
Chaos Computer Club - archive feed
21,021 episodes — Page 77 of 421
Full AACSess: Exposing and exploiting AACSv2 UHD DRM for your viewing pleasure (37c3)
Following the failure and easy exploitation of the AACSv1 DRM on HD-DVD and Blu-ray, AACS-LA went back to the drawing board and announced the next generation AACSv2 DRM scheme, launching alongside 4K UHD Blu-ray in 2015. Since then, nearly no information has come out publicly about any vulnerabilities or even the algorithms themselves, owing in large part to software players requiring the use of Intel SGX secure enclave technology, which promises integrity and confidentiality of AACSv2 code and data through local and remote attestation mechanisms. Join us as we explore the broken history of AACS, describe practical side-channel attacks against SGX, and present the first look into the inner workings of AACSv2 DRM, culminating in a demonstration of the first full compromise of AACSv2 and unofficial playback of a UHD-BD disc. The Advanced Access Content System (AACS) is a DRM scheme used to safeguard audio and visual content, particularly in high-definition formats like HD-DVD and Blu-ray. First introduced in 2005 following the failure of the Content Scramble System (CSS) used in DVDs, AACS was designed to be not only secure against regular piracy, but included multiple features intended to restrict the impact of a potential leak of cryptographic material such as revocation lists and traitor-tracing. The concepts and algorithms of AACS were described in a publicly-released whitepaper, relying on strong cryptography and secrecy of keys to maintain security. Unsurprisingly, less than a year after publication, the first unlicensed decryption tool was demonstrated using keys reverse-engineered from a software player binary. While AACS-LA was quick to revoke those keys, a cat-and-mouse game emerged with new keys being regularly extracted from sources such as software updates and PS3 firmware. With AACS effectively broken and easily bypassed as described in Eckersley’s 24c3 presentation, AACS-LA would announce the introduction of AACSv2 for the next generation 4K UHD Blu-ray discs. This time, however, AACS-LA would not release the specifications of the DRM publicly, requiring strict NDAs for implementers and increased software/hardware security measures. Most notably, playback of legitimately purchased UHD-BDs on PC requires Cyberlink PowerDVD software running on Windows 10 and an SGX-capable 7th-10th generation Intel CPU. Since the DRM would run exclusively in the SGX secure enclave, no further information about its inner workings or vulnerabilities would be discovered publicly, until now. In this presentation, we explore the security system of AACSv2 DRM and the Intel SGX trusted execution environment. We first analyze the principles of SGX and its promises of an isolated environment, protected from all software running on the machine. We also investigate the use of SGX local and remote attestation primitives intended to verify the integrity and confidentiality of AACSv2 key material and DRM code, and why it has resisted outside analysis for so many years. We then discover how hardware side-channel attacks can be used to undermine these guarantees of SGX, and craft an effective exploit to extract cryptographic material from the enclave and defeat the DRM code obfuscation. Following that, we present the first public description of the inner workings of AACSv2, the key derivation process, and the updated revocation and traitor-tracing mechanisms. We studied BIOS updates from six motherboard vendors to show how SGX can be broken both easily and cheaply, and that vendors are now faced with a decision of security vs. usability in trusting unpatched machines. Finally, we conclude with the first demonstration of a UHD Blu-ray disc being decrypted and played back on a non-official platform. about this event: https://events.ccc.de/congress/2023/hub/event/full_aacsess_exposing_and_exploiting_aacsv2_uhd_drm_for_your_viewing_pleasure/
Projekt Link: Multimobilität für alle (37c3-meta)
Im Projekt Link möchten wir einen multimodalen Routenplaner entwickeln und die Verkehrswende aktiv mitgestalten. Im ländlichen Raum auf's Auto verzichten? Für viele angesichts teils dünner ÖPNV-Anbindung undenkbar. In der Folge fahren viele Pendler*innen im eigenen Fahrzeug in die Stadt, wo alle unter Lärm, Platzmangel, Stau und Emissionen leiden – dabei ist der nächste Bahnhof häufig gar nicht allzu weit entfernt. Im Projekt Link möchten wir einen modernen, freien und echt multimodalen Routenplaner entwickeln, der alle persönlichen Belange berücksichtigt. Dafür suchen wir Mitstreiter*innen! ### Mitmachen Das Projekt wird gerade im Rahmen des *Take-Off-Accelerator*-Programms der Hochschule für Technik und Wirtschaft des Saarlandes gefördert. Wenn Du mitgestalten möchtest, freue ich mich, von Dir zu hören: * Bis Tag 4 bin ich auf dem 37c3 anzutreffen. Ruf mich an unter **DECT [5671](tel:5671)**! * Du erreichst mich auch per E-Mail an [[email protected]](mailto:[email protected]) (möglicherweise werde ich erst nach dem Congress antworten). about this event: https://pretalx.c3voc.de/37c3-lightningtalks/talk/HAS887/
