Chaos Computer Club - archive feed

Chaos Computer Club - archive feed

By CCC media teamTechnology
Download on the App Store

Chaos Computer Club - archive feed episodes

  • The smart home I didn't ask for (MCH2022)
    What happens when your home is “smart” before you even move in? More and more buildings are pre-installing smart devices that tenants didn’t ask for and may not want. These devices focus on comfort and convenience, an excellent focus as long as security is also considered. Given the deep integration these devices have, a vulnerable system could lead to devastating consequences like the loss of privacy and even unauthorized access. As a security researcher, these were my thoughts when I saw the tablet mounted on the wall of my new apartment.
    In a short period, I discovered multiple vulnerabilities in the system. A concern for sure, considering the system allows for remote access and has integration with services in my apartment and the building. This talk will cover my path, my process, and coverage of the vulnerabilities I discovered.
    The smart home system is based on a wall-mounted Android tablet, and is installed in thousands of properties throughout Europe. It allows for controlling lights, heating, motorized blinds, opening a building's main entrance door among other things.
    The talk will contain the following contents:
    * Introduction
    * Presentation of the smart home system
    * Methodology
    * How did I evaluate its security
    * Findings
    * Description of vulnerabilities found
    * Impacts and countermeasures
    * Disclosure timeline
    * Interactions with vendor
    * Raise awareness
    * Conclusion
    about this event: https://program.mch2022.org/mch2022/talk/JPLREJ/
    32 min
  • Non-Euclidean Doom: what happens to a game when pi is not 3.14159… (MCH2022)
    We all know that the value of pi is a constant with a particular immutable value. Anyone who has done any graphical programming also knows that visual rendering relies not just on pi but trigonometry more broadly as well as other mathematical techniques. If we look into the source code of the first person shooter Doom we find that the value of pi used in the game is wrong. In this talk I will explore what happens when we subtly and not so subtly break math in the source.
    Doom is a well known classic first person shooter game with source code released under the GPL in 1999. In this talk I will begin by exploring what happens to the game when we make the value of pi even more wrong. What about when we change other trigonometric functions and constants to incorrect values? How will our familiar understanding and ability to traverse this virtual world change when we do this. Are there any interesting gaming possibilities with non-Euclidean geometries? A brief segway will cover some optimization tricks made to enable the game to run well on hardware available at the time. At the end I will provide a link to other games and public source code repositories that also use an incorrect value of pi. Pointers will also be provided to allow the audience to compile their own incorrect math version of the game.
    about this event: https://program.mch2022.org/mch2022/talk/ZM99EG/
    20 min
  • How to charge your car the open source way with EVerest (MCH2022)
    We will give you a short overview over the current electric vehicle charging technology and why it sucks. Let's try to fix it with the open source software stack EVerest! We will explain the technology and architecture behind it and will invite you to join our efforts forward to a green sustainable transportation infrastructure.
    Building a standard for EV charging infrastructure failed so far for multiple reasons: "Innovations" are implemented on a timescale of years to decades, and the standard is typically “designed by committee”. Every new player in the game has to reimplement the standard and it's done typically “very lean”, which is furthermore delaying and bugging the situation.
    Our solution is to establish a open-source based SW stack for charging systems, which all companies, manufacturers and private persons can use and make it the common de-facto standard. By opening the software for all, anyone can help improve it.
    We have already made some progress on our SW stack called EVerest and we would like to welcome you all in helping to transform the EV charging world. EVerest is part of the Linux Foundation Energy, a community lead by the green energy transition.
    about this event: https://program.mch2022.org/mch2022/talk/NUNPWD/
    22 min
  • Electron microscopes - How we learned to stop worrying and love cheap lab equipment. (MCH2022)
    A tale of sketchy^H^H^H^H^H^H^Hawesome online shopping, grimy scrap bins, and crazy DIY projects:
    The adventures of a few friends who set up an electron-microscopy lab (and much more!) without breaking the bank. For all audiences: whether you just want to see some cool micrographs, hear a story of hacker adventure, or, want to set up your own SEM - this should be a good time.
    This talk will have several parts:
    First we will tell you a story of a hobby that started with modifying an old classroom microscope for
    semiconductor imaging and has led to owning one, possibly two scanning electron microscopes (SEMs). You will see how 2020's logistics drama, COVID, language barriers, etc resulted turned the "simple" task of buying an electron microscope into a roller coaster of an adventure.
