DEF CON 34 · United States · 2026

OWASP SAO (DEF CON 34)

Source-published 15-pixel touch SAO firmware project; physical artifact and handoff unverified

Punk Security's public repository calls its Arduino sketch "the firmware for the OWASP DefCon 34 SAO." Its final public source snapshot provides an actual `main.ino` rather than an event-labelled name alone: it defines 15 addressable RGB pixel positions, three PTC capacitive-touch nodes, and a README that says the SAO header exposes UPDI for reprogramming. This clears the catalogue threshold for a named, source-published pre-event electronic add-on project. It does not establish a final PCB, microcontroller, power path, exact SAO specification, fabricated unit, approved OWASP or DEF CON relationship, price, allocation, pickup, delivered handoff, credential function, or reusable image rights.

EventDEF CON 34
SeriesDEF CON
LocationLVCC West Hall, Las Vegas, Nevada
CountryUnited States

People

Authors & Credits

public repository publisher

Punk Security

This is the named public GitHub repository publisher. It does not establish a particular person's identity, sole hardware or firmware authorship, OWASP or DEF CON affiliation, a physical artifact, event authorization, or image-reuse permission.

Source

public source-commit author

SimonGurney

The final public commit carries this author name. It identifies a source-commit role only and does not establish a real-world identity, sole authorship, hardware manufacture, event affiliation, delivery, or image-reuse permission.

Source

Why It Mattered

It captures a newly published DEF CON 34 source trail while preserving the distinction between a real firmware project and a verified event artifact. The committed code is unusually specific about a 15-pixel interaction surface and three touch nodes, but it contains no board design, release, inventory, or organizer confirmation. Keeping those two facts together makes the record useful without converting public source code into an assertion of hardware delivery or official OWASP sponsorship.

Hardware

The commit-pinned sketch defines `NUM_LEDS = 15`, an addressable-pixel data output on PB3, LED-power control on PB2, and three PTC touch nodes on PA4, PA5, and PA6; its own comment calls those the original badge's three PTC nodes. The public material does not identify the microcontroller part, LED part/package/layout, touch-electrode geometry, PCB, schematic, BOM, SAO version/pinout/orientation, voltage/current limits, battery or power source, protection, enclosure, board revision, assembly, production, electrical test, host test, safety outcome, or final physical-unit parity.

Software & Apps

The public Arduino sketch uses `tinyNeoPixel_Static` and the PTC library for a touch-driven LED-animation surface, while the README credits MegaTinyCore as a firmware foundation and says UPDI is exposed on the SAO header for reprogramming. It is a source snapshot, not a tagged event firmware release: no build configuration, binary, source-to-unit mapping, supported reprogramming workflow, recovery path, security review, privacy statement, support policy, or explicit repository licence was recovered. This catalogue links the source but does not reproduce pin assignments, touch thresholds, animation controls, or programming instructions.

Lore

The repository's public commits date to August 3, 2026, immediately before DEF CON 34. Its README uses the exact OWASP DefCon 34 SAO name, and the final commit carries the public author name SimonGurney under the Punk Security repository. Those are source-publisher statements only: no reviewed OWASP, DEF CON, BadgeLife, village, marketplace, or delivery source confirms an authorized relationship, physical run, availability, attendee handoff, or admission role.

Source-backed hardware metadata

Technical Profile

Structured technical signals seeded from public badge documentation, repositories, schematics, firmware notes, or event evidence. These fields are designed for filtering, API use, repair planning, preservation, and future Companion Gear matching.

Artifact type

  • Electronic badge documented

    Punk Security's public README calls its Arduino sketch firmware for the OWASP DefCon 34 SAO. This classifies a named, source-published electronic add-on project, not a confirmed physical unit, official OWASP or DEF CON artifact, delivered attendee item, or credential.

    Signal source

Connectors

  • SAO documented

    The commit-pinned README calls the project an SAO and says UPDI is exposed on its SAO header. It does not identify a header version, pinout, orientation, power/data wiring, voltage/current limits, protection, host compatibility, or safe connection result.

    Signal source

Display / visual output

  • RGB LEDs documented

    The commit-pinned Arduino sketch defines 15 addressable RGB pixel positions and uses a tinyNeoPixel surface. It does not identify final LED part/package/layout, power budget, brightness/current behavior, installed firmware, or physical-unit parity.

    Signal source

Firmware

  • Arduino documented

    The public `.ino` source uses Arduino APIs, while the README credits MegaTinyCore. This records a source-published firmware surface, not a tagged release, reproducible event build, supported reprogramming workflow, or installed-unit state.

    Signal source

Repair, preservation, and legal lab context

Companion Gear

Parts, tools, and supplies that match this badge's documented hardware, protocols, or preservation needs. These are category-level recommendations, not compatibility guarantees.

SparkFun exact

SAO Headers

Headers and connector supplies for SAO repair, add-on testing, and preservation.

Why this matches

This badge has a documented SAO connector. Matched technical signals: SAO.

Matched evidence

Useful for add-on repair, testing, display, and bench documentation.

Open vendor search

Vendor link · selected for technical relevance

SparkFun likely

Qwiic / I2C Adapters

I2C adapter supplies for badge add-ons, sensors, and lab documentation.

Why this matches

SAO workflows often use I2C-compatible add-on testing and bench documentation. Matched technical signals: SAO.

Matched evidence

Useful for development and documentation of hardware you own or are authorized to work on.

