Not just specs

Issues & Camp Impact

Safety warnings, delivery problems, app-store gaps, team-process history, and first-hand reports are tracked as sourced records.

Reset
2166 matching issue record(s)

badge-sponsor relationship, allocation, and handoff boundary · official event recap, Punk sponsor listing, and maker archive · completed event and sponsor badge documented; recipient scope unrecovered

The official recap reports 200 checked-in participants, Punk Security identifies itself as badge sponsor, and its archive identifies the Space Badge for the event. The reviewed sources do not give a production count, ticket-tier eligibility, role allocation, recipient list, pickup/handoff record, replacement policy, or proof that all 200 checked-in participants received the badge.

The catalogue records a completed event-associated electronic badge without turning sponsorship or attendance totals into a universal allocation claim.

Source note: BSides Newcastle 2025 official recap; Punk Security event listing; Space Badge repository.

badge-sponsor relationship, allocation, and handoff boundary · official organizer sources, Punk sponsor listing, and maker archive · completed event and sponsor badge documented; recipient scope unrecovered

Organizer sources establish the completed October 3 Grand Pier conference, Punk Security identifies itself as badge sponsor, and its archive identifies the Crab Badge for the event. The reviewed sources do not give a production count, ticket-tier eligibility, role allocation, recipient list, pickup/handoff record, replacement policy, or proof that all conference attendees received the badge.

The catalogue records a completed event-associated electronic badge without turning sponsorship or attendance evidence into a universal allocation claim.

Source note: CSIDES sponsors page and Eventbrite listing; Punk Security event listing; Crab Badge repository.

badge-sponsor relationship, allocation, and handoff boundary · official event context, Punk sponsor listing, and maker archive · completed event and sponsor badge documented; recipient scope unrecovered

The official event page reports 200+ attendees, Punk Security identifies itself as badge sponsor and advertises skull badges, and its archive identifies the Skull Badge for the event. The reviewed sources do not give a production count, ticket-tier eligibility, role allocation, recipient list, pickup/handoff record, replacement policy, or proof that all reported attendees received the badge.

The catalogue records a completed event-associated electronic badge without turning sponsorship or attendance evidence into a universal allocation claim.

Source note: BSides Bournemouth 2025 official page and Security BSides listing; Punk Security event listing; Skull Badge repository.

badge-sponsor relationship, allocation, and handoff boundary · official event sources, Punk sponsor listing, and maker archive · completed event and sponsor badge documented; recipient scope unrecovered

The organizer sources establish the completed April 26 conference, Punk Security identifies itself as badge sponsor, and its archive says the Pirate Ship Badge was given out at BSides Exeter. The reviewed sources do not give a production count, ticket-tier eligibility, role allocation, recipient list, pickup/handoff record, replacement policy, or proof that all attendees received the badge.

The catalogue records a completed event-associated electronic badge without turning sponsorship or a broad maker distribution statement into a universal allocation claim.

Source note: BSides Exeter 2025 organizer ticket page and Security BSides listing; Punk Security event listing; Pirate Ship Badge repository.

badge-team role and allocation boundary · official team and programme pages · team-section credit available; work scope and recipients unreleased

The current team page lists Pedro Umbelino under Badge, while the About page promises an electronic badge. Neither page identifies design, hardware, firmware, manufacturing, sponsor, security review, support, ownership, licensing, compensation, or the final recipient scope.

A visible team credit can be preserved without claiming that the named person designed or built a particular device, or that any attendee class receives it.

Source note: BSidesLisbon 2026 Team and About pages.

badge-type, allocation, and credential boundary · official current registration, ticketing, and CFP sources · documented badge categories; individual allocation unverified

Official sources distinguish participant, donor, volunteer, speaker/mentor, and special conference badge paths, while also describing a participant badge for a speaker or mentor's designated plus-one. They do not publish a recipient ledger, final count, transfer policy for all badge types, exact privilege matrix, pickup confirmation for a named person, or a design/specification tying every category to one physical artifact.

The record describes the participant badge and its documented access context without treating every 2026 badge label as identical, universally issued, or an interchangeable DEF CON credential.

