
Chaos Computer Club - archive feed
21,021 episodes — Page 90 of 421
How to: Legal Blockieren (DS2023)
Über Möglichkeiten und Vorgehensweisen des legalen Blockierens. Nazis, Querdenken und andere verschwörungsideologische Aufmärsche - welche Möglichkeiten gibt es, in Einklang mit Versammlungsgesetzen und in Verhandlungen mit Polizei und Behörden legal zu blockieren? Im Januar 2022 gründete sich in Dresden eine lose Gruppe von Aktivist:innen, die unter dem Namen „QuerstellenDD“ diverse Querdenken-Aufmärsche und PEGIDA-Überbleibsel nicht weiter unwidersprochen durch die Stadt ziehen lassen wollte. Montag um Montag gelang es trotz deutlicher zahlenmäßiger Unterlegenheit, den - zu dieser Zeit oftmals unangezeigten - Aufzügen den Weg abzuschneiden, ihre Route zu beeinflussen und sie aus der Innenstadt oder gar aus ganzen Stadtteilen herauszuhalten. Frei nach dem Motto: Whose Streets? Our Streets! Diese Wochen waren und sind - ebenso wie die Gegenproteste rund um den 13. Februar - noch immer ein großes Lehrstück für den Umgang mit rechten Protesten, Polizeikräften und Versammlungsbehörden. Im Gegensatz zu klassisch linksaktivistischen Blockaden wurde bewusst und gut vorbereitet mit der Polizei und der Versammlungsbehörde in Kontakt getreten. Das ist und war ein relativ neuer Ansatz, der nicht nur oftmals von Erfolg beim Blockieren gekrönt wird, sondern polizeiliche Repression gegenüber der eigenen Gruppe proaktiv verhindert. Wissen ist zum Teilen da - Zeit, für Strategien, Verhaltensregeln und Tipps zum „legalen Blockieren“. about this event: https://talks.datenspuren.de/ds23/talk/NR38QL/
Into the federated Universe - Digital sovereignty through decentral communication (DS2023)
The fediverse as decentral, poly-feature communication platform and its developmental challenges. Mastodon? The fediverse? There is so much more, than you probably know. In this talk you will get a deep dive into what the fediverse is, how it works in the backend, why it is a absolute headache for developers right now and how things could change in the future. about this event: https://talks.datenspuren.de/ds23/talk/JS3ARW/
How to: Legal Blockieren (DS2023)
Lightning Talks (DS2023)
Lightning Talks about this event: https://talks.datenspuren.de/ds23/talk/MMKPDJ/
Lightning Talks (DS2023)
Alles EXCEL-lent an der TU-Dresden (DS2023)
Wie viel Geld zahlen sächsische Unis für Microsoft Produkte? Wie schwer ist es, das herauszufinden? Wir haben uns die Frage gestellt, wie viel Geld die TU-Dresden eigentlich für Microsoft Produkte bezahlt und einfach mal nachgefragt. Aber am Ende steckte hinter dieser kleinen Anfrage mehr Arbeit als erwartet. Wir nehmen euch mit auf dem Weg unserer Frage und wollen dabei ergründen, wer eigentlich mit Microsoft Verträge macht, warum alle Institutionen MS-Produkte nutzen, was eigentlich mit dem sächsischen Transparenz-Gesetz falsch ist, wie man sich vom MS-Monopol lösen kann und wie viel Geld die Unis nun wirklich ausgeben. about this event: https://talks.datenspuren.de/ds23/talk/UUMEFS/
What computers still cannot do (DS2023)
Buchvorstellung von Dreyfus "What Computers Still Cannot Do". Wissenschaftsphilosophische Kritik. Wissenschaftsphilosophische Kritik auf das Paradigma (den Glauben) hinter KI, Analyse wo Paradigma herkommt, Analyse der verschiedenen KI-Hypes. Phenomenologische Erklärungen einiger fundamentalen Probleme in der KI Entwicklung. about this event: https://talks.datenspuren.de/ds23/talk/WKZX8E/
What computers still cannot do (DS2023)
Alles EXCEL-lent an der TU-Dresden (DS2023)
GrapheneOS eine datenschutzfreundliche Android Alternative (DS2023)
