Chaos Computer Club - archive feed

Chaos Computer Club - archive feed

By CCC media teamTechnology
Download on the App Store

Chaos Computer Club - archive feed episodes

  • Censoring the internet & how to bypass it (MCH2022)
    In recent times, internet censorship has increased throughout the world. With governments realising the potential of the internet in spreading information as well as misinformation.
    To curb or rather control this, governments around the globe have taken to censoring parts of the internet by directing major ISPs to block access to those websites.
    The ISPs around the globe have used different methods to block the access. Some resulting in DNS filtering to others doing SNI ( Server Name Information ) inspection.
    There have been ways to bypass these restrictions, like DoH ( DNS over HTTPS ) and eSNI ( encrypted SNI ), now ECH ( Encrypted Client Hello ), supported by TLS 1.3.
    To counter these, some authoritarian regimes ( like China ) have blocked eSNI traffic altogether, to be able to sniff the traffic and block the websites accordingly on their ‘Great Firewall’.
    I will be talking about how these different mechanisms of blocking user traffic works, by doing a live demo of packet analysis using wireshark.
    Later on in the talk, I will show a comparative study of the different ISPs around the globe and what their approaches are at blocking the internet ( if any ).
    After understanding how the technologies work, I will show ways to bypass the censorship by some open source tools, DIY solutions and finally some paid/managed alternatives. What are the things that one should look for when choosing one such paid solution.
    Towards the end, I will announce the open source repo for the tool used to conduct this project, where people can contribute and use it for their own research purposes.
    I am analysing some of the major ISPs 'around the globe' and how they’re blocking websites and easy + cost-effective ways to bypass them. There has been some previous research into this, but that has included some limited dataset, back in 2020. From then to now a few things have changed including the way ISPs are blocking websites.
    With this project, I am trying to :
    1. Analyse the global censorship of internet
    1. Globally, how different ISPs block the network traffic
    2. Distribute the client globally and ask volunteers to run this at least once
    2. Release the client and server code as open source
    3. Publish all the data, country wise on a github repo for everyone to consume
    The talk would be in two parts :
    - First : Where I talk about the technical nitty-gritties as to how censoring in modern times work.
    - Second : After understanding how the technologies work, we will try to bypass those by some open source tools, some DIY solutions and finally some paid/managed alternatives, what are the things to look for when choosing one such provider.
    Hence, even for folks who aren't much into the technical details of censorship, would have some arsenal of tools to bypass it, by the end of the talk.
    Starting with the famous question :
    “What happens when you type a (https) URL in your browser and press enter ?”
    I will cover all the aspects, starting with
    1. DNS lookup
    2. TLS Handshake - ClientHello,TLS negotiation, ServerHello etc
    3. Encrypted Data Transfer
    All of these would be shown a live demo of in wireshark, alongwith decrypting the traffic using certificates.
    Explaining these stages are important because each of these involve ISPs tampering with to censor the internet. Once we know how it’s done, we will figure out how to resolve this privacy issue. Like :
    Stage
    How ISPs censorConfirmation TestBypass
    DNS Lookup
    Their own DNS as default
    DNS filtering
    Check on dnsleaktest.com
    Use DoH ( DNS over HTTPS )
    dnscrypt
    TLS Handshake
    SNI Inspection
    Use the tool
    Check on wireshark
    Use VPN
    eCH
    Further move on to ECH ( Encrypted Client Hello ) and why China hates it .
    Show a comparative analysis of the different ISPs I’ve tested using the tool.
    Towards the end talk about the open source tool, the client and server code themselves.
    The tool, client app :
    1. Sends request to alexa top 1M domains
    2. Records packet response and to find what kind of filtering is in place ( if any )
    3. Sends data to central dashboard server for generating heatmaps and graphs
    The tool, server app :
    1. Will consume all the JSON data and validate its findings.
    2. Generate heat maps for all the ISPs and different websites that are blocked.
    Talk about solutions to bypassing the censorship :
    1. Open source tools & solutions - DoH, changing default DNS etc
    2. DIY things - self hosted 1-click VPN, ephemeral on-demand sshtunnel etc
    3. Paid solutions - Things to look for when choosing one such paid solution
    about this event: https://program.mch2022.org/mch2022/talk/VYSFLR/
    50 min
  • Single Sign-On: A Hacker's Perspective (MCH2022)
    This talk gives an introduction in how single sign-on protocols (such as SAML, OAuth 2, and Open ID Connect) work. Subsequently, I will talk about the most commonly found vulnerabilities in these protocols. Finally, I will show various ways to resolve these vulnerabilities.
    Single sign-on remains a hot topic in 2022. Many organisations are in the process of moving identity management and authentication out of of their application, and offload it to an identity provider. By doing so, application owners hope to avoid the challenges that come with identity management. However, the application will still needs to obtain the user’s identity from the identity provider, which is done using a single sign-on protocol.
