DEF CON 33 - Passing the Torch - Mentoring and Protecting Our Students - Navaar Johnson, Sam Comini

DEF CON 33 - Passing the Torch - Mentoring and Protecting Our Students - Navaar Johnson, Sam Comini

Source: YouTube · DEFCONConference · published Oct 10, 2025 · 54:54

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

Revised Summary

The Defcon Education Community session was an interactive discussion led by Navar, an IT administrator at a K12 school district, and Ancho, a security professional with 25+ years of experience. The session evolved from a planned panel into an open audience participation format with red team versus blue team exercises 0:03.

Key Discussion Points:

K-12 schools as targets: Educational institutions are considered soft targets primarily for student data, personal information, and payroll systems rather than intellectual property. Attackers exploit student data for identity theft since students have clean credit histories that can be misused for years before detection 5:03.

Students as insider threats: Students often bypass security controls using technical skills and powerful hardware. Many have gaming computers capable of running password cracking tools and can write their own proxies or VPNs to circumvent school security measures. One participant noted students with machines containing multiple high-end GPUs can brute force passwords quickly 13:01.

Security vs. education balance: Educational institutions must balance implementing security controls with enabling their educational mission. Overly restrictive security measures can hinder learning, while too much openness creates vulnerabilities. This tension is evident in conflicts between IT departments and teaching staff over appropriate access levels 25:11.

Physical security challenges: School buildings are designed to be open and accessible, making physical security difficult. While front entrances may be fortified, service entrances, maintenance areas, and network infrastructure locations often remain unsecured. IDFs in janitorial closets near water so

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 1 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

All right, everyone. Thank you for coming to our talk today. Uh, this was supposed to be a panel where we discuss the problems that we face in our organizations and how to deal with them. Unfortunately, as you can see, there's not much of a panel. They they all uh were not able to make it here. So, I'm going to invite you guys to be the panelists uh in this talk. As compensation for your contributions, I have candy. Hopefully, that's enough. Uh, if you come up and you know, you you participate, take a piece of candy. Uh, it's also kind of a social experiment. I want to see if people like M&M's or if they like Skittles more. Um, so you guys are all a bunch of really smart people. Uh, you're here at Defcon, so you probably have some great insight into security. Uh, and the more that you cont…