Christiaan008
DEFCON 16: Flux on: EAS (Emergency Alert System)
updated
Project website: http://cic.christiaan008.tk
Music tracks:
"Undaunted" Kevin MacLeod (incompetech.com)
Licensed under Creative Commons: By Attribution 3.0
http://creativecommons.org/licenses/by/3.0
"Unity" Kevin MacLeod (incompetech.com)
Licensed under Creative Commons: By Attribution 3.0
http://creativecommons.org/licenses/by/3.0
Project website: http://cic.christiaan008.tk
Playlist: youtube.com/playlist?list=PLwP_SiAcdui2udo95mj_jAkKYSpJnRt2r
Song on the background: Sky Seeds - British Pop Mix used under creative commons license.
To download the video visit: http://bit.ly/OHM13_down
Playlist OHM 2013: http://bit.ly/OHM13_pl
Speaker: Felicitus
Considerations on how to build a solar powered autonomous router, from planning phase to the final project.
In this talk I'll go through the considerations on how to plan and build a solar powered autonomous router. This includes calculations on the solar panel size, which components the setup needs, how the system can do self-monitoring and what you can possibly do with such a system.
This talk is also suitable to learn the basics for stand-alone photo-voltaic systems; you don't necessarily power a router with the system. You'll learn how to calculate the panel and battery sizes required for your project.
Additionally I'll present a few projects on how to visualize collected power data as well as SolarWind, a solar-powered router for less than 100€.
To download the video visit: http://bit.ly/OHM13_down
Playlist OHM 2013: http://bit.ly/OHM13_pl
Speaker: Jeroen van der Ham
KPN and others are violating the Dutch Netneutrality laws. Learn how we found out and how you can help too!
The Internet Society Netherlands has a working group looking at the transparency of the Internet. In this group we already looked critically at the PirateBay website blockade, and we have created an app to test the openness of your Internet connection.
In this talk I describe how we further confirmed results from the app. The code is online and you can test this for yourself now too!
See also http://webwereld.nl/mobility/78712-uva-kpn-dochter-schendt-netneutraliteit (dutch)
To download the video visit: http://bit.ly/OHM13_down
Playlist OHM 2013: http://bit.ly/OHM13_pl
Speaker: Guy Martin
Networks are part of our daily life. A lot of information transit through them but few really know what is actually transmitted and what information can be extracted. This talk will present pom-ng, a network forensic tool that performs real time analysis. The talk will focus on describing the coding challenges faced with such tool, architecture and what can be done with it.
The talk will be split in 3 parts.
The first part will describe the way packets are processed and the different outputs that are produced. I'll go in more details about IP de-fragmentation, TCP re-ordering and other related activities such as temporary offline DNS caching.
The second part will consist of a live demo demonstrating possible use of pom-ng using live traffic and the audience's traffic. Example will include dumping files out of
In the third part, the LUA code used to perform the demo will be explained for a very short tutorial.
To download the video visit: http://bit.ly/OHM13_down
Playlist OHM 2013: http://bit.ly/OHM13_pl
Speaker: BECHA
How to rule the Internet (together with everybody else)
Internet Governance and Hackers: what do they have in common
What I want to achieve with my lecture is:
* to enrich & diversify existing Internet Governance communities with young generation and "new blood"
* to empower hackers, activists and free-software communities in influencing decisions in Internet Governance
* to increase understanding and cooperation between these communities...
... and finally: to improve the decisions made and harness the energy of hacktivists
I will be inviting OHM participants to take part in decision-making processes, explaining how existing structures work and how to contribute, and raising awareness about similarities and overlap of our goals & approaches (consensus-based decision-making process, bottom-up & decentralized, open and transparent).
To download the video visit: http://bit.ly/OHM13_down
Playlist OHM 2013: http://bit.ly/OHM13_pl
Speaker: Soheil Eskandari Bavani
During this research I have analyzed the newest file system of VMware on bitlevel which is called Virtual Machine File System version 5 (VMFS-5). The purpose of this research concerned a review of the structure of VMFS.
During this research I have analyzed the newest file system of VMware on bitlevel which is called Virtual Machine File System version 5 (VMFS-5). The purpose of this research concerned a review of the structure of VMFS. This structure can be used for other purposes like data reconstruction. Due to the lack of publically available documentation the research compromised of reverse-engineering the VM file system. In my research I have analyzed 5 system files of the VMFS which contain allocation registers. The VMFS file system registers the allocation condition of the available data resources in these system files.
