Chaos Computer Club - archive feed

Chaos Computer Club - archive feed

By CCC media teamTechnology
Download on the App Store

Chaos Computer Club - archive feed episodes

  • World in Vectors - Cross-platform Map Rendering using Rust (MCH2022)
    Digital maps are ubiquitous tools in our everyday life. In the early 90s, the idea of browsing the world digitally and visiting any place was groundbreaking. The first solution to this problem is known as "TerraVision", which was breathtaking at that time. Today, the idea of exploring your surroundings using digital maps has become pretty normal.
    But how do these maps work? In this talk, I want to provide an overview of the foundations of digital mapping solutions. Differences between maps which use vector data and rasterized satellite imaginary will be outlined. Furthermore, a new and open-source map renderer called [maplibre-rs](https://github.com/maplibre/maplibre-rs) will be presented, which is created using Rust and modern web technologies like WebWorkers and WebAssembly. Lastly, I want to show differences between commercial solutions and free and open-source ones.
    A lot of mobile and web applications depend on customizing and displaying maps. There are not many cross-platform solutions available. Some only work in the web. Some only work on mobile devices.
    Furthermore, there are only a few truly free and open-source mapping stacks available.
    I want to explain how [maplibre-rs](https://github.com/maplibre/maplibre-rs) can solve current challenges by leveraging a modern rendering stack.
    Last year I had a lot of spare time and decided to kick-start a project which combines different areas of interest: Rust, 3D rendering, Geo data
    This project was adopted recently by the [MapLibre](https://maplibre.org/) project and is now known as [maplibre-rs](https://github.com/maplibre/maplibre-rs).
    The [maplibre-rs](https://github.com/maplibre/maplibre-rs) library is a proof of concept which showed me the complexity of mapping solutions. It takes a lot of steps until edits from OpenStreetMap contributors are finally rendered in consumer applications. With this task I want to take listeners on a journey from drawing changes in the OpenStreetMap editor all the way until vectors are uploaded to from memory to GPUs.
    Like outlined in the abstract, I want to cover multiple topics:
    * Foundations of digital maps (How to determine which data should be loaded? What are vector and raster tiles?)
    * Show the technology stack which allows us to design and develop a cross-platform map renderer (Web, Mobile, Desktop)
    Lastly, I want to provide a software developer perspective on mapping technologies.
    about this event: https://program.mch2022.org/mch2022/talk/BRHLYE/
    22 min
  • IRMA's Idemix core: (MCH2022)
    IRMA is a system in which you are in control of sharing specific personal properties (aka attributes) such as your age, address and gender which are stored in the IRMA app on your phone. Technically, IRMA is a set of free and open source software projects implementing the Idemix attribute-based credential scheme. Although the Idemix credential system has been around for a while it is still relevant today. In this talk, we walk you through the crypto behind Idemix, explain how it works, why it is safe and give you the means to understand Gabi, the Go implementation of Idemix that is used in IRMA.
    Presentations on privacy products often focus on the principles of why we should want to protect our privacy and how the product does this from a birds-eye or user perspective. In case of IRMA, this focus would be on storing your attributes on your local device and on the information flow when the IRMA app is used.
    However, in this talk we want to dig deeper, demonstrate the crypto behind the curtains and give you the means to reason why IRMA is a neat solution.
    Note that the talk is very technical. We will cover the theory of the zero-knowledge proofs, the Camenisch-Lysyankaya signature and the Idemix credential verification, all so you can understand the Go implementation of the Gabi library. If time allows, we'll also cover IRMA-specific solutions such as the keyshare protocol and revocation.
    We will cover a lot of ground very quickly but after this talk you will have an excellent starting point for truely understanding this anonymous credential system. Of course we'll provide you with follow-up material and are happy to chat some more after the talk with a beer or two.
    Background knowledge that will help in understanding this talk:
    - General understanding of public key cryptography, especially RSA (https://www.youtube.com/watch?v=MsqqpO9R5Hc, https://www.youtube.com/watch?v=SL7J8hPKEWY)
    - Basic algebra, namely the laws of exponentiation
    - Some context on IRMA (https://irma.app/docs/overview/)
    about this event: https://program.mch2022.org/mch2022/talk/AFD3XT/
    51 min
  • Automatically Suspicious - Predictive policing in the Netherlands (MCH2022)
