
Chaos Computer Club - archive feed
21,276 episodes — Page 272 of 426
Elektroschrott - Welchen letzten Weg geht mein PC? (camp2019)
Elektronikschrott ist eine Handelsware. Schrott wird zu Gold. Geräte werden überall in der Welt mal gut, mal nicht so gut zerlegt. Wer verdient daran? Und was können wir tun, dass sich der Export nicht mehr lohnt? Die digitale Gesellschaft produziert Elektronikschrott. Dieser besteht aus Kunststoffen, Metallen und Platinen, die unterschiedlichen Verwertungswegen zugeführt werden müssen. Die beste Trennung ist immer noch das Zerlegen per Hand. Dabei können außerdem nutzbare Einzelteile extrahiert und direkt weiterverwendet werden. Dieses Vorgehen ist ökologisch sinnvoll, aber nicht besonders ökonomisch. Das spielt aber im Rahmen eines "Dismantling Cafés" (vis á vis dem Repair Café) keine Rolle. Dafür gibt es die Sicherheit, dass die eigenen Geräte nicht in einer der zahlreichen Dokumentationen über Agbotbloshie, den großen Elektroschrottplatz in Ghana, auftauchen. about this event: http://talx.thm.cloud/thms/talk/GYWNQP/
Exposing Systems of Power and Injustice (camp2019)
Presenting the Disruption Network Lab programme in Berlin, we will connect the debate on surveillance and whistleblowing to a cultural framework, analysing the influence of whistleblowing in empowering both experts and non-experts. A talk with Tatiana T_Bazz Bazzichelli and Lieke Ploeger / Disruption Network Lab. The act of whistleblowing is a concrete process able to reveal hidden facts, misconducts and wrongdoings of institutions and corporations, producing awareness about social, political and technological matters, informing about the reality we live in. Presenting the Disruption Network Lab programme in Berlin, we will connect the debate on surveillance and whistleblowing to a cultural framework, analysing the influence of whistleblowing in empowering both experts and non-experts. The talk will present the mutual interference between whistleblowing, art, hacking, and network development, as well as reflect on the influence of whistleblowing in the art & cultural field. This presentation aims to further question what we can collectively offer to encourage a critical debate on the effects of whistleblowing in society, as well as to generate experimental ways of thinking within the digital scenario. about this event: https://fahrplan.events.ccc.de/camp/2019/Fahrplan/events/10200.html
(emulate|fuzz|break) kernels (camp2019)
This talk will give an introduction to kernel fuzzing using *unicorefuzz*. Yes, yes. We all know fuzzing is a powerful tool to find bugs. For user space software, this is so 2014. Fuzzing kernels, however, can still be a daunting task. The state of the art kernel fuzzer, syzkaller, is somewhat complex to set up. So many unhappy parsers in the kernel remain unfuzzed to this day! Why can we not simply start fuzzing from some random breakpoint in the kernel, you ask? Well of course we can. Let's drop the whole thing into Unicorn Engine, a CPU emulator, and give it input. Simple as that. To stay on the punny side of things, we shall call this method *unicorefuzz*. about this event: http://talx.thm.cloud/thms/talk/QULQKV/
Cryptography of Killing Proof-of-Work (camp2019)
We briefly discuss the range of cryptographic primitives being used by protocols that seek to make proof-of-work protocols obsolete. We shall focus primarily on these cryptographic building blocks themselves, not overly on the different protocols built form them. There are a handful of protocols consuming enormous amounts of energy in proof-of-work schemes, which provide only rather tenuous security assurances. In practice, proof-of-work also invalidates these protocols original goal of being distributed. There is also a zoo of protocols designs, both new and from the 80s, that provide far stronger security than proof-of-work at minimal cost. We shall discuss the distinctive cryptographic primitives used by these protocols, without examining any of these critters too closely. In essence, our taxonomy splits as blind signatures vs. verifiable random functions (VRFs) vs. randomness beacons, with the latter consisting of publicly verifiable secret sharing (PVSS) and verifiable delay functions (VDFs). We only have time for a cursory look at the mathematics usable to build each of these, but this should explain some of their uses, strengths, and weaknesses. about this event: http://talx.thm.cloud/thms/talk/Z3VR8P/
Mapping Doomsday (camp2019)
The world is entering a new era of instability. The climate crisis will put great pressure on the (relatively) peaceful balance of world politics. But the field of open source intelligence (OSINT) provides us with a new and unique way to map, study and predict these flashpoints. This talk will look at several technical approaches for using these techniques and include several example studies. Intelligence agencies, NGOs, business groups, and insurance companies all agree that the worsening climate crisis will fuel war and global crises. Some go further, saying that societal collapse is all but inevitable. Whatever your view on this is, it is difficult to see our current paradigm of general peace continuing into the next few decades. But as this crisis worsens, modern technology has also gifted us with new tools to monitor, analyse and predict flashpoints. The emerging field of Open Source Intelligence (OSINT) is one such tool. OSINT uses publically available data (such as social media posts, video footage, satellite imagery, public databases and remote sensing) as the basis for in-depth investigations. This talk will look at the ways in which these techniques can be usefully applied, both journalistically and analytically, within the context of the aforementioned crisis. Specifically, it will look at two examples of how OSINT can be used to analyse past events over the last year, and one concept for predicting a future event. about this event: https://fahrplan.events.ccc.de/camp/2019/Fahrplan/events/10350.html
Introduction to Mix Networks and Katzenpost (camp2019)
This talk will introduce the fundamental concepts of mix networks as well as the Katzenpost mix network free software project. We are not just implementing a new mix network but starting a new anonymity movement and we welcome others to join us! Like Tor, mix networks protect metadata by using layered encryption and routing packets between a series of independent nodes. Mix networks resist vastly more powerful adversary models than Tor though, including partial defense against global passive adversaries. In so doing, mix networks add both latency and cover traffic. I shall outline the basic components of a mix network, touch on their roles in resisting active and passive attacks. In particular I'll mention how mix networks can be used with encrypted messaging applications and crypto currency to resist global network surveillance and traffic analysis. Academics have proposed various anonymity technologies with far stronger threat models than Tor, but by far the most practical and efficient option remains mix networks, which date to the founding of anonymity research by David Chaum in 1981. Tor was inspired by mix networks and shares some superficial similarities, but mix networks' are vastly stronger if they judiciously add latency and decoy traffic. There are several historical reasons why mixnets lost popularity and why Tor's onion routing won. Namely, Tor is low latency and can be used to browse the web. This is in contrast to mix networks which are essentially an unreliable packet switching network. Historically mix networks achieved enough mix entropy by using long delays whereas it is becoming more widely understood that there exists a trade off between legit traffic, decoy traffic and latency. After this introduction to mix networks I'll talk a bit about the Katzenpost mix network software project which is based off of the recently published academic paper "The Loopix Anonymity System". These new insights into mix network designs allow modern mix networks to make the correct design trade offs so that we can keep the latency relatively low. Historically high latency and unreliability has been a major obstacle to mass adoption. I shall explain how Katzenpost solves both of these problems and allows developers to easily add network services to the mix network to support a wide variety of client applications including but not limited to: encrypted messaging, crypto currency transaction transport, offline browsing and, transporting client interactions with Distributed Hash Tables and Conflict Free Replicating Data Types et cetera. about this event: https://fahrplan.events.ccc.de/camp/2019/Fahrplan/events/10226.html
