ToorCamp 2026

To see our schedule with full functionality, like timezone conversion and personal scheduling, please enable JavaScript and go here.
09:30
09:30
50min
Coffee Roasting 101 - the reckoning
Dylan McNamee

I gave a coffee roasting workshop / talk last camp, and have learned even more about roasting that I'm happy to share with you all. I'll talk a bit about my own coffee hobby journey, roasting basics (and a little bit beyond), and a little bit about bean varieties. We'll roast a few batches and will have some coffee to share (bring a mug!). We'll be roasting and brewing at the House of Pong as well, so stop by for a chat and some coffee even if you can't make the workshop!

Workshops - Hardware Hacking Stage
Hardware Hacking Stage
10:30
10:30
90min
Bronze metal clay jewelry
Amy Johnston

Metal clay combines fine metal particles in an organic clay base. In this workshop, we'll be making copper or bronze metal clay charms. No experience needed. If you need help with hand tools or following directions, please bring someone to assist you.

Arts & Crafts - Faerie Yurt
Great Faerie Crafting Yurt
10:30
20min
Opening Remarks
David Hulton

TBA

Talks - Prime Dome
Prime Dome
11:00
11:00
50min
Breaking the ICE: The Surveillance Stack Behind Your Sheriff’s “Community” App
Aaron Markham

My friend was disappeared by ICE for three days after a traffic stop in Nevada. He was arrested by Sheriffs, released, re-arrested by ICE in the parking lot, then held off the record. I built a jail roster monitor the next morning to find him. It alerted our Signal group the day that we was in jail under an ICE hold. Not a detention center. Jail. While I was building the jail roster scanner I noticed a data mining hook with Equifax on their recommended web portal "Vinelink", and warned my friends to NOT install the Sheriff app they require you to run to find someone that might be in their jail system. I later found that anyone searching for a loved one gave them access to read your SMS, phone history, location, and even activate your mic. Our friend group was being tracked the moment we started searching. Thus began a month-long struggle to know where my friend was being held: their chain of custody is non-existent, but spying ever-present in these law enforcement portals. This talk presents what I found inside 8 sheriff's apps, how the 287(g) program turns county jails into ICE infrastructure, and the zero-knowledge alternative I built so families can search without becoming targets.

Talks - Prime Dome
Prime Dome
11:00
90min
Free! American Red Cross Adult CPR/AED training (+first aid option)
Sova (no pronouns / name only preferred)

Join Sova and Karmic Project for a free training and certification in CPR and using an AED through the American Red Cross training course.

Workshops - Yoga Studio
Yoga Studio
11:00
150min
Lock Drilling Class
qweary

Learn the fine art of lock bypass with a drill from a professional locksmith. When lockpicking fails it's good to know the nuclear kinetic option.

Workshops - Hardware Hacking Stage
Hardware Hacking Stage
12:00
12:00
240min
Makerspace Open House
Curtis Mack

OlyMEGA brought a laser engraver / cutter, vinyl cutter, 3-D printer' and other tools. Bring your own SVGs, images, and ideas and work with an Olymegan to burn or cut them into whatever material you choose. We will provide boards or vinyl sheets if you need them. First come first served. We can actively work with around three people at a time. @ OlyMEGA Village

Workshops - Villages
OlyMEGA Village
12:00
50min
The Telephone Underground
J. B. Crawford

These days it seems like any hacker worth their salt cares about AT&T's microwave long distance network. Microwave is neither the beginning nor the end of long distance telephony, though. In this talk, we'll discuss the other kinds of Long Lines - long distance telephone leads that used hundreds of miles of copper. Along the way, we'll learn about AT&T's extensive program to build a coast-to-coast coaxial cable hardened against nuclear attack, complete with an underground fallout shelter every 150 miles. You'll learn to recognize historic telephone infrastructure that you can find throughout the US.

Talks - Prime Dome
Prime Dome
13:00
13:00
90min
Decorate your own dragon puppet
Sonya

Join us to create and decorate your own scaly friend in our dragon puppet workshop. No eperience required.

Arts & Crafts - Faerie Yurt
Great Faerie Crafting Yurt
13:00
50min
The Dinosaur in the Room: Mainframe Hacking in 2026
David M. N. Bryan - Aka VideoMan

Yes, Mainframes are still around. They make up the core of a suprising number of large fortune 500 companies . I will cover what a Mainframe is at a high level, how they tend to work, and regular security flaws that we see on a daily basis when testing these systems. If you've ever saw a movie and they say 'theyre hacking the mainframe', now you'll know what theyre talking about! By the end of this talk you'll know what a dataset is, how to test Unix (yes, Unix), and what these acronyms mean: JES2, RACF, NJE, TSO, OMVS.

Talks - Prime Dome
Prime Dome
14:00
14:00
120min
Badge Soldering Workshop
Curtis Mack

Badge assembly. Learn to solder using two different custom badges from past ToorCamps. Teens or older or with parental supervision. 2 sessions

Workshops - Hardware Hacking Stage
Hardware Hacking Stage
14:00
50min
Environmental DNA in Near-Real Time
Ryan Kelly, Aden Ip

Every organism around you is shedding DNA right now. Into the water, into the air, everywhere. We built a system that captures it, sequences it on a device the size of a USB stick, and identifies species live on screen. No lab. No internet. No waiting. At ToorCamp, we are pointing it at Doe Bay. Water goes in, and minutes later you are watching whales, sharks, fish, and birds appear on a dashboard as their DNA gets read in real time. We have run this on research ships, coral reefs, and in rainforest canopies. This time, you get to watch it happen. Come see what’s lurking around you.

Talks - Prime Dome
Prime Dome
15:00
15:00
20min
Always Bee Counting
Benjamin Foote

I count bees with a doohickey attached to my bee hive! Let me show you all the fun to be had with an ESP32 and custom board and how to send data via MQTT to Postgres and then pull it into Grafana for the most glorious graphs and analysis of what the bees are doing. There are a surprising number of things that you can tell from the data.

