{"conference_events":{"version":"CCC’84 nach Orion’64","events":[{"id":12338,"guid":"fddf9aa7-4952-497e-b706-2e802deef3cc","title":"37C3: Feierliche Eröffnung","subtitle":null,"description":null,"duration":1800,"logo":null,"type":"lecture","do_not_record":false,"track":"CCC","abstract":"Achievement unlocked! Der 37C3 öffnet seine Pforten und heißt das Publikum herzlich willkommen. Von erfahrenen Zeremonienmeistern wird Euch hier der notwendige Schwung verpasst, geschmeidig durch den Congress zu gleiten und die Vorfreude zu atmen, die das gesamte Team seit Monaten auf die Veranstaltung im Herzen trägt.","speakers":[{"guid":"a57b4a91-0621-553c-a97d-6b47df0f3f0e","id":19387,"image":"/system/people/avatars/000/019/387/original/derPUPE_avantar_github_1777337_zB27KA1.png?1701967119","name":"derPUPE","public_name":"derPUPE","abstract":"Jüngster Allhippy aller Zeiten - Information Security Manager bei der Deutschen Bahn AG, Hacker im Herzen und Datenschützer aus Überzeugung - Konzerndebugger mit einer humanoiden uptime von 50 years 6 months $days ago - Generation C64 / ZX81 - beruflich: seid 14 Jahren im Bereich IT und Information Security Management und Datenschutz in internationalen Konzernen tätig. Davor IT Normade mit verschiedensten Stationen siehe XING / LinkedIN. Kulturell geprägt durch das DFUE-Netz seid meines ersten Modems1988, dder WarezScene und Reisen in den Datennetzen dieser Welt .. Hobbies: typische nerdthemen + addons \u0026 Hörbucher, Schach und meine Mitmenschen. Slogan: Patch yourself to improve the system .. Bei Twitter steht: \"Weltensegler \u0026 Proclamator des gepflegten Schabernacks. Deutschlands jüngster Althippy - Überparteilichwirkender VollHerz Gesellschaftspatcher\", was neben meiner Beruflichen Profession mich immer noch sehr gut beschreibt. Durch FoeBud und CCC schon frühzeitig im Thema Datenschutz und Bürger:innen-Rechgte sozialisiert- Mitbegründer der Piratenpartei. Durch langjährlich Besuche auf nationalen und internationalen IT Management und Datenschutzkonferenzen habe ich in vielen Gespächen neben den eigenen die Wirkungsmechanismen in großen Firmen bei der Umsetzung und Kulturwandel kennenlernen dürfen.","description":null,"links":[]},{"guid":"a8991e85-b553-5ed0-bc66-c219d3d8ba2f","id":8662,"image":"/system/people/avatars/000/008/662/original/Katta_Quadrat.png?1539638331","name":"Katharina Nocun","public_name":"Katharina Nocun","abstract":"Katharina Nocun ist Publizistin und Autorin mehrerer Bücher. ","description":"Sie hat Politics, Economics \u0026 Philosophy (M.Sc.) an der Uni Hamburg studiert. Ihre Abschlussarbeit beschäftigte sich mit Markteintrittshürden für dezentrale Soziale Netzwerke. In ihrer Arbeit setzt sie sich vor allem mit dem Spannungsfeld Digitalisierung und Demokratie auseinander. Ihr Podcast Denkangebot war 2020 für den Grimme Online Award nominiert. Ihr erstes Buch \"Die Daten, die ich rief\" (2018) behandelt das Thema Datensammlungen von Staat und Konzernen. 2020 folgte der Bestseller \"Fake Facts – Wie Verschwörungstheorien unser Denken bestimmen\" (gemeinsam mit Pia Lamberty). Im Mai 2021 erschien das zweite gemeinsame Buch \"True Facts – was gegen Verschwörungserzählungen wirklich hilft\" und im September 2022 das dritte gemeinsame Werk \"Gefährlicher Glaube – Die radikale Gedankenwelt der Esoterik\".","links":[{"url":"https://www.kattascha.de","title":"Blog"},{"url":"https://twitter.com/kattascha","title":"Twitter"},{"url":"https://chaos.social/@kattascha","title":"Mastodon"},{"url":"https://www.denkangebot.org/","title":"Podcast Denkangebot"}]},{"guid":"a51ee48a-4185-58b4-a664-da02a3caa3ca","id":19505,"image":null,"name":"Mullana","public_name":"Mullana","abstract":null,"description":null,"links":[]}],"start_time":"2023-12-27T10:30:00.000+01:00","end_time":"2023-12-27T11:00:00.000+01:00","room":{"name":"Saal 1","id":471}},{"id":12339,"guid":"1dbaf470-5dff-4cbb-a1ef-40d75c01c43f","title":"37C3: Feierlicher Abschluss","subtitle":null,"description":null,"duration":1800,"logo":null,"type":"lecture","do_not_record":false,"track":"CCC","abstract":null,"speakers":[{"guid":"a8991e85-b553-5ed0-bc66-c219d3d8ba2f","id":8662,"image":"/system/people/avatars/000/008/662/original/Katta_Quadrat.png?1539638331","name":"Katharina Nocun","public_name":"Katharina Nocun","abstract":"Katharina Nocun ist Publizistin und Autorin mehrerer Bücher. ","description":"Sie hat Politics, Economics \u0026 Philosophy (M.Sc.) an der Uni Hamburg studiert. Ihre Abschlussarbeit beschäftigte sich mit Markteintrittshürden für dezentrale Soziale Netzwerke. In ihrer Arbeit setzt sie sich vor allem mit dem Spannungsfeld Digitalisierung und Demokratie auseinander. Ihr Podcast Denkangebot war 2020 für den Grimme Online Award nominiert. Ihr erstes Buch \"Die Daten, die ich rief\" (2018) behandelt das Thema Datensammlungen von Staat und Konzernen. 2020 folgte der Bestseller \"Fake Facts – Wie Verschwörungstheorien unser Denken bestimmen\" (gemeinsam mit Pia Lamberty). Im Mai 2021 erschien das zweite gemeinsame Buch \"True Facts – was gegen Verschwörungserzählungen wirklich hilft\" und im September 2022 das dritte gemeinsame Werk \"Gefährlicher Glaube – Die radikale Gedankenwelt der Esoterik\".","links":[{"url":"https://www.kattascha.de","title":"Blog"},{"url":"https://twitter.com/kattascha","title":"Twitter"},{"url":"https://chaos.social/@kattascha","title":"Mastodon"},{"url":"https://www.denkangebot.org/","title":"Podcast Denkangebot"}]},{"guid":"a57b4a91-0621-553c-a97d-6b47df0f3f0e","id":19387,"image":"/system/people/avatars/000/019/387/original/derPUPE_avantar_github_1777337_zB27KA1.png?1701967119","name":"derPUPE","public_name":"derPUPE","abstract":"Jüngster Allhippy aller Zeiten - Information Security Manager bei der Deutschen Bahn AG, Hacker im Herzen und Datenschützer aus Überzeugung - Konzerndebugger mit einer humanoiden uptime von 50 years 6 months $days ago - Generation C64 / ZX81 - beruflich: seid 14 Jahren im Bereich IT und Information Security Management und Datenschutz in internationalen Konzernen tätig. Davor IT Normade mit verschiedensten Stationen siehe XING / LinkedIN. Kulturell geprägt durch das DFUE-Netz seid meines ersten Modems1988, dder WarezScene und Reisen in den Datennetzen dieser Welt .. Hobbies: typische nerdthemen + addons \u0026 Hörbucher, Schach und meine Mitmenschen. Slogan: Patch yourself to improve the system .. Bei Twitter steht: \"Weltensegler \u0026 Proclamator des gepflegten Schabernacks. Deutschlands jüngster Althippy - Überparteilichwirkender VollHerz Gesellschaftspatcher\", was neben meiner Beruflichen Profession mich immer noch sehr gut beschreibt. Durch FoeBud und CCC schon frühzeitig im Thema Datenschutz und Bürger:innen-Rechgte sozialisiert- Mitbegründer der Piratenpartei. Durch langjährlich Besuche auf nationalen und internationalen IT Management und Datenschutzkonferenzen habe ich in vielen Gespächen neben den eigenen die Wirkungsmechanismen in großen Firmen bei der Umsetzung und Kulturwandel kennenlernen dürfen.","description":null,"links":[]},{"guid":"a51ee48a-4185-58b4-a664-da02a3caa3ca","id":19505,"image":null,"name":"Mullana","public_name":"Mullana","abstract":null,"description":null,"links":[]}],"start_time":"2023-12-30T18:20:00.000+01:00","end_time":"2023-12-30T18:50:00.000+01:00","room":{"name":"Saal 1","id":471}},{"id":12340,"guid":"b9987255-ba10-42d3-be52-5a8aff462666","title":"37c3 infrastructure review","subtitle":"Teams presenting how they helped making this awesome event","description":null,"duration":3600,"logo":null,"type":"lecture","do_not_record":false,"track":"CCC","abstract":"Many teams work hard to arrange the event, this talk allows them to show what they did and who they are.","speakers":[{"guid":"a8a4cae7-16cb-5a64-a94a-ba9a38db198b","id":5355,"image":null,"name":"nicoduck","public_name":"nicoduck","abstract":null,"description":null,"links":[]}],"start_time":"2023-12-30T17:15:00.000+01:00","end_time":"2023-12-30T18:15:00.000+01:00","room":{"name":"Saal Grace","id":472}},{"id":12032,"guid":"18552f41-6ff7-4724-badd-701532dae724","title":"About Gamma-Ray Bursts And Boats","subtitle":"What We (Don't) Know About the Most Energetic Events in the Universe","description":"Gamma-ray bursts are the biggest explosions in our Universe since the Big Bang: In just a few seconds, they release as much energy as the Sun will radiate over its entire lifetime. Even though they occur in far-away galaxies, their emission dominates the high-energy astrophysical sky during their seconds-long duration. They come from the cataclysmic deaths of very massive stars or the mergers of two compact objects such as neutron stars and black holes. In both cases the energy is concentrated in an astrophysical jet moving at approximately the speed of light. \r\nIn October 2022, a once-in-a-lifetime gamma-ray burst smashed records and was dubbed the ‘Brightest of All Time,’ or the BOAT. In fact, it was so bright that it oversaturated the most sensitive gamma-ray burst monitors, posing a challenge for data reconstruction and analysis. But why was it so bright? And how long do we have to wait until the next one? \r\n\r\nUsing the BOAT as an example, we will give an introduction about the fascinating phenomena called gamma-ray bursts. From their accidental discovery during the Cold War to our still surprisingly limited understanding of their nature. The talk will revisit the state-of-the-art of theoretical modelling/interpretations (how are jets launched? what produces the gamma rays?), as well as current detector techniques (how do we catch a gamma-ray photon on Earth or in space?). Naturally, we will also discuss what we really learn from prominent, outstanding events such as the BOAT -- and the questions that still give scientists headaches.","duration":3600,"logo":null,"type":"lecture","do_not_record":false,"track":"Science","abstract":"In October 2022 a gamma-ray burst dubbed the 'Brightest Of All Times' smashed records. But what is that actually, a gamma-ray burst? How do we detect it? And why was the BOAT so special?","speakers":[{"guid":"3ebce8d1-3c51-5a73-8257-52ff0307af78","id":7409,"image":null,"name":"Annika Rudolph","public_name":"Annika Rudolph","email":"annika.rudolph@desy.de","abstract":null,"description":null,"links":[]}],"start_time":"2023-12-29T16:00:00.000+01:00","end_time":"2023-12-29T17:00:00.000+01:00","room":{"name":"Saal Grace","id":472}},{"id":11781,"guid":"59a1c108-e367-4d71-bc50-7073cb8025e6","title":"Adventures in Reverse Engineering Broadcom NIC Firmware","subtitle":"Unlocking a system with 100% open source firmware","description":"This talk is about how I reverse engineered the final remaining firmware blob on the Talos II/Blackbird POWER9 systems, enabling it to be replaced with an open source replacement, in an intensive reverse engineering effort that spanned several years.