    Part two will look at the things we learned and what *you* should look out for if you want to get your own SEM: Things that will break, physics to watch out for, requirements for running it, and understanding the things that set different SEMs apart.
    Finally, we want to look at the future: Can we get a community of hackers building their own chips or replicating material science papers similar to the one we see abroad? Their achievements have been non-trivial to translate to European reality, but not impossible to. We hope to spur this on.
    about this event: https://program.mch2022.org/mch2022/talk/LE3MD7/
    50 min
  • Decoding the Anker 3800 lock (MCH2022)
    The Anker 3800 is a mechanical lock that has both traditional pins as well as magnetic sliders. Can it be opened without the key? This talk discusses how the lock works in a master keyed system and how it can possibly be defeated. It will cover decoding, picking and key duplication.
    The Anker 3800 is a mechanical lock that has both traditional pins as well as magnetic sliders. It was designed by Japanese company MIWA and is sold in the Netherlands under the Anker brand. It is a high security lock that is often used in large master keyed systems.
    I wondered: can it be opened without the key? I will present my adventures with the lock, having opened it up to see how it works, and several things I have tried to copy the key, pick the lock, decode the lock and find out what the master key looks like. The talk will include successes and failures and I will discuss designing 3D models, C&C work, electronics, Arduino programming, PCB design, and more.
    The talk is aimed at people with an interest in lockpicking. No prior knowledge is necessary.
    about this event: https://program.mch2022.org/mch2022/talk/XVBPNB/
    50 min
  • Attribution is bullshit - change my mind... (MCH2022)
    Borne out of a semi-flippant Twitter comment, this talk will take you on a journey across the benefits, pitfalls, and outright BS of attribution.
    Expect passionate opinions, trenchfoot inducing war stories, head+desk frustration, and a strong meme game.
    With this session, which is aimed at security practitioners, researchers, students, and anyone with an interest in cybersecurity, we hope to:
    • Highlight the value of decent threat intelligence
    • Establish why attribution can be valuable, but how it can be a distraction, or worse
    • Inform people who are interested in attribution and threat intelligence as areas of study how they can pursue it
    Borne out of a semi-flippant Twitter comment, this talk will take you on a journey across the benefits, pitfalls, and outright BS of attribution.
    Expect passionate opinions, trenchfoot inducing war stories, head+desk frustration, and a strong meme game.
    With this session, which is aimed at security practitioners, researchers, students, and anyone with an interest in cybersecurity, we hope to:
    • Highlight the value of decent threat intelligence
    • Establish why attribution can be valuable, but how it can be a distraction, or worse
    • Inform people who are interested in attribution and threat intelligence as areas of study how they can pursue it
    about this event: https://program.mch2022.org/mch2022/talk/ATVVN8/
    26 min
  • FreeSewing: sewing patterns based on code (MCH2022)
    Tired of clothing stores not having your size, or that you're stuck in between sizes? So was Joost de Cock, he didn't - and doesn't - like how clothing stores base their clothing sizes on an imaginary average person; every person has a different body. That got him to found FreeSewing: the open-source platform that translates custom measurements into well-fitting sewing patterns with code.
    The platform is working towards becoming the Wikipedia of sewing patterns, with new patterns being released every few months, plus a bunch of guides on how to sew. The platform also provides guides for designers and developers, to transform patterns into code.
    This system based on code allows not only for custom measurements, but also for tweaking the pattern (e.g. longer sleeves, or a crop top) and recycling parts of one pattern into another - whereas a traditional sewing pattern is based on the measurements of a perfect mannequin, which is then graded up and down for different body types, which is known to have many downsides.
    This talk will not be held by founder Joost de Cock himself, but by an enthusiastic contributor. He will gladly go more in depth on how the code works, common pitfalls, the motivation behind it and how it helps against the rise of fast fashion - maybe encouraging some to pick up sewing themselves?
    A platform that can make tailored sewing patterns, it sounds great - but how does it work exactly?
    It definitely is an upgrade from traditional sewing patterns. Making sewing patterns may sound easy: they are pieces of fabric, shaped in a specific way and sewn in a specific way. For example, a t-shirt pattern will have these parts: a front, a back and sleeves. But to figure out the right shape, the average pattern designer will make their design based on the shape of their perfect mannequin, and they grade it up and down for different body types. Adapting the pattern for a different shape can be a tedious task. That's where FreeSewing comes into play: sewing patterns aren't based on the measurements of one fit model, but they're parameters; they vary based on what the user puts into the system.