To download the video visit: http://bit.ly/OHM13_down
Playlist OHM 2013: http://bit.ly/OHM13_pl
Speaker: Jaya Baloo
A presentation of how KPN sees the infosec landscape of threats and risks and how we prepared a strategy to address it. We will present our approach to information security and ourselves. Our team will explain what we do every day to help make stuff more secure, and that its an ongoing activity.
To download the video visit: http://bit.ly/OHM13_down
Playlist OHM 2013: http://bit.ly/OHM13_pl
Speakers: Jurre van Bergen | David Goulet
USE OTR is an organisation that works on security, encryption and usability of open source instant messengers (IM). Our goal is simple: improving security, usability and encryption of existing IM software. This talk will outline our organisation and the "Off The Record Messaging" software ecosystem and what's coming up for the future.
We are an organisation that works on security, encryption and usability of open source instant messengers (IM). Our goal is simple: improving security, usability and encryption of existing IM software.
One key aspect is to have developers, resources and funds available to maintain OTR software over time and thus making them sustainable, up-to-date and secure. We will be collaborating and sharing resources with developers, as we believe educating them on usability, security and cryptography updates should be a core part of our work.
Another key aspect of our mission will be our partnership with other NGOs. While we have already started collaborating with the Centre for Investigative Journalism we want to extend our network and reach out to others. Indeed, having observed that journalists, NGOs and activists are the most exposed to surveillance, we believe they should have their say when it comes to dealing with usability. We want to hear from them and this is why we have started creating partnerships with organisations allowing us reach these populations.
By developing safer, usable encryption instant messaging tools we directly support freedom of speech and expression worldwide. In addition to that, we will improve the experience of the already existing IM software users, Pidgin itself is used by tens of thousands of users world wide.
In this talk we will provide an overview of what "Off The Record Messaging" is, what the software ecosystem looks like, what the projects are that USEOTR are developing and what's next for the future.
To download the video visit: http://bit.ly/OHM13_down
Playlist OHM 2013: http://bit.ly/OHM13_pl
To download the video visit: http://bit.ly/OHM13_down
Playlist OHM 2013: http://bit.ly/OHM13_pl
Speaker: Sara Sibai
At OHM2013, Spoken is a spoken-word tribute to: Observing, Hacking, Making. I would be honored to perform and share unique spoken-word poems in the hopes of inspiring others to do the same.
Spoken can be labelled as an art performance, but it is a co-created art performance that can be joined by any who attend and wish to express how they Observe, Hack, Make, via the medium of poetry.
I'm inspired to write and perform poetry based on my observations and interactions with others. I'm fascinated by people, the way they think, behave, love, give, share, create, and engage. I observe people around me intensely, it helps me understand human psyche and nature. This is why I thrive in diverse contexts.
To download the video visit: http://bit.ly/OHM13_down
Playlist OHM 2013: http://bit.ly/OHM13_pl
Speaker: Kimiko Ishizaka
Kimiko Ishizaka plays Bach and Chopin: A celebration of makers, and free culture.
Join Kimiko Ishizaka, the pianist who recorded the Open Goldberg Variations, for a journey into the musical worlds of two of the greatest musical geniuses.
J.S. Bach and Frederic Chopin were two of the greatest music hackers and makers of all time. Their works are timeless and continue to thrill audiences and performers centuries after their work was finished. Had either of them had the chance to attend OHM 2013, chances are they would have fit right in, hacking and making new things of wonder and gaining inspiration from the makers they observe.
Their music, in fact all of the great music that we have inherited in the public domain throughout time, is in need of modern electronic editions with free culture licensing, as well as quality public domain recordings that are reference quality and allow hackers to build new things out of them.
It is in the spirit of open source and #copyleft art that Kimiko Ishizaka offers this performance, on a concert grand piano, to all who would record and broadcast it under a Creative Commons (CC BY-NC 3.0) license.
To download the video visit: http://bit.ly/OHM13_down
Playlist OHM 2013: http://bit.ly/OHM13_pl
Speaker: Phons Bloemen
The Abuse Information Exchange is a project to help abuse desks of ISPs gathering the information about zombies and contaminated machines inside the networks(AS numbers) they are responsible for. The exchange will gather the information, correlates and splits it up by AS number and provide it in a generic, human and machine readable format
This project is done by the 7 big access ISPs in NL. It is currently running in a pilot phase, with the information provided by Shadowserver. When it is fully operational, there will be more Reliable Notifiers, who can report abuse in an automated manner. The goal is is to reduce the ratio of contaminated IP numbers in ASNs controlled by the Dutch ISPs. In later phases of the project, extension to hosting service providers and other countries is considered.