    Predictive policing is hip and happening. In the last few years we have seen a number of experiments with predictive policing in The Netherlands. How does that technology work? What were the outcomes of the experiments? And what is the legal status of a suspicion generated by a computer?
    "Predictive policing" is the name of a family of technology that use historical crime data to make predictions about future crimes (cue Minority Report). Police departments all over the world are very interested in this technology because it promises better results (more crimes prevented) at lower cost. In the Netherlands we have seen a number of experiments with predictive policing, and one of these systems (CAS) is currently being rolled out throughout the country. But how do these systems work? And how _well_ do they work? And what is actually the legal status of a suspicion generated by a computer?
    This talk will give discuss relevant predictive policing experiments in the Netherlands and abroad and will discuss the results of these experiments. The talk will also cover the legal status of suspicions generated by this technology in the Netherlands.
    about this event: https://program.mch2022.org/mch2022/talk/DJ8FCY/
    47 min
  • Hacking with Microbes (MCH2022)
    Microbes are everywhere. They are part of nature, both around us and inside of us. When you provide their desired niche, you can make them do something for you, in a mutually beneficial arrangement. This talk will take you into their realm, and show a few practical examples and hacking opportunities.
    Our climate is on fire, but we are still reaching for an Ultimate Solution. We don't move until we get a drop-in replacement to sustain current habits, at no extra cost. Our cognitive dissonance makes us trust politicians to deliver on promises, and energy vendors to withstand lucrative green washing. But it is both interesting and profitable to be part of the solution, and not of the problem.
    I have a long-standing fascination with microbial processes. They are adaptive and resilient while they modestly take on chores that pull things back to nature's standards. I think many problems that we are facing now can be solved locally and efficiently with clever combinations of technology and microbiology. Not always complete solutions and not everything is simple, but they certainly add to resilience and taking ownership of problem *and* solution.
    In a perfect situation, energy is harvested when&where it is abundant and moved to when&where it is needed. This talk demonstrates ways of doing at least some of that with the help of microbial systems. We will demonstrate overlap and connections, and conditions under which they may be hacked:
    Outline:
    * Beer. Vinegar. Innoculation. Permaculture.
    * Gut. Fiber or Fat. SCFA. Immune system. Epigenetics.
    * Biogas. Acetate. Sulphur and ammonia. Garbage in, garbage out.
    * Microbial fuel cell. Clay and carbon. Training.
    * Pee. Urea. Energy calculations for a Raspberry Pee.
    * Poo. Phosphate. Energy calculations for iPoo mobility.
    * Compost. Worms. Energy calculations for heat generation.
    * Climate change & zoonose. Cramming sick animals. Antibiotics. Government ignorance.
    Summary:
    * Making beer uses yeast to turn sugar to alcohol. Yeast can flexibly adapt from/to glucose via DNA switching to generate different enzymes. Let fruit flies in, and they bring along Acetobacter that reduce alcohol to vinegar. Wild fermentation is more natural, and yields a lambic beer. Save work by going for stable, naturally mixed processes.
    * Our gut processes whatever we can't. Two rough kinds of colonies co-exist. One consumes cholesterol/bile and the other plants/fiber. They tune our body via SCFA, the immune system and epigenetics. You can hack by changing your food (and after a few weeks, the microbes are thought to hack you by asking for more; so much for free will?!?)
    * Biogas works like a gut. It forms/consumes acetate CH₃COOH to produce CO₂ and methane CH₄ with byproducts hydrogen H₂, hydrosulphide H₂S and ammonia NH₃. Local cycles can process known sludge and produce usable liquid output, but large-scale anonymity destroys that. Some influences are possible, but the process is basically difficult, smelly and a bit dangerous.
    * Microbes can live in a fuel cell, which then accepts electrons and passes H+ through a membrane. Urine can be broken down with just clay and carbon -- and a culture. What are researchers doing? A variant to produce hydrogen H₂. And the potential of driving microbes by passing in a current.
    * Pee contains urea (NH₂)CO(NH₂), a hydrogen carrier. Urea is stable when dried, but otherwise reduces to ammonia NH₃. Soil microbes normally turn ammonia into atmospheric N₂ and water. But we can also use urea in a fuel cell to extract electricity or hydrogen.
    * Poo contains many microbes, some of which are pathogenic. But it is also our disposal channel for phosphorous (which we mine to grow food) and nitrogen. Troubled hygiene, but can this be safe? Is it a good idea?
