CCC media team
Chaos Computer Club - archive feed
A wide variety of video material distributed by the Chaos Computer Club. This feed contains events older than two years
Where to listen?
Podcasts in the app Replaio Radio Coming soonPodcasts are coming to the app soon. Install now and be the first to see a whole new take on podcasts
Episodes
Introduction to MQTT, Node-RED & Tasmota (MCH2022) Video 26.07.2022 33:40
A demonstration of the power of MQTT in combination with Node-RED. We'll also take a look at the "universal" Tasmota firmware for ESP8266 and ESP32-based devices. This all to hopefully make you enthusiastic to start building your own projects with these building blocks. A demonstration of the power of MQTT in combination with Node-RED. We'll also take a look at the "universal" Tasmota firmware for...
Sensor.Community - Global Open Environmental Data Platform (MCH2022) Video 26.07.2022 48:41
Sensor. Community - Global platform for Open Environmental Data We invite you to become part of Sensor. Community. The worldwide largest Air Quality sensor network run by contributors generating Open Data. Build a sensor, collect Open Data, share it in a continuous stream with the global network and join forces in local Sensor. Community groups. Sensor. Community is the global platform for environ...
How to Secure the Software Supply Chain (MCH2022) Video 26.07.2022 47:16
Open source code makes up 90% of most codebases. How do you know if you can trust your open source dependencies? Do you know what’s really going on in your node_modules folder? It is critical to manage your dependencies effectively to reduce risk but most teams have an ad-hoc process where any developer can introduce dependencies. Software supply chain attacks have exploded over the past 12 months...
A Smart Light Hacking Journey (MCH2022) Video 26.07.2022 48:48
Smart lights have become pervasive in many homes, but they are often designed in such a way that makes them completely reliant on the manufacturer's servers and connectivity to the Internet. However, we would much rather be fully in control of our own devices. As a target, we took on the cheap and popular Tuya white-label smart lights, which can be commonly found under many different brand names....
hack your brain (MCH2022) Video 26.07.2022 43:01
Food affects your body, food affects your mind. This talk describes how the performance of my brain has decreased over time and has returned by changing my diet. Basic food is not enough for your brain to deliver exceptional performance. Come with us and open your mind. Let your remedies be your food and your food be your remedies. Just think about it, I'm eating all day and losing weight. To be w...
Reproducible Builds for Trustworthy Binaries (MCH2022) Video 25.07.2022 31:04
Reproducible Builds is a technique that can be used to secure the software delivery pipeline. For open source software, they even allow independently auditing published binaries, removing a single point of trust from the distribution process. This can be used by individual projects or even complete Linux distributions. The software delivery pipeline is an increasingly popular attack vector: even w...
illumos SmartOS, specialized Type 1 Hypervisor (MCH2022) Video 25.07.2022 27:04
Overview of **SmartOS** - an illumos based distribution with **focus of virtualization**. Must be named technologies used by SmartOS: ZFS, Crossbow, Zones, DTrace, Bhyve. The talk will show you the benefits of SmartOS; Configuration and management of SmartOS virtualization technologies; Tooling on top of SmartOS. SmartOS is a specialized Type 1 Hypervisor platform based on illumos. It supports two...
Payment terminals as general purpose (game-)computers (MCH2022) Video 25.07.2022 42:41
What is inside a Verifone VX820 payment terminal and how can we run our own code (i.e. Doom) on it? This is a story of a software guy messing around with an interesting embedded device. It includes some reverse engineering, *interesting* security practices, proprietary executable formats, and a game of bootloader hopscotch. Starting with an overview of the Verifone VX820 payment terminal's hardwar...
Introducing CSIRT.global: if you love the internet, we need your help (MCH2022) Video 25.07.2022 24:36
The Dutch Institute for Vulnerability disclosure goes international. We’re building a community of enthusiasts to help stop the downward spiral of the internet, we’re calling it CSIRT.global. It’s aimed at international collaboration. Trust and communication, balanced with a sense of reality about the sensitive information we deal with, are key. Here’s how you can help, one vulnerability at a time...
Knock knock, who’s there? (MCH2022) Video 25.07.2022 22:36
One of the most used video entry systems is analysed for this talk. Severe security implications that range from passive, information gathering, attacks to active attacks where unauthorised access to buildings can be gained. During the talk the technical details of the bus system will be discussed and multiple attackvectors will be demonstrated. At the end of the talk the disclosure procedure to h...
Successfully building and programming sound field control systems (MCH2022) Video 25.07.2022 49:19
We will walk through the basics of sound field control systems and what you would need to build your own Wave Field Synthesis and Beamforming enabled system. We will unveil some of the challenges we faced at HOLOPLOT and what solutions power our tech stack. Most of us are very familiar with multiple ways of manipulating or creating audio content; filters, effects, synthesizers, etc., and most cert...
Censoring the internet & how to bypass it (MCH2022) Video 25.07.2022 49:28
In recent times, internet censorship has increased throughout the world. With governments realising the potential of the internet in spreading information as well as misinformation. To curb or rather control this, governments around the globe have taken to censoring parts of the internet by directing major ISPs to block access to those websites. The ISPs around the globe have used different method...
Single Sign-On: A Hacker's Perspective (MCH2022) Video 25.07.2022 45:24
This talk gives an introduction in how single sign-on protocols (such as SAML, OAuth 2, and Open ID Connect) work. Subsequently, I will talk about the most commonly found vulnerabilities in these protocols. Finally, I will show various ways to resolve these vulnerabilities. Single sign-on remains a hot topic in 2022. Many organisations are in the process of moving identity management and authentic...