\r\n\r\nThe talk will begin by introducing the open source firmware movement and its practical and ethical motivations, and note the obstacles to delivering fully open source firmware for contemporary x86 and other platforms and explaining the motive behind the project, before moving onto a more technical discussion of the adventure of firmware reverse engineering and the obstacles encountered.\r\n\r\nSubjects I intend to cover include: how the original proprietary firmware was reverse engineered from scratch with only limited knowledge of device internals; the long history of Broadcom NIC architecture and its evolution over time; the tools that had to be developed to enable the device probing, testing and reversing process; the story of a horrifying but necessary detour into reversing x86 real mode code and the novel methodology used to aid reversing; how modern NICs allow BMCs in servers to share network ports with the host, and the security hazards this creates; and how fully open source firmware was created legally using a clean room process.\r\n\r\nThis talk will be accessible to audiences unfamiliar with POWER9 or the open source firmware community, but is also intended to cover some new ground and be of interest to those familiar with the project. The talk will mainly be of interest to those interested in open source firmware and issues such as owner control and the security and auditability issues caused by proprietary firmware, and to those interested in reverse engineering.\r\n","duration":3600,"logo":null,"type":"lecture","do_not_record":false,"track":"Hardware \u0026 Making","abstract":"In an era where vendors increasingly seek to use proprietary software in the devices around us to exert control over their users, the desire for open source software has expanded to the firmware that allows our machines to function, and platforms which individuals can trust and control have never been more important. However, changes to hardware platforms in recent years such as the Intel ME, vendor-supplied binary blobs and vendor-signed firmware images have repeatedly set back efforts to create open source firmware for the computers we use. The release of Power servers with 99% open source firmware excited many who had been searching for a computer they could trust, but one proprietary firmware blob remained: that of the Ethernet controller. This is the story of how that blob was reverse engineered and replaced with an open source replacement, delivering the first machine with desktop-class performance and 100% open source firmware in many years.","speakers":[{"guid":"f98695f7-d9b2-5f02-b08e-a363fa812255","id":18751,"image":"/system/people/avatars/000/018/751/original/data?1698434183","name":"Hugo Landau","public_name":"Hugo Landau","email":"hlandau@devever.net","abstract":"A hacker and reverse engineer, I believe that computers should be under the control of their owners – and nobody else, in a world which seems to be headed in the opposite direction. I’ve been an owner control activist for over 20 years, having boycotted the upcoming Windows XP when I was 10 years old when I heard it would contain an anti-feature known as ‘product activation’. As functions such as DRM and Tivoisation, which are deliberately intended to work against the user, are added to more and more digital devices, I believe that the idea of hardware the individual user can trust to be on their side has never been more important, or more in danger. Much of my other work is focused on cryptography, decentralisation and mitigating mass surveillance. My fundamental mission is to create technology that empowers individuals. The computer is here to help you – but how often do you feel like that’s the case?","description":null,"links":[]}],"start_time":"2023-12-27T16:00:00.000+01:00","end_time":"2023-12-27T17:00:00.000+01:00","room":{"name":"Saal Grace","id":472}},{"id":11995,"guid":"776e58b5-f46d-4321-b06e-11bf220666f5","title":"A Libyan Militia and the EU - A Love Story?","subtitle":"Open-Source investigating Tareq Ben Zeyad Brigade and their evil deeds","description":"2023, Tariq Ben Zeyad Brigade (TBZ), a notorious East Libyan land-based militia, went maritime. They were deeply involved in the failed passage of the boat that sank near Pylos, in which up to 500 people drowned. For the first time, we unveiled how their new vessel, sponsored by UAE, operates in the Central Mediterranean. We could spot them, intercept communication, and record their crimes. We managed to do so through low-budget, open-source intelligence, voluntary work, and our civil monitoring flights. Our talk materializes at the crossroads of no-border activist nerdiness and broader geopolitical reflections. Starting with our first-hand material, we show TBZ's close ties with condemned war criminals, the smuggling business, the United Arab Emirates, the Frontex agency, and European governments, namely Greece, Italy, and Malta. We see the media being barely interested in the intricacies of Europe's proxy actors, such as TBZ, that help uphold fortress Europe. We will use CCC to discuss what has little space in our daily public work: weird details, daring predictions, and complex interlinkages.","duration":3600,"logo":null,"type":"lecture","do_not_record":false,"track":"Ethics, Politics \u0026 Society","abstract":"2023, Tariq Ben Zeyad Brigade (TBZ), a notorious East Libyan land-based militia, went maritime. They were deeply involved in the failed passage of the boat that sank near Pylos, in which up to 500 people drowned. With the help of low-budget, open-source intelligence, we were the first to unveil how their new vessel operates in the Central Mediterranean and with which European actors they communicate. This talk provides you with the details.","speakers":[{"guid":"20624d26-1361-5273-a7cf-89358334c7fc","id":19271,"image":null,"name":"Paul Wagner","public_name":"Paul Wagner","abstract":"I'm Paul, a freelance photographer, political scientist, Arabist, journalist and I'm currently working in the Sea-Watch Airborne media team","description":null,"links":[]},{"guid":"c81bab40-cfd0-5dad-87c6-831f214277ca","id":8990,"image":"/system/people/avatars/000/008/990/original/matthias-monroy-3516.jpeg?1609149622","name":"Matthias Monroy","public_name":"Matthias Monroy","email":"digit@so36.net","abstract":"Wissensarbeiter, Aktivist und Mitglied der Redaktion der Zeitschrift Bürgerrechte \u0026 Polizei/CILIP. ","description":"Publiziert in linken Zeitungen, Zeitschriften und Online-Medien, bei Telepolis, Netzpolitik und in Freien Radios. Alle Texte und Interviews unter digit.so36.net, auf englisch digit.site36.net, auf Twitter @matthimon.","links":[{"url":"https://digit.so36.net/","title":"Sicherheitsarchitekturen und Polizeizusammenarbeit in der Europäischen Union"}]},{"guid":"2471f058-d180-5426-a9c1-dfed8dc7df8d","id":19573,"image":null,"name":"Felix Weiss","public_name":"Felix Weiss","abstract":null,"description":null,"links":[]}],"start_time":"2023-12-30T14:45:00.000+01:00","end_time":"2023-12-30T15:45:00.000+01:00","room":{"name":"Saal Grace","id":472}},{"id":11761,"guid":"ff7f8d87-9319-41e4-857f-42c5c7124f4b","title":"All cops are broadcasting","subtitle":"TETRA unlocked after decades in the shadows","description":"In August 2023, we published the TETRA:BURST vulnerablities - the result of the first public in-depth security analysis of TETRA (Terrestrial Trunked Radio): a European standard for trunked radio globally used by government agencies, police, military, and critical infrastructure. Authentication and encryption within TETRA are handled by proprietary cryptographic cipher-suites, which had remained secret for over two decades through restrictive NDAs until our reverse-engineering and publication.\r\n\r\nTETRA:BURST consists of five vulnerabilities, two of which are critical, including the backdoored TEA1 cipher (crackable in minutes on commodity hardware by a passive adversary), a keystream recovery attack (which works regardless of the cipher employed), and a deanonymization attack with counter-intelligence implications.