Carnegie Mellon Team Grabs the Most Flags in DEF CON Competition

There are hackers, and then there are victors. Carnegie Mellon University's computer hacking team, the Plaid Parliament of Pwning (PPP), has for the second year running taken first place in a Capture the Flag competition at the DEF CON hacker convention.

In this type of contest participants have servers that they need to keep running and that every other team is trying to break into. Teams use whatever resources they have — Web hacking, patching, forensics, programming, binary reverse engineering, cryptography — to ward off attackers, wreak havoc on competitors, and steal away points. Or as organizer Legitimate Business Syndicate put it, "Fortune looks kindly upon boldness and skill. Failing those, she also seems pretty okay with treachery and subversion."

"Our team competed against universities and also against large defense contractors. This win is a huge accomplishment," said David Brumley, an associate professor of electrical and computer engineering and technical director of Carnegie Mellon CyLab. PPP grew out of an undergraduate computer security research group and currently has 35 students from the College of Engineering and the School of Computer Science. For the latest DEF CON, the team was limited to eight people.

"Our first day was a bit rough, but once we got in the swing of things we were able to take the lead pretty quickly," said team member Tyler Nighswander. "I think teamwork is really what gave us an edge and let us work so efficiently together."

cmu, a second CyLab team, won the Street Division category in "Crack Me If You Can," a 48-hour contest sponsored by security services firm KoreLogic Security. That activity required teams to expose or "crack" encrypted passwords; the goal: "to help push the envelope of password cracking techniques." The Carnegie Mellon team for that included one high schooler, Jonathan Bees, who interned in CyLab's Usable Privacy & Security (CUPS) Lab.

About the Author

Dian Schaffhauser is a former senior contributing editor for 1105 Media's education publications THE Journal, Campus Technology and Spaces4Learning.

Featured

  • closeup of hands typing on laptop with AI imagery overlaid

    Copilot Fall Update Introduces New Features

    Microsoft has unveiled a major update to its Copilot AI platform, adding new features to make the system more personalized, collaborative, and integrated across its suite of products.

  • magnifying glass revealing the letters AI

    New Tool Tracks Unauthorized AI Usage Across Organizations

    DevOps platform provider JFrog is taking aim at a growing challenge for enterprises: users deploying AI tools without IT approval.

  • Hand holding a stylus over a tablet with futuristic risk management icons

    Why Universities Are Ransomware's Easy Target: Lessons from the 23% Surge

    Academic environments face heightened risk because their collaboration-driven environments are inherently open, making them more susceptible to attack, while the high-value research data they hold makes them an especially attractive target. The question is not if this data will be targeted, but whether universities can defend it swiftly enough against increasingly AI-powered threats.

  • interconnected blocks of data

    Rubrik Intros Immutable Backup for Okta Environments

    Rubrik has announced Okta Recovery, extending its identity resilience platform to Okta with immutable backups and in-place recovery, while separately detailing its integration with Okta Identity Threat Protection for automated remediation.