    * Compost is incredibly straightforward and safe. The nutrient cycle is so short that nature could have invented it... oh wait, it did. Spring brings a gradual start, Summer collects energy, Autumn sheds it off and Winter benefits from the captured energy. Because composting generates heat, and has been used for heating homes, or parts of homes. Though mostly self-controlled, there are broad requirements for heat retention, moisture, oxygenation and C:N ratio. Working with these, you can have some degree of control over this process.
    * Microbes mutate if we force them into another environment. Like a sick animal. Or 3000 of them. Antibiotics form a bonus challenge. Many animal farmers carry resistent microbes. Zoonoses are on the rise due to climate change, and they are the common source of infectious diseases. Government practices [best effort management](https://www.rijksoverheid.nl/binaries/rijksoverheid/documenten/wob-verzoeken/2020/10/28/besluit-wob-verzoek-prognoses-ziektekiemen-uit-dierhouderijen/Besluit+Wob-verzoek+prognoses+ziektekiemen+uit+dierhouderijen.pdf) by chasing for *known* diseases; they are generally clueless about possible future zoonoses and any involved risk to humans.
    [Session image source](https://commons.wikimedia.org/wiki/File:Cyanobacteria_guerrero_negro.jpg)
    about this event: https://program.mch2022.org/mch2022/talk/D3QKXL/
    53 min
  • An Ontology Of Electronic Waste (MCH2022)
    This talk will investigate how the concept of private property has fundamentally altered our behavior towards the environment. We will investigate how an alternative ontology of electronic waste is needed and argue why dumpster diving, hacking and reverse engineering abandoned electronics is more relevant than ever to tackle this problem.
    Within the discourse that surrounds the global rise in electronic waste, only a select range of subjects receive attention from the public - international relations, global waste management strategies and corporate greenwashing rhetoric that emphasizes a ‘circular’ economy. Although the legitimacy of these strategies can be debated, they fail to address the root of the problem. Following the pervasive concept of private property and how it has infiltrated the ways in which we think about ourselves, our relationships between each other and the environment, we will arrive at how this concept has solidified itself within the ontological frameworks we use to make sense of waste and electronic waste in particular. We will discuss how, when we get rid of the concept of private property (and subsequently the concept of waste), we can reimagine what abandoned electronics mean to us and how we can best address the incessant pressure from manufacturers to treat them as expendable, throw-away objects. We will discuss how collective dumpster diving, hacking and reverse engineering abandoned electronics might be a possible solution and present free and open source tools that could aid us in the process.
    about this event: https://program.mch2022.org/mch2022/talk/QZDECX/
    49 min
  • Finding 0days in Enterprise Web Applications (MCH2022)
    Enterprise web applications have been deployed rapidly to the internet over the last ten years. Often, these applications remain secure, purely due to how difficult it is getting a copy of the source code. Unsurprisingly, some of the most popular enterprise web applications contain critical pre-authentication vulnerabilities. This presentation discusses how to get your hands on enterprise web applications and how to audit them for vulnerabilities, demonstrated through the disclosure of multiple 0days in popular enterprise web applications.
    When performing offensive source code analysis, the road to critical pre-authentication vulnerabilities usually involves a treacherous journey. From obtaining the source code, to mapping out sources and sinks, this presentation will take you on this journey to finding critical bugs in the following software:
    - IBM Websphere Portal / HCL Digital Experiences
    - Solarwinds Web Help Desk
    - Sitecore Experience Platform
    - VMWare Workspace One UEM (AirWatch)
    By experiencing the discovery process of 0days in popular enterprise web applications, this process can be repeated on the enterprise applications your company uses. The vulnerabilities discussed in this presentation have all gone through a responsible disclosure process.
    about this event: https://program.mch2022.org/mch2022/talk/EF7VSC/
    42 min
  • Building modern and robust Web-Applications in 2021, without writing any JavaScript (MCH2022)
    Building Web-Applications is hard. Making them scale is even harder. And nobody said anything about robust yet.
    Looking back over the past 25 years of Web-Development, not much has changed, except for tooling and languages. The approaches we use, also have not changed much. We still write lots of JavaScript, put special glue in between layers of languages, it's bleak.
