Chaos Computer Club - archive feed

Chaos Computer Club - archive feed

By CCC media teamTechnology
Download on the App Store

Chaos Computer Club - archive feed episodes

  • Wie man den Zustand „Gescheitert am ERP-System“ vermeidet (froscon2022)
    Erläutert werden Fallbeispiele aus Sicht des Produkt-Managers und Entwicklers, der die Entscheidung zwischen Integration in den Standard oder kundenspezifisches Customizing trifft.
    „Gescheitert am ERP-System“ titelt die Computerwoche und meint damit unter anderem die fehlgeschlagene Einführung von SAP bei Lidl.
    An dritter Stelle der Ursachenforschung wird unverhältnismäßiges Customizing genannt.
    Die Abwägung im Standard zu bleiben oder auf die Benutzer-Wünsche einzugehen fällt oft nicht leicht.
    Allerdings ist es mit git und dessen Rebase-Funktionalität möglich die Grenze etwas weiter in Richtung wartungsfähiges Customizing zu verschieben und somit die individuelle Benutzerakzeptanz zu erhöhen.
    Ferner helfen individuelle kundenspezifische Software-Tests bei der langfristigen Integrations-Arbeit.
    about this event: https://programm.froscon.org/2022/events/2767.html
    47 min
  • This is the way - Holistic (Network) Automation (froscon2022)
    The Systems Engineering / SRE world has undergone a shift of thinking towards intend driven holistic configuration management a long time ago, but it feels like the majority of network automation solutions are still following the idea of making incremental changes to the routers and switches out there, which at the same time might also be managed manually by operators typing (or copying) magic spells into a CLI. This makes the device configuration the synchronization point and we don’t really have an idea of what this configuration will look like in full without checking back on the device.
    I believe we as Network (Automation) Engineers need to follow suit, make the mental shift to the holistic approach, let Perl, Shell and expect scripts be, and bring software engineering methods to network automation. This way we are able to tackle the problems at hand at an abstract level, build solutions which can be reasoned with, tested on their own, and scale to our needs. For the most daunting problem of configuration management this means plugging some of those systems together and building a solution which generates and owns the full device configuration.
    Dealing with diverging configuration parts, across the fleet, carefully cleaning up old approaches to configure X, doing incremental changes, and figuring out how to interact with a platform API, a dialect of NETCONF, YANG, etc. would all be from the past –-- wouldn’t that be great?
    about this event: https://programm.froscon.org/2022/events/2820.html
    37 min
  • sectpmctl für LUKS Full Disk Encryption (FDE) (froscon2022)
    Die meisten Linux-Distributionen verwenden für die Festplattenverschlüsselung ein Passwort. sectpmctl benutzt das TPM 2.0 Modul zusammen mit Secure Boot für die Verschlüsselung. Wahlweise kann zusätzlich eine Boot-PIN verwendet werden, die hardwareseitig vor Brute-Force Angriffen geschützt ist. Veränderungen der Secure Boot Schlüssel und der Boot-Dateien durch Viren oder Angreifer werden erkannt und der Bootvorgang verhindert. Im Falle eines Diebstahls sind alle Daten des Geräts geschützt.
    Dieses Tool ist eine komplett integrierte und einfache Lösung. Die typischen Probleme, die mit dem TPM entstehen (PCR Brittleness z. B.) werden umgangen durch die Verwaltung und Nutzung von Secure Boot und dem Provisionieren des TPM's nach dem TOFU Prinzip (Trust on first use). Die Nutzung des TPM's ist immun vor Änderungen durch System Upgrades, die Entschlüsselung wird nicht an den Userspace gebunden, sondern an den Hardware-Zustand. Zum Booten wird systemd-stub and systemd-boot verwendet.
    about this event: https://programm.froscon.org/2022/events/2766.html
    1 hr 4 min
  • Wer bin ich und wenn ja wie viele? (froscon2022)
    Die Bestrebungen "Identität" von Menschen digital zu greifen und Kontext-übergreifend zu nutzen, werden immer konkreter. Was aber ist "Identität" eigentlich für uns Menschen. Und wie können wir aus "Identität" irgendwelches Vertrauen ableiten? In wie weit machen hier zentrale Ansätze bzw. Kontext übergreifende Ansätze Sinn? Und für wen? Gibt es alternative Ansätze?
