
Chaos Computer Club - archive feed
21,021 episodes — Page 95 of 421
Reality for real? Problematic perspectives in a virtual world. (mrmcd23)
Mammuts Eating Grains of Salt - Faking Mastodon Statistics (mrmcd23)
Mastodon is currently one of the leading services in the so called Fediverse as a federated online social network, so its inner workings are of special interest to understand and for attackers to potentially abuse. This talk aims to show one essential compontent of the Fediverse: Trust. And what will happen if you misuse it. The general architecture of the Fediverse to understand the design possibility for such attacks is also taken into account as well as ethical considerations to conduct research on a real social media network. It covers a part of current research as one example for the trust built into the design of most (ActivityPub) Fediverse platforms. about this event: https://talks.mrmcd.net/2023/talk/H93AD9/
Mammuts Eating Grains of Salt - Faking Mastodon Statistics (mrmcd23)
Reality for real? Problematic perspectives in a virtual world. (mrmcd23)
The question about what is real arouses great interest in different areas of knowledge, but what is actually reality? This question lies at a level of philosophical abstraction that is difficult even for philosophers to resolve. Still, the fact that it belongs to the realm of philosophy does not mean that anyone can answer this question or even think about it; since every human being and therefore homo sapiens-sapiens has some inner Sapientia (wisdom). With this intro, I would like to invite you to have a moment to ask yourself what is real and what is reality, and if you think that it depends on the perspective, how can you be sure that we are living in a real world, with real feelings, emotions, and experiences and have mutual conversations about reality and about who owns reality? about this event: https://talks.mrmcd.net/2023/talk/VMRTPD/
Reality & Dreams - Über die Cybersicherheit in KMU (mrmcd23)
Reality & Dreams - Über die Cybersicherheit in KMU (mrmcd23)
Mehr als 75% der mittelständigen Unternehmen in Deutschland sehen ein hohes Risiko, dass Marktbegleiter der eigenen Branche, Opfer von Cyberkriminalität werden. Doch lediglich 30-40% sehen dieses Risiko auch für das eigene Unternehmen. Das geht aus einer repräsentativen Umfrage von 300 Unternehmen hervor. Dieser Talk handelt von der Diskrepanz zwischen Realität und Wunschbild, wenn es um die Cybersicherheit in kleinen- und mittleren Unternehmen geht. about this event: https://talks.mrmcd.net/2023/talk/YGHV8S/
Woher weiss die shell was sie tun soll wenn ich TAB drücke? (mrmcd23)
Woher weiss die shell was sie tun soll wenn ich TAB drücke? (mrmcd23)
Tab-completion ist eine tolle Sache, aber woher weiss die shell eigentlich was sinnvolle Vervollständigungsvorschläge sind, und was nicht? Ich möchte einen kleinen Überblick darüber geben welche Mechanismen es da gibt, und wo ich Vor- und Nachteile unterschiedlicher Methoden gibt. Es gibt von Hand geschriebene Completion functions, Heuristiken die USAGE-Printout parsen, Code Generierung, Callbacks zwischen shell und Programm… Und diese Varianten stellen unterschiedliche Anforderungen an Software-Maintainer\*innen, downstream Contributer\*innen, Paktetierer\*innen von Linux Distributionen. Und natürlich soll auch der Einfluss auf Latenzen erwähnt werden. Das ganze aus der Sicht eines zsh-Nutzers der das rust-crate clap ziemlich cool findet, ich möchte mich aber auf allgemeine Problemstellungen und Lösungen konzentrieren, die auch für andere Programmiersprachen und shells relevant sind. about this event: https://talks.mrmcd.net/2023/talk/SRSSUV/
Ein Date zwischen Medizinphysik und Informatik (mrmcd23)
Code und Kekse: (mrmcd23)