Talks - Prime Dome
Prime Dome
15:30
15:30
20min
WHAT IF WE ACTUALLY TRIED? Renovating the Ethical Foundation of Democracy
Alex Cruise

The organizational technologies of democratic politics — parties, platforms, elections — compress citizens' high-dimensional policy preferences into a low-dimensional menu, destroying most of the information in transit. The result is a system that cannot represent what anyone actually thinks, cannot communicate the necessity of compromise, and cannot process warnings that do not arrive in partisan packaging. This is not a failure of voters or politicians. It is a failure of architecture.
What If We Actually Tried? quantifies this dimensional compression, traces its consequences through the political system — from the manufactured homelessness of the "centrist" to the comfort trap that blinds the affluent to the conditions of the poor — and proposes a specific architectural alternative. The deliberation layer replaces the party platform with self-organizing interest groups that produce structured policy analysis, evaluated by other groups and by citizens along multiple independent dimensions. Critic groups, whose authority may derive from lived experience rather than credentials, stress-test every proposal. A cryptographic identity system — personal certificates, unlinkable shards, zero-knowledge attestation — ensures that every participant is a verified unique human being while revealing nothing about who they are, making honest participation possible without professional or social risk.

The book engages directly with the Abundance discourse (Klein, Thompson, Dunkelman), arguing that their unsolved question — who decides what gets built, and how? — has an answer: citizens decide, through structured deliberation, with results bridged into existing politics. It engages with the far left, the far right, and the anarchist critique through the lens of Jason Pargin's diagnosis of why mainstream America fears the left, showing that the "dealbreaker idea" — the perceived denial of human agency — is a communication failure that the dimensional model resolves by allowing agency and structural analysis to coexist on separate dimensions rather than being collapsed into a false binary.

The book is honest about its limitations: the bootstrap problem, class capture, agenda-setting power. Its closing argument is that dissatisfaction with the current system has converged across communities that see themselves as enemies — progressive, conservative, libertarian, apolitical — and that this convergence, arising from perspectives that share almost no surface-level overlap, is itself evidence that the dimensional diagnosis is correct. The conditions for structural reform exist. The work is not finished. Neither are we at liberty to neglect it.

Talks - Prime Dome
Prime Dome
16:00
16:00
20min
A Better Life Underground
polack

Severely burnt out after seven years working in DFIR consulting, and at the onset of the pandemic, I needed an excuse to get me outside away from people and computers. I ended up diving deep into a hobby I never thought I'd get into: exploring abandoned mines.

Six years into this, I've spent hundreds of hours studying maps, tagged coordinates of over 10,000 tunnels, researched how to do this as safely as possible, almost gotten stranded in the wildness twice, hiked over 50 miles entirely underground, taken explosives training which aided me in helping with an EOD mission at a mine, and found a small cross-section of hackers also into this hobby who introduced me to an amazing community of passionate explorers.

Talks - Prime Dome
Prime Dome
16:00
90min
Breaking the ICE: Hands-On — Tear Down a Sheriff's App, Build the Replacement
Aaron Markham

Your government publishes data you need to monitor, but searching for it creates a trail you can't afford. In this workshop, you'll build a zero-knowledge notification service from scratch: encrypted queries, fuzzy matching against a live data source, and result delivery where the operator never sees what was searched or who asked. Then you'll flip sides: use Rizin to tear apart a real sheriff's app APK, extract hardcoded secrets and tracking infrastructure, and have an AI agent classify findings against a threat registry. You leave with both the surveillance-resistant alternative and the skills to audit what it replaces. The patterns come from Frio, a live system monitoring county jail rosters for families of ICE detainees, but the architecture generalizes to any public dataset where the act of searching is itself sensitive.

Workshops - Yoga Studio
Yoga Studio
16:00
120min
Intro to Sewing Workshop
Angela Livermore

Intro to sewing - Learn the basics In the cabin 4 people at a time. Teen or older. @ OlyMEGA Village

Workshops - Villages
OlyMEGA Village
16:00
90min
Meshtastic for Beginners: Join Your Local Community Mesh Net!
Kody Kinzie

Want to get started with Meshtastic, and other off-grid LoRa mesh protocols? Learn the key differences between Meshcore, Meshtastic, and Reticulum, and how to customize your custom Meshtastic node to join your local community mesh network. You'll set up your node, learn to customize settings, use your node with your smartphone, and adapt your setup for specific environments. We’ll also cover common attacks against mesh networks and how to defend against them!

Workshops - Hardware Hacking Stage
Hardware Hacking Stage
16:30
16:30
20min
Yes, an electric unicycle is the most practical way to get around: a love letter and an incident report
Dustin

A single wheel. No handlebars. No seat (usually). No brakes, in the traditional sense. 55 mph & 50 miles on a charge. Fits under a desk, charges from a wall outlet, and makes you look like a wizard, a lunatic, or both, depending on the lighting.

I won't be giving lessons at this talk, but I'm happy to teach throughout the weekend! If you'd like to give it a try, please fill out this liability release.

Talks - Prime Dome
Prime Dome
17:00
17:00
60min
Creative Mask Making
viper

Come join me for a hands-on mask-making workshop! Masks are a fun way to express your creativity - and maybe even a part of your identity. We’ll be making masks of all kinds, magically transforming basic cat mask bases into all kinds of animals, characters you love or have invented, something for a formal masquerade or just let your creativity loose!

Arts & Crafts - Faerie Yurt
Great Faerie Crafting Yurt
17:00
20min
What's after LoRA?
CNLohr

LoRA has been a significant force within the low-power, long-range radio space, enabling many protocols built on top from Reticulum to Meshtastic. But, the underlying protocol has some major shortcomings including susceptibility to jamming, sender detection and collisions. Let's explore what would be possible if we have more than some $4 radio silicon to play with. I hope to find other people in this space interested in working together to see what could be done.