Source note: BSides Las Vegas 2026 Registration Information, Humanitix ticketing, Volunteer Guide, and CFP.

battery, EMF, and electrical-safety boundary · primary maker listing · needs technical and safety documentation

The maker names a protected 18650 battery and a live EMF detector, but publishes no cell capacity/identity, charge or protection implementation, current/thermal data, fault behavior, replacement procedure, safety certification, sensor identity, calibration, accuracy, interference behavior, or usage limits.

The catalogue does not turn the seller's protected-battery and EMF language into a safety endorsement, electrical-service guide, calibrated-instrument claim, or paranormal-detection claim.

Source note: Spectre Sniffer Badge listing.

battery, charging, and modification safety boundary · primary maker storefront source · needs operating and safety documentation

The maker lists LiPo power, battery-management components, thermal monitoring, a buck-boost supply, and fast-charging support, plus a polycarbonate battery enclosure. It does not publish cell make/model, charge-current configuration, temperature thresholds, fault behavior, battery replacement procedure, current limits, safety guidance, certification, or modification instructions.

The record does not convert component names or marketing language into an electrical-safety endorsement, battery-service guide, or safe-modification claim.

Source note: Uberflux Shitty Kitty V2 product listing.

battery, charging, and modification safety boundary · primary organizer store and public repository · needs operating and safety documentation

The store names a 2,000 mAh LiPo and USB-C recharging with overcharge protection, while the source tree supplies firmware and board files. Neither reviewed source publishes battery cell identity, charge settings, thermal/current measurements, fault behavior, battery replacement procedure, safety certification, or a safe-modification guide.

The record does not transform source component claims into an electrical-safety endorsement, battery-service procedure, or sanctioned repair/modification instruction.

Source note: Gothcon Badge Store listing and gothcon-firmware repository.

battery, charging, and modification safety boundary · maker listing, firmware README, and CAD repository · needs final operating and safety documentation

Sources describe a Li-ion/18650 power path, USB-C charging/updating, TP4056 on early revisions, BQ25672 on v3, and 3D-printed mechanical modifications. They do not publish cell identity/capacity for the offered unit, charger settings, protection test results, current/thermal data, replacement procedure, certification, fault behavior, safe printed-material guidance, or a sanctioned modification process.

The catalogue does not turn public power or CAD material into a battery-service guide, electrical-safety endorsement, charging claim, or safe-modification authorization.

Source note: Celestial Wayfinder listing, firmware README, and Wayfinder-CAD README.

battery, charging, multi-SAO power, and host-safety documentation gap · maker high-level README · power claims documented; engineering validation absent

The README names two 18650 batteries, USB/barrel paths, stated 30 mA and 300 mA conditions, and surge protection, but does not publish cell chemistry/brand/protection, battery holder, charging/power-path circuit, fuse ratings, regulator design, input voltage limits, per-port power allocation, inrush, thermal, short-circuit, reverse-polarity, ESD, fault, battery-transport, or host-compatibility tests.

The record does not convert a high-level power-budget statement into a battery-safety instruction, a guaranteed power supply, or a safe multi-SAO integration certificate.

Source note: DC33-SaO-MANY-SAOs README and product page.

battery, power, and SAO host-compatibility gap · official high-level product description · needs technical and safety documentation

The product names two AAA batteries, a regulated 3.3 V supply, and a Sphere SAO claimed to work with upside-down SAO ports, but provides no voltage/current envelope, battery-holder details, power path, polarity/short protection, runtime, thermal data, charging/transport guidance, pinout, electrical test result, or supported-host matrix.

The catalogue preserves the seller's limited power/SAO statements without treating them as safe-use instructions, universal host compatibility, a battery-safety endorsement, or an electrical specification.

Source note: Zach's Hacks product page.

battery, power, antenna, radio, and safety documentation gap · maker component-level claims · needs final engineering documentation and testing

Public sources identify a 400 mAh 3.7 V LiPo, XIAO ESP32-S3, LCD, LEDs, vibration motor, and an external 2.4 GHz antenna path, but do not provide charger/protection circuit details, battery vendor/specification, current draw/runtime, USB power behavior, fusing, voltage/current limits, antenna gain/matching, RF emissions/compliance, enclosure/fire/drop testing, environmental limits, user warnings, or safety/compliance evidence.

The record retains source-named components without presenting the badge as electrically complete, radio-compliant, safe to charge/carry, or suitable for every configuration.

