Chaos Computer Club - archive feed

Chaos Computer Club - archive feed

By CCC media teamTechnology
Download on the App Store

Chaos Computer Club - archive feed episodes

  • Sensor.Community - Global Open Environmental Data Platform (MCH2022)
    Sensor.Community - Global platform for Open Environmental Data
    We invite you to become part of Sensor.Community. The worldwide largest Air Quality sensor network run by contributors generating Open Data. Build a sensor, collect Open Data, share it in a continuous stream with the global network and join forces in local Sensor.Community groups.
    Sensor.Community is the global platform for environmental open data.
    We provide the software and assembly guide for the DIY sensor kits for citizen empowerment.
    Mission Statement:
    Sensor.Community is a contributors driven global sensor network that creates Open Environmental Data.
    Our mission is to inspire and enrich people’s lives by offering a platform for the collective curiosity in nature that is genuine, joyful and positive.
    Sensor.Community started 2015 in Stuttgart / South Germany as a local project. The goal then was the deployment of 300 low cost Air-Quality sensors in Stuttgart. These devices should be easy to build for everyone. Until now the platform has grown to more than 14.000 sensors in over 70 countries (January 2022).
    These sensors are measuring environmental data as Air-Quality, temperature, pressure and relative humidity. You can see the live values on the live map at Maps.Sensor.Community. Everything ever measured is available as Open Environmental Data. You can download all historical Open Data.
    To participate you can join a local group which you can discover on the community layer of the map where live values are displayed. -> https://maps.sensor.community/#2/0.0/0.0
    We invite you to become part of the community. Build a sensor, generate Open Data, share it in a continuous stream with the network and join forces in local Sensor.Community groups to analyse it. Find like-minded people which care about the environment and the implications on our health. Stay informed and exchange with your neighbours.
    Once the sensor tube is connected to the network its measured values are available live on the map at Sensor.Community. These values are refreshed every 2 ½ minutes and enable all citizens to see how the situation is around them.
    The available historical Open Data of all ever measured values enable other projects to serve citizens with other specific services and functionality.
    Sensor.Community is here to serve citizens on a global layer with environmental Open Data. Our focus is to add further sensor methods, collaborate with institutions as RIVM.nl on data standards and better integrations in their daily work. One great example here is the integration of the Open Data from Sensor.Community into the Data-portal of the National Institute for Public Health and the Environment in the Netherlands at RIVM.nl
    about this event: https://program.mch2022.org/mch2022/talk/GNVPXC/
    49 min
  • A Smart Light Hacking Journey (MCH2022)
    Smart lights have become pervasive in many homes, but they are often designed in such a way that makes them completely reliant on the manufacturer's servers and connectivity to the Internet. However, we would much rather be fully in control of our own devices.
    As a target, we took on the cheap and popular Tuya white-label smart lights, which can be commonly found under many different brand names.
    In this talk, we'll take you on a trip through our 1-year journey of hacking these devices, including the details of finding and remotely exploiting a vulnerability in the firmware for devices based on the custom BK7231 SoC.
    Smart lights have become pervasive in many homes, but they are often designed in such a way that makes them completely reliant on the manufacturer's servers and connectivity to the Internet. However, for people who want full control of their own devices, there weren't many affordable and easily usable options.
    One such option became available near the end of 2018 when a vulnerability was discovered in the firmware of smart devices manufactured by Tuya Smart. Shortly after the discovery of said vulnerability, a project by the name of tuya-convert popped up. It allowed its users to remotely flash Tuya devices with custom firmware by exploiting the - at the time - new vulnerability.
    By 2020, however, tuya-convert stopped working for an increasing number of new devices. The manufacturer had patched the vulnerability, and unexploitable devices have begun showing up on the market. That's when we decided to look for the next vulnerability for Tuya's smart devices in order to allow remote custom firmware flashing once more.
    We spent some time hacking on early devices which were based on the ESP8266 platform, and a while later switched to the newer devices based on the custom BK7231 SoC. During the course of our research, we found issues in firmware on both platforms and rediscovered some helpful reversing techniques.
    In this talk, we'll cover our research journey with its ups and downs on both platforms, as well as the details of a memory corruption vulnerability which we exploited on the BK7231-based devices.
    about this event: https://program.mch2022.org/mch2022/talk/WKJKEY/
    49 min
  • hack your brain (MCH2022)
    Food affects your body, food affects your mind. This talk describes how the performance of my brain has decreased over time and has returned by changing my diet. Basic food is not enough for your brain to deliver exceptional performance. Come with us and open your mind.
    Let your remedies be your food and your food be your remedies. Just think about it, I'm eating all day and losing weight. To be wide awake and in your right mind without "Club Mate" or coffee. Great recipes with three ingredients in a blender in seconds. Step by step with food to healing.
    Can you imagine a tasty gourmet cleansing cure? Results are better appearance, feel reborn, more powerful, mentally more stable, stress-resistant. Hack your food.
    A report of personal experience and feelings.
    about this event: https://program.mch2022.org/mch2022/talk/ZZVHAL/
    44 min
  • How to Secure the Software Supply Chain (MCH2022)
    Open source code makes up 90% of most codebases. How do you know if you can trust your open source dependencies? Do you know what’s really going on in your node_modules folder? It is critical to manage your dependencies effectively to reduce risk but most teams have an ad-hoc process where any developer can introduce dependencies. Software supply chain attacks have exploded over the past 12 months and they’re only accelerating in 2022. We’ll dive into examples of recent supply chain attacks targeting the JavaScript, Node.js, and npm ecosystems, as well as concrete steps you can take to protect your apps, projects, and teams from this emerging threat.
    Open source code makes up 90% of most codebases. How do you know if you can trust your open source dependencies? Do you know what’s really going on in your node_modules folder? It is critical to manage your dependencies effectively to reduce risk but most teams have an ad-hoc process where any developer can introduce dependencies. Software supply chain attacks have exploded over the past 12 months and they’re only accelerating in 2022. We’ll dive into examples of recent supply chain attacks targeting the Node.js, JavaScript, and npm ecosystems, as well as concrete steps you can take to protect your apps, projects, and teams from this emerging threat.
    Takeaways for this talk:
    1. Understand the scope of the supply chain threats against the open source ecosystem, specifically with a focus on JavaScript, Node.js, and npm.
    2. Review of our work to audit every open source package on npm to detect the following types of attacks: malware, typo-squats, hidden code, misleading packages, permission creep
    3. Specific examples and code walk-throughs of actual malware that was found on npm
    4. Discussion of existing methods and tools for detecting supply chain attacks against open source, including limitations
    5. Introduction of new open source tool which helps detect supply chain attacks in real-time
    about this event: https://program.mch2022.org/mch2022/talk/VWGMEH/
    48 min
  • Reproducible Builds for Trustworthy Binaries (MCH2022)
    Reproducible Builds is a technique that can be used to secure the software delivery pipeline.
    For open source software, they even allow independently auditing published binaries, removing a single point of trust from the distribution process. This can be used by individual projects or even complete Linux distributions.
    The software delivery pipeline is an increasingly popular attack vector: even when your project source code is known-good (audited), an attacker can inject malware by gaining access to the machine used to build (and sign) the binaries.
    Reproducible Builds provides a mechanism to counter such attacks: by building the same source code on independently-administered machines and comparing their outcome.
    Several Linux distributions (Debian, Arch, openSUSE, NixOS, OpenWrt, ...) are working towards using Reproducible Builds to make their binary packages independently verifiable, but also individual projects use it to verify their deliverables. This talk will give an overview of progress, results and next steps.
    about this event: https://program.mch2022.org/mch2022/talk/E33B8K/
    32 min
  • Payment terminals as general purpose (game-)computers (MCH2022)
    What is inside a Verifone VX820 payment terminal and how can we run our own code (i.e. Doom) on it?
    This is a story of a software guy messing around with an interesting embedded device. It includes some reverse engineering, *interesting* security practices, proprietary executable formats, and a game of bootloader hopscotch.
    Starting with an overview of the Verifone VX820 payment terminal's hardware and software, we will follow my curious exploration with the final goal of arbitrary code execution. We will see how such seemingly single-purpose devices actually allow for general purpose computing under the hood, and even contain all the peripherals needed for a fun (retro-)gaming experience.
    I will show the struggles and practicalities of turning a (previously found and published) bootloader vulnerability into a practical exploit. This includes some reverse-engineering of bootloaders, kernel code, communication protocols and file headers.
    Following this I will cover the "engineering" part: how to construct a minimum viable "toolchain" to be able to port a codebase like Doom.
    There will be demos of the exploit and some programs that have been ported :)
    about this event: https://program.mch2022.org/mch2022/talk/PBTBJG/
    43 min
  • illumos SmartOS, specialized Type 1 Hypervisor (MCH2022)