Wie bekommt man in einem Großkonzern das unbeliebte Thema Softwaresicherheit umgesetzt? Wir zeigen, wie wir bei DB Vertrieb die Sicherheitsmaßnahmen unseres Softwarelebenszyklus erklären und Unterstützung für die Umsetzung gewinnen. Softwaresicherheit ist in großen Organisationen ein Thema, das oft wenig Begeisterung in Entwicklungsabteilungen auslöst. Das Backlog ist voll, der Zeitdruck für schnell umzusetzende Sprintziele bestimmt den Alltag und das nächste große Release lässt unbeliebte Themen wie Sicherheit, Wartbarkeit oder Skalierbarkeit in den Hintergrund treten. Um Sicherheit in diesem Spannungsfeld zu gewährleisten, kommt es nicht nur auf das technische Knowhow des Einzelnen an, sondern wir müssen alle Beteiligten abholen, um Sicherheit erfolgreich in die Prozesse der Organisation zu integrieren. Unser Vortrag zeigt, wie wir Mitarbeitenden der DB Vertrieb mit zwei Plüschmonstern unterhaltsam und ohne mahnenden Zeigefinger die Bestandteile unseres sicheren Softwareentwicklungslebenszyklus vermitteln: In der Parallelstraße der Sesamstraße wurden aus einem smarten Tresor alle Kekse geklaut. Der Lagerverantwortliche Krümel M. fragt sich: Wer macht so etwas? Wie konnte das passieren? Wer trägt Schuld? Glücklicherweise übernimmt Privatdetektiv Sherlock H. die Ermittlungen und zeigt auf, wie Krümel M. künftig Software sicher entwickeln sollte und erklärt wie Sicherheitsmaßnahmen - zum Beispiel Penetration-Tests, statische Codeanalyse, Threat Modeling - funktionieren und warum man diese umsetzen will. about this event: https://talks.mrmcd.net/2023/talk/ZA888E/
Code und Kekse: (mrmcd23)
Ein Date zwischen Medizinphysik und Informatik (mrmcd23)
Ablauf und Planung einer Strahlentherapie, Umgang mit der Planugs-Software, sinnvolle Hilfestellung durch KI (?) am realen Beispiel Der Vortrag thematisiert einige Schnittstellen zw Medizin, Physik und Informatik am Beispiel der Strahlentherapie, der Planung einer Bestrahlung mittels geeigneter Software, was eigentlich im Körper passiert, wenn dieser mit hochenergetischer Strahlung "beschossen" wird und wie KI ggf dabei helfen kann und wo sie versagt. Diese ist eine Fortführung des Vortrags "Medizinphysik - von Strahlung und KI" von der GPN21. Auf den Studiengang selbst und die Arbeit im Berufsfeld MPE werde ich nicht mehr eingehen, könnt ihr aber hier (https://www.youtube.com/watch?v=-AiI0WFyDVU) und hier (https://medizinphysik.wiki/) nachschauen. about this event: https://talks.mrmcd.net/2023/talk/C8RLGP/
mrmcd23 Closing: Das Ende der Realität (mrmcd23)
Es geht zu Ende about this event: https://talks.mrmcd.net/2023/talk/7RKEUH/
mrmcd23 Closing: Das Ende der Realität (mrmcd23)
Demoparty Preisverleihung (camp2023)
Award ceremony for the winners of the night before. Award ceremony for the winners of the night before. We'll present the winning entries. about this event: https://pretalx.c3voc.de/camp2023/talk/LJQF7F/
Chaos Communication Camp 2023 Closing (camp2023)
Chaos Communication Camp 2023 Closing (camp2023)
A heartfelt farewell about this event: https://pretalx.c3voc.de/camp2023/talk/NXDM8Z/
#CCCamp23 Review (camp2023)
#CCCamp23 Review (camp2023)
Zahlen, Daten, Fakten. Natürlich wie immer ohne Gewähr. Die #CCCamp23 Review Session - Damit auch DU weißt, was du verpasst hast. Eine stark willkürliche Auswahl von großartigen Dingen auf dem Camp. about this event: https://pretalx.c3voc.de/camp2023/talk/ACVRNU/
Project Blinkenlights (camp2023)
The complete story of Project Blinkenlights: achievements, failures, technology and its cultural impact In 2001, the Chaos Computer Club surprised the world with a simple but impressive interactive light installation on a building in the heart of Berlin: Blinkenlights illuminated 144 windows forming a huge but low-resolution pixel matrix on the facade of House of the Teacher at Alexanderplatz. But this was just the beginning. Much bigger follow-ups took place in Paris and Toronto and in between a lot of other things happenend. This talk shows it all: what worked, what did not work, the good ideas, the bad ideas and all that jazz. This year at Camp, we celebrate Blinkenlights history with another interactive light installation at the Camp. about this event: https://pretalx.c3voc.de/camp2023/talk/E7XGY9/
Project Blinkenlights (camp2023)
Cadus e.V. (camp2023)
Chaos Family Cadus e.V. about this event: https://pretalx.c3voc.de/camp2023/talk/1668/
Cadus e.V. (camp2023)
Bosch sensors in the flow3r badge (camp2023)
Reproducible Builds, the first ten years (camp2023)