GrapheneOS ist ein freies und quelloffenes Android-basiertes Betriebssystem GrapheneOS ist ein freies und quelloffenes Android-basiertes Betriebssystem für ausgewählte Smartphones welches ein speziellen Fokus auf Datenschutz und Sicherheit legt. In diesem Vortrag möchte ich das Betriebssystem vorstellen und auf die wichtigsten Features eingehen. Der Vortrag richtet sich explizit an Einsteiger und soll hauptsächlich die Anwenderseite und weniger die technische Seite beleuchten about this event: https://talks.datenspuren.de/ds23/talk/Z9MNWB/
GrapheneOS eine datenschutzfreundliche Android Alternative (DS2023)
Was hat sich durch das sächsische Transparenzgesetz geändert? (DS2023)
Seit Januar 2023 gilt das sächsische Transparenzgesetz. Doch was hat sich dadurch wirklich geändert? § 1 Sächsisches Transparenzgesetz: "Anspruch auf Transparenz (1) Jede Person hat gegen die transparenzpflichtigen Stellen einen Anspruch auf Veröffentlichung der in § 8 genannten Informationen und auf Zugang zu Informationen, soweit keine Ausnahme gilt (Transparenzanspruch)." Was bedeutet das? Welche Informationen können Bürger:innen nun erhalten und was hat sich im Vergleich zu vorher verändert? Diese Fragen möchte ich zusammen mit euch in meinem Vortrag klären. Einen kleinen Video-Teaser findet ihr bereits hier: https://video.dresden.network/w/1G7Zu7TRK6Vmpdy3bicMsT about this event: https://talks.datenspuren.de/ds23/talk/77YSW7/
Was hat sich durch das sächsische Transparenzgesetz geändert? (DS2023)
Open Source Hardware - Changing the Paradigms of Production (DS2023)
Open Source Hardware - Changing the Paradigms of Production (DS2023)
We will explore the impact of open source hardware and its significance in driving innovation. In this presentation, we will delve into the world of open source hardware and its transformative impact on production paradigms. We will explore key concepts surrounding open source hardware, such as collaboration, accessibility, and innovation. We will highlight existing projects that have leveraged the power of open source hardware, showcasing their contributions to various fields. Furthermore, we will introduce our own project called "oshop," which aims to foster a vibrant open source hardware ecosystem. Oshop provides a platform where companies, developers, and creators can collaborate, share knowledge, and contribute to the advancement of open source hardware in manufacturing. about this event: https://talks.datenspuren.de/ds23/talk/TAZRF8/
Was ist AKND3? (DS2023)
Was ist AKND3? (DS2023)
Na der Arbeitskreis für nachhaltige Digitalisierung Dresden! Was wir so machen, was unsere Ziele sind und warum wir auf lokaler Ebene arbeiten, das stellen wir euch in diesem kurzen Talk vor. about this event: https://talks.datenspuren.de/ds23/talk/HFVD8L/
Mit HyperLogLog gegen Vorratsdatenspeicherung (DS2023)
Wie wir personenbezogene Daten verarbeiten können, ohne dabei die Privatsphäre zu verletzen Social-Media-Daten werden in großem Umfang genutzt, um Erkenntnisse über soziale Ereignisse zu gewinnen, sei es auf lokaler oder auf globaler Ebene. Zur Auswertung ist es gängige Praxis, diese Daten erstmal herunterzuladen und lokal zu speichern. Rücksicht auf den Schutz der Privatsphäre der Social-Media-Nutzer fällt dabei oft hinten runter. Der Schutz der Privatsphäre beim Umgang mit personenbezogenen Daten ist jedoch sowohl aus ethischer als auch aus juristischer Sicht geboten. Das trifft selbstverständlich nicht nur auf Social-Media-Daten zu, sondern geht weit darüber hinaus. In diesem Vortrag möchte ich eine privatsphäreschützende Methode zur Verarbeitung von personenbezogenen Daten vorstellen, in der eine Technologie namens HyperLogLog zum Einsatz kommt. HyperLogLog ist ein sogenannter Cardinality-Estimation-Algorithmus, also ein Verfahren, in dem die Anzahl von Elementen einer Menge nur geschätzt wird. Es arbeitet sehr performant und ist darum für große Datenmengen gut geeignet. Es kommt deswegen bereits in vielen Datenbanksystemen zum Einsatz. Ich möchte dieses Verfahren jedoch nicht zur Leistungsoptimierung zum Einsatz bringen, sondern zum Schutz der Privatsphäre. Der Besitz