Chaos Computer Club - archive feed

Chaos Computer Club - archive feed

By CCC media teamTechnology
Download on the App Store

Chaos Computer Club - archive feed episodes

  • Lightning Talks Monday (MCH2022)
    Lightning talks are a 5 to 10 minute quick talk on an interesting subject. They can be with or without slides, and with or without proper preparation. if you weren't accepted in the main CfP, this is also a great opportunity to give an abridged version of your talk. These sessions will be available to sign up to later on, with details on the wiki: https://wiki.mch2022.org/Static:Lightning_Talks
    Lightning talks are a 5 to 10 minute quick talk on an interesting subject. They can be with or without slides, and with or without proper preparation. if you weren't accepted in the main CfP, this is also a great opportunity to give an abridged version of your talk. These sessions will be available to sign up to later on, with details on the wiki.Lightning talks are a 5 to 10 minute quick talk on an interesting subject. They can be with or without slides, and with or without proper preparation. if you weren't accepted in the main CfP, this is also a great opportunity to give an abridged version of your talk. These sessions will be available to sign up to later on, with details on the wiki: https://wiki.mch2022.org/Static:Lightning_Talks
    about this event: https://program.mch2022.org/mch2022/talk/LGUFFZ/
    1 hr 3 min
  • Project TEMPA - Demystifying Tesla's Bluetooth Passive Entry System (MCH2022)
    The security of Tesla's cars has been a hot topic in recent months. In addition to being one of the safest cars on the road, it is also well-protected from hacks and attacks. But how does Tesla make sure their vehicles are safe and secure?
    This case study sheds light on the inner workings of Tesla's Passive Entry System and core VCSEC protocol, and reveals possible attack vectors.
    The security of Tesla's cars has been a hot topic in recent months. In addition to being one of the safest cars on the road, it is also well-protected from hacks and attacks. But how does Tesla make sure their vehicles are safe and secure?
    Tesla is a company that has been innovating in the automobile industry for many years. They have been designing and manufacturing electric vehicles which are environmentally friendly and sustainable. Tesla has also been pioneering and implementing new technologies in the automotive industry. One of these innovations is their Bluetooth interface which is used for locking and unlocking vehicles and can be used to uniquely identify cars, as well as to track them in real-time with apps like "Tesla Radar".
    The introduction of Tesla's Bluetooth passive entry system, previously only used by model 3 and model y, into new product lines like the Tesla 2021 Model S/X facelift variant, shows the strategic importance of this technology for Tesla in the years to come.
    This case study sheds light on the inner workings of Tesla's Passive Entry System and core VCSEC protocol, and reveals possible attack vectors.
    about this event: https://program.mch2022.org/mch2022/talk/DCTJDE/
    52 min
  • Plotting the Pandemic... (MCH2022)
    Only three years ago you wouldn't have had a chance to get this so-called reality past any decent editor. Now, plotting a book or movie has become increasingly hard and the next years in publishing will be interesting, since our standards in what is scary or believable or how dumb can one be to do XY as a book character, to get into whatever problems, have tremendously changed.
    I'm an author, writing crime novels and scifi and during the last three years, some collegues and I have often said the phrase "if this was a book, you wouldn't get that past an editor". But it seems, our standards on what is real, believable or doable have changed somewhat over the pandemic. This does not only afflict society itself (fake news, mobs, conspiracy myths etc.), but also (pop) culture and the its creators like authors of books or movie scripts. I have no forecast, on where we might end up or if movies and books will return to story worlds of our old believes, but I can share musings about society, tech and humanity's deepest desire in stories and authors who have to face a different kind of basic understanding of the world to start from when writing stories.
    about this event: https://program.mch2022.org/mch2022/talk/CPT3CD/
    51 min
  • TASBot OoT ACE: (MCH2022)
    TASBot has appeared at multiple charity events raising more than $1.3M to date by hacking classic video game consoles through controller ports. In this talk, dwangoAC will show how TASBot, with help from a human speedrunner, can use a Stale Reference Manipulation exploit in the N64 game Legend of Zelda: Ocarina of Time to achieve persistent Arbitrary Code Execution to obtain the Triforce and many other surprising outcomes that have to be seen to be believed.
    The TASBot community, led by dwangoAC, has exploited glitches in a variety of creative ways leading to Twitch chat streamed through a Super Game Boy, Super Mario Bros. being played inside Super Mario World, and many more. Most of these exploits were on older NES and SNES consoles, but what could be done if Arbitrary Code Execution could be achieved on an N64? This talk aims to show the beautiful results that can ensue after taking complete control of Legend of Zelda: Ocarina of Time, including obtaining the Triforce itself! The talk will cover controller protocol evil maid attacks, Stale Reference Manipulation (Use After Free) exploitation, a four stage bootstrap chain to attain high speed data transfer, and more with audiovisual elements that are sure to be a surprise.
    about this event: https://program.mch2022.org/mch2022/talk/CNYE7A/