To download the video visit: http://bit.ly/OHM13_down
Playlist OHM 2013: http://bit.ly/OHM13_pl
Speaker: Alexandre Poltorak
Elphel Open Hardware and Free Software Reconfigurable Network Cameras
See http://en.wikipedia.org/wiki/Elphel
To download the video visit: http://bit.ly/OHM13_down
Playlist OHM 2013: http://bit.ly/OHM13_pl
Speaker: polto
A short presentation about LSM / RMLL, and an open invitation for participation / organization.
LSM is a non-commercial cycle of conferences, round tables and practical workshops based on Libre Software and its uses. Its aim is to provide a platform for Libre Software users, developers and stakeholders.
A short presentation about LSM / RMLL, and an open invitation for participation / organization.
LSM is a non-commercial cycle of conferences, round tables and practical workshops based on Libre Software and its uses. Its aim is to provide a platform for Libre Software users, developers and stakeholders.
Web site - http://rmll.info , http://2012.rmll.info , http://2011.rmll.info , ...
Videos are available on http://video.rmll.info
Photos - http://photo.rmll.info
To download the video visit: http://bit.ly/OHM13_down
Playlist OHM 2013: http://bit.ly/OHM13_pl
Speaker: Pedro Noel
Present the initiative of the Associated Whistle-Blowing Press, AWP, a decentralized network of whistle-blowing platforms and international newswire focused on denouncing human-rights violations.
About the AWP
The Associated Whistle-Blowing Press (AWP) is a not-for-profit information agency to be based in Iceland, dedicated to bringing forth and analyzing leaked information coming from different sources around the world. It aims to have a network of prominent journalists, researchers, lawyers, IT experts and media activists working together to provide society with a trustful and friendly source of analysis of information leaked by whistle-blowers around the world.
In the long run the AWP will make the whistle-blowing community more robust by automatizing the dissemination process and minimizing the effort needed for sources and analysts to make their work reach a wider audience. At the same time it will gather whistle-blowers, IT experts, researchers, activists and journalists under a formal structure, increasing the repercussion of their efforts in media channels, independent Internet sites or blogs. Thanks to this we believe the general cause for freedom of speech and information will be strengthened.
The AWP is structured as a network that functions internationally, with whistle-blowing platforms focused on specific local contexts and working with different languages.Each node allows local citizens to send information proving abuse or corruption in a safe and anonymous way: the main goal is to make governments and corporations accountable for their actions by bringing them into the light. Through these nodes, contacts in local media outlets (traditional and non-traditional) will be made in order to coordinate the submission, analysis and publishing of leaked information.
To download the video visit: http://bit.ly/OHM13_down
Playlist OHM 2013: http://bit.ly/OHM13_pl
Speaker: Quux
Introduction to ColoClue and why you want to become a member.
To download the video visit: http://bit.ly/OHM13_down
Playlist OHM 2013: http://bit.ly/OHM13_pl
Speaker: Linda Sandvik
Code Club is a global network of volunteer-led after school coding
clubs for children aged 9-11. Learn what it's all about, how to start
one, and why all children should be given the chance to learn to code.
Code Club started just over a year ago in a pub when I met with
my friend Clare to plan a hackday but ended up ranting about how the ICT curriculum in the UK sucks. I'd like to tell you how we got from
"someone should do something about this" to running over 900 weekly clubs in the UK, and now trying taking over the world.
To download the video visit: http://bit.ly/OHM13_down
Playlist OHM 2013: http://bit.ly/OHM13_pl
Speaker: Merlijn Wajer
"Hart voor internetvrijheid" is a foundation setup to help in
circumventing censorship online. Our primary goal is to run a bunch of Tor nodes. We are a partner at; torservers.net/partners.html
To download the video visit: http://bit.ly/OHM13_down
Playlist OHM 2013: http://bit.ly/OHM13_pl
Speaker: bastinat0r
In my current project I gather and visualize data from the spaceAPI. I will tell people about my project and what is cool about spaceAPI.
Because we have no official opening hours at our hackerspace I wanted to gather statistics to see when the door is open. Then I extendet the software to work for all spaces in the directory of spaceAPI.net - you can see the result at http://spacestatus.bastinat0r.de
To download the video visit: http://bit.ly/OHM13_down
Playlist OHM 2013: http://bit.ly/OHM13_pl
Speaker: Elger Jonker aka Stitch
Awesome Retro is an organization that has it's roots in the hacker
scene. Their mission is to make retrogaming possible for everyone. In this short talk the speaker showcases previous highlights and looks at what's going to happen in the near future.
