PLAY PODCASTS
Chaos Computer Club - archive feed

Chaos Computer Club - archive feed

21,276 episodes — Page 158 of 426

Decoding the Anker 3800 lock (MCH2022)

Jul 23, 202250 min

Electron microscopes - How we learned to stop worrying and love cheap lab equipment. (MCH2022)

A tale of sketchy^H^H^H^H^H^H^Hawesome online shopping, grimy scrap bins, and crazy DIY projects: The adventures of a few friends who set up an electron-microscopy lab (and much more!) without breaking the bank. For all audiences: whether you just want to see some cool micrographs, hear a story of hacker adventure, or, want to set up your own SEM - this should be a good time. This talk will have several parts: First we will tell you a story of a hobby that started with modifying an old classroom microscope for semiconductor imaging and has led to owning one, possibly two scanning electron microscopes (SEMs). You will see how 2020's logistics drama, COVID, language barriers, etc resulted turned the "simple" task of buying an electron microscope into a roller coaster of an adventure. Part two will look at the things we learned and what *you* should look out for if you want to get your own SEM: Things that will break, physics to watch out for, requirements for running it, and understanding the things that set different SEMs apart. Finally, we want to look at the future: Can we get a community of hackers building their own chips or replicating material science papers similar to the one we see abroad? Their achievements have been non-trivial to translate to European reality, but not impossible to. We hope to spur this on. about this event: https://program.mch2022.org/mch2022/talk/LE3MD7/

Jul 23, 202249 min

Electron microscopes - How we learned to stop worrying and love cheap lab equipment. (MCH2022)

Jul 23, 202249 min

FreeSewing: sewing patterns based on code (MCH2022)

Jul 23, 202231 min

Attribution is bullshit - change my mind... (MCH2022)

Jul 23, 202225 min

FreeSewing: sewing patterns based on code (MCH2022)

Tired of clothing stores not having your size, or that you're stuck in between sizes? So was Joost de Cock, he didn't - and doesn't - like how clothing stores base their clothing sizes on an imaginary average person; every person has a different body. That got him to found FreeSewing: the open-source platform that translates custom measurements into well-fitting sewing patterns with code. The platform is working towards becoming the Wikipedia of sewing patterns, with new patterns being released every few months, plus a bunch of guides on how to sew. The platform also provides guides for designers and developers, to transform patterns into code. This system based on code allows not only for custom measurements, but also for tweaking the pattern (e.g. longer sleeves, or a crop top) and recycling parts of one pattern into another - whereas a traditional sewing pattern is based on the measurements of a perfect mannequin, which is then graded up and down for different body types, which is known to have many downsides. This talk will not be held by founder Joost de Cock himself, but by an enthusiastic contributor. He will gladly go more in depth on how the code works, common pitfalls, the motivation behind it and how it helps against the rise of fast fashion - maybe encouraging some to pick up sewing themselves? A platform that can make tailored sewing patterns, it sounds great - but how does it work exactly? It definitely is an upgrade from traditional sewing patterns. Making sewing patterns may sound easy: they are pieces of fabric, shaped in a specific way and sewn in a specific way. For example, a t-shirt pattern will have these parts: a front, a back and sleeves. But to figure out the right shape, the average pattern designer will make their design based on the shape of their perfect mannequin, and they grade it up and down for different body types. Adapting the pattern for a different shape can be a tedious task. That's where FreeSewing comes into play: sewing patterns aren't based on the measurements of one fit model, but they're parameters; they vary based on what the user puts into the system. And the platform doesn't just provide sewing patterns; it also has a lot of guides available, for general sewing, specific sewing patterns and even on how to code a pattern into the system. This makes it not just a platform for sewists, but also for designers and developers. So, enough about how cool I think it is, what exactly do I mean with "sewing patterns based on code"? FreeSewing is written in JavaScript and the technique is quite similar to how you would draw a traditional pattern: a bunch of lines for the right measurements, but now a system is drawing those lines for you. A line needs a beginning point and an end point, usually also points that determine the curve; the 'coordinates' of these points are based on the measurements. The sewing patterns aren't just based on custom measurements, but you can also tweak them however you'd like (and within what's possible), e.g. wanting longer sleeves, or a crop top. Another advantage of having code as a base is that you can 'recycle' pattern parts from one sewing pattern into another. Not just the sewing patterns are easily accessible online, but also the software needed to create the code: the core library and patterns are available both for NodeJS and the browser. The code and markdown content is hosted by [Github](https://github.com/freesewing/). I'm happy that this project wasn't created by a capitalist overlord, but by someone who wanted to change the world for the better. Now there are a lot of sewing patterns available for all types of bodies and I hope it will encourage more people to start sewing their own clothes. Sewing is difficult to learn, not to mention coding, but it's so worth it. Luckily FreeSewing has a vibrant community where there's always someone ready to help with problems. My goal is to share this enthusiasm with others and maybe encourage some to pick up sewing or help out with coding. about this event: https://program.mch2022.org/mch2022/talk/M9JWKM/

