35C3 is over, and the recordings are available so in case you did not have the
chance or the time to watch the live streams during the holidays or overwhelmed
with the number of talks, see in the following a list of recommended talks to
fill your evenings or weekends. Apart from the broad coverage of topics in
different areas (Ethics, Society & Politics, Hardware & Making, Resilience, Art
and Culture, Security, Science, Resilience), foundation talks were aiming for
the very basics following this year’s motto “Refreshing Memories.”
This blogpost will be about my first steps with coreboot and libreboot and a
life with as few proprietary firmware blobs as possible. My main motivation were
the latest headlines about fancy firmware things like Intel ME, Computrace and
UEFI backdoors. This post is not intended to be about a as much as possible
hardened system or about coreboot/libreboot being more secure, but rather to be
able to look into every part of software running on that system if you want to.
“Lockpicking in the IoT, …or why adding BTLE to a device sometimes isn’t smart
at all” by Ray was one of my favourite talks, as it beautifully showed many
different attack vectors as well as giving a nice guide for getting started in
this area.
It impressed me how carefree vendors and startups handled hardware and software
security in “smart” devices as it seems that their devices were more or less
easy to own. In his talk Ray pointed out physical AND implementational
weaknesses that remained even after he reported them to the vendors.
The most prominent sample he gave was when he opened a “Masterlock” by spinning
a magnet on the lock itself to open it.
This
was one of the few technical talks at 33c3 I managed to see, by that I mean
live-stream during an access control shift, by Clémentine Maurice and Moritz
Lipp.
The talk gave an overview of some already known possible information leaks by
abusing certain x86 instructions(the same concept applies to ARM too though) and
demonstrating the various ways an attacker could use them. They started off by
quickly explaining how the caches on modern CPUs are set up and how they work
and how you can exploit the timing differences in memory accesses to leak data
without actually knowing the content of the cache. This data leak can then be
used to establish a covert channel.
This is part 1 of our report series on interesting talks of the 33rd
Congress of the Chaos Computer Club. Every year the congress attracts hundreds
(up to twelve thousand this year) of technical interested people with the
opportunity to socialize and exchange knowledge with each other. The congress is
organized by the European largest hacker association and speakers give talks
about technical and societal issues like surveillance, privacy, freedom of
information, data security and various more.
Hello everybody and welcome to the second part of our 32C3 recap!
In case you didn’t see
the first part, make sure
to check it out 😉
Logjam
by **Nadia Heninger & Alex Halderman
**Video |
Slides
This talk was held by Nadia Heninger and Alex Halderman on the second day of the
congress. Both work in academic and the field of cryptology. They talked about
the “Logjam”-Attack they and several colleagues discovered and published in may
of 2014. They started their talk by explaining how they uncovered the
vulnerability which was quite interesting since Logjam was no breaking news
anymore. And well it was inspired by the congress of the year before, 31C3. The
research was conducted because they got curious how the NSA might be able to
decrypt VPN traffic as stated by Jacob Applebaum and Laura Poitras in their
“reconstructing narratives” talk.
Niklaus and me had the chance to talk about our research on RedStar OS on the
32nd Chaos Communication Congress in Hamburg this year. You can see the talk
online at
media.ccc.de
or on Youtube.
We talked about the details of the watermarking mechanism that
we found in July
and additional features of RedStar OS like it’s “Virus Scanner” and the system
architecture. During the days after our talk we were able to find watermarks
applied by RedStar OS in the wild on some sites on the Internet. We can confirm
at least 7 different instances of RedStar OS that have applied watermarks to
JPGs. Cleaning up the data is work in progress and we will get back to you with
the results! Niklaus has put our presentation and additional resources in the
git. Feel free to join us in our
research and make the world a safer place!
As every year some of us used the holidays to visit the Chaos Communication
Congress to socialize with like-minded people and to hear interesting talks.
I mean what other reasons than learning about security might exist to leave
behind all your lovely in-laws you’ve been sharing some relative’s house with
the days before … 😉
Here is a short recap of some of the talks we found most interesting:
Mining for Bugs with Graph Database Queries by Fabian Yamaguchi Video
One of my favorite talks at this years congress was about the open source tool
joern, a code analysis platform for C/C++
applications. Fabian, the main author of joern, presented his work on
vulnerability discovery in large code bases. One of the key points of his work
is robustness, meaning that the resulting tools should produce meaningful
results in large and noisy real world projects even if this results in a loss of
accuracy. The second important point is that tools should assist human auditors,
not replace them, which seems to be one of the more interesting current research
directions (see also
this paper).
At its core joern combines standard compiler technology with modern graph
databases to offer auditors a powerful way to search for certain code
constructs. To do this joern parses source code into an AST (Abstract Syntax
Tree) and creates the corresponding CFG (Control Flow Graph), as well as a Data
Dependency Graph (PDG) for all functions. This creates the Code Property Graph
which combines all three representation forms into a single unified layer.
The Code Property Graph is stored inside a graph database (joern uses
neo4j), which can be queried using a powerful graph
traversal language named gremlin
(https://github.com/tinkerpop/gremlin/wiki). The combination of gremlin with
some wrapper tools included in joern gives an auditor the possibility to
construct powerful search queries against the code base. Fabian presented
different queries he used to search for vulnerabilities in the VLC video player,
as well as the Linux kernel that resulted in really impressive results (and a
high number of discovered vulnerabilities). Joern is definitely a tool you
should check out and I’m looking forward to more impressive research by its
author.
– Felix
We wish you a happy new year and a good start to 2014. A new year has begun and,
just before that, 30C3 took place. I think almost all of you have heard about
the congress and its topics. In particukar there was Glenn Greenwald’s
keynote or
there were new
publications/revelations
by Jacob Appelbaum, which you will probably have heard about from main media.
But besides of all that, there were really a lot of other interesting talks we
want to give you a short introduction to. Overall it was a really good
conference this year and a lot of awesome talks. But, like always, it is not
possible to see all of them, so here is a short summary of some of our
favorites: