on human trust, inattention, and cognitive biases, leveraging the "fun house mirror" effect to deliver tailored, believable falsehoods.
- Experts (e.g., Malware Analysts): Through more sophisticated, technically oriented deceptions such as false flags, fileless malware, deceptive metadata, code injection, and rotating command and control (C2) infrastructure. These techniques aim to mislead skilled professionals, wasting their time, misdirecting their investigations, or obscuring the true nature and origin of an attack.
The talk's foundational "finding" is thus a methodological one: the path to robust defense against deception lies in an adversarial mindset derived from studying the art of offense. Understanding the psychological, operational, and technical components that make a deception successful—its plausibility, consistency, timeliness, and exploitation of the target's biases—is the first step towards building resilient systems and critical thinking faculties capable of discerning truth from falsehood in a world increasingly saturated with engineered untruths. The talk aims to derive specific counter-deception principles from this understanding, though these specific principles are not detailed within the provided transcript segment.
Technical Deep Dive
▶ Watch: Tom Cross introduces himself and his background (3:20)
While the transcript does not delve into the intricate technical mechanics or code examples of specific exploits, it does highlight various technical deception methods employed in information security, targeting both general users and highly specialized experts. These methods exemplify how digital systems and human-computer interactions are exploited to propagate false narratives and achieve malicious objectives.
For general users, technical deception often manifests through:
- Phishing: This remains a primary vector, leveraging meticulously crafted emails or messages that appear legitimate to trick users into revealing sensitive information or executing malicious actions. The technical aspect involves spoofing sender addresses, embedding malicious links (often shortened or disguised), and designing convincing fake websites.
- Typo Squatting / Domain Mimicry: Attackers register domain names that are slight variations or common misspellings of legitimate sites (e.g.,
micros0ft.cominstead ofmicrosoft.com). Technically, this involves DNS registration and hosting malicious content on these lookalike domains to intercept traffic or trick users into entering credentials. - Spoofed Login Pages: These are fake web pages designed to perfectly mimic legitimate login portals. Technically, they involve replicating the HTML, CSS, and sometimes JavaScript of a genuine site, often hosted on a typo-squatted domain, to capture user credentials entered into the fraudulent form.
For security experts like malware analysts, the deception becomes far more sophisticated, designed to evade detection, attribution, and analysis:
- False Flags: Attackers embed artifacts (e.g., language in code, specific malware characteristics, network indicators) that falsely attribute an attack to a different actor or nation-state. This requires careful engineering of the malicious payload and infrastructure to plant misleading clues.
- Fileless Malware: This type of malware operates entirely in memory, leveraging legitimate system tools and processes (e.g., PowerShell, WMI) rather than dropping files to disk. Technically, it avoids detection by traditional signature-based antivirus solutions and forensic analysis that primarily scan file systems.
- Deceptive Metadata: Attackers manipulate metadata within files (e.g., creation dates, author information, compiler versions) to mislead analysts about the malware's origin, age, or development environment. This requires specific tools to alter file headers and properties.
- Code Injection: This involves inserting malicious code into a running, legitimate process. Techniques range from DLL injection to process hollowing, where a legitimate process's memory space is overwritten with malicious code. The deception lies in the malware masquerading as a trusted process, making it harder to identify through process monitoring.
- Rotating Command and Control (C2) Infrastructure: Attackers frequently change their C2 servers, domains, or communication protocols to evade network-based detection and takedowns. This technical agility involves dynamic DNS, fast flux networks, domain generation algorithms (DGAs), and using legitimate services (e.g., social media, cloud storage) as covert C2 channels. The constant rotation makes it challenging for defenders to blacklist or block communication effectively.
The common thread across all these technical deceptions is the manipulation of information at various layers of abstraction—from the visual representation of a website to the intricate details of a binary's execution—to influence the target's perception and decision-making. The talk implies that understanding the technical underpinnings of these offensive techniques is crucial for developing robust defensive countermeasures, even if the detailed mechanisms are not fully explored in this specific transcript segment.
Demo / Proof of Concept
▶ Watch: Talk agenda: crafting effective deceptions from military doctrine (4:30)
The provided transcript does not contain any mention of a live demonstration, a proof of concept, or any specific tools or code being showcased during the talk. The speakers focus on establishing the conceptual framework for understanding deception and counter-deception, drawing upon historical examples and outlining the types of technical deception observed in modern cybersecurity.
Defensive Implications
▶ Watch: Talk agenda: deriving counter-deception defense principles (5:00)
Understanding the principles of deception, as highlighted by Cross and Conti, provides a crucial foundation for developing effective defensive strategies. While the specific "counter-deception principles" are not detailed in this transcript segment, the discussion of offensive tactics directly implies several defensive postures and considerations for individuals, organizations, and the broader security community.
- Cultivating Critical Thinking and Media Literacy: The "fun house mirror business" thrives on validating existing biases. Defensively, this necessitates promoting critical thinking skills, encouraging individuals to question information sources, and fostering media literacy. This includes verifying claims, cross-referencing information from diverse and credible outlets, and recognizing psychological manipulation tactics embedded in narratives. For organizations, this translates into robust security awareness training that goes beyond simply clicking on links, focusing on the psychological aspects of social engineering.
