
Chaos Computer Club - archive feed
21,021 episodes — Page 97 of 421
Service Location Protocol DoS Amplification Attack (camp2023)
We will talk about the lately published Denail of Service attack abusing the Service Location Protocol. The research has shown that there are still protocols lurking in the dark to be explored and ab/used. The focus will be on basics of DoS attacks, then focus on SLP, the impact, defense mechanisms as well as the global attack surface. Furthermore, there will be some goodies in regard of other use-cases. Overview 1. Introduction to DoS attacks 2. Introduction to SLP 3. How is the attack working 4. Observations in the wild 5. Fun with SLP 6. Questions? 7. Finish about this event: https://pretalx.c3voc.de/camp2023/talk/NWDFBT/
Bid3 and CounterMilitarisim Mapping (camp2023)
Sharing experiences of two technical and educational projects that aimed to provide support for the decentralized grass movement in Sudan. showcase of two technical-sociopolitical projects ## Bid3a: The project aims to make socio-political interventions and creatively express themselves through the courage and symbolism of manipulating and artistically hacking tech devices around. At the core of their approach lies the intersection between art, technology, and political thought. Its strives to create something new and innovative by extensively exploring ready-made devices, operating systems, microcontrollers, and circuits. The objective is to expand their imagination, seeking to discover novel ways of socio-political existence and actively participate in the global discourse on cutting-edge technology, driven by the spirit of the ongoing Sudanese revolution. ## Sudan Civic Map: Sudan civic map is Counter-Militarisation Mapping project is a political statement that challenges the dominant narrative of the Sudan conflict. By foregrounding the experiences of civilian-led movements, the project aims to shift the focus from military-centric news towards the humanitarian efforts of these actors and alternative revolutionary practices. Through mapping and visual representation, the project asserts the importance of non-combatant actors in the Sudan conflict, subverting the conventional portrayal of the conflict as a two-party war. about this event: https://pretalx.c3voc.de/camp2023/talk/WHVPD3/
Delta Chat messenger (camp2023)
Delta Chat messenger (camp2023)
[Delta Chat](https://delta.chat) is an e-mail based messenger that works on all platforms. Apart from an Whatsapp/Telegram-style user interface it features a security-audited [Rust-core library](https://github.com/deltachat/deltachat-core-rust), server [templates for setting up a state-of-the-art e-mail server](https://delta.chat/en/serverguide), many different bots, Matterbridge support and, last but not least, a way write standard web apps that can be shared in a chat (https://webxdc.org) which is now also experimentally supported by the XMPP Android messenger Cheogram. The talk will both discuss and demonstrate other unique features, among them QR-code based onboarding and support for protection against machine-in-the-middle attacks against end-to-end encryption, and we'll also provide glimpses in what's brewing for 2023/2024. about this event: https://pretalx.c3voc.de/camp2023/talk/UL7CQU/
PID Loops Control All the Things (camp2023)
How to succeed at capturing the flag (camp2023)
PID Loops Control All the Things (camp2023)
Hidden inside basically every physical machine that needs precise control, PID loops are running the show. Quadcopters, self-balancing robots, and even the hot end of your 3D printer all use the same simple routines. Knowing how they work, deep down, and how to set their mystical three parameters is part art and part science, but it's nothing you can't pick up in a quick talk. Nothing explains complex math better than a few hands-on demos, and we'll definitely be tempting the fates here. By the end, you should be confident enough to code up your own PID routines from scratch and get started tuning. about this event: https://pretalx.c3voc.de/camp2023/talk/3HXEEC/
How to succeed at capturing the flag (camp2023)
Do you struggle at Attack/Defense style capture the flag (CTF)? Have you ever wondered how top teams can automatically steal tons and tons of flags and defend against attacks? Have you ever wondered what goes into succeeding at Attack/Defense? If so, this talk is for you. In this talk, we will take you behind the curtain of the top CTF team of 2022, the [‘organizers’](https://ctftime.org/team/42934). We will show you how we play Attack/Defense, what tools we use, our cursed strategies, and we will share some cool stories from our experience in major events like DEF CON CTF. about this event: https://pretalx.c3voc.de/camp2023/talk/YVGMLE/
flow3r Badge (camp2023)
Die langjährigen CCC Badge Team Mitglieder schneider und Sec lassen sich von Andi auf der grauen Couch im C3VOC.tv Studio 1 ausfragen. about this event: https://pretalx.c3voc.de/camp2023/talk/1484/