    Menschen haben im täglichen Umgang miteinander ganz andere Vorstellungen von ihrere Identität oder der anderer Menschen, als was häufig versucht wird digital abzubilden. Von vielen Menschen, mit denen wir interagieren kennen wir nicht einmal den Namen und häufig genug interessiert er uns auch nicht wirklich. Selbst von Stammkunden weiß z.B. der Bäcker häufig nicht den Namen, wo sie sonst noch einkaufen, wo sie wohnen oder wie alt sie genau sind.
    Und wir können uns z.B. auf einer Veranstaltung stundenlang mit jemandem unterhalten, ohne den Namen zu kennen. Um andere Menschen einzuordnen sind uns andere Dinge wichtiger, wie gemeinsame Bekannte, Hobbys, Beruf. All dies sind für uns viel wichtigere "Filter", als die "Eigenschaften" die sich typischerweise in staatlichen Identitätsansätzen niederschlagen.
    Auf der anderen Seite gibt es die sozialen Medien. Diese können viele verschiedene Verbindungen zwischen Menschen und ihren Aktivitäten herstellen und uns ziemlich gut abbilden. Aber dafür gibt es hier andere Probleme.
    Menschen "sind" je nach Kontext unterschiedliche "Personen". Wir zeigen uns auf der Arbeit typischerweise anders, als gegenüber der Familie, beim Sport oder auf einer Party. Umgekehrt interessieren wir uns je nach Kontext auch für andere Eigenschaften des jeweiligen Gegenübers.
    In wie weit macht es hier überhaupt Sinn die verschiedenen "Persona" zu verknüpfen? Wir nutzen für verschiedene Kontexte ja auch bewusst unterschiedliche Tools, Emails, Gruppen, Accounts und teilweise sogar Geräte.
    Eine "Identität" bildet uns nicht wirklich gut ab. Wir trennen bewusst auch die eigenen Informationen über uns und andere aus den verschiedenen Kontexten voneinander ab.
    Eine einzelne, allwissende, allmächtige "Identität" benötigen wir nicht und ist im Zweifel sogar schädlich.
    Wie kann man es anders machen? Es einige alternative Ansätze. Und auch solche, die dezentral sind, ohne der Akkumulation der Informationen, wo man sonst noch so aktiv ist bei einem zentralen Anbieter auskommen, generell nur die Informationen herausgeben, die für den jeweiligen Kontext relevant sind und unsere zwischenmenschlichen Vernetzungen mit berücksichtigen können. Ein Ansatz von CAcert verwendet Client-Zertifikate basierend auf einem WebOfTrust und openId Connect.
    Dies ist aber nur ein Beispiel. Wichtiger ist, dass wir als Open Source Community uns den Weg zu "menschlicheren" Ansätzen nicht verbauen und uns nicht nur singulär auf die Big Player verlassen.
    about this event: https://programm.froscon.org/2022/events/2801.html
    1 hr 1 min
  • Gamification und Crowdsourcing (froscon2022)
    Zu einem Projekt beitragen, aber wie und warum? Spielerisch geht das mit Gamification. Besonders Crowdsourcing-Projekte können von Gamification profitieren und es Einsteiger*innen leicht machen.
    In diesem Vortrag erzählen wir, wie man zum Beispiel zu OpenStreetMap spielerisch beitragen kann und was überhaupt Gamification und Crowdsourcing ist. Wir zeigen verschiedene Beispiele aus dem Open- und Closed-Source-Bereich.
    Anhand von OpenStreetMap schauen wir uns Ansätze an, wie aus spielerischen Beiträgen Daten werden und wie später aus diesen Daten sogar wieder neue Spiele werden.