In this talk Holger Levsen will give an overview about reproducible builds, the past, the presence and the future. How it started with a small BoF at DebConf13 (and before), how it grew from being a Debian effort to something many projects work on together, until in 2021 it was mentioned in an executive order of the president of the United States. And of course the talk will not end there but rather outline where we are today and where we still need to be going, until we'll all be running 100% reproducible software, verified by many. In this talk Holger Levsen will give an overview about reproducible builds, the past, the presence and the future. How it started with a small BoF at DebConf13 (and before), how it grew from being a Debian effort to something many projects work on together, until in 2021 it was mentioned in an executive order of the president of the United States. And of course the talk will not end there but rather outline where we are today and where we still need to be going, until we'll all be running 100% reproducible software, verified by many. And while Holger's day to day work and this talk will have a Debian focus, reproducible builds in other project will be featured and not be left behind as Holger has been involved in Reproducible Builds since 2014 and has been working on reproducing Arch Linux, coreboot, Fedora, FreeBSD, NetBSD, OpenWrt and others. Other important software projects will also be covered and last not least Holger will also explain why you'll want verifiable S BOMs and not just SBOMs. So what is this talk about exactly again? "A build is reproducible if given the same source code, build environment and build instructions, any party can recreate bit-by-bit identical copies of all specified artifacts." (https://reproducible-builds.org/docs/definition) about this event: https://pretalx.c3voc.de/camp2023/talk/J7SDTF/
Wir müssen über KI sprechen (camp2023)
Reproducible Builds, the first ten years (camp2023)
Bosch sensors in the flow3r badge (camp2023)
Exploration of the sensor hardware and programming of the flow3r badge. In particular the pressure sensor BMP581 and acceleration/gyrometer BMI270. I will give a quick introduction into the Bosch MEMS technology and sensors. Next I want to show some very basic steps how to use MicroPython on flow3r to play with LEDs and sensors. about this event: https://pretalx.c3voc.de/camp2023/talk/Z3CPTN/
Wir müssen über KI sprechen (camp2023)
Dass wir bald von Superintelligenzen beherrscht werden, die wie ChatGPT Texte generieren, ist unwahrscheinlich. Aber es gibt offene Fragen: zu Wissensgerechtigkeit, Teilhabe und Monopolisierung durch Konzerne. Künstliche Intelligenz ist eine Projektionsfläche. Jetzt wird alles anders! Dabei ist die Beschäftigung damit, wie Maschinen Aufgaben erledigen, von denen wir bisher dachten, dass sie nur Menschen bewältigen können, fast so alt wie Computer selbst. Und auch die Probleme damit, wie Technik eingesetzt wird, sind ähnlich geblieben. Welche Zukunft darf es sein: Gerecht und frei zugänglich für alle, oder doch lieber in den Händen von wenigen? Es gibt offene Fragen: Wer produziert Wissen unter welchen Rahmenbedingungen? Ist das gerecht? Wie können wir uns als Menschen um mehr Gerechtigkeit bemühen und verhindern, dass die Macht der wirtschaftlichen Giganten unter dem Label "KI" noch weiter wächst? Ein Gedankenanstoß zur politischen und gesellschaftlichen Dimension des Hype-Themas der vergangenen Monate. about this event: https://pretalx.c3voc.de/camp2023/talk/EJBDYN/
Nerds touching grass (camp2023)
16 years after the international Hackspace revolution, we are finding ourself in the midst of a global crisis with a search for answers. At Bio-Hack-Spaces we create mycelium based build materials, research new ways of growing (or foraging) our own food, build technological bridges to nudge nature in our desired direction or tinker on devices that help us to better understand our surroundings. 16 Years ago, a series of talks by Johl and Pylon on Hackspace Design Patterns sparked an international revolution. Within a few months tens of new Hackspaces were founded all over the world. And while the fun lasted for a while, we are now in the midst of a global crisis, that its least is urgently asking for mitigation strategies. At Bio-Hack-Spaces we create mycelium based build materials, research new ways of growing (or foraging) our own food, build technological bridges to nudge nature in our desired direction or tinker on devices that help us to better understand our surroundings. The Biopunk movement is in almost every regard comparable to the old school hacker movement. It is about resilience, creativity and autonomy. And yet, there is one fundamental difference: While you bend a computer to your will, you can only politely ask anything that lives. So in that sense, Biopunk is about understanding that we aren’t separated from nature, we are nature. And nature will teach us something that society needs more than anything else: the ability to listen. about this event: https://pretalx.c3voc.de/camp2023/talk/FBQJAG/