    Unfortunately (or fortunately?), single sign-on protocols are difficult to get right. Flaws in the implementation of single sign-on protocols can have serious consequences. In the worst case, such flaws allow hackers to log into the application as an arbitrary user. And this is not just a theoretical risk, but something I encounter in my work as ethical hacker on a regular basis.
    I will start this talk by giving an introduction to some of the protocols that are commonly used to achieve single-sign on. Such protocols include SAML, OAuth 2, and Open ID Connect. Subsequently, I will talk about the state of single-sign on applications as I encounter them as an ethical hacker. I will demonstrate which vulnerabilities I encounter in the real world, and what the consequences of such vulnerabilities could be.
    At the end of this talk, you should have a good overview of how single sign-on protocols work, what types of vulnerabilities typically occur in them, and how to protect against such vulnerabilities.
    about this event: https://program.mch2022.org/mch2022/talk/MTTAXV/
    46 min
  • Rocking the Web Bloat: Modern Gopher, Gemini and the Small Internet (MCH2022)
    The web is a mess, bloated with data-gathering trackers, predatory UX, massive resource loads, and it is absorbing everything it touches. The Small Internet is a counter-cultural movement to wrangle things back under control via minimalism, hands-on participation, and good old fashioned conversation. At its heart are technologies like the venerable Gopher protocol or the new Gemini protocol offering a refuge and a place to dream of a better future.
    Join me and be reintroduced to Gopher in 2021 and learn what this old friend has to offer us in a world full of web services and advertising bombardment. We will also explore the new Gemini protocol and how it differs from Gopher and HTTP.
    We will explore the protocols themselves, their history, and what the modern ecosystems are like. I will briefly review the technical details of implementing servers or clients of your own, and how to author content as a user. Discussion will cover limitations, grey-areas, and trade-offs in exchange for speed and simplicity.
    Through these alternative protocols we'll see the small internet in action.
    about this event: https://program.mch2022.org/mch2022/talk/RPVQD8/
    48 min
  • OpenKAT: Looking at security with cat eyes (MCH2022)
    During crises – like COVID19 – software is made under immense pressure in a volatile environment. Security should focus on anything that makes one vulnerable. OpenKAT does this with real forensic proof, with the right context and useful in real life.
    The COVID19-crisis forced to build dozens of software solutions rapidly with too few people under immense pressure. Meanwhile the threat level as well as the stakes are high. Failure is not an option yet guaranteed. You can no longer afford vague questions like are we secure? You need to find what makes you vulnerabilities before that hit you as well as soon as they hit you.
    With dozens COVID-testing organizations to monitor, three countries to help, 17 projects to help come to life and to guard during operation security is an impossible job with the tools and people available. The options are simple: drown or find a trick to survive.The COVID19-crisis forced to build dozens of software solutions rapidly with too few people under immense pressure. Meanwhile the threat level as well as the stakes are high. Failure is not an option yet guaranteed. You can no longer afford vague questions like are we secure? You need to find what makes you vulnerabilities before that hit you as well as soon as they hit you.
    With dozens COVID-testing organizations to monitor, three countries to help, 17 projects to help come to life and to guard during operation security is an impossible job with the tools and people available. The options are simple: drown or find a trick to survive.
    The OpenKAT-project was started to fill in that gap to take a radical different approach on security while not discarding what we have already. KAT (cat in Dutch) delivers information on vulnerabilities in a forensic accurate manners, monitors environments and more over proves how things change over time.
    The OpenKAT-project was started to fill in that gap to take a radical different approach on security while not discarding what we have already. Just like a cat you see more while looking at the same information just by interpreting it differently. KAT (cat in Dutch) delivers information on vulnerabilities in a forensic accurate manners, monitors environments and more over proves how things change over time.
    about this event: https://program.mch2022.org/mch2022/talk/UB3SGY/
    45 min
  • macOS local security: escaping the sandbox and bypassing TCC (MCH2022)
    "SomeApp would like to access files in your Documents folder." Anyone who has used macOS recently will be familiar with these prompts. But how do they work? What happens if you deny the access? Are they an effective defense against malware?
    This talk will give an up to date overview of the local security measures of macOS and describe some ways they can be defeated in practice.