    49 min
  • Hope : It is too late to be pessimistic (about climate change) (MCH2022)
    We know that we are in trouble as a human society, so what are we going to do about it?
    Showcase projects that do good things
    What can you do?
    Tension between system-level problems and the massive powers that be and the scope of individual impact. How do you leverage your privilege?
    imagining yourself in 2050 narratives.
    We know that we are in trouble as a human society, so what are we going to do about it?
    Showcase projects that do good things
    What can you do?
    Tension between system-level problems and the massive powers that be and the scope of individual impact. How do you leverage your privilege?
    imagining yourself in 2050 narratives.
    about this event: https://program.mch2022.org/mch2022/talk/KFEEZ7/
    1 hr 33 min
  • PolyCoin - A game played across MCH (MCH2022)
    PolyCoin - A distributed game across MCH. The history at EMF Camp 2018 and 2022, and how it was made and works. See what is on the inside of the PolyCoin crypto miner devices, and why they were designed the way they were and what had to be compromised along the way, what can be improved, and plans for future versions.
    PolyCoin - is a game being deployed at MCH 2022, you'll see the PolyCoin crypto miner units installed throughout the site. This game involves "capturing" the crypto miners using an RFID card to collect the fictional crypto currency PolyCoin. Each player selects one of four fictional global corporations to support, and captures the crypto miners for their chosen company producing PolyCoins for them. The company with the most PolyCoins wins!
    Delving in to the brief history of the game at EMF Camp 2018 and 2022, and then explaining how it works and the various bits hang together to create the overall game. Covering PICmicro, ESP8285 (micropython), DFR0299, RC522 RFID, MQTT, Python on Raspberry Pi, and the hidden features of the game waiting to be discovered.
    I'll cover the problems with the original game deployed in EMF 2018 and how they were addressed with the PolyCoin game in 2022. Then the problems encountered in 2022 at EMF camp (far less issues!).
    This would ideally be suited to having this presentation followed by a hands-on session to see the parts that make the game. I should have enough bits to run a workshop as well to build a PolyCoin crypto miner unit, including surface mount and hand soldering all the parts and assembling the units themselves.
    about this event: https://program.mch2022.org/mch2022/talk/CRHHCU/
    37 min
  • The War in Ukraine: Cyberfront (MCH2022)
    When the pandemic was declared over, Europe went into a war. This was the first major conflict in Europe where an important part of the war was waged online.
    Anonymous, disBalancer, IT ARMY, and the western governments.
    These are stories from the cyber front lines.
    Welcome to a panel of speakers from Ukraine and EU. We will discuss what happened on the front, how it helped to turn the war in Ukraine's favor, the international cooperation, the cyber offensive, and the how and why of it.
    We will discuss, DDoS, information disclosures, backdooring, psyops, and propaganda.
    Chris Kubecka, CEO and Founder of HypaSec, Anastasiia Voitova, security software engineer at Cossack Labs, and Peter van den Heuvel, Security analyst from Saxion, are joining us to share their stories.
    https://twitter.com/SecEvangelism
    https://twitter.com/vixentael
    https://twitter.com/pvdheuvel_
    https://twitter.com/KirilsSolovjovs
    about this event: https://program.mch2022.org/mch2022/talk/PL3FTM/
    1 hr 25 min
  • First Privacy, Now Safety: (MCH2022)
    As of today, most discussions on cyber security focus on privacy and the implications of incidents involving data. However, those of us in cyber physical security often see things differently as we study actors attempting to use computers to impact the physical world (e.g. critical infrastructure and industrial controls). Geopolitical conflicts and accessible offensive security tools make defending against these threats increasingly complex. The anthology I bring for you illustrates the evolution of cyber physical threats through several stories with topics that span from non-fiction espionage and crime thrillers to politically-motivated intrusions and master tinkerers’ ill-fated creations. By focusing on the different players involved and their motivations, I intend not to hype up the scenario, but instead to accurately describe what we observe daily in the cyber physical threat intelligence community.
    “First Privacy, Now Safety: An Anthology of Tales from the Front Lines of Cyber Physical Security” will consist of a series of real stories to illustrate the evolution of cyber physical threats related to topics that span from non-fiction espionage and crime thrillers to politically-motivated intrusions and master tinkerers’ ill-fated creations. The selection of topics results from my personal experience as a member of the cyber threat intelligence community in Washington, D.C. with a very pacifist perspective of life. Some example stories include:
    • The Unwilling Pawn – How our infrastructure gets swept up in geopolitical conflicts
    • Everybody Be Cool, This is a Robbery! – How criminals can make more money by getting physical.
    • What if I Click Here? – Errant tales from hackers learning about cyber physical systems. (And sometimes erring in the process).
    All of the stories I will talk about can be verified by the audience in open sources and specialized publications, although they may not appear in any popular books or videos until a couple years from now.
    about this event: https://program.mch2022.org/mch2022/talk/QYAUZT/