To download the video visit: http://bit.ly/OHM13_down
Playlist OHM 2013: http://bit.ly/OHM13_pl
Speaker: Yan
In January and February, 2013, around 20 hackerspaces and universities around the world joined together in keeping Aaron Swartz's legacy alive through a series of hackathons. Join us as we summarize what happened at these hackathons and start planning for another series in the Fall.
For a detailed summary of the worldwide hackathon series, see noisebridge.net/wiki/Worldwide_Aaron_Swartz_Memorial_Hackathons. We'll go over some highlights and pitfalls from these events, and discuss what else we could do to continue the spirit of Aaron's work. Anyone interested in joining us in organizing the next hackathon series is invited to a meeting after the talk (time/location to be decided).
To download the video visit: http://bit.ly/OHM13_down
Playlist OHM 2013: http://bit.ly/OHM13_pl
Speaker: Karsten Nohl
SIM cards are among the most widely-deployed computing platforms with over 7 billion cards in active use, but little is known about their security beyond manufacturer claims.
Besides SIM cards main purpose of identifying subscribers, most of them provide programmable Java runtimes. Based on this flexibility, SIM cards are poised to become an easily extensible trust anchor for otherwise untrusted smartphones, embedded devices, and cars.
The protection pretense of SIM cards is based on the understanding that they have never been exploited. This talk ends this myth of unbreakable SIM cards and illustrates that the cards -- like any other computing system -- are plagued by implementation and configuration bugs.
To download the video visit: http://bit.ly/OHM13_down
Playlist OHM 2013: http://bit.ly/OHM13_pl
Speaker: Robert Douglass
How the ideas behind open source collaboration can influence the way classical musicians work together and share music.
In 2012 pianist Kimiko Ishizaka and software company Musescore
collaborated to create new public domain versions of the Goldberg
Variations by Bach. Both a new recording and a new score were created,
and the funding for the project came from Kickstarter.com.
Along the way, Ishizaka became a focal point for the #copyleft fight
in Germany, and her music went on to create even more works of art as
others incorporated it into their works.
Now, Ishizaka is planning an even bigger project building on the lessons learned. This talk will approach the topics of:
- Why do we need Open Source Bach, isn't that stuff already in the public domain?
- What kinds of opportunities are we missing out on by not protecting our public domain goods?
- Does Open Goldberg Variations represent a new model for funding artist recordings?
- What's next?
To download the video visit: http://bit.ly/OHM13_down
Playlist OHM 2013: http://bit.ly/OHM13_pl
Speakers: Herbert Bos | Rejo Zenger | Merel Koning
In several European countries proposals for vast expansion of the powers of law enforcement in the digital realm are floating about. The most concrete is a Dutch proposed law that among other things gives law enforcement the authority to break into remote computers. The panel focuses on the pros and cons of such powers.
To download the video visit: http://bit.ly/OHM13_down
Playlist OHM 2013: http://bit.ly/OHM13_pl
Speaker: Arjan van Hattum
An analysis of over 100,000 copyright infringement notices sent on behalf of content holders to an ISP over a period of over 3 years.
The past couple of years have seen a concerted effort of content rights holders to combat file sharing in all possible areas, ranging from legislative and judicial efforts, to protected content serving systems as well as building a capability to map out and report unlawful content sharing. As an ISP, we receive thousands notices of claimed infringement each week, detailing who shared what at which time with the request to undertake corrective action.
Who is sending these notices and on who's behalf? What sort of content is shared and through which medium? What sort of information is tracked and reported about the end user? These are some questions I'll address, using information collected from roughly 100,000 served notices in the past three years.
To download the video visit: http://bit.ly/OHM13_down
Playlist OHM 2013: http://bit.ly/OHM13_pl
Speaker: Amanda Fielding
Drugs are bad for you so that's why they are banned in society and so we're stuck with a 'war on drugs'. But are drugs actually 'bad' for you? How do different illegal drugs compare to alcohol, sigarettes and coffee? Let's see what science has to say.
The aim of the Beckley Foundation scientific programme is to increase our understanding of the functioning of the brain and consciousness. Our pioneering research is conducted in conjunction with leading scientific institutions around the globe, including Imperial College London, John Hopkins University, and Kings College. We use psychoactive substances as tools to alter brain activity. By investigating these changes with the latest brain-imaging technology (fMRI and MEG), we open up exciting new avenues of treatment for physical and mental conditions, and unveil the mechanisms by which psychedelics produce their profound effects. By changing consciousness, we learn more about normal consciousness.
To download the video visit: http://bit.ly/OHM13_down
Playlist OHM 2013: http://bit.ly/OHM13_pl
Speaker: Ruud Schramp
BIOS swap on server PC. Memory acquisition using firewire, reboot or userspace tools is standard. What if your intel motherboard BIOS wipes ECC memory and live plugging PCIe fails?
The presentation describes an alternative way to initialise RAM using methods from the coreboot project. After initialisation the RAM can be dumped compressed over serial and a LPC-USB device.
To download the video visit: http://bit.ly/OHM13_down
Playlist OHM 2013: http://bit.ly/OHM13_pl
Speakers: John Gilmore | Paul Wouters
A crypto-memorial in honour of cypherpunk Hugh Daniel, who died June 3rd, 2013
On June 3rd, cypherpunk Hugh Daniel unexpectedly died.
Those who met him, know him. Principled to the core, and very present in any room, he compelled people to listen to him - both by what he said, and how loud he said it.
He was one of the cypherpunks involved with getting PGP exported to the free world by turning the software into a book, exporting it, and OCRing it at Hacking In Progress ("HIP 97"), his first out-of-the-US trip where many Dutch hackers met him for the first time.
He has made many contributions during the early days of IPsec and DNSSEC. He was a manager of the FreeS/WAN IPsec Project for many years and co-founder of The Openswan Project and recently The Libreswan Project, although his health prevented him from being as active and he wanted to be in the last two years.
As an active player in the ever ongoing Crypto Wars, his contributions have enhanced the security and privacy of everyone.
He would condone wasting a perfectly good time slot with a large audience on "kust a memorial service", so in a compromise between remembering Hugh and carrying on his work, John Gilmore and Paul Wouters will share some of Hugh's Crypto War stories while teaching some geopolitical and practical crypto deployment.
To download the video visit: http://bit.ly/OHM13_down
Playlist OHM 2013: http://bit.ly/OHM13_pl
Speakers: mourn | edcv
VoIP phones are deployed in a large number of companies. It has already been showed how to use a phone as a spying device (Hacking Cisco Phones [29C3] by Cui and Costello). In this presentation we will focus on other brands of VoIP phones and show how to use reverse engineering in order to be able to log in some phone RTOS and generate rogue updates for permanent "modifications" as well as understanding the phone internals in order to use it as a remote spying device.
This presentation will focus on Broadcom based VoIP phones, running vxWorks as their Real-Time OS.
Presentation is divided in 3 party:
- Reverse engineering of a vxWorks image
- Finding flaws in vxWorks and Broadcom part of the code.
- Reversing the authentication method for FW updates in the Original Design Manufacturer part of the code.
To download the video visit: http://bit.ly/OHM13_down
Playlist OHM 2013: http://bit.ly/OHM13_pl
Speaker: Tim Becker
A brief introduction to EMV, the protocol spoken between smart card based credit cards and terminals. A mixture of plastic and RF, bits, bytes and anecdotes, based around a single payment transaction performed live on stage.
My talk will be an introduction helping beginners to start playing around with (chip based & contactless) credit cards and provide some deeper insight for people with knowledge of chip card but little knowledge of EMV. While the technology is fairly accessible, there's a steep learning curve and no beginner's literature. I've been involved in two large EMV (CPA, Visa, Master, contact and contactless) implementation projects and think it might be interesting to take 45 minutes to step through a single transaction and use it to eleborate some of the concepts used, the equipment and software necessary as well as the protocol of course and share some anecdotes. Quite a few people "play around" with payment cards, but unfortunately, not a lot of reliable information about the technology is available, I'd like to change that.
I'm not introducing any new attacks, but I'll elaborate some of the classic hacks against chip and pin during the talk. This lecture is meant purely as an (re)introduction to the protocol.
This is an updated version of a similar talk held at 29C3.
To download the video visit: http://bit.ly/OHM13_down
Playlist OHM 2013: http://bit.ly/OHM13_pl
Speakers: Hermes Center for Transparency and Digital Human Rights
We'll introduce Digital Whistleblowing, how it's effectively used and adapted to different context: Investigative Journalism, Activism, Corporations and Governments.
The new GlobaLeaks 0.2 software will be presented with a show case of design, security principle and tips on how to use it or hack it.
Digital Whistleblowing with represent the next frontier for hackers, investigative journalists and the society at large to spot unethical practices of humans.
There was many different initiatives that has been done in the area of Anonymous Whistleblowing, by merging together Hackers, Journaliss and Activists. Someone succeeded, someone didn't succeeded.
This talk is to share the GlobaLeaks experience in working with different organization interested in setting up Anonymous Whistleblowing initiatives.
Within OHM2013 GlobaLeaks 0.2 software version will be officially released.
