Chaos Computer Club - archive feed

Chaos Computer Club - archive feed

By CCC media teamTechnology
Download on the App Store

Chaos Computer Club - archive feed episodes

  • What have you done against covid (MCH2022)
    From complaining out loud about a televised government app-a-thon to being hired by the Ministry of Health, Welfare and Sport as lead developer RoHS running a team of devs to work on all the covid backend infrastructure exception routes and making sure no person is left in digital limbo in just under an hour.
    When late 2019 the first signs from China of the novel Corona virus came I was intrigued,
    During the first "lock down" in the Netherlands our Ministry of Health, Welfare and Sport created an app-a-thon . . and much hilarity ensued.
    As all geeks had seen . . nice ideas people . . but Apple and Google already have a standard agreed.
    And a lot of us "Dutch Hackers" where pretty vocal about it as usual.
    Meanwhile at "the ministry" a civil servant started hiring people from the Dutch hacker scene.
    Late December 2020 it came to their attention that there was some missing or ancient infrastructure in place for vaccine registration, not at all ready for the then upcoming vaccination landrush.
    14th of December I get a call . . can you clean your calendar for the year?
    Sure . . just over two weeks, one of them I had planned as holiday anyway to watch CCCongres talks. .
    Little did I know they meant clear agenda for 2021 .. and 2022 . . not 2020.
    This story takes you from getting very privacy and security aware infrastructure for registering the first ever Covid vaccination in the Netherlands built and tested in 3 weeks to the current state of the DCC infra up close and personal.
    about this event: https://program.mch2022.org/mch2022/talk/PHSMTF/
    47 min
  • Lightning Talks Saturday (MCH2022)
    Lightning talks are a 5 to 10 minute quick talk on an interesting subject. They can be with or without slides, and with or without proper preparation. if you weren't accepted in the main CfP, this is also a great opportunity to give an abridged version of your talk. These sessions will be available to sign up to later on, with details on the wiki.
    Lightning talks are a 5 to 10 minute quick talk on an interesting subject. They can be with or without slides, and with or without proper preparation. if you weren't accepted in the main CfP, this is also a great opportunity to give an abridged version of your talk. These sessions will be available to sign up to later on, with details on the wiki.Lightning talks are a 5 to 10 minute quick talk on an interesting subject. They can be with or without slides, and with or without proper preparation. if you weren't accepted in the main CfP, this is also a great opportunity to give an abridged version of your talk. These sessions will be available to sign up to later on, with details on the wiki.
    about this event: https://program.mch2022.org/mch2022/talk/BZ3Y7X/
    49 min
  • Reclaiming our faces (MCH2022)
    What are the risks and problems of face search engines like Clearview AI and PimEyes? Since institutional protection against these systems is failing us, how can we protect ourselves against this? Three people involved in the fight against biometric mass surveillance share their experiences and reflections. Come to this talk to exchange experiences, learn what tools there are for your protection, how to use them and how you can help stop the creep of mass surveillance technologies.
    Face search engines like [Clearview AI](https://reclaimyourface.eu/how-to-reclaim-your-face-from-clearview-ai/) and [Pimeyes](https://edition.cnn.com/2021/05/04/tech/pimeyes-facial-recognition/index.html) have all our faces and process our biometric data. They didn't ask us if we like their *service* and if they may use our data. Users of these search engines can now identify us anytime, anywhere.
    Since biometric data enjoy special protection under GDPR, we filed complaints in multiple European states. We report how data protection authorities did nothing for a long time and tell of the first successes. However, it became clear that GDPR does not protect against biometric surveillance.
    That's why we have joined forces to form the **[Reclaim Your Face](https://reclaimyourface.eu/)** campaign. Together, we call on the European Commission to strictly regulate the use of biometric technilogies in order to avoid undue interference with fundamental rights. In particular, we ask the Commission to prohibit, in law and in practice, indiscriminate or arbitrarily-targeted uses of biometrics which can lead to unlawful mass surveillance.
    The two face search engines are not the only examples of everyday biometric surveillance. However, it is difficult to track where else we are being monitored: There is a lack of transparency and oversight. Public authorities and private companies rarely report on their own what they have been up to. We share how we've used FOIA requests, among other things, to create a little more publicity.
    about this event: https://program.mch2022.org/mch2022/talk/SQQ3D9/
    29 min
