Hacking qlutoo got a talk at 34c3's console hacking/security section!

  • Thread starter Thread starter adrifcastr
  • Start date Start date
  • Views Views 76,709
  • Replies Replies 383
  • Likes Likes 19
oh....so no congress for me...i live in Hamburg and cant affort to travel to Leipzig

--------------------- MERGED ---------------------------

the Congress Center Hamburg is being rebuild....know i remember..thats why it is not in Hamburg this time...crap

--------------------- MERGED ---------------------------

i know the CCC a friend of mine is member
 
well he will not be alone at the 34c3
ScreenShot_20171214000722.png
 
Last edited by TheGreek Boy,

Looks like what I suspected, he (they) will be going into what they've learned about the security of the system and discussing why its as secure as they suggest. So this may indeed be fairly disappointing for those who aren't actually interested in this from the perspective of what it is and only for 'the hax'.

I don't see him revealing anything actually critical here but it may serve as a guide (especially since homebrew in general is already possible, so they may even spend time discussing Rohan's security flaw).

Reminds me of the first PS4/Linux fail0verflow presentation, except I don't expect them to hot-wire it on stage.
 
Last edited by V-Temp,
Looks like what I suspected, he (they) will be going into what they've learned about the security of the system and discussing why its as secure as they suggest. So this may indeed be fairly disappointing for those who aren't actually interested in this from the perspective of what it is and only for 'the hax'.

I don't see him revealing anything actually critical here but it may serve as a guide (especially since homebrew in general is already possible, so they may even spend time discussing Rohan's security flaw).

Reminds me of the first PS4/Linux fail0verflow presentation, except I don't expect them to hot-wire it on stage.
Actually, sounds like something I would enjoy a lot.
I hope they stream it (they usually do)... and I hope I have an Internet service available for that date (moving/changing providers in the next weeks)
 
  • Like
Reactions: V-Temp
Actually, sounds like something I would enjoy a lot.
I hope they stream it (they usually do)... and I hope I have an Internet service available for that date (moving/changing providers in the next weeks)

I certainly will enjoy it. Twas more a bit of attempt to check the expectations of others.
 
Looks like what I suspected, he (they) will be going into what they've learned about the security of the system and discussing why its as secure as they suggest. So this may indeed be fairly disappointing for those who aren't actually interested in this from the perspective of what it is and only for 'the hax'.

I don't see him revealing anything actually critical here but it may serve as a guide (especially since homebrew in general is already possible, so they may even spend time discussing Rohan's security flaw).

Reminds me of the first PS4/Linux fail0verflow presentation, except I don't expect them to hot-wire it on stage.
If you're going by past c3's (32 and 33), pluto and derrek revealed just enough info in their talks for other programmers to implement the exploits that were discussed. Sometimes it took months, but it eventually would get done.
That doesn't mean it has to happen that way again in 34c3, but it does give one a good hope or two.
 
If you're going by past c3's (32 and 33), pluto and derrek revealed just enough info in their talks for other programmers to implement the exploits that were discussed. Sometimes it took months, but it eventually would get done.
That doesn't mean it has to happen that way again in 34c3, but it does give one a good hope or two.

Well yes, I said a guide after all. But he's not going to just dump a step-by-step instruction manual. And given the Switch's rigid security (and part of this talk no less), hints and a guide may take time and a lot of work to reproduce.

Or maybe no one will or it will take years, hence why I referenced PS4/Linux.

For end users and hax, Rohan's already here.
 
  • Like
Reactions: zoogie
Also as a german, I wonder if naehrwert (if he isn't german, idk if he is) knows that naehrwert (mostly written in modern grammar as "nährwert") means "nutritional value"
 
Also as a german, I wonder if naehrwert (if he isn't german, idk if he is) knows that naehrwert (mostly written in modern grammar as "nährwert") means "nutritional value"
Maybe that's what it means since he likes to post foodie pics on twitter.

Anyway, I think it would be a good idea to post that link in the OP, or better, a pic of it since it has important info like the date, time, and location of the event. That's the main reason I tagged you before.
 
  • Like
Reactions: adrifcastr
Maybe that's what it means since he likes to post foodie pics on twitter.

Anyway, I think it would be a good idea to post that link in the OP, or better, a pic of it since it has important info like the date, time, and location of the event. That's the main reason I tagged you before.
yeah I know, I just came back from school lol, I'll screenshot the schedule w my pc, I'm at the phone rn, gimme some mins
 
  • Like
Reactions: zoogie
https://en.wikipedia.org/wiki/Chaos_Communication_Congress

The C(haos)C(omputer)C(lub) originally was urged to be founded (taking on the official status of a club, having an organisational structure thats transparent, ...) so that the german government would _not_ "have to declare them a terroristic union", as is often only half jokingly said about their creation myth.