    Overview of **SmartOS** - an illumos based distribution with **focus of virtualization**. Must be named technologies used by SmartOS: ZFS, Crossbow, Zones, DTrace, Bhyve. The talk will show you the benefits of SmartOS; Configuration and management of SmartOS virtualization technologies; Tooling on top of SmartOS.
    SmartOS is a specialized Type 1 Hypervisor platform based on illumos. It supports two types of virtualization:
    - OS Virtual Machines (Zones): A light-weight virtualization solution offering a complete and secure userland environment on a single global kernel, offering true bare metal performance and all the features illumos has, namely dynamic introspection via DTrace
    - Hardware Virtual Machines (KVM, Bhyve): A full virtualization solution for running a variety of guest OS's including Linux, Windows, *BSD, Plan9 and more
    Virtualization in SmartOS builds on top of the foundational illumos technologies inherited from OpenSolaris, namely:
    - ZFS for storage virtualization
    - Crossbow (dladm) for network virtualization
    - Zones for virtualization and containment
    - DTrace for introspection
    - SMF for service management
    - RBAC/BSM for auditing and role based security
    - And more
    about this event: https://program.mch2022.org/mch2022/talk/SNNLNX/
    28 min
  • Introducing CSIRT.global: if you love the internet, we need your help (MCH2022)
    The Dutch Institute for Vulnerability disclosure goes international. We’re building a community of enthusiasts to help stop the downward spiral of the internet, we’re calling it CSIRT.global. It’s aimed at international collaboration. Trust and communication, balanced with a sense of reality about the sensitive information we deal with, are key. Here’s how you can help, one vulnerability at a time.
    The internet is wonderful. It is also broken and spiralling downward. Governments and big tech often don’t serve the interests of internet enthusiasts. Some people decided to “be the change”. In 2019, The Dutch Institute for Vulnerability was founded, and now it has over 70 volunteers. You have likely heard of our work, like Citrix and Kaseya. Communication is key in disclosing and informing organizations. Internationally, this can pose a real challenge. Therefore, we are building an international community, and we’re calling it CSIRT.global. Trust and communication are key. In this talk, you will learn why we’re expanding, what our challenges are, how we deal with sensitive information, and why it’s logical a volunteer organisation takes the lead. Finally, you’ll learn how you can help.
    about this event: https://program.mch2022.org/mch2022/talk/ZY39UT/
    25 min
  • Successfully building and programming sound field control systems (MCH2022)
    We will walk through the basics of sound field control systems and what you would need to build your own Wave Field Synthesis and Beamforming enabled system. We will unveil some of the challenges we faced at HOLOPLOT and what solutions power our tech stack.
    Most of us are very familiar with multiple ways of manipulating or creating audio content; filters, effects, synthesizers, etc., and most certainly don’t think about where the audio content is going to be reproduced. What if I told you your creativity could go further, and you can also control how sound is being reproduced?
    In this talk, we will learn about sound field generation and control systems, their benefits, and everything you need to build your own Wave Field Synthesis and Beamforming system. Additionally, we will unveil some of the implementation and infrastructure challenges we faced and solved at HOLOPLOT and then let you hear what a HOLOPLOT Matrix Array can actually do.
    about this event: https://program.mch2022.org/mch2022/talk/JN39DH/
    50 min
  • Knock knock, who’s there? (MCH2022)
    One of the most used video entry systems is analysed for this talk. Severe security implications that range from passive, information gathering, attacks to active attacks where unauthorised access to buildings can be gained.
    During the talk the technical details of the bus system will be discussed and multiple attackvectors will be demonstrated. At the end of the talk the disclosure procedure to high value targets and the manufacturer are also discussed.
    Feeling safe at home and at work is one of the most basic requirements for living. Part of being, and feeling, safe is the physical access system of the building.
    For this talk the video intercom system designed and manufactured by one of the most used brands in building access control and video entry technology is… evaluated.
    In order to paint a picture of the magnitude of the security implications it is good to mention that this system is not just used in apartment buildings but also in government offices such as the probation office in The Netherlands.
    The talk will discuss the technical aspects of the bus system and how and why this has major security implications. Not only passive attacks will be shown but also more active attacks that can compromise physical security in the buildings where the system is used.
    The talk will also include how disclosure to some potential targets was done. The reaction from the manufacturer will also be discussed in the talk.
    about this event: https://program.mch2022.org/mch2022/talk/NV9RBY/
    23 min

About Chaos Computer Club - archive feed

From the publisher's feed

Der Chaos Computer Club ist die größte europäische Hackervereinigung, und seit über 25 Jahren Vermittler im Spannungsfeld technischer und sozialer Entwicklungen.