großer personenbezogener Datenmengen ist immer mit dem Risiko verbunden, dass die Daten versehentlich in die falschen Hände gelangen. Frei nach dem Motto "was ich nicht hab, kann ich nicht verlieren" möchte ich am Beispiel von Social-Media-Daten zeigen, wie große Datenmengen analysiert werden können, ohne überhaupt in den Besitz der eigentlichen Rohdaten zu gelangen. Auf diese Weise kann das Risiko des Missbrauchs oder der versehentlichen Veröffentlichung von Datensätzen gemindert und die Privatsphäre der Social-Media-Nutzer geschützt bleiben. Der Vortrag soll euch zum lauten Nachdenken "über morgen™" anregen. Im Anschluss möchte ich nämlich mit euch diskutieren, in welchen weiteren Anwendungsfällen diese Methodik zum Einsatz kommen könnte. Vor welchen dystopischen Horrorszenarien könnte uns diese Technologie schützen? about this event: https://talks.datenspuren.de/ds23/talk/G7YCLU/
Mit HyperLogLog gegen Vorratsdatenspeicherung (DS2023)
#FediBuzz: Globale Hashtags fürs Fediverse (DS2023)
https://fedi.buzz Hashtags sind ein hilfreiches Mittel um Menschen in sozialen Netzwerken in Kontakt zu bringen. Obwohl wird Dezentralisierung als wichtige technologische Entwicklung wahrgenommen wird, stellt sie globale Sichtbarkeit vor größere Hindernisse. In der Praxis heißt das: dein Mastodon-Server sieht die Posts nur all jener Leute, denen die lokalen User folgen. Tatsächlich gibt es aber ältere dezentrale Systeme, von denen wir lernen können; dem World-Wide Web zum Beispiel. Also haben wir uns eine kleine Suchmaschine gebaut, die Live-Inhalte von ein paar Tausend Mastodon-Servern bekommt. Damit können wir unter https://fedi.buzz einen Einblick in trending Hashtags im Fediverse geben. Zusätzlich bieten wir mit BuzzRelay noch ein sogenanntes ActivityPub-Relay, mit welchem Mastodon-Administratoren ihren Server mit Inhalten nach Wunsch-Hashtag befüllen lassen können. Viele kleine Server weltweit nutzen diesen Dienst bereits um ihren wenigen Nutzern mehr themenspezifische Inhalte zu liefern. about this event: https://talks.datenspuren.de/ds23/talk/TL9EYN/
#FediBuzz: Globale Hashtags fürs Fediverse (DS2023)
Presentation on Iran´s Situation (DS2023)
Presentation on Iran´s Situation (DS2023)
History of the struggles for freedom among people, who live within political borders of Iran. With the beginning of Jina’s movement, all eyes turned into Iran. A country notorious for its human right violation and imposed restrictions on women’s life, suddenly made headlines due to an uprising mainly led by women and youth and people within different nations and ethnic groups in Iran. Events that followed after Jina’s state murder, shattered all the existing dominant narratives about Iran, exposing the reality behind the curtain of what seemed to be a culturally and politically homogeneous society. In this presentation Shaghayegh is telling tell us, bits and pieces from now and then, from here and there, about the history of resistance and struggles for freedom among the people, who live within political borders of Iran, about constant presence, efforts and attempts of counter revolutionary forces to keep and maintain the foundations and structure of power, with understanding Iran's role, ties, and geopolitical impact on the region, as much as time allows. about this event: https://talks.datenspuren.de/ds23/talk/9RX3TZ/
George Orwell: 1984; Überwachung, Zensur, Macht (DS2023)