flow3r Badge (camp2023)
c3 MorningShow (camp2023)
Wetter, Verkehr, etc. about this event: https://pretalx.c3voc.de/camp2023/talk/3HFNWT/
c3 MorningShow (camp2023)
DON’T PANIC (camp2023)
DON’T PANIC (camp2023)
Love it or hate it, blockchain has become a playground for technologists. Blockchain also fuels criminal ecosystems through major hacking incidents. In this talk, we aim to shed light on the most common bug types found in one of the main blockchain frameworks (Substrate) and provide insights and tools to find them. Blockchain bugs present unique challenges for developers and security testers. Drawing from several hundred blockchain security issues we reported, we identified five common issue types. We discuss the potential impact of each issue type and provide practical tips for testing blockchain systems. To promote accessibility to blockchain hacking, we release a fuzzer for Substrate-based chains. During the talk, we demo the fuzzer and showcase typical bugs, including arithmetic errors, reachable panics, and others. about this event: https://pretalx.c3voc.de/camp2023/talk/LMWGLZ/
Mastering the Maze (camp2023)
Mastering the Maze (camp2023)
## How can artificial intelligence support penetration testing? Most processes in for the penetration-testing cycle require detailed knowledge, time and human resources. While the are sophisticated scripts for the reconnaissance and various exploits, creating a detailed plan of the attack path can be complicated and laborious. The use of an enforcement learning algorithm can help penetration-testing identify the various attack vectors and provide a detailed overview of the system landscape. This can automate important aspects of the process and make it more efficient. We like show an overview, on how reinforcement learning can be integrated into the penetration testing process to gain automated access to a system landscape. To achieve this, we show approaches how an AI can be used for lateral movement within the system landscape to subject an entire landscape to the penetration-testing process. We like show an overview, on how reinforcement learning can be integrated into the penetration testing process to gain automated access to a system landscape. about this event: https://pretalx.c3voc.de/camp2023/talk/XBQFGK/
Defeating planned obsolescence for Cisco Meraki switches (camp2023)
Cisco Meraki Ethernet switches are cloud-managed and require a license to function, or do they? In this talk I will discuss developing a FOSS firmware for various Meraki switch models and the challenges faced. This talk will include a hardware overview of various Cisco Meraki Ethernet switch models (past and present). We will look into the Cisco Meraki stock firmware, boot process, and switch management software. Finally, we will discuss the current state of support and what the future holds for open-source firmware on Cisco Meraki network devices. about this event: https://pretalx.c3voc.de/camp2023/talk/Z87KAX/
Defeating planned obsolescence for Cisco Meraki switches (camp2023)
Peeking over the tape moat (camp2023)
Peeking over the tape moat (camp2023)
As the threat of ransomware continues to grow, many organizations look towards magnetic tape storage solutions to provide a last line of defense for their data. Tape has a number of interesting properties which set it apart from flash and spinning disk technology, such as an air-gap between the storage media and the reading/writing device, immutability of written data, and a long shelf life. These make it an attractive option for keeping data safe over longer periods of time. Doomsayers have long foretold the death of tape, yet there has never been more data stored on it than today. Tape system users include major financial institutions, government archives, and hyperscaler cloud providers, just to name a few. This presentation will give an introduction to data storage on tape media, potential attack vectors, and mitigations for these. This presentation will have two parts: A brief introduction to how magnetic tape works and is used in a data center, followed by security aspects from an operator's point of view. This presentation is of course just my thoughts on tape and in no way shape or form organized by, approved by, or representing the views of CERN the organization. about this event: https://pretalx.c3voc.de/camp2023/talk/CSYA7B/
Physical Vulnerability Research (camp2023)
Exploring the methodology and exploitation of physical security systems. Locks, access control and alarm systems with real life examples and the practical exploitation thereof. With digital security crossover. about this event: https://pretalx.c3voc.de/camp2023/talk/ADJX98/
Physical Vulnerability Research (camp2023)
DearMEP (camp2023)
