Issue dossier

The README and sketch establish a named OWASP DefCon 34 SAO firmware project, 15 source-level pixel positions, three source-level PTC nodes, and an UPDI statement. They do not identify the microcontroller, LEDs, touch electrodes, PCB, schematic, BOM, board revision, SAO version or pinout, orientation, voltage/current budget, power source, protection, assembly, fabrication, test record, host compatibility, electrical safety, compliance, or a physical unit.

A linkable camp-impact record with badge context, severity, evidence confidence, and source notes.

Back to issues index

physical hardware, MCU, power, and SAO-interface boundary · commit-pinned README and Arduino-source review · firmware source published; physical artifact and interface unverified

The catalogue records the actual firmware trail without treating source pins or library use as a finished, safe, fabricated, standard-compliant, or plug-and-play add-on.

Badge
OWASP SAO (DEF CON 34)
Category
physical hardware, MCU, power, and SAO-interface boundary
Severity
note
Confidence
commit-pinned README and Arduino-source review
Status
firmware source published; physical artifact and interface unverified
Timeframe
2026 pre-event source pass
Source note
DC34-OWASP-SAO commit-pinned README and main.ino source snapshot.

Evidence

Related Resources

commit-pinned Arduino firmware source

OWASP DEF CON 34 SAO firmware

The public sketch defines 15 addressable RGB positions, LED-power/data controls, and three PTC touch-node source pins. It is source evidence rather than a final release, binary, source-to-unit map, supported reprogramming guide, or proof of a physical event unit.

Badge: OWASP SAO (DEF CON 34)

commit-pinned project documentation

OWASP DEF CON 34 SAO README

The commit-pinned README calls this firmware for the OWASP DefCon 34 SAO, credits MegaTinyCore as a foundation, and says UPDI is exposed on the SAO header for reprogramming. It does not identify the exact MCU, final physical artifact, connector pinout, host compatibility, safe procedure, or event delivery.

Badge: OWASP SAO (DEF CON 34)

immutable public firmware snapshot

OWASP DEF CON 34 SAO commit-pinned source snapshot

The final public commit snapshot fixes the reviewed README and Arduino sketch. It documents a source-level 15-pixel, three-touch-node interaction surface, but not a microcontroller part, PCB, SAO header specification, power design, completed hardware, release, or image-reuse basis.

Badge: OWASP SAO (DEF CON 34)

official event registration page

DEF CON 34 official registration context

DEF CON's official registration page provides DEF CON 34 dates, location, and Human-badge context only. It does not name this OWASP SAO, approve it, establish a maker or village role, confirm distribution, or make it an admission credential.

Badge: OWASP SAO (DEF CON 34)

public independent firmware repository

OWASP DEF CON 34 SAO source repository

Punk Security's public repository root contains a README, `main.ino`, and an unlicensed front-image asset. Its README calls the sketch firmware for the OWASP DefCon 34 SAO. The repository establishes a named source-published project, not a final PCB, official OWASP or DEF CON authorization, manufacture, allocation, delivery, credential use, or image-reuse permission.

Badge: OWASP SAO (DEF CON 34)

Source trail

Evidence Sources

Punk Security / GitHub · retrieved 2026-05-15

DC34-OWASP-SAO README

Primary commit-pinned project statement naming the OWASP DefCon 34 SAO, MegaTinyCore context, and exposed UPDI statement. It does not establish OWASP endorsement, exact MCU, production, host behavior, supported reprogramming, or delivery.

Badge: OWASP SAO (DEF CON 34)

Punk Security / GitHub · retrieved 2026-05-15

DC34-OWASP-SAO main.ino

Primary commit-pinned Arduino source for 15 addressable RGB positions and three PTC touch nodes. The code establishes source-level behavior, not a final hardware design, deployed firmware, final effect set, safe operation, or physical-unit parity.

Badge: OWASP SAO (DEF CON 34)

Punk Security / GitHub · retrieved 2026-05-15

OWASP DEF CON 34 SAO source snapshot

Commit-pinned primary source tree for the final public README and Arduino sketch. It establishes a firmware source surface only, not a specific board configuration, correct assembly, electrical safety, compatible host, event deployment, or image-reuse license.

Badge: OWASP SAO (DEF CON 34)

Punk Security / GitHub · retrieved 2026-05-15

punk-security/DC34-OWASP-SAO

Primary public repository whose README calls `main.ino` firmware for the OWASP DefCon 34 SAO. It supports a named independent event-labelled source project, not final hardware, official OWASP or DEF CON status, manufacture, allocation, completed handoff, credential function, or reusable image permission.

Badge: OWASP SAO (DEF CON 34)