Talks - Prime Dome
Prime Dome
17:30
17:30
20min
Hacker Foundation Hijinks
Dean Pierce

In 2024 the Portland Hacker Foundation was founded with the goal of accelerating security research in the Portland area and delivering asymmetric impact to the local community. This is that story. How the Foundation was set up, the research we've funded, and how you can go out and build similar systems to empower your local community.

Talks - Prime Dome
Prime Dome
18:00
18:00
20min
Building a Kids-only Phone Network
n3wscott

There is nothing worse than being asked to text your kid's friends mom to see if they are free to hangout. Being a huge fan of ShadyTel, I built a kid only phone network with phones and open-source to solve the problem! I will show how I have been building this, the protocol behind it, and some of the tools that I have built to manage it along the way!

Talks - Prime Dome
Prime Dome
18:00
90min
Meshcore & Meshtastic for Beginners: Solder Your Encrypted Off-Grid Node! (soldering)
Kody Kinzie

Build your own cat-themed Nibble Mesh node and join the massive off-grid LoRa mesh networks popping up worldwide! In this class, you will learn to solder and flash Meshcore and Meshtastic onto your device, allowing you to connect, message, and explore independent networks. You will also build an environmental sensor to create your own remote weather station. For beginners to intermediate soldering skills.

https://retia.io/toorcamp

Workshops - Hardware Hacking Stage
Hardware Hacking Stage
19:00
19:00
60min
0xfff3 plays a chill daytime set
m

Join 0xfff3 for a relatively chill dj set featuring some breakcore, dnb, maybe jungle and a healthy amount of ambient.

Music
Yoga Studio Front Lawn
20:00
20:00
60min
Echo's techno
echo

A eurorack techno set, featuring thundering bass, squelchy acid leads, and strange samples

Music
Yoga Studio Front Lawn
21:00
21:00
300min
NightMrkt
pinguino kolb

Thursday and Friday 9p-2a at the volleyball courts! Trade your warez!

Workshops - NightMrkt / Volleyball Court
Volleyball Court - NightMrkt After Dark
21:00
60min
Syntax + Luna
syntax

DnB + Viz with Luna

Music
Yoga Studio Front Lawn
09:30
09:30
90min
Open Craft Time
Amy Johnston

Come share in craft time. Bring your own project or work on a project you started during a craft workshop. We have an assortment of craft tools and supplies on hand to share.

Arts & Crafts - Faerie Yurt
Great Faerie Crafting Yurt
10:00
10:00
30min
Making Pizza... with Science! (Part 1 - Making the Dough)
Randy Pargman

We'll use the America's Test Kitchen method of scientific experimentation to find the easiest and most fun ways to cook real pizza while camping, using different methods for crust, sauce making, cooking techniques, different fuels, different cheese and toppings. Please see the description for what you need to bring (gluten free is possible too)

Workshops - Picnic Tables (Outside Yoga Studio)
Yoga Studio Front Lawn
10:30
10:30
120min
Badge Soldering Workshop
Curtis Mack

Badge assembly. Learn to solder using two different custom badges from past ToorCamps. Teens or older or with parental supervision. 2 sessions

Workshops - Hardware Hacking Stage
Hardware Hacking Stage
11:00
11:00
90min
Free! American Red Cross Adult CPR/AED training (+first aid option)
Sova (no pronouns / name only preferred)

Join Sova and Karmic Project for a free training and certification in CPR and using an AED through the American Red Cross training course.

Workshops - Yoga Studio
Yoga Studio
11:00
50min
KEYNOTE: Jack Rhysider, Darknet Diaries
Jack Rhysider

Jack will tell you a story and give you free chemicals. His operating system of choice is wetware, and he will demonstrate how hackable it is.

Talks - Prime Dome
Prime Dome
11:00
90min
Tapestry Weaving for Beginners
Sonya

Join us to learn the basics of tapestry weaving. Using a handheld loom you will create your own fabric using yarn, thread, and maybe even things from the world around you! No experience necessary.

Arts & Crafts - Faerie Yurt
Great Faerie Crafting Yurt
12:00
12:00
50min
Physical Access, Digital Lies: How a Locksmith Hacked His Recommended Lock
qweary

I spent years installing Trilogy Alarm Locks for the military. Other locksmiths asked for recommendations, I let them know of Trilogy's fast response to responsible disclosures (at that time), and I soon started seeing them in pharmacies, more government buildings, and banks. Then, after the company stopped responding to my vulnerability disclosures, I spent a year figuring out how to hack them. Nearly every angle I approached it from, I found a new vulnerability. The company never responded, despite acknowledging through a third party.

This talk walks through a five-layer attack chain against the T2/T3 lock platform: physical bypasses that leave little to no trace, NAND flash manipulation that injects ghost users with master privileges, a firmware hook on the MSP430 microcontroller that writes a persistent backdoor code during factory reset (using hand-patched TI assembly, because apparently that's a thing I do now), and USB emulation of the proprietary audit cable using FaceDancer and a GreatFET One.

Over a year later, I was able to prove that a lock deployed in critical infrastructure has credentials that can be cloned from the trash, firmware that can be rewritten through an unblown JTAG fuse, and whose audit trail (the one used as legal evidence) can be fooled by a device that costs less than the lock itself.

I'm not a firmware engineer; I'm a locksmith who got curious, bricked a lot of boards, filled a notebook with bad hypotheses, and eventually taught myself enough TI assembly to write a 38-byte payload that survives every factory reset method. The tools were a $30 flash programmer, a soldering iron, and an unreasonable amount of stubbornness.

The talk closes with a constructive argument: self-auditing endpoints are fundamentally broken. If the lock controls access AND writes the audit log, you have a suspect writing their own alibi, not a log that should be used in legal evidence. I'll propose an Observer System Model where independent sensors verify what the lock claims, and discuss why even cheap mitigations (blow the JTAG fuse, encrypt the NAND, authenticate the cable, use a TPM) would have stopped every attack in this chain.

