
DEF CON 33 - 10 Years of IoT Village: nsights in the World of IoT - Stephen Bono, Rachael Tubbs
Source: YouTube · DEFCONConference · published Oct 10, 2025 · 20:52
IoT Village was founded 10 years ago to expose security flaws in IoT devices through hands-on hacking contests, evolving into a major cybersecurity forum that highlights both the rapid innovation and persistent security gaps in connected devices. 0:31
Key Takeaways:
• The core mission of IoT Village began with a Defcon research project on hacked routers, leading to the "Hopelessly Broken" contest in 2014 and expanding to include diverse IoT devices like refrigerators and toilet seats 0:31-0:59.
• Despite rapid development speed—from idea to product in days—the biggest security issue remains poor deployment and lack of security by design, especially in critical infrastructure 1:00-1:50.
• Persistent gaps include weak firmware, lack of secure defaults, and inadequate user education, with consumers often unable to configure secure settings 1:50-2:20.
• AI is a major enabler and disruptor, accelerating IoT innovation but also increasing risks through autonomous, agentic control and potential for real-world harm (e.g., exploding ovens or malfunctioning medical devices) 11:34-12:45.
• The "who cares" question underscores the need to educate the public on IoT’s broader impact beyond convenience, especially in high-risk environments 13:10-14:24.
The future of IoT hinges on security-first design, public-private collaboration, and clearer definitions of "secure" in consumer products—without relying solely on regulation. 12:00-12:45
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
We are IoT Village. Um, my name is Rachel Tubs. I'm the organizer of IoT Village. I'm gonna let the panelists introduce themselves really quickly. >> Hi everyone. I'm Sandeep. I'm global field CTO with Nomi Networks. >> I'm Ted Harrington. I'm one of the partners along with Steve at ISC and we are behind running IoT Village. >> And I'm Steve. I'm CEO of independent security evaluators and yeah, creators of the IoT Village. >> Cool. So to start, I want to hear from Steve and Ted really quick. Why did you start IoT Village 10 years ago? >> Yeah. Um, it was a little bit before 10 years ago that we got started on some our company was doing some research on uh off-the-shelf routers and things like that. And we had hacked like 15 different devices and found hundreds of different vulnerabilities …