Chaos Computer Club - archive feed

Chaos Computer Club - archive feed

By CCC media teamTechnology
Download on the App Store

Chaos Computer Club - archive feed episodes

  • Detecting Log4J on a global scale using collaborative security (MCH2022)
    Utilizing collaborative security to collect data on attacks we were able to detect Log4J in a quite unusual but effective manner. We'll show you how CrowdSec enables the entire infosec community to stand together by detecting attempts to exploit a critical 0day, reporting them centrally thereby enabling anyone to protect themselves shortly after the vulnerability was made public. The unusual part is that this is done using FOSS software and by analyzing logs of real production systems but in a way that doesn't compromise the anonymity of anyone (except the attacker, of course) and doing so with a reliable result where poisoning and false positives are almost impossible. Too good to be true? Come by and judge for yourself!
    The objective with the talk is to inspire the audience to understand why the world needs to think differently towards the threats of cyberattacks from criminals and which advantages it has when you’re really utilizing the power of the crowd.
    Basically we’ve been doing it wrong until now by thinking that all the world’s problems can be solved by throwing money at them. Guess what: They can’t. Defending against hackers is a full time, complex task that requires a lot of complex tasks to be carried out in the same order and same way every time to be effective. That’s difficult to do so in order to make it more doable we should try working together. CrowdSec is FOSS software that does exactly this by enabling users to share information about current attacks by parsing log files and sharing basic information (anonymously) about the attack (source ip, timestamp, IoC) with the crowd.
    CrowdSec could be perceived as a modern form of Fail2ban, though for Cloud and container-based infrastructure as well and capable of taking way more advanced decisions a lot faster. Mainly, it’s using a decoupled and distributed approach (detect here, remedy there) and an inference engine that leverages leaky buckets, YAML & Grok patterns to identify aggressive behaviors. It acquires signals from various data sources like files, syslogd, journald, AWS Cloudwatch and Kinesis, Docker logs and Windows Event Log, normalizes them, enriches them to apply heuristics and triggers a bouncer to deal with the threat, if need be. Since it’s written in Go, it’s compatible with almost any environment, fast in execution and ressource conservative.
    To make sure signals are generally trustworthy we’ve implemented a reputation engine. Not only don’t we want any false positives - we also don’t want data to be poisoned. This is taken care of by a trust-ranking system where we assign a trust to each agent that will grow over time as the agent provides reliable signals. In this process both persistence and consistency is taken into account. In this process both persistence and consistency is taken into account. When an ip is voted for, it needs a certain amount of points based on the trust rank of each agent that has reported the ip. This system makes it expensive to poison collected data. Not only does it take a long time to reach a trust rank that makes any real difference - also diversity of AS NNumbers are being taken into account as well. The outcome of this is a reliable blocklist that’s constantly redistributed to network members in order to achieve a form of digital herd immunity. An ip caught aggressing WordPress sites will quickly be banned by all members who subscribed to the WordPress defense collection.
    While CrowdSec is in charge of the detection, the reaction is performed by “bouncers” that aim to be deployable at any level of the applicative / infrastructure stack :
    via nftables/iptables/pf based on an IP set
    via nginx/openresty LUA scripting
    via a Wordpress plugin
    via a general PHP/Python/JS bouncer that works with all applications written in those languages
    on Cloudflare or Fastly via our bouncer that integrates with the provider’s API
    on AWS WAF via our bouncer that integrates with AWS’ API.
    .. or in many other ways. Over time the possibilities will increase as the application design basically supports anything.
    Bouncers can enforce several types of remediations, like blocking, sending a captcha, notifying, lowering rights, speed, sending a 2FA request, etc.
    This approach, combined with a declarative configuration and a stateless behavior, makes it an efficient tool to enhance the security of modern stacks (containers, k8s, serverless and more generally automatically deployed infrastructures).
    We are committed to building a strong community, with all that it implies :
    a public hub to find, share and amend parsers, scenarios, and blockers
    permissive open-source license (MIT) to stay business-friendly
    and overall a strong commitment to transparency and community-first mentality, by tooling and behavior