How to hack the European Parliament by giving voters a voice in the decisions on the floor. Contacting your representative in Parliament is not as easy as it should be. What are their email addresses, phone numbers, social network profiles? Are they in Brussels or in Strasbourg right now? How much will it cost to call someone in France anyway? What should you even say to them? And does it even make sense to talk to that particular person, or are they so fundamentally opposed to your request that it would be a waste of time? The tool we are developing aims to bring citizens closer to their elected representatives. It empowers users to contact Members of the European Parliament (MEPs) efficiently and with a low entry barrier. The software takes the burden away from users to understand the EU and which MEPs are best to contact on a particular issue. It also knows how to contact them, and even allows the user to call them free of charge. DearMEP is being developed as a white label solution that can be applied to any EU level decision that has to be voted upon in the plenary of the European Parliament. NGOs that campaign around an EU decision can use the software to mobilize the public efficiently with the goal to influence particular plenary votes. Currently, the DearMEP software is tailored to address the whole European Parliament and to be used by citizens from all EU countries to contact MEPs from their countries. In this presentation, we would like to show you the current development state of this tool. We are planning to use DearMEP in the ongoing campaign against the chat control proposal. After that legislative file has concluded, we will release the software under the AGPL free software licence. During the CCCamp we will provide access to the current beta. We would love to hear your feedback. Drop us an email at [email protected]. about this event: https://pretalx.c3voc.de/camp2023/talk/7VSZTC/
DearMEP (camp2023)
Horror Stories from the Automotive Industry (camp2023)
Horror Stories from the Automotive Industry (camp2023)
In this talk, we will revisit some of the scariest stories we faced during more than 50 penetration testing and security research projects, with a twist. In the ever-emerging industry of automotive, with old and new OEMs trying to get a share of the pie, many things are at stake, with many things getting overlooked, forgotten, or even deliberately covered. We will go through a journey of critical findings in different targets and the constant battle between penetration testers, developers, and mid to upper management. This will help the audience get an understanding of how the industry behaves right now, what they (and what we) are doing wrong, and how the future of automotive security should be shaped, not only for the sake of security, but also for the sake of safety and reliability. This talk will try to raise awareness on the current state of automotive security, how does the industry behave in the whole spectrum of it (100-year-old OEMs to 2-year-old OEMs and Tier 1 suppliers) and ultimately try to propose a way forward for both the automotive and security industries, with the goal being a safer and more reliable future for everyone, in and out of the streets. Working with some of the biggest OEMs and Tier 1 suppliers on pre-production vehicles gave us an understanding and experience of the whole spectrum of developing a vehicle, from architectural design to homologation and sales. This led us in many realizations and pitfals that the automotive industry falls into, and in order to avoid another Miller/Valasek we have to educate the people of the industry. While most of the people/companies in this industry try to keep the gates closed for apparent reasons, we try to share as much as possible, with the hope of making a change to the industry that will have an impact on how and where it progresses in the future. about this event: https://pretalx.c3voc.de/camp2023/talk/UEHEVD/
Sex Workers Versus Surveillance (camp2023)
Sex Workers Versus Surveillance (camp2023)
Sex workers have always been at the vanguard of technology—in ways that protect and restrict their rights. Laws and policies that impact sex workers never stop at this population so it is imperative that these case studies reach general audiences concerned with human rights as a whole. This talk will include a history of surveillance mechanisms directed against sex workers and will focus on the ways and means that digital surveillance has been impacting sex worker rights of mobility and free expression in recent years. New laws enforcing the censorship of pornography and the collateral damages they levy on reproductive health and LGBTQ+ community building will be discussed as well as border crossing and payment processing. Information about how AI and facial recognition software target sex workers will be detailed as well as the tools, advocacy, social engineering strategies sex workers can use to fight back. This talk is not limited to sex workers and their allies. It will include a primer on why sex worker rights include all human rights and show evidence that these laws are not limited to sex workers at all. LGBTQI+ people and reproductive health activists will be immediately impacted as well as all people who believe in the freedom of information. about this event: https://pretalx.c3voc.de/camp2023/talk/8HF9X9/