Open vendor search

Vendor link · selected for technical relevance

SparkFun likely

SAO Extension Cables

Extension wiring and jumper supplies for testing or displaying SAO add-ons away from the main badge.

Why this matches

Extension wiring is useful for testing and displaying SAO add-ons. Matched technical signals: SAO.

Matched evidence

Useful for authorized bench testing and display setups.

Open vendor search

Vendor link · selected for technical relevance

Amazon generic

ESD Storage

Anti-static bags and storage supplies for preserving loose badge PCBs and sensitive components.

Why this matches

This is documented as an electronic or hardware artifact where anti-static storage can support preservation. Matched technical signals: Electronic badge.

Matched evidence

Useful for preserving loose PCBs, add-ons, and sensitive electronic components.

Open vendor search

Vendor link · selected for technical relevance

Lifecycle

Add-ons & Upgrades

source-published firmware framework public source snapshot; release and licence unrecovered

Arduino and MegaTinyCore firmware source

The `.ino` source uses Arduino APIs and the README credits MegaTinyCore as a foundation. It establishes a published firmware lineage, not an exact MCU selection, tagged event release, reproducible build, source-to-unit mapping, open-source licence, support commitment, or permission to reuse the source.

Compatibility: OWASP SAO (DEF CON 34); exact MCU, final firmware, and physical unit unverified

Source
source-published interaction firmware commit-pinned source; physical artifact unverified

15-pixel RGB and three-node PTC touch source surface

The public Arduino sketch defines 15 addressable RGB pixel positions and comments that the original badge has three PTC touch nodes; it changes its visual mode through the source's touch-handling path. This records a code-level interaction surface, not exact LEDs or electrodes, tested hardware, final installed behavior, or a safe operating procedure.

Compatibility: OWASP SAO (DEF CON 34); physical board, SAO specification, and host compatibility unverified

Source
source-published programming surface README statement; supported workflow and physical header unverified

UPDI reprogramming source surface

The README says UPDI is exposed on the SAO header for reprogramming. It does not provide or establish a pinout, voltage levels, programmer compatibility, access-control policy, safe procedure, supported recovery path, final-board implementation, or successful event-unit result.

Compatibility: OWASP SAO (DEF CON 34); header specification and safe compatibility unverified

Source

Operational history

Issues & Camp Impact

event association, distribution, and credential boundary note

The project README calls its sketch firmware for the OWASP DefCon 34 SAO, while DEF CON's official registration page establishes the event setting. No reviewed OWASP, DEF CON, BadgeLife, village, marketplace, maker announcement, manufacturing, sales, or delivery source confirms authorization, production, price, stock, recipient eligibility, pickup, shipping, attendee handoff, organizer role, Human-badge status, or admission function.

The exact public event label remains discoverable without turning it into evidence of OWASP or DEF CON endorsement, a physical run, availability, a completed delivery, or a credential.

Confidence
repository's exact DEF CON label and official DEF CON event context
Status
independent pre-event source project; official relationship and handoff unrecovered
Timeframe
2026 pre-event source pass
Source note
DC34-OWASP-SAO repository and commit-pinned README; DEF CON 34 official registration page.
firmware release, license, and operating-procedure boundary note

The repository exposes a README, `main.ino`, and a front-image asset, but no root license file or GitHub-detected repository license was recovered. The reviewed source does not establish a tag or release, binary, complete toolchain/configuration, reproducible build, source-to-unit mapping, signed update, safe UPDI workflow, recovery package, security review, privacy statement, support policy, warranty, or final installed effect set.

The public code is linked as evidence without being presented as licensed, supported, reproducible, safe to reprogram, or equivalent to a delivered event firmware image.

Confidence
repository metadata, root-tree, README, and source review
Status
source snapshot published; tagged release, explicit licence, and supported workflow unrecovered
Timeframe
2026 pre-event source pass
Source note
DC34-OWASP-SAO repository metadata, root contents, commit-pinned README, and main.ino.
missing rights-cleared image note

No OWASP SAO (DEF CON 34) image is published because the current public source trail has not been paired with a reusable original badge or artifact photo or official upstream raster render with source URL, license or permission basis, attribution, and processing notes.

The United States record remains source-backed and image-free rather than copying source-page media, documentation screenshots, event photos, social media, placeholders, or generated approximations.

Confidence
local project policy
Status
needs licensed original replacement
Timeframe
current catalogue build
Source note
badge.gallery image policy and Punk Security's public DC34-OWASP-SAO repository, commit-pinned README and firmware, and official DEF CON 34 registration context.
physical hardware, MCU, power, and SAO-interface boundary note

The README and sketch establish a named OWASP DefCon 34 SAO firmware project, 15 source-level pixel positions, three source-level PTC nodes, and an UPDI statement. They do not identify the microcontroller, LEDs, touch electrodes, PCB, schematic, BOM, board revision, SAO version or pinout, orientation, voltage/current budget, power source, protection, assembly, fabrication, test record, host compatibility, electrical safety, compliance, or a physical unit.

The catalogue records the actual firmware trail without treating source pins or library use as a finished, safe, fabricated, standard-compliant, or plug-and-play add-on.

Confidence
commit-pinned README and Arduino-source review
Status
firmware source published; physical artifact and interface unverified
Timeframe
2026 pre-event source pass
Source note
DC34-OWASP-SAO commit-pinned README and main.ino source snapshot.

Resources

Sources