Ich lese Textpassagen vor und erzähle, was mir hierzu einfiel. Keine Vorkenntnisse nötig. Ich möchte einige interessante Textpassagen aus George Orwells "1894" vorlesen (deutsche Übersetzung) und erzählen, was mir spontan zu diesen einfiel. Folgende Themen kommen darin vor: * (Video)Überwachung durch staatliche Einrichtungen ** Auswirkungen von Überwachung auf Gesellschaft ** Nutzen von öffentlicher Videoüberwachung * Zensur * Ethische Aspekte zu diesem Komplex: ** Verhaltensänderung durch Überwachung, Disziplinargesellschaft ** Überwachung und Sozialdarwinismus ** Michel Foucault: Macht- und Wahrheitsstrukten ** Sprachökonmie, Sapir-Whorf-Hypothese Ich würde auch kurz auf die Metadaten des Werks eingehen, jedoch nicht auf die Handlung. Es ist _nicht_ notwendig, das Buch vorher gelesen zu haben. Den Vortrag hielt ich in ähnlicher Form bereits im November 2022 in der Otto-von-Guericke-Universität Magdeburg in der Lehrveranstaltung "Informatik und Ethik". about this event: https://talks.datenspuren.de/ds23/talk/9Z9QHK/
George Orwell: 1984; Überwachung, Zensur, Macht (DS2023)
Das kleine 1x1 der sicheren Computernutzung (DS2023)
Eine Einführung in das Thema Sicherheit auf Linux für Neulinge Seid ihr unsicher, wie ihr zeitgemäß und sicher einen Computer betreiben könnt? Hier möchte ich euch einen Überblick über relevante Themen verschaffen, wie ihr von der Einrichtung eures Rechners über Endanwendungen bis hin zu Online-Diensten euren Alltag gut und sicher gestalten könnt. about this event: https://talks.datenspuren.de/ds23/talk/RZWYPH/
Das kleine 1x1 der sicheren Computernutzung (DS2023)
This is not fine! (DS2023)
Ein deprimierender Überblick und ein hoffentlich weniger deprimierender Ausblick. Das Meme mit dem "This is fine"-Hund in Flammen ist beliebt. Aber damit morgen besser als heute wird, müssen wir aushalten, das vieles so gar nicht in Ordnung ist. Nicht nur, wenn es um Klimakatastrophe und Co. geht, sondern auch in Bezug auf den Grundrechteabbau in unserer digitalen Welt - trotz der vermeintlichen "Fortschrittskoalition". Ein deprimierender Überblick zur Halbzeit der Legislatur, was brennt. Und ein hoffentlich nicht ganz so deprimierender Ausblick, was wir tun können, um die Brände zu löschen. Damit übermorgen besser als heute wird. about this event: https://talks.datenspuren.de/ds23/talk/YJUHK9/
This is not fine! (DS2023)
Eine Reise ins Neuland (DS2023)
Eine Reise ins Neuland (DS2023)
http, ssl, html, js, Werbeblocker ublock origin, noscript, ghostery. ... Was passiert wenn wir uns ins Neuland begeben? In diesem Talk wird eine Reise ins Neuland unternommen. about this event: https://talks.datenspuren.de/ds23/talk/KBWS7U/
Opening (DS2023)
Opening about this event: https://talks.datenspuren.de/ds23/talk/VY99KZ/
Opening (DS2023)
Pentaradio live! (DS2023)
Podcast Soiree Wir reden wie immer über die News des Monats sowie über OT-Sicherheit. Außerdem füllen wir eure Podcast-Queue. about this event: https://talks.datenspuren.de/ds23/talk/DJYKKS/
Pentaradio live! (DS2023)
Militant protest and prisoners' support in russia during the war (DS2023)
Presentation from Solidarity Zone initiative that support those repressed for actions against war Solidarity zone's member will talk about political context, led to the failure of peaceful protest, screws tightening and appearing of individual acts of militant resistance against russian imperialism and military aggression in Ukraine. In our helping work we face, on the one hand, with symbolic actions, and on the other, with more prepared acts of sabotage. Both of them seem to be significant for further understanding of ongoing social processes and political inertia of russian society. about this event: https://talks.datenspuren.de/ds23/talk/KVBND9/
Militant protest and prisoners' support in russia during the war (DS2023)
3 years after uprising in Belarus - political situation and repressions in the coutry (DS2023)
3 years after uprising in Belarus - political situation and repressions in the coutry (DS2023)