    And the platform doesn't just provide sewing patterns; it also has a lot of guides available, for general sewing, specific sewing patterns and even on how to code a pattern into the system. This makes it not just a platform for sewists, but also for designers and developers.
    So, enough about how cool I think it is, what exactly do I mean with "sewing patterns based on code"? FreeSewing is written in JavaScript and the technique is quite similar to how you would draw a traditional pattern: a bunch of lines for the right measurements, but now a system is drawing those lines for you. A line needs a beginning point and an end point, usually also points that determine the curve; the 'coordinates' of these points are based on the measurements.
    The sewing patterns aren't just based on custom measurements, but you can also tweak them however you'd like (and within what's possible), e.g. wanting longer sleeves, or a crop top. Another advantage of having code as a base is that you can 'recycle' pattern parts from one sewing pattern into another.
    Not just the sewing patterns are easily accessible online, but also the software needed to create the code: the core library and patterns are available both for NodeJS and the browser. The code and markdown content is hosted by [Github](https://github.com/freesewing/).
    I'm happy that this project wasn't created by a capitalist overlord, but by someone who wanted to change the world for the better. Now there are a lot of sewing patterns available for all types of bodies and I hope it will encourage more people to start sewing their own clothes. Sewing is difficult to learn, not to mention coding, but it's so worth it. Luckily FreeSewing has a vibrant community where there's always someone ready to help with problems. My goal is to share this enthusiasm with others and maybe encourage some to pick up sewing or help out with coding.
    about this event: https://program.mch2022.org/mch2022/talk/M9JWKM/
    32 min
  • Free children from the digital stranglehold (MCH2022)
    The current digital educational system is dominated by tech giants. Fundamental rights, like the privacy, freedom and sovereignty of children, parents and educators are insufficiently secured. Ed-tech is mainly closed source and full of vendor lockins. Products are either overpriced, harvesting data, or both. The time to replace surveillance capitalist based Ed-tech by ethical open source alternatives is now. And our coalition for fair digital education is going to do it.
    Private companies do not have the same interests as public institutions like schools. Schools do not have the time, knowledge or budget to hack their own IT environment together. Hence, BigTech and Ed-Tech fix this problem for schools, by offering services that have a very low price tag in euro's, but the actual payment is in data: meta data, "service"-data and user-data. DPIA you say? *(Detailed Privacy Impact Analysis)* That will achieve sort-of-legally compliant services at max. If only the authorities would actually bite, but alas, enforcement is lax, and four years of GDPR and the IT environment in schools is still riddled with privacy risks. Essential online services are out-of-scope of the DPIA's and purposes like "product improvement" (read: feeding AI and machine learning algorithms) is GDPR-Okay. If you or your kid goes to a 'Google school' and is forced to use a Chromebook, you'll be producing data to train Google, and you will be trained to love Google services. Consequently children won't develop core digital skills or a critical attitude toward digital services.
    Thus, there is a huge gap between core values of big tech companies versus public values in the educational system. Therefore, enforcement to make Big Tech embrace those public values will never be effective. ​​​​​​​That is why we need to build a school IT environment based upon public values: transparent, open source, privacy-by-design, decentralized, fair and respecting our digital sovereignty. Our coalition for fair digital education is going to build this. This is a huge project and a lot of work, so join us.
    about this event: https://program.mch2022.org/mch2022/talk/AZVEA8/
    50 min
  • ICS stands for Insecure Control Systems (MCH2022)
    Last April we won Pwn2Own Miami by demonstrating five zero-day attacks against software that is commonly used in the ICS world. ICS, or Industrial Control Systems, are systems that are involved with running an industrial process, for example in a factory or power plant. Our targets range from SCADA to HMI systems. During this talk we would like to share details about the competition and the vulnerabilities we found.
    ICS is an interesting field for security research. As a successful attack could have devastating results. Luckily the number of successful attacks that truly targeted ICS environments are scarce. At the same time this industry faces some difficult challenges, such as high availability requirements, old technology and a low security maturity.