75 Jahre Journalismus im WWW (camp2019)
Detlef Borchers, Peter Glaser und Erich Moechel erzählen, was sie im digitalen Neolithikum gesehen und erlebt, aber nie geschrieben haben. Episoden aus der Frühzeit über Gier & Dummheit & Illusionen bis die Dot.com-Blase brannte & die Datengeilheit in die digitale Welt kam. Geschichten aus den "Crypto Wars" samt schrägen Begegnungen mit Schattenmenschen, wie schnell man in was hineingeschlittert wurde & was dabei kaputtging. Wie das WWW halt wurde, was es heute ist. Der genauere Inhalt musst erst gemeinsam festgelegt werden, es wird auch Bilder geben. Sicher ist, wir werden Klartext reden, wobei auch ein Outing nicht auszuschließen ist. about this event: https://fahrplan.events.ccc.de/camp/2019/Fahrplan/events/10210.html
Was tun gegen Digitale Gewalt gegen Frauen (camp2019)
Digitale Gewalt ist mehr als Hatespeech: Dazu gehören Doxing, Identitätsdiebstahl, Bildmanipulationen und deren Veröffentlichung, Spy Apps und noch mehr. Das meiste davon ist verboten, gilt aber nicht als 'Cybercrime'. Der Talk beschreibt, was dazu gehört, wer betroffen ist, was sich bei dem Thema seit den Doxing-Fällen im Januar getan hat und was nötig wäre, um langfristig etwas zu ändern. Auf die Frage, ob Digitale Gewalt gegen Frauen auch ‚Cybercrime‘ sei, antwortete die Bundesregierung Ende November 2018: „Da es sich bei digitaler Gewalt nicht um Straftaten handelt, die sich gegen das Internet, Datennetze, informationstechnische Systeme oder deren Daten richten, sind sie nicht dem Phänomen Cybercrime im engeren Sinne zuzuordnen.“ Wenige Wochen später drehte sich der Wind, als Anfang Januar bekannt wurde, dass 1000 Prominente gedoxt* worden waren, darunter viele Bundestagsabgeordnete. Mit diesem Fall wurde ein Vorgehen zum schwerwiegenden IT-Sicherheitsproblem, von dem vorher schon viele andere Menschen betroffen waren, ohne dass ein Hahn danach krähte. In diesem Talk wird im ersten Teil der aktuelle Stand der Erkenntnisse zu den verschiedenen Phänomen erläutert, die unter den Sammelbegriff Digitale Gewalt gegen Frauen fallen: Beleidigungen, Bedrohungen, Erpressung mit der Drohung, intime Bilder zu veröffentlichen oder das Veröffentlichen solcher Bilder - auch bekannt als ‚Revenge Porn‘ - , geheime Ton-/Bild-/Videoaufnahmen und die Weitergabe an Dritte, Online-Stalking, das Installieren von Spy-Apps, Identitätsdiebstahl und -missbrauch, Doxing, Manipulation und Veröffentlichung von Bildern bspw. zusammen mit der Wohnadresse usw. usf. Das alles ist verboten, aber aus verschiedenen Gründen ist es oft schwierig, sich dagegen zu wehren. Deswegen geht es im zweiten Teil darum, dass und wobei Betroffene zu wenig Unterstützung bekommen: praktisch, juristisch, durch Polizei und Politik. Das beginnt oft bei der Frage der Zuständigkeit. Unter Cybercrime wird in der Regel kriminelles Verhalten gegenüber Geräten, Unternehmen oder Infrastrukturen verstanden, jedenfalls nach Auffassung deutscher Innenpolitiker. Dazu kommen Fälle, bei denen es ums Geld geht und natürlich auch Kinderpornographie. Innenminister Seehofer hat im Januar verkündet, dass das neue IT-Sicherheitsgesetz die Probleme lösen soll, die zu den Doxingfällen des „Adventskalenders“ geführt haben. Auf dem Tisch liegen Vorschläge für mehr Überwachung, weniger Verschlüsselung und mehr Geld für die Sicherheitsbehörden. Immerhin: Das BSI soll sich mehr um Verbraucherschutz kümmern. So wie es aussieht, ist die digitale Seite der häuslichen Gewalt aber wieder nicht dabei – dafür ist ja das Familien- und Frauenministerium zuständig. Betroffene von Doxing, Revenge Porn, ferngesteuerten ‚Smart Devices‘ oder Spy Apps haben es meist schwer, kompetente Ansprechpartner*innen bei Polizei und Justiz zu finden. Es gibt auch kaum Beratungsstellen für diese Fälle, obwohl die Folgen manchmal schwerwiegend sind. Deswegen gibt es im dritten Teil konkrete Tips für Betroffene und Hinweise, wo derzeit Lücken bestehen und Vorschläge, wie die geschlossen werden können Vielleicht - hoffentlich - ergibt sich im Anschluss an den Talk die Gelegenheit darüber zu sprechen, wie in manchem Fällen ganz praktisch Abhilfe geschaffen werden kann. *Doxing bezeichnet das Veröffentlichen privater Daten oder Informationen (= Dokumente, ‚Docs‘) im Netz Image by <a href="https://pixabay.com/users/ElisaRiva-1348268/?utm_source=link-attribution&amp;utm_medium=referral&amp;utm_campaign=image&amp;utm_content=1831016">ElisaRiva</a> from <a href="https://pixabay.com/?utm_source=link-attribution&amp;utm_medium=referral&amp;utm_campaign=image&amp;utm_content=1831016">Pixabay</a> about this event: https://fahrplan.events.ccc.de/camp/2019/Fahrplan/events/10346.html
Sinn von Unsinn unterscheiden - Glaub ich's oder glaub ich's nicht? (camp2019)
Pyramiden wurden von Außerirdischen gebaut! Impfen macht Autismus! Gott hat die Welt geschaffen! Kornkreise, Handystrahlung, Chemtrails, Homöopathie, Astrologie, Wasserkristallbilder, Aurafotografie, Quantenheilung... about this event: http://talx.thm.cloud/thms/talk/ARDC3J/
Neue europäische Überwachungslandschaft (camp2019)
Mit neuen Verordnungen und Richtlinien wachsen in der Europäischen Union weitere Datentöpfe heran. Internetanbieter sollen außerdem Inhalte entfernen und Telekommunikationsdaten auf Verlangen herausgeben. Auch der Kreis der Zugriffsberechtigten wird deutlich erweitert. Ganz legal könnten sogar US-Behörden bald in Europa Abhören dürfen. Unter dem Stichwort „Interoperabilität“ vernetzt die Europäische Union ihre großen Datenbanken im Bereich Justiz und Inneres. Der Beschluss fiel bereits, nun steht die Umsetzung an. Fingerabdrücke und Gesichtsbilder werden in einem „gemeinsamen Identitätsspeicher“ abgelegt und mit einem „Europäischen Suchportal“ prozessiert. Mit dem Projekt wird der polizeiliche Datenverkehr drastisch steigen, allein Europol rechnet mit 100.000 täglichen Abfragen seiner Dateien. Im Herbst, wenn sich das neue Parlament konstituiert hat, will die EU außerdem den Zugriff auf elektronische Beweismittel auf drei Wegen vereinfachen. Die „E-Evidence“-Verordnung“ soll die polizeiliche Abfrage von Daten bei Internetfirmen in anderen EU-Staaten unter Androhung hoher Bußgelder drastisch erleichtern. Für Firmen mit Sitz in den USA plant die EU-Kommission ein Durchführungsabkommen im Rahmen des „CLOUD Act“, den die US-Regierung erlassen hat. Dann können auch US-Behörden Daten von Sozialen Netzwerken oder Messengern in Europa abfragen, möglich wäre sogar das Abhören in Echtzeit. Zusätzlich verhandelt auch der Europarat über die schnelle Herausgabe elektronischer Beweismittel. Die „Budapest-Konvention“ zur Kooperation bei Computerstraftaten soll um eine „Sicherungsanordnung“ erweitert werden. Ebenfalls auf der Tagesordnung stehen die weiteren Verhandlungen für eine Verordnung zur „Verhinderung der Verbreitung terroristischer Online-Inhalte“. Hierzu sollen die Strafverfolgungsbehörden Anordnungen erlassen, denen innerhalb einer Stunde entsprochen werden muss. Die Firmen sollen außerdem Uploadfilter („automatisierte Werkzeuge“ gegen erneutes Hochladen) installieren. Auch das BKA beteiligt sich an den Vorbereitungen mit einer „nationalen Meldestelle“, die seit ihrem kurzen Bestehen bereits 6.000 Meldungen zur Entfernung von Inhalten verschickt hat. Schließlich arbeitet die EU an einer Neuauflage der Vorratsdatenspeicherung von Telekommunikationsdaten. Im Juni haben die Innenminister hierzu Schlussfolgerungen erlassen, die den Fahrplan vorgeben. Zwar ist die Rede von einer „beschränkten“ Vorratsdatenspeicherung. Tatsächlich wollen die Polizeien und Geheimdienste aber nur auf wenige Informationen verzichten, darunter die Länge genutzter Antennen, die Verbindungsqualität oder die Zahl der Klingeltöne des genutzten Telefons. Auch Berufsgeheimnisträger werden anlasslos überwacht, außer sie stellen einen Antrag auf Befreiung. Längst beschlossen und umgesetzt ist die EU-Richtlinie zur Speicherung von Fluggastdaten. Airlines, Reisebüros und andere Reiseanbieter müssen vor jedem internationalen Flug „Passenger Name Records“ (PNR) an die zuständige Fluggastdatenzentralstelle übermitteln. Allein in Deutschland werden in den nächsten Monaten 500 neue Stellen bei BKA, Bundespolizei, Zoll und Verwaltungsamt besetzt. Diese ufer- und anlasslose Vorratsdatenspeicherung ist ein gutes schlechtes Beispiel, weshalb den noch zu beschließenden EU-Vorhaben entschlossen entgegengetreten werden muss. about this event: https://fahrplan.events.ccc.de/camp/2019/Fahrplan/events/10195.html