Gläserne Geflüchtete (37c3)
Gläserne Geflüchtete (37c3)
Digitale Bezahlkarten, Migrationsvorhersage mit sogenannter KI, digitalisierte Grenzen zur Festung Europa und immer mehr davon. Ein Überblick, wie Digitalisierung jenseits des öffentlichen Aufschreis genutzt wird, um den Pull-Faktor Menschlichkeit zu drücken. In der Hackerethik steht: „Computer können dein Leben zum Besseren verändern." Aber viel zu oft werden sie für das Gegenteil genutzt. Vor allem im Bereich der digitalisierten Migrationskontrolle. Mit dabei: das Ausländerzentralregister, eines der größten automatisierten Register der öffentlichen Verwaltung; die Idee für digitale Bezahlkarten, die mehr Freiheitsbeschränkung sind als Zahlungsmittel; die üblichen Verdächtigen unter den BAMF-IT-Assistenzsystemen; Vorhersage-Systeme für Migrationsbewegungen; die digitale Festung Europa. Und ganz neu: das Schneller-Abschieben- und das Datenübermittlungsvorschriftenanpassungsgesetz. Die aktuelle Bundesregierung macht munter dabei mit, ihre digitalen Kontrollhelfer weiter auszuweiten. Und fast niemand schaut hin. about this event: https://events.ccc.de/congress/2023/hub/event/glaserne_gefluchtete/
Digitalsensible Bildung | Bridging the Nerdgap (37c3-meta)
Digitalsensible Bildung | Bridging the Nerdgap (37c3-meta)
Das Wissen über Open Source Tools, der Zugang zu datensensiblen Technologien und das Verständnis, warum das Datensammelverhalten des DB Navigators ein Problem ist, sind hauptsächlich einer sehr priveligierten Gruppe von Menschen vorbehalten. Das @all-Kollektiv hat es sich zur Aufgabe gemacht diesen Nerdgap zumindest ein bisschen zu schrumpfen und mehr Menschen an netzpolitischen Diskussionen teilhaben zu lassen. Wie, das erzählen wir euch in unserem Lightning Talk! Es ist faszinierend mitzuerleben, wie sich die FOSS-Bewegung den Techgiganten tagtäglich mit unglaublich viel Kreativität und tausend tollen Tools entgegenstellt, die unsere persönlichen Daten persönlich sein lassen und uns in immer mehr Bereichen Alternativen zu fancy durchdesignten Apps bieten, die oft mehr shiny sind als nice. Dennoch bleibt das Wissen über all die tollen Möglichkeiten zum Schutz der eigenen Daten und warum das überhaupt wichtig sein soll, häufig ein intellektuelles Privileg. Und auch Hardcore-Nerds überblicken doch meist nur ihr eigenes kleines Techno-Village und bekommen gar nicht mehr mit, dass Open Source, Fediverse und DDOS-Attacke vielen Menschen einfach gar nichts sagen. Wir, das @all-Kollektiv, finden, dass sich das dringend ändern muss. Es sollte netzpolitisch woken Nerds nicht egal sein, ob ihre Friends weiter ihre Adressbücher, Passwörter, Standortdaten und Nacktfotos mit iDrive teilen und in ihre GCloud laden. Datenschutz darf kein Privileg sein! about this event: https://pretalx.c3voc.de/37c3-lightningtalks/talk/HBFXMP/
Vorstellung HW Hacking 101 Board (37c3-meta)
Vorstellung HW Hacking 101 Board (37c3-meta)
Kurze Vorstellung eines HW Hacking 101 Boards und Motivation Im Rahmen einer IT-Security Vorlesung (Vertiefung) an der DHBW in Mosbach kam die Idee ein kleines Hardware Hacking 101 inkl. Hardware und Challanges zu erstellen. Das Test-Board und Challanges sind so aufgebaut, das diese mit vorgelagerten Vorlesung und Übung an zwei 4-5h Blockveranstaltungen gelöst werden können. **Ziel:** Den Student:inen in der Angewandten Informatik Embedded Security und Design anhand von typischen HW- und SW-Designfails näher zu bringen. about this event: https://pretalx.c3voc.de/37c3-lightningtalks/talk/HXYASN/
The Analog Thing: Der Arduino des Analogy Computings (37c3-meta)
The Analog Thing: Der Arduino des Analogy Computings (37c3-meta)
We present THE ANALOG THING, an open source / open hardware project demonstrating how analog computers work. There is no processor in this board. Analog Computing is an unconventional computer architecture based on mathematical analogies. It shares aspects with quantum computing (nonalgorithmic, initial state preparation and measurement) but is way easier to grasp. 5mins of your time are sufficient. about this event: https://pretalx.c3voc.de/37c3-lightningtalks/talk/WNNDEZ/
The Free Software Foundation Europe (37c3-meta)