Jul 23, 202231 min

Attribution is bullshit - change my mind... (MCH2022)

Borne out of a semi-flippant Twitter comment, this talk will take you on a journey across the benefits, pitfalls, and outright BS of attribution. Expect passionate opinions, trenchfoot inducing war stories, head+desk frustration, and a strong meme game. With this session, which is aimed at security practitioners, researchers, students, and anyone with an interest in cybersecurity, we hope to: • Highlight the value of decent threat intelligence • Establish why attribution can be valuable, but how it can be a distraction, or worse • Inform people who are interested in attribution and threat intelligence as areas of study how they can pursue it Borne out of a semi-flippant Twitter comment, this talk will take you on a journey across the benefits, pitfalls, and outright BS of attribution. Expect passionate opinions, trenchfoot inducing war stories, head+desk frustration, and a strong meme game. With this session, which is aimed at security practitioners, researchers, students, and anyone with an interest in cybersecurity, we hope to: • Highlight the value of decent threat intelligence • Establish why attribution can be valuable, but how it can be a distraction, or worse • Inform people who are interested in attribution and threat intelligence as areas of study how they can pursue it about this event: https://program.mch2022.org/mch2022/talk/ATVVN8/

Jul 23, 202225 min

Free children from the digital stranglehold (MCH2022)

Jul 23, 202249 min

ICS stands for Insecure Control Systems (MCH2022)

Jul 23, 202243 min

Free children from the digital stranglehold (MCH2022)

The current digital educational system is dominated by tech giants. Fundamental rights, like the privacy, freedom and sovereignty of children, parents and educators are insufficiently secured. Ed-tech is mainly closed source and full of vendor lockins. Products are either overpriced, harvesting data, or both. The time to replace surveillance capitalist based Ed-tech by ethical open source alternatives is now. And our coalition for fair digital education is going to do it. Private companies do not have the same interests as public institutions like schools. Schools do not have the time, knowledge or budget to hack their own IT environment together. Hence, BigTech and Ed-Tech fix this problem for schools, by offering services that have a very low price tag in euro's, but the actual payment is in data: meta data, "service"-data and user-data. DPIA you say? *(Detailed Privacy Impact Analysis)* That will achieve sort-of-legally compliant services at max. If only the authorities would actually bite, but alas, enforcement is lax, and four years of GDPR and the IT environment in schools is still riddled with privacy risks. Essential online services are out-of-scope of the DPIA's and purposes like "product improvement" (read: feeding AI and machine learning algorithms) is GDPR-Okay. If you or your kid goes to a 'Google school' and is forced to use a Chromebook, you'll be producing data to train Google, and you will be trained to love Google services. Consequently children won't develop core digital skills or a critical attitude toward digital services. Thus, there is a huge gap between core values of big tech companies versus public values in the educational system. Therefore, enforcement to make Big Tech embrace those public values will never be effective. ​​​​​​​That is why we need to build a school IT environment based upon public values: transparent, open source, privacy-by-design, decentralized, fair and respecting our digital sovereignty. Our coalition for fair digital education is going to build this. This is a huge project and a lot of work, so join us. about this event: https://program.mch2022.org/mch2022/talk/AZVEA8/

Jul 23, 202249 min

ICS stands for Insecure Control Systems (MCH2022)

Last April we won Pwn2Own Miami by demonstrating five zero-day attacks against software that is commonly used in the ICS world. ICS, or Industrial Control Systems, are systems that are involved with running an industrial process, for example in a factory or power plant. Our targets range from SCADA to HMI systems. During this talk we would like to share details about the competition and the vulnerabilities we found. ICS is an interesting field for security research. As a successful attack could have devastating results. Luckily the number of successful attacks that truly targeted ICS environments are scarce. At the same time this industry faces some difficult challenges, such as high availability requirements, old technology and a low security maturity. Pwn2Own Miami is an annual edition of the Pwn2Own competition, that focuses solely on ICS applications. Targets range from OPC UA implementations (on of the main communication protocol in ICS), to data gateways and SCADA systems. They challenge competitors to find zero-days attacks against any of the targets. Participants need to demonstrate their zero-days by compromising a target machine running the latest version of the application. Last year we participated in the Pwn2Own Austin edition, which focused on Enterprise applications, with a zero-day chain against the Zoom client. This year we decided to participate in the ICS edition. It was a close race, but ultimately we beat the competing teams and won this year's edition. We demonstrated 3 RCE's, one DoS and an interesting certificate verification bypass, which in total was good for 90 points and $90,000. about this event: https://program.mch2022.org/mch2022/talk/KW7LDS/

