Chaos Computer Club - archive feed

Chaos Computer Club - archive feed

By CCC media teamTechnology
Download on the App Store

Chaos Computer Club - archive feed episodes

  • Tech didn’t cause misinformation, and it won’t solve it (by itself) (MCH2022)
    There’s no quick fix for the misinformation, disinformation, and lies were seeing in the world these days, and its natural for hackers want to work on the problems with the skills at hand. I’m going to talk about why, for hackers, that’s not necessarily a good move to do solo. I’ll go over mistakes I’ve seen way too many technologists and academics make when approaching the subject, where misinformation *really* comes from, and where the audience can harness what they’re good at.
    It is deceptively easy to see misinformation as a data problem, as a societal issue of algorithms run amok on soulless social media platforms. However, just because the delivery of misinformation is purely technical, it doesn’t mean that the cause, or solution, is also technical. In the more than half a decade I have been working on factchecking misinformation and disinformation I have see this point lost over and over to technologist, hackers, hobbyists and academics.
    This is a huge waste of talented resources, and in this talk I will go over why this is the case and explain the most serious problems that journalists, fact-checkers and politicians are facing. Hackers have been addressing large-scale issues for decades, and my talk will lay a framework down for how the MCH community and beyond can work on the lies that are propagated across the internet and the world.
    There’s never been more of a need for help, and I will explain how to get the most bang for your buck.
    about this event: https://program.mch2022.org/mch2022/talk/MLVGMM/
    51 min
  • How to sneak past the Blue Team of your nightmares (MCH2022)
    If the perfect Blue Team exists, does that mean the Red Team doesn’t stand a chance against it or is there still a way to sneak their phish in the mailbox of their target? Well in this talk we investigate how a Red Team could sneak past even the best Blue Team imaginable.
    We analyse how a perfect Blue Team would detect malicious domains targeting their organization, how they would correlate these to other threat infrastructure to burn the whole campaign and how they would block a successful initial foothold in case they did not detect the phish campaign before its launch.
    By assuming the perfect adversary, we discuss techniques and important OPSEC measures Red Teams need to use to get a successful and undetected initial foothold in their targeted organization.
    Through practical demos and real-life examples, attendees will learn invaluable techniques and OPSEC measures to improve their Blue or Red Team tradecraft.
    If the perfect Blue Team exists, does that mean the Red Team doesn’t stand a chance against it or is there still a way to sneak their phish in the mailbox of their target? Well in this talk we will investigate how a Red Team could sneak past the best Blue Team imaginable. By analyzing techniques the perfect Blue Team would use, we define OPSEC measures and techniques to remain undetected and accomplish a successful initial foothold.
    How would a perfect Blue Team detect malicious domains targeting their organization?
    o BLUE: By dissecting patterns of adversaries and resulting OPSEC mistakes, we specify how domain and Certificate Transparency Log monitoring can unveil domains impersonating your organization.
    o RED: We explain measures the Red Team can take to avoid being caught through domain and CTL monitoring by using wildcard SSL certificates and avoiding typosquatting.
    How would a perfect Blue Team correlate detected malicious domains to related threat infrastructure?
    o BLUE: Once a suspicious domain is identified, we can correlate this to other threat infrastructure using NetLoc intelligence techniques. Through correlation, Blue Teams can leverage OPSEC mistakes to uncover and potentially burn the whole campaign.
    o RED: We explain measures the Red Team can take to avoid the correlation between their threat infrastructure and avoid the detection of one domain leading to the whole threat infra being burned.
    How would the perfect Blue Team attempt to block undetected phishing campaigns during their launch.
    o BLUE: We analyze how the use of reputational scoring based on IP, Domain and Mail server, can block many phishing campaigns during the launch itself.
    o RED: We explain how Red Teams can age and categorize their domains to pass IP/Domain/Mail based reputation detections.
    What if a phishing mail sneaks by the Blue Team and lands in the inbox of one of their employees, has Red Team won? Not yet:
    o BLUE: The perfect Blue Team has hardened employee endpoints to make a successful exploitation after a click almost impossible. We discuss several defensive techniques on how to block successful initial foothold through Macro execution hardening, Applocker, Exploit Guard and endpoint security solutions.
    o RED: Assuming a fully hardened system, we discuss strategies that could bypass all off these hardening measures and have been proven to be successful in past engagements
    We conclude with a summary of techniques both Blue and Red Teamers can use to perfect their tradecraft.
    about this event: https://program.mch2022.org/mch2022/talk/HKJCGA/
    46 min
  • Audio networks and their security implications (MCH2022)
    We will take a cursory look at the protocols that underpin audio over IP from studios to stages and on to broadcast. Focusing on AES67 the you will gain a basic understanding of what it is, how it works and how it is inherently vulnerable to attack. At a high level this talk should be accessible and entertaining to all, although to grasp the more nuanced details a rudimentary knowledge of IP networking and audio digitisation will be helpful.
    Description:
    In the professional audio space the heavy and expensive XLR snakes of old have largely been replaced with audio over IP. Operationally this move to audio over IP has provided many benefits, such as being able to use the same equipment for audio as they use for video and lighting rather than special sets of gear for each aspect of a production. However with the increased use of commodity IT hardware in this operational technology (OT) environment comes an increase in attack surface from more software, easier access and less segmentation. As with many places where IT components get re-purposed for OT the administration practices and development practices of the vendors haven’t necessarily caught up with the with the best practices of there IT counterparts. There are some hard problems to solve for audio over IP such as multicast encryption and authentication but also much simpler but more cultural things like updating a working system.
    It is hoped that by presenting this topic to the broader community of hackers that more talented people get interested in the hard bits, and perhaps we can even reach the folks on the operational technology side to see what measures can be taken to improve the security of existing systems.
    about this event: https://program.mch2022.org/mch2022/talk/JKSE7N/
    42 min
  • Intro to OSINT and Geolocation (MCH2022)
    The talk is on Introduction to opens source investigations. Aiganysh will explain what "open source" is, what kind of research you can do with it, and the challenges it entails from Bellingcat's experience. The presentation will be full of case studies and exercises such as geolocating ISIS supporters from Twitter and identifying neo-nazi criminals in the US.
    Bellingcat has conducted open source investigations into the downing of MH17, syrian chemical attacks, high level poisonings, corruption investigations, ecological research, war monitoring and etc. So what is open source investigations, how can you do it and what challenges come with it?
    To learn more about that join the talk by Aiganysh Aidarbekova, Bellingcat's researcher and trainer. The talk will also have case studies and exercises such as geolocating ISIS supporters from Twitter and identifying neo-nazi criminals in the US.
    about this event: https://program.mch2022.org/mch2022/talk/RSAY8Q/
    52 min
  • Meta-Press.es (MCH2022)
    Meta-Press.es is a WebExtention to help you exploring the online press, with no middlemen between the newspapers and your web browser. It allows you to discover millions of results within seconds and lists the last ones of each sources. Searches can be scheduled and results can be selected and exported.
    Meta-Press.es is a free software project built as a decentralized alternative to Google News. It is developed by Simon Descarpentries, ex-member of La Quadrature du Net, treasurer of the Fund for Defense of Net Neutrality FDN2.org and web artisan with 20 years of experience.
    Meta-Press.es runs entirely from your web browser and requires nothing else than online newspapers with internal search features to run. It supports currently more than 500 sources (newspapers, scientific press, online agendas…) but everything is made to help users contributing more sources.
    Using Meta-Press.es, there is no data sent to third parties (including our servers). We're not asking the users to believe us about the respect of their privacy, it's a matter of verifiable fact. No Meta-Press.es servers also means that Meta-Press.es is not a single point of failure, surveillance or censorship, like GAFAM are.
    Meta-Press.es helps you evading the swamp of third-party trackers and it works great from a Tor Browser.
    about this event: https://program.mch2022.org/mch2022/talk/ZRSJMG/
    50 min
  • Live streaming 360° video with your own infrastructure (MCH2022)
    Panoramic 360° video offers more immersion, but has unique challenges. There are plug and play solutions, however they use centralized services such as Facebook and YouTube.
    In this talk (live streamed in 360° video) i will explain how to setup your own 360° live stream using your own streaming servers and viewing the 360° stream on desktops, mobile devices and VR headsets in the browser.
    The pandemic has brought live streaming video to the masses. Panoramic 360° video offers more immersion, but has unique challenges. There are plug and play solutions, however they use centralized services such as Facebook and YouTube that invade our privacy and spam us with ads.
    In this talk (live streamed in 360° video) i will explain how to setup your own 360° live stream using your own free software streaming servers and viewing the 360° stream on desktops, mobile devices and VR headsets in the browser. If you want to setup your own stream you'll need a camera (i tested with Insta360 One R and HumanEyes Vuze).
    The talk will cover all parts:
    1. Camera setup
    2. Setting up the RTMP streaming server
    3. Adding HTML5 Live Streaming (HLS)
    4. Setting up browser based clients for desktop, mobile and VR
    about this event: https://program.mch2022.org/mch2022/talk/EBKZRV/
    36 min
  • Gigatron - creating a hobby kit (MCH2022)
    The Gigatron is a microcomputer without a microprocessor. It was made into a DIY electronics kit and sold over 1000 pieces from 2018 to 2020. It is now open source. In this talk, I will not go into the working of the kit, but explain what you need to think about when creating a kit and keeping it manageable. Think of what to design, sourcing components, testing, preventing too many support calls and more.
    The Gigatron is a microcomputer without a microprocessor. During the design phase, a decision was made to maybe make it into a Do-It-Yourself electronics kit. Many design decisions have been influenced by that decision, as creating a unique prototype is a lot different from creating a succesful kit.
    In this talk, I will go over some of these design decisions. I think the majority of them worked out very well, as over 1000 kits were sold between 2018 and 2020, before the Gigatron becoming open source. These design decisions were influenced by other kit builders, who had already gone through that process, like the people behind the PiDP-8 and Enigma-E.
    I would like to share some of that knowledge, so you can also stand on the shoulders of the giants before me. And of course to also stimulate the attendees to make their hobby project into a kit.