\r\n\r\nIn this talk, we will discuss and demonstrate the TETRA:BURST vulnerabilities themselves and will - for the first time - disclose the details of the TA61 identity anonymization primitive and our Meet-in-the-Middle deanonymization attack against it. In addition, we will provide more background on how the TEA1 backdoor proliferated throughout Europe and provide attendees with an update on new developments since our initial disclosure, the future of TETRA, and the vast amount of TETRA hardening work that still needs to be done in critical infrastructure.","duration":3600,"logo":"/system/events/logos/000/011/761/original/tetraburst.png?1698154669","type":"lecture","do_not_record":false,"track":"Security","abstract":"This talk will present details of the TETRA:BURST vulnerablities - the result of the first public in-depth security analysis of TETRA (Terrestrial Trunked Radio): a European standard for trunked radio globally used by government agencies, police, military, and critical infrastructure relying on secret cryptographic algorithms which we reverse-engineered and published in August 2023. Adding to our initial disclosure, this talk will present new details on our deanonymization attack and provide additional insights into background and new developments.","speakers":[{"guid":"c713a197-726d-5058-a1ce-cde37a88d448","id":6657,"image":"/system/people/avatars/000/006/657/original/jos_narrow.jpg?1698155586","name":"Jos Wetzels","public_name":"Jos Wetzels","abstract":"Jos Wetzels is a security researcher and consultant at Midnight Blue specializing in embedded systems security. His research and consultancy work has involved reverse-engineering, vulnerability research and exploit development across various domains ranging from industrial and automotive systems to IoT, networking equipment and deeply embedded SoCs. He previously worked as a researcher at the Distributed and Embedded Security group (DIES) at the University of Twente (UT) in the Netherlands where he developed exploit mitigation solutions for constrained Industrial Control Systems (ICS) devices used in critical infrastructure, performed security analyses of state-of-the-art network and host-based intrusion detection systems and has been involved in research projects regarding on-the-fly detection and containment of unknown malware and Advanced Persistent Threats.","description":null,"links":[{"url":"https://www.midnightblue.nl","title":"Homepage"}]}],"start_time":"2023-12-28T16:00:00.000+01:00","end_time":"2023-12-28T17:00:00.000+01:00","room":{"name":"Saal 1","id":471}},{"id":12061,"guid":"a3d8166c-e841-4071-ac0c-ddadaeeaef22","title":"AlphaFold – how machine learning changed structural biology forever (or not?)","subtitle":"Getting first-hand insights into the impact of machine learning on life science","description":"\u003cp\u003eIn 2021, Google published the methodology and source code for AlphaFold and within days, scientists adapted the code to allow virtually everyone to predict their own protein structures without prior knowledge.\u003c/p\u003e\r\n\r\n\u003cp\u003eNow, two years after its public release, AlphaFold has established itself as an essential tool in structural biology. Yet, with time, we've also gained a deeper insight into its limitations.\u003c/p\u003e\r\n\r\n\u003cp\u003eIn this talk, I would like to delve into AlphaFold and similar machine learning techniques and explore their impact on science and structural biology. To truly appreciate their significance, we will first need to understand the role of protein structures and how they shape our daily lives. Additionally, we’ll have to examine how protein structures were traditionally solved prior to the advent of AlphaFold. We’ll then touch upon the concepts of protein evolution to better understand the biological basis behind this breakthrough, before we’ll look at the intricacies of the neural network itself and discuss the training data necessary to achieve its remarkable capabilities. Drawing from my experience as a practicing structural biologist, I will illustrate these points with real-life examples, showcasing instances where AlphaFold has succeeded and where it has encountered challenges. Lastly, we will peer into the future and speculate on the potential trajectory of this scientific journey and its potential to transform science and our approaches towards it.\u003c/p\u003e\r\n","duration":3600,"logo":null,"type":"lecture","do_not_record":false,"track":"Science","abstract":"\u003cp\u003eIn 2020, the scientific community was shaken when the results of a special contest for protein prediction, known as the Critical Assessment of Protein Structure Prediction (CASP), were revealed. A relatively new competitor emerged as the champion, surpassing all other teams that had been participating in the game for decades. This new competitor was Google and their predictor was a neuronal network called \"AlphaFold\". Their new approach caused significant waves in the field of structural biology, even capturing the attention of the mainstream media. Several news channels featured reports on AlphaFold, with one German magazine, \"Der Spiegel,\" declaring that \"The year 2020 will be known [...] as the year when machines began to outstrip us in research.\"\u003c/p\u003e\r\n\u003cp\u003eJoin me as we explore the background behind this transformative development and assess the magnitude of machine learning's impact on science, with a particular focus on structural biology.\u003c/p\u003e\r\n","speakers":[{"guid":"63529ea2-9122-5a96-ab76-63b205fed350","id":18988,"image":null,"name":"Jan Gebauer ","public_name":"Jan Gebauer ","abstract":null,"description":null,"links":[{"url":"https://gebauer.koeln/","title":"Homepage Jan Gebauer"}]}],"start_time":"2023-12-28T14:45:00.000+01:00","end_time":"2023-12-28T15:45:00.000+01:00","room":{"name":"Saal Zuse","id":473}},{"id":11716,"guid":"f6c9f293-934d-4505-8a14-f85870e3d746","title":"Analog rotary phones get a second life with raspberry pi","subtitle":null,"description":"Rotary-dial analogue phones were once a necessity, but now they lay dormant on shelves or tucked away in attics. This is largely due to the replacement of traditional landlines with fibre-optic modems, rendering analogue phones obsolete.\r\nIn addition to their sentimental value, rotary dial phones provide several advantages, including reduced electrosmog emissions, protection against eavesdropping, repurposing outdated technology, and promoting a slower pace of life.\r\nThe contribution explains how to build a private telephone exchange for eight people using rotary dial phones. The exchange is powered by a Raspberry Pi and custom analogue electronics. The following themes are covered:\r\n- The construction of a PBX which resembles telephone exchanges in various countries worldwide, giving users a realistic experience.\r\n- Handling of call initiation, routing, full duplex voice transmission and human-machine communication.\r\n- The software implementation on the Raspberry Pi running Linux. \r\n- A study of enhancing the open-source software with additional functionalities.\r\n\r\nDue to the readily available Raspberry Pi hardware and software programmability, this project invites everyone to participate.\r\n\r\n","duration":2400,"logo":"/system/events/logos/000/011/716/original/rpi_pbx.jpeg?1697714389","type":"lecture","do_not_record":false,"track":"Hardware \u0026 Making","abstract":"An open source project involving an automated telephone exchange powered by Raspberry Pi, utilizing old rotary phones. The system imitates exchange setups from different countries across the globe, allowing users to feel the genuine experience.","speakers":[{"guid":"46ea4057-c6d2-5dc9-ac52-d890bacfe84a","id":18952,"image":null,"name":"Hans Gelke","public_name":"Hans Gelke","abstract":"Currently, researcher in Embedded Computer Systems, lecturer of computer science, digital electronics and integrated circuits design.\r\nPreviously designed the first 32-bit fault-tolerant UNIX minicomputer, video special effects machines, medical diagnostics equipment and mobile phone chips. I lived and worked in the US, Germany and Switzerland.","description":"I build my first digital electronics circuits with the age of 14 (1974) and, inspired by that, studied electrical engineering in Germany. After my studies I moved to San Francisco, California and worked for several companies in Silicon Valley. I participated in the design of the first UNIX 32-bit fault-tolerant minicomputer (Veritas), video special effects machines (Ampex) and medical diagnostics equipment (Siemens-Acuson). After 12 years in Silicon Valley, I moved to Switzerland and worked for Philips Semiconductors and designed integrated circuits for the mobile phone industry. I am now a researcher and lecturer for embedded Systems at ZHAW in canton Zurich, Switzerland. My hobbies are electronics, sports, travelling and bicycling","links":[]}],"start_time":"2023-12-30T12:55:00.000+01:00","end_time":"2023-12-30T13:35:00.000+01:00","room":{"name":"Saal 1","id":471}},{"id":11904,"guid":"ebbb938f-c1f7-4aad-a37d-ba1aea84eac0","title":"A NEW HOPE [de]","subtitle":"Ein Pep Talk für alle, die gerade verzweifeln ","description":"Die Klimakrise und der Nahostkonflikt eskalieren, die Ampel bläst zur Abschiebeoffensive, die AfD ist bei über 20 % und die CDU will vorsorglich schon mal Autobahnen bauen. Derweil machen KI \u0026 Kommerz das Internet kaputt und Elon Musk Twitter. Demnächst verschwindet dann auch noch das letzte Katzenvideo hinter irgendeiner Paywall, so dass man sich nicht mal mehr vernünftig ablenken kann – es ist zum Verzweifeln in diesen Zeiten.