jawn (noun) : used to refer to a thing, place, person, or event that one need not or cannot give a specific name to.
October 16-18, 2026
Arcadia University in the Commons Building

Friday Main Stage | Friday Track 2 | Saturday Main Stage | Saturday Track 2 | Saturday HAM | Sunday Main Stage | Sunday Track 2

Main Stage - Friday
Opening Remarks 9:15 AM
Friday
Information about what all ya'll Jawn are about to experience!
Russell Handorf
Keynote 10:00 AM
Friday
It's Matt; you'll like this!
Dr. Matt Blaze
THE WHITE HAT HACKER AND THE COMPUTER FRAUD AND ABUSE ACT 11:00 Friday
The Computer Fraud and Abuse Act (CFAA) was first passed by Congress in 1986. It has been amended many times, expanding its coverage and adapting to the rapidly changing world of computing. Originally, all "hackers" were white hats - people interested in exploring the workings of computers and networks. Computers have increased in speed and power, and the Internet has changed from a military communications network into what it is today since the Act was passed. With those developments, some hackers saw opportunities for profit or malicious damage, creating the divide between white hats and black hats (with a few in between). The CFAA is properly applied to the black hats. But large questions remain about white hats and the CFAA. The CFAA outlaws unauthorized access and unauthorized damage to computers. Both the courts and the U.S. Department of Justice have taken steps interpreting these phrases that may help white-hat hackers. My talk will discuss the path to where we are today.
MICHAEL LEVY
AI Governance - There's so many standards!! What should I use??? 13:00 Friday
You're using AI. You are, whether or not anybody approved it. So when it leaks your data, misleads a customer, or acts in your name, who's accountable? A pile of AI governance standards claims to answer that: some are law, some are risk frameworks, some are self-graded homework, and a few still haven't noticed that agents exist. This talk cuts through them: which one is actually pointed at you, which are theater, and the gaps every one of them leaves open. Certified, accredited, self-assessed, or none of the above, come find out which you actually need.
Joshua Marpet
Screen To Table: How Board Games Cured My Digital Fatigue 14:00 Friday
The COVID lockdown of 2020 made me realize just how much of my life was in front of a screen: playing on my phone, working on my computer, and watching TV. The world of board games helped me appreciate how important real interactivity, connection, and communication truly are, as well as the near-endless variety of themes, mechanisms, puzzles, complexities, and types of games available. If you're feeling stuck in a digital landscape or looking for a new challenge that doesn't require power, join me at the table and let's play!
Mike D'Amelio
ham for hackers 14:30 Friday
Software-Defined Radios (SDRs) like the RTL-SDR and HackRF have made radio frequency sniffing a staple of the hacker toolkit. However, most security researchers stop at passive reception or low-power ISM-band experimentation. Why limit your RF exploration to milliwatts and 2.4 GHz noise when an Amateur (Ham) Radio license unlocks up to 1,500 Watts of transmitting power, gigahertz of dedicated spectrum, and the legal freedom to build and test custom wireless hardware?
Ed Wilson
Threat Intel is Mutual Aid: Building a People-First Sharing Network 15:00 Friday
IFIN, the Independent Federated Intelligence Network, is a new nonprofit dedicated to sharing the knowledge of how to collect, analyze, and employ threat intelligence. In this talk, we'll share our origin story, how we're building a network of people that protects each other and the internet more broadly, and how you can get involved.
Michael Taggart
Still Possible: Land a Cybersec Job in the AI Era 16:00 Friday
Look, the cybersec job market is rough right now. Everyone's telling you it's impossible to break in, the entry-level jobs all want five years of experience, and AI is going to take the whole field anyway. But hold on, we still need good people.