Jul 23, 202243 min

RE-VoLTE: Should we stop the shutdown of 2G/3G to save lives?? (MCH2022)

Jul 23, 202229 min

RE-VoLTE: Should we stop the shutdown of 2G/3G to save lives?? (MCH2022)

A lack of VoLTE standardisation breaks voice calling globally. Your brand new smartphone may not work because VoLTE is screwed up by manufacturers and carriers. Voice-over-LTE (4G), voice-over-NR (5G) and voice-over-WiFi have been standardized for years, but now that more and more 2G and 3G networks are shut down by operators, users discover their phones don't work anymore with basic voice calling. The cause is a massive mess in standardization, with a boatload of options and settings and vendors and carriers interpreting it differently, masked by fall-back to 2G and 3G and lack of "international roaming" agreements for VoLTE. Handset manufacturers decided to implement shortcuts (neglecting parts of the standards) or even worse, implementing white-lists with only mayor operators included, so you cannot switch operators anymore and are up for a big surprise while roaming in another country. The result: Even your brand new phone might be unable to provide voice calling in one country but work in another. Voice-calling might work if you're lucky, but you cannot reach 112/911, the eCALL system in your car fails after 2G/3G shutdown or you cannot receive an SMS you need for remote Two-Factor-Authentication while roaming in another country. It's such a disastrous mess, so should we stop the 2G/3G shutdown and get-it-fixed? This is a tale of a disaster still looming in most of Europe for Europeans, as 2G/3G still works as the fall-back mode of your device. As a result nobody noticed that VoLTE was screwed up. However many non-Americans roaming with their phones into the USA suddenly learn their brand new phone isn't working for voice-calls, as AT&T has shut down 2G/3G on July 1st 2022. Problems already did happen to users roaming into countries like India. Users who buy seemingly the same recent model of a supplier like Samsung or Apple, and think they are safe, might be up for a big suprise too. Months of testing needed per device was considered way too cumbersome and too expensive by many, so at best it was halfway done. Manufacturers decided to cope with it by curtailing the myriad of options and settings, included mobile-network-code white-lists or implement short-cuts (neglecting parts of the standards). With white-lists you suddenly are tied to an operator and changing your subscription from a major Mobile Network Operator to an MVNO, makes voice-calling on your brand new smartphone defunct, only allowing data communications working. The "advice" to complainers is just to use voice-apps, but these don't allow Emergency calls. eCALL devices built into cars that dial emergency numbers may work in your home country, but fail when driving in another land on your holiday. Roaming agreements between international carriers have up to now been made only between major operators in large countries, There are merely 50 international VoLTE roaming agreements actually working. If you are from a "small country" like Sweden, you're out of luck in the USA. Voice-over-LTE (4G), voice-over-NR (5G) and voice-over-WiFi have been screwed up by an unholy alliance of handset manufacturers, carriers, the GSM-Association and IMS-core vendors and standardization bodies, who couldn't decide to settle VoLTE down to a limited set of options and prescribe large scale compulsory plugfests and compatibility tests. Regulators have looked away, expecting the "magic of the market would resolve all issues". Some vendors have engaged in favoritism with white-listing or don't deal with MVNOs and MVNEs, as they don't order millions of devices. This talk explains the cause of the mess and highlights the problems lurking in your brand new device. It provides real problems, with devices and disfunctional VoLTE, collected in 2021/2022. We should ask the question whether the announced shutdowns of 2G/3G in most of Europe have to be stopped. Must device manufacturers and carriers be forced to clean-up their act now, and halt their anti-competitive practices and favoritism, before people die as they cannot reach 112/911 during an Emergency? about this event: https://program.mch2022.org/mch2022/talk/7TVHSD/

Jul 23, 202229 min

HomeComputerMuseum, the making, the challenges and the importance. (MCH2022)

Jul 23, 202251 min

HomeComputerMuseum, the making, the challenges and the importance. (MCH2022)

The HomeComputerMuseum's idea originated in 2016 and opened the doors in 2018. Since then, we faced several challenges but we came out on the other end and became one of the largest museums about computers with an award-winning social impact, an enormous social network, collaborations over the whole world and even are of essential importance to the Dutch government. The talk is about the original concept, how we build it to what it is now. The original concept of the HomeComputerMuseum is a hands-on computermuseum dedicated to the home computer or connected computers. Because a museum is a terrible businessplan I decided to create a few services, like repairs, selling overstock and reading old media. For this could not be done by one person, I decided to have people with autism help me by simply not putting a label on them. The businessplan was created and eventually a building was rented. The entire museum is physically built in 7 days (not even kidding) and we were off to a very rough start and even balancing on the edge of bankruptcy. However, we managed to stay afloat and we even moved to a much better and bigger building where we enjoyed for a full month before corona hit the museum. As an unsubsidized museum and without big sponsors we were faced a brand new challenge. But we overcame and grew stronger than ever.... (and then there's plenty of story to tell more). about this event: https://program.mch2022.org/mch2022/talk/XTJRMK/

