PLAY PODCASTS
Chaos Computer Club - archive feed

Chaos Computer Club - archive feed

21,021 episodes — Page 31 of 421

SIP Interworking between voice carriers (denog16)

Everything uses IP nowadays but some stuff is special: Telephony. The connection between customers and their provider is well known but the interconnections of providers themselves are something different. This talk covers the German market, other countries work totally different (some examples might be given). Licensed to the public under http://creativecommons.org/licenses/by/4.0 about this event: https://pretalx.com/denog16/talk/HSQJC7/

Nov 19, 202428 min

NIS2 Implementing Act for Digital Services – EU regulation maze revisited (denog16)

Following up on last year's introductory talk about NIS2 and the cybersecurity regulations, we'll look at the technical and methodological requirements specifically for digital service providers. Licensed to the public under http://creativecommons.org/licenses/by/4.0 about this event: https://pretalx.com/denog16/talk/Y88EBE/

Nov 19, 202431 min

NIS2 Implementing Act for Digital Services – EU regulation maze revisited (denog16)

Nov 19, 202431 min

End of Day 1 (denog16)

Nov 18, 20245 min

End of Day 1 (denog16)

That's a wrap for day1, we'll share all details about the social and how to get there! Licensed to the public under http://creativecommons.org/licenses/by/4.0 about this event: https://pretalx.com/denog16/talk/38JPGU/

Nov 18, 20245 min

Analyzing network reliability up to 800G - Impact of SNR thresholds on BER for Coherent (16QAM) and Non-Coherent (PAM4) high speed transceivers under environmental variations (denog16)

This presentation investigates the proximity to a low Signal-to-Noise Ratio (SNR) threshold that can still maintain a tolerable Bit Error Rate (BER) in 100G / 400G / 800G network links. Additionally, we account for factors such as temperature and cable length to predict the duration for which a reliable network connection can be sustained between transceivers. The analysis, based on data retrieved using a Flexbox, focuses on comparing the reliability of coherent (16QAM) and non-coherent (PAM4) transceivers, with a detailed discussion on the implications of these technologies on network performance. For a better understanding of the correlation between these factors, Machine Learning techniques were used. Licensed to the public under http://creativecommons.org/licenses/by/4.0 about this event: https://pretalx.com/denog16/talk/KBFMT3/

Nov 18, 202430 min

Certification of Network Products for Application in German Public Mobile Networks (denog16)

Starting with 1st of January, 2026, operators of public mobile networks in Germany are obliged to employ certified network products within their networks. The obligation affects all network products, which are newly introduced into public mobile networks and provide functions, for which a security assessment document has been approved by the BSI. This also includes network products, which provide 3GPP-specified functionalities and are listed in the list of critical functions by the Federal Office for Information Security (BSI) and the Bundesnetzagentur (BNetzA). The talk will address the necessary steps by operators of public mobile networks to successfully include certification of network products into their procurement and onboarding processes. Therefore, the talk will showcase the technical approaches taken in the certification process and how they are intended to interplay with provider processes. Licensed to the public under http://creativecommons.org/licenses/by/4.0 about this event: https://pretalx.com/denog16/talk/BHTKAJ/

Nov 18, 202427 min

Certification of Network Products for Application in German Public Mobile Networks (denog16)

Nov 18, 202427 min

What could possibly go wrong with FTTH - ask the Swiss! (denog16)

Nov 18, 202427 min

What could possibly go wrong with FTTH - ask the Swiss! (denog16)

The so-called ‘Glasfaserstreit' (fibre optic dispute), an antitrust case, successfully prevented the intention of the incumbent to monopolise the Swiss fibre optic network. As a result, >2 million households can currently subscribe to a symmetrical 25 Gigabit FTTH connection for ~€70 per month. Licensed to the public under http://creativecommons.org/licenses/by/4.0 about this event: https://pretalx.com/denog16/talk/DJAA3V/

Nov 18, 202427 min

Instant Overflow Injection - Shifting traffic to overflow providers in a moment's notice (denog16)

Single peering interfaces can get loaded during peak usage and/or failure scenarios while the network as a whole still has spare capacity. As remedy we can use upstream via our so-called overflow providers. In normal operation mode we will prefer direct peerings and only use overflow providers as fallback. For events like the European Football Championship we want to be able to shift traffic to those fallback routes with low effort, low wait times, high granularity and high confidence. We have implemented a service that injects on-demand copies of the existing fallback routes with the preferences tuned to let them be preferred over the "normal" peering routes. The routes are advertised via BGP sessions to our routers and are not distributed any further. The service is using GoBGP and running in Kubernetes. Licensed to the public under http://creativecommons.org/licenses/by/4.0 about this event: https://pretalx.com/denog16/talk/NCYK9Q/

Nov 18, 202412 min

Instant Overflow Injection - Shifting traffic to overflow providers in a moment's notice (denog16)

Nov 18, 202412 min

IPv4 over IPv6 networks (denog16)

In this session we are going to cover usage of RFC8950 (IPv4 NLRIs with IPv6 Next Hop) Licensed to the public under http://creativecommons.org/licenses/by/4.0 about this event: https://pretalx.com/denog16/talk/BWWEJ7/

Nov 18, 202411 min

IPv4 over IPv6 networks (denog16)

Nov 18, 202411 min

SCION: Secure Path-Aware Internet Routing (denog16)

Nov 18, 202414 min

SCION: Secure Path-Aware Internet Routing (denog16)

SCION is a secure path-aware Internet architecture, designed to achieve high resilience to routing attacks and path selection for Internet users and operators with safety critical traffic such as in financial and healthcare sectors. RPKI/ROV is useful for origin validation but does not validate paths, ASPA is still an evolving technology, whilst BGPSEC has yet to be widely deployed and needs explicit router support along a path to achieve the full benefits. SCION has commercial and open-source implementations and is in production use by the financial services and healthcare industry in Switzerland and internationally. This includes the SCION Research & Education Network (SCIERA) which includes connections to OVGU Magdeburg. It is also currently being evaluated for use in government, power utility, aviation, military and other applications, with a number of vendors interested in implementing it in their products. This talk will discuss the SCION design and architecture, its trust model, how it can be deployed, as well as some deployment experiences to-date. It will also discuss the IETF/IRTF work, and the community efforts supported by the SCION Association to encourage further deployment and development. Licensed to the public under http://creativecommons.org/licenses/by/4.0 about this event: https://pretalx.com/denog16/talk/GZAQ7E/

Nov 18, 202414 min

“Subsea internet cables could help detect earthquakes” (denog16)

Nov 18, 202412 min

“Subsea internet cables could help detect earthquakes” (denog16)

There are plenty of seismic stations on land helping detect and record earthquakes but very little deployed in our sea’s and oceans. Marine seismic detectors have traditionally been expensive, unreliable and not widely deployed. In recent years, research has shown that new and existing submarine cables can be used to detect seismic activity. Given that two thirds of our planet is covered by Oceans, this new development provides a great opportunity to improve our knowledge of the geological activity of our planet. Additionally, an early warning of an imminent Tsunami can save thousands of lives. This presentation will introduce the recent developments in sensing on Submarine Fibre Optic Cables and introduce the key sensing technologies employed. Licensed to the public under http://creativecommons.org/licenses/by/4.0 about this event: https://pretalx.com/denog16/talk/SVMJWM/

Nov 18, 202412 min

Submarine cables - lifelines of countries and continents (denog16)

In recent years, we’ve heard a bit more about submarine cables, mostly related to fiber cuts. Given that they’re lifelines of countries or even continents, they are important, yet we know little about them. So, what’s the rationale behind the large selection of submarine cables, often on the same route? Is it just about resiliency and shorter routes, or are there other differentiators? This talk will provide insight into the construction, operation, maintenance, and selection of submarine cables, using the connections between the United Kingdom and Continental Europe as an example. We will dive into what it takes to construct a submarine cable, discover why and how it breaks, and provide guidance on what to consider when purchasing. Licensed to the public under http://creativecommons.org/licenses/by/4.0 about this event: https://pretalx.com/denog16/talk/CKRBRG/

Nov 18, 202421 min

Submarine cables - lifelines of countries and continents (denog16)

Nov 18, 202421 min

Deployment of a multi vendor EVPN based data center fabric using Netbox and Ansible (denog16)

Nov 18, 202429 min

Deployment of a multi vendor EVPN based data center fabric using Netbox and Ansible (denog16)

This year we deployed a new data center fabric from scratch. A requirement was to use different vendors with different nos. In addition we use Ansible for the whole configuration. This talk is about: - how to efficiently use Netbox with Ansible - using Ansible with multi vendor equipment - challenges building a multi vendor EVPN fabric from scratch Licensed to the public under http://creativecommons.org/licenses/by/4.0 about this event: https://pretalx.com/denog16/talk/DSWSHD/

Nov 18, 202429 min

Creating a Sustainable Supply Chain in the Network Industry (denog16)

In response to increasing regulatory pressures, major telecommunications providers have begun to measure and report their carbon footprints. However, this initial step is just the beginning of a complex journey toward achieving sustainability. One of the most significant challenges these companies face is addressing Scope 3 emissions, which are generated by their supply chains and lie outside their direct control. In this presentation, I will discuss the current state of sustainability efforts within the telecom industry, with a particular focus on the intricacies of reducing Scope 3 emissions. Rather than offering quick fixes, I will explore practical approaches companies can consider, such as switching to more sustainable suppliers, collaborating closely with existing suppliers, and gradually introducing contractual clauses that emphasize sustainability. Attendees will gain a realistic understanding of the challenges involved and will be introduced to strategies that can help their organizations begin the process of reducing their supply chain's carbon footprint. This discussion aims to provide a balanced view, emphasizing that while these steps are crucial, they require time, commitment, and a willingness to engage in long-term efforts. Licensed to the public under http://creativecommons.org/licenses/by/4.0 about this event: https://pretalx.com/denog16/talk/7VPLSK/

Nov 18, 202424 min

Creating a Sustainable Supply Chain in the Network Industry (denog16)

Nov 18, 202424 min

Introduction of RPKI at the Deutsche Telekom global Network AS 3320 (denog16)

Introduction of RPKI at the Deutsche Telekom global Network AS3320 was finalized in February 2024, since 22nd February 2024 AS 3320 rejects RPKI invalid Prefixes. This presentation talks about the Project phases, the implementation and experiences we made during the introduction of RPKI on a global Tier-1 ISP Network. This includes some technical details and organizational view for the continuous RPKI operation. Licensed to the public under http://creativecommons.org/licenses/by/4.0 about this event: https://pretalx.com/denog16/talk/ACGCDS/

Nov 18, 202434 min

Introduction of RPKI at the Deutsche Telekom global Network AS 3320 (denog16)

Nov 18, 202434 min

The Elephant on an Adventure: A Custom-Built Shelter for Network Devices (denog16)

We take you along on our adventurous journey through the design and implementation phases of a custom-built outdoor cabinet, from conception to completion, sharing what we’ve learned in the process. While building a new fiber network from scratch, Eurofiber faced a dilemma: We needed to install network devices in the great outdoors of Berlin’s heating power plant sites, but your typical data center devices wouldn’t fit in the standard telco cabinets available on the market. For our purposes, we require full-depth racks, access from both sides, and active cooling. So we could either go for smaller, hardened outdoor equipment, which limits the choice of devices. Or we’d have to buy concrete data center containers the size of a garage, which are larger than we need, take more bureaucracy to build, and are also expensive. To bridge this gap and keep the costs reasonable, we designed our own micro-datacenter, basically a larger street cabinet tailored specifically to our requirements: It provides active cooling, front and rear access, and fits full-depth devices while providing redundant power and sufficient protection from the elements. This adventure took us deep into the engineering world of the infrastructure required for operating network devices. Have you ever had to consider cooling capacities, battery temperatures, air-flow velocities, or noise emission laws? We take you through the design process as well as the lessons we learned on the construction site and the operational experiences after finally taking the network into production. Licensed to the public under http://creativecommons.org/licenses/by/4.0 about this event: https://pretalx.com/denog16/talk/8GNVX9/

Nov 18, 202427 min

DENOG16 Opening (denog16)

Welcome to Berlin, welcome to DENOG16 Licensed to the public under http://creativecommons.org/licenses/by/4.0 about this event: https://pretalx.com/denog16/talk/AYJDAW/

Nov 18, 202436 min

DENOG16 Opening (denog16)

Nov 18, 202436 min

Newcomer Session (denog16)

Welcome to DENOG, if this is your first event, feel free to join us to learn everything about the event, the community and more! Licensed to the public under http://creativecommons.org/licenses/by/4.0 about this event: https://pretalx.com/denog16/talk/VWX3FM/

Nov 18, 202418 min

Newcomer Session (denog16)

Nov 18, 202418 min

Closing (god2024)

Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/ about this event: https://c3voc.de

Nov 13, 20244 min

Closing (god2024)

Nov 13, 20244 min

Modern solutions against Cross-Site Attacks (god2024)

Web security is increasingly an opt-in approach, leaving developers with both the opportunity and the responsibility to protect their applications. This talk will explore why and how developers can secure their sites against evolving threats. We'll delve into the nuances of cross-site leaks (xs-leaks) and discuss the Cross-Origin Resource Policy (CORP) as well as the abstractions provided by. Learn how these tools can empower you to build custom defenses and proactively safeguard your web applications. Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/ about this event: https://c3voc.de

Nov 13, 202427 min

Modern solutions against Cross-Site Attacks (god2024)

Nov 13, 202427 min

Double-Edged Crime: How Browser Extension Fingerprinting Might Endanger Users and Extensions Alike (god2024)

Browser extensions are powerful tools that enhance the web browsing experience, offering their users a wide range of functionalities. However, these features can also introduce security and privacy issues for their users, mainly through a technique known as extension fingerprinting — where malicious websites track users based on the extensions they have installed. This is particularly interesting since many websites rely on advertising-based revenue for their existence, and the cookie-less form of tracking is also increasingly getting traction on the Web. Popular libraries such as FingerprintJS and Castle have already incorporated extensions as identifiable sources in their armor. In this talk, we will present the growing threat of browser extension fingerprinting, shedding light on how extensions can inadvertently expose both users and the extension to certain risks. Our recent research uncovers that over 3,000 Chrome and Firefox extensions are vulnerable to fingerprinting through techniques such as JavaScript namespace pollution and other observable side effects despite existing defense mechanisms [1]. The audience will takeaway the following: What are some of the ways by which browser extensions can be fingerprinted. The risks for both user privacy and extensions' behavior. Insights from recent research on vulnerable extensions. Potential strategies to mitigate fingerprinting risks. And, of course, how to keep your extensions from being the "most wanted" on the Web! [1] Agarwal, Shubham, Aurore Fass, and Ben Stock. "Peeking through the window: Fingerprinting Browser Extensions through Page-Visible Execution Traces and Interactions." (To appear at) Proceedings of the 31st ACM SIGSAC Conference on Computer and Communications Security. 2024. Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/ about this event: https://c3voc.de

Nov 13, 202423 min

Double-Edged Crime: How Browser Extension Fingerprinting Might Endanger Users and Extensions Alike (god2024)

Nov 13, 202423 min

Protecting Web Applications with Project Foxhound (god2024)

Nov 13, 202411 min

Protecting Web Applications with Project Foxhound (god2024)

Recent developments in web technologies have seen a paradigm shift from monolithic server-based applications to REST-based microservices with feature-rich browser-based frontends. This progression has brought with it novel classes of security flaws. In this talk we review how client-side variants of injection vulnerabilities such as cross-site scripting (XSS), cross-site request forgery (CSRF) and the recently discovered client-side request hijacking, arise and how traditional defense mechanisms are ineffective. We summarize recent research in this area which shows that such issues are widespread and can have a diverse range of consequences. We go on to show how dynamic taint-tracking has proved to be an effective technique for the discovery of vulnerabilities in client-side JavaScript. The initial overhead in implementing tainting is, however, extremely high, as it typically involves delving into the inner workings of modern web browsers and JavaScript interpreters. We show how Project Foxhound (https://github.com/SAP/project-foxhound/) can help to reduce this burden by providing a flexible, open-source tool which can be fully integrated into browser automation frameworks such as Playwright. Foxhound is gaining traction in the community as the go-to tool for client-side vulnerability studies. We finish the talk by showing how Foxhound can also be used in privacy studies, an update on upcoming features, and how the community use and contribute to the project to help build a safer web! Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/ about this event: https://c3voc.de

Nov 13, 202411 min

SSRF: Attacks, Defense and Status Quo (god2024)

Web apps use Server-Side Requests to request data from other servers, e.g., for link previews. However, they are exploited by attackers who might request internal resources or non-public services. This attack is called Server-Side Request Forgery (SSRF). The talk explains what SSRF is, how it can be used to exploit servers, and how to defend against it, which is surprisingly complex. Finally, we will discuss our research on the prevalence of countermeasures in the wild. Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/ about this event: https://c3voc.de

Nov 13, 202410 min

SSRF: Attacks, Defense and Status Quo (god2024)

Nov 13, 202410 min

„Well, What Would You Say if I Said That You Could?” – Scanning for Vulnerabilities Without Getting Into Trouble (god2024)

The need for comprehensive measurements of security and privacy risks on the Web is undeniable as it helps developers in focusing on emerging trends in security. However, large-scale scans for server-side vulnerabilities remains a sensitive topic, due to their potential to harm servers, disrupt services, and incur financial losses. Even smaller, singular tests can be controversial, as demonstrated by incidents like the CSU scandal around Lilith Wittmann in 2021 or the Modern Solution case in 2023. The gray area surrounding the legality, ethics, and industry perspectives on server-side scanning has led to hesitancy among researchers and ethical hackers, creating a critical gap in our understanding of how to conduct such scans responsibly. In this talk, we investigate and interactively discuss the murky boundaries of vulnerability scanning by exploring five typical scanning scenarios that researchers face on the Web. Drawing from We give insights into 23 in-depth interviews we conducted with legal experts, research ethics committee members, and website/server operators to identify what types of scanning practices are acceptable and where the red lines are drawn. We further substantiate these insights with findings from an online survey conducted with 119 server operators. Attendees will gain great insights into the current state of Web scanning, including the lack of judicial clarity and the ethical dilemmas researchers and ethical hackers face. This interactive session also offers a platform for audience members to challenge their own understanding of ethics, share opinions, and contribute to shaping the future of responsible Web security scans. In this talk, the audience will: Get an in-depth understanding of the legal and ethical challenges associated with large-scale server-side scanning research. Learn current best practices for conducting responsible Web security scans (at scale). See firsthand insights from legal experts, ethics committees, and operators on acceptable security research practices. Get an opportunity to engage in an interactive discussion to voice opinions and help influence future research Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/ about this event: https://c3voc.de

Nov 13, 202427 min

„Well, What Would You Say if I Said That You Could?” – Scanning for Vulnerabilities Without Getting Into Trouble (god2024)

Nov 13, 202427 min

SAP from an Attacker's Perspective – Common Vulnerabilities and Pitfalls (god2024)

As organizations increasingly rely on SAP systems to manage critical business processes, the security of these environments is an increasing challenge for companies and has also been recognized by the OWASP Core Business Application Security (CBAS) project. This talk will explore the security of SAP systems from an attacker's perspective, uncovering common vulnerabilities and pitfalls and their respective impact. Drawing from extensive penetration testing experience, this presentation will provide a deep dive into how attackers might exploit SAP vulnerabilities and offer practical guidance on mitigating these threats. We will begin by highlighting prevalent SAP vulnerabilities discovered during real-world pentesting engagements, covering key attack techniques used against SAP systems that exploit misconfigurations, insecure coding practices, and authentication flaws. As an example, we will illustrate the configuration options of SNC, the proprietary protocol for transport layer encryption in SAP environments. Using the open-source tool sncscan, security professionals and administrators alike can assess the encryption and signing settings of SAP systems, ensuring the confidentiality and integrity of sensitive data. The session will also provide actionable guidance on mitigating these vulnerabilities, focusing on best practices and tools that can significantly enhance the security posture of SAP systems. By raising awareness of common vulnerabilities and pitfalls we aim to empower security professionals and SAP administrators to better protect their systems against potential exploitation. Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/ about this event: https://c3voc.de

Nov 13, 202422 min

SAP from an Attacker's Perspective – Common Vulnerabilities and Pitfalls (god2024)

Nov 13, 202422 min

Network Fingerprinting for Securing User Accounts - Opportunities and Challenges (god2024)

Network fingerprinting exists for a while and some methods such as JA3 have achieved wide adoption across the industry. Introducing network fingerprinting into login flows can help you stave off attackers. However, there are various challenges that you need to overcome: technical, organizational and regulatory. In this talk we will take a look at the opportunities that network fingerprinting provides us. We will go through the various challenges that can arise and discuss possible ways of tackling them. I will draw from insights gathered at 1&1 Mail & Media - the company behind web.de, GMX and mail.com. Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/ about this event: https://c3voc.de

Nov 13, 202425 min

The Debian OpenSSL bug and other Public Private Keys (god2024)

In early 2024, hundreds of DKIM setups still used cryptographic keys vulnerable to a bug from 2008 in Debian's OpenSSL package. Vulnerable hosts included prominent names like Cisco, Oracle, Skype, and Github. In 2022, it was discovered that printers generated TLS keys that could be trivially broken with an over 300-year-old algorithm by Pierre de Fermat. Vulnerabilities in public/private key generation are amongst the most severe ones in cryptographic software. The speaker has developed the open-source tool badkeys, a tool to check cryptographic keys for known vulnerabilities. The talk will cover some of the findings and plans for future improvements in badkeys. Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/ about this event: https://c3voc.de

Nov 13, 202421 min

The Debian OpenSSL bug and other Public Private Keys (god2024)

Nov 13, 202421 min

GenAI im Threat Modeling (god2024)

Viele Teams stehen vor der Herausforderung, beim Threat Modeling relevante Bedrohungen zu identifizieren, insbesondere wenn nur wenig Security-Expertise vorhanden ist. Die Auswahl und Bewertung von potenziellen Risiken kann für Nicht-Experten schwierig sein. Dieser Lightning Talk zeigt, wie Generative AI (GenAI) hier unterstützen kann, indem sie Bedrohungsszenarien basierend auf bestehenden Daten und Modellen vorschlägt und hilft, erste Entscheidungen zu treffen. Der Vortrag gibt einen kurzen Überblick, wie GenAI als Hilfestellung den Threat-Modeling-Prozess effizienter und zugänglicher machen kann - und welche Einschränkungen es gibt. Licensed to the public under https://creativecommons.org/licenses/by-sa/4.0/ about this event: https://c3voc.de

Nov 13, 20249 min

GenAI im Threat Modeling (god2024)

Nov 13, 20249 min