Source note: DC801 Helgatchi Badge product page and Pips801/Helgatchi repository.

beta firmware, sensitive-data, and security-critical-use boundary · public firmware README · public source explicitly pre-1.0 beta

The later public CDC Badge OS README states that flashing can wipe stored FIDO2/U2F credentials, TOTP seeds, password-vault entries, GPG keys, and PIN data; it calls the project a proof of concept/demonstrator and says not to use it as-is for production or security-critical deployments.

The record may describe the public software capability surface but does not endorse the firmware, vouch for its cryptography, privacy, data durability, or safety, or imply it was the software deployed at 39C3.

Source note: krim404/cdc-badge-os README.

build and USB caveat · primary docs · documented

The build guide requires a Linux machine tested on Ubuntu 22.04 and 24.04 and warns the Buildroot build can take around an hour and a half; the FAQ also documents Windows, macOS USB-C, Wi-Fi, SSH, keyboard, and battery-reset caveats.

The record presents Winglet OS as publicly buildable and hackable while making clear that toolchain, USB, and access workflows are not frictionless for every host.

Source note: Building Winglet OS guide and AV Badge FAQ.

builder-completion caveat · primary project and Hackaday article · documented

Public sources describe the badge as a PCB canvas with space for builders to add their own electronics, including a MicroMod variant, rather than a complete stock electronics-and-firmware package.

The record avoids inventing a fixed MCU, app set, puzzle, or firmware behavior for the base Remoticon.2 template.

Source note: Hackaday article, Hackaday.io project description, file list, and project logs.

challenge integration gap · self-identified challenge source · needs challenge walkthrough

ShenLabs explicitly identifies itself as a BSides Roanoke 2026 badge challenge, but no reviewed source explains how the participant badge connected to the web puzzle, its clues, a QR/URL/credential mechanism, a solution, or any reward path.

The catalogue can document the declared challenge companion without claiming that it was firmware, a badge-hosted application, or a particular physical interaction.

Source note: ShenLabs footer and reviewed BSides Roanoke / organizer ticketing sources.

challenge, multiplayer, privacy, and behavior boundary · official maker pages · marketing-level behavior only

The project page and listing differ between 30-plus and 35-plus CTF/puzzle wording and make high-level multiplayer/link-up/word-building claims. They do not publish final challenge inventory, spoilers policy, rules, score validation, pairing/transport protocol, range, player-data handling, threat model, privacy/security review, accessibility details, event support, or a stable behavior contract.

The catalogue preserves the game and collaboration claims without inventing a final challenge count, protocol, network/privacy guarantee, completed event experience, or solution material.

Source note: BigTaro Wordweaving project page and Uberflux product page/payload.

challenge-artifact caveat · source-backed but incomplete · needs deeper artifact inventory

Public sources document hardware, firmware updates, SAO/IR hints, serial/Morse material, and solving paths, but this pass does not mirror or audit every firmware image, forum attachment, add-on, or final badge state.

The catalogue records the verified hardware and challenge surfaces while leaving full artifact preservation for a later pass.

Source note: DEF CON forum badge-hacking thread, Hackaday hands-on article, and Science Viking Labs writeup.

challenge-artifact classification · official C517 source plus first-hand finalist writeup · documented

The ESP32 trinket is documented as a TISC finals challenge device handed to finalists, not as an all-attendee DEF CON Singapore badge or universal conference credential.

The catalogue includes it as a source-backed C517 Village challenge artifact while avoiding an official admission-badge claim.

Source note: CSIT C517 Village page, U-Zyn Chua finalist writeup, and DEF CON Singapore event page.

challenge-completion caveat · primary retrospective · documented

The retrospective says more than four dozen people actively worked on the B.E.N.D.E.R. challenges, but that no individual player beat the full game during the event because progress was spread across different challenge areas and social collaboration did not converge in time.

The software record describes the intended and observed challenge surface without implying a completed public solve path for every attendee.

Source note: AND!XOR DC26 retrospective.

challenge-detail caveat · official source but intentionally narrow · needs post-event walkthrough

The badge-challenge page deliberately withholds hints and says it is possible there may not be a winner this year; this pass did not recover an official puzzle solution, final badge artwork, clue inventory, or challenge source archive.

