<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>33C3 on Insinuator.net - Bold Statements</title>
    <link>https://insinuator.net/tags/33c3/</link>
    <description>Recent content in 33C3 on Insinuator.net - Bold Statements</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Tue, 14 Feb 2017 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://insinuator.net/tags/33c3/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Summary of “Lockpicking in the IoT” at 33C3</title>
      <link>https://insinuator.net/2017/02/summary-of-lockpicking-in-the-iot-at-33c3/</link>
      <pubDate>Tue, 14 Feb 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/02/summary-of-lockpicking-in-the-iot-at-33c3/</guid>
      <description>&lt;p&gt;“Lockpicking in the IoT, …or why adding BTLE to a device sometimes isn’t smart at all” by Ray was one of my favourite talks, as it beautifully showed many different attack vectors as well as giving a nice guide for getting started in this area.&lt;/p&gt;&#xA;&lt;p&gt;It impressed me how carefree vendors and startups handled hardware and software security in “smart” devices as it seems that their devices were more or less easy to own. In his talk Ray pointed out physical AND implementational weaknesses that remained even after he reported them to the vendors.&lt;br&gt;&#xA;The most prominent sample he gave was when he opened a “Masterlock” by spinning a magnet on the lock itself to open it.&lt;/p&gt;</description>
    </item>
    <item>
      <title>33c3 Talks – What could possibly go wrong with “insert x86 instruction here” ?</title>
      <link>https://insinuator.net/2017/02/33c3-talks-what-could-possibly-go-wrong-with-insert-x86-instruction-here/</link>
      <pubDate>Wed, 01 Feb 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/02/33c3-talks-what-could-possibly-go-wrong-with-insert-x86-instruction-here/</guid>
      <description>&lt;p&gt;&lt;a href=&#34;https://media.ccc.de/v/33c3-8044-what_could_possibly_go_wrong_with_insert_x86_instruction_here&#34;&gt;This&lt;/a&gt; was one of the few technical talks at 33c3 I managed to see, by that I mean live-stream during an access control shift, by Clémentine Maurice and Moritz Lipp.&lt;/p&gt;&#xA;&lt;p&gt;The talk gave an overview of some already known possible information leaks by abusing certain x86 instructions(the same concept applies to ARM too though) and demonstrating the various ways an attacker could use them. They started off by quickly explaining how the caches on modern CPUs are set up and how they work and how you can exploit the timing differences in memory accesses to leak data without actually knowing the content of the cache. This data leak can then be used to establish a covert channel.&lt;/p&gt;</description>
    </item>
    <item>
      <title>ERNW at 33C3 – Part 1</title>
      <link>https://insinuator.net/2017/01/ernw-at-33c3-part-1/</link>
      <pubDate>Thu, 26 Jan 2017 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2017/01/ernw-at-33c3-part-1/</guid>
      <description>&lt;p&gt;This is &lt;strong&gt;part 1&lt;/strong&gt; of our report series on &lt;strong&gt;interesting talks of the 33rd Congress&lt;/strong&gt; of the Chaos Computer Club. Every year the congress attracts hundreds (up to twelve thousand this year) of technical interested people with the opportunity to socialize and exchange knowledge with each other. The congress is organized by the European largest hacker association and speakers give talks about technical and societal issues like surveillance, privacy, freedom of information, data security and various more.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Woolim – Lifting the Fog on DPRK’s Latest Tablet PC</title>
      <link>https://insinuator.net/2016/12/woolim-lifting-the-fog-on-dprks-latest-tablet-pc/</link>
      <pubDate>Wed, 28 Dec 2016 00:00:00 +0000</pubDate>
      <guid>https://insinuator.net/2016/12/woolim-lifting-the-fog-on-dprks-latest-tablet-pc/</guid>
      <description>&lt;p&gt;Niklaus, Manuel and me had a great time speaking about one of the latest Tablet PCs from DPRK at &lt;a href=&#34;https://fahrplan.events.ccc.de/congress/2016/Fahrplan/events/8143.html&#34;&gt;33C3 this year&lt;/a&gt;. Our work on &lt;a href=&#34;https://insinuator.net/2015/07/redstar-os-watermarking/&#34;&gt;RedStar OS from last year&lt;/a&gt; revealed a nasty watermarking mechanism that can be used to track the origin and distribution path of media files in North Korea. We have seen some interesting dead code in some of RedStar’s binaries that indicated a more sophisticated mechanism to control the distribution of media files. We got hands on a Tablet PC called “Ul-lim” that implemented this advanced control mechanism.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