Nerds touching grass (camp2023)
Landstraßen-, Wirtschafs- und Feldwegnutzung für Stadtmenschen kurz erklärt (camp2023)
Landstraßen-, Wirtschafs- und Feldwegnutzung für Stadtmenschen kurz erklärt (camp2023)
Menschen Fahren aus der Stadt aufs Land. Da fährt (sonntags) kein Bus, deshalb bringen sie ihr Auto mit. Dieser Talk erklärt, wie man vermeidet, dass der Ausflug ins Grüne zum Fiasko wird und wie sich auf dem Land der Strassenverkehr von Staedten unterscheidet. about this event: https://pretalx.c3voc.de/camp2023/talk/VYGPCZ/
Jugend Hackt (camp2023)
Chaos Family Jugend Hackt about this event: https://pretalx.c3voc.de/camp2023/talk/2648/
FIDO2 (camp2023)
FIDO2 (camp2023)
Passwords suck, Multi Factor Authentication is hip, everyone wants to use it, but most methods rely on some kind of generated One-Time passcode, which are as vulnerable to phishing as the passwords they should help protect. Other possible factors, like app-based authentication also bring similar design flaws to the table A good alternative to insecure factors is the FIDO2 Standard, also sometimes referred to as WebAuthn, and its latest addition, passkeys. This presentation will demonstrate the functionality of FIDO2/WebAuthn and compare it to other possible (multiple) factors. It will also demo setup and some basic configuration. Special emphasis will be brought to passwordless authentication and the benefits and drawbacks of passkeys. about this event: https://pretalx.c3voc.de/camp2023/talk/R3ETSG/
Jugend Hackt (camp2023)
Bootloader Crimes (camp2023)
Energy Consumption of Data Centers (camp2023)
Energy Consumption of Data Centers (camp2023)
The energy consumption of datacenters is increasing exponentially. Local community heating is required to heat houses. The talk will give an overview of the existing problems and examples how data centers can be integrated into green power generation to heating concepts producing data center services en passant. 3% of global electricity consumption today and are projected to touch 4% by 2030. The average hyperscale facility consumes 20-50MW annually – theoretically enough electricity to power up to 37,000 homes[1]. Newer concepts reduce the energy for cooling to zero and integrate the datacenter into photovoltaic energy sources and local community heating as a sink[2]. Open source concepts allow to run a local cloud zone in this location regaining control of citizen data. [1] https://datacentremagazine.com/articles/efficiency-to-loom-large-for-data-centre-industry-in-2023 [2] https://www.ala-magazin.de/_thumbnails_/1680_2_JH-Computers_BHKW.jpg)](http://www.ala-magazin.de/ala-magazin/artikel/2021/jh-computers-gmbh.php about this event: https://pretalx.c3voc.de/camp2023/talk/KXXKKX/
Bootloader Crimes (camp2023)
Sometimes Windows can't be avoided, usually to run or dissect some weird piece of software. Fortunately, we have virtual machines for that, but installing or maintaining such an image is always a hassle. I built a web-tool based on open-source tools to make the experience of building such images much more enjoyable and discovered some interesting quirks and ways to run and install Windows. about this event: https://pretalx.c3voc.de/camp2023/talk/LLV8KV/
Unlock the Door to my Secrets, but don’t Forget to Glitch (camp2023)
Curious case of Indian metros (camp2023)
Curious case of Indian metros (camp2023)
Major states/cities in India have metro railway system for easy commute. The technology, _however_, has been exploited for a long period of time. I'll go through what's wrong with current system and how to make profit (free travel, I mean) out of it. The talk is majorly about NFC (majorly, MiFare DESFire EV1 cards & classic cards). Keep in mind that this is not a NFC 101. I barely understand NFC due to lack of documentation, I just know enough to make profit out of it. I'll go through the ideas that floated in my mind during this hacking journey and also all the issues that I fell into. about this event: https://pretalx.c3voc.de/camp2023/talk/VHABLM/