Hacker conventions "happen" around the world openly and especially in the US are frequently sponsored and or attended by government agencies to recruit talent - so essentially, they are almost abused by governments in that regard. ;) The Chaos Communication Congress in germany is one of the biggest gatherings in the world, and it is entirely self financed (through ticket sales), so no corporate or state sponsors there. :)

Just like with any congress - at least one overarching theme per year, an open call for papers, and a committee that decides who can talk and when. ;) (Also a couple of events on the side.)

Also - its the only hacker con where all talks are livestreamed to the net (for free), and then available on demand afterwards (for free). (In some very rare cases (usually because of licensing issues) some talks may not be streamed.) Anyone can participate via livestream and chat, anyone can buy tickets - although they are usually sold out very quickly - even doing staged ticket sales, so more people have a chance of getting one for non scalper prices.

Videos of previous talks can be found on media.ccc.de or youtube.

F.e.:




The knowledge a "hacker" accumulates isnt illegal. Reverse engineering hardware isnt illegal (might depend on where youre from). But, other stuff is. The CCC also offers legal council for its members (onother reason why it was founded), and in the past decades has given technical council to the german government on more than one occasion (but also published, analyzed and contextualized their spy trojans, in the german media ;) ) , and is a nonprofit that hopefully helps us never to sink as low as the United States just did today by dropping net neutrality ("they talk to politicians").
 
Last edited by notimp,
OK...
we are pretty familiar with the proceedings around here
Sweet, now - when will you come around to explain to new folks, that hacking isnt necessarily what Hollywood and the news make it look like to normal people? :) I didnt write the short synopsis to outdo anyone, or to explain the obvious to the innitiated - but to make it perfectly clear that there are those big "contact surfaces" to what "hackers do" out there in the open for anyone to lock at, if they find it interesting.

Hacker in the way that a Steve Wozniak never became tired explaining, is just someone that wants to understand how technology works, and change its behavior, playing around with it. Most of the people you see on stage at the console hacking panels, are computer science students learning on a project. Their main motivation, more often than not is taking things apart to understand how they work.

The negative connotation towards the "image" of a hacker comes out of "normal folks" not understanding, what they are doing. The social stigma comes out of one person understanding how systems work, being able to accumulate individual "powers", that previously were only held by "bigger actors" (state, industries, ...). From that comes an institutional need to get a handle on what those groups are doing, which is why government agencies usually show interest. From the inner understanding, what you are able to do as a group usually comes an ethos that actually drives "self regulation" (more than in any corporate sector I've seen).

Now, the 300 kids and adults that hacked into the NASA computers at the onset of "this internet thing" and "shared passwords" did this, because they liked to understand the systems, and loved the doors with the big "no entry" sign on them. That nowadays they could use the same drive to analyze a state trojan, modify it to become ransom ware, and stop the largest freight shipping fleet in the west for more than three months, makes them children, criminals, or entrepreneurs depending on whom you ask, and when in the process they stop. :)

Also - in the US there is an extreme "libertarian" angle to the scene, and always has been - that gets very easily exploited by anyone that knows how to stroke a kids ego (NSA, DoD, ...), and thats proven unfit to uphold even the most plain societal needs (open Internet, net neutrality, not surveying everyone in the world...). (I think thats worth a little slant.. Also considering, that the big five are all within your "jurisdiction" (FB, Amazon, Google, Apple, MS).) -

But the fundementals stay the same - ultimately its not in societies interest to prevent folks from trying to understand technology, and if in silicon valley every angel investor throws away millions trying to find a way how to psychologically exploit human minds (all over the world) in a reward loop using a phone app, you dont have to work for a far eastern crime ring to exploit inter banking transaction systems to skim cents of a dollar - illegally, or set up fake news sites with far right content to sell to americans, that like to click on that stuff in facebook, when they have an election pending.

The hollywood hacker mainly only ever existed, because he was such a good plot device to suspend disbelief. You show someone in a hoody hammering on a keyboard - and voila, deus ex machina. (You can look that up on Wikipedia. :) )

If you look into the actual examples of hackers being dragged to court in the early days in the US, you more often than not end up with scenarios where kids with aspergers were jailed for months, and sometimes even years for "their potential to do whatever the judge and the prosecutor could imagine in their wildest dreams". ("Whisteling nuclear launch codes into a phone." is a direct quote, I believe.) Or people being jailed for violating individual or a companys privacy, which is (now) basically what the NSA does in a nutshell. (Also Facebook (shadow accounts, face tracking on images, ..), Google (Android location services, Gmail automated content parsing, geolocation specific search results, ...), Apple (BT low energy beacons, find my iPhone, ...)
 
Last edited by notimp,

Site & Scene News

Popular threads in this forum