\r\n \r\nWie soll man da noch Hoffnung schöpfen? Wenn auch ihr euch diese Frage stellt, wenn ihr mit dem Gefühl der Resignation bereits vertraut seid, dann seid ihr hier genau richtig:\r\n\r\nWir haben Aktivist*innen zusammengebracht, die sich auf die Straße kleben, Menschen pflegen oder Daten schützen, die an unterschiedlichen Krisenherden täglich kämpfen und scheitern: Gewerkschafter*innen, Antifaschist*innen, humanitäre Helfer*innen – wir haben sie gefragt, warum und worauf sie überhaupt noch hoffen, und wir haben sie auf die CCC-Bühne eingeladen, damit wir uns darüber austauschen und gemeinsam neue Hoffnung schöpfen können – denn noch gibt es sie: Strategien, die funktionieren, starke Bündnisse und zumindest Teilerfolge: Hier \u0026 da können wir uns also gegenseitig Mut machen. ","duration":2400,"logo":null,"type":"lecture","do_not_record":false,"track":"CCC","abstract":"Hinter der Stadt brennt der Wald und der Kanzler hetzt gegen Flüchtende wie eine auf Reddit trainierte KI, der Freundeskreis zerbricht am Nahostkonflikt, außerdem wurde das Backup vergessen und das Kilo Tomaten ist auch schon wieder einen Euro teurer. Gründe zum Verzweifeln gibt es genug. Wir sprechen deshalb mit Aktivist*innen, die sich den multiplen Krisen entgegenstellen, darüber, was sie eigentlich noch hoffen lässt. ","speakers":[{"guid":"85b05f4d-8b7c-50ee-bac3-cf5a1ba42bd6","id":7110,"image":"/system/people/avatars/000/007/110/original/Neugebauer_20150322_5901-200x200.jpg?1476096579","name":"Ruben Neugebauer","public_name":"Ruben Neugebauer","email":"ruben@directaction.training","abstract":"Ruben Neugebauer is co-founder of Sea-Watch \u0026 #LeaveNoOneBehind. Formerly he was working as Journalist and activist at the Peng Collective, also he was part of the project Kabulluftbrücke. Today he is supporting progressive initiatives at direct:action gUG","description":null,"links":[{"url":"https://www.sea-watch.org","title":"Sea-Watch"},{"url":"https://lnob.net/","title":"#LeaveNoOneBehind"},{"url":"https://pen.gg","title":"Peng"},{"url":"http://directaction.training/","title":"direct:action"},{"url":"https://www.kabulluftbruecke.de","title":"Kabul Luftbrücke"}]},{"guid":"283b7e1a-f83b-52b1-b401-acba7f7c0a80","id":19140,"image":"/system/people/avatars/000/019/140/original/Bildschirmfoto_2023-11-07_um_17.50.32.png?1699376099","name":"Johannes Bayer","public_name":"Johannes Bayer","email":"johannes@directaction.training","abstract":null,"description":null,"links":[]},{"guid":"79502193-8099-5a01-8b78-0707c8aebcee","id":19581,"image":null,"name":"Carla Reemtsma","public_name":"Carla Reemtsma","abstract":null,"description":null,"links":[]},{"guid":"7c29904e-c407-5f62-bf8e-8a9235dddbd6","id":5605,"image":"/system/people/avatars/000/005/605/original/Arnesemsrott.jpg?1545783146","name":"Arne Semsrott","public_name":"Arne Semsrott","abstract":"Arne ist Projektleiter von FragDenStaat und Gründer des Freiheitsfonds. Er ist Journalist und Politikwissenschaftler.","description":null,"links":[{"url":"https://FragDenStaat.de","title":"FragDenStaat"}]},{"guid":"3b3a4cb5-437f-5754-aa06-72c197187f14","id":19584,"image":null,"name":"Lara Eckstein","public_name":"Lara Eckstein","abstract":null,"description":null,"links":[]},{"guid":"a855519d-568d-5d80-988a-a74eed8229df","id":19586,"image":null,"name":"Julian Hessenthaler","public_name":"Julian Hessenthaler","abstract":null,"description":null,"links":[]},{"guid":"8ae205f6-f51c-54ce-8183-58d0fd9a1604","id":19582,"image":null,"name":"Helena Steinhaus ","public_name":"Helena Steinhaus ","abstract":null,"description":null,"links":[]}],"start_time":"2023-12-28T21:10:00.000+01:00","end_time":"2023-12-28T21:50:00.000+01:00","room":{"name":"Saal 1","id":471}},{"id":12344,"guid":"43685bb3-3d09-4811-ba98-893c8b2625d0","title":"ANIMAL()CITY","subtitle":"Unleashed!","description":"With ANIMAL()CITY we draw inspiration from the ghostly presence of foxes that roam the city at night – which nowadays is a common appearance in urban environments – evoking echoes of a pre-industrial era while at the same time drawing people’s attention to a layer of the city that completely eludes their perception in everyday life. In these moments we witness animals and plants forming their own realm and the city itself having its own life, acting like an entity, a ghost at times. Encounters with wild animals in the city make the parallel layers of the landscape momentarily tangible and remind us that we are part of these ‘non-human’ networks as well. On a darker note: urban wildlife not only echoes pre-industrial times but also projects an idea of what our cities will look like when all the people have disappeared due to the consequences of the climate catastrophe. However, the city may also be read analogous to the internet. Animals, humans and plants seldomly interact within the city, and while we might notice traces or encounter their phantoms we seem to live in parallel worlds. Similarly, online we are divided by platforms into threads and channels, living in multi-layered structures haunted by uncanny bots and AI agents.\r\n\r\nWe believe that AR sculptures highlight an ethereal quality of the digital; they appear to transcend from the realm of immateriality into the physical space – the so-called spatial internet that overlays our cities. AR layers possess a magical quality in that they exist as objects whose influence on our world is – on a first step – contingent to our acceptance and perception of them as physical objects.\r\n\r\nANIMAL()CITY is an aesthetic inquiry of the artists’ views on how AR may intercept different layers of perception and realities or completely superimpose them.\r\n\r\nThe exhibition presents a collection of animals that transcend their natural forms and assume various \"non-natural\" shapes; from fantastical mythical creatures to archetypical animal sculpture adhering to classical composition to the most basic 3D animal assets, taken from game engine templates. These AR-animals introduce elements of imagination to their representation, inviting viewers to explore their own interpretations and engage with the artworks on different levels.","duration":1800,"logo":null,"type":"other","do_not_record":false,"track":"Art \u0026 Beauty","abstract":"Presentation/introduction to the ongoing 37C3 art exhibition groupshow with Joachim Blank, Eva Davidova, Meredith Drum, exonemo, Jonas Lund, Sahej Rahal, Ingeborg Wie by panke.gallery (Sakrowski).","speakers":[{"guid":"5d3bcf8e-0ad4-539a-99aa-a151bcd1844b","id":19580,"image":"/system/people/avatars/000/019/580/original/Eva_Davidova_by_Gustavo_Murillo_2020.jpg?1702486699","name":"Eva Davidova","public_name":"Eva Davidova","abstract":"Eva Davidova is an interdisciplinary artist with focus on new media(s) and their socio- political implications. Davidova has exhibited at the Bronx Museum, the UBV at the Everson Museum, the AKG Buffalo Art Museum, MACBA Barcelona, CAAC Sevilla, CBA Madrid, Instituto Cervantes, La Regenta, and Museum of the Moving Image in New York City among others.","description":"EVA DAVIDOVA explores behavior, ecological disaster, and  the political implications of technology through performative works rooted in the absurd. Challenging a singular narrative, she combines ancient mythology with the current technological moment to address the impending ecological catastrophe. Her practice involves research, performance, 360 video and 3D sculpture, game engines, participatory Virtual Reality and interactive, site-specific immersive installations. Davidova has exhibited at the Bronx Museum, the UVP at Everson Museum, Buffalo AKG Museum, MACBA, CAAC Sevilla and La Regenta. Her latest solo exhibitions were at ISSUE Project Room, Harvestworks, and the Instituto Cervantes in New York. Starting October 2023 the Museum of the Moving Image in NYC presents Davidova’s interactive installation Global Mode \u003e .","links":[{"url":"https://www.evadavidova.com/","title":"Website"},{"url":"https://openar.art/u/74","title":"Open AR profile"},{"url":"https://www.instagram.com/evadavidovany/","title":"Instagram profile"},{"url":"https://twitter.com/EvaDavidovaNY","title":"Twitter profile"}]},{"guid":"d97cfaea-2e0d-564d-9a8b-5d3816d81e0c","id":19579,"image":"/system/people/avatars/000/019/579/original/sakrowsi___foto_Hannah_Rumstedt.png?1702466459","name":"Sakrowski","public_name":"Sakrowski","abstract":"Sakrowski is a berlinbased curator with focus on net.art. He is working sind 1999 in various projects to exhibit, kontextualize and archive netart.   