The Free Software Foundation Europe (37c3-meta)
Get an understanding of what the Free Software Foundation is and what we are doing to empower user to control technology Software is deeply involved in all aspects of our lives. Free Software gives everybody the rights to use, understand, adapt, and share software. These rights help support other fundamental rights like freedom of speech, freedom of press, and privacy. about this event: https://pretalx.c3voc.de/37c3-lightningtalks/talk/ANWWN9/
Google Cloud’s insecure default configurations (37c3-meta)
Google Cloud’s insecure default configurations (37c3-meta)
When using Google Cloud, default configurations and policies are enabled by default that might lead to an increase in the attack surface. These configurations include, and not limited to, identity and access management (IAM) and network setup. about this event: https://pretalx.c3voc.de/37c3-lightningtalks/talk/XM9MGR/
Browsers biggest TLS mistake (37c3-meta)
Bird Clock Opera/ w text from Days Of The Week (fireshonks)
Browsers biggest TLS mistake (37c3-meta)
Chrome and Firefox's TLS certificate verification have a weird hack, and it might be a long term mistake, this talk quickly goes over the quirk, and provides data on how many people it impacts about this event: https://pretalx.c3voc.de/37c3-lightningtalks/talk/XGML8T/
Bird Clock Opera/ w text from Days Of The Week (fireshonks)
The texts for this piece were originally written as part of a revision of the Homeric Hymn to Demeter; a revision which broadens the picture of Black women who are descendant of colonial enslavement. A dialogue based on the contrast of Artemis’ power and agency over her body compared to women who have been unsafe for generations. Women who carry these wounds as warnings and a call out for accountability. The underlying track called ‚Xercathalon’s Debut: A Bird Clock Opera, is a piece based on the sounds of childhood as remembered and incorporated into this collaborative soundscape. The question works such as these answer is a soft approach towards understanding the people that 37C3 wants to become more diverse towards. Diversity, equity and inclusion are more than catchy phrases. They don't happen overnight, but through art and literature there are greater options for briding understanding. Prism Obsidian Duo Obsidian is a visual artist and researcher in postcolonial theology, culture and education. She is taking a Black Quantum Afrofuturist approach towards tackling issues of racism, cultural appropriation, intersectionality and sustainable urban regeneration by drawing on an image of global Black cultures. Prism is a musician and visual artist specialising in rainbowgoth sound design and crafting analog double exposure captures. She is based in Berlin and responds to the inspiration of memory, saturation, and the dreamworld. about this event: https://events.ccc.de/congress/2023/hub/event/bird-clock-opera-w-text-from-days-of-the-week/
Darf's noch etwas visionärer sein? (37c3)
Universities, Step into the Fediverse! Reclaiming Digital Sovereignty (37c3-meta)
Universities, Step into the Fediverse! Reclaiming Digital Sovereignty (37c3-meta)
Universities can be important creators of digital public spaces and use, design and provide public-interest network structures such as the Fediverse. In line with its FLOSS tradition, the University of Innsbruck focuses on the Fediverse and has established an instance on university servers. Alongside insights into the process, motivation and networking is the aim of this Lightning Talk. Universities, join the Fediverse! The disaster with Twitter highlighted the risks of relying on commercial platforms for central communication channels. This isn't new, but it sharply illustrates the issues with much of social media's structure. Universities can significantly contribute to establishing the Fediverse as a decentralized, non-commercial, privacy-conscious network. Using the example of the University of Innsbruck, the talk will show how a trio from different departments, science communication, data protection and IT, set up a Fediverse instance for institutional science communication on Mastodon on university servers. This Lightning Talk aims to inform and showcase how one university successfully engaged with the Fediverse, serving as a call to action for other universities to join in seizing the opportunity to improve online communication structures. Melanie Bartos, Hansjörg Pehofer, Matthias Weiler about this event: https://pretalx.c3voc.de/37c3-lightningtalks/talk/UXKQBQ/
Darf's noch etwas visionärer sein? (37c3)