I've been doing this for 30 years - hired people, let people go, watched people make it from some genuinely weird starting points. Photographers. Librarians. Kids straight out of high school. None of them had a perfect resume. All of them had their head right and knew what to actually work on.
This is the talk nobody gave me when I was starting out. As a hiring manager in cybersec, I'll tell you what we're actually checking for, including how I structure interviews. We'll also get into what's really happening with AI in this field and what you should be doing that will matter.
Raymond Pompon
Track 2 - Friday
A Boot to the Head: Cybersecurity Learned from the Mosh Pit and how to use them before the world goes completely to hell 13:00 Friday
The mosh pit doesn't lie.
It strips away titles, org charts, and polished LinkedIn summaries. What you're left with is raw signal: who picks you up when you go down, who sees you fall and keeps dancing, who's there to release energy together - and who showed up to hurt people.
George Sandford spent formative years in the Philadelphia hardcore and punk scene - the Trocadero, TLA, basement shows where the crowd was the security model. Philly crowds have a reputation for being intense, unforgiving, and a little chaotic. They're also fiercely loyal, deeply communal, and genuinely dangerous when threatened. Turns out that's a pretty good template for a security team.
We're past the warm-up now. Nation-state actors aren't pretending. AI is accelerating attacks while quietly automating away defenders. Monocultures - on teams, in tooling, in thinking - are dying fast. And the people who were supposed to keep things safe? Some are gone. Some are the problem.
This isn't a metaphor. It's operational.
This talk translates hard-won pit survival skills into concrete team-building and leadership practice: how to build teams that absorb impact without breaking, how to identify and eject bad actors before they consolidate influence, how to protect your most vulnerable people when the environment turns hostile, and how to maintain function - and humanity - when trust is fractured and institutions have failed.
Community isn't networking. It's mutual defense. Diversity isn't a checkbox. It's operational resilience. Picking each other up isn't charity. It's infrastructure.
You'll leave with real frameworks, not inspiration porn. Come ready to work. Leave with scars and skills.
Because sitting this one out was never an option.
George Sandford
How to make a Cyber Dragon 14:00 Friday
By popular request - a talk on how to make your very own polygonal light-up dragon head mask! This will be broken into a talk + workshop. As a full build would take much longer than can be done during a workshop, the workshop portion will focus on Soldering 101 - making the lighting rig for the head itself.
Gary Cohn
Hacker Public Radio - why you should listen, and contribute. 15:15 Friday
Hacker Public Radio is a community podcast that runs 5 days a week. It is dedicated to sharing knowledge and has been running in various forms for nearly 20 years. Anyone that has anything that is of interest to hackers is welcome to submit a show.
murph nj
From Game Hacking to eCrime (feat. Meccha Chameleon & CSGO) 16:00 Friday
The overlap between game hacking communities and eCrime groups has never been more prevalent, with the emergence of stolen account marketplaces and game hacking communities that rely on stolen accounts to continue cheat development efforts and cheating communities that also utilize these accounts for play, which are typically compromised through phishing, infostealers, or other account takeover methods, such as sim swapping. This talk will dive into the overlap between the two groups and the pipeline that escalates from cheating and gaming platform account takeover to crypto theft and physical violence.
John Moutos
Main Stage - Saturday
AI Security Myths We Can Finally Stop Repeating 10:00 Saturday
Artificial Intelligence has become cybersecurity's latest hype cycle. Vendors promise revolutionary protection, headlines predict catastrophic attacks, and organizations struggle to distinguish genuine threats from marketing-driven fear, uncertainty, and doubt.