Jul 23, 202251 min

Electronic Locks: Bumping and Other Mischief (MCH2022)

Jul 23, 202229 min

Hacking the Quincy Drawing Robot (MCH2022)

Jul 23, 202224 min

Hacking the Quincy Drawing Robot (MCH2022)

This session will go over my journey to hack the Quincy drawing robot. This is a cheap 3-axis drawing robot, that uses a proprietary "closed" system. I wanted to hack this robot to draw Pokémon's for my son. I will explain how I deciphered the file formats, figured out how the robot could be controlled (which needed some very very difficult math!) and the software I made to create your own drawings. BONUS: At the end of the session you can WIN one of these Quincy Robots!!! This session will explain step by step the process I took to decode the proprietary file formats, using some simple python coding. This will give you an insight in general how you can try to decode file formats that are not documented. Besides understanding the files, the math behind controlling this robot turned out to be very complicated. I will explain the difficulty and if you are a Math Nerd you can see if you could solve this difficult challenge. Finally I will show the software I made to create your own drawing files. about this event: https://program.mch2022.org/mch2022/talk/787GY3/

Jul 23, 202224 min

Electronic Locks: Bumping and Other Mischief (MCH2022)

Modern electronic locks are often optimized for cost, not security. Or their manufacturers don’t do security research. Or they ignore it. For whatever reason, many current electronic lock systems are susceptible to surprisingly simple attacks. We’ll look at some of them, and at the underlying basics, so that you can do your own research. In this talk, we look at a number of modern electronic locks and their security flaws. Surprisingly many current systems are susceptible to very simple attacks, like the equivalent of using bump keys. Of course, there are electronic and/or SW-based attacks, too. We’ll look at some of them, and at the underlying basics, so that you can do your own research. Some of the problems have been fixed by manufacturers, but typically only for future production runs, so you will get some practical advice on how to test your own hardware for these critical flaws. about this event: https://program.mch2022.org/mch2022/talk/KBVXRU/

Jul 23, 202229 min

Reverse engineering the Albert Heijn app for fun and profit (MCH2022)

Jul 23, 202229 min

Reverse engineering the Albert Heijn app for fun and profit (MCH2022)

The Albert Heijn, everyone (in the Netherlands at least) knows it. It's the largest supermarket chains here. They have a very extensive API. This API is not public unfortunately, but in this talk I will show you how you can reverse engineer the app to figure out how the API works and how we can use it to our advantage. The Albert Heijn, everyone (in the Netherlands at least) knows it. It's one of the largest supermarket chains with a very extensive API. This API is not public unfortunately, but in this talk I will show you how you can reverse engineer the app to figure out how the API works and how we can use it to our advantage. AirMiles, tracking stamps for the current saving program, receipts, personal discounts. All these can be viewed or tracked within the Albert Heijn app. But, what if you want to track your savings over time? I want my pretty Grafana dashboard gosh darn it! This talk will go into the story behind randombonuskaart.nl (a website for a 'random' bonuskaart right when you need it), talk about how your private API is not really private and how we can use the Albert Heijn API to track various data and do tedious actions for us. The knowledge gained from this talk can also be used with other apps, but the Albert Heijn app proves for a very good example. about this event: https://program.mch2022.org/mch2022/talk/F88JGH/

Jul 23, 202229 min

Don't turn your back on Ransomware! (MCH2022)

Jul 23, 202227 min

Don't turn your back on Ransomware! (MCH2022)

Ransomware is making a comeback and attacking us all! Learn and sharpen your blades in order to defend against this multi headed monster! There’s a lot to learn from every ransomware attack. By demounting every bit of the attack and looking at every stage there’s much to gain for setting up proper detection and other defence techniques Remember those times when a popup appeared on your screen with the message to immediately transfer an amount of bitcoins to retrieve your files? Ransomware is still a serious threat to a lot of people and organisations and nowadays using more and more advanced techniques to target you and steal your data. This talk will tell us what Ransomware actually is, who’s writing the code and making money out of it, it shows us a bit of the Ransomware history and what types were out there, to better understand what we’re dealing with. And explain all of the ransomware attack stages and what you can do in terms of detection and defence inside your security operations. about this event: https://program.mch2022.org/mch2022/talk/8JETCV/

Jul 23, 202227 min

Repair for Future (MCH2022)