    No previous knowledge is needed. The talk is aimed at people wanting to turn their hobby project into a kit project.
    about this event: https://program.mch2022.org/mch2022/talk/33EPHD/
    51 min
  • Fault Injection on a modern multicore System on Chip (MCH2022)
    Hardware attacks on security relevant components, such as fault injection, have been known for decades and have been shown to be successful on a wide range of devices ranging from general purpose microcontrollers to dedicated security engines. In this work we give an overview of different methods used for fault injection and the effectiveness of these methods. We discuss electromagnetic fault injection in more detail. Most of the published research focuses on attacking low performance secure devices. However, we present the results of electromagnetic fault injection on a modern multicore system on chip running at gigahertz speed and discuss its effectiveness.
    In this presentation we discuss hardware attacks in general, their use cases, and real-world examples. We then discuss electromagnetic fault injection in detail. We compare the results of the previous research on microcontrollers and secure elements to more modern high performance system on chip devices. We discuss relevant features of modern Arm systems on chip and answer the two main questions of this research. Are electromagnetic fault injection attacks applicable and efficient when applied to software running at gigahertz speed on a modern multicore system on a chip? And to what extent does the operating frequency change the effectiveness of electromagnetic fault injection attacks?
    about this event: https://program.mch2022.org/mch2022/talk/9NZHED/
    52 min
  • Democracy: Eventually Digitally Transparent? (MCH2022)
    Governments should be radically more transparent. While calls for more open data and initiatives like the Open Government Partnership have existed for more than a decade, there is still much to be desired. Where do we stand? And, fun to imagine, where could and should we go?
    It is hard to have a perfect overview of the status of open government across the world. We at [Open State Foundation](https://openstate.eu/) focus mostly on accelerating digital transparency in the Netherlands. We will explain things like:
    - Why is the **Handelsregister** (company register) still only fully accessible for those with a lot of money?
    - Why are **Wob-verzoeken** (Freedom of Information requests) on average not answered within the legal deadline?
    - How transparent are the **external meetings of ministers** and who do they talk to?
    On the other hand we show why the Netherlands is a great place if you want to know how your municipalities spend their money or want to access national statistics.
    Still there is much to learn from other countries:
    - **How does Norway manage their information so well** that they respond to Freedom of Information requests much faster?
    - What country has **a minister that deals in the most open way with lobbyists**?
    - Can governments produce **modern open source software**?
    These examples can show us a future of a digitally transparent democracy.
    We end the talk by opening up the floor to the audience and love to hear about positive examples of transparent forms of governments around the world.
    about this event: https://program.mch2022.org/mch2022/talk/LFVBN3/
    46 min
  • World in Vectors - Cross-platform Map Rendering using Rust (MCH2022)
    Digital maps are ubiquitous tools in our everyday life. In the early 90s, the idea of browsing the world digitally and visiting any place was groundbreaking. The first solution to this problem is known as "TerraVision", which was breathtaking at that time. Today, the idea of exploring your surroundings using digital maps has become pretty normal.
    But how do these maps work? In this talk, I want to provide an overview of the foundations of digital mapping solutions. Differences between maps which use vector data and rasterized satellite imaginary will be outlined. Furthermore, a new and open-source map renderer called [maplibre-rs](https://github.com/maplibre/maplibre-rs) will be presented, which is created using Rust and modern web technologies like WebWorkers and WebAssembly. Lastly, I want to show differences between commercial solutions and free and open-source ones.
    A lot of mobile and web applications depend on customizing and displaying maps. There are not many cross-platform solutions available. Some only work in the web. Some only work on mobile devices.
    Furthermore, there are only a few truly free and open-source mapping stacks available.
    I want to explain how [maplibre-rs](https://github.com/maplibre/maplibre-rs) can solve current challenges by leveraging a modern rendering stack.
    Last year I had a lot of spare time and decided to kick-start a project which combines different areas of interest: Rust, 3D rendering, Geo data
    This project was adopted recently by the [MapLibre](https://maplibre.org/) project and is now known as [maplibre-rs](https://github.com/maplibre/maplibre-rs).
    The [maplibre-rs](https://github.com/maplibre/maplibre-rs) library is a proof of concept which showed me the complexity of mapping solutions. It takes a lot of steps until edits from OpenStreetMap contributors are finally rendered in consumer applications. With this task I want to take listeners on a journey from drawing changes in the OpenStreetMap editor all the way until vectors are uploaded to from memory to GPUs.
    Like outlined in the abstract, I want to cover multiple topics:
    * Foundations of digital maps (How to determine which data should be loaded? What are vector and raster tiles?)
    * Show the technology stack which allows us to design and develop a cross-platform map renderer (Web, Mobile, Desktop)
    Lastly, I want to provide a software developer perspective on mapping technologies.
    about this event: https://program.mch2022.org/mch2022/talk/BRHLYE/
    22 min

About Chaos Computer Club - archive feed

From the publisher's feed

Der Chaos Computer Club ist die größte europäische Hackervereinigung, und seit über 25 Jahren Vermittler im Spannungsfeld technischer und sozialer Entwicklungen.