Fireside Chat - The Dark Tangent and National Cyber Director Harry Coker Jr.

The Dark Tangent, Harry Coker Jr.

DEF CON 32 Main Stage · Day 1 · Main Stage

Overview

This Fireside Chat from DEF CON 32 featured a significant dialogue between the hacker community and high-level U.S. government, represented by National Cyber Director Harry Coker Jr., moderated by Jason Healey. The talk, while brief in its provided transcript, served as a crucial introductory address, setting the stage for a deeper engagement between the White House Office of the National Cyber Director (ONCD) and the cybersecurity research community. Director Coker's presence at DEF CON, his first attendance, underscored a notable shift in Washington D.C.'s perception and approach to independent security researchers.

Watch on YouTube

Visual summary for Fireside Chat - The Dark Tangent and National Cyber Director Harry Coker Jr. by The Dark Tangent, Harry Coker Jr.
Visual summary for Fireside Chat - The Dark Tangent and National Cyber Director Harry Coker Jr. by The Dark Tangent, Harry Coker Jr.

Fireside Chat - The Dark Tangent and National Cyber Director Harry Coker Jr.

Speakers: The Dark Tangent; Harry Coker Jr.

Conference: DEF CON 32

YouTube: https://www.youtube.com/watch?v=IUEjbuiAX18

Overview

This Fireside Chat from DEF CON 32 featured a significant dialogue between the hacker community and high-level U.S. government, represented by National Cyber Director Harry Coker Jr., moderated by Jason Healey. The talk, while brief in its provided transcript, served as a crucial introductory address, setting the stage for a deeper engagement between the White House Office of the National Cyber Director (ONCD) and the cybersecurity research community. Director Coker's presence at DEF CON, his first attendance, underscored a notable shift in Washington D.C.'s perception and approach to independent security researchers.

The core message of the session revolved around bridging the historical gap between the government's traditional "build and protect" ethos and the hacker community's "break to make stronger" philosophy. Director Coker articulated a growing recognition within the White House of the invaluable role hackers play in identifying vulnerabilities across critical areas like memory safety, BGP security, firmware vulnerability, and open source software. This engagement signifies a strategic pivot towards leveraging the community's unique insights to enhance national cybersecurity and foster a safer, more secure, and innovative digital landscape.

The talk highlighted the ONCD's proactive initiatives, including a white paper titled "Back to the Building Blocks" focused on memory safety, as tangible evidence of this evolving collaboration. It emphasized that the government is not only learning from but actively seeking to recruit talent from the DEF CON community, signaling a profound cultural transformation in how policymakers view and interact with cybersecurity experts. This interaction at one of the world's most prominent hacker conferences represents a landmark moment for open dialogue and shared responsibility in securing the digital future.

Background

For decades, a significant cultural and operational chasm existed between the U.S. government and the independent cybersecurity research community, often epitomized by events like DEF CON. As moderator Jason Healey highlighted, there was a time "decades ago" when serving on the National Security Council staff meant one "weren't even allowed to come to Defcon." This historical context underscores a period of mutual suspicion and misunderstanding, where the government viewed hacking primarily through a lens of threat and illegality, while the community often perceived government as an outsider, slow to grasp technical realities and sometimes hostile to independent research.

The fundamental disconnect stemmed from differing foundational philosophies. Director Coker eloquently articulated this, noting that society "is predisposed to celebrate builders, inventors, engineers," who are "lauded for what they've designed and constructed." In contrast, the hacker culture "where tinkering is turned toward breaking things, albeit to make them stronger," or "decompiling code to find its weaknesses," or even "manipulating people in the form of social engineering is venerated as a way of finding the weak points in a system," was largely "foreign" to Washington, D.C. Elected officials and civil servants, sworn to "protect and defend the Constitution," found it "far from intuitive how hacking could possibly be in that interest."