This presentation examines some of the most common AI security myths and compares them to real-world capabilities and risks. Drawing on decades of experience observing security trends, Space Rogue explores claims that AI can autonomously hack organizations, replace security analysts, and fundamentally change the rules of cybersecurity.

Attendees will learn where AI genuinely increases risk, such as data leakage, overprivileged AI agents, and automation bias, and where traditional security fundamentals remain the most effective defense. The session will also examine how defenders can leverage AI for detection, investigation, and operational efficiency without falling victim to unrealistic expectations.
Space Rogue
When Responsible Disclosure Fails: A Collaborative Framework for Zero-Day Reporting 11:00 Saturday
Traditional responsible disclosure can become a black hole when vulnerability reports disappear into unresponsive or ineffective channels. Rather than treating vendor notification as the end of the researcher's responsibility, this talk explores a collaborative model in which trusted, ethical researchers work together to understand and address security problems while vendor notification occurs in tandem.
Christy Caraballo, William Entriken
Breaking PBKDF and Java Encryption - Adversarial Cryptanalysis and Techniques 13:00 Saturday
Breaking encryption isn't hard-it's just taught poorly.

Using decades-old OpenJDK PBKDF flaws, forgotten RFCs, hash collisions, and a few semantic edge cases, we'll compromise multiple cryptographic systems with little more than a handful of carefully chosen values and several "useless" tools.

This talk explores how implementation bugs, legacy compatibility, and architectural assumptions can undermine otherwise sound cryptography-and why the real attack surface is often everything around the algorithm.
Ken Pyle
Bringing your product to market - "just the highlights" 14:00 Saturday
"I have a great idea, I should be able to make money with this, what do I do next?" This community is full of ideas and tends to be very skilled in bringing technology to life at "project size". This talk will hit the highlights of the things that need to be considered to monetize your project as a business venture. We'll hit the big rocks on what goes into a business plan that will let you seek investment, how to forecast demand and revenue, and figure out ROI. We'll hit the major considerations around supply chain, warehousing, and logistics. Most importantly we'll talk about what role you need to play in your business and why a visionary isn't always "CEO".

The goal here isn't a full business course, it's an intro to get you thinking about what you need to know, and what steps you'd need to take.
Jonathan Spangenberg
Veilid: The Private Internet we were all promised 14:30 Saturday
The Cult Of The Dead Cow (cDc) is breaking the internet with Veilid, an open-source, peer to peer, mobile-first, network application framework. Veilid goes above and beyond existing privacy technologies and has the potential to completely change the way people use the Internet. Veilid has no profit motive, which puts it in a unique position to promote ideals without the compromise of capitalism. With Veilid, the user is in control, in a way that is approachable and friendly, regardless of technical ability.

This framework shares some similarities with IPFS and Tor in its overall design, but it is built to deliver better performance while natively supporting all services through a privately routed network. It allows developers to create fully decentralized applications without depending on a blockchain or transaction-processing layer as the foundation. The framework can either be integrated directly into end-user applications or operated as a standalone headless node by advanced users who want to contribute resources and help strengthen the network. Thousands have already joined the Veilid network, integrating it into their daily lives and building privacy-focused projects on top of it.

Together, we can give the world the private Internet we should have had all along.
Bianca Lewis
It Takes A Hardware Village - The making of the Whose Slide Is It Anyway DEF CON badge 15:00 Saturday
Ultimately, this is a talk about community. No google search, no datasheet, nor any number of AI prompts can match the criticality of being able to lean on a community of makers all hell bent on conquering code and electricity. To get from prototype to PCB, it truly takes a hardware village.

To build or not to build? Well, after the first time you make an LED go blink, that isn't even a question. Things escalate exponentially after that first hardware success. It took me 6 months from the first time I really dove into a kit from HackerBoxes.com, fumbling the entire way, to creating my first ever badge for the 10 year anniversary for my Whose Slide Is It Anyway contest at DEF CON 34.

This talk begins at the beginning, from re-learning how to solder a single pin, to staring at a KiCad screen questioning any positive thing my mother ever told people about me. I will lay bare every failure that led to every success in the goal of putting some bling around the necks of our contestants.
Danny Akacki
LUA before Lua: The Recovered Works of Louise Ursula Albright (Apple //e, 1987) 16:00 Saturday
In early 2021, an Apple 10MB ProFile hard drive surfaced at an auction and passed, months later, into a pile of Apple //e equipment inherited by the presenter - who built recovery hardware for it (publicly documented at the time) without understanding what he had. Five years on, a close reading of the recovered ProDOS volume revealed the complete working environment of Louise Ursula Albright (b 1938-?), a Chippewa Falls, Wisconsin high-school mathematics teacher who, in 1987, appears to have accomplished something the historical record insists did not happen: a self-hosting dynamic language "LUA" on the Apple //e, six years before "Lua" existed. Her initials, inked as a file extension, explain the system's name; the coincidence of 1993 is a matter this presentation declines to litigate.