Supereffiziente digitale Technik als Lösung aller Probleme oder doch lieber die selbstgebaute ressourcensparsame Low-Tech-Variante? Die Zukunftsvorstellungen, die den Einsatz digitaler Technik und ökologische Fragen zusammendenken, sind in der deutschen Diskurslandschaft nicht gerade üppig gesät. Im Vortrag werden die Ergebnisse einer Kurzstudie präsentiert, bei der wir die Zukunftsvorstellungen digital-ökologischer Transformation bei gesellschaftspolitischen Akteuren gesucht, analysiert und zu Visionskategorien zusammengefasst haben. Der Vortrag bietet einen Einblick in die Ergebnisse einer erstmaligen systematischen Untersuchung der im deutschsprachigen Diskurs präsenten Visionen zur digital-ökologischen Transformation und setzt diese in einer Landschaft an Vorstellungen von Transformation, Nachhaltigkeit und Technikgestaltung zueinander in Beziehung. Bei der Recherche wurden zivilgesellschaftliche, staatliche, wissenschaftliche und wirtschaftliche Akteure berücksichtigt. Das Ergebnis sind sechs verschiedene Typen an Visionskategorien: „Dematerialisierung", „Digital-ökologische Modernisierung", „Leitplanken einer zukunftsfähigen Digitalpolitik", „Digital-ökologischer TÜV", „Digitale Suffizienz" und „Low-Tech" bilden die Landschaft der Visionen digital-ökologischer Transformation im deutschsprachigen Raum. Die Vorstellung, dass digitale Technik durch Effizienzsteigerungen zu einer Entkopplung von Wirtschaftswachstum und Ressourcenverbrauch beiträgt, kann unter dem Begriff „Dematerialisierung” gefasst werden. „Digital-ökologische Modernisierung” bezeichnet einen eher technokratischen Ansatz, in dem die ökologischen Kosten der Digitalisierung durch Sparsamkeit, Recycling und vor allem den flächendeckenden Einsatz von erneuerbaren Energien zu bewältigen sind. Vertreter\*innen des Visionstyps „Leitplanken einer zukunftsfähigen Digitalpolitik” geben statt einer scharf formulierten Vision eher Leitplanken für die zukünftige Gestaltung der Digitalisierung im Rahmen ökologischer Grenzen vor. Die Kategorie „Digital-ökologischer TÜV” beschreibt Ansätze, die eine Bewertung des Verhältnisses von Ökologie und digitaler Technik von einer fortlaufenden Überprüfung des Einsatzes digitaler Technik abhängig machen. Bei „Digitaler Suffizienz” wird das Konzept der Suffizienz auf den Bereich Digitalisierung übertragen und orientiert sich an dem Motto „so viel Digitalisierung wie nötig, so wenig wie möglich“. Zuletzt kann die Idee der Abkehr vom linearen Fortschrittsdenken und von damit einhergehenden ressourcenintensiven High-Tech-Infrastrukturen als „Low-Tech”-Vision bezeichnet werden. Im Vortrag wird das Verhältnis der einzelnen Kategorien zueinander anhand von verschiedenen Dimensionen, wie ihr zugrundeliegendes Transformationsverständnis oder die Radikalität der beschriebenen Veränderungen, dargestellt sowie deren politische Bedeutung reflektiert. Welche Visionen erfüllen den Anspruch an eine global gerechte Digitalität der Zukunft? about this event: https://events.ccc.de/congress/2023/hub/event/darf_s_noch_etwas_visionarer_sein/
The FIM (Fbi IMproved) Universal Image Viewer (37c3-meta)
The FIM (Fbi IMproved) Universal Image Viewer (37c3-meta)
FIM (Fbi IMproved) is a "swiss army-knife" image viewer for: either the Linux Framebuffer or the graphical environment, or in text terminals (ASCII Art, also coloured), with a consistent interface and with many powerful features. FIM is known among enthusiasts of Raspberry Pi and other minimalistic computing devices, but also among VIM/Emacs users seeking functionality, configurability, and flexibility. My flash presentation will show the ideas of FIM and why it can be useful to many. See a full presentation at https://archive.fosdem.org/2023/schedule/event/om_fim/ about this event: https://pretalx.c3voc.de/37c3-lightningtalks/talk/FLJNGZ/
More privacy for the EHDS (37c3-meta)
More privacy for the EHDS (37c3-meta)
I will explain and propose to use a storage technology based on a cardinality estimation algorithm called HyperLogLog for the so-called secondary use within the European Health Data Space EU launched the European Health Data Space to make health records of all Europeans accessible from anywhere. The so-called "secondary use" of these data should be made available for research, decision-making, development and innovation. This is a highly privacy-relevant issue as it affects every EU citizen. Over the last few years I have been working on a research project on a similar privacy-relevant problem. I came up with a solution that relies on a cardinality estimation algorithm called HyperLogLog. It stores data in sets in a way that makes it impossible to retrieve individual data items, thus protecting the privacy of social media users. In this lightning talk, I will present the algorithm and propose this technology to be used for the secondary use of the European Health Data Space in order to improve privacy. about this event: https://pretalx.c3voc.de/37c3-lightningtalks/talk/9Y8ZGZ/