This discussion will start with a brief summary on the history of repair initiatives. We can report about our personal repair activities during the pandemic. Subsequently, I'll outline the achievements of the right to repair movement and we can discuss ideas for the future. During a peak in public interest, the repair café movement was caught by the covid pandemic. Many local initiatives adapted quickly and opened online repair consultation hours. In the german-speaking countries, a monthly central online repair café was established. I'll give a lessons-learned about the experiences and limits of these online activities. The political right to repair movement has brought many interesting improvements, for example the french repairability index or the European ecodesign directive. I'll talk about them and what else is to be expected in the near future. This is in interactive discussion format, so ideally I'll only present a few facts and guide through topics while the audience chimes in with their personal experiences and questions. Slides: https://pads.schaffenburg.org/p/Repair-for-future-MCH about this event: https://program.mch2022.org/mch2022/talk/ZNJYHC/

Jul 23, 202246 min

Taking Action against SLAPPs in Europe (MCH2022)

Jul 23, 202248 min

Repair for Future (MCH2022)

Jul 23, 202246 min

Taking Action against SLAPPs in Europe (MCH2022)

SLAPP suits (strategic lawsuits against public participation) are nuisance lawsuits designed to get journalists, activists, historians, whistleblowers and others to keep quiet. This kind of lawfare isn't new, but there is an increasing focus on the issue in Europe, with new legislation coming. Here's where you find out more. You receive a threatening letter from a major law firm, probably based in London, trying to stop your reporting, or your activism, threatening you as an individual as well as the organisation you are affiliated with - congratulations, you've just been SLAPPed. Strategic lawsuits against public participation (SLAPPs) are on the increase worldwide, and Europe is beginning to take notice. Lawyers' associations in Italy and Croatia report hundreds of nuisance suits being laid against journalists. In Hungary, Poland and Slovenia, the state and its allies are SLAPPing opponents - journalists, anticorruption activists, LGBTI+ rights advocates - with impunity. Litigation has been turned against the activist community, oligarchs try to silence debate and Eastern Europe has become the new home of SLAPP-based oppression, as politics slide into autocracy and leaders stamp down on dissent. Blueprint is part of an 11-country coalition working on the ground to train lawyers to help the victims of SLAPPs strike back. We're currently developing a curriculum from scratch, drawing on European human rights principles and local knowledge. If you want to understand the European situation better, or if you have experience of SLAPPS and can help us understand what kinds of legal training and other defences are useful to civil society, we'd love for you to join this conversation. about this event: https://program.mch2022.org/mch2022/talk/ZUYKEC/

Jul 23, 202248 min

How I made the municipality pay a 600.000 euro fine for invading your privacy (MCH2022)

Jul 23, 202226 min

How I made the municipality pay a 600.000 euro fine for invading your privacy (MCH2022)

When gathering data for public services becomes privacy infringement and what you as a citizen can do about it. Or: How I made the municipality pay a 600.000 euro fine for invading your privacy. In September 2017 The Municipality of Enschede started tracking visitor movements in the city center 24/7 by registering their mobile phones WIFI MAC addresses. Is this an infringement on our privacy, even when the underlying identities remain concealed? In September 2017 The Municipality of Enschede started tracking visitor movements in the city center 24/7 by registering their mobile phones WIFI MAC addresses. Is this an infringement on our privacy, even when the underlying identities remain concealed? Yes it is, claimed speaker and privacy activist Dave Borghuis. After a 4 year process the dutch DPA agreed and Enschede was charge a massive fine for its infringement. Now, can we learn from this case? Where does or should our privacy start? And what can we, as citizens, do to protect our freedom to move about in privacy? Read more on my blog https://daveborghuis.nl/wp/wifi-tracking/ about this event: https://program.mch2022.org/mch2022/talk/LQRMFA/

Jul 23, 202226 min

It's not just stalkerware (MCH2022)

Jul 23, 202225 min

It's not just stalkerware (MCH2022)

Stalking is unwanted and/or repeated surveillance by an individual or group toward another person. But what is the impact of tech companies making it easier to do this with the development of technology? In the news, we hear about the increase in stalkerware found on devices or scary government spyware. But it’s not just that, there are so many more common tools used by stalkers. From September 2020 to May 2021, the number of devices infected with stalkerware increased by 63 percent, according to a study by Norton Labs. But stalkerware is not what I encounter most when I get contacted by stalking victims. Almost anyone can become a victim of stalking; stalkers do not just target celebrities. Sometimes they are ex-partners known to the victim, other times they may be a casual acquaintance, or just a simple stranger. With stalkerware, the actor needs access to the device or needs to persuade the victim to install something. In cases where the stalker is a (ex-)partner, that might be doable. But in other cases, it is easier to gain access to the accounts of the victim, gather information about the victim from social media, or use tracking devices (looking at you Apple and Tile) to follow the victim. Tech companies develop new apps and gadgets seemingly without thinking about other ways these can be used. And they end up making it easier to stalk someone. But what can we do about this problem? Should we lower efforts hunting stalkerware and help victims gather evidence? Or can we do something else. about this event: https://program.mch2022.org/mch2022/talk/THP7HG/

