Issue dossier
The project README calls its sketch firmware for the OWASP DefCon 34 SAO, while DEF CON's official registration page establishes the event setting. No reviewed OWASP, DEF CON, BadgeLife, village, marketplace, maker announcement, manufacturing, sales, or delivery source confirms authorization, production, price, stock, recipient eligibility, pickup, shipping, attendee handoff, organizer role, Human-badge status, or admission function.
A linkable camp-impact record with badge context, severity, evidence confidence, and source notes.
Back to issues index
event association, distribution, and credential boundary · repository's exact DEF CON label and official DEF CON event context · independent pre-event source project; official relationship and handoff unrecovered
The exact public event label remains discoverable without turning it into evidence of OWASP or DEF CON endorsement, a physical run, availability, a completed delivery, or a credential.
- Badge
- OWASP SAO (DEF CON 34)
- Category
- event association, distribution, and credential boundary
- Severity
- note
- Confidence
- repository's exact DEF CON label and official DEF CON event context
- Status
- independent pre-event source project; official relationship and handoff unrecovered
- Timeframe
- 2026 pre-event source pass
- Source note
- DC34-OWASP-SAO repository and commit-pinned README; DEF CON 34 official registration page.
commit-pinned Arduino firmware source
The public sketch defines 15 addressable RGB positions, LED-power/data controls, and three PTC touch-node source pins. It is source evidence rather than a final release, binary, source-to-unit map, supported reprogramming guide, or proof of a physical event unit.
Badge: OWASP SAO (DEF CON 34)
commit-pinned project documentation
The commit-pinned README calls this firmware for the OWASP DefCon 34 SAO, credits MegaTinyCore as a foundation, and says UPDI is exposed on the SAO header for reprogramming. It does not identify the exact MCU, final physical artifact, connector pinout, host compatibility, safe procedure, or event delivery.
Badge: OWASP SAO (DEF CON 34)
immutable public firmware snapshot
The final public commit snapshot fixes the reviewed README and Arduino sketch. It documents a source-level 15-pixel, three-touch-node interaction surface, but not a microcontroller part, PCB, SAO header specification, power design, completed hardware, release, or image-reuse basis.
Badge: OWASP SAO (DEF CON 34)
official event registration page
DEF CON's official registration page provides DEF CON 34 dates, location, and Human-badge context only. It does not name this OWASP SAO, approve it, establish a maker or village role, confirm distribution, or make it an admission credential.
Badge: OWASP SAO (DEF CON 34)
public independent firmware repository
Punk Security's public repository root contains a README, `main.ino`, and an unlicensed front-image asset. Its README calls the sketch firmware for the OWASP DefCon 34 SAO. The repository establishes a named source-published project, not a final PCB, official OWASP or DEF CON authorization, manufacture, allocation, delivery, credential use, or image-reuse permission.
Badge: OWASP SAO (DEF CON 34)
DEF CON · retrieved 2026-05-15
Official event source for the DEF CON 34 setting. It does not name Punk Security's source project, an OWASP SAO, an authorized relationship, allocation, sale, giveaway, handoff, credential function, or image rights.
Badge: OWASP SAO (DEF CON 34)
Punk Security / GitHub · retrieved 2026-05-15
Primary commit-pinned project statement naming the OWASP DefCon 34 SAO, MegaTinyCore context, and exposed UPDI statement. It does not establish OWASP endorsement, exact MCU, production, host behavior, supported reprogramming, or delivery.
Badge: OWASP SAO (DEF CON 34)
Punk Security / GitHub · retrieved 2026-05-15
Primary commit-pinned Arduino source for 15 addressable RGB positions and three PTC touch nodes. The code establishes source-level behavior, not a final hardware design, deployed firmware, final effect set, safe operation, or physical-unit parity.
Badge: OWASP SAO (DEF CON 34)
Punk Security / GitHub · retrieved 2026-05-15
Commit-pinned primary source tree for the final public README and Arduino sketch. It establishes a firmware source surface only, not a specific board configuration, correct assembly, electrical safety, compatible host, event deployment, or image-reuse license.
Badge: OWASP SAO (DEF CON 34)
Punk Security / GitHub · retrieved 2026-05-15
Primary public repository whose README calls `main.ino` firmware for the OWASP DefCon 34 SAO. It supports a named independent event-labelled source project, not final hardware, official OWASP or DEF CON status, manufacture, allocation, completed handoff, credential function, or reusable image permission.
Badge: OWASP SAO (DEF CON 34)