    Sandboxing on macOS was introduced 13 years ago, but Apple didn't leave it at that. Starting with the release of macOS Catalina in 2019, even non-sandboxed apps need to deal with sandbox-like restrictions for files: all apps now need to ask permission to access sensitive files, like those in the user's documents or desktop folder. Features such as the camera and geolocation already needed user approval from a permission prompt. This system of user controlled permissions is known as Transparency, Consent, and Control (TCC).
    Any new security measure like this will also mean the introduction of new security boundaries, with new classes of vulnerabilities. Many parts of the system have to be re-examined to check for these vulnerabilities. For example, apps can now try to attack other apps in order to "steal" the permissions granted by the user to those apps. Apple has taken steps to allow apps to defend themselves against this, such as the hardened runtime. Ultimately, however, it is up to the developer of an app to safeguard its permissions. Many developers are not aware of this new responsibility or do not take it seriously. Developers who are used to the security model of Windows or Linux often do not know that these boundaries even exist. To make matters worse, Apple's documentation and APIs for these features are not as clear and easy to use as they should be.
    This talk will start with an overview of local security restrictions on the latest version of macOS, Mojave. Then, it will cover some ways these protections might be bypassed in third-party applications. Finally, we will show some vulnerabilities we found in software that allowed escaping the macOS sandbox, stealing TCC permissions and privilege escalation, such as CVE-2021-30688, CVE-2020-10009 and CVE-2020-24428.
    about this event: https://program.mch2022.org/mch2022/talk/WEBRZC/
    51 min
  • Scanning and reporting vulnerabilities for the whole IPv4 space. (MCH2022)
    The Dutch Institute for Vulnerability Disclosure scans the internet for vulnerabilities and reports these to the people who can fix them. Our researchers will go into some of our recent cases, our board members will describe how we professionalise vulnerability disclosure and why we are allowed to somewhat break laws on computer crime and privacy.
    The Dutch Institute for Vulnerability Disclosure scans the internet from our own AS (50.559) for vulnerabilities and reports these to the people who can fix them. In this session our board members will describe how we professionalise vulnerability disclosure with an independent foundation, a Code of Conduct, a common identity, a collaboration platform for independent researchers and a CSIRT to report vulnerabilities to owners of vulnerable systems.
    Our researchers will go into some of our more known cases, ranging from Citrix 2020, to KaseyaVSA and Log4j in 2021 and others which commenced between filing this proposal and the conference. They will demonstrate how to scan, validate data, report to users and how they responded.
    By doing this, we kind of break several laws on computer crime and privacy protection. Still, we are allowed to as we serve to make the internet more secure. Moreover, we also guide young security researchers to the responsible path of vulnerability disclosure. And we do it Dutch style: open, direct and for free.
    Chris and Astrid will go into the way we work, Frank and Lennaert will do the cases.
    about this event: https://program.mch2022.org/mch2022/talk/9LMTLA/
    49 min
  • Ethics does not belong on the wall! Ethical framework for the use of location data (MCH2022)
    The use of data is accelerating, not only owing to increasing technical possibilities like AI and earth observation, but also as a result of crises such as COVID-19 and climate change which accelerate the deployment of data and technology. This is happening on a small and local scale, as well as on a large and global one. Precisely because these data are potentially personal, and its use is becoming commonplace, it is urgent to internalize shared principles for the responsible use of data to achieve greater common value, better data and better products. These are preferably intrinsic principles that guarantee the safety and privacy of people, our social values and human dignity. In this talk we discuss an ethical framework for the use of location data. Together with the crowd we will investigate several dilemma's in which location data play an important role. How far can you go? Which values are more important? These are the kind of questions we will present and discuss.
    The ethical framework is designed for the use of (personal) location data.
    How do we ensure that the technology we develop is at the service of society? How do we respect shared public values and the individual rights when developing applications made possible by location data? With the discussions that have erupted around apps for monitoring the COVID-19 pandemic, it is clear that the answers to these questions are not crystal clear.
    The purpose of the ethical reference is to inspire data users, but also policy makers and decision makers to help them collect, use and apply personal location data responsibly. Location data are all data that show where people are located and how they move, whether or not they can be traced. This data can, for example, be collected via mobile apps.
    In this talk we discuss the different values that are conflicting in the use of location data. We present several dilemma's and cases and will involve the public actively in discussing these dilemma's.
    You can find a concept of the ethical framework at https://www.geonovum.nl/themas/geo4covid/ethical-framework
    In our work looking for responsible use of spatial data we are working together with W3C: https://w3c.github.io/sdw/responsible-use/