Chiptune with GameBoys and Nanoloop2 (camp2023)
Chiptune , 16 step looper, live performed on a NDSLite I make chiptune using Game Boys with the software called Nanoloop2. I will play for 1 hour. You might have heard my loops at Congress, GPN, SHA, CPU and MRMCD. I wrote a few new ones that I presented at GPN21 which can be heard here: https://www.youtube.com/watch?v=-VNmZGe2SN0 For other sound samples please visit my profile https://chaos.social/@bobo_pk or have a look at https://peertube.1312.media/w/cu1fPFfy49kgFhzs8NrgJp UPDATE: btr and nr4 will perform live visuals. I gave this workshop and am planning on doing it again on camp as SOS if you are interested. https://cfp.gulas.ch/gpn21/talk/L8CRA8/ about this event: https://pretalx.c3voc.de/camp2023/talk/MEMSEH/
Chiptune with GameBoys and Nanoloop2 (camp2023)
TrustMeRelay? Investigating Apple's iCloud Private Relay (camp2023)
TrustMeRelay? Investigating Apple's iCloud Private Relay (camp2023)
Apple strongly emphasizes the security and privacy of its devices and services. I analyze the dual-hop architecture, deployed protocols, and inner workings of their privacy-centric, VPN/Tor-alike service iCloud Private Relay. I will talk about my reverse engineering process and falsify Apple's privacy by design and access control claims. Apple's iCloud Private Relay is a novel Internet privacy service allowing users to securely and privately browse the Internet. It is directly implemented into Apple's operating systems and included with all iCloud+ subscriptions. Compared to traditional VPN services, Private Relay's dual-hop architecture separates the knowledge of the user's IP address and their destination website between two different Relays. Apple operates the first Relay while the second one is by one of its four partners: Akamai, CloudFlare, or Fastly. Apple claims its architecture enforces enhanced protection of users' privacy ("privacy by design") while still providing a high-performance browsing experience. Their president of software engineering, Craig Federighi, even mentions that Apple does not want users to have trust in them. Further, the company claims its service incorporates anti-abuse and fraud prevention mechanisms. As Private Relay validates any connection at the account and device level, website operators can trust them. I reverse engineer Private Relay's macOS implementation, present its involved technical components and how they collaborate. With that gained knowledge, I analyze authentication and authorization mechanisms deployed by Private Relay regarding potential ways of abuse. Furthermore, I review the privacy claims regarding the architecture and its deployment. about this event: https://pretalx.c3voc.de/camp2023/talk/7RDPNH/
Fantastic build system failure modes and how to fix them (camp2023)
Fantastic build system failure modes and how to fix them (camp2023)
Rebuilding target files when source files have changed is seems easy, but is not. Commonly used build systems (make, ninja, etc.) are often unable to guarantee both that they rebuild only what needs to be rebuilt and that they do not rebuild what does not need to be rebuilt. I will show how to reliably encounter common build system failure modes and explain which architectural choices lead to those. Using DJB's “redo” design as an example, I will show how build system architecture determines if failure modes can be addressed at all. Lastly, I will speculate why many developers dismiss such issues before encountering them – and some even do afterwards. ”Listen Morty, I hate to break it to you, but what people call a build system is just a bunch of rules that compel computers to output garbage. It hits hard, Morty, then it slowly fades, leaving you stranded with a mis-compiled binary. I did it. Your friends are gonna do it. Break the cycle, Morty. Rise above. Focus on build correctness.” about this event: https://pretalx.c3voc.de/camp2023/talk/CFASNP/
Logbuch:Netzpolitik 466 (camp2023)
Logbuch:Netzpolitik 466 (camp2023)
Logbuch:Netzpolitik (LNP) ist der Versuch, das netzpolitische Geschehen im deutschsprachigen Raum weitgehend neutral, unaufgeregt und meist gut gelaunt in einem regelmässigen Podcast einzufangen. Der Podcast soll Einblicke in die Themen aber auch Verständnis für die Hintergründe bieten. Aufzeichnung einer Live-Sendung auf dem Chaos Communication Camp 2023 in Mildenberg. Vor zahlreichen Gästen haben wir mit Julian Hessenthaler gesprochen, dem Initiator des Ibiza-Videos, das die Korruption der FPÖ-Eliten im allgemeinen und Heinz-Christian Strache im besonderen plastisch demonstriert hat und letztlich zum Scheitern der damaligen ÖVP-FPÖ-Koalition geführt hat. Wir sprechen mit Julian über seine Motivation, seine Erlebnisse, seine Erfahrungen, die Verfolgung, Anklage und Haft, die er letztlich erleiden musste und das System Österreich. about this event: https://logbuch-netzpolitik.de/lnp466-wodka-red-bull