Presentation about repressions in Belarus and anarchists movement in exile In August 2020 belarusian people rose against dictatorship of Alexander Lukashenko hopying to overthrow a regime, existing in Belarus since 1994. Several months of protests ended up in mass wave of repressions and political migration from the country. With thousands of political prisoners out of which at least 30 are anarchists, Belarus is the country with one of the highest levels of repressions in Europe this days. Couple of years later Vladimir Putin started full scale invasion of Ukraine with support of belarusian regime. This created even more problems for the rest of resistance against dictatorship in Belarus. During this talk member of ABC-Belarus will present the current political situation inside the country and in diaspora organized in Poland/Lithuania. What are the perspectives of the people trying to overthrow dictatorship and what is the role of anarchists in the whole story? The talk will be around 90 minutes with space for questions and a discussion. about this event: https://talks.datenspuren.de/ds23/talk/FWVA3H/
Closing session of All Systems Go! 2023 (asg2023)
Closing session of All Systems Go! 2023 (asg2023)
Closing session of All Systems Go! 2023 about this event: https://cfp.all-systems-go.io/all-systems-go-2023/talk/PKSMVD/
antlir2: Deterministic image builds with buck2 (asg2023)
asynchronous dbus with C++ co-routines (asg2023)
sdbusplus generates ergonomic and compile-time type-checked dbus bindings built atop sd-bus. This library is heavily used within the OpenBMC project to provide all IPC between its many userspace processes. This talk will give an overview of how OpenBMC leverages dbus, how sdbusplus facilitates its usage, as well as an introduction on our approach for asynchronous programming with C++ co-routines. about this event: https://cfp.all-systems-go.io/all-systems-go-2023/talk/QUMHR3/
asynchronous dbus with C++ co-routines (asg2023)
antlir2: Deterministic image builds with buck2 (asg2023)
In this talk we’ll discuss antlir2, Meta’s solution to building container and bare metal operating system images. We’ll talk about how we have built performant, hermetic and deterministic image building infrastructure on top of buck2 (Meta’s new open source build system) and how we enable users to compose their own multi-language projects with full operating systems, write tests and deploy their images. Along the way, we’ll also cover how antlir2 wrangles dnf and other upstream tooling to behave more predictably for better, more reliable images. about this event: https://cfp.all-systems-go.io/all-systems-go-2023/talk/9E9MLC/
Building image-based OSes with BuildStream (asg2023)
Microsoft Azure Boost: Image-based Linux powering the Azure fleet. Wait, what? Really?! Yes! (asg2023)
A quick journey through the Azure infrastructure, specifically looking at how image-based Linux is used for Azure Boost, what it enables, what interesting security and performance features were added and where to find them upstream. Believe it or not, today Linux is right at the core of Microsoft Azure's infrastructure, on the very nodes that run all those fancy virtual machines. Getting there was not easy, and a lot of work was needed to meet the very stringent security and performance goals that were set. We built a custom distribution, added several security features such as signed dm-verity and kernel-enforced code integrity, came up with a way to keep state alive across kexec with PMEM, and implemented the stackable Portable Services image model that ultimately became sysexts and confexts. And much more! This talk will walk through this effort, starting with a peek under the cover at the hardware that powers it and what it enables, passing through the custom OS and ending up at all the features we added to systemd and elsewhere that you all can enjoy as well. about this event: https://cfp.all-systems-go.io/all-systems-go-2023/talk/7URRNC/
Building image-based OSes with BuildStream (asg2023)
