DEF CON's Franklin project turns hacker ingenuity on critical infrastructure
Curated by the Inblix editorial team
Jeff Moss has a problem with how we secure critical infrastructure. “We’ve been doing it wrong,” the DEF CON founder essentially told the crowd this week, and he’s betting the entire conference on a different approach.
The Franklin project, named after Benjamin Franklin’s volunteer fire department, is scaling up a model that already proved itself in the Voting Village. For years, hackers there found vulnerabilities in election systems that vendors and government auditors missed entirely. Now Moss is applying that same adversarial mindset to water systems, power grids, and other infrastructure most people don’t think about until the lights go out.
The shift is from passive bug bounties to active, structured collaboration between hackers and infrastructure operators. It’s the difference between locking your door and actually trying to break in to see what gives. The Voting Village results weren’t just academic — they led to real changes in how states procure and configure election equipment.
What’s different here is the scale and the stakes. Critical infrastructure is a patchwork of legacy systems, proprietary protocols, and underfunded IT departments. Throwing a DEF CON’s worth of creative, persistent hackers at that problem will surface issues that compliance checklists never catch. The question isn’t whether they’ll find serious vulnerabilities. It’s whether the operators will patch them faster than adversaries can exploit them. Moss seems to think shame is a powerful motivator — nobody wants to be the utility that ignored a DEF CON finding and got breached six months later.
💡 Key Takeaways
- The Voting Village model proved that adversarial hackers find vulnerabilities compliance audits miss, and Moss is now betting the entire DEF CON conference on extending that approach to water systems and power grids.
- Franklin is a structural shift from passive vulnerability reporting to active collaboration, pairing hackers directly with infrastructure operators who typically rely on checkbox security assessments.
- The real test isn't discovery — it's whether under-resourced utility operators can patch what hackers surface before adversaries weaponize the same flaws against them.
Keep reading: See related articles below for more coverage on this topic.
Get smarter about AI
The sharpest AI news, curated daily. Delivered free to your inbox.