Chaos Computer Club - archive feed

Chaos Computer Club - archive feed

By CCC media teamTechnology
Download on the App Store

Chaos Computer Club - archive feed episodes

  • UBports: Imagine a phone that does everything you expect and nothing you don't. (MCH2022)
    This talk explains what the UBports Foundation does: managing the Ubuntu Touch OS for mobile devices. The challenges, the why, what and how.
    The world needs another phone OS. With more focus on privacy.
    And the Ubuntu Touch OS tries to be the best in the field of open source OS's for mobile devices.
    In this talk we tell you why.
    We tell you about our challenges and how we try to solve them.
    This means we tell you the "what"
    What is VoLTE and why do we need it in an open source phone OS?
    And we tell you the "how"
    How are we working on VoLTE support in Ubuntu Touch?
    How is knowledge management organized?
    How do we develop software?
    How are devices supported?
    The world needs another phone OS. With more focus on privacy.
    And the Ubuntu Touch OS tries to be the best in the field of open source OS's for mobile devices.
    In this talk we tell you why.
    We tell you about our challenges and how we try to solve them.
    This means we tell you the "what".
    For example: What is VoLTE and why do we need it in an open source phone OS?
    And we tell you the "how"
    How are we working on VoLTE support in Ubuntu Touch?
    How is knowledge management organized?
    How do we develop software?
    How are devices supported?
    about this event: https://program.mch2022.org/mch2022/talk/HR9XSQ/
    44 min
  • Modernizing the Tor Ecosystem for the Future (MCH2022)
    In this presentation, we will be updating the audience on the ongoing modernization efforts of the software developed inside The Tor Project -- the organization behind the most widely deployed anonymity network. We will look at upcoming features and changes to the core technology that drives the Tor network and why a Browser may no longer be the only product we have to provide for the user-base that is so crucial in need of Tor's anonymity properties for safe internet access.
    The Tor ecosystem is currently going through a more extensive modernization phase where we are simplifying our goals slightly to make space for larger projects that we find necessary.
    This work includes implementing a new, more memory-safe Tor implementation in the Rust programming language named Arti. This work will make it easier for application developers to integrate their applications and benefit from the safety features that Tor can provide.
    Additionally, we will talk about some recent or upcoming changes to the network:
    - Give a status update on deploying modern congestion control algorithms in the Tor network. This work should significantly enhance the performance barrier that most Tor users experience.
    - The roadmap towards UDP support in the client and relay software. This work should allow more modern use-cases of the Tor software such as voice and video communication, WebRTC, and other protocols that leverage datagram-based data transfer.
    - Move to more modern cryptography in Tor's protocols, including support for Post-quantum cryptography and why this is needed.
    - Allowing Tor users to access the network using a VPN-like tunneling mechanism as an alternative to simply web-browsing and other socks5 enabled applications.
    about this event: https://program.mch2022.org/mch2022/talk/MUP7MX/
    50 min
  • All you never wanted to know about the Banking System and why it keeps crashing Economics. (MCH2022)
    Based on the world´s first, and as far as we know still the only accurate double entry bookkeeping based simulation of the banking system, we will talk through how fractional reserve banking really works from a network perspective, and how it has influenced both economic activity and economic theory in many unappreciated ways.
    If you want to be able to predict what the central banks will do next, and how to make sensible financial decisions despite this, this is the talk to you. Inflation is back, and it´s still the same. We´ll also talk about ways to contribute to the development of economic models and simulations that are based on real economies, and not on a 30 year practice of fitting a very short mathematical ruler, to a very long curve.
    It all started innocently enough, with an attempt to build a simple banking simulation in python of the standard Economics 101 textbook description of the banking system. This failed to work as soon as loan repayments were put in. The next version was a little more complicated, agent based, and used double entry book keeping, and the version after that added some simple economic features like widget producers and households (which actually makes it as sophisticated as "sophisticated economic models" (it´s still nowhere complete though), and has been used to enlighten/confuse several classes of computer science students at Reykjavik University in Iceland.
    Along the way we learnt how money gets created and destroyed, how several different kinds of bank regulation actually worked, identified several positive feedback loops in the financial system, how international money transfers don´t actually transfer money, and why it was probably inevitable cryptocurrency would re-invent fractional reserve banking right after they reinvented its book keeping.