    Zuletzt überlegen wir, welche Probleme es mit dem Gamification-Konzept gibt, was Datenschutz und Lizenzen damit zu tun haben und ob daraus wirklich wertvolle Beiträge zu Open-Source-Projekten werden können.
    about this event: https://programm.froscon.org/2022/events/2800.html
    43 min
  • Wikimedia Italia - What is it doing for the Italian OSM community? (sotm2022)
    Wikimedia Italia, the Italian OpenStreetMap Local Chapter of the OSM Foundation, presents its activities, online infrastructure developed to support OpenStreetMap in Italy and the Italian community. The talk will share the experience, situations and factors that have influenced agreat collaboration with the local contributors and institutions during the last years.
    The presentation will go through different areas of the Local Chapter’s activities. The recently updated infrastructure, composed by the Tasking Manager and the OSM extracts for Italy. Those tools are available and used by the Italian OSM community. Moreover, the official new Italian OSM website, the OSM licences tracking process and other tools developed to support the community will be presented.
    Other experiences that will be shared are the collaborations with local institutions, with the scope of strengthening local communities and increase the data in OSM. The keys to success are the volunteer coordinators. They are a point of contact important to establishing collaborations with individuals and institutions throughout the national territory
    about this event: https://2022.stateofthemap.org/sessions/MRK3C8/
    26 min
  • Mapping crises, communities and capitalism on OpenStreetMap: situating humanitarian mapping in the (open source) mapping supply chain (sotm2022)
    This proposal expands an understanding of humanitarian mapping from an ethnographic perspective, seeking to understand the complex mechanics behind this confluence of humanitarianism, technology, and crowdsourced labor. It seeks to scaffold a notion of the “open source mapping supply chain”, situating both humanitarian mapping and OpenStreetMap itself within a larger ecosystem of commercial, humanitarian, open source, government, and other actors in developing geospatial-related technologies.
    This presentation presents a selection of a MA dissertation project, pursued over the course of more than 1.5 years of immersive fieldwork on OpenStreetMap. This presentation will focus on humanitarian mapping through qualitative study, seeking to expand an understanding of humanitarian mapping (particularly that which has emerged from mappers associated with the Humanitarian OpenStreetMap Team - also known as HOT) through the use of ethnographic tools, seeking to understand the complex mechanics behind this confluence of humanitarianism, technology, and crowdsourced labor, asking how and why people contribute to open-source platforms like OSM, and what role humanitarian mapping plays within the wider ecosystem of geospatial and mapping technologies. Ultimately however, it seeks to scaffold a notion of the “open source mapping supply chain”, situating both humanitarian mapping and OpenStreetMap itself within a larger ecosystem of commercial, humanitarian, open source, government, and other actors in developing geospatial-related technologies.
    Founded in the aftermath of the 2010 earthquake in Haiti, the Humanitarian OpenStreetMap Team (HOT) helps both globally remote and local in-person volunteers to identify roads, buildings, and other features on the OpenStreetMap (OSM) platform. Created as a “free, editable map of the world,” OSM has enabled the mass-creation of volunteered geographical information (VGI) on a scale that is now more accurate than proprietary maps in many places, particularly as “crisis-mapping” has emerged as a means to gather real-time data on areas that have been affected by natural disasters or socio-political conflicts. OSM has also become also a site of resistance, where local and indigenous communities have engaged in mapping projects to reclaim autonomy, agency, and space through the historically contested practice of (digital) mapping. For these reasons, such crowdsourced maps have increasingly been used by humanitarian organisations to facilitate aid and disaster relief, and as open training data for algorithms learning how to automatically detect features through Artificial Intelligence (AI). As a key partner of humanitarian, corporate, and local actors, and having mobilised over 200,000 volunteers since 2010, HOT lies at the crux of these ongoing entanglements and contestations, both within and around the field of OSM.