Join the 'Task Tracker Systems' team! (37c3-meta)
Join the 'Task Tracker Systems' team! (37c3-meta)
You like to tinker with electronics, software or mechanical design in your spare time? 🧑💻 And would you like to develop a system as part of a supportive team? 👥💪 This talk invites you to join some devs working on a small open source project. 👋 Our goal is to experiment and play with technology while working together towards a common product. 🚀 The system we develop is a combination of a handheld device to track time spent on tasks and a desktop/mobile app which additionally allows to transfer the records to existing accounting systems. Our primary goal is to learn and practice technologies and exchange ideas with the team. While there is room to experiment, there is a useful product we want to deploy eventually. Some of the technologies currently applied or planed in the project: - ESP32 - KiCAD - Prusa 3D printer - Kotlin - modern C++ - unit tests and continuous integration Visit 👉[🔗 Task Tracker Systems on GitHub](https://github.com/Task-Tracker-Systems)👈! Contact: - 📧 [email protected] - ☎️ DECT 5689 @ 37C3 about this event: https://pretalx.c3voc.de/37c3-lightningtalks/talk/RV7CMY/
The Serenity Operating System (37c3-meta)
The Serenity Operating System (37c3-meta)
The SerenityOS project has been developing a from-scratch Unix desktop operating system over the past five years. A five-minute look at what that means and why it's interesting. The SerenityOS project has been developing a from-scratch Unix desktop operating system over the past five years. The system has excellent vertical integration, since we write all the software ourselves, from standard library to applications. An important part of the project is the Ladybird Browser, a new cross platform browser that's compatible with large parts of the modern Web. This talk is not only an overview over the project and what we are doing, but also an invitation to our assembly and the project in general. about this event: https://pretalx.c3voc.de/37c3-lightningtalks/talk/TWFWL9/
Developing the Next Generation Open Source Event Management with eventyay (37c3-meta)
The new version of the open source event system eventyay is currently being developed and we will release the first version in February. In this lightning talk I will share about the exiting features and AI capabilities we are working on. about this event: https://pretalx.c3voc.de/37c3-lightningtalks/talk/WBRVVN/
Local Change, Global Impact: Transforming International Development through Local Empowerment (37c3-meta)
Local Change, Global Impact: Transforming International Development through Local Empowerment (37c3-meta)
We're tackling a key issue in international development cooperation by empowering local change agents with direct funding and a platform to share their data and stories. Our mobile-first solution will combine e-payment and information sharing, addressing an industry-wide challenge. We present an approach to address a fundamental challenge of international development cooperation. Currently, the sector is deeply shaped by a hierarchical North-South structure that influences not only funding flows, but also priorities, methods, tools, and concerns. We want to change this by empowering local change agents. How do we do this? By directing funding flows directly to these individuals, and empowering them to share key data and their own stories - not those created by donors. Our technical solution: a mobile-first solution that combines an e-payment system with information tracks to share relevant information - both data and (micro) stories. This approach has immense potential because it addresses an industry-wide challenge. about this event: https://pretalx.c3voc.de/37c3-lightningtalks/talk/TZ7CE3/
Let’s change the default language of the Internet (37c3-meta)
Let’s change the default language of the Internet (37c3-meta)