However, the proliferation of cyber threats, the increasing reliance on a globally interconnected internet, and the recognition of its "miracle of human ingenuity" but also its inherent need for "protecting," has necessitated a paradigm shift. The establishment of the Office of the National Cyber Director (ONCD) within the White House marks a critical step in this evolution, providing a dedicated entity to coordinate national cybersecurity policy and strategy. Director Coker's personal experiences, collaborating with "reverse engineers" and "colleagues in the intelligence community," led him to challenge the traditional Washington mindset, urging them "to think a bit deeper" and understand that the hacker's desire "to take things apart is rooted in the hope that they will be made stronger." This talk at DEF CON 32 represents a significant milestone in the ONCD's ongoing effort to bridge this historical divide, fostering collaboration and talent acquisition from a community previously viewed with skepticism.

Key Findings

While this segment of the talk primarily served as an introduction and did not delve into specific research findings, Director Coker's remarks highlighted several crucial observations and strategic directions from the perspective of the White House Office of the National Cyber Director (ONCD). These can be considered the "key findings" regarding the current state of government-hacker community relations and national cybersecurity priorities:

  1. Cultural Shift in Washington D.C.: The most significant finding is the explicit acknowledgment of a profound cultural transformation within the U.S. government, particularly in Washington D.C. Director Coker stated, "My voice is not alone in Washington. The chorus is growing." He highlighted that "for the first time, we are seeing policy makers consider how to leverage unique aspects of the security research community to solve some of the very hardest problems in cyber security." This indicates a move away from historical mistrust towards an understanding of the hacker community's value.
  1. Recognition of Hacker Community's Vital Role: Director Coker unequivocally affirmed the importance of the security research community, describing it as "special, but often misunderstood." He emphasized that the community's ethos of "breaking things, albeit to make them stronger" is "important and vital to our way of life" for making the internet a safer place. This represents an official embrace of the community's methodology and purpose.
  1. Government Engagement and Recruitment: The White House is not just acknowledging the community but actively engaging with it. Director Coker noted that "the feds are here in force to learn and to celebrate the work of this community. We are recruiting." This signifies a direct effort to attract talent and integrate the expertise of independent researchers into national cybersecurity efforts, moving beyond mere observation to active participation and talent acquisition.
  1. Strategic Focus on Foundational Technical Issues: The ONCD has identified and is prioritizing fundamental technical challenges critical to national cybersecurity. Director Coker explicitly listed memory safety, BGP security, firmware vulnerability, and open source software as areas for discussion. This indicates a high-level governmental understanding that robust national cybersecurity hinges on addressing these core technical weaknesses, rather than solely focusing on reactive measures.
  1. Endorsement of Technical Solutions (e.g., Memory Safety): A tangible output of the ONCD's new approach is the white paper "Back to the Building Blocks," which focuses on memory safety. Director Coker expressed his surprise and subsequent conviction that it was "vital that the White House shine a spotlight on the need to adopt solutions on the most critical vulnerabilities." The fact that "The White House endorsing formal methods is now a bit of a meme" indicates a successful, albeit perhaps unexpected, penetration of technical concepts into policy discourse, signaling a shift towards promoting secure-by-design principles at a national level.

Technical Deep Dive

While the provided transcript primarily outlined the intent to delve into specific technical topics rather than conducting the deep dive itself, Director Harry Coker Jr.'s explicit mention of memory safety, BGP security, firmware vulnerability, and open source software provides critical insight into the White House Office of the National Cyber Director's (ONCD) strategic priorities for national cybersecurity. These are not merely buzzwords; they represent foundational pillars of modern digital infrastructure, each presenting unique challenges and opportunities for enhanced security.

Memory Safety

Memory safety is a critical concept in cybersecurity, referring to the prevention of programming errors that lead to memory corruption vulnerabilities. These vulnerabilities, such as buffer overflows, use-after-free bugs, and double-free errors, allow attackers to read from or write to arbitrary memory locations, often leading to arbitrary code execution, denial of service, or information disclosure. Languages like C and C++, which offer direct memory access, are particularly susceptible to these issues, and a significant percentage of critical vulnerabilities (often cited as 70% or more by organizations like Microsoft and Google) stem from memory safety flaws.