    Previous studies of crowdsourced geographical information and crisis-mapping have generally revolved around quantitative analyses of OSM’s data, focusing on the credibility of the data itself, the makeup of the communities that contribute to it, the effects of “event-centric” crowdsourcing, or “newcomer retention” in humanitarian mapping (Dittus et al., 2016a, 2016b, 2017; Haklay, 2010; Haworth et al., 2018; Sui et al., 2013). Alternatively, they have also focused on the “spatial knowledge”, “hacker political imaginary”, and gender composition of mappers themselves (Brandusescu & Sieber, 2018; McConchie, 2015; Stephens, 2013).
    Parallel studies of other volunteer-driven communities like “Wikipedians” have taken similar approaches, analysing “user-generated content” and the motivations behind them (Nov, 2007; Yang & Lai, 2010). Both hacking and free and open source software (F/OSS) have also been explored ethnographically (Coleman, 2012; Kelty, 2008). While automated detection of features on OpenStreetMap has only recently become an important topic of research, ongoing studies have primarily focused on the accuracy or credibility of this endeavour (Brovelli et al., 2017; Resor, 2016).
    While existing studies of digital communities have focused on the socialities they engender or labor they require, they tend to forget the bureaucratic apparatuses that have emerged to govern them, both implicitly and explicitly (Coleman, 2012; Kelty, 2008). Similarly, studies of humanitarianism have focused on the ethics they operationalize, or the technologies that are mobilized in turn, but often at the expense of engaging in the wider spectrum of social and economic life that they enable (Cross, 2013; Redfield, 2012, 2016a; Scott-Smith, 2013, 2016a, 2019; Ticktin, 2014a). While this project draws upon these overlapping strains of research, it seeks to push the debate in an ethnographic direction, scaffolded by theories of bureaucratic technology, political economy, and humanitarianism.
    This research draws from participation in over 40 online events over 1.5 years, including mapathons, conferences and online lectures with OSM mappers, as well as semi-structured interviews conducted with 27 key-informants, alongside watching more conference videos, and reading blogs, mailing list emails, Twitter exchanges, and other internet archives. While empirically influenced by studies of hacking and open source software, this work ultimately focuses on the mechanisms and means through which this “free and open map” is created, and ultimately the ways of seeing and doing that it enables (Coleman, 2012; Kelty, 2008). Ultimately, it was the “supply chains” heuristic that emerged as a means to understand and illustrate this process.
    Similar to how supply chains “link ostensibly independent entrepreneurs, making it possible for commodity processes to span the globe”, the OSM project relies upon a series interconnected processes that enable the creation of the world’s crowdsourced map in a process that is far more precarious, and much less secure than promotional material might have one think (Tsing, 2009). Similar to how the satellite, computer, and software industries converged to create the conditions that allowed for OSM’s creation, so do people – and their associated institutions create map data through an almost miraculous collision of circumstances, assured precedent, and training. The Humanitarian OpenStreetMap Team, which was the initial entry point into open source mapping through, made its name by optimizing the mapping value chain: that is, by making it easier to contribute to OSM. But it also extended outwards: contributing to OSM was enabled not only by the wider socio-economic forces that coalesced to produce the project in the first place, but also by a series of digital value chains – both past and present.
    By delineating this supply-chains approach, this study hopes to scaffold a mental model of humanitarian mapping and the OpenStreetMap more broadly, to be employed in future studies – both quantitative and qualitative. Practically, it hopes to provide a heuristic and application of ethnographic tools, and present questions and queries directly to the community more broadly.
    about this event: https://2022.stateofthemap.org/sessions/NWB9QF/
    28 min
  • Automatisierung im Cyberspace (froscon2022)
    Die Zeiten des einsamen weißen Hackers im Keller seiner Eltern sind lange vorbei. Moderne Cyber-Angriffe werden von Staaten oder organisierten kriminellen Gruppen durchgeführt. Um gegen die schiere Anzahl solcher Angriff und Akteure an zu kommen ist viel Kreativität und Durchhaltevermögen gefragt.