Unlock the Door to my Secrets, but don’t Forget to Glitch (camp2023)
Microcontrollers are used in numerous applications and even in security-relevant areas, for example in form of hardware security tokens or crypto wallets. Hence, the non-volatile flash memory of microcontrollers contains sensitive assets such as cryptographic secrets or intellectual property, that need to be protected from being read out by adversaries. In order to prevent illegal extraction through the integrated debug interface, dedicated protection features are in place. In this talk, we take a look at an attack vector that we call *flash erase suppression*. This attack vector leverages that many microcontrollers allow to deactivate their debug interface protection under the condition that the entire flash memory is erased first. The attack suppresses this mass erase with a glitch whereby its contents are preserved and accessible through the activated debug interface. This type of attack was first presented by Schink et al. at CHES 2021, but only received little attention so far. The talk provides an introduction to this attack vector and gives a foretaste of a comprehensive analysis that will be published soon. The attack will be demonstrated live on stage with an exemplary microcontroller. about this event: https://pretalx.c3voc.de/camp2023/talk/AS9MQY/
c3lingo (camp2023)
. Frag die Teams about this event: https://pretalx.c3voc.de/camp2023/talk/2381/
c3lingo (camp2023)
c3 MorningShow (camp2023)
. about this event: https://pretalx.c3voc.de/camp2023/talk/B7YFEV/
Hack My handicap (camp2023)
Our environment is full of technologies, connected objects and other gadgets that make our daily life much easier. It is indeed, quite easy to remotely command all kind of devices from our smartphones, with a single click. These technologies are also very efficient to help compensate certain handicaps but they have limits when it regards people whose handicap – or combination thereof - prevents them from manipulating a smartphone, reading a screen or using vocal commands. The good news is that it is not necessary to reinvent the wheel as alternative ways to interact with our technological environment, already exist. These solutions however, often stay inaccessible because their usage is judged too complex, their implementation considered time-consuming but mostly because of their (outrageous) price. As a patient, it can be very frustrating to be shut down from these possibilities to improve our quality of life and become more independent. That’s why I turned all my hopes to open-source hardware and tools, right after my I soldered my first TV-B-Gone, about 10 years ago :) I’ve been working on this “Impossible Interface” ever since. I can only describe it as a universal remote control that can also interact with non connected physical objects like the buttons of a lift or a simple light switch. The name Impossible Interface was chosen because of the amount of time I was told it was impossible to build such a device, especially for less than 500 euros but ... Bootchoo II, my latest prototype basically is a Arduino compatible 5 Axis Robot Arm (https://www.adeept.com/robotic-arm-uno_p0118.html) to which I just added a Bluetooth module and I am currently testing several ways of controls it. Ideally, commanding that little bot could be personalized depending on the type of handicap(s) that needs to be compensated. I am currently focusing on patients with low finger mobility, testing different sizes of joysticks as well as other “alternative remote” possibilities such as the ones offered by the MCH2022 badge and the Flipper Zero. As for the reason why I submitting this small talk – even though I am very shy – is because it is precisely not about me. Being as autonomous as possible is a need we all share and it should not be considered a luxury. I’ve mostly worked alone on this project but I got a lot of support from the Hacking Health Besançon association (https://hacking-health.org/fr/besancon-fr/), since I submitted this project during their latest edition. I’ll also admit that it is also time to ask for help to make this open-source assistive robot, safer, stronger and smarter and I can’t think of a better place to share my humble experiments, than at CCCamp. about this event: https://pretalx.c3voc.de/camp2023/talk/38XP9W/