The ONCD's white paper, "Back to the Building Blocks," specifically highlighting memory safety, underscores the government's recognition of this pervasive problem. The paper likely advocates for the adoption of memory-safe languages such as Rust, Go, Swift, or C# for new development, or the implementation of stringent formal methods and static/dynamic analysis tools for existing C/C++ codebases. This includes leveraging compiler-level protections, runtime sanitizers (e.g., ASan, MSan, UBSan), and secure coding guidelines. The White House's endorsement of such a technical and foundational concept marks a significant policy shift, aiming to address the root causes of a vast category of vulnerabilities rather than merely patching symptoms.

BGP Security

Border Gateway Protocol (BGP) is the routing protocol that makes the internet work, allowing different autonomous systems (ASes) to exchange routing information and direct traffic across the global network. Despite its critical role, BGP was designed decades ago with trust as a fundamental assumption, leading to inherent security weaknesses. These vulnerabilities can be exploited for route hijacking, where an attacker advertises routes for IP prefixes they do not control, diverting traffic through their network (e.g., for eavesdropping or blackholing), or BGP leaks, where internal routing policies are inadvertently propagated globally, causing traffic misdirection.

Securing BGP is a monumental task requiring global coordination. Key initiatives include Resource Public Key Infrastructure (RPKI), a cryptographic framework that allows network operators to vouch for the legitimacy of their routing announcements. RPKI creates digitally signed objects called Route Origin Authorizations (ROAs), which cryptographically bind IP prefixes to the ASes authorized to originate routes for them. Operators can then validate incoming BGP announcements against RPKI data, rejecting invalid routes. The ONCD's interest in BGP security reflects the understanding that the stability and integrity of the internet's routing fabric are paramount for national security and economic stability. Discussions would likely cover the slow but increasing adoption of RPKI, challenges in its deployment, and policy incentives to accelerate its global uptake.

Firmware Vulnerability

Firmware is persistent software programmed into hardware devices, ranging from basic input/output systems (BIOS/UEFI) in computers to embedded systems in IoT devices, network equipment, and industrial control systems. It acts as the intermediary between hardware and the operating system, making it a highly privileged and critical component. Firmware vulnerabilities are particularly insidious because they operate at a layer below the operating system, making them difficult to detect, patch, and remediate. A compromised firmware can provide an attacker with persistent access, bypass OS-level security controls, and even survive reinstallation of the operating system.

The challenges in securing firmware include:

  • Lack of visibility: Many organizations lack tools to inspect or monitor firmware integrity across their entire device fleet.
  • Complex supply chains: Firmware often incorporates components from multiple vendors, creating a complex attack surface.
  • Patching difficulties: Updating firmware can be a delicate process, sometimes requiring specific tools or even physical access, and is often neglected compared to OS or application updates.
  • Persistent threats: Firmware rootkits or bootkits can establish deep, stealthy persistence.

The ONCD's focus on firmware vulnerability highlights the need for robust supply chain security for hardware, secure boot mechanisms (like UEFI Secure Boot), regular firmware integrity checks, and standardized, reliable firmware update processes. This also extends to securing the development and distribution pipelines for firmware.

Open Source Software

Open Source Software (OSS) is ubiquitous, forming the backbone of nearly all modern digital infrastructure, from operating systems (Linux) and web servers (Apache, Nginx) to development tools and cloud platforms. Its collaborative nature fosters innovation and transparency, but also introduces significant security challenges, particularly concerning the supply chain. The reliance on a vast ecosystem of open-source components means that a vulnerability in a single, widely used library (e.g., Log4j, Heartbleed) can have catastrophic downstream effects across countless applications and systems.

Key concerns regarding OSS security include:

  • Vulnerability management: Tracking and patching vulnerabilities in dependent OSS libraries is a continuous challenge.
  • Dependency hell: Projects often have complex dependency trees, making it difficult to ascertain the full scope of their open-source components.
  • Maintenance burden: Many critical OSS projects are maintained by a small number of volunteers, making them susceptible to neglect or targeted attacks.
  • Malicious package injection: Attackers can introduce malicious code into OSS repositories or compromise legitimate packages.