Everything is published: code, dumps, patches, pcaps, 33 pages of handwritten notes, and a 4,000-word research journal documenting every wrong turn.
Repo:
https://github.com/Qweary/T2-T3-Lock-Exploitation-Research
Blog:
https://qweary.github.io/backburner/

Talks - Prime Dome
Prime Dome
12:30
12:30
240min
Flame Effects for the Hacker
Jack Chatterton

This four-hour workshop will teach the legal basis of flame effect installation, including NFPA 160 and other codes, as well as some basic physical properties of LP gas. With that in place, we'll move on to constructing a simple static effect, i.e. a tiki torch, and then using that as the pilot light for an wifi-connected dynamic effect, i.e. a poofer. By the end of the course, you will have the basic knowledge necessary to add a flamethrower to your own network

Workshops - Villages
Moon Rock Village
13:00
13:00
90min
One Page One Shot Think Tank Madness
Lesley Jones

Storytelling through games doesn't have to be complicated! Come on down and scribble on some printer paper with friends! In this sort-of-guided-ish workshop experience, we'll build simple tabletop RPGs that can be played in 15 minutes, about whatever the heck we want! I'll bring the dice, let's get wierd.

Workshops - Yoga Studio
Yoga Studio
13:00
50min
Owning the Packbot: A full stack teardown of an EOD robot.
Gigstorm, astradotpng

Remotely operated vehicles are increasingly integral to modern operations, with bomb disposal robots serving as some of the earliest pioneers of robotics. This presentation provides a deep technical analysis into the architecture and 25-year evolution of iRobot’s PackBot. Originally developed by iRobot, creators of the Roomba vacuum, the PackBot saw extensive use while keeping operators safe. However, beneath its ruggedized exterior lies an ecosystem built on legacy open-source software, and commercial off-the-shelf hardware.
Despite two decades of iterative hardware improvements, the PackBot’s software stack has remained largely static, running on legacy distributions of Linux and relying heavily on Python 2.5 for core functionality in its second-generation and later models. Attendees will be taken through a comprehensive hardware teardown and introduction to my PackBot. We will map the system across the Operator Control Unit (OCU), the radio links, and the robot itself. Finally, we will detail the reverse-engineering process used to gain access to each component, analyze the control protocols, and demonstrate how a hacker can customize and make a PackBot into something new.
My PackBot, Boomba, will also be present at the talk and be available the entire week for autographs or to pass the butter.

Talks - Prime Dome
Prime Dome
13:00
90min
Wi-Fi Self Defense & Hacker Hunting For Beginners (no soldering)
Kody Kinzie

Get hands-on instruction on advanced Wi-Fi hacking while learning how to defend against common advanced techniques. You will learn essential skills for defending against five common, powerful Wi-Fi attacks. Explore how to physically track down any Wi-Fi device, detect Wi-Fi leaks, identify malicious QR codes and phishing networks, and defend against advanced Wi-Fi karma attacks.

Workshops - Hardware Hacking Stage
Hardware Hacking Stage
14:00
14:00
50min
Skip the Breadboard: Designing Eurorack with Simulation and SMT
Aaron St. John

Analog synthesizers have become a playground for DIY electronics builders, but the traditional playbook - breadboard everything and build through-hole prototypes - is slow, messy, and increasingly out of date. Modern tools make it possible for a single hacker to design and manufacture professional-quality surface-mount modules quickly and cheaply.

In this talk I’ll walk through my end-to-end workflow for designing Eurorack modules without breadboards. Using real modules as a case study, I’ll cover circuit simulation in LTspice, schematic capture and PCB layout in KiCad, and low-cost manufacturing with JLCPCB. I’ll also show the inevitable mistakes: debugging first prototypes, tweaking component values, and refining the design. The goal is to demystify modern PCB development and show how approachable it is to go from idea to fully manufactured hardware.

If you’ve ever wanted to design your own synth module - or any small electronic gadget - this talk will show how modern tools and manufacturing make it easier than ever.

Talks - Prime Dome
Prime Dome
15:00
15:00
120min
Badge Soldering Workshop
Curtis Mack

Badge assembly. Learn to solder using two different custom badges from past ToorCamps. Teens or older or with parental supervision. 2 sessions

Workshops - Hardware Hacking Stage
Hardware Hacking Stage
15:00
20min
Dubious Computing Conventions -- that hurt us.
Aaron Peterson

Our computer systems will fail, without trying. We can and should save the user from unexpected errors and lost data.
We can categorize these as: Physical, Legacy, New for Newness, Cultural, and Security,

Some gotcha corner cases are so hard to deal with, we just ignore them. We would have to add extra evaluations at many layers in the system and interact with the user, which may cause complications, but with sane defaults we can manage

Filesystem case sensitivity, character encoding, miss clicks, focus change, system lag, the cat walks across the keyboard and starts batting the touch screen, and you should have known better.

Talks - Prime Dome
Prime Dome
15:00
90min
Hecate: A Trivial UART Tool
Joe FitzPatrick, nyx

Hecate is an open source UART implant framework designed to make common hardware hacking tasks easy with minimal code. It turns any CircuitPython microcontroller into a powerful, customizable UART implant.

In this workshop, you'll get to use all the core features of Hecate and see how they work against multiple target devices. We'll start hands-on by listening to a device's UART output, and then configuring Hecate to operate in standalone mode and log it to a file. Once we've seen it in action, we'll step back for a bit of lecture about UART, what it's used for, and what we designed Hecate to be capable of.
Armed with this knowledge, you'll dive into more hands-on labs: a payload dropper that will playback a custom transaction and a simple detector that will signal an alert when it detects a pattern. We'll reconvene for a last bit of lecture on Hecate's advanced features like in-flight implant-in-the-middle attacks in case you want to explore them after the workshop.