GlobaLeaks 0.2 is part of a wider vision to enable thousands organizations to setup secure anonymous digital dropbox within a model that can satisfy the different concrete and practical requirements of various users.
It's not just a file upload with some HTML form, it's globaleaks.
To download the video visit: http://bit.ly/OHM13_down
Playlist OHM 2013: http://bit.ly/OHM13_pl
Speaker: Karnei Gozman
A birds eye view of the diagrammatic representation of Rayleigh-Schrödinger Perturbation Theory(RSPT), a general formula for generating perturbed calculations. plus a a brief, mostly inaccurate introduction to programing for quantum computers.
Quantum computation requires a different type of calculation unlike current modern day stochastic analysis.
Rayleigh-Schrödinger Perturbation Theory is a good place to start thinking about where this new computation could lead us.
To download the video visit: http://bit.ly/OHM13_down
Playlist OHM 2013: http://bit.ly/OHM13_pl
Speaker: Zoltan Balazs
Hacking client side protection systems (sandboxes, internet security suites, financial endpoint protection systems) with malicious browser extensions.
In 2012 I have created and published proof-of-concept malicious browser extensions for Firefox, Chrome and Safari. With these, one can steal cookies, passwords, spy on webcam, use the browser as a proxy, change financial transactions in the background, steal files, and many more malicious things. In this presentation I will investigate the internet security suites, "safe browsers", sandboxes and how they (don't) protect against malicious browser extensions running in user space. In the second part of the presentation I will hack the "financial endpoint protection systems" usually offered by financial institutions with phrases like "Use this and you'll be safe".
My presentation will be about a unique research on how the "hacking game" is shifting from the operating system to the browser, how the current solutions work and how they can be circumvented. Three hacking demos will be shown, two including Paypal.
To download the video visit: http://bit.ly/OHM13_down
Playlist OHM 2013: http://bit.ly/OHM13_pl
Speakers: Annie Machon | Ray McGovern | Coleen Rowley | Thomas Drake | Nick Farr | Jesselyn Radack
Former employees of three-letter-agencies-that-are-out-to-get-you talk about where we are in the world and what we can do to fix it.
To download the video visit: http://bit.ly/OHM13_down
Playlist OHM 2013: http://bit.ly/OHM13_pl
Speaker: RFguy
A View about mechanical/electronic Masterkey Systems that use at your home, in comercial installations and even critical public infrastructure. Analyse of possible attaks and masterkey generation.
Take a view to the technical Background of mechanic and electronic Masterkey Systems. A detailed view different Variants of mechanical construction of these systems, advance and disadvance.
Generation of the Masterkey without knowing it's mechanical data, defeats the security of obscurity, what is the only way to hide the Masterkey data. Also an overview of currently used electronic key system, that still used old crypto variants and its security of obscurity in 100 % marketing. Active and passive Transponder technologie, combined mechanical/electronic systems.
Some possible attaks to Masterkey systems
Access different doors in private living areas.
Get access even to restricted key profiles.
Lock systems in elevators, electric access panals and firemen access.
Security in public telephone, power and transport facelities.
To download the video visit: http://bit.ly/OHM13_down
Playlist OHM 2013: http://bit.ly/OHM13_pl
Speaker: Elger Jonker
Every month for eight years a warez compilation disc was released under the name Twilight. Selling over 60.000 each month, not getting caught and transforming from piece of art to shrinkwrap.
From the mid-ninenties to the early 2000's a warez compilation cd was released under the name Twilight. It featured the latest and greatest in games and applications and was sold for 25 Dutch guilders via friends and collegues. With a total of 89 volumes and absolute secrecy, it's a challenge to find how well they managed.
Challenge accepted: each and every Twilight was taken apart to find clues, mistakes, hidden gems and easter eggs. All this resulted in a great overview and timeline of a magnificent warez compilation CD where greatness tranformed into criminality.
In all the madness of running an illegal product for eight years, did they manage to uphold their standards, or where the pirates being pirated?
To download the video visit: http://bit.ly/OHM13_down
Playlist OHM 2013: http://bit.ly/OHM13_pl
Speaker: Genomic Gastronomy
Hacker and maker communities are increasingly interested in food, food politics and food security. From open source kitchen hardware, to recipe databases there are many natural crossovers. However, food is not code. This talk will present a few projects that are attempts at hacking the food system beyond the screen and outside of the home kitchen. We will have copies of our new journal 'FoodPhreaking" on hand.