    Building Web-Applications is hard. Making them scale is even harder. And nobody said anything about robust yet.
    Looking back over the past 25 years of Web-Development, not much has changed, except for tooling and languages. The approaches we use, also have not changed much. We still write lots of JavaScript, put special glue in between layers of languages, it's bleak.
    Let's have a look at the Phoenix Framework, a modern approach to building Web-Applications in Elixir, on the Erlang VM, without having to resort to a multitude of languages and frameworks.
    In this talk we will
    - **NOT** pick a JavaScript framework like React or Angular
    - **NOT** write a single line of JavaScript
    - **NOT** care about Erlang or it's Syntax
    - **NOT** spend hours to making the application WebSocket-capable and feel "live"
    But we will
    - write a state-of-the-art application that looks and feels professional in record time
    - have tests for every feature, buttons, links or forms we implement (test-coverage upwards of 90%)
    - have formatted our code, linted, error checked
    - run the test-suite, before every commit
    about this event: https://program.mch2022.org/mch2022/talk/L3HRXH/
    44 min
  • Scientist Rebellion (MCH2022)
    I present background, rationale and future plans of Scientist Rebellion, a growing international group of currently over a thousand scientists venturing into civil disobedience since writing more papers about the climate emergency does not yield the needed political sense of urgency and actions.
    I'll present Scientist Rebellion, an international group of scientists taking the scientific view of the climate emergency seriously, stepping away from writing yet another paper giving the same warnings and venturing into civil disobedience.
    We've had worldwide (27 countries) actions and growing rapidly, as more scientists feel the necessity for society to do more (not just throwing more money at companies when they promise to be less polluting, but strict laws preventing such pollution levels).
    Dutch site: https://www.scientistrebellion.nl/
    International site: https://scientistrebellion.com/
    about this event: https://program.mch2022.org/mch2022/talk/9LZJYH/
    49 min
  • Hacking the pandemic's most popular software: Zoom (MCH2022)
    Last year we won Pwn2Own by demonstrating remote code execution, using a chain of three vulnerabilities, on the then latest version of the Zoom client. In this talk we would like to share all details of the vulnerabilities we found and how we combined them into a fully working exploit.
    When the pandemic required everyone to work from home, we saw a huge growth on the video conferencing market. It was this movement that made the organisation behind the world famous Pwn2Own competition decide to add an 'Enterprise Communications' category to last year’s competition. Everyone who was able to successfully demonstrate a zero-day attack against Zoom or Microsoft Teams would be rewarded $200,000. We decided to take them up on this challenge and started researching Zoom. This resulted in a working remote exploit against the at the time latest version of Zoom that would give the attacker full control over the victim’s system (CVE-2021-34407).
    During this talk, we will walk you through how we started our research, explain the vulnerabilities that were found and finally how those vulnerabilities were incorporated into the exploit that successfully performed the attack during the contest.
    about this event: https://program.mch2022.org/mch2022/talk/QVXXUP/
    49 min
  • Lightning Talks Sunday (MCH2022)
    Lightning talks are a 5 to 10 minute quick talk on an interesting subject. They can be with or without slides, and with or without proper preparation. if you weren't accepted in the main CfP, this is also a great opportunity to give an abridged version of your talk. These sessions will be available to sign up to later on, with details on the wiki: https://wiki.mch2022.org/Static:Lightning_Talks
    Lightning talks are a 5 to 10 minute quick talk on an interesting subject. They can be with or without slides, and with or without proper preparation. if you weren't accepted in the main CfP, this is also a great opportunity to give an abridged version of your talk. These sessions will be available to sign up to later on, with details on the wiki.Lightning talks are a 5 to 10 minute quick talk on an interesting subject. They can be with or without slides, and with or without proper preparation. if you weren't accepted in the main CfP, this is also a great opportunity to give an abridged version of your talk. These sessions will be available to sign up to later on, with details on the wiki: https://wiki.mch2022.org/Static:Lightning_Talks
    about this event: https://program.mch2022.org/mch2022/talk/PUNDRB/
    1 hr 20 min

About Chaos Computer Club - archive feed

From the publisher's feed

Der Chaos Computer Club ist die größte europäische Hackervereinigung, und seit über 25 Jahren Vermittler im Spannungsfeld technischer und sozialer Entwicklungen.