He has founded and curated the panke.gallery projectspace in Berlin-Wedding since 2016.","description":"Robert Sakrowski works and lives in Berlin. From 1999/2003 he curated exhibitions and lectures on net art within the project netart-datenbank. From 2007/9 he worked as a freelance researcher on the \"Netzpioniere 1.0\" research project at the Media.Art.Research Institute in Linz. Since 2007 he has been working with the web.video phenomena under the name CuratingYouTube and provides with gridr.org (2012) a specially designed online tool. 2014/15 he worked as curator for the transmediale festival \"capture all\". Since October 2016 he has been managing and curating the panke.gallery. In 2021, with Jeremy Bailey and Vincent van Uffelen, he developed the openAR web platform for presenting and curating web-based augmented reality objects. In Since 2022 he also maintains with the Zentrum für Netzkunst e.V. the project space /rosa. ","links":[{"url":"https://panke.gallery","title":"panke.gallery"},{"url":"https://openar.art/","title":"openAR"},{"url":"https://curatingyoutube.net","title":"curatingYouTube"}]},{"guid":"50334061-2488-574f-b1aa-f0c0bf3ba681","id":19577,"image":null,"name":"Sembo","public_name":"Sembo","abstract":null,"description":null,"links":[]}],"start_time":"2023-12-29T16:00:00.000+01:00","end_time":"2023-12-29T16:30:00.000+01:00","room":{"name":"Saal 1","id":471}},{"id":12074,"guid":"a06319d5-f4a6-4efa-8255-dff6317e9632","title":"Apple's iPhone 15: Under the C","subtitle":"Hardware hacking tooling for the new iPhone generation","description":"The iPhone's Lightning connector was a proprietary beast with a lot of hidden features: By sending custom SDQ commands there, it was possible to get it to expose hardware debugging features such as JTAG and UART. For a long time, this was only easily possible using either gray and black-market cables such as the Kanzi-Cable, or proprietary tools such as the Bonobo Cable. Last year, we released an open-source tool to get access to the iPhone debugging features called the Tamarin Cable - finally allowing anyone to get JTAG and UART on the iPhone for just a couple of $ in parts. \r\n\r\nBut then the iPhone 15 came along, and with that USB-C: All previous hardware and software tooling basically became useless, but that did not stop us from trying: We knew from the Apple Silicon macs and the work of t8012-team and the AsahiLinux project that Apple uses USB-C's VDM feature - Vendor Defined Messages - to allow access to features such as the UART console, and so chances were high that we could use something similar to get access to the hardware debugging features on the iPhone 15.\r\n\r\nSo we pre-ordered the iPhone 15, a couple of PCBs, a case of Club Mate and got started: And less than 48 hours after the launch we got JTAG working on the iPhone 15.\r\n\r\nIn this talk we will start by looking at the history of iPhone and Lightning hardware hacking, and then look at how USB-C is used for debugging on Apple Silicon devices, and what we had to do to get JTAG on the iPhone 15.\r\n\r\nWe will also use this talk to release the new version of the open-source Tamarin Cable firmware: Tamarin-C. A fully integrated, open-source debugging probe for the iPhone 15 and other Apple Silicon devices. Tamarin-C is also able to give access to a DFU mode that you can't access without sending VDMs.\r\n\r\n\r\nNote: This talk will not contain any 0days or previously unknown vulnerabilities. Production iPhones are locked, and so while we get access to some of the device's busses we can't for example access the CPU core.\r\n\r\n\r\nThis talk is about laying the groundwork for future work.","duration":2400,"logo":null,"type":"lecture","do_not_record":false,"track":"Security","abstract":"If you've followed the iPhone hacking scene you probably heard about cables such as the Kanzi Cable, Kong Cable, Bonobo Cable, and so on: Special cables that allow access to hardware debugging features on Lightning-based iPhones such as UART and JTAG. However with the iPhone 15, all of those tools became basically useless: USB-C is here, and with that we need new hardware and software tooling.\r\n\r\nThis talk gives you a brief history of iPhone hardware hacking through the Lightning port, and then looks at the new iPhone 15, and how - using vendor defined messages, modifying existing tooling like the Central Scrutinizer, and a bit of hardware hacking - we managed to get access to the (unfortunately locked on production devices) JTAG interface exposed on the USB-C port on the new iPhone 15.\r\n\r\nAnd how you can do it using open-source tooling too.","speakers":[{"guid":"bab5293f-69e4-5f76-9b01-8e00d58ea4b7","id":7775,"image":"/system/people/avatars/000/007/775/original/watermark.png?1699705285","name":"stacksmashing","public_name":"stacksmashing","abstract":"Thomas Roth is an embedded security researcher \u0026 trainer, with a focus on fault injection, bootloader security and other low-level shenanigans.\r\n\r\nHe also runs a YouTube channel called stacksmashing about security, reverse engineering and hardware hacking.","description":null,"links":[{"url":"https://youtube.com/stacksmashing","title":"YouTube"},{"url":"https://twitter.com/ghidraninja","title":"Twitter"}]}],"start_time":"2023-12-27T12:00:00.000+01:00","end_time":"2023-12-27T12:40:00.000+01:00","room":{"name":"Saal 1","id":471}},{"id":12254,"guid":"f68ec6e2-72ce-4f8a-bc14-af174fdae140","title":"ARMore: Pushing Love Back Into Binaries","subtitle":"Aarch64 binary rewriting adventures but mostly pains","description":"There's a bunch of closed-source arm64 binaries out there that we can't really fuzz efficiently due to slow dynamic instrumentation. \r\nStatic binary rewriting has been around since decades, but was mostly focused on x86.\r\nPorting it to arm64 should be a straightforward task, right? \r\n\r\nThis is the story of how a simple \"4-week port of an existing x86 rewriter\" took 2+ years instead.\r\nMaybe the real treasure is the CVEs we made along the way? \r\nWarning: the talk might contain sensitive imagery of ARM Assembly. Viewers have been warned. \r\n","duration":2400,"logo":"/system/events/logos/000/012/254/original/heart.png?1699741296","type":"lecture","do_not_record":false,"track":"Security","abstract":"A talk on the first heuristic-free static binary rewriter for aarch64.\r\nWhy is it the first? Because everyone else already knew how much of a bad idea this would have been.","speakers":[{"guid":"9ef179da-dc86-5b02-a231-353fe964e2e9","id":19378,"image":null,"name":"@cyanpencil (Luca Di Bartolomeo)","public_name":"@cyanpencil (Luca Di Bartolomeo)","abstract":null,"description":null,"links":[]}],"start_time":"2023-12-28T21:10:00.000+01:00","end_time":"2023-12-28T21:50:00.000+01:00","room":{"name":"Saal Grace","id":472}},{"id":12337,"guid":"93d72015-6763-4bd2-9c42-cf6c54b9dcd0","title":"Audio Interventionen und künstlerischer Ausdruck mit Sound Graffiti, Protest-Jingles und Sprachwerkstätten","subtitle":null,"description":"Wir machen Sound Grafitti mit Echokammern, produzieren Protest-Jingles und Sprachwerkstätten. Mit diesem Beitrag möchten wir euch zwei Vorgehensweisen zu dieser Art von „Protest mit Sound als Audio Intervention\" vorstellen, sowie die künstlerischen, kreativ-technischen Prozesse näher bringen und euch einladen, diese kritisch zu beäugen und zu hören, sich unserer Ideen und Verfahren zu ermächtigen und die dargestellten Formen und Ansätze nach eurem Belieben weiterzuentwickeln und anderweitig zu verwenden. Wir glauben an die Wirksamkeit von Vielfalt von Protest und sehen diesen als wichtiges Element demokratischer Meinungsbildung und um für politische Rechte zu kämpfen und gegen Diskriminierung mobil zu machen (sprich im kleinsten gemeinsamen Nenner: #fightnazis,  #afdwegbassen und #saytheirnames).\r\n\r\n„Sound Grafitti\" und „Protest-Jingles\" beherbergen disruptives Potenzial und können als Audio-Interventionen bestehende Diskurse in öffentlichen und digitalen Räumen aufbrechen / bereichen. Zum einen, indem überhaupt einmal bestimmte Meinungen / Äußerungen anderen außerhalb der eigenen „Bubbles\" und Räume zugänglich gemacht werden, zum anderen, um kollektiv verfasste Äußerungen in Konfrontation mit Menschen zu bringen, um auf Probleme zu verweisen, solidarische Anliegen vorzubringen und Handlungsvorschläge (für Protest-Vorhaben) anzubieten. \r\n\r\n„Echokammern\" sind Open Source DIY-Lautsprecher für Audio-Interventionen, nutzbar für Sound-Graffiti im öffentlichen Raum. Als Basis nutzen wir Baustellenlampen, die wir zu mobilen Lautsprechern umfunktionieren. Durch einen Hack werden die allgegenwärtigen Baustellenlampen zu Mitteln der Kommunikation und Irritation im öffentlichen Raum. Ein Objekt, das uns aufmerksam macht und auf Gefahren hinweist, wird manipuliert und zur Echokammer gesellschaftlich relevanter Anliegen und Probleme. Ausgangspunkt für dieses Projekt war der rassistische Terroranschlag in Hanau im Jahr 2020, bei dem neun Menschen von einem rechtsradikalen Terroristen getötet wurden. In einer Zeit, in der es aufgrund der Pandemie und damit verbundener Regelungen nur eingeschränkt möglich war gemeinsam zu gedenken, zu protestieren und zu trauern, haben wir nach Möglichkeiten gesucht, die Forderung \"SAY THEIR NAMES\" auf die Straße zu bringen. So entstand ein Werkzeug, das seither für verschiedene politische Kämpfe und Themen genutzt wurde. So bespielten die Lautsprecher zuletzt in diesem Jahr die Straßen Berlins zum Protest gegen den Weiter-Bau der Autobahn A100.