    43 min
  • Threat modeling mechanical locking systems, by analyzing puzzles? (MCH2022)
    Mechanical locks are everywhere and come in all shapes and flavors. But choosing the right lock can be rather difficult. For example, what is better? A lock that is hard to pick, or a lock with hard to duplicate keys. This talk will not give you the answers, but it will help you understand the trade-offs. Furthermore, we will have fun threat modeling our locks.
    Is lockpicking a threat you should be concerned about, or is the brick the tool you should care for? Jan-Willem, from The Open Organization of Lockpickers (Toool), will share his ideas on mechanical security and threat modeling. We will make it fun and use several case studies, starting with defining a lock, threat modeling mechanical puzzles, and use several case studies where the threat was overrated. Simply put, attacks against locks range from the trivial to mastery. I'll share multiple failed attempts of attacks that should be trivial, but were not in practice, and we will analyze them together.
    about this event: https://program.mch2022.org/mch2022/talk/T8MCQW/
    36 min
  • drand: publicly verifiable randomness explained (MCH2022)
    drand is an opensource project allowing anybody to run a “randomness beacon”. Its goal? Providing a trustable, verifiable source of public randomness that would enable full transparency in online lotteries, leader election or blockchain smart contracts.
    This talk is about what distributed randomness is, what it means for developers, and users, and why you’d want to use it. I will also present to you the current ecosystem around drand, and what it enables you to do differently and why it is desirable in a distributed, decentralized web to have public, verifiable randomness.
    Don’t worry though: we will first go through an easy overview of how it works without diving too much into the gory cryptographic details. In addition, I’ll demo how drand works in practice, and explain you how you can easily use it in your applications since drand nodes can be queried by anybody.
    Disclaimer: this is NOT a blockchain talk, but rather a distributed system one.
    [drand](https://drand.love/) (pronounced "dee-rand") is a distributed randomness beacon daemon written in Golang.
    It has been used by Cloudflare, EPFL, Kudelski Security, UCL and other partners to setup a distributed randomness project that was unveiled in June 2019: the ["League of Entropy"](https://blog.cloudflare.com/league-of-entropy). Since then even more members have joined the league.
    Servers running drand can be linked with each other to produce collective, publicly verifiable, unbiasable, unpredictable random values at fixed intervals using bilinear pairings and threshold cryptography. Drand nodes can also serve locally-generated private randomness to clients.
    Generating public randomness is the primary functionality of drand.
    Public randomness is generated collectively by drand nodes and publicly available. The main challenge in generating good randomness is that no party involved in the randomness generation process should be able to predict or bias the final output. Additionally, the final result has to be third-party verifiable to make it actually useful for applications like lotteries, sharding, or even "nothing up my sleeves" parameter generation for security protocols.
    drand relies on the following cryptographic constructions:
    - Pairing-based cryptography and Barreto-Naehrig curves.
    - Pedersen's distributed key generation protocol for the setup.
    - Threshold BLS signatures for the generation of public randomness.
    - ECIES for the encryption of private randomness.
    These are well known, while still relatively cutting edge cryptographic schemes.
    Why do we need such randomness?
    A lot of reasons actually:
    - Lotteries, jury selection, election event, random sampling for audits, ...
    - Protocols & cryptography:
    - Verifiable gossip: randomly choosing peers in a verifiable way in a network to disseminate information
    - Parameters: Nonces & IV for symmetric encryptions, composite or prime numbers for selecting a field for RSA, or even ECC
    - Schemes: Diffie Hellman exchange, Schnorr signatures, more generally for zero knowledge proofs,
    - Protocols: Tor (e.g. path selection), sharding (Omniledger), leader election for consensus
    - Statistics: verifiable random sampling, reducing bias e.g. in controlled trials in medicine, etc.
    Now, drand is a software ran by a set of independent nodes that collectively produce randomness and whose long term goal is to implement Randomness-as-a-Service:
    - Fetching randomness should be as simple as fetching time from NTP servers.
    - Nodes can serve both private randomness and public randomness:
    - Unpredictable and bias-resistant
    - Publicly Verifiable
    - Decentralized service using threshold cryptography, with high availablity, reliability and trust.
    This talk will NOT be about just the cryptography behind drand, but I will cover some of the basics in a simple way in order to tease the people that could be interested, while introducing cool cryptographic constructions to the rest. It will NOT be about how drand is built, but it will really be about the **practical use-cases for drand**, how to use it, its kind of randomness, what it means and why you might want to use it.
    about this event: https://program.mch2022.org/mch2022/talk/YWHF7Z/
    39 min

About Chaos Computer Club - archive feed

From the publisher's feed

Der Chaos Computer Club ist die größte europäische Hackervereinigung, und seit über 25 Jahren Vermittler im Spannungsfeld technischer und sozialer Entwicklungen.