Hecate makes developing embedded implants trivial, while remaining flexible enough for advanced research and rapid prototyping. You'll walk away with hands-on experience using the Hecate framework and a working understanding of what's possible with UART interception, manipulation, and exploitation.

Workshops - Yoga Studio
Yoga Studio
15:00
120min
Intro to Sewing Workshop
Angela Livermore

Intro to sewing - Learn the basics In the cabin 4 people at a time. Teen or older. @ OlyMEGA Village

Workshops - Villages
OlyMEGA Village
15:30
15:30
20min
No GPS, No Problem!
Pierce Nichols

Mariners have been crossing the seas guided by nothing more than precise measurement of star positions for centuries. This talk will discuss automating the process of celestial navigation so that you or your robot can navigate without the aid of GPS or other navigation aids.

Talks - Prime Dome
Prime Dome
16:00
16:00
20min
Shipspotting - An Introduction to AIS
Adrian Studer

Automatic Identification System (AIS) is a radio protocol used for marine traffic management. This talk introduces the basics of AIS and its obvious use: tracking ships! We will then nerd out on more obscure applications, technical details, and their security implications. The talk will end with a guide to low-cost tools and open source resources to kickstart your own shipspotting adventure.

Talks - Prime Dome
Prime Dome
16:30
16:30
20min
Radio Technologies: RDS and RDS-2
Tycho Pendraig

Discussion on the history of RDS technology, as well as recent developments in and applications of RDS-2. Presented by Tycho Pendraig, in collaboration with Allen Hartle of KIXP and the StayAlert system.

Talks - Prime Dome
Prime Dome
17:00
17:00
90min
Making Pizza... with Science!
Randy Pargman

We'll use the America's Test Kitchen method of scientific experimentation to find the easiest and most fun ways to cook real pizza while camping, using different methods for crust, sauce making, cooking techniques, different fuels, different cheese and toppings. Please see the description for what you need to bring (gluten free is possible too)

Workshops - Picnic Tables (Outside Yoga Studio)
Yoga Studio Front Lawn
17:00
20min
rtlsdr.tv: Broadcast TV in your browser
Karl Koscher

This talk introduces rtlsdr.tv and will cover the basics of digital video streams, programmatically feeding live content to tags through Media Source Extensions, and using WebUSB to interact with devices that previously required kernel drivers. We will also dive into a few "vibe-porting" tricks used to automatically convert tedious portions of Linux drivers to JavaScript.

Talks - Prime Dome
Prime Dome
17:30
17:30
5min
Visualizing the Invisible: Rendering Spectrum As Light
Paul Carrigg

The spectrum around you is crowded - phones hunting for known networks, wearables advertising themselves, mesh routers gossiping in the background. None of it is visible, and the tools we have are built for analysis, not atmosphere. I wanted an ambient display driven by the spectrum.

In this system, each node senses, passively listening for the wireless traffic that betrays nearby devices. It coordinates, sharing what it sees with the other nodes. It expresses, driving a layered animation engine where device counts, traffic bursts, proximity, and movement through the space all become inputs that shape color and motion.

Talks - Prime Dome
Prime Dome
18:00
18:00
20min
Gatekeeping the exit: retail loss prevention technology
J. B. Crawford

We've all done it, you walk out of the store and the exit portals start beeping.... So you just keep walking. Tag-based retail anti-theft systems have been with us for decades, and there are several distinct generations of technology in use. Some of them rely on interesting physics, others use state of the art RFID technology for integrating into point of sale and supply chain systems. All of them are, almost universally, hated and ignored. We'll learn about magnetostriction, visibility networks, and shopping carts that form mesh network swarms while they wait in the parking lot.

Talks - Prime Dome
Prime Dome
18:30
18:30
20min
Stupid Hackathon Kickoff
Moonrock

Sign up for the Stupid Shit No One Needs & Terrible Ideas Hackathon, a time-limited event that gives creators the opportunity to produce variously useless, horrifying, boring, and/or bad things. Create terrible things alone or with a group! After 24 hours of production time, bring your terrible thing to our Stupid Hackathon showcase for judging.

Talks - Prime Dome
Prime Dome
19:00
19:00
5min
Lightning Talks
David Hulton

Have an idea for a lighting talk? Email david@toorcon.org so we can add you to the schedule or just show up and be prepared to talk for 5 minutes on a subject.

Talks - Prime Dome
Prime Dome
19:30
19:30
60min
Republic Dogs
Pierce Nichols

For the first time in more than thirty years... Republic Dogs will be performed live. This scintillating modernist reinterpretation of Plato's Republic has been hidden away in the depths of the Internet for decades, but this Toorcamp, it will emerge back into the light.

Talks - Prime Dome
Prime Dome
20:00
20:00
60min
Kalikat DJ Set
Jessa Gegax

I'd like to apply to be a DJ at the con! My DJ name is Kalikat (like Kali Linux) and I like to spin minimal house beats but can do other more experimental styles if necessary. Here is my latest SoundCloud set:
- https://on.soundcloud.com/g197bQsNDAUjKM7dct

Some other styles I can do (in a Spotify playlist):
- https://open.spotify.com/playlist/4J5mMOFTGTuvKaVsJKqREe?si=Ihnhdug-RaKGjY2uiwEYpg&pi=BoU4DkiZRFqZe
- https://open.spotify.com/playlist/7rc1J83yYHh8oJnhepTfS8?si=8xQpzoOPShmJNhfnVNPvtg&pi=uOY9JQjbQ_atL

Music
Yoga Studio Front Lawn
20:00
90min
Live Jam Session
qweary

Live jam: Relax with classical and jazz music played on trombone by a guy named Piano (Qweary). Jazz backgrounds over speaker, bring an instrument if you want to join.

Workshops - Hardware Hacking Stage
Hardware Hacking Stage
21:00
21:00
300min
NightMrkt
pinguino kolb

Thursday and Friday 9p-2a at the volleyball courts! Trade your warez!