\r\n\r\nProtest-Jingles sind Audio-Beiträge zu Protestvorhaben, die diese ankündigen, flankieren, erklären und in denen Themen und damit verbundene Anliegen verhandelt werden und zur Teilnahme aufgerufen wird. 2018 hat Reclaim Club Culture damit erstmals mit eigens dafür produzierten Jingles zu einem Groß-Protest gegen Nazis unter dem Motto #afdwegbassen aufgerufen, um mit diesen die Mobilisierung (z.B. abgespielt durch DJs in Clubs, zum Teilen über Social Media, zum Versenden an Redaktionen und Journalistinnen) zu dem Protest zu unterstützen sowie um während des Protestes den Aufruf als Meinungsäußerung von Lautsprecher-Wägen abzuspielen zu können. \r\nSprachwerkstätten als Variation dessen sind mit Protest-Jingles in der Hinsicht artverwandt, als dass sie Versuche darstellen, Meinungen von Menschen zu bestimmten Themen einzuholen und  künstlerisch kuratiert als Audio-Collage darzustellen und anderen zugänglich zu machen. Sie machen ein Angebot zum Reflektieren und Partizipieren, welches keinen Anspruch auf Vollständigkeit oder Wahrheit hat und immer nur eine Auswahl darstellt.\r\nDie Ergebnisse der vergangenen fünf Jahre stehen für sich und werden in diesem Beitrag in einer Auswahl auch performt. ","duration":2400,"logo":null,"type":"lecture","do_not_record":false,"track":"Art \u0026 Beauty","abstract":"Wir machen Sound Grafitti mit Echokammern, produzieren Protest-Jingles und Sprachwerkstätten. Mit diesem Beitrag möchten wir euch zwei Vorgehensweisen zu dieser Art von „Protest mit Sound als Audio Intervention\" vorstellen, sowie die künstlerischen, kreativ-technischen Prozesse näher bringen und euch einladen, diese kritisch zu beäugen und zu hören, sich unserer Ideen und Verfahren zu ermächtigen und die dargestellten Formen und Ansätze nach eurem Belieben weiterzuentwickeln und anderweitig zu verwenden. Wir glauben an die Wirksamkeit von Vielfalt von Protest und sehen diesen als wichtiges Element demokratischer Meinungsbildung und um für politische Rechte zu kämpfen und gegen Diskriminierung mobil zu machen","speakers":[{"guid":"e0fc9483-4742-5ae2-9a50-c9423cb1159c","id":19279,"image":"/system/people/avatars/000/019/279/original/profil_liebkos.png?1699732050","name":"Thomas Liebkose","public_name":"Thomas Liebkose","abstract":"DJ, producer, feminist, researcher and political activist. ","description":"I like sound, art and political resistance. My work focuses on the transformation of society towards a more just, sustainable and life-worthy world for all. ","links":[]},{"guid":"bc6e1235-4271-5d0c-bf66-a714d32ba98f","id":19282,"image":"/system/people/avatars/000/019/282/original/profilbild.png?1699615957","name":"echokammer","public_name":"echokammer","email":"echokammer@systemli.org","abstract":"We are two Sound Guerillas from Berlin","description":null,"links":[]}],"start_time":"2023-12-27T13:50:00.000+01:00","end_time":"2023-12-27T14:30:00.000+01:00","room":{"name":"Saal Zuse","id":473}},{"id":12309,"guid":"7cde08a9-def1-4788-8e3e-b799e7b42556","title":"A year of surveillance in France: a short satirical tale by La Quadrature du Net","subtitle":"From the so-called Country of human rights to a surveillance State","description":"Looking back to France in 2023, what do we see? Implementation of new technologies such as drones, DNA marking or new generation of spywares. Also, an intensification of political surveillance, either by law enforcement deploying disproportionate means of investigations towards environmental activists or intelligence services using cameras or GPS beacons to spy on places or people that they find too radical. It was also the year of the “8 December” case, a judicial case where among other things, encrypted communications of the prosecuted persons were considered as signs of \"clandestinity\" that reveal criminal intentions.\r\n\r\nOn top of this, we also had to deal with the legalization of biometric surveillance for the Olympics and massive censorship of social networks when riots erupted in suburbs against police violence.\r\n\r\nThis talk is about showing the reality of the situation at stake right now in France, and how it could influence the rest of Europe. At the end, we hope to raise awareness in the international community and start thinking about how, together, we can put pressure on a country who uses its old reputation to pretend to be respectful of human rights.","duration":2400,"logo":null,"type":"lecture","do_not_record":false,"track":"Ethics, Politics \u0026 Society","abstract":"Fighting against surveillance has never been easy. But in the past year it has been specially tough in France.  This talk is about shedding light on the many situations where the French State used surveillance to increase repression, mainly against activists, during the last months. Not to despair of this, but willing to provide a sincere overview to the rest of the world, La Quadrature du Net proposes to depict this situation as a satirical tale, with its own characters, plots and suspense. We want to show the political tension going on right now in France and how the checks and balances are lacking to stop this headlong rush to a surveillance state.","speakers":[{"guid":"a2a3b790-b1f1-518f-9175-f67662ea7109","id":19482,"image":null,"name":"Noémie, Marne and Nono","public_name":"Noémie, Marne and Nono","abstract":null,"description":null,"links":[]}],"start_time":"2023-12-28T12:00:00.000+01:00","end_time":"2023-12-28T12:40:00.000+01:00","room":{"name":"Saal Zuse","id":473}},{"id":12144,"guid":"c51b416f-e656-4f43-a9dd-b9b3bedf3056","title":"Back in the Driver's Seat: Recovering Critical Data from Tesla Autopilot Using Voltage Glitching","subtitle":null,"description":"Apart from building electric vehicles, Tesla has gained a reputation for their integrated computer platform comprising a feature-rich infotainment system, remote services through Tesla's Cloud and mobile app, and, most notably, an automated driving assistant. Enabled by a dedicated arm64-based system called Autopilot, Tesla offers different levels of \"self-driving\". The \"full self-driving\" (FSD) is provided to specific customers via in-car purchases and has been subject to public discourse.\r\n\r\nDespite using multiple cameras and Autopilot's machine learning (ML) models, accidents persist and shape FSD reporting. While the platform security of Autopilot's hardware protects the code and ML models from competitors, it also hinders third parties from accessing critical user data, e.g., onboard camera recordings and other sensor data, that could help facilitate crash investigations.\r\n\r\nThis presentation shows how we rooted Tesla Autopilot using voltage glitching. The attack enables us to extract arbitrary code and user data from the system. Among other cryptographic keys, we extract a hardware-unique key used to authenticate Autopilot towards Tesla's \"mothership\". Overall, our talk will shed light on Autopilot's security architecture and gaps.\r\n\r\nBefore delving into Autopilot, we successfully executed a Tesla Jailbreak of the AMD-based infotainment platform and presented our attack at BlackHat USA 2023. This achievement empowered custom modifications to the root file system and temporarily facilitated the activation of paid car features.","duration":2400,"logo":null,"type":"lecture","do_not_record":false,"track":"Security","abstract":"Tesla's driving assistant has been subject to public scrutiny for good and bad: As accidents with its \"full self-driving\" (FSD) technology keep making headlines, the code and data behind the onboard Autopilot system are well-protected by the car manufacturer. In this talk, we demonstrate our voltage-glitching attack on Tesla Autopilot, enabling us root privileges on the system.\r\n","speakers":[{"guid":"1dd011c2-0620-5625-a6f3-38b2caa7f0a8","id":19310,"image":null,"name":"Niclas Kühnapfel","public_name":"Niclas Kühnapfel","abstract":null,"description":null,"links":[]},{"guid":"2176075a-bf9f-5724-8c53-d9d142608af1","id":8290,"image":"/system/people/avatars/000/008/290/original/semiformell_quadratisch.JPG?1538404134","name":"Christian Werling","public_name":"Christian Werling","abstract":"After completing his academic education at the Hasso Plattner Institute, Potsdam, as well as the Technische Universität, Berlin, in 2019, Christian now works as an IT Security Consultant and Ethical Hacker at the Berlin-based hacking research collective SRLabs.\r\n\r\nHis research interests include Firmware and Embedded Security as well as Cloud Security.","description":null,"links":[]}],"start_time":"2023-12-27T13:50:00.000+01:00","end_time":"2023-12-27T14:30:00.000+01:00","room":{"name":"Saal Grace","id":472}},{"id":11948,"guid":"e9ecf88b-5dde-4801-b9ce-3b62ac06b899","title":"Bifröst: Apple's Rainbow Bridge for Satellite Communication","subtitle":null,"description":"With the release of the iPhone 14, users can reach out to emergency services by sending an SOS message via a satellite link directly from their phone. This use of the GlobalStar network facilitates two-way communication with emergency responders through the Messages app. Users can easily send text messages and respond to queries. This communication channel, due to its sensitive nature, demands robust security and authentication. It is imperative for Apple to ensure that the system is foolproof, negating the possibility of dispatching emergency responders to incorrect locations or individuals. Equally significant is the protection of the privacy of those in need, including their location and the nature of their emergency.\r\n\r\nIn our talk, we demonstrate how a rooted iPhone without satellite capabilities can be tricked into thinking that it can communicate with the satellite network. This technique allows us to trigger various emergency situations without actually contacting emergency services. On the rooted iPhone, we can then inspect the transport security and key derivation while these features are being used. We will present various insights into the proprietary satellite communication protocol based on this analysis.