The ONCD's interest reflects a national imperative to enhance the security of the OSS supply chain. This involves promoting initiatives like Software Bill of Materials (SBOMs) to provide transparency into software components, investing in OSS security audits, encouraging secure development practices within OSS communities, and fostering public-private partnerships to support critical open-source projects. The goal is to harness the benefits of OSS while mitigating its inherent risks to national infrastructure.

These four areas collectively represent a comprehensive approach to securing the digital commons, acknowledging that robust national cybersecurity requires attention to foundational technical layers, global internet infrastructure, and the software supply chain.

Demo / Proof of Concept

The provided transcript covers the introductory remarks of the Fireside Chat and does not include any demonstration or proof of concept. Director Harry Coker Jr.'s address was focused on setting the context for the discussion, emphasizing the importance of the hacker community, and outlining the key technical topics (memory safety, BGP security, firmware vulnerability, and open source software) that would be explored during the subsequent conversation. Therefore, no technical demonstration was part of this particular segment of the talk.

Defensive Implications

The White House Office of the National Cyber Director's (ONCD) engagement with the DEF CON community and its explicit focus on foundational technical areas like memory safety, BGP security, firmware vulnerability, and open source software carry significant defensive implications for organizations, developers, and policymakers alike. These implications signal a shift towards proactive, systemic security improvements rather than merely reactive patching.

For software developers and organizations involved in product development, the ONCD's emphasis on memory safety is a clear directive. This means prioritizing the adoption of memory-safe programming languages (e.g., Rust, Go, C#) for new development where possible, thereby intrinsically reducing an entire class of critical vulnerabilities. For legacy codebases in languages like C and C++, it necessitates a deeper investment in advanced security practices, including the use of static and dynamic analysis tools, fuzzing, and rigorous formal verification methods to identify and remediate memory corruption flaws. This approach, advocated by the ONCD's "Back to the Building Blocks" white paper, aims to build security in from the ground up, making systems inherently more resilient.

For network operators and internet service providers (ISPs), the focus on BGP security underscores the urgent need to implement and enforce routing security best practices. The primary defensive measure here is the widespread adoption and validation of Resource Public Key Infrastructure (RPKI). Organizations should generate and maintain valid Route Origin Authorizations (ROAs) for their IP address space and implement BGP route origin validation to filter out illegitimate route announcements. This collective action is crucial to preventing route hijacking and BGP leaks, which can disrupt global internet connectivity and facilitate malicious traffic redirection.

For hardware manufacturers and IT departments managing device fleets, the attention to firmware vulnerability demands a more rigorous approach to device lifecycle security. Defensively, this involves:

  1. Supply Chain Due Diligence: Ensuring that firmware components from third-party suppliers are secure and free from known vulnerabilities.
  2. Secure Boot Implementation: Activating and correctly configuring secure boot mechanisms (e.g., UEFI Secure Boot) to prevent unauthorized firmware or bootloader modifications.
  3. Regular Firmware Updates: Establishing robust processes for timely firmware patching, treating firmware updates with the same criticality as operating system updates.
  4. Firmware Integrity Monitoring: Deploying tools capable of monitoring firmware integrity on devices to detect unauthorized modifications or compromises.

Finally, for all organizations relying on open source software (OSS), the ONCD's focus highlights the need for enhanced software supply chain security. Defensive strategies include:

  1. Software Bill of Materials (SBOMs): Generating and consuming SBOMs to gain comprehensive visibility into all open-source components used in applications and their dependencies.
  2. Vulnerability Management: Implementing automated tools and processes to continuously scan for and track vulnerabilities in open-source dependencies (e.g., using Software Composition Analysis (SCA) tools).
  3. Dependency Hardening: Pinning dependencies to specific versions, regularly auditing critical open-source components, and contributing back to vital projects where possible.
  4. Secure Development Practices: Educating developers on secure coding practices within the context of open-source contributions and consumption.

