Chaos Computer Club - archive feed

Chaos Computer Club - archive feed

By CCC media teamTechnology
Download on the App Store

Chaos Computer Club - archive feed episodes

  • Screaming into the void: All e-signatures in the world are broken! (MCH2022)
    E-signatures in your country are insecure.
    They have been hacked 10 years ago.
    Everyone knew that but no one wanted to talk about it since there is no easy fix.
    We decided to create a PoC and poke the government with it.
    This is a story on what happened.
    ⭐ PoCs included ⭐
    Electronically signed documents were a great relief to organizing our daily life during the pandemic. They have actually been helping us for many years (depending on the country).
    It's been known for some time that **dynamic content + e-signatures = trouble**, but we were surprised that no one has really done anything about it.
    In 2021 we got tired of explaining the vulnerability each partner that sends in a vulnerable asice for signing, so we created multiple practical PoC that allow you to modify content of e-signed documents post-signing.
    Some of these PoC work against many countries. And there is PoC for every single country.
    - What is the actual impact?
    - Why is no-one fixing this?
    - Can we even fix it?
    - What are we gonna do about it then?
    about this event: https://program.mch2022.org/mch2022/talk/TW9ECH/
    29 min
  • Running a Domain Registrar for Fun and (some) Profit (MCH2022)
    Ever wondered what happens behind the scenes when you click buy on that domain for a new side project that'll definitely happen (you will get to it eventually, right)? Well this is the talk for you! We'll cover all the extremely cursed details of how exactly one sells and manages a domain, the standards for this (or lack thereof), and some pointers for how you could get started managing your own domains directly, if you're not completely put off by this talk's contents.
    Back at the start of lockdown in 2020 I think we where all a bit bored at home with not much to do; well, me and a friend decided it would be a good idea to start a domain registrar (big mistake, big, huge). This is the tale of how that went, what we learn, and why you might not want to do it yourself.
    We'll cover the technical aspects of how a domain is actually managed by your registrar, touch on the absolutely crazy business structures of the domain world with the likes of ICANN and friends, and how we ended up in this situation. Some of the standards are extremely cursed, some are extremely old, most are both. We'll also cover more recent developments in the domain space, such as the move from WHOIS to RDAP, and improvements in DNSSEC deployment.
    And finally after all that if you decide that somehow this is something you want more of in your life we'll give some pointers for how one might setup their own registrar, especially if they want to take greater control of their own domains, or just have some fun.
    about this event: https://program.mch2022.org/mch2022/talk/RETGE7/
    51 min
  • Literally Hacking the Planet: How Earth Systems Models Work (MCH2022)
    People have been modeling different parts of Earth's systems for decades, on different scales and with different goals from short term weather forecasting through actuarial risk prediction to long term climate models. In this talk I'll explore some of the typical models, methods, data formats, infrastructure layouts and design assumptions that go into such models, and discuss some low hanging fruit available to improve them.
    Earth is a pretty complicated system, consisting of numerous sub-systems operating at different time and energy scales. All the systems are strongly coupled. These include the atmosphere, oceans, freshwater, cryosphere and biosphere, all of which can be further subdivided by various schemes.
    The problems facing people trying to model these systems are numerous: there's a lot of data, all of it is bad, most of the code is written in Fortran, and all of it is horribly slow.
    To make matters worse, modeling Earth is computationally intractable without some simplifying assumptions. For instance, if your global grid for weather prediction has "pixels" that represent more than 16km², the physical parameterization can't "see" convection, so you miss most storms. And yet somehow people manage.
    In this talk, we'll start with a brief introduction to how some Earth systems work, describe some parameterizations, and then look at different free software/open source models operating under different domains, assumptions, and scales. Finally, we'll do a quick review of some of the many places where there is room for improvement.
    about this event: https://program.mch2022.org/mch2022/talk/TKTHUG/
    49 min
  • The tooling ecosystem that adds joy to KiCad (MCH2022)
    A number of people have built wonderful and useful tools to make the life of KiCad users easier. cpresser and Kliment are here to give you a tour of a number of the most useful addons, and show you what they're good for and how they can improve your life.