  • OpenRAN – 5G hacking just got a lot more interesting (MCH2022)
    Many 5G networks are built in fundamentally new ways, opening new hacking avenues.
    Mobile networks have so far been monolithic systems from big vendors. Networks are rapidly changing to an "open" model that mixes software from specialized vendors, hosted in cloud environments.
    The talk dives into the hacking potential of the technologies and new interfaces needed for these open networks. We illustrate the security challenges with vulnerabilities we found in real-world networks.
    # Background #
    Mobile networks are undergoing a paradigm shift from single-vendor monoliths to open cloud environments. Telco software now comes from different vendors and is installed on commodity hardware.
    OpenRAN is introduced in many (not all) 5G network globally. Operators hope that OpenRAN will be more flexible and cheaper. But what about security?
    To make building blocks interoperable, OpenRAN comes with new interfaces, with often unclear security properties. OpenRAN also adds complex IT technologies, which come with their own hacking issues. Many components are run on Linux in Docker containers on top of Kubernetes, adding multiple layers of possible hacking interference.
    Mobile networks also become easier to test, including for pentesters with experience in web apps and cloud environments. This talk explores how we can best use this new accessibility.
    # What we discuss #
    *1. Technology overview.* Which technologies and interfaces are used in OpenRAN
    *2. Baseline security.* Which security measures are part of OpenRAN, and which gaps are left open
    *3. Pentest/hacking advice.* How do you test whether a network uses necessary security measures
    *4. Tales of caution.* Vulnerabilities we found in real-world networks
    about this event: https://program.mch2022.org/mch2022/talk/8BEFCG/
    45 min
  • Honey, let's hack the kitchen: (MCH2022)
    Attacks on cyber physical systems are perceived as necessarily complex and requiring significant time and resources. However, in the last couple years we have also observed the inverse: simple attacks where actors with varying levels of skill and few resources gain access to software and interfaces that control physical processes. These compromises appear to be driven by ideological, egotistical, or financial objectives, taking advantage of an ample supply of internet-connected cyber physical systems. This is sometimes concerning, for example when it is affects panels for controlling processes in a water facilities or manufacturing processes. Sometimes, though, it is absurd, such as when the critical systems actors claim to compromise are in fact toys or domestic appliances. In this talk, we will share a series of stories of success and failure involving low sophistication compromises on cyber physical systems. We will describe the different types of cases we have observed, what the actors did, and how you can reproduce them for good. At last, we will discuss to what extent these crimes of opportunity represent a risk to cyber physical systems and what we can do about it.
    In november 2021, I presented a version of this talk at a local non-profit event in Bergamo, Italy. For this event - NoHat - I focused on sharing the stories of low sophistication compromises we observed involving software used to control physical processes. However, for MCH I did some modifications in the title and the presentation itself to share not only the cases, but also how to reproduce them for good.
    The purpose of this talk is to share with the audience how actors without necessarily a lot of skills or resources are using very simple tools to hack cyber physical systems. I will do some experiments to show very quick results the audience can get reproducing these techniques so that they learn how to find these internet-connected cyber physical assets and notify the owners.
    The outline of the initial presentation was:
    • Introduction
    o Story: Hacked kitchen was supposed to be a gas system
    • Define low sophistication cyber physical compromises
    • (De)evolution of cyber physical threats
    o From state-sponsored to financial, and now opportunistic
    • Describe low sophistication compromises of cyber physical systems
    o Distribution and claims of exposed systems
    o Seeming actor motivations
    o Common actor techniques
    o Types of evidence (or lack of)
    • Low Sophistication Threat Actors Access HMIs and Manipulate Control Processes
    o Oldsmar, Florida modified HMI on water facility
    o Israel’s advisory on compromises to water facility systems
    o Solar energy and dam surveillance system
    o Hotel BAS
    • Amateur Actors Show Limited OT Expertise
    o “Train control system” was in fact a human resources tool
    o Second “train control system” controls toy trains
    o Website leaks claiming access to SCADA systems
    • Hacktivist and Researcher Tutorials
    o Two hacktivist groups share tutorials for finding and compromising cyber physical systems
    o Researchers have done too – including a couple examples, such as a recent script to identify tank gauges