    Pwn2Own Miami is an annual edition of the Pwn2Own competition, that focuses solely on ICS applications. Targets range from OPC UA implementations (on of the main communication protocol in ICS), to data gateways and SCADA systems. They challenge competitors to find zero-days attacks against any of the targets. Participants need to demonstrate their zero-days by compromising a target machine running the latest version of the application.
    Last year we participated in the Pwn2Own Austin edition, which focused on Enterprise applications, with a zero-day chain against the Zoom client. This year we decided to participate in the ICS edition. It was a close race, but ultimately we beat the competing teams and won this year's edition. We demonstrated 3 RCE's, one DoS and an interesting certificate verification bypass, which in total was good for 90 points and $90,000.
    about this event: https://program.mch2022.org/mch2022/talk/KW7LDS/
    44 min
  • RE-VoLTE: Should we stop the shutdown of 2G/3G to save lives?? (MCH2022)
    A lack of VoLTE standardisation breaks voice calling globally. Your brand new smartphone may not work because VoLTE is screwed up by manufacturers and carriers.
    Voice-over-LTE (4G), voice-over-NR (5G) and voice-over-WiFi have been standardized for years, but now that more and more 2G and 3G networks are shut down by operators, users discover their phones don't work anymore with basic voice calling. The cause is a massive mess in standardization, with a boatload of options and settings and vendors and carriers interpreting it differently, masked by fall-back to 2G and 3G and lack of "international roaming" agreements for VoLTE.
    Handset manufacturers decided to implement shortcuts (neglecting parts of the standards) or even worse, implementing white-lists with only mayor operators included, so you cannot switch operators anymore and are up for a big surprise while roaming in another country.
    The result: Even your brand new phone might be unable to provide voice calling in one country but work in another. Voice-calling might work if you're lucky, but you cannot reach 112/911, the eCALL system in your car fails after 2G/3G shutdown or you cannot receive an SMS you need for remote Two-Factor-Authentication while roaming in another country.
    It's such a disastrous mess, so should we stop the 2G/3G shutdown and get-it-fixed?
    This is a tale of a disaster still looming in most of Europe for Europeans, as 2G/3G still works as the fall-back mode of your device. As a result nobody noticed that VoLTE was screwed up.
    However many non-Americans roaming with their phones into the USA suddenly learn their brand new phone isn't working for voice-calls, as AT&T has shut down 2G/3G on July 1st 2022.
    Problems already did happen to users roaming into countries like India.
    Users who buy seemingly the same recent model of a supplier like Samsung or Apple, and think they are safe, might be up for a big suprise too. Months of testing needed per device was considered way too cumbersome and too expensive by many, so at best it was halfway done.
    Manufacturers decided to cope with it by curtailing the myriad of options and settings, included mobile-network-code white-lists or implement short-cuts (neglecting parts of the standards).
    With white-lists you suddenly are tied to an operator and changing your subscription from a major Mobile Network Operator to an MVNO, makes voice-calling on your brand new smartphone defunct, only allowing data communications working.
    The "advice" to complainers is just to use voice-apps, but these don't allow Emergency calls.
    eCALL devices built into cars that dial emergency numbers may work in your home country, but fail when driving in another land on your holiday.
    Roaming agreements between international carriers have up to now been made only between major operators in large countries, There are merely 50 international VoLTE roaming agreements actually working. If you are from a "small country" like Sweden, you're out of luck in the USA.
    Voice-over-LTE (4G), voice-over-NR (5G) and voice-over-WiFi have been screwed up by an unholy alliance of handset manufacturers, carriers, the GSM-Association and IMS-core vendors and standardization bodies, who couldn't decide to settle VoLTE down to a limited set of options and prescribe large scale compulsory plugfests and compatibility tests.
    Regulators have looked away, expecting the "magic of the market would resolve all issues".
    Some vendors have engaged in favoritism with white-listing or don't deal with MVNOs and MVNEs, as they don't order millions of devices.
    This talk explains the cause of the mess and highlights the problems lurking in your brand new device.
    It provides real problems, with devices and disfunctional VoLTE, collected in 2021/2022.
    We should ask the question whether the announced shutdowns of 2G/3G in most of Europe have to be stopped. Must device manufacturers and carriers be forced to clean-up their act now, and halt their anti-competitive practices and favoritism, before people die as they cannot reach 112/911 during an Emergency?
    about this event: https://program.mch2022.org/mch2022/talk/7TVHSD/
    30 min

About Chaos Computer Club - archive feed

From the publisher's feed

Der Chaos Computer Club ist die größte europäische Hackervereinigung, und seit über 25 Jahren Vermittler im Spannungsfeld technischer und sozialer Entwicklungen.