    Man spricht klassischerweise davon, dass es eine Asymmetrie zwischen Hackern und Defendern gibt: die erste Gruppe ist Pro-Aktiv, braucht nur einmal erfolgreich sein, und muss die Malware lediglich schreiben. Defender auf der anderen Seite können immer nur reagieren, müssen immer erfolgreich sein, und das manuelle Analysieren von Malware ist sehr zeitaufwändig.
    In diesem Talk werden wir exemplarisch einige Vorfälle durchgehen und einen Vorschlag umreißen, welche Asymmetrien in die entgegengesetzte Richtung bestehen.
    about this event: https://programm.froscon.org/2022/events/2778.html
    52 min
  • The 'SUASecLab' Virtual Laboratory (froscon2022)
    Because of access restrictions imposed during the Covid-19 pandemic, access to the physical laboratories of our university was no longer possible for students.
    Lectures requiring specific hardware which is only available to students in laboratories could no longer take place.
    Therefore, we developed a solution which allows remote access to hardware of our laboratory.
    The FLOSS application WorkAdventure is used as base for our platform.
    WorkAdventure (WA) already makes privacy friendly online meetings possible in a 16-bit 2D computer game design.
    We extended WA to provide interactive, virtual lecture rooms by integrating BigBlueButton (BBB).
    However, privately communicating with fellow students sitting nearby is still possible.
    This creates a more realistic feeling when attending online lectures.
    As far as this solution is well known, but we wanted considerably more...
    In order to give lecturers and students different rights in BBB, we reimplemented parts of the proprietary administration services of WA.
    With them, we can give out different invitation links, so they also act as access control method.
    Furthermore, we embed noVNC, a web application acting as VNC client, into WA.
    With noVNC, it is possible to access virtual machines (VM) we set up on the computers residing in our physical laboratory from home.
    Here, we also developed a software which makes it possible to work in groups on the VMs remotely.
    This software puts all users connected to a VM into a Jitsi conference room, which allows the users to communicate.
    By using USB pass-through, it is possible to connect the physical hardware to the VMs.
    Then, by accessing the VMs, students can control the hardware remotely.
    Therefore, we were able to offer the lectures and exercises requiring special hardware by offering them in our virtual laboratory.
    Our software solution has a high transferability: New use-cases can be addressed quickly, as web applications can be integrated into WA easily.
    On the other side, parts of our solution can be used independently in own instances targeting other use cases.
    We invite developers to participate in the project and further develop the solution for possible use in high schools.
    Problem Description:
    Working in physical laboratories during the Covid-19 pandemic was no longer possible due to imposed access restrictions.
    This makes lectures with special hardware requirements impossible, as students can no longer access the laboratory.
    Furthermore, we have not enough devices to hand out to students.
    Therefore, it was necessary to find a solution that allows us to use hardware located in a laboratory in groups online.
    In our use case, students should be able to program Internet of Things (IoT) microcontrollers remotely.
    Furthermore, many online lectures were not as interactive as we hoped.
    While students can ask questions in popular online lecturing tools like BigBlueButton (BBB), it is not possible to quickly switch between working in groups and lecturing.
    Moreover, switching between multiple groups is not straightforward.
    Also discussing the lecture's topics with seat neighbors is no longer possible when using only BBB.
    Therefore, we looked for a solution, which creates a more lecture-like feeling.
    Furthermore, students should be able to work within groups and switch between them easily.
    Especially commercial products often harvest user data and use it for analyses.
    Some companies even sell collected data to advertisement companies.
    However, the personal information of students should be well protected.
    Therefore, our solution should also be privacy-friendly.
    In the optimal case, the used software follows privacy-by-design principles.
    This means it only collects information which is necessary for operating the service.
    Approach:
    During our research in order to find a solution, we could not find a FLOSS application which offers all the features we required.
    Therefore, we decided to build our own platform.
    We chose to use the FLOSS software WorkAdventure (WA), developed by TheCodingMachine, as underlying platform.
    WA is a web application which enables interactive online conferences and has a 16-bit 2D computer game design.
    WA follows the privacy-by-design principles, as almost all information exchanged with the clients is only stored temporary and removed from the backend after the user closes the tab.