The recovered volume holds a 10KB bytecode VM in Merlin-8 assembly; a 20KB compiler written in its own language and compiled by itself; and - most precious! - the bootstrap ladder by which one person climbed from "no compiler exists" to "the compiler compiles itself," using nothing but Merlin-8 2.58 and a RamWorks 1MB card. We will perform the recovered works on period instruments: Merlin will assemble the VM byte-for-byte before your eyes; the machine will compile its own compiler.

In the tradition of Prof. Peter Schickele's researches into P.D.Q. Bach: the history is invented and the presenter admits it cheerfully. But every artifact shown is real. Every demonstration runs on real period hardware. The fiction is the story, but the engineering is real.
Jorj Bauer
Track 2 - Saturday
Everyday Flipper, from TVs to Trackers: Basic Tasks for That Flipper Zero You Bought But Rarely Touched 10:00 Saturday
A few years ago, the Flipper Zero was popularised as the "Swiss Army Knife" of wireless hacking tools. It lit all the influencer channels on fire and got itself banned in hotels and countries worldwide. Some even accused it of stealing your car and cloning your credit cards. It really can't do those... at least not on its own. You probably bought one to see what the talk was all about. Nowadays we rarely see it in the news, channels, or socials. We rarely see it in our hands or causing mayhem at local stores too. That may be due to the Flipper Zero's bad rep as a hacking tool only, and not a useful addition to a household toolbox. We'll cover what the Flipper Zero does with real-world and useful examples. We might even do a bit of "hacking", but nothing that will get you arrested or kicked out of a restaurant (no promises). Bring your own to join in the hands-on activities, or just sit back and take some notes. A laptop and USB cable to link it with your Flipper would be helpful too.
Grey Fox
APT, Meet OPSEC: Turning Mistakes into Intelligence 13:00 Saturday
Threat reports frequently highlight the sophisticated attacks conducted by advanced persistent threats (APTs), but far less attention is given to their OPSEC failures. These mistakes can be leveraged to gain valuable intelligence and give the security community an upper hand. This talk will cover a handful of real-life OPSEC failures, the intelligence they revealed, and the skills and platforms required to turn adversary mistakes into actionable intelligence.
0XFFaraday
Identity All The Way Down 14:00 Saturday
When you think of "exciting topics in security", rarely do you think about identity. But identity underpins nearly every other activity that we as security professionals undertake. It is, arguably, THE hard problem in security with aspects that you have likely never thought of before. Come explore some of the rarely visited corners of identity so that you, too, can start seeing identity everywhere you look!
Amanda Draeger
Pushing the Limits of Static Sites 14:30 Saturday
Most everybody has heard of static site generation at this point. Typically first thought of as a mechanism to generate documentation sites for github with Jekyll, we found another use case: online historical collections. It's not just markdown and it's not just text. The web browser is an immensely powerful system, and nearly every feature we had could be replaced by in browser capabilities.

But what of the things that can't be done in browser? Does it have to be a web connection connected to a fully empowered dynamic back end, or could we build something more robust and basic?
Jeff Goeke-Smith
Power Without Binaries: Bringing Native Offensive Techniques to Fileless Runtimes 15:00 Saturday
Advanced stealth tradecraft, including syscall dispatching, unmanaged memory access, and runtime evasion, is typically designed for compiled binaries. This talk explores what happens when those traditionally native capabilities are translated into a fileless runtime.

PowerShell was chosen as the target runtime because it is broadly available in Windows environments and exposes surprisingly low-level .NET and unmanaged functionality while often remaining enabled in enterprise settings.