These days, English is the _lingua franca_, the language that “everyone” speaks and understands. But which English? Our common choice is between two different waning empires that have been imposing their culture and voice on the world for the past few centuries. For most audiences, this is a choice between two foreign locales. We need to do better. We can choose another English: an International English. Our choice of language defines the framework for our communication. It defines what’s expressible, and what the defaults are. It limits our expressibility in ways seen and unseen, and subtly hints where our allegiances lie. In this post-Brexit Europe, English is a more neutral choice than it’s ever been. We need to recognise this, and to capitalize on this opportunity to appropriate the language wholesale. In the software we write and the sites we maintain, we can: European English and International English are already supported by the underlying standards and libraries, and it’s up to us to use them, and to own our voice. The English we speak in international contexts does not need to change; we only need to explicitly realise that it is _our_ language, and that it does not need to bow to imperial authorities. Beyond that, I want to change default language of the Internet. Let me tell you how we can do that. about this event: https://pretalx.c3voc.de/37c3-lightningtalks/talk/P7REEC/
Einführung in Smartphone Malware Forensik (37c3)
Numerical Air Quality Modeling Systems (37c3)
Digital Fordite (37c3-meta)
Numerical Air Quality Modeling Systems (37c3)
High performance computing (HPC) in environmental science is usually associated with research on climate change, investigating the impact of atmospheric greenhouse gases (GHG) over the next century. Besides these GHGs, there are many other gases and aerosolos in the atmosphere, which have a much more direct and immediate impact on human health: air pollutants. The World Health Organization (WHO) considers air pollution to be the world's single largest environmental health threat, accounting for approximately 7 million deaths worldwide every year. That's why in this talk we want to speak about how the problem of air pollution can be understood and predicted using HPC pollution modeling and its application based on general concepts and our own research. We are Dr. Johannes Bieser and Dr. Martin Ramacher, both working at the Helmholtz Zentrum Hereon in the field of numerical pollution modelling. While Dr. Bieser wrote his Dissertation on emission modelling and its application, Dr. Ramacher wrote his Dissertation on pollutant transport and exposure modelling. In our talk on numerical air quality modelling systems, we want to introduce basic principles and share our personal knowledge in the field of numerical pollution modelling, covering the entire pathway from emissions, transport, transformation and human exposure. Each of these steps relies heavily on large amounts of data from many different sources - satellite data, activity and meta data, measurements and many more - and skills in computer science. By default, environmental scientists are often not trained in computer science and high performance computing which implies a challenge of its own (and allows Nerds like us to excel). Our talk will be enriched with practical, technical and partially political examples to demonstrate the difficulties scientist face during their quest to improve air quality for everyone: from TB of wasted data due to historically grown data formats to counterproductive policy decisions to „improve“ air quality. We’ve seen it all and after participating in the CCC for many years now, we decided to draw attention to some state-of-the science approaches for solving one of the world’s single largest environmental health threats: „air pollution“. about this event: https://events.ccc.de/congress/2023/hub/event/numerical_air_quality_modeling_systems/
Einführung in Smartphone Malware Forensik (37c3)
Smartphones sind in den letzten zehn Jahren zu einem allseits beliebten Angriffsziel geworden, sei es für Stalkerware, Staatstrojaner oder Banking-Malware. In diesem Vortrag wollen wir einen Überblick geben, mit welchen Techniken und Open-Source-Tools man auf Smartphones (unter iOS und Android) auf die Jagd nach Malware gehen kann. Im Anschluss findet ein Workshop mit einem praktischen Teil zum Ausprobieren einiger dieser Techniken statt. Die Qualität von Anleitungen und Einführungen zu Smartphone-Forensik im Internet ist leider sehr durchwachsen: Hier will dir jemand ein buntes Tool verkaufen, hier riecht es nach einem Scam, vielerorts geht es um das, was Strafverfolgungsbehörden machen, nämlich in den Daten fremder Leute wühlen. Stattdessen möchten wir in diesem Vortrag einen strukturierten Überblick geben, welche (öffentlichen) Möglichkeiten es in der einvernehmlichen Smartphone-Forensik mit Open-Source-Tools gibt. Wir zeigen euch, wie man welche Arten von Malware finden kann, welche Spuren sie hinterlassen und wie sich Stalkerware und Staatstrojaner in der Praxis unterscheiden. Um 14:15 findet ein praktischer Workshop statt indem gelerntes aus dem Vortrag umgesetzt werden kann: https://events.ccc.de/congress/2023/hub/en/event/introduction-to-smartphone-malware-forensics-pract/ about this event: https://events.ccc.de/congress/2023/hub/event/einfuhrung_in_smartphone_malware_forensik/
