DEF CON 34 · AND!XOR badge

We took the badge apart
and built two tools for it.

The AND!XOR DC34 badge runs on light-genes and a tiny display. So we made it do what we wanted — push any image to it from a phone, and breed designer light patterns straight into it with a single QR code.

0
bytes uploaded anywhere
WebUSB
works from your phone
AES-GCM-SIV
gene exchange, reversed

A badge that grows its own light show.

The DC34 badge doesn't just blink a fixed pattern. It carries a genome — nine bytes that describe how its LEDs breathe, chase, and shift hue — and it breeds with other badges over QR codes to mix new patterns. That's the game. These two tools let you win it on your terms.

🖼️

The display

A small screen you can drive with any image or icon. Stock, that means fiddling with a keyboard. We wanted a phone.

🧬

The light-genes

Nine haploid bytes — period, rate, direction, saturation, hue base and bound, chaser, nonlinearity — define the whole animation.

🔥

The breeding

Two badges swap gametes over QR and produce a child pattern. Deterministic crypto guards the exchange — which is exactly what we leaned on.

Badge Uploader

Push any image to the badge display straight from your phone's browser. No app, no cable to a laptop, no cloud round-trip.

● Live
Phone → badge, over WebUSB

Open it in Chrome on your phone, plug the badge in, pick an image, hit send. It renders entirely on-device — nothing is ever uploaded to a server.

1
Open the tool in ChromePhone or desktop. WebUSB does the talking — no install.
2
Pick an imageOFC presets, ~thousands of searchable game-icons, or upload your own photo with optional dithering.
3
Send to the badgeThe pixels stream straight over the USB connection to the badge display.
  • Fully local. Runs in-browser; nothing leaves your device.
  • Preset library. Curated OFC icons plus the full game-icons.net set, searchable.
  • Bring your own image. Dither for photos, crisp mode for logos and line art.
  • No pairing dance. Plug in, grant the port once, upload.
  • Phone-first. Built for standing in a hallway at con, not a bench setup.
Launch the uploader → Chrome / Android · needs a badge plugged in to actually send

Gene Seeder

Skip the hunt for a donor badge that happens to carry the colors you want. The seeder forges a valid donor reply QR for any genome you choose — a software "Bob" the badge will authenticate and breed with.

⌨ CLI
Designer light-genes on demand

The badge's gamete exchange is deterministic AES-256-GCM-SIV. Reproduce the algorithm and you can hand the receiver a ciphertext byte-identical to what a real donor would compute — so it verifies, and breeds with the genes you picked.

1
Scan the target's nonce QRThe badge shows a fresh nonce when it wants to breed. That's your input.
2
Choose the genomeNine bytes of light-gene — designer patterns, or ones a badge would never roll on its own.
3
Show it the reply QRThe seeder renders a base45 QR on screen. Hold it to the badge's GeneScan (🔥) within ~60s and it breeds.
  • Deterministic by design. Same crate as the badge (aes-gcm-siv 0.11.1); the tag matches, so the receiver accepts it.
  • Keyless-by-default. Won't forge a reply without a key — harmless to keep built and ready.
  • Self-test built in. Round-trips a gamete and renders a QR with no key needed, to prove the pipeline.
  • Type-aware. Sends a neutral badge type so the receiver injects your genes exactly, instead of mutating them.
# prove the pipeline — no key required qr-seeder selftest # forge a donor reply for a genome you choose qr-seeder seed \ --nonce-qr <base45 from the badge's nonce QR> \ --gamete <9 light-gene bytes> \ --type none
Get the write-up → Rust CLI · source shared at the con · full technical write-up on request

Same idea, both directions.

One tool controls what the badge shows. The other controls what it inherits. Together they turn a badge you were handed into one you actually author — which, at a con built on badgelife, is the whole point.

📡

Reverse the protocol

WebUSB for the display, AES-GCM-SIV for the genes. We read the badge's own crate and spoke its language back to it.

🛡️

Safe to carry

The uploader never touches a server. The seeder refuses to forge without a key. Built to be ready, not reckless.

🎒

Field-ready

Phone-native uploader, single-binary CLI seeder. Designed for a hallway at DEF CON, not a lab.

Want the technical write-up?

Drop your email and we'll send the full teardown — how the gene exchange works, the WebUSB flow, and the source when it goes public.