Workshops - NightMrkt / Volleyball Court
Volleyball Court - NightMrkt After Dark
21:00
60min
PatAttack!
PatAttack

PatAttack is a Security Engineer by day, and a DJ when he's not asleep. This year for ToorCamp, he's bringing you some delicious Liquid Drum and Bass!

Music
Yoga Studio Front Lawn
08:00
08:00
180min
Blade Runners: The ToorCamp Trail Half-Marathon
David Hulton

It turns out that it's roughly 11-13 miles to run from Doe Bay to the top of Mt. Constitution and back so let’s do it! There is no set course, so everyone is encouraged to plan a route ahead of time-- although here's the most direct route according to Strava (11.42mi / 3020ft gain): https://www.strava.com/routes/3237629479105980898. Take a selfie when you get to the top and post to #bladerunners on discord as your proof of making it and in front of the TOORCAMP sign at the Prime Dome when you return to register your finish time.

The run kicks off at 8am sharp from the volleyball court. We encourage everyone to bring ample hydration and fuel.

Workshops - NightMrkt / Volleyball Court
Volleyball Court - NightMrkt After Dark
11:00
11:00
20min
Anything but Ethernet
Ben Kurtz

Invented by Nate Bezanson at Notacon 2 in Cleveland in 2005, this game is the ultimate test of hacker ingenuity.

https://wiki.toorcamp.org/AnythingButEthernet

Workshops - Picnic Tables (Outside Yoga Studio)
Yoga Studio Front Lawn
11:00
90min
Dead Bytes Tell No Lies: Hands-On NAND Flash Decoding for Access Control Locks
qweary

Somewhere in a pharmacy right now, there's a lock protecting a drug cabinet. The lock stores every user code, privilege level, and active flag in plaintext on a NAND flash chip. No encryption. No MAC. No checksums. No TPM. Just raw bytes in a predictable layout, readable with a $30 programmer and a clip.

In this workshop, you'll learn to decode that layout by hand.

We'll work through real NAND dumps extracted from Alarm Lock Trilogy T3 units; the same locks deployed across healthcare, government, and financial facilities in the US. You'll learn how to identify page boundaries (hint: look for 0xFD), decode 6-digit user codes stored as interleaved ASCII nibbles with a delightful quirk where zero is encoded as “B”, parse permission flags to determine who has master access, and spot the forensic artifacts that indicate flash tampering (like the "Power Up Complete, Data Restored From Flash Memory" audit entry that appears after injection).

Along the way, I'll explain the lazy write model that makes all of this possible: the MSP430 microcontroller only commits volatile RAM to NAND on battery removal or low-voltage interrupt, creating a window where the flash doesn't reflect the lock's current state. We'll also look at what happens when you inject malformed data: some edits will show injected codes in its "Print Users" output (using the vendor's older and less used infrared printer) but silently omit them from "Export Users” in DL-Windows (the vendor audit software used on a computer), creating a stealth window where printed and digital records disagree.

No soldering required. Bring a laptop with a hex editor (HxD, wxHexEditor, or whatever you prefer). I'll provide printed reference sheets with the full NAND page layout and sample binary dumps to work through. If time permits and curiosity demands, I'll have a T48 universal programmer and a lock board on hand for a live read/write demo.

You'll leave knowing how to read embedded flash memory from a class of devices that assumed nobody would bother, and take part in showing that assumption is a security failure.

Workshops - Yoga Studio
Yoga Studio
11:00
50min
The New War on Privacy, and How We Win -- Lessons from the History of Hacker Activism
Naomi Brockwell

The surveillance state is exploding. Flock cameras blanket the country. Palantir watches everything. ICE buys location data by the truckload. Age-verification mandates are being baked into operating systems. And the developers building tools to push back are getting arrested.

We are losing this fight. But we don't have to.

Past generations of hackers already wrote the playbook for winning fights like this one. Phil Zimmermann beat the U.S. export-control regime by publishing PGP source code. Cult of the Dead Cow forced Microsoft to take security seriously by handing out 10,000 CDs of a Windows exploit at DEF CON. Matt Blaze killed the Clipper Chip with a single peer-reviewed paper. We can follow the same playbook.

This talk walks through how they succeeded, and what the community needs to do right now to win current surveillance war.

Talks - Prime Dome
Prime Dome
11:30
11:30
90min
Solder Your Very Own IoT Purrsheen Cat Lamp with WLED! (soldering)
Kody Kinzie

Learn rapid prototyping and build your own open-source, internet-controlled LED art! In this class, you will solder and assemble an adorable, squishy "Purrsheen" Wi-Fi lamp. Once built, you'll learn how to control your new glowing cat baby via Wi-Fi or Home Assistant using WLED. For beginners!

https://retia.io/toorcamp

Workshops - Hardware Hacking Stage
Hardware Hacking Stage
11:50
11:50
10min
The Toorcamp Pride Parade Start
Tendy

The Toorcamp Pride Parade!

Wear your proudest gear, bring your proudest flag, we will have temporary tattoos and body paint!

As usual, it will begin above the Prime Dome, parade through camp, end with a group photo down at the end of the road near the Doe Bay Cafe, and have an after party at Beerocracy with beats, beverages (both alcoholic and non alcoholic), and our big gay selves!

THIS IS A FAMILY FRIENDLY EVENT, all are welcome

Talks - Prime Dome
Prime Dome
12:00
12:00
50min
WebPKI and You
Bryce

There’s been a push over the last twelve years to move web traffic off unencrypted HTTP to encrypted HTTPS, to protect the general public from dragnet surveillance, gaping assholes on public wifi, backhauls over unencrypted satellites, that kinda thing. HTTPS relies on a public key infrastructure to make sure only authorized servers have keys for specific websites.

This public key infrastructure isn’t just a bunch of servers and vaults in datacenter cages around the world. It’s a social and political system operated and regulated by several parties with conflicting goals.

We'll go over the high-level view (no math!) of how it works, various organizational failures and outcomes from these failures, and what we can do to make this system work better.