Digital Fordite (37c3-meta)
Fordite are polished bits of many layers of hardened enamel car paint. Originally, this car paint was just dumped, until some years ago, when people started to dig them out of the garbage dump, polished them and used them in jewellery. I wrote some code that simulates that process to generate pretty (2D) images and animations. I will quickly show what actual fordite is, then show my early attempts to use the same underlying process to make pretty pictures, describe what is implemented now, show some pretty (abstract) pictures and (if possible) some animations that have been created with it. about this event: https://pretalx.c3voc.de/37c3-lightningtalks/talk/A9REYL/
Building your own algorithms for social networks - Bluesky Custom Feeds with SkyFeed (37c3-meta)
Building your own algorithms for social networks - Bluesky Custom Feeds with SkyFeed (37c3-meta)
Most social networks use proprietary algorithms to recommend new content and keep you on their platform for as long as possible. Other platforms don't use advanced algorithms, but this can make it difficult to discover new content and communities. What if, instead, everyone could simply build their own transparent open source algorithms and publish them for everyone to use? This is possible on Bluesky using SkyFeed (and other tools) today and this talk shows how that works and why you should care :) about this event: https://pretalx.c3voc.de/37c3-lightningtalks/talk/S3GEE8/
Apple Wireless Direct Leaks (37c3-meta)
Apple Wireless Direct Leaks (37c3-meta)
This talk will explain the Apple Wireless Direct Link protocol, which is the basis for AirPlay and AirDrop. about this event: https://pretalx.c3voc.de/37c3-lightningtalks/talk/QGSENV/
Fuzzing the TCP/IP stack (37c3)
Lightning Talk Introduction (37c3-meta)
Fuzzing the TCP/IP stack (37c3)
In this talk, we delve into the captivating realm of TCP/IP stack fuzzing. As the backbone of internet communication, the TCP/IP stack is a prime target for cyber threats. This presentation will unravel the intricacies of fuzzing techniques applied to several TCP/IP stacks, shedding light on how these methodologies can uncover bugs, crashes and vulnerabilities. From the fundamentals of packet fuzzing to advanced mutation strategies, attendees will gain valuable insights into the proactive ways to fuzz a TCP/IP stack. Whether you're a seasoned cybersecurity professional or a curious enthusiast, this talk promises to be an enlightening journey into the heart of TCP/IP stack security and the crucial role of fuzzing in safeguarding our interconnected world. Our exploration begins with an honest appraisal of traditional fuzzing methodologies that have been applied to TCP/IP stacks before, like ISIC, revealing their inherent limitations, e.g., they can't reach beyond the TCP initial state. Recognizing the need for a more evolved approach, we take a different approach, where we leverage a full-blow active network connection for fuzzing. A key revelation in this journey is the deliberate decision to sidestep the arduous task of constructing a custom TCP/IP stack, a choice rooted in practical considerations. The reluctance to build a bespoke TCP/IP stack leads us to innovative strategies such as embedding hooks in the Linux kernel and tapping into userland TCP/IP stacks like PyTCP, Netstack (part of Google gVisor), and PicoTCP. PicoTCP takes center stage, offering a userland TCP/IP stack that becomes integral to our state fuzzing methodology. Attendees will gain a deeper understanding of its architecture, APIs, and documentation, appreciating its pivotal role in fortifying network security. As the presentation unfolds, we navigate through the development of a powerful fuzzer, a core element in our approach to identifying vulnerabilities within the TCP/IP stack. The intricacies of driving traffic through the system, simulating real-world scenarios, and leveraging reproducibility and diagnostics techniques are revealed. The discussion expands to showcase tangible results, including trophies obtained, bugs reported, and the eventual release of the project on GitHub. The session concludes with an engaging Q & A, encouraging participants to delve into the intricacies of TCP/IP stack fuzzing and its profound implications for network security. about this event: https://events.ccc.de/congress/2023/hub/event/fuzzing_the_tcp_ip_stack/
Lightning Talk Introduction (37c3-meta)
A short introduction into the session that shows how everything works. about this event: https://pretalx.c3voc.de/37c3-lightningtalks/talk/HMAEGD/