    Furthermore, decentralized communication channels based on WebRTC technologies are used whenever possible.
    In WA, people walk a character over a map.
    Whenever multiple people stand nearby, a communication channel is established between their clients and they can communicate.
    The communication channel is closed when walking away from the group.
    However, this way of communication only works for smaller groups.
    When entering specific, pre-defined areas of the map, corresponding actions can be run in the users' browsers.
    By default, WA uses this feature to allow embedding Jitsi conference rooms in order to make bigger conferences possible.
    Furthermore, WA allows embedding websites by using the HTML iframe tag.
    Based on these features, we decided to build our own maps and set up our own, customized, WA instance.
    This instance extends the already mentioned capabilities by those we require.
    In order to make online lectures possible, we embedded BigBlueButton, which was already used at our university as lecturing tool.
    For this, we extended the frontend and the backend of WA to make an automated assignment of instructor and participant roles possible.
    Then, instructors are allowed to upload presentations, while participants are not.
    Furthermore, we reimplemented parts of the proprietary administration services in order to create different invitation links for assigning the different roles.
    By using this way, either the instructor or participant role is assigned in BBB based on the link that was used to join the laboratory.
    Moreover, handing out unique invitation links provides access control for the virtual laboratory.
    We can then define parts of the map as BBB rooms.
    We use this for setting up lecture halls.
    By enabling the group communication features mentioned above, it is possible to talk to fellow students sitting nearby while attending the lecture.
    This creates a more realistic feeling when attending online lectures.
    For making it possible to program IoT devices remotely, we set up virtual machines (VM) on different servers.
    We can then connect the physical devices to the VMs by attaching them to the hypervisors and enabling USB passthrough.
    The hypervisor provides remote access to the VMs by providing a VNC server.
    In order to make access to the VMs from WA possible, we integrated noVNC, a web application acting as VNC client, into WA.
    Here, we use websockify to translate the data transmitted through the VNC server port to a websocket, which can then be accessed by noVNC.
    Then, it is possible to remotely control the VM and work with the attached USB devices.
    Furthermore, we extended WA to automatically authenticate WA users on the VMs in order to provide access control for the VMs.
    For making it possible to work in groups, we developed the multi-user-vm-assigner.
    It allows multiple people working on a VM to communicate by putting all people connected to a specific VM into a Jitsi Meet room.
    For programming lectures, we also set up a general-purpose virtual PC pool.
    Here, students can try out different programming languages and get familiar with the GNU/Linux ecosystem.
    Moreover, Docker was installed on these VMs to feature a webserver, which also makes web development possible.
    Transferability:
    As the solution bases on WA, it provides all features from WA.
    This includes e.g. working in groups online and a high interactivity when meeting in groups as well as Jitsi conference rooms.
    These features can be used for online meetings, such as conferences and lectures.
    We extended these features by making it possible to work with computers in groups remotely.
    This e.g. makes it possible to work on programming projects decentralized.
    As, our virtual laboratory can be used for remote group work, online workshops and tutorials are also possible.
    More features can be integrated easily into WA by embedding a corresponding web application.
    Therefore, the current software can be extended in order to adopt new use cases quickly.
    Furthermore it is possible to reuse parts of our solution (e.g. the reimplemented administration services) in own instances, even if they address other use cases.
    It is our medium-term goal to further develop this solution so that it is suitable for use at high school.
    Additional information:
    The source code of the virtual laboratory is available on GitHub (https://github.com/SUASecLab).
    An article about the laboratory was published in German language in the journal "Informatik Spektrum" of Springer Nature (https://doi.org/10.1007/s00287-022-01447-2).
    about this event: https://programm.froscon.org/2022/events/2792.html
    57 min

About Chaos Computer Club - archive feed

From the publisher's feed

Der Chaos Computer Club ist die größte europäische Hackervereinigung, und seit über 25 Jahren Vermittler im Spannungsfeld technischer und sozialer Entwicklungen.