    • Does this activity pose an actual risk to cyber physical systems?
    o Each incident provides threat actors with opportunities to learn more about OT, such as the underlying technology, physical processes, and operations.
    o Even low-sophistication intrusions into OT environments carry the risk of disruption to physical processes, mainly in the case of industries or organizations with less mature security practices.
    o The publicity of these incidents normalizes cyber operations against OT and may encourage other threat actors to increasingly target or impact these systems.
    • On the bright side…
    o There are safety methods in place that stop immediate computer instructions from modifying actual physical processes
     Engineering and human processes
     Missing security on the software side
    Additional Materials:
    Please find in this link our recent blog on this topic: https://www.fireeye.com/blog/threat-research/2021/05/increasing-low-sophistication-operational-technology-compromises.html
    about this event: https://program.mch2022.org/mch2022/talk/C9FANR/
    39 min
  • Digital Civil Disobedience (MCH2022)
    Greenpeace is a direct action organisation. We have been doing physical direct civil disobedience actions for 50 years now. Civil disobedience has always played an important part in evolving democratic society if you look for instance at womens’ voting rights, the civil rights movement in the US and de ‘klimaatspijbelaars’. The digital realm is becoming more and more important in all of our lives. That is why we are working on a research project on what digital civil disobedience can look like. This is something else than mere ‘clicktivism’. What are the differences and similarities of online and offline civil disobedience? How do you 'drop' a digital banner or how do we digitally 'occupy' a building or mine? During this talk we want to tell about this project and give you an insight look on how we prepare disobedient actions at Greenpeace.
    Greenpeace is a direct action organisation. We have been doing direct civil disobedient actions for over 40 years now. At Greenpeace we know our strength and our weaknesses when doing actions in physical spaces. We scale buildings and hang banners, we have blocked the petrol harbour in Rotterdam (multiple times) and we stop oil/gas rigs from operating. All these kinds of actions are part of a struggle for a healthy climate and safe planet to live on and so ideologically motivated.
    The right to protest is a fundamental European right, a right that is very dear to us and important when chased by the law. At Greenpeace we always look at new ways to do disobedient actions. This is why we started a research on how online actions can contribute to campaigns. The last few months we have been looking into the possibilities of digital civil disobedience actions. We looked at the risks, the actions and the possibilities it will bring. One thing we learned is that everyone we talk to about this topic is super excited.
    about this event: https://program.mch2022.org/mch2022/talk/J9PRJK/
    43 min
  • bug hunting for normal people (MCH2022)
    A series of isolated problems encountered when attempting to fuzz software, in this case Adobe Reader (DC), and hackish solutions to said problems. Constructing a fuzzing pipeline capable of finding real bugs by stringing together freely available tools creating the bare minimum of glue.
    Starting from target selection, moving over requirements for a given fuzzing campaign to smart input generation, briefly touching on scaling challenges and performance issues. This presentation describes a practical approach to creating a fuzzing pipeline with the purpose of finding real world bugs in closed source software, in this case Adobe Reader (dc). The approach taken is suitable for anyone with basic scripting capabilities, is easy to replicate, and leads to bug hunting capabilities without a doctoral degree or years of experience in vulnerability discovery.
    about this event: https://program.mch2022.org/mch2022/talk/HVQDNE/
    49 min
  • Everything is an input device (fun with barcodes) (MCH2022)
    If we consider technology sufficiently advanced indistinguishable from magic, then the closest we get to ancient magical glyphs are barcodes. In this talk, we will show how barcodes are not just simple numbers, but can be used to control the machines.
    If we consider technology sufficiently advanced indistinguishable from magic, then the closest we get to ancient magical glyphs are barcodes. In this talk, we will show how barcodes are not just simple numbers, but can be used to control the machines.
    In this talk we do a brief introduction into barcodes, the way they are built, their uses and their misuses. This will be illustrated with a couple of examples of misuses in the real world.
    After this, we will demonstrate how a common implementation of (barcode)-scanning is vulnerable to a deceptively simple attack, which can lead to some interesting results.
    about this event: https://program.mch2022.org/mch2022/talk/LFTLBD/
    31 min
  • The art of online discobingo (MCH2022)