Hacker and maker communities are increasingly interested in food, food politics and food security. From open source kitchen hardware, to recipe databases there are many natural crossovers. However, food is not code. Fantasies of on-demand, 3-D printed food are interesting to prototype, but they do not accurately capture the ecological, biological, cultural or political dimensions of the human food system. The values of free information and open culture are applicable to the food system, and hackers can help build these open systems and open cultures by following the organisms.
This talk will present a few projects (Glowing Sushi Cooking Show, Vegan Ortolan Cooking Competition, Cobalt-60 Sauce, Smog Tasting & Curry for Cascadia) that are attempts at hacking the food system beyond the screen and outside of the home kitchen. Building on our talk from 2011's Chaos Communication Congress we want to share ingredients, databases, security flaws and ideas from the global food system that hackers can explore, exploit and experiment with. In particular we want to present the biological, ecological and cultural dimensions of the food system, answer questions, and brainstorm ways to strengthen and deepen the crossovers between foodies and hackers.
We will have copies of our new journal 'FoodPhreaking" on hand.
To download the video visit: http://bit.ly/OHM13_down
Playlist OHM 2013: http://bit.ly/OHM13_pl
Speaker: Stefan Arentz
Firefox OS is a new mobile operating system developed by Mozilla. It is built on web technology and is following the same principals which have made the web a success: open, hackable, universal. This talk will explain how Firefox OS functions both at low and high level, how you can hack on it and how you can write applications for it.
Firefox OS is built entirely on web technologies using Open Source Software. Everything the user sees and interacts with is rendered using standard HTML and CSS. All application code is written in JavaScript, as is the implementation of many of the new APIs which are exposed to applications and web pages.
This talk will focus on three areas to get people excited about this new Mozilla initiative: how does it work, how hackable is it and how can you write apps for it.
There will first be a high-level overview of the architecture of the Firefox OS platform, introducing key concepts and explaining how it's components interact at a basic level.
Then you will learn how you can hack on Firefox OS, either on real devices or in an emulator. You will also see how you can grab the source code, make modifications and push a customized version of Firefox OS to your phone.
The last part of the talk will focus on writing applications for end-users. You will get a good idea about technologies used and what you need to do to get started.
To download the video visit: http://bit.ly/OHM13_down
Playlist OHM 2013: http://bit.ly/OHM13_pl
Speaker: Philippe Langlois
Nothing's wrong with Telecom Security? No, not according to vendors, not according to some operators. Why? Because most of them benefit from the relative absence of awareness of its actual lack of security. SS7 is totally unauthenticated. Even Diameter, which is recent, doesn't show much in term of message authentication. Supporting systems are unpatched and using default. Telecom applications are developed without security in mind. Telecom protocol stacks are largely untested, or just at the IP level - and that applies even to the super recent S1 and X2 LTE EPC stacks from most of the vendor. IPsec is used as snake oil "patch all" remedy, which in reality is not really helping. Message reach and depth into the network shows how unadequate the security model is, enabling many peers to crash HLRs, HSSes, MMEs and MSCs. ATCA based systems make it even more hackable, from monolithic legacy stacks to now recent but outdated Linux distributions. There's something wrong in this domain.
One of the reason is the lack of expertise and the obscurity about security information from the vendor. How can we get away from this status quo?
We'll talk about professional disclosure on security vulnerability in Core Network elements, in billing systems, in Network Management Systems and OSS. We'll see how Vulnerability knowledge is key for operators, governments AND for vendors. We will also investigate the practical consequences of Telecom Security regulation from India Department of Telecommunications (DOT/TRAI) and see how this can go further. We will also speak about the emerging role of TCERT (Telecom CERT) compared to 3GPP SA3 and GSMA Security Group.
To download the video visit: http://bit.ly/OHM13_down
Playlist OHM 2013: http://bit.ly/OHM13_pl
Speaker: Ajin Abraham
The talk is about abusing and exploiting Firefox add-on Security model and explains how JavaScript functions, XPCOM and XPConnect interfaces, technologies like CORS and WebSocket, Session storing and full privilege execution can be abused by a hacker for malicious purposes. The widely popular browser add-ons can be targeted by hackers to implement new malicious attack vectors resulting in confidential data theft and full system compromise. This paper is supported by proof of concept add-ons which abuse and exploits the add-on coding in Firefox 18, the release which Mozilla boasts to have a more secure architecture against malicious plugins and add-ons. The proof of concept includes the implementation of a Local keylogger, a Remote keylogger, stealing Linux password files, spawning a Reverse Shell, stealing the authenticated Firefox session data, and Remote DDoS attack. All of these attack vectors are fully undetectable against anti-virus solutions and can bypass protection mechanisms.