Mit dem Getränkeautomaten in die Cloud (camp2019)
Ob an Getränkeautomaten oder in der Kantine: Oft wird in Universitäten oder großen Firmen mit einem internen Ausweis bezahlt. Wir haben eines dieser internen Bezahlsysteme einmal genauer in Bezug auf seine IT-Sicherheit untersucht und dabei überraschend viele Schwachstellen festgestellt. Interne, bargeldlose Bezahlsysteme können Transaktionen über einen Cloud-Dienst abwickeln. Die Informationssicherheit ist bei diesen Systemen von großer Bedeutung, um das Geld der Kunden und auch das Geld des Betreibers, der für die Abwicklung der Zahlung an die jeweiligen Abteilungen oder Dienstleistern die Verantwortung trägt, zu schützen. In diesem Talk soll die Sicherheit eines dieser Cloud-basierten Systeme genauer beleuchtet und dabei ein Großteil seiner Sicherheitsarchitektur auseinandergenommen werden. about this event: https://fahrplan.events.ccc.de/camp/2019/Fahrplan/events/10201.html
IT-Sicherheit in vernetzten Gebäuden (camp2019)
Ein automatisiertes Gebäude ist schön, komfortabel und praktisch. Doch das wäre nicht Thema für einen Vortrag beim CCCamp, wenn es nicht einige gravierende Schwachstellen in den Bussystemen gäbe. Der Vortrag bietet eine Einführung in die Funktionalität von vernetzten Gebäuden am Beispiel des KNX Standards. Ohne dass ihr großes Vorwissen benötigt, berichte ich euch von Sicherheitsproblemen und möglichen Lösungsansätzen zur nachträglichen Steigerung der Sicherheit solcher Gebäudeautomatisierungssysteme. Feldbusse wie KNX werden in modernen Gebäuden eingesetzt, um typische Vorteile der Gebäudeautomation zu erzielen. Man verspricht sich Komfortgewinn, Kosteneinsparungen und Flexibilität. Klassische Schutzziele wurden beim Design dieser Bussysteme hintenangestellt und IT-Sicherheit so sträflich missachtet. Funktionalitäten wie Verschlüsselung oder Authentifikation der Kommunikationsteilnehmer sucht man bisweilen vergeblich. Sind die Gebäude erst einmal gebaut, wird die installierte Infrastruktur über Jahrzehnte betrieben. Das Licht des Kollegen im Nachbarbüro zu schalten ist ebenso leicht, wie das Steuern einer an den Feldbus angebundenen Heizung. Was im Büro noch verhältnismäßig harmlos erscheint, wird bedrohlich, wenn man bedenkt, dass auch Kraftwerke und andere kritische Infrastrukturen ähnliche Systeme nutzen. Nach einer Einführung in den KNX Bus geht der Vortrag auf Schwachstellen und deren mögliche Folgen in automatisierten Gebäuden ein. Es wird gezeigt, dass sich aus scheinbar harmlosen Sensoraktivitätsdaten bereits intime, personenbezogene Informationen herausarbeiten lassen. Um die Sicherheit bereits installierter, langlebiger Gebäudeinfrastrukturen dennoch zu erhöhen, werden bereits bekannte Verfahren aus der IP-Welt auf Feldbusse übertragen. Netzwerksegmentierung, IDS und Filterung sind erste Ansätze, auf die der Vortrag eingeht. Es werden deren Möglichkeiten und Grenzen beschrieben. Darüber hinaus wird ein entwickelter Testdatensatz zur Evaluierung solcher und anderer Ansätze vorgestellt. about this event: https://fahrplan.events.ccc.de/camp/2019/Fahrplan/events/10349.html
#Fusionbleibt (camp2019)
Polizeiwache mitten auf dem Festival? Wasserwerfer? Räumpanzer? WTF?? dachte sich da auch das Fusion Festival. Der Kampf gegen die absurden Pläne von Polizeipräsident Nils Hoffmann-Ritterbusch konnte zum Glück gewonnen werden. Und ist ein Lehrstück dafür, dass zivilgesellschaftlicher Druck eben doch Berge versetzen kann. Wir lassen Drohungen, Protest und Absurditäten aus diesem Lehrstücks gemeinsam Revue passieren. Und ja: es darf gelacht werden. about this event: https://fahrplan.events.ccc.de/camp/2019/Fahrplan/events/10438.html
What you see is not what you get - when homographs attack (camp2019)
This talk offers a brief overview about homograph attacks, describes part of the mechanics behind the registration of homograph domains, highlights their risks and presents a chain of two practical exploits against Signal, Telegram and Tor Browser that could lead to nearly impossible to detect phishing scenarios and also situations where more powerful exploits could be used against an opsec-aware target. Since the introduction of Unicode in domain names (known as Internationalized Domain Names, or simply IDN) by ICANN over two decades ago, a series of brand new security implications were also brought into light together with the possibility of registering domain names using different alphabets and Unicode characters. This talk offers a brief overview about homograph attacks, describes part of the mechanics behind the registration of homograph domains, highlights their risks and presents a chain of two practical exploits against Signal, Telegram and Tor Browser that could lead to nearly impossible to detect phishing scenarios and also situations where more powerful exploits could be used against an opsec-aware target. Historical security issues related to Unicode and confusable homographs, as well as other attack vectors not discovered by the author will also be explored in this presentation. about this event: https://fahrplan.events.ccc.de/camp/2019/Fahrplan/events/10258.html
Updates from the Onion (camp2019)
The Tor Project is building usable free software to fight surveillance and censorship across the globe. In this talk we'll give an update on what we have been up to in the past months, what happened in the wider Tor ecosystem, and what lies ahead of us. In the last year the Tor Project has been working hard on improving the software, building and training communities around the world as well as creating an anti-censorship team and roadmap that can push forward technologies to circumvent censorship. This talk will cover major milestones we achieved and will give an outline about what is lying ahead. In particular, we'll talk about the release of Tor Browser for Android and restructuring our anti-censorship efforts as well as working on next generation pluggable transports. Moreover, we'll explain our defense against website traffic fingerprinting attacks and plans for improving onion services and making them more usable (DDoS resistance, better user interfaces for authentication and dealing with errors). Finally, we'll shed some light on efforts to get Tor support directly embedded into other browsers, like Firefox and Brave, and educating users both by reorganizing the content on our website and extensive trainings throughout the world. about this event: https://fahrplan.events.ccc.de/camp/2019/Fahrplan/events/10340.html
Zombie Apocalypse vs. International Health Regulations (camp2019)
The little known International Health Regulations are Earth's last defence line against world-wide health risks. I discuss how they would perform during a Zombie Apocalypse. The International Health Regulations (IHR) are a piece of legally binding, international law that (theoretically) all countries have to adhere to. After the catastrophic 2003 SARS outbreaks, unlikely partners such as the USA and Iran, together with 192 other member states of the World Health Organisation, agreed upon these rules that entered into force in 2007. This set of rules aims to prevent international spread of health risks (usually communicable diseases) while balancing international travel and, of course, trade. I will use the popular Zombie Apocalypse metaphor to illustrate the various prevention mechanisms of the IHR and how they were (and will be) circumvented by past and future epidemics. about this event: https://fahrplan.events.ccc.de/camp/2019/Fahrplan/events/10367.html