Gespräch (camp2023)
Hackerspaces – Fireside Chat (camp2023)
Fireside Talk about the birth, life, death and rebirth of Hackerspaces about this event: https://pretalx.c3voc.de/camp2023/talk/8544/
A spontaneous introduction to the demoscene (camp2023)
Gespräch (camp2023)
Warum brauchen wir digitales (Bar-)geld? Welche Eigenschaften müsste eine gute digitale Währung haben? Wie könnte sich unser Alltag dadurch verändern? Und wie funktioniert das in der Praxis? Christian Grothoff (GNU Taler), Leena Simon (Digitalcourage) und padeluun (Digitalcourage) diskutieren, Publikumsbeteiligung erwünscht. Die etablierten bisherigen digitale Bezahlmethoden sind alles andere als anonym. Neben den klassischen nicht anonymen Bezahlmethoden durch Überweisung und Kreditkarte (die zunehmend nur noch über den Umweg großer Finanzdienstleister angeboten werden), gibt es privatwirtschaftliche Finanzdienstleister wie Paypal, Amazon Pay und Klarna, die jede Menge Daten sammeln und mit ihrer Marktmacht immer unausweichlicher werden. Darüber hinaus gibt es verschiedene Crypto-Währungen wie den Bitcoin, die aber auch nicht wirklich anonym sind. padeluun und Leena Simon erklären, wie sie sich digitales Bargeld vorstellen. Christian Grothoff ist einer der Erfinder des [GNU Taler](https://taler.net/de/index.html) und berichtet, welches Konzept hinter dem Freie Software-Bezahlsystem steckt und welche praktischen Feldversuche es damit bisher schon gab. about this event: https://pretalx.c3voc.de/camp2023/talk/CVYSWW/
A spontaneous introduction to the demoscene (camp2023)
Because a scheduled speaker didn't appear, BoboPK steps in and gives a short introduction und wrap up of the demoscene. The scene started with the home computer revolution of the early 1980s, and the subsequent advent of software cracking. Crackers altered the code of computer games to remove copy protection, claiming credit by adding introduction screens of their own ("cracktros"). They soon started competing for the best visual presentation of these additions. Through the making of intros and stand-alone demos, a new community eventually evolved, independent of the gaming: and software sharing scenes. about this event: https://pretalx.c3voc.de/camp2023/talk/ZHFJ7Q/
Hackerspaces – Fireside Chat (camp2023)
Haecksen (camp2023)
. Chaos Family about this event: https://pretalx.c3voc.de/camp2023/talk/1852/
Haecksen (camp2023)
c3 NewsShow + Brennpunkt "Flaschen" (camp2023)
Die Themen von Tag 3 about this event: https://pretalx.c3voc.de/camp2023/talk/W7LLWD/
A Guided Tour through Tor Network Health and Performance (camp2023)
c3 NewsShow + Brennpunkt "Flaschen" (camp2023)
A Guided Tour through Tor Network Health and Performance (camp2023)
Since the last time, we were all at camp, several significant changes have happened within the Tor network ecosystem, both technically and socially. In this presentation, we will review some exciting recent updates to the Tor network and look into the world of bad relay tracking, general network health observations, and the situation where multiple extensive Denial of Service attacks have caused a slowdown of the overall network performance. We wish to guide the audience through a number of new technologies that have been added to the network. These innovations include a modern congestion control mechanism, our multi-path circuit feature, Conflux, and a Proof-of-Work (PoW) mechanism to help against Onion Services attacks. Additionally, we will discuss some upcoming changes to the current C Tor code base and our journey towards a Rust Tor relay implementation as part of our Arti re-implementation of Tor. Finally, in addition to the technology modifications, we also would like to talk about some of the social developments happening with the network, amongst others, a new mechanism for handling incoming technical and social proposals from the greater Tor community. about this event: https://pretalx.c3voc.de/camp2023/talk/SMB8SM/
AMA mit Digitalpolitikerin Anke Domscheit-Berg (@anked), MdB, Die LINKE (camp2023)
AMA mit Digitalpolitikerin Anke Domscheit-Berg (@anked), MdB, Die LINKE (camp2023)
Aus dem Leben und der Arbeit einer Bundestagsabgeordneten Nach kurzer Vorstellung und Intro könnt Ihr mich alles fragen. Als digitalpolitische Sprecherin der Linksfraktion im Bundestag beantworte ich gern Eure Fragen zum Geschehen im Bundestag, zu digitalpolitischen Themen oder zu allem, was Ihr mich schon immer mal fragen wolltet. about this event: https://fahrplan.alpaka.space/camp-2023/talk/SDESSA/