    We will go through a number of tools that people have built into the KiCad ecosystem - you may have used some of them, but a surprising number of KiCad users aren't aware they exist. We're here to fix that. We'll show you how to make your boards have fancy labels, how to get an interactive assembly guide for your designs, how to easily pack a bunch of boards in a production panel, how to automatically generate footprints, how to make your PCBs fit the real world, how to not repeat your effort when making lots of the same circuit, and how to not make terrible mistakes and lose your work. It will be a wild tour, but you'll have much more fun with your PCB design work afterwards.
    about this event: https://program.mch2022.org/mch2022/talk/T8XRKC/
    29 min
  • Wired Norms: Inscription, resistance, and subversion in the governance of the Internet infrastructure (MCH2022)
    Warning (but don't be afraid): this talk contains an overarching theory of the workings of Internet governance (with an emphasis on human rights)!
    The rules of the road for the Internet infrastructure are designed in different governance bodies, such as the Internet Engineering Taskforce (IETF), the Internet Corporation for Assigned Names and Numbers (ICANN), and in Regional Internet Registries (RIRs).
    I will showcase how Internet governance institutions are tied together through 'the infrastructural norm of interconnection'. This concept helps explain how Internet governance works and why many social and legal norms, such as human rights and data protection, get resisted and subverted in the governance of the Internet infrastructure.
    This talk is the outcome of 6 years participation in and research of Internet governance institutions and processes, and is suitable for both issue matter experts and people who never heard of Internet governance before.
    The entanglement of the Internet with the daily practices of governments, companies, institutions, and individuals means that the processes that shape the Internet also shape society. For this talk, I studied the norms that shape the Internet’s underlying structure through its transnational governance. Norms are the ‘widely-accepted and internalised [sic] principles or codes of conduct that indicate what is deemed to be permitted, prohibited, or required of agents within a specific community’ (Erskine and Carr 2016, 87). Internet governance is the development, coordination, and implementation of policies, technologies, protocols, and standards. Internet governance produces a global and interoperable Internet functioning as a general-purpose communication network in transnational governance bodies. I examine four cases of norm conflict and evolution in three key Internet governance institutions: the Internet Engineering Taskforce (IETF); the Internet Corporation for Assigned Names and Numbers (ICANN); and the Réseaux IP Européens Network (RIPE).
    I show how social and legal norms evolve and are introduced, subverted, and resisted by participants in Internet governance processes with distinct and dynamic values and interests, in order to develop policies, technologies, and standards to produce an interconnected Internet. I leverage notions and insights from science and technology studies and international relations to illuminate how a sociotechnical imaginary—the combination of visions, symbols, and futures that exist in groups and society—architectural principles, and an entrenched norm function as instruments of metagovernance in the Internet infrastructure. This way, I demonstrate how a sociotechnical imaginary, values, and norms facilitate, instruct, and evaluate the norm setting processes in Internet governance.
    This talk is empirically grounded in the analysis of mailing lists; technical documents; policy documents; interviews and the extensive observation of governance meetings. I have operationalized this analysis using the following methods: quantitative descriptive analysis; network analysis; quantitative and qualitative discourse analysis, as well as in participant observation, including semi-structured interviews and ethnographic probes.
    The aim of this talk is to show how Internet governance happening in multistakeholder bodies, what I call private Internet governance, solely functions to increase interconnection between independent networks. In this process, the introduction of social and legal norms—such as human rights principles and data protection regulations that might hamper increased interconnection—is resisted by significantly represented stakeholders in the process. Ultimately, I argue that while the sociotechnical imaginary and architectural principles serve to legitimize this governance ordering, the entrenched norm, what I call the infrastructural norm that transcends singular institutions, guides the distributed private governance regime.
    The infrastructural norm of voluntary interconnection plays an instructing and evaluating role in the process of norm development and evolution in private Internet governance. The infrastructural norm is embedded in its institutional configuration, technological materiality, economical incentives, and supranational interest, and ties the private Internet governance regime together. In conclusion, I posit that the private Internet governance regime is designed and optimized for the narrow and limited role of increasing interconnection. As a result, the governance regime resists aligning Internet infrastructure with social or legal norms that might limit or hamper increasing interconnection.
    about this event: https://program.mch2022.org/mch2022/talk/GUVANG/