\r\n\r\nMoreover, Apple's satellite features allow users to share their location in Find My with up to ten friends via a satellite link. This capability serves as a convenient tool for staying connected with friends and family while venturing off the beaten path. We’ll take a look into how this new Find My extension is implemented.","duration":2400,"logo":"/system/events/logos/000/011/948/original/Stewie-Satellite_Logo.jpg?1699539569","type":"lecture","do_not_record":false,"track":"Security","abstract":"Apple's cutting-edge emergency SOS and location sharing services provide crucial communication alternatives when no cellular network is available. This talk will shed light on how these satellite services work, how they are integrated into existing fall and crash detection, present the security measures employed to safeguard resource access and privacy, and explore how this communication is embedded within the operating system.","speakers":[{"guid":"bea982b5-fd36-56c6-adba-e0dbdfc57e73","id":19277,"image":"/system/people/avatars/000/019/277/original/Close.jpg?1699539254","name":"Alexander Heinrich","public_name":"Alexander Heinrich","email":"aheinrich@seemoo.tu-darmstadt.de","abstract":"Alexander is a PhD-candidate and security researcher. His work focuses on proprietary protocols, such as Find My, Ultra-Wide Band and Satellite communications. ","description":"Deeply rooted in the Apple ecosystem, Alexander has been an app developer since he was 16 years old. His curiosity expanded from app development to the security aspects of mobile devices, protocols, and especially security wireless communication. He not only uncovers new security and privacy issues but also creates free, open-source tools like OpenHaystack and AirGuard. AirGuard was the first app capable of detecting AirTags and warning victims of stalking.","links":[]},{"guid":"51dad350-72e0-5b60-bb64-da6700007b21","id":4927,"image":"/system/people/avatars/000/004/927/original/jiska.jpg?1608996245","name":"jiska","public_name":"jiska","abstract":"Jiska breaks things and her unicorn wears a tinfoil hat.","description":null,"links":[]}],"start_time":"2023-12-27T20:15:00.000+01:00","end_time":"2023-12-27T20:55:00.000+01:00","room":{"name":"Saal Grace","id":472}},{"id":11907,"guid":"5e80f829-e2fe-4dd9-906c-7a18e9b7518a","title":"Blackbox Chemieindustrie","subtitle":"Die energieintensivste Industrie Deutschlands","description":"Flammschutzmittel für Elektrogeräte, die Metalllegierung zum Löten und Plastik für fast alle Anwendungen im Alltag – all diese Materialen produziert die Chemische Industrie. Sie steht am Anfang der Wertschöpfungskette. Die Materialien, die sie herstellt definiert das Spektrum, mit dem Produktdesigner*innen arbeiten können. Schockierend ist: Die Industrie verwendet nicht nur fossile Rohstoffe für viele ihrer Produkte, sondern ist auch größter Industrieverbraucher von Energie in Deutschland. Allein für die Produktion von Plastik für Verpackungen verwendet die Industrie in Deutschland mehr Primärenergie, als das Land Slowenien insgesamt. Viele Produkte der Industrie bergen Umwelt- und Gesundheitsgefahren und kein deutsches Chemieunternehmen hat eine Strategie ihre Schadstoffe zu reduzieren. Tatsächlich produzieren und exportieren die Unternehmen sogar weiterhin Schadstoffe, die in der EU längst verboten sind. Dass es so nicht weiter gehen kann erkennt auch die Industrie. Ihre angeblich klimaneutralen Transformationspfade sind technisch und wirtschaftlich nicht sinnvoll und gehen mit einem enormen Anstieg an nicht verfügbarer erneuerbarer Energie und Wasserstoff einher. Der Bedarf übersteigt was die Bundesregierung für ganz Deutschland vorsieht. Wir zeigen auf: Die Transformation der Chemieindustrie kann nicht nur innerhalb dieser Branche gedacht werden. Es darf jetzt nicht in Technologien investiert werden, die Scheinlösungen sind. Die Herausforderungen Klimakrise, Verschmutzung und Biodiversitätskrise müssen jetzt angegangen werden durch echte Defossilisierung, Ressourceneinsparung und Kreislaufwirtschaft und einer Umstellung auf sichere und nachhaltige Chemikalien. ","duration":2400,"logo":"/system/events/logos/000/011/907/original/Titel_Blackbox_Chemieindustrie.jpg?1701862906","type":"lecture","do_not_record":false,"track":"Sustainability \u0026 Climate Justice","abstract":"Am Anfang von jedem Chip, jedem Computer, jedem Plastik steht die Chemieindustrie. Sie ist Deutschlands größter Industrieverbraucher an fossilen Ressourcen wie Öl und Gas. Wir stellen eine neue Studie „Blackbox Chemieindustrie“ des BUND zum Energie- und Ressourcenbedarf der Industrie vor. Die angeblich klimaneutralen Transformationspläne der Industrie werden kritisch hinterfragt und echte Lösungen werden aufgezeigt.","speakers":[{"guid":"edf321d0-cf6e-5e1c-8a45-f78531baad27","id":19161,"image":"/system/people/avatars/000/019/161/original/kuhlmann.janna.jpg?1701696240","name":"Janna Kuhlmann","public_name":"Janna Kuhlmann","email":"janna.kuhlmann@bund.net","abstract":"Janna has a background in Environmental Chemistry and Health from Copenhagen University and works for BUND eV as a chemicals and consumer protection senior policy officer. She was a founding member of the open laboratory Curious Community Labs eV in Hamburg and the agroforestry project Feld Food Forest eV in Berlin and is a part-time vegetable farmer.","description":null,"links":[]},{"guid":"266a5417-02ce-50bb-819b-8d856e7c8258","id":19293,"image":"/system/people/avatars/000/019/293/original/1_2.PNG?1701331488","name":"Janine Korduan","public_name":"Janine Korduan","email":"janine.korduan@bund.net","abstract":"Janine is a Senior Expert on Circular Economy and has been working for BUND (Bund für Umwelt und Naturschutz - Friends of the Earth Germany) since 2020. Before she has been working for more than five years for Heinrich Boell Foundation on Geoengineering. She is also working for about ten years as a freelancer for Environmental Investigation Agency on Climate Policy. Privately she engages for feminism.","description":"Janine is a Senior Expert on Circular Economy and has been working for BUND (Bund für Umwelt und Naturschutz - Friends of the Earth Germany) since 2020. Before she has been working for more than five years for Heinrich Boell Foundation on Geoengineering. She is also working for about ten years as a freelancer for Environmental Investigation Agency on Climate Policy. Privately she engages for feminism.","links":[{"url":"https://www.youtube.com/@shefixtutorials4514/","title":"She*Fix Tutorials"}]}],"start_time":"2023-12-30T12:00:00.000+01:00","end_time":"2023-12-30T12:40:00.000+01:00","room":{"name":"Saal 1","id":471}},{"id":12342,"guid":"f795f0e3-6aa9-4166-ae24-9183c701810a","title":"BLUFFS: Bluetooth Forward and Future Secrecy Attacks and Defenses","subtitle":"Breaking and fixing the Bluetooth standard. One More Time.","description":"Bluetooth is a pervasive technology for wireless communication.\r\nBillions of devices use it in sensitive applications and to exchange\r\nprivate data. The security of Bluetooth depends on the Bluetooth\r\nstandard and its two security mechanisms: pairing and session establishment. No prior work, including the standard itself, analyzed the future and forward secrecy guarantees of these mechanisms, e.g., if Bluetooth pairing and session establishment defend past\r\nand future sessions when the adversary compromises the current.\r\nTo address this gap, we present six novel attacks, defined as the\r\nBLUFFS attacks, breaking Bluetooth sessions’ forward and future\r\nsecrecy. Our attacks enable device impersonation and machine-in-the-middle across sessions by only compromising one session key. The attacks exploit two novel vulnerabilities that we uncover in the Bluetooth standard related to unilateral and repeatable session key derivation. As the attacks affect Bluetooth at the architectural level, they are effective regardless of the victim’s hardware and software details (e.g., chip, stack, version, and security mode).