The entry keeps the challenge description narrow until an official or first-hand walkthrough appears.

Source note: BSides Tampa 2026 badge-challenge page.

challenge-details, participant-data, software-release, support, and license boundary · public Player Guide only · high-level player guide published; complete archive and terms unrecovered

The guide describes a badge-local quest, configurable participant handle, local network settings, saved progress, serial interaction, and reset/recovery concepts, but the reviewed repository exposes no implementation source, firmware/binary, board files, release/tag, license, build/deployment record, challenge-state/data-retention policy, privacy/security review, event terms, vulnerability policy, recovery package, support channel, warranty, or image-reuse grant. The guide itself directs use only of the assigned badge and advertised services.

The catalogue intentionally does not reproduce connection credentials, network or local-service details, flags, hidden resources, challenge hints, serial commands, reset steps, or exploit material; it also does not imply a privacy/security review, safe operational configuration, reproducible build, legal reuse, or ongoing support.

Source note: The Shattered Shard Player Guide and repository root, reviewed 2026-08-05.

coin-cell brownout and field-repair history · first-person maker account · maker-reported repair applied; affected scope and final validation unverified

The maker reports that the original coin-cell setup could brown out after roughly two minutes, then says more than 200 already programmed badges were reprogrammed before distribution and informally appeared to have substantially improved battery life. The source does not provide a controlled test, exact firmware change, affected-unit count, serial/revision mapping, battery characterization, follow-up failure rate, or confirmation that every distributed unit received the repair.

The record keeps an attributable production/reliability history visible without offering repair instructions, declaring the hardware safe, or generalizing a maker observation into a verified universal outcome.

Source note: Terence Chan Zun Mun's public Greycademy Hackbadge account.

collection-boundary caveat · official MiniBadges page · documented

The 2021 archived page documents many MiniBadges with distinct status, community, contest, booth, personal, and unofficial acquisition paths, so this record is a collection entry rather than a single universal attendee-issued main badge.

The catalogue preserves the MiniBadge ecosystem while keeping per-board authorship, distribution, electronics, and official/unofficial status boundaries separate.

Source note: SAINTCON 2021 Content - MiniBadges page.

collection-boundary caveat · official guide category definitions · documented

The 2022 assembly guide covers official, sponsor, and personal MiniBadges, so this record is a documented collection entry rather than a claim that every listed PCB was a universal conference-issued attendee badge.

The catalogue preserves the MiniBadge ecosystem while keeping acquisition routes, creator roles, and support boundaries separate from main-badge distribution claims.

Source note: MiniBadges-of-2022 assembly guide official, sponsor, and personal category definitions.

collection-boundary caveat · official FAQ plus community data export · documented

The 2023 public evidence supports a MiniBadge ecosystem with official, community, contest, and personal entries, not a single uniform attendee-issued main badge or a claim that every listed board was organizer-built.

The catalogue preserves the verified trading and collection surface while keeping per-board authorship, acquisition, electronics, and support boundaries narrow.

Source note: SAINTCON 2023 FAQ and MiniBadge Wiki 2023 data export.

collection-boundary caveat · official trading page plus standards trail · documented

The official 2024 page describes submitted and official MiniBadges brought to the conference, so this record models a collection/trading ecosystem rather than a single uniform attendee-issued main badge.

The catalogue preserves the verified BadgeLife surface while avoiding unsupported claims about universal distribution, per-MiniBadge electronics, or official status for every submitted design.

Source note: SAINTCON 2024 MiniBadge trading page and 2024 build-guide link.

community-event access-rule and final-event-outcome boundary · official DEFCON Furs event-space and meetup schedules · badge-required event-space wording published; implementation and outcome unrecovered

The official Furry Village schedule says DEFCON Furs badge required and lists badge pickup, and the meetup schedule lists pickup sessions. Neither page identifies credential material, visual design, barcode, QR, RFID/NFC access use, account linkage, reader, venue verification process, staff discretion, revocation, personal-data practice, actual operation, or every attendee's completed pickup or entry result.

The catalogue records the published DEFCON Furs event-space boundary without inventing a technical access-control system or a record of individual access.

Source note: DEFCON Furs 2026 Furry Village and meetup schedules.