Domain computers have accounts, too! (camp2019)
In Microsoft Active Directory, computers also have their accounts. We used to consider them useless when they turned up during pentests, but recent research showed that successfully relaying a machine account can actually lead to completely owning the machine. This talk will explain the foundation of such attacks and end with a demonstration of how a non-privileged domain user can get SYSTEM privileges on remote machines. Active Directory is notorious for using long-broken protocols and preserving them for ages because backwards compatibility. In recent years, pentesters are realizing more and more how terrible these protocols can be, and security experts are finding more and more abuse scenarios. Take for example the NTLMv2 challenge-response protocol: It was first introduced back in Windows NT 4.0 SP4 and is still readily available on modern windows. Apart from not being very resistant to cracking (using just a few MD5s), it turned out it's not resistant to MITM attacks at all. An attacker in a MITM position can relay any authentication attempts to almost any target. There were some mitigitations for this over the years, but we are just now starting to see people actually starting to use them. So when relaying came to existence, security researches focused on "what can we do with this"? Obviously, if you manage to succesfully relay a Domain Administrator account, you have won; but that's not always possible. Another protocol used extensively in Active Directory is Kerberos. The Microsoft implementation has several delegation/impersonation techniques available. And now, we know how to combine all these to be able to impersonate any user to a computer, given we were able to relay that computer's authentication at least once. The talk will cover these main areas: <ul> <li>NTLM Relaying</li> <li>Kerberos delegation</li> <li>Getting machines to authenticate to us</li> </ul> All tools necessary to perform this attack will be released as impacket modules. This talk is mainly based on research by @tifkin_ (Lee Christensen), @harmj0y (Will Schroeder), @enigma0x3 (Matt Nelson), @elad_shamir (Elad Shamir), @_dirkjan (Dirk-jan). about this event: https://fahrplan.events.ccc.de/camp/2019/Fahrplan/events/10207.html
Participatory art event tools, co-creation and silk road networks (camp2019)
The Borderland is a participatory art event in Denmark with 3210 co-creators. Over the last three years, we have created online tools to keep participation and co-creation high as the event has tripled in size in only three years. This seminar is about the design philosophy behind these tools, drawing parallels to the ancient silk road. These tools have since been spread to at least five other events around the world. In developing the Borderland community online and offline, we've built tools that help us create denser networks, allowing for share creative processes, distributed art-grant allocation, empowered community members and decentralized decision making. These tools, called Dreams and Realities are run alongside a customized version of the Loomio platform and our own instance of the Pretix ticketing platform. Dreams is for distributed art-grant distribution and project guidance. Realites is for stakeholder-mapping to understand how the needs, responsibilities, people and dependencies fit together in a decentralized organization. about this event: https://fahrplan.events.ccc.de/camp/2019/Fahrplan/events/10204.html
Introduction to OpenGLES and GLSL programming (camp2019)
This foundation talk describes the basic concepts of the OpenGLES 2.0 real-time rasterizer. We will explain the different stages of the rendering pipeline, briefly introduce the mathematics involved, show the boilerplate code required to setup an OpenGLES program, and finally look at the real fun stuff, which is the GLSL language used in vertex and fragment shaders. From notebooks and smartphones to embedded systems and game consoles, every modern computing platform contains chips for hardware accelerated 3d rendering. The OpenGL standard and API describes the drawing directives provided by these chips and is used to compose and animate user interfaces and to render interactive virtual scenes. Basically, every pixel that you see has been processed by an OpenGL pipeline. Engines like Unity3d provide a convenient way to describe and render threedimensional scenes without having to deal with the low level drawing directives. But this convenience makes it difficult to understand the path by which your logic becomes pixels, and coding closee to the hardware can be a lot of fun. This foundation talk describes the basic concepts of the OpenGLES 2.0 real-time rasterizer. We will explain the different stages of the rendering pipeline, briefly introduce the mathematics involved, show the boilerplate code required to setup an OpenGLES program, and finally look at the real fun stuff, which is the GLSL language used in vertex and fragment shaders. After watching this talk, you will have a better understanding of the pipelines that are used to create the pixels on your screen. If you already know a high-level programming language such as C/C++, Java or Go, the examples provided will help you get started with coding your own 3d app, game or demo. about this event: https://fahrplan.events.ccc.de/camp/2019/Fahrplan/events/10256.html
Taking Bluetooth lockpicking to the next level (camp2019)
If hacking chinese padlocks and bike sharing systems isn't enough any more, let's go and open some new doors. Like the ones of some 37th floor Hotel Suites... We're taking Bluetooth LE hacking from toys and padlocks to the real world. Improving the tools and methods we used in previous research to break the AES cryptography of the NOKE Padlock, we went to do the one thing a mobile hotel key is supposed to prevent: wirelessly sniff someone entering his room - or just unlocking the elevator - and then reconstruct the needed data to open the door with any BTLE enabled PC or even a raspberry pi. In this talk we will show and explain the tools and methods we used and developed to break the BTLE based mobile phone key system of a large hotel chain. And then come from the academic proof of concept to a reliable setup that can be used in real life scenarios to carry out the attack. Methods shown will cover the reverse engineering of the wireless protocol based on BTLE captures, analyzing phone apps and intercepting the TLS encrypted traffic to the back end API, which in combination led to the compromise of a system used in quite some big and expensive hotels for their "next level" customer experience: mobile room keys. about this event: https://fahrplan.events.ccc.de/camp/2019/Fahrplan/events/10241.html
E-Mail-Privatheit und Mailbox-Verschlüsselung (camp2019)
Überblick über den aktuellen Stand der Privatheit von E-Mails und Präsentation von [Userli](https://systemli.github.io/userli/), einer Webapplikation um E-Mailboxen zu verschlüsseln. Zuerst werden die derzeitigen Probleme der Privatheit von E-Mail beleuchtet. Dies soll zeigen, dass es sich um eine Vielzahl von Problemen handelt, welche einzeln gelöst werden müssen. Danach wird Userli präsentiert, welches einen Teil dieser Probleme angeht: Die Privatheit des E-Mail-Storage. Userli ist eine FOSS-Webapplikation um die Verwaltung von E-Mail-Konten für Communities zu unterstützen und Postfächer zu verschlüsseln. Auch die Admins eines Servers können dann nicht mehr in die gespeicherten E-Mails schauen. Userli fokussiert sich auf die Selbstverwaltung kleiner Communities und bietet daher auch Einladungsmechanismen, Domain-spezifische Admins und weitere Rollen. Alias-Adressen helfen deine Identität vor Dritten zu verschleiern. Userli verwendet das Dovecot MailCrypt Plugin und libsodium um Postfächer zu verschlüsseln und einen Passwort-Reset-Mechanismus anzubieten, welcher ohne persönliche Informationen auskommt. about this event: http://talx.thm.cloud/thms/talk/ACSFZ7/
TAPS Transport Services API (camp2019)
In the last year, a group of researchers and some industry people at the IETF decided to join forces and design a replacement of the BSD Socket API. This talk gives an overview about why the BSD Socket API is considered harmful for the Internet's future and how TAPS tries to solve this problem. Besides the facts, also gives some hints about how standardisation at the IETF works and why all this takes so long… The BSD Socket API was designed more than 30 years ago. No one back than imagined hosts with multiple access networks, concurrent use of multiple communication protocols, e.g., IPv4 vs IPv6 and TCP/TLS vs QUIC, and incorporating quality of service (QoS), security and cost constrains for setting up communications. The result is a complex ecosystem of APIs and techniques that must be manually combined in order to write state of the art network applications. The talk will give a brief overview on what choices state of the art network applications can make, why the BSD socket API does not support it and how TAPS tries to solve this. I will also talk a little bit about how standardisation at the IETF works, why one may want to get involved and why all this takes so long… about this event: https://fahrplan.events.ccc.de/camp/2019/Fahrplan/events/10298.html
Anykernels meet fuzzing (camp2019)
Battle of making the NetBSD better software by leveraging anykernels The NetBSD offers RUMP anykernel which lets users to do the magic and execute drivers, network stacks or file systems in userspace. Having kernel parts running in user space is a great opportunity to fuzz them efficiently without fancy kernel approaches. First general information about RUMP will be discussed to get the audience familiar with the subject, then results focused on testing network stack will be presented along with encountered problems and other fuzzing efforts that currently are taking place in the NetBSD project. about this event: https://fahrplan.events.ccc.de/camp/2019/Fahrplan/events/10334.html
Dissecting the AMD Platform Security Processor (camp2019)
The AMD Platform Security Processor (PSP) is a security subsystem in AMD CPUs comparable to the Intel ME and was introduced in 2013. It is essential for system startup – in fact, in runs before the main processor is even started – and offers runtime services to the main processor. For this, it has full access to the system memory space (inlcuding MMIO). The PSP runs undocumented, proprietary firmware. This talk presents efforts of investigating what the PSP does and if it's secure. For the first time, it documents the PSP firmware's proprietary filesystem and provides insights into reverse-engineering such a deeply embedded system as the PSP. The talk further sheds light on how we might regain trust in AMD CPUs despite the delicate nature of the PSP. With the ongoing digitalization, not only the number of IT systems is increasing in many domains, but also the amount of software and hardware that forms the trusted computing base of an application. Applications in industrial systems, infrastructure and consumer electronics rely on the security of these systems. Emerging security technologies try to mitigate the risk of insecure software and hardware by embedding secure components into these untrusted systems. AMD introduced the AMD Secure Processor to provide a trusted execution environment for critical operations. This talk comprehensively analyzes the undocumented and largely unknown security co-processor and discovers its inner workings. It aims to find out if it is able to keep its promise – or if it opens up another attack vector. about this event: http://talx.thm.cloud/thms/talk/LEA7LY/
Lightning Talks (camp2019)
about this event: https://fahrplan.events.ccc.de/camp/2019/Fahrplan/events/10380.html
Robotron (camp2019)
In den letzten 2 Jahren habe ich mich in meiner künstlerischen Arbeit mit der Computerherstellung in der DDR beschäftigt. Technikproduktion in der DDR war durch Planwirtschaft und dem COCOM-Hochtechnologieembargo besonderen Bedingungen unterworfen. Entlang der künstlerischen Ausseinandersetzung möchte ich in dem Vortrag ein Bild über Ostdeutsche Computertechnologie nachzeichnen. Die Web Serie Robotron – a tech opera spielt im VEB Kombinat Robotron, dem größten Computerhersteller der ehemaligen DDR und einer der bedeutendsten Produzenten von Informationstechnologie im sozialistischen Osteuropa. Anhand der eigenen Familiengeschichte zeichne ich eine Technikgeschichte nach die heute niemanden mehr interessiert. Weil sie nicht der Logik einer Erfolgsgeschichte entspricht und es sich bereits um obsolete Technik handelt. Als zeitgenössisches Netzformat tauchen in den meisten ASMR Videos nur aktuelle High-tech Utensilien auf um Tingles (Kopfkribbeln) hervorzurufen. In Soft Nails ~ ♥ [ASMR] Kleincomputer Robotron KC87 ♥ greife ich bewusst auf High-tech aus der DDR zurück und überführe sie in ein popkulturelles Format. Der Versuch einer gängigen US-amerikanischen Technikerfolgsgeschichte ein alternatives Narrativ entgegensetzen/ hinzufügen. In der Arbeit The Adventures of WH beschäftige ich mich in Kollaboration mit der Künstlerin Anne Baumann, mit Werner Hartmann (1912 - 1988), mein Stiefopa und der Begründer der Mikroelektronik in Ostdeutschland. Von 1961 – 1974 war er Leiter der AME, auch genannt AMD (Arbeitstelle für Molekularelektronik Dresden). Werner Hartmann gehörte einer wissenschaftlichen Elite in der DDR an und wurde aufgrund seiner Parteilosigkeit seit 1965 in der DDR systematisch beschattet und sogar 1974 wegen Spionage-Vorwürfen als Direktor der Arbeitsstelle für Molekularelektronik in Dresden suspendiert. Die Stasi hat 49 Ordner zur Überwachung von WH angelegt. Parallel legte WH ein Archiv mit seinen Memoiren (wissenschaftl. Tätigkeit in der Nazizeit, Sowjetunion und der DDR) sowie seinen Gedanken zur Mikroelektronik, u.a. an. about this event: https://fahrplan.events.ccc.de/camp/2019/Fahrplan/events/10293.html
OpenCodes (camp2019)
Computer können Kunst erzeugen. Museen können Kunst ausstellten. Wie kann das zusammen kommen? Und welche Rolle spielen Community- und OpenSource-Gedanken darin? Der Vortrag ist die Geschichte eines Ausstellungs- und Bildungskonzeptes, welches auch von Hackern entworfen wurde. Die Ausstellung 'Open Codes' wurde zusammen mit Karlsruher Communities, unter anderem dem Entropia, FabLab und Freifunk entworfen und erweitert. Es geht um einen Blick hinter die Kulissen einer Gesellschaft, die immer weiter in das Digitale wandert. Kostenloser Eintritt, Freifunk-WLAN, Tische, Sofas, Tischtennisplatte, kostenlose Getränke und Snacks, Hackathons, die Gulaschprogrammiernacht, PyCon, Wikimedia usw. lassen einen fast vergessen, dass man in einem Museum steht. Programmieren und hacken im Museum, wie geht das? Die Ausstellung ist weit mehr als eine kuratierte Sammlung von Medienkunstwerken, die sich mit dem Thema Code befasst. Es werden auch Themen wie OpenSource und die Hackercommunity greifbar gemacht. Die Werke sind Eckpunkte für Diskussionen, die bereits in Hacker-, Mackerspaces und digitalen Communities passiert. Der Vortrag verfolgt den gesamten Weg der letzten drei Jahre: von der ersten Konzeptskizze und Tschunkparties mit Kuratorinnen und Hackern über die Ausstellungseröffnung mit Feldtelefon, Hackcenter und Häppchen, "Bitte nicht hacken, das ist Kunst"-Schildern bis zu einer Lovestory - Still a Better Love Story than Twilight - zwischen zwei Welten, die anders nicht sein könnten. Da dürfen Indien und China auch nicht fehlen... about this event: https://fahrplan.events.ccc.de/camp/2019/Fahrplan/events/10400.html
Achtung, Datenpannen! (camp2019)
<p>Eine Mischung aus einem Vortrag und einer Spiel- und Lernshow rund um die Datenschutz-Grundverordnung, die spielerisch Wissenswertes rund um Datenschutz und die Datenschutz-Grundverordnung vermittelt – anhand von tatsächlichen Beratungsanfragen und Datenpannen-Meldungen, die tagtäglich bei den Aufsichtsbehörden eingehen. Im Stil der Spielshow „Der Große Preis“ stehen Kandidaten Rede und Antwort zu skurrilen Fällen und heiß diskutierten Problemen rund um Datenschutz, technischen Maßnahmen und die DS-GVO.</p> <p>Bei Diskussionen über Datenschutz kommen technische Maßnahmen aus dem Bereich der IT-Sicherheit bisher oftmals viel zu kurz. Dabei können fehlende oder falsch implementierte Maßnahmen Sanktionen der Aufsichtsbehörden nach sich ziehen.</p> <p>Die große <strong>Datenschutz- und DSGVO-Show</strong> vermittelt auf spielerische Weise rechtliche, technische und praktische Hilfe rund um Datenschutz und die EU-Datenschutz-Grundverordnung. </p> <ul> <li>Welche Verschlüsselungs-Verfahren muss ein Datenverarbeiter verwenden, um kein Bußgeld zu riskieren?</li> <li>Erfüllt ein verschlüsselter ZIP-Anhang in einer E-Mail die Anforderungen der DS-GVO auf „Sicherheit der Verarbeitung“?</li> <li>Oder die „bisher ungeknackte Vollbitverschlüsselung“?</li> <li>Ist ein Messenger-Dienst „sicher“, wenn er Telefonnummern als SHA-256-Hash speichert?</li> <li>Muss ein Online-Shop wirklich alle Kunden informieren, wenn „ein Hacker“ erfolgreich „nur die E-Mail-Adressen der Kunden“ kopiert hat?</li> <li>Und was ist mit Google Analytics oder Facebook-Plugins auf Websites?</li> <li>Welche Rechte hat ein Betroffener gegenüber Datenkraken?</li> </ul> <p>Die Moderatoren sind der <em>Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg</em> Stefan Brink und zwei Referenten und berichten aus der praktischen Arbeit einer Aufsichtsbehörde. Vor und während dem eigentlichen Quiz geben sie eine kurze Einführung über häufige Datenpannen-Meldungen, rechtliche Grundlagen, Hinweise zu technischen Maßnahmen nach Artikel 32 DS-GVO und die oftmals schwierige Risikoabschätzung.</p> <p>Im Quiz selbst müssen die Kandidaten in ihren Antworten praktische Lösungsvorschläge für häufige technische und rechtliche Probleme vorschlagen, zum Beispiel welche technischen Maßnahmen bei bestimmten Datenpannen nach dem „Stand der Technik“ angebracht sind, ob man als Website-Betreiber denn nun Google Analytics nutzen darf oder wie man sich gegen rechtswidrige Datensammler wehrt. Dadurch können Teilnehmer wie Zuschauer die praktische Anwendung der DS-GVO spielerisch lernen.</p> about this event: https://fahrplan.events.ccc.de/camp/2019/Fahrplan/events/10344.html
A mobile phone that respects your freedom (camp2019)
Motivation and challenges building a mobile phone that respects your freedom, privacy and digital rights - and is hackable. This talk will present a summary of a two year journey, which is still ongoing. Today mobile phones are _the_ computing device of the decade, maybe even of this century. Almost everyone carries one, every day to every place. They are pretty much always connected and we entrust almost our entire digital life to them - any form of communication (voice, text, video), all kinds of entertainment (reading, web surfing, video/movies), personal information (address books, social media), location (navigation, location sharing) etc. Pretty much our entire digital life is mirrored by these devices and to a growing extent happening right on them. What is often not fully recognized is that this huge ecosystem of mobile hard- and software is controlled by only a very few globe spanning companies. Our digital life is to a large part controlled by these companies and currently there is little way around them. This talk will present the experiences we had and have in this industry creating a mobile phone that is running 100% free software, respects the user's digital rights and gives back full control over data and communication to the user - by separating radios from the main CPU, by providing hardware kill switches and by using only free software for the full stack. We will also talk about the huge challenges encountered, from CPU choice to radio choice up through the software stack. It will also share our approaches to solve these challenges and share experience in working with hardware manufacturing companies (globally), from electronics design to product manufacturing. about this event: https://fahrplan.events.ccc.de/camp/2019/Fahrplan/events/10238.html
Als Netzaktivistin im Bundestag – Insider Einblicke und Mitmachmöglichkeiten (camp2019)
Automated security testing for Software Developers who dont know security! (camp2019)
Automated security testing for Software Developers who dont know security! (camp2019)
i'll show how the average developer (like me) can secure their software and systems by automatically checking for known vulnerabilities and security issues as part of their CI-Toolchain. The Talk will introduce basic security knowhow, then show how you can use Open Source Frameworks to check for vulnerable dependencies, containers and (web-)APIs in a live demo about this event: https://fahrplan.events.ccc.de/camp/2019/Fahrplan/events/10181.html
Hambacher Forst #hambibleibt (camp2019)
Seit 2012 ist der Hambacher Wald besetzt. about this event: https://fahrplan.events.ccc.de/camp/2019/Fahrplan/events/10389.html
500.000 Recalled Pacemakers, 2 Billion $ Stock Value Loss (camp2019)
Als Netzaktivistin im Bundestag – Insider Einblicke und Mitmachmöglichkeiten (camp2019)
Der Bundestag ist anders als man denkt. Analoger als man ohnehin vermutet, mit irrsinnigen Abläufen und unvorstellbaren Papierbergen. Es ist viel anstrengender, als man sich je hätte ausmalen können. Man hat zu viel Durst und zu wenig Schlaf und kaum noch ein Privatleben. Aber man kann einen Unterschied machen und deshalb will ich zeigen, dass Politik auch kompetent, transparent und partizipativ möglich ist. In dieser Session gebe ich Insider Einblicke in den Alltag als netzpolitische Sprecherin der Linksfraktion im Bundestag, zeige die Handlungsmöglichkeiten einer Oppositionspolitikerin und wie Ihr als Netzcommunity mich als Eure Volksvertreterin nutzen könnt, um z.B. auf offiziellen Kanälen Informationen abzufragen, an die man sonst nicht kommt, denn Wissen ist Macht. Die Arbeit einer Bundestagsabgeordneten hatte ich mir anders vorgestellt. Schon rein vom praktischen Alltag her. Mich überraschten Trinkverbote, 17-stündige Plenartage ohne Pausen, Schreibmaschinen, Karteikarten und Faxgeräte, ich verlief mich in unterirdischen Labyrinthen, fing 19 Mäuse im Büro und freute mich, als 2018 endlich das WLAN kam. Ich wurde netzpolitische Sprecherin der Linksfraktion, Mitglied bzw. stellvertretendes Mitglied im Digitalausschuss, im Beirat der Bundesnetzagentur (Megathema 5G Lizenzversteigerung), der Enquete Kommission Künstliche Intelligenz, in den Ausschüssen für Bildung/Forschung/Technikfolgen sowie für Verkehr und digitale Infrastruktur. In 22 Monaten hielt ich 19 Reden, stellte 43 schriftliche Fragen, 33 Kleine Anfragen, 5 Anträge und reichte einen eigenen Gesetzentwurf ein. Es ging um Überwachung am Südkreuz, Open Source, das NetzDG, Hackbacks, IPv6, Künstliche Intelligenz, DNA Analysen in der Stammbaumforschung, Uploadfilter, IT Sicherheit, Impressumpflichten, barrierefreie Notrufe, Whistleblower, Mobilfunk, Open Data, KfZ Scanning, Funkzellenabfragen und stille SMS, digitale Gewalt gegen Frauen, Bundeswehr bei re:publica, Verschlüsselung, Lobbyregister, social Innovation und vieles mehr. Auf parlamentarischen Reisen im Ausland lernte ich, wie weit das links regierte Uruguay in der digitalen Bildung ist, wie man in Oman durch kluge Regulierung die Funklöcher auf dem Land los wurde und wie viele Lichtjahre wir vom eGovernment in Dänemark entfernt sind. Seit 10 Jahren setze ich mich für transparente und partizipative Politik ein. Jetzt will ich meine eigenen Ansprüche daran auch erfüllen. Ich berichte vor allem auf Twitter und Instagram live aus Ausschüssen, Anhörungen und von Parlamentarierreisen und greife Anregungen auf, die mich auf irgendeinem Kanal erreichen. Ich verstehe mich als Volksvertreterin im Wortsinn und möchte als Netzaktivistin ganz besonders Sprachrohr der Netzcommunity sein. Als Politikerin einer Oppositionspartei kann ich Themen setzen und Informationen beschaffen, ich kann fiese Fragen stellen – in langen und kurzen Formaten und die Bundesregierung muss darauf antworten. In dieser Session werde ich Beispiele zeigen, über meine Pläne reden und Euch fragen, was Ihr schon immer von der Bundesregierung in Netzfragen wissen wollten, damit ich die GroKo weiter nerven kann und wir alle besser wissen, was sie tun. about this event: http://talx.thm.cloud/thms/talk/GRRQTX/
Blockchain: Proof of ignorance (camp2019)
<p>A rant about liberty and autonomy for some! The Blockchain is celebrated for solving all the hard questions, trusted third-parties? Done! Supply-chain-control? Easy! Deliberation of the individual? Complete! But how come, that so many users move to Exchanges (Bitcoin), lawyers consider smart contracts not contracts (Etherium) and most other actually used Blockchains are either permissioned or private (read: databases). So, why does blockchain does not solve any problem and only grants liberty and autonomy for some &ndash; the techies themselves? Come hear my take on this and let's debate the present misunderstanding of what the blockchain technology actually can deliver.</p> about this event: http://talx.thm.cloud/thms/talk/WCSCAX/
Logbuch:Netzpolitik 311 (camp2019)
Logbuch:Netzpolitik ist ein in der Regel wöchentlich erscheinender Podcast, der im Dialog zwischen Linus Neumann und Tim Pritlove die wichtigsten Themen und Ereignisse mit netzpolitischem Bezug aufgreift und diskutiert. https://logbuch-netzpolitik.de/lnp311-i-love-you-but-i-have-chosen-datenschutz Es war wieder Camp und es war wieder einmal das tollste Camp, was es je gab. Und Logbuch:Netzpolitik war mit dabei auf der Bühne des wundervollen Three Headed Monkeys Village. Und wie so oft haben wir wieder ein paar Gäste dabei, die die Grenzen zwischen Kunst und Aktivismus verschwimmen lassen. Wir sprechen mit Markus und Johannes über ihre Analysen der Twitter-Aktivitäten von dem ehemaligen Verfassungsschutz-Chefs Maaßen und mit Sofia und Viktor von der Digitalen Freiheit, die auch noch gemeinsam als Band auftreten. about this event: http://talx.thm.cloud/thms/talk/LJQNKC/
Fully Open, Fully Sovereign mobile devices (camp2019)
Removing the barriers to making network independent mobile communications. In this talk I will discuss our thinking and progress towards making personal mobile communications devices, i.e., things that you use like a smart-phone, but that are fully under the control of the owner. While this has been done before, we have been focusing on how to make this much easier to do, so that individuals or small teams can create their own custom devices, with whatever features, inclusions and physical form they like, without huge time or cost requirements. This makes it possible to solve security and privacy problems, and also problems like creating custom devices for people living with disability, so that they can have a device that works for them and with their abilities and needs. I will discuss our work-in-progress in this area, the MEGAphone, which is not only a mobile phone, but also includes UHF packet radio and a modular expansion scheme, that can allow allow the incorporation of satellite and other communications. It is also backwards compatible with the Commodore 64, so can already play loads of privacy-preserving games, and has its own open-source slide presentation software that we hope to use to deliver the talk. Private UHF and VHF radio communications is a complex space, in terms of regulation, which we have some experience in due to the Serval Project, which has informed our design of the MEGAphone. I will thus discuss issues such as using "license free" bands around the world, as well as options for using either licensed spectrum or existing legacy public spectrum allocations, such as Citizen Band (CB) radio. As the MEGAphone platform is FPGA based, it is quite possible to implement software defined radio solutions to allow flexible and low-cost access to such spectrum. about this event: https://fahrplan.events.ccc.de/camp/2019/Fahrplan/events/10378.html
River Crab, Harmony and Euphemism (camp2019)
An informative and lighthearted overview of contemporary Chinese online culture A river crab (Hé Xiè) is a homophone of “harmony”(Hé Xié) in Mandarin Chinese. The word "harmonious society" was brought up by ex-Chinese leader Hu Jintao's in his speech on signature ideology, which gradually led to the censorship policy that we see nowadays on Chinese internet. The talk will introduce its recent history and status quo of the censorship with actual cases. I’ll explain, as a native speaker of Chinese language, the subversive humor and ingenious creativity that Chinese netizens employ to get around the infamous online censorship. The censorship scheme is as bad as portrayed in Western media, however you don’t often see people talk about its inefficiency, if not futility. Due to the complicated nature of Chinese language, the collective intelligence can always quickly come up with many ways- homophones being one of them - to circumvent the existing list of censorship. You won’t become a China expert after the talk but your will definitely know a bit more about the linguistic and cultural aspects of the gigantic country than before. about this event: https://fahrplan.events.ccc.de/camp/2019/Fahrplan/events/10239.html
Fangespielen mit IMSI-Catchern (camp2019)
Mobiltelefone hinterlassen aufgrund ihrer Funkaktivität in der Umgebung vielfältige Spuren, die von entsprechendem passiven Equipment aufgespürt und verarbeitet werden kann. Doch um tiefer in die Kommunikation zu schauen, braucht es aktive Netzwerkomponenten – sogenannte IMSI-Catcher oder Stingrays, die den Kontakt zu ihren Zielen direkt suchen und Informationen austauschen. Doch wenn sich solche hinterhältigen Basisstationen auf die Lauer legen, müssen sie sich zu Erkennen geben – und können erkannt werden. Der Vortrag erörtert technische Hintergründe, verräterische Anzeichen eines Angriffs und was Netzwerkbetreiber und Nutzer dagegen tun können. Oshie arbeitet seit 4 Jahren an Heuristiken zur Erkennung und Werkzeugen zur Visualisierung von rogue base stations. Der Vortrag gibt einen Überblick wie IMSI Catcher arbeiten, was sie heutzutage leisten und wie sie dabei beobachtet werden können. Hierbei werden Sicherheitsfeatures der unterschiedlichen Netzgenerationen, von 2g bis 4g, betrachtet und was das konkret für den Einsatz von IMSI Catchern bedeutet. about this event: https://fahrplan.events.ccc.de/camp/2019/Fahrplan/events/10357.html
Caught in the Net (camp2019)
Increasingly, governments are moving to impose regulatory measures that would require the removal of extremist speech or privatize enforcement of existing laws. But all too often, these regulations infringe on human rights. What should societies be doing to counter extremism while ensuring the rights of the vulnerable are preserved? Social media companies have long struggled with what to do about extremist content on their platforms. While most companies include provisions about “extremist” content in their community standards, such content is often vaguely defined. Governments increasingly rely on platforms to regulate speech for them, relying on the very same rulesets. These vague policies, coupled with the practice of for-profit commercial content moderation, has led to mistakes at scale that are decimating human rights content on these platforms and threatening our civil liberties. Furthermore, the very idea that censorship can solve the deeply rooted problems of extremism in modern society is a mistake. about this event: https://fahrplan.events.ccc.de/camp/2019/Fahrplan/events/10255.html
Die 5G-Überwachungsstandards (camp2019)
Europol und die nationalen Polizeibehörden laufen Sturm gegen die neuen Überwachungsstandards, die im „European Telecom Standards Institute“ (ETSI) gerade für die 5G-Netze entwickelt werden. Die Telekom-Industrie hatte die Strafverfolger im ETSI überstimmt. Es sei "jetzt wichtig, politischen Druck“ auszuüben, "um die Definition des Standards noch zu beeinflussen“, heißt es in einem internen Schreiben von Anti-Terror-Koordinator Gilles de Kerchove an den EU-Ministerrat. Konkret will man die Terlekoms zwingen, ihre 5G-Netzarchitektur entlang der Bedürfnisse der Strafverfolger auf- und Sicherheitslücken für IMSI-Catcher einzubauen. Der Vortrag schildert den letzten Stand dieser Auseinandersetzung. about this event: https://fahrplan.events.ccc.de/camp/2019/Fahrplan/events/10211.html
Beyond the Pile of Knobs (camp2019)
