Chaos Computer Club - archive feed

Chaos Computer Club - archive feed

By CCC media teamTechnology
Download on the App Store

Chaos Computer Club - archive feed episodes

  • HomeComputerMuseum, the making, the challenges and the importance. (MCH2022)
    The HomeComputerMuseum's idea originated in 2016 and opened the doors in 2018. Since then, we faced several challenges but we came out on the other end and became one of the largest museums about computers with an award-winning social impact, an enormous social network, collaborations over the whole world and even are of essential importance to the Dutch government. The talk is about the original concept, how we build it to what it is now.
    The original concept of the HomeComputerMuseum is a hands-on computermuseum dedicated to the home computer or connected computers. Because a museum is a terrible businessplan I decided to create a few services, like repairs, selling overstock and reading old media. For this could not be done by one person, I decided to have people with autism help me by simply not putting a label on them. The businessplan was created and eventually a building was rented. The entire museum is physically built in 7 days (not even kidding) and we were off to a very rough start and even balancing on the edge of bankruptcy. However, we managed to stay afloat and we even moved to a much better and bigger building where we enjoyed for a full month before corona hit the museum. As an unsubsidized museum and without big sponsors we were faced a brand new challenge. But we overcame and grew stronger than ever.... (and then there's plenty of story to tell more).
    about this event: https://program.mch2022.org/mch2022/talk/XTJRMK/
    52 min
  • Electronic Locks: Bumping and Other Mischief (MCH2022)
    Modern electronic locks are often optimized for cost, not security. Or their manufacturers don’t do security research. Or they ignore it.
    For whatever reason, many current electronic lock systems are susceptible to surprisingly simple attacks. We’ll look at some of them, and at the underlying basics, so that you can do your own research.
    In this talk, we look at a number of modern electronic locks and their security flaws. Surprisingly many current systems are susceptible to very simple attacks, like the equivalent of using bump keys. Of course, there are electronic and/or SW-based attacks, too.
    We’ll look at some of them, and at the underlying basics, so that you can do your own research.
    Some of the problems have been fixed by manufacturers, but typically only for future production runs, so you will get some practical advice on how to test your own hardware for these critical flaws.
    about this event: https://program.mch2022.org/mch2022/talk/KBVXRU/
    30 min
  • Hacking the Quincy Drawing Robot (MCH2022)
    This session will go over my journey to hack the Quincy drawing robot. This is a cheap 3-axis drawing robot, that uses a proprietary "closed" system. I wanted to hack this robot to draw Pokémon's for my son. I will explain how I deciphered the file formats, figured out how the robot could be controlled (which needed some very very difficult math!) and the software I made to create your own drawings.
    BONUS: At the end of the session you can WIN one of these Quincy Robots!!!
    This session will explain step by step the process I took to decode the proprietary file formats, using some simple python coding. This will give you an insight in general how you can try to decode file formats that are not documented.
    Besides understanding the files, the math behind controlling this robot turned out to be very complicated. I will explain the difficulty and if you are a Math Nerd you can see if you could solve this difficult challenge.
    Finally I will show the software I made to create your own drawing files.
    about this event: https://program.mch2022.org/mch2022/talk/787GY3/
    25 min
  • Reverse engineering the Albert Heijn app for fun and profit (MCH2022)
    The Albert Heijn, everyone (in the Netherlands at least) knows it. It's the largest supermarket chains here. They have a very extensive API. This API is not public unfortunately, but in this talk I will show you how you can reverse engineer the app to figure out how the API works and how we can use it to our advantage.
    The Albert Heijn, everyone (in the Netherlands at least) knows it. It's one of the largest supermarket chains with a very extensive API. This API is not public unfortunately, but in this talk I will show you how you can reverse engineer the app to figure out how the API works and how we can use it to our advantage.
    AirMiles, tracking stamps for the current saving program, receipts, personal discounts. All these can be viewed or tracked within the Albert Heijn app. But, what if you want to track your savings over time? I want my pretty Grafana dashboard gosh darn it!
    This talk will go into the story behind randombonuskaart.nl (a website for a 'random' bonuskaart right when you need it), talk about how your private API is not really private and how we can use the Albert Heijn API to track various data and do tedious actions for us.
    The knowledge gained from this talk can also be used with other apps, but the Albert Heijn app proves for a very good example.
    about this event: https://program.mch2022.org/mch2022/talk/F88JGH/
    30 min
  • Don't turn your back on Ransomware! (MCH2022)
    Ransomware is making a comeback and attacking us all! Learn and sharpen your blades in order to defend against this multi headed monster! There’s a lot to learn from every ransomware attack. By demounting every bit of the attack and looking at every stage there’s much to gain for setting up proper detection and other defence techniques
    Remember those times when a popup appeared on your screen with the message to immediately transfer an amount of bitcoins to retrieve your files? Ransomware is still a serious threat to a lot of people and organisations and nowadays using more and more advanced techniques to target you and steal your data. This talk will tell us what Ransomware actually is, who’s writing the code and making money out of it, it shows us a bit of the Ransomware history and what types were out there, to better understand what we’re dealing with. And explain all of the ransomware attack stages and what you can do in terms of detection and defence inside your security operations.
    about this event: https://program.mch2022.org/mch2022/talk/8JETCV/
    28 min
  • Repair for Future (MCH2022)
    This discussion will start with a brief summary on the history of repair initiatives. We can report about our personal repair activities during the pandemic. Subsequently, I'll outline the achievements of the right to repair movement and we can discuss ideas for the future.