    about this event: https://program.mch2022.org/mch2022/talk/T3CLJC/
    52 min
  • My journey to find vulnerabilities in macOS (MCH2022)
    My journey to find vulnerabilities in macOS. During 2020 and 2021 I found two major vulnerabilities from macOS. In this presentation I walk you through the whole exploit chain to compromise users' sensitive data with one click. I will also explain my methodology to find logic bugs.
    My journey to find vulnerabilities in macOS. During 2020 and 2021 I found two major vulnerabilities from macOS. In this presentation I walk you through the whole exploit chain to compromise users' sensitive data with one click.
    I will walk you through how I solved the following steps:
    - Fundamentals how I find vulnerabilities
    - Basics about the "extra" security protections in macOS
    - How to get payload delivered with one click
    - Code execution with arbitrary mount
    - Gatekeepper evasion
    - TCC protection evasion
    - SIP -protection evasion
    - Timeline
    - How Apple will credit the researches
    about this event: https://program.mch2022.org/mch2022/talk/973QGG/
    40 min
  • Hacking COVID: Hackers helping the government (MCH2022)
    During the COVID19-pandemic the Netherlands turned to hackers to help them make digital solutions to fight the pandemic. Why was it? What does this do to a government body like ministry? What does this mean for privacy, security and the tech choices that are made?
    In 2020, when the pandemic started, scientists suggested to also digitally support fighting the pandemic. One of the suggestions was digitally supported contact tracing. After first asking the market for solutions the Dutch Ministry of Health, Welfare and Sport decided to self build open, privacy friendly, secure and accessible solutions with help of a large open source community.
    When vaccinations became available and timeframes for building solutions were near impossible the next step was clear: get hackers involved. This isn’t just to stick to the values, but also to create solutions in ways that aren’t always common for governments. How do you hack processes and rules to create what some ministries called magic?
    This talk will tell the inside hacker tale of the pandemic and show the dilemmas that were overcome. This is a story of hackers in a ministry at the heat of the moment.
    about this event: https://program.mch2022.org/mch2022/talk/BVGYKQ/
    49 min
  • Trusted CDNs without gatekeepers (MCH2022)
    I want a Web where CDNs are unnecessary.
    Where different organizations, different website operators, can help each other out by hosting assets for each others' websites, thus spreading the load across many orgs in solidarity, instead of centralizing it in gatekeepers.
    I believe I might slowly be getting to a point of having a decent answer to that question. No blockchain required.
    What if I told you the [code for this is already mostly there](https://gitlab.com/rysiekpl/libresilient/)?
    All major browsers support Service Workers and Subresource Integrity, which means we can have a piece of JS that:
    1. only gets updated from the original domain
    2. handles all requests for the website
    3. routes these requests to the original domain, or hits third party endpoints when the original domain is unavailable for whatever reason
    4. has ways of distributing and checking Subresource Integrity on any fetched resource.
    And we do!
    Points 1. and 2. are assured by Service Workers API, so browsers enforce that.
    Point 3. can be achieved with [LibResilient's the alt-fetch plugin](https://gitlab.com/rysiekpl/libresilient/-/blob/master/plugins/alt-fetch.js).
    Point 4. is the job of [LibResilient's signed-integrity plugin](https://gitlab.com/rysiekpl/libresilient/-/blob/master/plugins/signed-integrity.js).
    This is all very PoC. Documentation is lacking or non-existent. But it's already there, ready to be tested and improved.
    about this event: https://program.mch2022.org/mch2022/talk/W7MB7H/
    47 min
  • Hacking UK train tickets for fun, but not for profit (MCH2022)
    We take a scenic tour through the origins of the UK train ticket, from the original BR specification in the 1970s through to modern replacements like mTickets, eTickets and ITSO.
    This is just a detour though, and we'll focus on the 'orange ticket' (RSP 9399/9599) - which continues to be a stalwart of the UK rail network. Surely they can't be that secure? After all, anyone can encode a magstripe - right?
    We'll take a look through the data encoded on these tickets, what interesting things you can do with them and maybe (assuming I've got it working by then) we'll be able to read and write our own!
    We take a scenic tour through the origins of the UK train ticket, from the original BR specification in the 1970s through to modern replacements like mTickets, eTickets and ITSO.
    This is just a detour though, and we'll focus on the 'orange ticket' (RSP 9399/9599) - which continues to be a stalwart of the UK rail network. Surely they can't be that secure? After all, anyone can encode a magstripe - right?
    We'll take a look through the data encoded on these tickets, what interesting things you can do with them and maybe (assuming I've got it working by then) we'll be able to read and write our own!
    about this event: https://program.mch2022.org/mch2022/talk/XMCUHG/
    32 min
  • Building a cheap laser harp for percussionists (MCH2022)