I will be explaining the Firefox add-on structure, weakness of Firefox Security model, about how features like XPCOM, XPConnect, technologies like CORS, WebSocket, authenticated Session data saving feature etc. can be abused and exploited by a hacker resulting in data theft and full system compromise. I will also describe an attack scenario of spreading the malicious add-on by different methodologies effectively and will discuss about the mitigation strategies. Finally concludes with how it makes a real threat to security, a challenge for anti-virus vendors and addressing a serious security flaw in the security architecture to Mozilla foundation.
To download the video visit: http://bit.ly/OHM13_down
Playlist OHM 2013: http://bit.ly/OHM13_pl
To download the video visit: http://bit.ly/OHM13_down
Playlist OHM 2013: http://bit.ly/OHM13_pl
Speaker: Anwen
The pursuit of happiness is an age-old meme that desperately requires an update to meet the needs of the networked nerd. Here's how and why.
To paraphrase Eric S. Raymond, every (Open Data) project starts with an itch you have to scratch. My "itch" had already been the topic of mental health in hacker and activist communities for quite some time - but with the death of Aaron Swartz in Jan.2013, the need to scratch became unbearable.
As more and more parts of everyday life move online, the Internet is more noticeably turning into a "psychological" space. (Maybe it's been that way all along, but in any case, "special-needs" networks and increasingly public communication of mental issues are on the rise.)
And despite the development of relatively new research angles within "Internet psychology" and big data, a lot of Nerds feel underserviced by conventional psychology. It is the networked public itself, not the psychologists and experts, that is finding new ways of dealing with the emotional demands of a specific demographic.
Aaron's death showed us how a wave of empathy and sorrow can spread globally in real-time -- are such metrics already indicators of another, more sensitive and compassionate web? How do we change online "life quality"? Are our identities lost in transmission, negotiated somewhere between Facebook profile neurosis and the statistical glitches of OKCupid user data? Will Big Data finally make us all happier?
These are some of the very simple questions I want to discuss - along with some very messy answers on the matter of happiness, mental health and big data. Ideally this talk will include an "Eudaimonia 101", a debate on World-Coping for nerds, supported by current examples, projects and community developments, as well as ample time for discussion and questions.
To download the video visit: http://bit.ly/OHM13_down
Playlist OHM 2013: http://bit.ly/OHM13_pl
Speaker: Annie Machon
The tide of history is with us — more and more countries are speaking out about the failure of prohibition. LEAP (Law Enforcement Against Prohibition) supports and contributes to this discussion.
LEAP has representatives across the world with a wide range of professional expertise: police officers, drug czars, judges, prison governors, lawyers, drug enforcement officers, and even the occasional former spook....
Our varied experiences on the front line of the "war on drugs" have brought us to one conclusion: we all assess it to have been an abject failure that causes more global societal harm than good, as well as funding organised crime, terrorism and white collar bank crime.
We urgently need to rethink the failed UN drug conventions.
To download the video visit: http://bit.ly/OHM13_down
Playlist OHM 2013: http://bit.ly/OHM13_pl
Speaker: Vinay Gupta
Within 10 years, the villages and slums of the world are going to join the internet, unleashing revolutions in education, connectivity, and potentially politics.
In this talk we will discuss engineering out way out of a global crisis that few are even willing to full acknowledge: we are slaughtering the poor and killing the ecosystem we evolved in at an ever-increasing rate, while our governance structures regulate the only structure humanity has built which might scale to provide a solution.
Long neglected thinkers on the political aspects of engineering hold the keys to a solution. We will rattle their cages.
This is going to be a gruelling, hard going talk. Most "internet native" politics are weak on global issues and operate within a European or American frame. Even Stallman, when he talks about the world, carries strongly western assumptions.
There is another politics, hidden behind our cultural façade: the engineering-led globalism of Buckminster Fuller, and the Autonomist Socialism of Mahatma Gandhi. Both Fuller and Gandhi are misunderstood and marginalized: what both discussed was the practical business of creating a world without political oppression by getting the engineering right! Gandhi's work on assessing the social and economic impact of technologies before adopting them was central to his critique of the Industrial Revolution - with one hand, it automated, and with the other hand, it taxed to feed people without employment. We remember the Salt March, but we forget Gandhi's vision of an economy built on self-sufficient village-scale engineering.
To download the video visit: http://bit.ly/OHM13_down
Playlist OHM 2013: http://bit.ly/OHM13_pl
Speaker: Ot van Daalen
Bits of Freedom got relaunched at HAR2009. Now that four years have passed we would like to provide you with a summary of what we did in the meantime, but also what we are working on right now.