    46 min
  • Keep Ukraine Connected (MCH2022)
    In March 2022 the Global NOG Alliance (GNA) started the Keep Ukraine Connected task force to help network operators in Ukraine during and after the invasion. These are our experiences. A simple idea turned into an interesting logistics puzzle with a steep learning curve into customs rules.
    What started as a simple idea ("Our goal is to help network operator groups, I'm sure there is more that we can do than hosting their websites and email when there is a war going on) turned into a global aid campaign. We have shipped a truck full of network equipment to Ukraine, and that was only a tiny part. Many companies and individuals from around the world have donated money, hardware and software to help the Ukrainian network operators. Everything from WiFi access points and PoE switches to be used in the bomb shelters to full-rack core routers for rebuilding their infrastructure.
    In the end the logistics are the hardest part. Finding warehouses to temporarily store the donated hardware to getting help shipping equipment across borders and through complicated customs rules (network devices are dual-use goods, and convincing customs officers that a truck full of gear qualifies as humanitarian aid can be a challenge…)
    about this event: https://program.mch2022.org/mch2022/talk/QUFG7J/
    33 min
  • What if locks could talk; what stories would they tell? (MCH2022)
    Most security implementations leak information, mechanical security is no different. It takes sharp eyes, a soft touch, and a good hearing to distinguish between information and noise. In this talk we will go in depth on how locks works, and how we can persuade them to disclose their secrets, and open them without damage.
    The Open Organization of Lockpickers (Toool) is a group of nerds obsessed with mechanical security. We create, collect, take apart, discuss, and attempt to defeat locks. While we are known for lockpicking, there are many other techniques for opening locks without damage.
    This talk will focus on the language of the locks, the side channels in mechanical security systems. We will start with binding order, the mechanism to isolate the locking elements, and exploit them one by one. Then we will discuss a wide variety of other methods of gathering information and opening locks. Most of these methods are not practical, but working them out gives us great joy, and we would like to share the highlights with you.
    about this event: https://program.mch2022.org/mch2022/talk/ACWT8Y/
    46 min
  • M̶a̶y̶ Will Contain Climate Change (MCH2022)
    A multi-disciplinary lecture and follow up discussion about sustainability from the hacker perspective. It will combine the state of the art scientific knowledge and evidence with observations on the cultural dynamics of the hacker community. It is the continuation of the series started at OHM 2013, SH2017, Balccon 2019 and Bornhack 2019
    Climate change, habitat and biodiversity loss, environmental pollution and other consequences of the current globalized society are here to stay and will get worse in the near future. In this talk, we will explore the known, expected and possible technical, environmental, social, economic and political changes that we will be facing in the next decades. This talk will approach the problem from the hacker / maker perspective. What can and will the impacts be on technology, privacy, communication, openness, communities and most important of all, Aliexpress shipments? What can we, as the hacker community, do to prepare ourselves and the communities around us to be robust and resilient to those changes? What can we do to reverse the course of these changes? Do not expect a prepper talk (okay, just a tiny bit), but rather a discussion based on empirical observations and scientific insights from a wide variety of academic disciplines. After the lecture a informal discussion session will be organized.
    about this event: https://program.mch2022.org/mch2022/talk/U8AEE9/
    46 min
  • Hacking the genome: how does it work, and should we? (MCH2022)
    Building on the very well attended DNA presentations ("DNA: The Code Of Life") at SHA2017, this talk will cover:
    * A brief recap what DNA is and how it works
    * It is surprisingly digital!
    * How reading DNA is within 'pro-sumer' reach now
    * (I might bring a live demo for after the talk)
    * An overview of DNA editing technologies (offline, and online: on living organisms)
    * Including the famous CRISPR-CAS, but also newer variants
    * How does such editing actually work in a lab?
    * The surprising lack of a definitive link between most DNA mutations and any effect
    * Could you hack your DNA? Will people start doing this?
    * Should we try to stop them?
    * Wild speculation on what this might mean for the future
    The goal of this presentation is to provide real non-hyped information on what DNA editing is and what it might achieve. And since we are hackers, I hope to explain how a hackerspace could start reading DNA right now with USB-powered hardware. And finally, since no hacker can resist tinkering: could you hack your own genome, or your cat's, or improve on your favorite plant?
    Building on the very well attended DNA presentations ("DNA: The Code Of Life") at SHA2017, this talk will cover:
    * A brief recap what DNA is and how it works