Jul 23, 202225 min

Reclaiming our faces (MCH2022)

Jul 23, 202228 min

Lightning Talks Saturday (MCH2022)

Jul 23, 202248 min

What have you done against covid (MCH2022)

Jul 23, 202246 min

Climate Crisis: The gravity of the situation. What is going on? (MCH2022)

Jul 23, 20221h 59m

Reclaiming our faces (MCH2022)

What are the risks and problems of face search engines like Clearview AI and PimEyes? Since institutional protection against these systems is failing us, how can we protect ourselves against this? Three people involved in the fight against biometric mass surveillance share their experiences and reflections. Come to this talk to exchange experiences, learn what tools there are for your protection, how to use them and how you can help stop the creep of mass surveillance technologies. Face search engines like [Clearview AI](https://reclaimyourface.eu/how-to-reclaim-your-face-from-clearview-ai/) and [Pimeyes](https://edition.cnn.com/2021/05/04/tech/pimeyes-facial-recognition/index.html) have all our faces and process our biometric data. They didn't ask us if we like their *service* and if they may use our data. Users of these search engines can now identify us anytime, anywhere. Since biometric data enjoy special protection under GDPR, we filed complaints in multiple European states. We report how data protection authorities did nothing for a long time and tell of the first successes. However, it became clear that GDPR does not protect against biometric surveillance. That's why we have joined forces to form the **[Reclaim Your Face](https://reclaimyourface.eu/)** campaign. Together, we call on the European Commission to strictly regulate the use of biometric technilogies in order to avoid undue interference with fundamental rights. In particular, we ask the Commission to prohibit, in law and in practice, indiscriminate or arbitrarily-targeted uses of biometrics which can lead to unlawful mass surveillance. The two face search engines are not the only examples of everyday biometric surveillance. However, it is difficult to track where else we are being monitored: There is a lack of transparency and oversight. Public authorities and private companies rarely report on their own what they have been up to. We share how we've used FOIA requests, among other things, to create a little more publicity. about this event: https://program.mch2022.org/mch2022/talk/SQQ3D9/

Jul 23, 202228 min

Climate Crisis: The gravity of the situation. What is going on? (MCH2022)

Goal is to discuss the gravity of the situation and create shared set of ideas on what is likely coming at us. We will do a Threat Modelling exercise around the climate change topic. Via a collective mind mapping exercise we will create a shared mental model and identify the things that will happen and how they will affect various people at various locations. Goal is to discuss the gravity of the situation and create shared set of ideas on what is likely coming at us. We will do a Threat Modelling exercise around the climate change topic. Via a collective mind mapping exercise we will create a shared mental model and identify the things that will happen and how they will affect various people at various locations. about this event: https://program.mch2022.org/mch2022/talk/UCSKRM/

Jul 23, 20221h 59m

Lightning Talks Saturday (MCH2022)

Lightning talks are a 5 to 10 minute quick talk on an interesting subject. They can be with or without slides, and with or without proper preparation. if you weren't accepted in the main CfP, this is also a great opportunity to give an abridged version of your talk. These sessions will be available to sign up to later on, with details on the wiki. Lightning talks are a 5 to 10 minute quick talk on an interesting subject. They can be with or without slides, and with or without proper preparation. if you weren't accepted in the main CfP, this is also a great opportunity to give an abridged version of your talk. These sessions will be available to sign up to later on, with details on the wiki.Lightning talks are a 5 to 10 minute quick talk on an interesting subject. They can be with or without slides, and with or without proper preparation. if you weren't accepted in the main CfP, this is also a great opportunity to give an abridged version of your talk. These sessions will be available to sign up to later on, with details on the wiki. about this event: https://program.mch2022.org/mch2022/talk/BZ3Y7X/

Jul 23, 202248 min

What have you done against covid (MCH2022)