From a policymaking and governmental perspective, the defensive implications are equally profound. The ONCD's initiative signals a commitment to fostering collaboration with the security research community, recruiting talent, and investing in foundational security research and development. This includes creating policy incentives for industry to adopt secure-by-design principles, supporting the development of secure software tools and practices, and engaging internationally to strengthen global cybersecurity standards and protocols. The government aims to lead by example, encouraging a systemic shift towards a more resilient digital infrastructure across the nation.

Key Takeaways

  • Cultural Transformation in Washington: The U.S. government, particularly the White House Office of the National Cyber Director (ONCD), is undergoing a significant cultural shift, moving from skepticism to active engagement and appreciation for the hacker community's role in strengthening national cybersecurity.
  • Hacker Community as a National Asset: The security research community, with its ethos of "breaking things to make them stronger," is now formally recognized as vital to the nation's effort to make the internet safer, more secure, innovative, and prosperous.
  • ONCD's Focus on Foundational Technical Issues: The ONCD is prioritizing core, systemic cybersecurity challenges, including memory safety, BGP security, firmware vulnerability, and open source software, indicating a strategic shift towards addressing root causes of vulnerabilities.
  • "Back to the Building Blocks" on Memory Safety: The ONCD's white paper, "Back to the Building Blocks," is a key initiative promoting the adoption of memory-safe programming languages and formal methods to reduce a significant class of software vulnerabilities.
  • Government Recruitment from DEF CON: The presence of federal officials at DEF CON to "learn and to celebrate" also includes a direct call for talent, signaling active recruitment from the cybersecurity research community to bolster government cyber capabilities.
  • Bridging the Policy-Technical Divide: The talk exemplifies a concerted effort to bridge the historical gap between policymakers and technical experts, fostering a deeper understanding and collaboration necessary for effective national cybersecurity strategy.

About the Speaker(s)

Jason Healey served as the moderator for this Fireside Chat, bringing a wealth of experience from both the cybersecurity policy and research communities. He has been an active member of the DEF CON review board for approximately 10 years, playing a crucial role in curating the conference's talks. Furthermore, Healey has direct experience within the U.S. government, having served at the White House twice between 2003 and 2005, and was involved in the foundational efforts to establish the Office of the National Cyber Director (ONCD). His background positions him uniquely to facilitate dialogue between these often-disparate worlds.

Harry Coker Jr. currently serves as the National Cyber Director for the United States, a pivotal role in shaping the nation's cybersecurity strategy. This DEF CON 32 appearance marked his first attendance at the renowned hacker conference, a significant event signaling his commitment to engaging directly with the security research community. Director Coker's professional journey includes an early exposure to coding as a computer science graduate student. He has extensive experience collaborating with reverse engineers and colleagues within the intelligence community, which has provided him with a deep appreciation for the specialized skills and perspectives of security researchers. His personal experiences have led him to advocate for a deeper understanding in Washington D.C. of how the hacker community's methodology of "breaking things to make them stronger" ultimately serves the national interest in protecting the internet.

Reviews

Dr. Zero (Offensive Security Researcher) — MUST SEE

This fireside chat, featuring National Cyber Director Harry Coker Jr. at DEF CON 32, represents a monumental shift in how Washington D.C. engages with the cybersecurity research community. Coker's presence, coupled with the explicit acknowledgment of the hacker community's vital role and the ONCD's focus on foundational technical issues like memory safety, BGP security, firmware vulnerability, and open source software, provides critical insider signal. It’s a direct call for collaboration and talent, indicating a genuine, albeit nascent, cultural transformation in national cybersecurity strategy.

Heather Calloway (CISO) — MUST SEE

This fireside chat with National Cyber Director Harry Coker Jr. at DEF CON marks a pivotal moment, signaling a profound cultural and strategic shift within the U.S. government regarding its engagement with the cybersecurity research community. Director Coker's presence and explicit articulation of the White House's intent to leverage hacker insights for critical areas like memory safety, BGP security, firmware, and open-source software demonstrate clear risk ownership at the highest level. This session offers essential context for security leaders, validating foundational security investments and highlighting a national commitment to systemic improvements and talent acquisition.

→ Top-rated talks at DEF CON 32 Main Stage

All talks from DEF CON 32 Main Stage