    * It is surprisingly digital!
    * How reading DNA is within 'pro-sumer' reach now
    * (I might bring a live demo for after the talk)
    * An overview of DNA editing technologies (offline, and online: on living organisms)
    * Including the famous CRISPR-CAS, but also newer variants
    * How does such editing actually work in a lab?
    * The surprising lack of a definitive link between most DNA mutations and any effect
    * Could you hack your DNA? Will people start doing this?
    * Should we try to stop them?
    * Wild speculation on what this might mean for the future
    The goal of this presentation is to provide real non-hyped information on what DNA editing is and what it might achieve. And since we are hackers, I hope to explain how a hackerspace could start reading DNA right now with USB-powered hardware. And finally, since no hacker can resist tinkering: could you hack your own genome, or your cat's, or improve on your favorite plant?
    about this event: https://program.mch2022.org/mch2022/talk/Y898KK/
    50 min
  • Bring Your Own IDentity (MCH2022)
    Thanks to DNSSEC and DANE, it is possible to automatically verify [email protected] identities by checking with domain.name servers. The real problem however, is integration with existing protocols, instead of inventing something completely new and perhaps web-only. The purpose of our work on Realm Crossover mechanisms has been to design generic solutions that extend many different application protocols, without changing their protocol specs.
    For clients, being able to control an online identity is not just a cool matter of adding their domain name at the end. It also means that they control how long the identity exists, if it is an alias, if it can be a group account with members that they control. (We made identity and access control libraries to support all that, along with identities that are only usable until a timeout, from a certain remote domain, under a particular communication topic, and so on.)
    For servers, being able to authenticate users from any domain is an answer to many questions that otherwise stagnate:
    * Why does every HTTP server want us to create an account under its domain, instead of letting us use our own?
    * Why do we constantly need to confirm our email address by clicking links?
    * Why not authenticate SMTP senders and subject others to the most stringent spam filtering?
    * Why not publish a mailing list archive in IMAP, available only to subscribers and searchable with their own tooling?
    * Why not use AMQP as an automation-friendly document push protocol with authenticated senders for form submission, bill processing, blog publications, document archiving, ...
    * Why not share your MQTT dataflow with external parties, so they don't need to keep a web page open to be notified about, say, a newly posted document?
    * Why not share your PGP keys and contact information in your own LDAP directory but with access control to decide who may see what?
    All these questions stagnate on problems like *You would need to have accounts for all users in the World*. So that is what we solved in this project.
    This project expands the usefulness of many protocols by changing the way their implementations handle authentication; instead of local accounts, they follow a backlink to the client's domain. We designed and built the extensions needed for the backend, and made a few first implementations. We are hoping to show the usefulness of adopting these ideas in your own tooling.
    We present a number of generic mechanisms for Realm Crossover:
    1. SASL tokens can be relayed to a Diameter server under the domain.name;
    2. Kerberos supports Realm Crossover, and a keying handshake can do this on-demand;
    3. X.509 certificates and PGP keys can be assured with DANE-akin structures for clients or by a lookup in an LDAP server for domain.name.
    For each, some form of domain-owned identity provider is run to assert identity when an external service needs it. The level of security is a matter of the user and their domain.name; an external service should not have to force down the security level of the client's domain.
    These three Realm Crossover mechanisms cover the majority of application protocols, the notable exceptions being the oldest ones, like Telnet, FTP and HTTP. Specifically for HTTP, we have defined an authentication mechanism that adds SASL; this means that new security mechanisms can be defined in SASL, where it benefits many protocols; it also means that authentication shifts from the HTTP application to the server, where the coding environment is better suited for such responsibilities.
    We end with a demo, showcasing a useful authentication flow:
    * Client desktop, with FireFox and a HTTP-SASL plugin
    * Server domain, running Apache with HTTP-SASL module under an independent domain
    * Server identity client, using Diameter to relay SASL to the Client Domain
    * Client Domain, running an identity provider with SASL over Diameter
    about this event: https://program.mch2022.org/mch2022/talk/NMNWQB/
    49 min

About Chaos Computer Club - archive feed

From the publisher's feed

Der Chaos Computer Club ist die größte europäische Hackervereinigung, und seit über 25 Jahren Vermittler im Spannungsfeld technischer und sozialer Entwicklungen.