From complaining out loud about a televised government app-a-thon to being hired by the Ministry of Health, Welfare and Sport as lead developer RoHS running a team of devs to work on all the covid backend infrastructure exception routes and making sure no person is left in digital limbo in just under an hour. When late 2019 the first signs from China of the novel Corona virus came I was intrigued, During the first "lock down" in the Netherlands our Ministry of Health, Welfare and Sport created an app-a-thon . . and much hilarity ensued. As all geeks had seen . . nice ideas people . . but Apple and Google already have a standard agreed. And a lot of us "Dutch Hackers" where pretty vocal about it as usual. Meanwhile at "the ministry" a civil servant started hiring people from the Dutch hacker scene. Late December 2020 it came to their attention that there was some missing or ancient infrastructure in place for vaccine registration, not at all ready for the then upcoming vaccination landrush. 14th of December I get a call . . can you clean your calendar for the year? Sure . . just over two weeks, one of them I had planned as holiday anyway to watch CCCongres talks. . Little did I know they meant clear agenda for 2021 .. and 2022 . . not 2020. This story takes you from getting very privacy and security aware infrastructure for registering the first ever Covid vaccination in the Netherlands built and tested in 3 weeks to the current state of the DCC infra up close and personal. about this event: https://program.mch2022.org/mch2022/talk/PHSMTF/

Jul 23, 202246 min

OpenRAN – 5G hacking just got a lot more interesting (MCH2022)

Many 5G networks are built in fundamentally new ways, opening new hacking avenues. Mobile networks have so far been monolithic systems from big vendors. Networks are rapidly changing to an "open" model that mixes software from specialized vendors, hosted in cloud environments. The talk dives into the hacking potential of the technologies and new interfaces needed for these open networks. We illustrate the security challenges with vulnerabilities we found in real-world networks. # Background # Mobile networks are undergoing a paradigm shift from single-vendor monoliths to open cloud environments. Telco software now comes from different vendors and is installed on commodity hardware. OpenRAN is introduced in many (not all) 5G network globally. Operators hope that OpenRAN will be more flexible and cheaper. But what about security? To make building blocks interoperable, OpenRAN comes with new interfaces, with often unclear security properties. OpenRAN also adds complex IT technologies, which come with their own hacking issues. Many components are run on Linux in Docker containers on top of Kubernetes, adding multiple layers of possible hacking interference. Mobile networks also become easier to test, including for pentesters with experience in web apps and cloud environments. This talk explores how we can best use this new accessibility. # What we discuss # *1. Technology overview.* Which technologies and interfaces are used in OpenRAN *2. Baseline security.* Which security measures are part of OpenRAN, and which gaps are left open *3. Pentest/hacking advice.* How do you test whether a network uses necessary security measures *4. Tales of caution.* Vulnerabilities we found in real-world networks about this event: https://program.mch2022.org/mch2022/talk/8BEFCG/

Jul 23, 202244 min

OpenRAN – 5G hacking just got a lot more interesting (MCH2022)

Jul 23, 202244 min

Honey, let's hack the kitchen: (MCH2022)

Attacks on cyber physical systems are perceived as necessarily complex and requiring significant time and resources. However, in the last couple years we have also observed the inverse: simple attacks where actors with varying levels of skill and few resources gain access to software and interfaces that control physical processes. These compromises appear to be driven by ideological, egotistical, or financial objectives, taking advantage of an ample supply of internet-connected cyber physical systems. This is sometimes concerning, for example when it is affects panels for controlling processes in a water facilities or manufacturing processes. Sometimes, though, it is absurd, such as when the critical systems actors claim to compromise are in fact toys or domestic appliances. In this talk, we will share a series of stories of success and failure involving low sophistication compromises on cyber physical systems. We will describe the different types of cases we have observed, what the actors did, and how you can reproduce them for good. At last, we will discuss to what extent these crimes of opportunity represent a risk to cyber physical systems and what we can do about it. In november 2021, I presented a version of this talk at a local non-profit event in Bergamo, Italy. For this event - NoHat - I focused on sharing the stories of low sophistication compromises we observed involving software used to control physical processes. However, for MCH I did some modifications in the title and the presentation itself to share not only the cases, but also how to reproduce them for good. The purpose of this talk is to share with the audience how actors without necessarily a lot of skills or resources are using very simple tools to hack cyber physical systems. I will do some experiments to show very quick results the audience can get reproducing these techniques so that they learn how to find these internet-connected cyber physical assets and notify the owners. The outline of the initial presentation was: • Introduction o Story: Hacked kitchen was supposed to be a gas system • Define low sophistication cyber physical compromises • (De)evolution of cyber physical threats o From state-sponsored to financial, and now opportunistic • Describe low sophistication compromises of cyber physical systems o Distribution and claims of exposed systems o Seeming actor motivations o Common actor techniques o Types of evidence (or lack of) • Low Sophistication Threat Actors Access HMIs and Manipulate Control Processes o Oldsmar, Florida modified HMI on water facility o Israel’s advisory on compromises to water facility systems o Solar energy and dam surveillance system o Hotel BAS • Amateur Actors Show Limited OT Expertise o “Train control system” was in fact a human resources tool o Second “train control system” controls toy trains o Website leaks claiming access to SCADA systems • Hacktivist and Researcher Tutorials o Two hacktivist groups share tutorials for finding and compromising cyber physical systems o Researchers have done too – including a couple examples, such as a recent script to identify tank gauges • Does this activity pose an actual risk to cyber physical systems? o Each incident provides threat actors with opportunities to learn more about OT, such as the underlying technology, physical processes, and operations. o Even low-sophistication intrusions into OT environments carry the risk of disruption to physical processes, mainly in the case of industries or organizations with less mature security practices. o The publicity of these incidents normalizes cyber operations against OT and may encourage other threat actors to increasingly target or impact these systems. • On the bright side… o There are safety methods in place that stop immediate computer instructions from modifying actual physical processes  Engineering and human processes  Missing security on the software side Additional Materials: Please find in this link our recent blog on this topic: https://www.fireeye.com/blog/threat-research/2021/05/increasing-low-sophistication-operational-technology-compromises.html about this event: https://program.mch2022.org/mch2022/talk/C9FANR/