    In my talk I will dig into the technical nitty-gritty part of CrowdSec, the architecture and concepts and focus specifically on how we managed to collect data from live Log4J exploitation attempts using the crowd and how efficient this strategy turned out to be. CrowdSec is still collecting data and tracking the result on https://crowdsec.net/log4j-tracker/
    The bigger the CrowdSec community becomes, the better protection against cyber criminals. So I really want to inspire the audience to engage in CrowdSec either by installing and using the software, to contribute documentation or code - or all of them. For the good of everybody!
    Currently CrowdSec is collecting data from more than 45.000 agents in 158 countries. Each day more than 3M signals are collected. Over the last more than a year over 2.4M malevolent ips have been detected and verified.
    about this event: https://program.mch2022.org/mch2022/talk/DWKYMM/
    29 min
  • The Best Worst Thing (MCH2022)
    This is a submission for a keynote talk at MCH2022. The Internet is both a familiar, comfortable place as well as a bottomless rabbit hole you can lose yourself in. The Internet has always been like this from its inception, the difference now is the scale and consequences are almost immeasurable - and it tests the limits of human imagination. When you look into the mirror of the Internet what you see reflected back depends on what you are looking for. It has become largely a reflection of yourself.
    Some inventions are so good that they change the world. When a new innovation is useful enough, we no longer want to live without it – and once a technology is practical enough, it soon becomes compulsory.
    Electrical networks are a good example of this. While it is hard to imagine modern life without electricity, electrical networks are a fairly recent invention. Nowadays, a power outage brings everything to a halt. If an outage is extensive, not only homes will be affected – shops and factories also close. Once these networks are down, society will be offline. Modern society could only last for a few days in a complete power outage.
    If the Internet were to fail, the impacts would be much less dramatic. Society would not stop during a network outage. Factories would continue to operate. Information would flow via TV antennas and FM radio. Of course, work would be much more difficult without network connections. Most monetary transactions would also cease. In a nutshell, internet outages are expensive, but they don't kill people.
    I predict that, before long, the information network and electrical network will be equally important to our society. Before long, much like a power outage, a network outage will bring life to a halt. In fact, before long, a network outage will also mean a power outage.
    Electrical networks have been highly beneficial, but we have become highly dependent on them. The same is now happening in relation to information networks. The electrical network needs the information network to work, and vice versa. Technological development is changing our society in a fundamental way. This dependency is happening on our watch.
    about this event: https://program.mch2022.org/mch2022/talk/R9LCYW/
    30 min
  • Using Passcrow to recover from lost passwords (MCH2022)
    Have you ever forgotten a passphrase or lost a hardware token? Lost access to enough Bitcoin to buy a pizza or two? Encryption is fundamental to securing our liberties, but key and password management remain difficult even for professionals, let alone the general public.
    This talk presents Passcrow, an Open Source project attempting to address one of crypto's largest usability issues: password and key recovery in a decentralized environment.
    Passcrow is a system for community-assisted secure “password escrow”, making it possible to recover from forgetting or losing a key, password or passphrase. Born out of a desire to make strong encryption easier (and safer!) to use for less technical users, the project is in an early stage of development - but code has been published and the system is usable today.
    Passcrow is many things: there is an underlying protocol, basic user experience guidelines, a client library for integration with other (Python) apps, an HTTP API server, and a command-line tool for making use of the system by hand. Potential applications include password managers, secure messengers, general purpose encryption tools (including OpenPGP and hard drive encryption) and cryptocurrency wallets.
    In this talk, I will discuss the motivation and rationale for the project, demonstrate how the system works and talk about some of the challenges and design decisions we have seen so far.
    The purpose of this talk is to solicit feedback and participation from the community; if you are interested in the subject, please come find me afterwards (my base at MCH will be The Quarantine Arms village) and let's have a chat! If you miss the talk, you can read about it at www.passcrow.org.
    Passcrow is a spin-off from Mailpile (www.mailpile.is), the secure e-mail client. Passcrow is inspired by Mailpile's experience attempting to make e-mail encryption more usable for less technical users, and will be used in future versions of the app.
    about this event: https://program.mch2022.org/mch2022/talk/GMA8VX/
    30 min
  • Lightning Talks Friday (MCH2022)
    Lightning talks are a 5 to 10 minute quick talk on an interesting subject. They can be with or without slides, and with or without proper preparation. if you weren't accepted in the main CfP, this is also a great opportunity to give an abridged version of your talk. These sessions will be available to sign up to later on, with details on the wiki.
    Lightning talks are a 5 to 10 minute quick talk on an interesting subject. They can be with or without slides, and with or without proper preparation. if you weren't accepted in the main CfP, this is also a great opportunity to give an abridged version of your talk. These sessions will be available to sign up to later on, with details on the wiki.Lightning talks are a 5 to 10 minute quick talk on an interesting subject. They can be with or without slides, and with or without proper preparation. if you weren't accepted in the main CfP, this is also a great opportunity to give an abridged version of your talk. These sessions will be available to sign up to later on, with details on the wiki.
    about this event: https://program.mch2022.org/mch2022/talk/G9ZWRZ/
    37 min
  • The Silicon Passion (MCH2022)
    What do big tech, synthesizers, the crucifixion and Matthäus Passion have in common? Find the answer in the tech performance The Silicon Passion. We’ve all embraced big tech —but is it a warm hug or a strangulation? Bear witness to a debate of biblical proportions between tech nerds, technology and its users. In The Silicon Passion SETUP, in collaboration with de Transmissie (David Schwarz en Derk Stenvers) and Rodrigo Ferreira, is looking for a way out of the pit that technology has created for them.
    The performers draw inspiration from one of the most important stories about penance: the crucifixion. They want to find out exactly who or what should be nailed to the cross, and what the world might look like after a resurrection.Taking the St Matthew Passion as a starting point, both for the valuable lessons as well as musical inspiration. Armed with Bachst’ St Matthew Passion and synthesizers we will look for a new way of dealing with big tech.
    SETUP (Utrecht) is a media lab exploring the day-to-day future of technology. Using a critical yet humorous perspective, SETUP translates complex themes into more tangible ideas for everyone. In 2021, SETUP asked several artists to offer new perspectives on penance and forgiveness for big tech, using the St Matthew Passion. A composed group consisting of multidisciplinary theater collective de Transmissie and musician Rodrigo Ferreira came to a stunning result, with live performances from Theater Kikker and Pakhuis de Zwijger in April 2021. The new performance in 2022 is the next step in this research.
    about this event: https://program.mch2022.org/mch2022/talk/DEJQME/
    1 hr 13 min
  • ⚠️ May Contain Hackers 2022 Opening (MCH2022)
    ⚠️ Warning! This talk may contain hackers. There may be hackers in the room. There may be hackers surrounding the room. There may be hackers recording this. There may be hackers listening in. There may be hackers that exfiltrate data. There may be hackers wearing shirts. There may be hackers carrying spying devices. OH NO! There are hackers EVERYWHERE! What can we do now, except having a party?
    This talk serves as an introduction to the camp. It tells how the camp works, what new features are being released, how to participate and what to be aware of.
    During this talk there will be some audio-trickery in the Abacus stage which can not be relayed to the recording or via the stream. As we cannot film audience reactions, know that it will be more epic than the final battle scene of LOTR.
    In all seriousness: there are absolutely stunning new additions to the camp.
    I'm have to write at least 5
    about this event: https://program.mch2022.org/mch2022/talk/JBNXAX/
    35 min
  • Workshops organisieren (petitfoo)
    Ich möchte einen Workshop organisieren! Aber wie? In diesem Petit Foo stelle ich verschiedene Möglichkeiten vor um einen Workshop zu organisieren und gebe Tipps worauf man bei der Durchführung achten sollte.
    about this event: https://www.chaospott.de
    24 min
  • Leben ist Glück (jh22)
    Ein Spiel, das zeigt, wie viel im Leben auf Glück basiert
    about this event: https://pretalx.c3voc.de/jugend-hackt-rhein-neckar-2022/talk/WFAAQJ/
    8 min
  • TrävelBuddy (jh22)
    Eine App, die reisen leichter macht
    about this event: https://pretalx.c3voc.de/jugend-hackt-rhein-neckar-2022/talk/EGUGBQ/
    5 min
  • CCCTV (jh22)
    Die datenschutzsichere Sicherheitskamera
    about this event: https://pretalx.c3voc.de/jugend-hackt-rhein-neckar-2022/talk/RQ9FHA/
    9 min

About Chaos Computer Club - archive feed

From the publisher's feed

Der Chaos Computer Club ist die größte europäische Hackervereinigung, und seit über 25 Jahren Vermittler im Spannungsfeld technischer und sozialer Entwicklungen.