PCMag editors select and review products independently. If you buy through affiliate links, we may earn commissions, which help support our testing.

10-Year-Old Presents App Exploit at DefCon

 & Sara Yin Junior software analyst

Our team tests, rates, and reviews more than 1,500 products each year to help you make better buying decisions and get more from technology.

Our Expert
LOOK INSIDE PC LABS HOW WE TEST
65 EXPERTS
43 YEARS
41,500+ REVIEWS

DefCon, the long-running, annual hacker conference in Las Vegas, lowered its age restrictions this year for the inaugural "DefCon Kids Village."

Roughly 60 young hacker-wannabes aged eight to 16 were mentored in the arts of "white hat" hacking, or hacking in a responsible manner, this past weekend. They listened to talks by Black Hat and DefCon founder Jeff Moss, a.k.a. "The Dark Tangent," Steven Levy, a writer for Wired, and Johnny Long, best known for using Google Search to discover security loopholes. The kids were taught how to open Master locks, Google hacking, social engineering, coding in Scratch, and more.

CyFi, a ten-year-old Girl Scout and DefCon Kids co-founder from California, presented her findings on an exploit in an unnamed social game. She began tinkering with the code after growing impatient with the game's slow place, and discovered that by disconnecting her phone from Wi-Fi and re-setting the clock forward in small increments, she could fast-forward many of the actions in the game, "a new class of vulnerabilities" she dubbed "TimeTraveler."

CyFi presented her findings at a talk called "Apps—A Traveler of Both Time and Space, And What I Learned About Zero-Days and Responsible Disclosure."

"The world of apps has obviously not thought about security yet," read the presentation summary. "Here is an important lesson they can learn from a Girl Scout. I'll show a new class of vulnerabilities I call TimeTraveler. By controlling time, you can do many things, such as grow pumpkins instantly. This technique enables endless possibilities. I'll show you how. Wanna play a game? Let's find some zero-days! (Cuz it's fun!)"

In the spirit of responsible disclosure CyFi did not publicize the names of the apps she'd cracked in order to allow the companies affected time to fix the vulnerabilities.

About Our Expert

Sara Yin

Sara Yin

Junior software analyst

Sara Yin is a junior analyst in the Software, Internet, and Networking group at PCmag.com, pouring most of her energy into app testing and security matters at Security Watch with Neil Rubenking. She lies awake at night pondering the state of mobile security (half-true). Prior to joining PCMag.com, Sara spent five years reporting for publications in New York City (Huffington Post), Hong Kong (South China Morning Post), and Singapore (Campaign Asia, Men's Health). Follow her on Twitter at @SecurityWatch and @sarapyin, or contact her the old school way: email. That's sara_yin AT pcmag.com.

Read full bio