The badge handed out at this year's Defcon, the long-running hacker and security conference, is more than a conference credential. According to Wired, it carries a chip called the Baochip-1x — an open source processor whose security properties can be independently verified, and which can double as a hardware security token of the sort people use to log into online accounts.
The chip was created by Andrew "bunnie" Huang, described by Wired as a legendary hardware hacker. Wired reports that the badges are meant to push the boundaries of security and transparency.
The aggregator Techmeme, summarizing Kim Zetter's reporting for Wired, describes the Baochip-1x the same way: an open source chip whose security is verifiable, usable as a hardware security token.
Why this is unusual is worth spelling out. Nearly every security chip in a phone, laptop, or plug-in login key is a black box. Users are asked to trust that the manufacturer built it correctly and that nobody slipped anything extra inside, because the design itself is proprietary and cannot be inspected. An open design inverts that arrangement: the blueprints are public, so claims about what the chip does — and doesn't — can be checked rather than taken on faith.
Defcon badges have a tradition of being elaborate hardware projects rather than laminated name tags, and putting a verifiable chip in the hands of thousands of security researchers is also, functionally, an invitation to try to break it.
It matters because the hardware that guards our accounts and data has long asked for blind trust, and a chip anyone can inspect is a test of whether that trust can be earned in the open instead.