Talks - Prime Dome
Prime Dome
13:00
13:00
50min
Architectures of Autonomy: Adversarial Orchestration and the Collapse of "Human-in-the-Loop" Security
infosecanon

The last two years represent a paradigm shift from AI as a "chat assistant" to an autonomous agentic workforce. Meanwhile, "vibe hacking" and prompt injection are rapidly evolving into machine-speed warfare driven by autonomous AI agents. As models continue their exponential parameter growth, threat actors are now leveraging agentic connectors for zero-click data exfiltration (AgentFlayer) and utilizing AI-orchestrated espionage campaigns (GTG-1002) that operate at speeds physically impossible for human defenders to counter. Furthermore, "semantic corruption" through disinformation networks, like Pravda, now target the models' internal logic by flooding and poisoning their training and retrieval data.

This evolution is driven by persistent orchestration frameworks like GasTown and RalphWiggum, which move away from ephemeral sessions toward Git-backed work ledgers and the "GUPP" (Execute Immediately) principle. While these systems offer massive productivity gains, "vibe coding" builds software with intent rather than manual review. We have fundamentally expanded the attack surface while we have little visibility into the silent, machine-to-machine, exploitation of the "agent stack." This talk explores how these autonomous architectures have decoupled technical execution from human oversight, requiring a complete rethink of enterprise trust boundaries. [183]

Talks - Prime Dome
Prime Dome
13:00
120min
Intro to Sewing Workshop
Angela Livermore

Intro to sewing - Learn the basics In the cabin 4 people at a time. Teen or older. @ OlyMEGA Village

Workshops - Villages
OlyMEGA Village
13:30
13:30
90min
AIS Hacking Session
Adrian Studer

This informal hands-on workshop is about turning my talk "Shipspotting - An Introduction to AIS" into action.

There will be two independent topics to explore:
1) Setting up your own AIS receiving station with an RTL-SDR or a specialized AIS receiver.
2) Decoding and processing live AIS data streams with Python

I will bring a few AIS receivers and antennas, and there will be a live AIS data stream of local ship traffic over wired or wireless network.

While anyone is welcome to shoulder-surf, hands-on participants should bring a laptop.

If you want to setup your own AIS receiving station, bring an RTL-SDR dongle (optional). I recommend to install AIS-catcher ahead of time to placate the internet gods:
https://jvde-github.github.io/AIS-catcher-docs/installation/overview/
I will bring binaries for Windows, but installation for Linux and MacOS requires an internet connection.

To hack on the live AIS data, only Python is required. I recommend to pip install the Python packages aiscat, pyais, matplotlib and sqlite3.

Workshops - Hardware Hacking Stage
Hardware Hacking Stage
13:30
90min
Red, Green, and Blue, And So Can You
Trevor Schrock - spacemeat

Learn the basics of the hardware and software / source code needed to drive animated LED strips and matrices. Interested folk can walk away with a working kit, ready to be used or modified. We shall demystify the art and craft of custom programmed LED animations.

Workshops - Yoga Studio
Yoga Studio
14:00
14:00
50min
Working the Slop Mines
Dean Pierce

As humans, things have gotten pretty weird. What does the world look like when difficult work is increasingly delegated to machines that have no sense of ego? What does crime look like? How can organizations structure themselves to survive in these sorts of rapidly shifting environments, and how can these tools empower individuals and the communities they care about?

Talks - Prime Dome
Prime Dome
15:00
15:00
180min
Makerspace Open House
Curtis Mack

OlyMEGA brought a laser engraver / cutter, vinyl cutter, 3-D printer' and other tools. Bring your own SVGs, images, and ideas and work with an Olymegan to burn or cut them into whatever material you choose. We will provide boards or vinyl sheets if you need them. First come first served. We can actively work with around three people at a time. @ OlyMEGA Village

Workshops - Villages
OlyMEGA Village
15:00
20min
Presenting, the Andromeda Strain
Vyrus

This talk introduces, demonstrates, and explains the construction methodology of Andromeda; A command and control (C2) / implant framework that leverages large language models (LLMs) to dynamically instantiate position implicit byte code as a means of performing dynamic remote functionality execution. The implant works by transmitting a dynamically constructed collection of offsets to instrumented native library functions (along with some basic system metadata) to the C2. The C2 is an LLM agent that leverages a large collection of AI skills to take instructions from an operator in plain verbiage, before subsequently using it's skills collection to dynamically construct byte code designed to satisfy the operator's request. This byte code is then transmitted downstream to the implant instances that in turn execute the byte code in a continuous execution cycle.

In the presentation, the novel-ness of this approach will be presented as an iteration on earlier capabilities (such as Metasploit's "Rail-Gun"), as well as the pros vs cons of transferring elements of runtime complexity (such as behavioral obfuscation) to the C2 vs the Implant, as is more typical in C2/Implant frameworks.

Talks - Prime Dome
Prime Dome
15:00
90min
Solder Your Own Cat-Themed Wi-Fi Hacking Tool! (soldering)
Kody Kinzie

Test out your soldering skills to create your own open-source, cat-themed hacking tool! In this class, we’ll create a microcontroller-powered hacking tool called the Wi-Fi Nugget that allows us to track down suspicious Wi-Fi devices, attack and defend networks, and even spoof drone signals! Beginners in this class will practice soldering while creating a cute and powerful IoT device in a beautiful 3d printed case! For intermediate soldering skills.

https://retia.io/toorcamp

Workshops - Hardware Hacking Stage
Hardware Hacking Stage
15:30
15:30
120min
Binary Jiujitsu: White Belt Fundamentals
Joshua Connolly