Jul 23, 202238 min

Digital Civil Disobedience (MCH2022)

Jul 23, 202242 min

Digital Civil Disobedience (MCH2022)

Greenpeace is a direct action organisation. We have been doing physical direct civil disobedience actions for 50 years now. Civil disobedience has always played an important part in evolving democratic society if you look for instance at womens’ voting rights, the civil rights movement in the US and de ‘klimaatspijbelaars’. The digital realm is becoming more and more important in all of our lives. That is why we are working on a research project on what digital civil disobedience can look like. This is something else than mere ‘clicktivism’. What are the differences and similarities of online and offline civil disobedience? How do you 'drop' a digital banner or how do we digitally 'occupy' a building or mine? During this talk we want to tell about this project and give you an insight look on how we prepare disobedient actions at Greenpeace. Greenpeace is a direct action organisation. We have been doing direct civil disobedient actions for over 40 years now. At Greenpeace we know our strength and our weaknesses when doing actions in physical spaces. We scale buildings and hang banners, we have blocked the petrol harbour in Rotterdam (multiple times) and we stop oil/gas rigs from operating. All these kinds of actions are part of a struggle for a healthy climate and safe planet to live on and so ideologically motivated. The right to protest is a fundamental European right, a right that is very dear to us and important when chased by the law. At Greenpeace we always look at new ways to do disobedient actions. This is why we started a research on how online actions can contribute to campaigns. The last few months we have been looking into the possibilities of digital civil disobedience actions. We looked at the risks, the actions and the possibilities it will bring. One thing we learned is that everyone we talk to about this topic is super excited. about this event: https://program.mch2022.org/mch2022/talk/J9PRJK/

Jul 23, 202242 min

Everything is an input device (fun with barcodes) (MCH2022)

Jul 23, 202230 min

bug hunting for normal people (MCH2022)

Jul 23, 202248 min

Everything is an input device (fun with barcodes) (MCH2022)

If we consider technology sufficiently advanced indistinguishable from magic, then the closest we get to ancient magical glyphs are barcodes. In this talk, we will show how barcodes are not just simple numbers, but can be used to control the machines. If we consider technology sufficiently advanced indistinguishable from magic, then the closest we get to ancient magical glyphs are barcodes. In this talk, we will show how barcodes are not just simple numbers, but can be used to control the machines. In this talk we do a brief introduction into barcodes, the way they are built, their uses and their misuses. This will be illustrated with a couple of examples of misuses in the real world. After this, we will demonstrate how a common implementation of (barcode)-scanning is vulnerable to a deceptively simple attack, which can lead to some interesting results. about this event: https://program.mch2022.org/mch2022/talk/LFTLBD/

Jul 23, 202230 min

bug hunting for normal people (MCH2022)

A series of isolated problems encountered when attempting to fuzz software, in this case Adobe Reader (DC), and hackish solutions to said problems. Constructing a fuzzing pipeline capable of finding real bugs by stringing together freely available tools creating the bare minimum of glue. Starting from target selection, moving over requirements for a given fuzzing campaign to smart input generation, briefly touching on scaling challenges and performance issues. This presentation describes a practical approach to creating a fuzzing pipeline with the purpose of finding real world bugs in closed source software, in this case Adobe Reader (dc). The approach taken is suitable for anyone with basic scripting capabilities, is easy to replicate, and leads to bug hunting capabilities without a doctoral degree or years of experience in vulnerability discovery. about this event: https://program.mch2022.org/mch2022/talk/HVQDNE/

Jul 23, 202248 min

The art of online discobingo (MCH2022)

Jul 23, 202244 min

Respirators, Runtime Errors, Regulations – A Journey into Medical Software Realization (MCH2022)

Jul 23, 202248 min