    A laser harp is a magic musical instrument that makes sounds from light beams.
    Ever since Jean-Michel Jarre used a laser harp in his live concerts to play Rendez Vous 2, many people have dreamt to play one. But they are ridiculously expensive!
    Klaas van Gend will discuss his ongoing journey with Pascal Ahout to design a cheap and simple laser harp suitable for a local percussionist group. A revolutionary simple laser harp, using only an Arduino board, and no moving parts.
    Hopefully, at the time this talk happens, the design is ready to be demoed, so we’ll end with a live demo or a video recording showcasing our working laser harp.
    The director from St. Caecilia percussionists group Lieshout-Mariahout in Brabant always wants to go beyond just playing music. He loves to bring in nonstandard instruments, video or lighting tricks.
    For an upcoming show, he wants to compose a new piece with a laser harp.
    As usual, he came to his audio and lighting engineer Pascal Ahout, who asked software engineer Klaas van Gend to join in.
    Together, they started designing a reliable laser harp from scratch, reviewing various sources on the internet and revisiting all design decisions. Their laser harp design looks remarkably different – no moving parts, no complex optics and cheap!
    This talk will show the design process, implementation details and hopefully the results.
    Indeed: the development is not done yet. So we may end the talk explaining why our ideas weren’t smart enough… We’ll have to see!
    But we intend to end with a working demo.
    about this event: https://program.mch2022.org/mch2022/talk/KBEJVL/
    43 min
  • IOT: International Outage Technology (Disclosure of DIVD-2022-00009) (MCH2022)
    DIVD researcher Jelle (aka SchizoDuckie) has a hobby. He likes to find credentials in places where they don't belong, like GitHub and Postman. And this hobby has gotten him into many places he should not have, like the Dutch Tax office and many larger company.
    But, in February 2022 he found an account with an even bigger reach, an account who's abuse could mean trouble for our national critical infrastructure. His simple GitHub query uncovered a secret that could switch off a country, now what...
    While Jelle is enjoying his vacation his DIVD colleagues, Chris van 't Hof, Célistine Oosting and Frank Breedijk, will present the story of one of the more significant vulnerabilities discovered by DIVD this year. The long windy but mostly slow and silent road to disclosure and remediation and how mitigation did not take away all the risks.
    This talk digs into the, up to this point, untold story of case DIVD-2022-00009 and will include numbers "Doc" Brown will jealous of.
    about this event: https://program.mch2022.org/mch2022/talk/FEZFET/
    19 min
  • Freedom, Ownership, Infrastructure, and Hope (MCH2022)
    How should we live together? How do we make a complex, interdependent, infrastructural society less exploitive? In this talk, we'll try to frame questions, if not answers, grounded in the context of the political changes required to mitigate and survive climate change, global fascism, and hypercapitalism.
    This talk starts from two threads. First, the common understanding of "freedom" derives from the institution of slavery. Looking at alternate definitions provides the foundation for rethinking the building blocks of society and human interaction. Second, climate change represents an immediate existential threat to human civilization, but mitigating it is no longer a question of technology — only of collective will.
    If we insist on maintaining existing structures of ownership and inequality, we significantly reduce our chance of survival. However, these questions of freedom, ownership, and equity aren't just political questions, they're directly encoded in the infrastructure we all rely on to survive — that same infrastructure that we currently need to replace, almost wholesale.
    In reality, any path to survival will imply a muddle of adaptation, mitigation, replacement, and elimination, both of infrastructural components and of elements of the social contract and its governance systems. Harm reduction is more important and more probable than ideologically perfect revolutions (or even evolutions). However, plausible visions of the future are a critical ingredient for the hope we need to continue the work, and will also directly shape that work.
    Most folks who live in ownership societies (almost everyone, now) find the idea of moving away from an ownership model terrifying, because it means giving up those things that give them a sense of security. Understanding the emotional interiority of life in a post-ownership society can change that, and understanding the dynamics of different freedoms can help us understand how we might get there.
    As people who build infrastructure, we can play with the social models our infrastructure encodes — and have been doing so for decades. Likewise, we can (and have been) rebuilding pieces of the social contracts that shape our personal lives. This talk aims to leave you with new questions and new directions for that work.
    about this event: https://program.mch2022.org/mch2022/talk/VPKCC7/
    51 min

About Chaos Computer Club - archive feed

From the publisher's feed

Der Chaos Computer Club ist die größte europäische Hackervereinigung, und seit über 25 Jahren Vermittler im Spannungsfeld technischer und sozialer Entwicklungen.