    about this event: https://program.mch2022.org/mch2022/talk/VJVH9E/
    47 min
  • A CISO approach to pentesting; why so many reports are never used (MCH2022)
    Pentesting can provide vital information to organisations about their security. However, many reports end up never being used or not being used to their full potential. That is partly due to the pentesters and their writing skills. But in large part is also to be attributed to CISO's lack of guidance and involvement.
    I am not a spokesperson for all CISOs, but I do have quite a bit of experience in the pentesting field as a CISO. As such; I would like to share my thoughts about how a CISO can lead the pentesting process as effectively as possible, as well as what I as a CISO like to see in my pentesting reports.
    I will also highlight why some reports don't get used and why I think we struggle with this as much as we sometimes do.
    I think this information is usefull for pentesters and CISO's alike, because it shows both sides how the other one works and thinks.
    Many pentesting reports are never followed up on, which is a shame, because a lot of hard work goes into them a lot of the time.
    In this talk I will try to explain why this happens and will try to clarify how we can make some changes to the practice, reporting and follow up to make pentests more effective.
    I will also talk about some of the things that have gone wrong during pentests I've been involved in. Scoping is important y'all!
    If you're interested in what managers generally think certain jargon means (what's a checksum?), come check out the talk and you'll find out ;).
    p.s. I can't find where to edit my personal profile, but I'm currently no longer CISO for DIVD. Since the beginning of this year I've joined the Board instead.
    about this event: https://program.mch2022.org/mch2022/talk/QXRYJH/
    50 min
  • Nuggets of Shannon Information Theory (MCH2022)
    In his 1948 [scientific article](https://en.wikipedia.org/wiki/A_Mathematical_Theory_of_Communication) entitled ["A mathematical theory of communication"](https://people.math.harvard.edu/~ctm/home/text/others/shannon/entropy/entropy.pdf), Claude E. Shannon introduced the word “bit”. The article laid down the foundations for the field of information theory which in turn opened up the way to digital information processing.
    In this overview talk, I will present in an accessible way three nuggets from Shannon information theory:
    1. Shannon entropy, a mathematical quantification of uncertainty of a probability distribution.
    2. Information Compression: Shannon entropy provides a fundamental lower bound on how much information from a source can be compressed so that it can later be recovered.
    3. Error correction: when digital information is transmitted over a noisy channel, the methods of error-correction provide ways to protect this information from noise. Yet again, Shannon entropy provides the fundamental quantity of how much information can be transmitted over a noisy channel.
    While the content of this talk is of mathematical nature, I will try my best to make it accessible to anybody with (very) basic knowledge of probabilities and programming.
    **All material (including presentation, Jupyter notebooks etc.) for this talk are available at https://github.com/cschaffner/ITNuggets**
    Since 2014, I have been teaching a yearly master course about information theory at the University of Amsterdam. Together with my PhD student Yfke Dulek, we have written [lecture notes](https://github.com/cschaffner/InformationTheory/blob/master/Script/InfTheory3.pdf) on the topic and developed some additional learning tools based on these notes.
    I love the mathematical beauty of Shannon’s information theory, and I believe that the three concepts above can be appreciated by a much wider audience that does not regularly read scientific papers of the mathematical kind. While I will focus on making the fundamental theoretical aspects accessible to the audience, all of these concepts also have some interesting (and challenging) programming aspects to them that can be explored further after my talk.
    about this event: https://program.mch2022.org/mch2022/talk/8DFDSE/
    50 min
  • Cyber crises and what you can do to face the challenge (MCH2022)
    Your organization suffers from a serious system compromise from a cyber-crime ring, state-actor or both. The cyber inferno is raging through your organisation. In this talk I’d like to walk you through a situation which escalated quickly. The talk is intended to inspire people to take preventative measures, keep their heads as cool as possible, and keep a grip on the situation.
    Your organisation suffers from a serious system compromise from a cyber-crime ring, state-actor or both. The cyber inferno is raging through your organisation. The problems are countless. A neighbouring organisation is looking at your problems and wondering about the potential of spillovers. What if these spillovers escalate beyond your grasp? How and what do you communicate internally and externally? In this talk I’d like to walk you through a situation which escalated quickly. The talk is intended to inspire people to take preventative measures, keep their heads as cool as possible, and keep a grip on the situation regardless of the size of the challenge.
    about this event: https://program.mch2022.org/mch2022/talk/CVGHG9/
    45 min

About Chaos Computer Club - archive feed

From the publisher's feed

Der Chaos Computer Club ist die größte europäische Hackervereinigung, und seit über 25 Jahren Vermittler im Spannungsfeld technischer und sozialer Entwicklungen.