This case study of NoScript’s UX redesign showcases tried and true design principles that make security tools usable to a wider range of audiences. Open source security tools are often associated with customizability and transparency: users are given many options (configurations, self-hosting), and system states are more often than not visible to users (detailed connection info, logs). Sometimes, that means bulky user interfaces and technical language, making an otherwise useful and recommended tool less usable for non-technical audiences. This presents a distinct design challenge: is it possible to build tools that are more usable without compromising on customizability and transparency? In this talk, we will present some UX design principles based on our work with NoScript, a browser extension that allows users to fine-tune their script blocking in Firefox and Chrome/Chromium. We will focus on 1) understanding the value you add for your users, 2) choosing sensible default options, and 3) updating interface language for a wider audience. In the course of that, we will also present our process of human-centered design for improving security tools. (Outlined here: https://simplysecure.org/what-we-do/usable-security-audit/ ) about this event: https://fahrplan.events.ccc.de/camp/2019/Fahrplan/events/10368.html
15 Jahre netzpolitik.org (camp2019)
Im Sommer 2004 erschienen die erste Artikel auf netzpolitik.org. Was als Seitenprojekt begann, entwickelte sich in 15 Jahren zu einer der schlagkräftigsten Organisationen zur Verteidigung von digitalen Grundrechten in Deutschland. Der Vortrag will einen nicht ganz ernsten Überblick über die Geschichte von netzpolitik.org geben, was auch eine kleine Geschichte der digitalen Zivilgesellschaft in Deutschland ist. Von den erfolgreichen Kämpfen gegen Softwarepatente über die Vorratsdatenspeicherung und Zensursula bis hin zu ACTA und den Uploadfiltern. Mit Bildern, Screenshots und vielleicht auch dem einen oder anderen kurzen Video. about this event: http://talx.thm.cloud/thms/talk/9P8DR9/
500.000 Recalled Pacemakers, 2 Billion $ Stock Value Loss (camp2019)
During an independent security assessment of several pacemaker vendors multiple lethal and highly critical vulnerabilities were found. Based on previous experience with one specific vendor a new way of monetising vulnerabilities has been chosen. After going public a huge discussion on vulnerability disclosure ethics and responsibilities began. The stock value of the affected vendor dropped by 2 billion dollar just in one single day. The security researchers got discredited and a huge lawsuit was started. After a year of mutual accusations and denial more than 500.000 pacemakers got recalled. This talk will provide insights into pacemaker security and share first-hand experience gathered during this project. A special focus will also be on ethical vulnerability disclosure and lessons learned for future security research. about this event: https://fahrplan.events.ccc.de/camp/2019/Fahrplan/events/10288.html
Tales from Hardware Security Research (camp2019)
Almost every microcontroller features firmware readout protection. It aims at securing the code, algorithms, and cryptographic keys against unauthorized access. Despite datasheets are promising strong security, our research shows that this is often far from being true. In this talk we want to shed light onto the "why?" and especially "how?" we approach the security testing of such protection mechanisms. Furthermore, we will talk about our attempts, discussions, and hassles from the vulnerability disclosure process - from successful ones to dead ends. Since several years, we, Johannes and Marc, do practical research in the field of embedded system security at a research institute. In this talk, we want to give an insight into the daily work as hardware security researchers. This ranges from giving recommendations on how to secure systems up to verifying microcontroller security in real environments. However, no practical experience and information on the resilience of common microcontrollers is publicly available - a gap we want to close. Especially when trying to make use of the integrated security features, their effectiveness often collapses quickly due to design weaknesses. Our focus lies on firmware protection mechanisms since they often are the root of security in embedded systems. During our research we were able to circumvent several mechanisms implemented from different manufacturers. In most cases, each attack requires only low-priced equipment, thereby increasing the impact of each weakness and resulting in a severe threat altogether. We will present one of those attacks, which can be performed within minutes, on stage. Due to the severe impact of these results, we immediately informed the manufacturers in a coordinated disclosure process. However, this is often not as simple as expected and maybe even risky. In this talk we will shortly state the chosen approach and will then compare our expectations on coordinated disclosure with the real reactions of the addressed manufacturers - ranging from a friendly discussion, over tricking-into-NDA, up to ghosting. Finally we will give some ideas on how to read between the lines in datasheets. Additionally, we will outline the legal gray area of applied security research in academia. about this event: https://fahrplan.events.ccc.de/camp/2019/Fahrplan/events/10292.html
Denn so wissen wir, was sie tun: Das Berliner Transparenzgesetz (camp2019)
Ein Hoch auf Volksentscheide! Wir erzählen vom Berliner Volksentscheid für ein Transparenzgesetz, das wir ins Leben gerufen haben. Hier könnt ihr unterschreiben. Und wir zeigen, wie ihr mitmachen könnt. Im August hat die Unterschriftensammlung für das Berliner Transparenzgesetz begonnen. Ein breites Bündnis aus Open Knowledge Foundation, Mehr Demokratie, CCC und vielen weiteren hat einen 64-seitigen Gesetzentwurf geschrieben, der in Berlin zu mehr Transparenz und Bürgerbeteiligung führen würde. Und nebenbei müsste die Berliner Verwaltung auch den Quelltext ihrer Software offenlegen. about this event: http://talx.thm.cloud/thms/talk/MRJQ7S/
On bendy inflatables and travelling techno (camp2019)
I’ve made several interactive hackercamp installations over the years. I’ll talk about how they work, how they were made (generally very cheaply), about how people found ways to interact with them, and about what I’ve learned about experience design from them. And about where you can find the source code, obviously. about this event: https://fahrplan.events.ccc.de/camp/2019/Fahrplan/events/10324.html
Privacy leaks in smart devices: Extracting data from used smart home devices (camp2019)
Konviviale Software vor und jenseits des digitalen Kapitalismus (camp2019)
Der Vortrag geht der Frage nach, welche Aspekte der Geschichte des digitalen Wandels mit der Bestrebung nach einer sozial-ökologischen Gestaltung von Technik zu tun haben. Dabei wird gezeigt, was die Nachhaltigkeitsbewegung von der Free-Software-Bewegung und der Hacker-Ethik lernen kann, insbesondere bzgl. der Autonomie gegenüber digitalen Großkonzernen durch Selbstverwaltung und kollaborative Entwicklung. Andersherum wird diskutiert, was die Techszene über die Notwendigkeit und Möglichkeiten einer sozial-ökologischen Transformation lernen kann. Im Grunde genommen geht es hier darum, die emanzipatorischen Elemente der digitalen Technikentwicklung (die vor dem digitalen Kapitalismus des 21. Jahrhunderts existierten und sich ihm weiterhin entgegenstellen) und die Botschaften der politischen Ökologie in eine gemeinsame Erzählung zusammenzuführen. Der Begriff "Konvivialität" wurde in der politischen Ökologie eingeführt, um eine Vorstellung von Technik zu beschreiben, die sich von der industriellen Produktivität unterscheidet. Dabei geht es darum, Technik auf der Grundlage sozial-ökologischer Kriterien zu bewerten. Diese Kriterien werden vorgestellt und auf den Bereich digitale Technik angewandt. Ein Überblick über die Geschichte der Softwareentwicklung und des digitalen Kapitalismus wird zeigen, dass Konvivialität viel mit FOSS-Prinzipien zu tun hat, im Gegensatz zu kommerzieller Software, die von Konzernen entwickelt wird. Die Analyse anhand von Konvivialitätskriterien wird dadurch zur nützlichen Methode, um über digitale Technik zu reflektieren. Perspektivisch könnte das zu einer Annäherung der kritischen Tech- und Ökologiebewegungen führen: die etablierte Praxis der Free-Software-Bewegung könnte zu einer Keimform einer sozial-ökologischen Utopie jenseits des digitalen Kapitalismus werden. about this event: http://talx.thm.cloud/thms/talk/ET9CFU/