BuildStream is a tool for building / integrating software stacks. In a way, it has a similar goal to bitbake / yocto and Android repo, but takes a completely different approach. It can be used to take software from various sources, build it with various buildsystems in a reproducible sandbox, and cache results for speedy rebuilds. In this talk I give a brief overview of Buildstream, how it is used to build GNOME OS, and the challenges we face in using it. I also go over freedesktop-sdk which is a base runtime that can be used as a base to build your own system. I also discuss the challenges we encountered with using buildstream with ostree and the steps we're taking to support updating with systemd-sysupdate. about this event: https://cfp.all-systems-go.io/all-systems-go-2023/talk/G8UZGL/
Microsoft Azure Boost: Image-based Linux powering the Azure fleet. Wait, what? Really?! Yes! (asg2023)
Wolfi: A Secure-by-Default Distro for Curing Container CVE Chaos (asg2023)
Are you using container images with hundreds of known vulnerabilities? The majority of us are using images based on the Docker official images available on the Docker Hub. This includes base images – such as Debian and Ubuntu – as well as application images such as nginx and redis. Unfortunately these images often have hundreds of known vulnerabilities due to excessively large dependency trees with out-of-date packages. This security debt can lead to unnecessary security risks and slower development cycles. Wolfi (https://github.com/wolfi-dev/) is a new Linux distribution optimized for building minimal, secure container images. Wolfi maintainers prioritize a rolling release model built on a rapid package update cycle, which ensures that new vulnerabilities are remediated quickly. This talk not only describes the problems that motivate Wolfi but also provides hands-on knowledge to help developers take advantage of Wolfi. By the end of the talk, developers will learn about packaging techniques with apko and melange, tools specifically designed to build Wolfi packages and turn them into minimal, low- or no-vulnerability containers. Key Takeaways and Highlights Popular, off-the-shelf base images and containers often have hundreds of known vulnerabilities (“CVEs”), which can, at worst, be a security risk and, at best, be a giant time suck. Wolfi is a new secure-by-default linux distribution that prioritizes rapid package updates and, by extension, fast mean time-to-remediation for known vulnerabilities. Packages in Wolfi can form the foundation of secure, minimal base images and containers, freeing developers of tedious vulnerability management tasks and increasing security for cloud-native applications. Talk Outline The Cloud-Native Application Status Quo: Bloated, Outdated, Vulnerability-Laden Images Containers 101 Show the results of running security scanners against popular Dockerhub official images Use (grype, an open source scanner) to scan golang:latest and nginx:latest. Show via command line. Show data and analysis on package counts, package staleness, vulnerability counts of official Docker Hub images Draw on six months of daily scanning results collected by presentation team Overview of Wolfi Fast package update times Fast vulnerability mean time-to-remediation Granular packages Wolfi packages are often packaged at a more granular level than their counterparts in other distributions, which allows developers to pick and choose only the components that are essential for an image, without dragging in unnecessary functionality and attack surface. Rolling release Why not alternative approaches, either other minimal images or using other distros? Google distroless Debian-based so there can be slow update times for packages Debian - Slow package updates How to build images with Wolfi packages Explain melange and building packages Example of building a package with melange Explain apko and building images Demo of building an image with apko about this event: https://cfp.all-systems-go.io/all-systems-go-2023/talk/V9EZSS/