OpenKAT: Looking at security with cat eyes (MCH2022) Video 25.07.2022 44:01
During crises – like COVID19 – software is made under immense pressure in a volatile environment. Security should focus on anything that makes one vulnerable. OpenKAT does this with real forensic proof, with the right context and useful in real life. The COVID19-crisis forced to build dozens of software solutions rapidly with too few people under immense pressure. Meanwhile the threat level as wel...
Rocking the Web Bloat: Modern Gopher, Gemini and the Small Internet (MCH2022) Video 25.07.2022 47:33
The web is a mess, bloated with data-gathering trackers, predatory UX, massive resource loads, and it is absorbing everything it touches. The Small Internet is a counter-cultural movement to wrangle things back under control via minimalism, hands-on participation, and good old fashioned conversation. At its heart are technologies like the venerable Gopher protocol or the new Gemini protocol offeri...
Scanning and reporting vulnerabilities for the whole IPv4 space. (MCH2022) Video 25.07.2022 49:00
The Dutch Institute for Vulnerability Disclosure scans the internet for vulnerabilities and reports these to the people who can fix them. Our researchers will go into some of our recent cases, our board members will describe how we professionalise vulnerability disclosure and why we are allowed to somewhat break laws on computer crime and privacy. The Dutch Institute for Vulnerability Disclosure s...
macOS local security: escaping the sandbox and bypassing TCC (MCH2022) Video 25.07.2022 50:48
"SomeApp would like to access files in your Documents folder." Anyone who has used macOS recently will be familiar with these prompts. But how do they work? What happens if you deny the access? Are they an effective defense against malware? This talk will give an up to date overview of the local security measures of macOS and describe some ways they can be defeated in practice. Sandboxing on macOS...
Ethics does not belong on the wall! Ethical framework for the use of location data (MCH2022) Video 25.07.2022 46:21
The use of data is accelerating, not only owing to increasing technical possibilities like AI and earth observation, but also as a result of crises such as COVID-19 and climate change which accelerate the deployment of data and technology. This is happening on a small and local scale, as well as on a large and global one. Precisely because these data are potentially personal, and its use is becomi...
A CISO approach to pentesting; why so many reports are never used (MCH2022) Video 25.07.2022 49:06
Pentesting can provide vital information to organisations about their security. However, many reports end up never being used or not being used to their full potential. That is partly due to the pentesters and their writing skills. But in large part is also to be attributed to CISO's lack of guidance and involvement. I am not a spokesperson for all CISOs, but I do have quite a bit of experience in...
Nuggets of Shannon Information Theory (MCH2022) Video 25.07.2022 49:23
In his 1948 [scientific article](https://en.wikipedia.org/wiki/A_Mathematical_Theory_of_Communication) entitled ["A mathematical theory of communication"](https://people.math.harvard.edu/~ctm/home/text/others/shannon/entropy/entropy.pdf), Claude E. Shannon introduced the word “bit”. The article laid down the foundations for the field of information theory which in turn opened up the way to digital...
Cyber crises and what you can do to face the challenge (MCH2022) Video 25.07.2022 44:56
Your organization suffers from a serious system compromise from a cyber-crime ring, state-actor or both. The cyber inferno is raging through your organisation. In this talk I’d like to walk you through a situation which escalated quickly. The talk is intended to inspire people to take preventative measures, keep their heads as cool as possible, and keep a grip on the situation. Your organisation s...
Lightning Talks Monday (MCH2022) Video 25.07.2022 1:02:11
Lightning talks are a 5 to 10 minute quick talk on an interesting subject. They can be with or without slides, and with or without proper preparation. if you weren't accepted in the main CfP, this is also a great opportunity to give an abridged version of your talk. These sessions will be available to sign up to later on, with details on the wiki: https://wiki.mch2022.org/Static:Lightning_Talks Li...
Project TEMPA - Demystifying Tesla's Bluetooth Passive Entry System (MCH2022) Video 25.07.2022 51:11
The security of Tesla's cars has been a hot topic in recent months. In addition to being one of the safest cars on the road, it is also well-protected from hacks and attacks. But how does Tesla make sure their vehicles are safe and secure? This case study sheds light on the inner workings of Tesla's Passive Entry System and core VCSEC protocol, and reveals possible attack vectors. The security of...
Hope : It is too late to be pessimistic (about climate change) (MCH2022) Video 25.07.2022 1:32:11
We know that we are in trouble as a human society, so what are we going to do about it? Showcase projects that do good things What can you do? Tension between system-level problems and the massive powers that be and the scope of individual impact. How do you leverage your privilege? imagining yourself in 2050 narratives. We know that we are in trouble as a human society, so what are we going to do...
TASBot OoT ACE: (MCH2022) Video 25.07.2022 48:28
TASBot has appeared at multiple charity events raising more than $1.3M to date by hacking classic video game consoles through controller ports. In this talk, dwangoAC will show how TASBot, with help from a human speedrunner, can use a Stale Reference Manipulation exploit in the N64 game Legend of Zelda: Ocarina of Time to achieve persistent Arbitrary Code Execution to obtain the Triforce and many...
Similar podcasts
Replaio is not a podcast publisher; show names, artwork and audio belong to their authors and are distributed through public RSS feeds.