Rather than treating PowerShell as "just an automation tool," this research asks how far a fileless scripting runtime can be pushed toward native offensive capability development. I will walk through the technical implementation realities including AMSI, CLR behavior, modern AV/EDR visibility, and where AI-assisted workflows accelerated difficult interoperability and translation challenges.

Through a progression of working and failed implementations for a fileless process injector, attendees will see how traditionally native tradecraft evolves from standard C and ASM to WinAPI, NTAPI, direct syscalls, and indirect syscalls performed entirely within PowerShell. Techniques discussed include P/Invoke, marshalling, unmanaged invocation, shellcode loading, process injection, NTDLL parsing, and syscall strategies within a fileless context.

A pre-recorded POC demonstration will show the resulting framework successfully operating in a fileless execution model to perform process injection. This will be followed by a discussion of observability, detection opportunities, and defensive implications. The framework will be publicly available at the time of the talk.

For defenders, this talk highlights meaningful opportunities for telemetry, detection engineering, and defensive prioritization.
Jacob Covey
Taking Back Control of Your Digital Music: Revive Your MP3 Players with Rockbox 16:00 Saturday
In today's digital world, people have become enthralled and ensnared in digital music services that claim user freedom and user control are anything but, and with services like Spotify, Amazon Music, and Apple Music, among others, getting worse with user freedom and user control of our own music libraries, things may look bleak, but there are ways of taking back control of our music and our lives. With the revival of offline music and physical media, we need a solution for our old MP3 players and breaking the old ecosystems they were tied to. The free software jukebox software Rockbox offers that freedom. This talk will cover what Rockbox is and how we can use it to gain digital freedom for our old devices, and also cover digital sovereignty and reclaiming our old tech.
Robert Menes
Main Stage - Sunday
Wardriving AI 10:00 Sunday
This talk discusses both the value and shortcomings of using AI to aid OSINT analysis. It details the results of an experiment designed to pressure test the analytical capabilities of three frontier LLMs using open-source telecommunications data.
Victoria Whitaker
Paging in 2026 - From current carriers to OSS and hobbyist networks 10:30 Sunday
While pagers once ruled the '90s, these communications devices have generally fallen out of favor with the popularity of cell phones and text messaging. Pagers are still used by many people today, and the technology and infrastructure to run it is still there, but aspiring individuals can also make use of the underlying protocols and vintage equipment to create and operate paging implementations or build small sites for their own or existing projects.

This talk will cover the current landscape of paging, an overview of the protocols, provider consolidation and current support, security considerations and attack vectors, and how alphanumeric paging can be done today. Further, we will cover an integration of paging support into open source software, showing how to easily support/make use of various paging protocols today. We will also explore how to join and use DAPNET, a worldwide decentralized paging network for amateur radio operators, allowing users to build and operate small paging sites with inexpensive or surplus hardware easily and legally.
Mike Dank, Naveen Albert
Hack the Mission: From Hacker to Nonprofit Board President 11:30 Sunday
Hackers already know how to give back. We build ShmooCon, JawnCon, BSides, and local communities, while organizations such as Hackers for Charity have applied technical talent directly to humanitarian work. But another high-impact opportunity is hiding in plain sight: established nonprofits need capable board members who can help them make consequential decisions and remain healthy.

This fast-paced talk follows an offensive-security leader's path from first-time board member to President of the Delaware Symphony Orchestra. In 25 minutes, he will unpack the real board work: selecting a Music Director and CEO, navigating the musicians' collective bargaining agreement, setting strategy, overseeing financial health and donor relationships, and asking how a 120-year-old institution can reach younger audiences.

Attendees will learn what boards actually do, where hacker instincts help, when they hurt, what to ask before joining, and how to create impact without becoming the unpaid help desk. Hackers already help build communities; board service lets us help sustain the institutions those communities depend on.
Frank Clowes
Closing Remarks 13:30 Sunday
Let's wrap this up!
Russell Handorf
Track 2 - Sunday
Softmodems Are Cool Now: The Dark Art of V.34 10:00 Sunday
Softmodems used to be the bane of the earth (or at least the Linux part), but now they're a key part of Fax over VoIP. The BTX and Viewdata 1200/75 Baud FSK modes are easy enough, but what about 28,800 or 33,600 V.34? What don't the ITU tell you in the V.90 spec? Why did some softmodem DSPs compare so poorly to a "real modem"? And might softmodems actually be cool now?
Phil Pemberton
Thought on System Security Assessments 11:00 Sunday
Assessing a system's security is more than finding vulnerabilities with tools or LLM's. Security is one of a broad set of non-functional requirements (such as scalability, performance, reliability, etc) that we expect our systems to have. Understanding how to assess a full system, including understanding weaknesses in context, impacts on operations due to system complexity, and judging risk is part art, part skill, and a lot of experience.

This talk will cover the philosophy and strategy around security assessments. This won't be a deep dive into vuln discovery (tho, I will touch on it). Rather, it's an attempt to paint a picture of a system where security is one piece within many. I'll cover techniques to gain broad understanding of a system, building lists of functional and non-functional security requirements, find areas of high complexity and high risk, and how to structure the actual assessment.
Bruce Potter
Chillout Space All Weekend
And Two Baby Zebras: Care and feeding of Zebra ID printers. 10:00 Friday
Stop by for a fun showing of the care and feeding of Zebra ID printers.
Leave with a custom printed badge, and a peek behind how everyday cards are made.
Walt Zarnoch , Mike Baker
Philly Radio and Mesh Chillout Space 10:00 Friday
Meshtastic and Meshcore are an open source project that repurposes inexpensive LoRa radios into a peer-to-peer, off-grid, encrypted communications platform without requiring a license like amateur radio.
The network in Philly has grown significantly over the past few years and has new users joining every day.
Join us to learn more about these technologies, tell us about your experiences, or take a look at some of the hardware options we'll have on display.

Philly Mesh is a group over 1,000 strong with curious people interested in wireless technology, and we are excited for others to join us on our learning journey. Several of our members have even used this technology as a stepping stone into getting their technician radio license and beyond!

Caleb Frey, Emily Boda
TOOOL Lockpicking Village 10:00 Friday
Looking for a place to hang out while you wait for the next talk to start? Or how about a place to rest your legs but not your head? Then come check out at TOOOL's Lockpicking Village at JawnCon! Whether you're a novice who just stumbled upon LockpickingLawyer, a seasoned safecracker, or somewhere in between, come chill with us as we pop some locks!
Leo Nendza
PhilTel 10:00 Friday
PhilTel will have a selection of payphones on "free play" for attendees to use. These phones can connect to the PSTN and make/take calls from it, but it is also connected to PhreakNet, a hobbyist telephony network catering to phreaks; tandem-stacking, red-boxing, blue-boxing, and other techniques are all fair game here! In addition to payphones we will have other telephony equipment for display and use! We are considering bringing video phones, a WebTV, an AT&T Sceptre terminal, a radio phone patch so radio amateurs can call our phones, and more!
Mike Dank, Naveen Albert
Ex Machina Parlor Range Day 10:00 Friday
If you're a potential homelab enthusiast, system engineer, or cyber range developer come and check out the EMP Crew's Cyber Range Day! We'll be showcasing our portable cyber range kit we took to DEFCON and Blackhat USA this year. You'll get to play around in our range with our new Tengu Marauder Stryker units and robots in an emulated IoT range.
Leo Nendza
Saturday HAM Study and Exam
Study and take the HAM Radio Exams! 9:00 Saturday
Take a study session starting in the morning so that by after lunch, you'll feel more prepared to take the exam!
N2XDD

JawnCon™0x3  JawnCon™0x2  JawnCon™0x1  JawnCon™0x0  Code Of Conduct FAQ  CFP  Sponsor  Tickets  Schedule  Map  Schwag  Mastodon  Discord  YouTube  Thanks
Ⓒ 2026 - JawnCon™, LLC. Website written in haste with VI, as mother nature intended.