Breaking into binary exploitation can feel overwhelming — the tools are unfamiliar, the concepts are low-level, and it's hard to know where to start. This hands-on workshop cuts through the noise and gets you exploiting real binaries from minute one using Binary Jiu-Jitsu, a gamified learning platform built specifically for the journey from zero to hacker.
About the Workshop:
Binary Jiu-Jitsu is a multiplayer RPG-style cybersecurity learning platform designed to teach binary exploitation and reverse engineering through structured, hands-on challenges. Rather than passive lectures, participants progress through a belt-ranked challenge system where each solved vulnerability unlocks new techniques and territory. The platform is built around the belief that exploitation is a skill — and like any discipline worth mastering, it's best learned by doing.
In this workshop, attendees will be guided through their first real exploitation challenges, covering foundational concepts like memory layout, the call stack, and hijacking program control flow. Challenges are dynamically generated and sandboxed, so every participant works in their own environment without interference.
By the end of this session, attendees will have:
* Hands-on experience exploiting their first binary vulnerabilities
* A mental model for how programs behave at the memory level
* Access to the Binary Jiu-Jitsu platform to continue training after the workshop
Whether you've never opened a debugger or just want a structured path forward, this workshop meets you where you are. Come ready to break things.

Workshops - Yoga Studio
Yoga Studio
15:30
20min
The Other Disaster: from Ebola camps to a token factory
Dustin

I used to do emergency telecommunications for the United Nations. The satellite link, the field network, the thing the medics and the logisticians and the press and everyone else needs before they can do anything at all. Ebola response in West Africa. The earthquake in Haiti. Puerto Rico after Maria. The work was triage in the literal sense: not enough bandwidth, not enough power, not enough time, who gets the link first.

Then I left to do [stuff] at a token factory. People ask why. There's usually an unspoken second half to the question still hanging in the air.

This talk is the long version of the answer.

Talks - Prime Dome
Prime Dome
16:00
16:00
20min
Crypto Engineering in Practice
SalusaSecondus

Many of us enjoy a peek behind the curtains to see how things are made. Unfortunately, if we aren't one of those specialists, we rarely get the chance.

Come listen to a real-world story of how SalusaSecondus designed a new cryptographic construction (FLOE) and proved it secure. The focus of this talk isn't the details of cryptography, but instead an opportunity to hear the considerations and strategies of a less common engineering practice.

Talks - Prime Dome
Prime Dome
16:00
30min
li-nk : develop your interests, find your community
Colin Williams

li-nk is a social platform for planning and discovering activities and events. Members create and propose activities organized by interest, then connect with others who want to join. li-nk is actively developed and worked on signficantly through the #tcombinator at toorcamp 24'

Interests range widely, including outdoor adventures, arts, technology, sports, food, wellness, learning, games, and community causes.

li-nk grew out of a simple observation on Orcas Island and across the Salish Sea. People often live near one another and care about the same things, yet never cross paths. Rather than organizing around follower counts or feeds, li-nk starts with the activity itself, so community forms among the people who show up. The guiding idea is easy to remember: develop your interests, find your community!!

li-nk has strong geographical capabilities to help find activities currently across the USA, strong privacy controls. Custom E2EE encrypted video, voice , and messaging implementation supported through the olm / megolm encryption protocols. Li-nk currently provides an android client through a Google Play internal testing track and is waiting for Apple to approve a developer account to publish an iOS release.

Curious individuals may try the demo at demo.li-nk.social, no signup required, or learn more at li-nk.social.

li-nk contributes back to OSS projects which it employs at https://github.com/li-nkSN . Notable contributions include: the Zoned UID feature to the Open ZFS kernel supporting rootless containers employing the OpenZFS filesystem; A greater than 60% reduction in compilation times for the ProtoQuill integrated query library; Improvments to the Caliban GraphQL library including GraphQL Spec conformance and serialization helpers.

li-nk is dedicated to MrPrim8 (RIP) who ran a 2600 chapter in HS in SWFL in the 90s. Moved to Seattle metro in the 00s. Was part of the Seattle 2600 scene. And lead developer (PNWsoft) of the ConnectU platform developed at Harvard University counterpoint to "The Facebook" . In many ways, MrPrim8 was remarkably mature in his twenties. Growing up with MrPrim8 I really looked up to his integrety and values. I believe li-nk is a platform Winston would be proud of.

Workshops - NightMrkt / Volleyball Court
Volleyball Court - NightMrkt After Dark
16:30
16:30
20min
DIY Smart Chicken Coop
Sebastian Noack, rosie

This talk covers how we brought home automation into our chicken coop — from building an automated door to adding sensors that monitor feed and drinking water — all powered by an ESP32 microcontroller running ESPHome.

Talks - Prime Dome
Prime Dome
17:00
17:00
20min
The Time Is Now, The Person Is You
D

Boy, things sure are bad! But as the line famously goes - "don't mourn, organize!"

This talk is about getting involved and building community. You'll get an introduction to a variety of groups in the Puget Sound area that are working toward a future where we can all thrive, with pointers for the types of work each is doing and how you can help. Joining things can be intimidating, so we'll finish with some advice about what to expect when you're getting started and some basics on the dynamics of organizing.

Talks - Prime Dome
Prime Dome
17:30
17:30
20min
Closing Remarks
David Hulton

TBA

Talks - Prime Dome
Prime Dome
19:00
19:00
60min
Nerd Culture in Dance Music
noise

A danceable journey through connections related to geek, sci-fi, and hacker culture.

Music
Yoga Studio Front Lawn
20:00
20:00
60min
Music
mattrix

Matrix is adj

Music
Yoga Studio Front Lawn
21:00
21:00
60min
bash explode (LOVE+FEAR+HATE live set)
bash explode

bash explode will perform his latest album LOVE+FEAR+HATE Vol.1 in it's entirety.

Post-hardcore + Nu metal + Cybergrind + Dubstep = bash explode.

Music
Yoga Studio Front Lawn
22:00
22:00
240min
Saturday Night Party \w Keith Myers and Friends
David Hulton

Keith Myers has an incredible night planned for us all with some great music and guest DJs.

Music
Yoga Studio
No sessions on Sunday, June 28, 2026.