    This presentation will includes insights in starting your own online pirate radiostation, the mathematics of bingo cards, keeping participants data up to GDPR standards, Fitbit-statistics, and the optimization of bingo winner-calculations. This presentation will also at one point include a guy in an ice cream cone costume with an offensive name, as well as an optional disco bingo party with songs supplied by visitors to the conference.
    As the first Covid lockdown made it impossible to continue hosting live events in pubs, many presenters and questioneers quickly adapted to hosting online quizzes. Slightly depressed by the notion that online quizzes would involve a great amount of cheating and the thought that participants would see it as an “okay substitute for the offline version”, I choose to develop an online event that would be impossible to cheat and would give people a unique experience, whilst still being a game that can also be played in pubs.
    When this presentation is held, there will have been at least 200 installments of DJ Cone Yo’s online Discobingo, with over 5.000 participants on all 6 continents, all from a laptop on a nightstand next to my bed. It proved to be an event accessible to both Children as well as high-level employees of companies such as Deloitte, PWC, Gemeente Amsterdam, and then some.
    Please note that this will not be a presentation on any personal accomplishment with this event. Because let’s be honest: it’s a guy doing digital conga shuffles in front of the webcam. However, during the development of this activity I learned how to build up an https online radio server with Icecast2, created calculation models in excel to manufacture unique cards, optimized this data to supply me predictive data to rapidly check results, and created a way to supply participants with all information, including unique cards, whilst living up to GDPR-standards. With this presentation I’d like to provide some inspiration regarding how to develop each of these things without any knowledge of programming and using some of the most basic pieces of software. Also: share the joy of bingo math.
    There is an option to also do a shared evening activity. People can supply songs for an evening discobingo which can be played in multiple locations at the same time. So if there are any restrictions still set, the radio stream can be played in tents or in smaller groups, and everyone that wishes to join can receive a unique card and play along. In the spirit of the event, people can even submit their own prizes to the bingo as to share them with others at the festival.
    And on a personal note:
    After visiting SHA2017 back when I was working as a campaign strategist for Bits of Freedom (where I got to design campaigns such as the Rijksveiligheidsdienst) I have thought about how amazing it would be to do a presentation at one of these events. Back then, me and a few colleagues specifically enjoyed a presentation on “how to start an escape room”. Doing something along these lines and sharing insights gained from developing entertainment is something I am good at.
    about this event: https://program.mch2022.org/mch2022/talk/PQXR8Y/
    45 min
  • Respirators, Runtime Errors, Regulations – A Journey into Medical Software Realization (MCH2022)
    Medical devices come in all shapes and sizes, and a great deal of them contain – or consist of – software. If they are faulty, they can kill. We’ll talk about different types and classes of medical devices, the regulations that try to ensure their safety and what all of this means for medical software projects.
    So you have a great idea for a medical product with software that will make the world a better place? It helps people to regain or improve their health, cope with a permanent condition or analyze their vital stats? That’s fantastic! What could possibly go wrong?
    History has shown that faults in medical devices can have disastrous consequences. Those products may cause severe injury, permanent damage, even death. In order to make sure that your product does not harm its users there is a bunch of regulations that you have to comply with. How does this affect your work?
    First we’ll take a look at where to find software in or around medical devices from embedded code to stand-alone sofware with AI. Then I’ll provide a few infamous examples of what went wrong (including a great talk about faulty software in pacemakers from CCC Camp 2019 – you know, that last great event before THE VIRUS).
    Then we’ll talk about the regulatory part, especially at the EU Medical Device Regulation and what it means for planning, implementing and maintaining software for medical products (my favourite topic: traceability. ;-) ). It’s also of interest for non-EU participants because many of the regulations are ISO-harmonized.
    about this event: https://program.mch2022.org/mch2022/talk/V77FEC/
    49 min

About Chaos Computer Club - archive feed

From the publisher's feed

Der Chaos Computer Club ist die größte europäische Hackervereinigung, und seit über 25 Jahren Vermittler im Spannungsfeld technischer und sozialer Entwicklungen.