    During a peak in public interest, the repair café movement was caught by the covid pandemic.
    Many local initiatives adapted quickly and opened online repair consultation hours. In the german-speaking countries, a monthly central online repair café was established. I'll give a lessons-learned about the experiences and limits of these online activities.
    The political right to repair movement has brought many interesting improvements, for example the french repairability index or the European ecodesign directive. I'll talk about them and what else is to be expected in the near future.
    This is in interactive discussion format, so ideally I'll only present a few facts and guide through topics while the audience chimes in with their personal experiences and questions.
    Slides: https://pads.schaffenburg.org/p/Repair-for-future-MCH
    about this event: https://program.mch2022.org/mch2022/talk/ZNJYHC/
    47 min
  • Taking Action against SLAPPs in Europe (MCH2022)
    SLAPP suits (strategic lawsuits against public participation) are nuisance lawsuits designed to get journalists, activists, historians, whistleblowers and others to keep quiet. This kind of lawfare isn't new, but there is an increasing focus on the issue in Europe, with new legislation coming. Here's where you find out more.
    You receive a threatening letter from a major law firm, probably based in London, trying to stop your reporting, or your activism, threatening you as an individual as well as the organisation you are affiliated with - congratulations, you've just been SLAPPed.
    Strategic lawsuits against public participation (SLAPPs) are on the increase worldwide, and Europe is beginning to take notice. Lawyers' associations in Italy and Croatia report hundreds of nuisance suits being laid against journalists. In Hungary, Poland and Slovenia, the state and its allies are SLAPPing opponents - journalists, anticorruption activists, LGBTI+ rights advocates - with impunity.
    Litigation has been turned against the activist community, oligarchs try to silence debate and Eastern Europe has become the new home of SLAPP-based oppression, as politics slide into autocracy and leaders stamp down on dissent.
    Blueprint is part of an 11-country coalition working on the ground to train lawyers to help the victims of SLAPPs strike back. We're currently developing a curriculum from scratch, drawing on European human rights principles and local knowledge.
    If you want to understand the European situation better, or if you have experience of SLAPPS and can help us understand what kinds of legal training and other defences are useful to civil society, we'd love for you to join this conversation.
    about this event: https://program.mch2022.org/mch2022/talk/ZUYKEC/
    49 min
  • How I made the municipality pay a 600.000 euro fine for invading your privacy (MCH2022)
    When gathering data for public services becomes privacy infringement and what you as a citizen can do about it. Or: How I made the municipality pay a 600.000 euro fine for invading your privacy.
    In September 2017 The Municipality of Enschede started tracking visitor movements in the city center 24/7 by registering their mobile phones WIFI MAC addresses. Is this an infringement on our privacy, even when the underlying identities remain concealed?
    In September 2017 The Municipality of Enschede started tracking visitor movements in the city center 24/7 by registering their mobile phones WIFI MAC addresses. Is this an infringement on our privacy, even when the underlying identities remain concealed? Yes it is, claimed speaker and privacy activist Dave Borghuis. After a 4 year process the dutch DPA agreed and Enschede was charge a massive fine for its infringement. Now, can we learn from this case? Where does or should our privacy start? And what can we, as citizens, do to protect our freedom to move about in privacy?
    Read more on my blog https://daveborghuis.nl/wp/wifi-tracking/
    about this event: https://program.mch2022.org/mch2022/talk/LQRMFA/
    27 min
  • It's not just stalkerware (MCH2022)
    Stalking is unwanted and/or repeated surveillance by an individual or group toward another person. But what is the impact of tech companies making it easier to do this with the development of technology? In the news, we hear about the increase in stalkerware found on devices or scary government spyware. But it’s not just that, there are so many more common tools used by stalkers.
    From September 2020 to May 2021, the number of devices infected with stalkerware increased by 63 percent, according to a study by Norton Labs. But stalkerware is not what I encounter most when I get contacted by stalking victims. Almost anyone can become a victim of stalking; stalkers do not just target celebrities. Sometimes they are ex-partners known to the victim, other times they may be a casual acquaintance, or just a simple stranger. With stalkerware, the actor needs access to the device or needs to persuade the victim to install something. In cases where the stalker is a (ex-)partner, that might be doable. But in other cases, it is easier to gain access to the accounts of the victim, gather information about the victim from social media, or use tracking devices (looking at you Apple and Tile) to follow the victim. Tech companies develop new apps and gadgets seemingly without thinking about other ways these can be used. And they end up making it easier to stalk someone. But what can we do about this problem? Should we lower efforts hunting stalkerware and help victims gather evidence? Or can we do something else.
    about this event: https://program.mch2022.org/mch2022/talk/THP7HG/
    26 min
  • Climate Crisis: The gravity of the situation. What is going on? (MCH2022)
    Goal is to discuss the gravity of the situation and create shared set of ideas on what is likely coming at us.
    We will do a Threat Modelling exercise around the climate change topic. Via a collective mind mapping exercise we will create a shared mental model and identify the things that will happen and how they will affect various people at various locations.
    Goal is to discuss the gravity of the situation and create shared set of ideas on what is likely coming at us.
    We will do a Threat Modelling exercise around the climate change topic. Via a collective mind mapping exercise we will create a shared mental model and identify the things that will happen and how they will affect various people at various locations.
    about this event: https://program.mch2022.org/mch2022/talk/UCSKRM/
    2 hr

About Chaos Computer Club - archive feed

From the publisher's feed

Der Chaos Computer Club ist die größte europäische Hackervereinigung, und seit über 25 Jahren Vermittler im Spannungsfeld technischer und sozialer Entwicklungen.