Issue dossier
The repository exposes C source plus tracked hex/ELF files and describes a possible convention reflash, but the reviewed root has no explicit LICENSE/COPYING file, release/tag, checksum, version-to-board mapping, fuse map, programmer package, update image, recovery path, dependency lock, security review, vulnerability policy, support policy, or warranty. The README's build outline does not itself grant reuse rights or establish a supported update path.
A linkable camp-impact record with badge context, severity, evidence confidence, and source notes.
Back to issues index
firmware release, update, support, and licence gap · public source-tree review · source and compiled artifacts visible; explicit release/licence/support terms absent
The catalogue can link the implementation without presenting it as licensed open hardware/software, a stable release, a reproducible final build, a safe reflashing process, or an ongoing support commitment.
- Badge
- NilbinSec DC34 Main Badge Fuzzer SAO
- Category
- firmware release, update, support, and licence gap
- Severity
- note
- Confidence
- public source-tree review
- Status
- source and compiled artifacts visible; explicit release/licence/support terms absent
- Timeframe
- repository rechecked 2026-08-04
- Source note
- NilbinSec repository root, README, Firmware/Makefile, and tracked firmware artifacts.
Evidence
Related Resources
NilbinSec public project repository
Maker-controlled public repository whose description identifies the artifact as a DC34 conference-badge fuzzing SAO. Its root exposes the README, KiCad schematic, BOM CSV, PCB archive, firmware source, and compiled firmware files, but no explicit root licence or release is visible.
Badge: NilbinSec DC34 Main Badge Fuzzer SAO
maker operating documentation
Primary maker documentation for the intended DEF CON 34 main-badge target, the three initial modes, selector/trigger use, potential badge-damage warning, possible convention reflash statement, flashing outline, and claim that Gerbers, schematic, BOM, and firmware are included.
Badge: NilbinSec DC34 Main Badge Fuzzer SAO
public firmware source
Primary C implementation source for the ATtiny1614 target, GPIO stimulation, open-drain wake assertion, passive I²C listener, LED/button mappings, 0x08–0x77 sweep implementation, 0x19/0x3C skip list, UART debug surface, and serialUPDI context. It is source code, not proof of final on-site firmware or a licence grant.
Badge: NilbinSec DC34 Main Badge Fuzzer SAO
public hardware source
Public tree containing DCBadgeFuzzer.kicad_sch, DCBadgeFuzzer.csv, and a PCB archive. The BOM records the ATtiny1614, SAO v1.69bis connector, two switches, four LEDs, 1×3 connector, resistors, and capacitors, but does not establish a final manufactured revision, test evidence, or media-reuse permission.
Badge: NilbinSec DC34 Main Badge Fuzzer SAO
Source trail
Evidence Sources
GitHub / NilbinSec · retrieved 2026-05-15
Primary maker-controlled project source identifying a NilbinSec SAO for the DC34 conference badge and exposing the technical source tree. It does not prove DEF CON organizer issuance, target-badge authorization, a sale or giveaway, production volume, completed handoff, final firmware, or reusable-image rights.
Badge: NilbinSec DC34 Main Badge Fuzzer SAO
GitHub / NilbinSec · retrieved 2026-05-15
Primary maker source for the pre-event main-badge fuzzing purpose, the three documented modes, input/LED behavior, warning that Mode 1 may harm a badge, prospective reflash wording, and build/flash guidance. It presents intended behavior, not a guaranteed or authorized outcome on a final badge.
Badge: NilbinSec DC34 Main Badge Fuzzer SAO
GitHub / NilbinSec · retrieved 2026-05-15
Primary BOM source naming the ATtiny1614-SS, four LEDs, two switches, SAO v1.69bis connector, J1 1×3 connector, 470-ohm resistors, and capacitors. It documents the public design inputs only, not final component substitutions, electrical characterization, production, safety, or a hardware licence.
Badge: NilbinSec DC34 Main Badge Fuzzer SAO
GitHub / NilbinSec · retrieved 2026-05-15
Primary implementation source for the ATtiny1614, GPIO/LED/button mapping, GPIO stimulus/release/sample loop, open-drain wake behavior, passive I²C implementation, 0x08–0x77 sweep, and skip list. It differs from the README's broad 0x00–0x7F description and does not establish a released final binary or explicit licence.
Badge: NilbinSec DC34 Main Badge Fuzzer SAO