- Enhanced User Education Against Social Engineering: Given the prevalence of phishing, typo squatting, and spoofed login pages, continuous and updated user education is paramount. This education should not only highlight the technical indicators of deception (e.g., suspicious URLs, email headers) but also the psychological triggers attackers exploit (e.g., urgency, authority, fear, validation). Simulating phishing attacks and providing immediate feedback can significantly improve user vigilance.
- Advanced Detection and Analysis for Experts: For security analysts and incident responders, the focus must be on detecting and analyzing sophisticated technical deceptions:
- Anti-Forensics and Evasion Techniques: Defenders need to be aware of false flags, deceptive metadata, and fileless malware. This requires moving beyond signature-based detection to behavioral analysis, memory forensics, and understanding the attacker's intent to mislead. Tools that analyze process injection, inspect memory regions for hidden code, and track process lineage are vital.
- C2 Infrastructure Resilience: To counter rotating C2 infrastructure, defenders must implement proactive threat intelligence, monitor network traffic for anomalous patterns (even to legitimate services), and use egress filtering to restrict unauthorized outbound connections. Employing network traffic analysis (NTA) and Security Information and Event Management (SIEM) systems capable of correlating diverse logs can help identify evolving C2 patterns.
- Attribution Challenges: The use of false flags means that initial attribution should always be treated with skepticism. Defensive teams should focus on verifiable technical indicators and behavioral patterns rather than easily manipulated artifacts, employing the concept of "assume breach" and focusing on containment and eradication regardless of the apparent origin.
- Adopting an Adversarial Mindset: The core insight from military doctrine is that understanding the adversary's intent and methods is key to defense. Security teams should proactively study common deception techniques, conduct red teaming exercises that incorporate sophisticated social engineering and technical camouflage, and continuously update their threat models based on evolving deceptive practices. This involves thinking like an attacker to anticipate their moves.
- Building Trustworthy Information Ecosystems: At a broader level, the pervasive nature of internet deception calls for efforts to rebuild trust in digital information. Projects like Tom Cross's Feed Seer, which aggregates news and community commentary on Mastodon, exemplify attempts to create more transparent and context-rich information environments, helping users discern what "people are saying about each link" and potentially identify coordinated deception campaigns.
In essence, the defensive implications revolve around building resilience through awareness, education, and technical sophistication. By recognizing that deception is a deliberate act designed to influence decision-making, defenders can shift from a reactive stance to a more proactive, intelligence-driven approach, actively seeking out and neutralizing the "lies" that pervade the digital landscape.
Key Takeaways
- The internet, despite its initial promise, has become a "massive deception engine" that often prioritizes ego validation over genuine knowledge.
- Deception is an ancient strategy, extensively refined in military doctrine, aiming to influence a target's decisions for an advantage.
- Modern deception techniques target both general users (e.g., phishing, typo squatting) and security experts (e.g., fileless malware, false flags, rotating C2).
- Understanding the offensive principles and mechanisms of deception is crucial for developing effective counter-deception strategies.
- Defenders must cultivate critical thinking, enhance user education, and employ advanced technical analysis to combat sophisticated digital deceptions.
About the Speaker(s)
Tom Cross is a long-time attendee of Defcon, having been part of the community since its early days. He has a career rooted in information security and has frequently spoken at various conferences on infosec topics. Tom is also involved in social media projects, including his current endeavor, Feed Seer, a news reader application for Mastodon. This app curates the top links posted on a user's feed over the past 24 hours and displays community commentary surrounding each link, aiming to provide context and insight.
Greg Conti brings a deep and extensive background in military and cyber security. He served as a long-term faculty member at West Point, where he directed their cyber security research and education programs. His experience also includes working at the National Security Agency (NSA) twice and the US Cyber Command twice. Greg has developed and taught the "Information Operations" course at Black Hat training for seven years and has also run the "Military Strategy and Tactics for Cyber Security" course for a decade. Together, Tom Cross and Greg Conti also teach a class on "Adversarial Thinking" at Defcon training.
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
Cross and Conti deliver a brutally honest assessment of the internet as a 'deception engine,' leveraging deep historical military doctrine to construct a robust framework for understanding and countering modern information warfare. The talk, while lacking a live technical demo, provides immense conceptual depth and actionable insights for anyone serious about defense in a world saturated with engineered falsehoods. Their expertise is undeniable, and the strategic reframing of deception is highly valuable.
Heather Calloway (CISO) — STRONG ACCEPT
Cross and Conti deliver a highly relevant talk on counter-deception, framing the internet as a potent engine of manipulation and drawing critical parallels to military strategy. Their central premise—that understanding offensive deception is paramount to building effective defenses—resonates deeply. While the provided text outlines the conceptual framework and implications rather than specific counter-deception principles, it offers valuable strategic insights for security leaders and operational teams grappling with an increasingly untrustworthy digital landscape.