\r\n\r\nWe also release BLUFFS, a low-cost toolkit to perform and automatically check the effectiveness of our attacks. The toolkit employs seven original patches to manipulate and monitor Bluetooth session key derivation by dynamically patching a closed-source Bluetooth firmware that we reverse-engineered. We show that our attacks have a critical and large-scale impact on the Bluetooth ecosystem, by evaluating them on seventeen diverse Bluetooth chips (eighteen devices) from popular hardware and software vendors and supporting the most popular Bluetooth versions. Motivated by our empirical findings, we develop and successfully test an enhanced key derivation function for Bluetooth that stops by-design our six attacks and their four root causes. We show how to effectively integrate our fix into the Bluetooth standard and discuss alternative implementation-level mitigations. We responsibly disclosed our contributions to the Bluetooth SIG.","duration":3600,"logo":"/system/events/logos/000/012/342/original/thumbnail.jpg?1701942545","type":"lecture","do_not_record":false,"track":"Security","abstract":"Ciao! We present the BLUFFS attacks (CVE-2023-24023), six novel attacks breaking Bluetooth's forward and future secrecy. Our attacks enable device impersonation and machine-in-the-middle across sessions by compromising and re-using one session key. We discuss the four vulnerabilities in the Bluetooth specification enabling the attacks, two of which are new and related to unilateral and repeatable session key derivation. We describe the toolkit we developed and open-sourced to test our attacks via firmware binary patching, our experiments where we exploited 18 heterogeneous Bluetooth devices, and the practical and backward-compliant session key derivation protocol we built to fix the attacks by design. We also cover related work like KNOB, BIAS, and BLUR, and educational Bluetooth security tips and tricks.","speakers":[{"guid":"8796ca4f-2e16-5ccb-8fb6-ab3c157891e1","id":19546,"image":"/system/people/avatars/000/019/546/original/icon.png?1701778282","name":"Daniele Antonioli","public_name":"Daniele Antonioli","abstract":"Ciao, I am Daniele, an Assistant Professor at EURECOM with the software and system security (S3) group. I am doing research and teaching in applied system security and privacy with an emphasis on wireless communication, such as Bluetooth and Wi-Fi, embedded systems, such as cars and fitness trackers, mobile systems such as smartphones, and cyber-physical systems such as industrial control systems.","description":null,"links":[{"url":"https://francozappa.github.io/","title":"personal website"}]}],"start_time":"2023-12-28T23:00:00.000+01:00","end_time":"2023-12-29T00:00:00.000+01:00","room":{"name":"Saal Grace","id":472}},{"id":12142,"guid":"68160267-a6a5-4a41-8a51-d8735c8aa338","title":"Breaking \"DRM\" in Polish trains","subtitle":"Reverse engineering a train to analyze a suspicious malfunction","description":"The talk will be a mix of technical and non-technical aspects of analysis which should be understandable for anyone with a technical background. We’ll briefly explain how modern EMUs look like inside, how the Train Control \u0026 Monitoring System works, and how to analyze TriCore machine code.","duration":3600,"logo":null,"type":"lecture","do_not_record":false,"track":"Hardware \u0026 Making","abstract":"We've all been there: the trains you're servicing for a customer suddenly brick themselves and the manufacturer claims that's because you've interfered with a security system.\r\n\r\nThis talk will tell the story of a series of Polish EMUs (Electric Multiple Unit) that all refused to move a few days after arriving at an “unauthorized” service company. We'll go over how a train control system actually works, how we reverse-engineered one and what sort of magical “security” systems we actually found inside of it.\r\n\r\nReality sometimes is stranger than the wildest CTF task. Reality sometimes is running `unlock.py` on a dozen trains.","speakers":[{"guid":"da4e3a81-8cc3-5e5e-8d05-4c4070a8bce4","id":19415,"image":"/system/people/avatars/000/019/415/original/twitter2_cropped.jpg?1701609040","name":"Redford","public_name":"Redford","email":"redford@dragonsector.pl","abstract":"Michał is a reverse engineer interested in cryptography and low-level hacking, who analyzes random things just to check how they work.","description":"Currently works at Invisible Things Lab on SGX-related projects. Vice captain of Dragon Sector CTF team, actively playing CTFs since 2013. Recently he also hacks satellites with the Poland Can Into Space team as its captain.\r\n\r\nHe co-authored a book about reverse engineering (Praktyczna inżynieria wsteczna, PWN, 2016) and was a speaker at REcon BRX (“Hacking Toshiba Laptops”, 2018).","links":[]},{"guid":"0e8b22b2-6c87-5137-8954-4cb96e55bb48","id":18744,"image":null,"name":"q3k","public_name":"q3k","abstract":null,"description":null,"links":[]},{"guid":"896a597a-5dbd-5ce0-8d12-0d0068105042","id":19459,"image":null,"name":"MrTick","public_name":"MrTick","abstract":"Amateur train driver.","description":"Enthusiast. Amateur train driver.\u003cbr\u003e\r\nLikes to type stuff on a computer.\u003cbr\u003e\r\nOne of those guys that carry a soldering iron everywhere.\u003c/p\u003e","links":[]}],"start_time":"2023-12-27T23:00:00.000+01:00","end_time":"2023-12-28T00:00:00.000+01:00","room":{"name":"Saal 1","id":471}},{"id":12138,"guid":"e112c214-3c40-47aa-8ca8-e8f99f6d175a","title":"Buffered Daemons","subtitle":null,"description":"In the piece, three different containers of sound are presented: acoustic(Sound diffusion in the architecture), digital (computer based sound algorithms) and analogue (electromagnetic tape and analog processing). This containers, or buffers, are then being intertwined by the performer creating thus sonic textures that interplay with the resonances of the space.\r\n\r\nThe strategy for the sound performance is to articulate a metaphor of a circular-buffer, a data structure used in Computer Science, to the idea brought upon in Derrida’s interview with Ornette Coleman, in which Improvisation practice in music is understood as a reading in which the borders between reading and writing are obfuscated.\r\n\r\nThe work is inspired by the concept of daemon and non-locality explored by Timothy Morton in his reading of Plato’s Ion as well as Ursula K. Le Guin’s The Carrier Bag Theory of Fiction.","duration":2400,"logo":null,"type":"concert","do_not_record":false,"track":"Art \u0026 Beauty","abstract":"The work titled Buffered Daemons is a sound performance that attempts to explore the concepts of translation and non-local interaction in the sound realm. It does so by playing with the idiosyncrasies of audio representation/playback and mobilises them through the creation of an expanded musical situation.","speakers":[{"guid":"45d8778b-63c2-545a-b35a-88d7426ec182","id":19419,"image":null,"name":"airpc","public_name":"airpc","abstract":"Pedro A. Ramírez (1993, Colombia) is an artist working with sound and performance. Be it analog synthesizer or computer processes, he’s interested in the concepts of noise both as an aesthetic and conceptual framework. His references come information theory’s cybernetics, computer music algorithms as well as the aural knowledge of informal musical scenes and their word of mouth myth-making strategies.  ","description":null,"links":[{"url":"https://airpopcrack.com/","title":"website"}]}],"start_time":"2023-12-29T23:00:00.000+01:00","end_time":"2023-12-29T23:40:00.000+01:00","room":{"name":"Saal Zuse","id":473}},{"id":12303,"guid":"91ab3951-df7a-4a92-a457-2c72cfde66ec","title":"CCC カラオケ – aktuelle Karaokeforschung ","subtitle":"vom Deutschen Institut für Karaokeforschung","description":"Liebe Fördermitglieder des Institutes für Karaokeforschung,\r\n\r\nin den letzten Tagen haben wir uns intensiv mit den Karaoke-Gewohnheiten der örtlichen Bevölkerung des CCC im CCH befassen können. Unsere motivierten Proband*innen im Alter zwischen 17 und 85 Jahren haben uns in dieser repräsentativen Studie direkte Einblicke in ihren Alltag gegeben. Allein dafür sind wir unendlich dankbar, Sie haben der Karaokeforschung einen großen Dienst erwiesen!\r\n\r\nNun möchten wir Euch und Ihnen in einer Zwischenpräsentation Insights aus unserem aktuellen Kooperationsprojekt mit dem CCC präsentieren – und damit auch die dritte Phase der international angelegten Forschungsarbeit einläuten. \r\n\r\nIm Namen des gesamten Vorstandes möchte ich mich bei Ihnen recht herzlich für die Unterstützung auch im nächsten Jahr bedanken. Gleichzeitig die Bitte, Ihre Bankverbindung zu überprüfen, um die Arbeit unserer Buchhaltung zu vereinfachen. Wir freuen uns über Ihre Teilnahme an der Präsentation und bitten um eine kurze Bestätigung.\r\n\r\nEs grüßt Sie herzlich\r\nIhre Gitte Schmitz\r\n(Vorsitzende Deutsches Institut für Karaokeforschung)","duration":2400,"logo":null,"type":"lecture","do_not_record":false,"track":"Entertainment","abstract":"Vorstandsvorsitzende Gitte Schmitz stellt aktuelle Ergebnisse des Deutschen Instituts für Karaokeforschung vor. ","speakers":[{"guid":"db7775d4-77d2-5990-baaf-886c914c5a76","id":19476,"image":"/system/people/avatars/000/019/476/original/pornopromo_thegitteschmitz3.jpg?1699789265","name":"Gitte Schmitz ","public_name":"Gitte Schmitz ","abstract":"Gitte Schmitz researches asynchronous queer pop culture and applied drag sciences. She is chairwoman of the German Institute for Karaoke Research.","description":null,"links":[{"url":"gitteschmitz.de","title":"Webseite"}]}],"start_time":"2023-12-30T17:35:00.000+01:00","end_time":"2023-12-30T18:15:00.000+01:00","room":{"name":"Saal Zuse","id":473}},{"id":12240,"guid":"7ec3194b-0f3e-42dc-a515-fb8511deaf5e","title":"Chatkontrolle - Es ist noch nicht vorbei!","subtitle":" Eine Tragödie in X Akten","description":"Über die Chatkontrolle wurde in den letzten zwei Jahren viel geredet – die problematischen Inhalte des Gesetzes kommen den meisten von uns wahrscheinlich zu den Ohren heraus.\r\nAber letztlich geht es um nicht weniger als einen historischen Kampf um Ende-zu-Ende-Verschlüsselung.\r\nAuf dem Tisch liegt das Thema aber schon deutlich länger. Wir wollen zurückblicken auf die Ursprünge und Kernpunkte des Gesetzesvorschlags. Und dann zusammen mit dem Publikum noch einmal die unüberschaubaren Wege gehen, die die Arbeit an diesem Gesetzesentwurf genommen hat.\r\nAus der Perspektive von Deutschlands oberstem Datenschützer (Ulrich Kelber), dem Abgeordneten des Europäischen Parlamanets (Patrick Breyer) und der digitalen Zivilgesellschaft (khaleesi) erzählen wir die bisherige Geschichte der Chatkontrolle. \r\nWenn ihr dachtet, ihr hättet alles zur Chatkontrolle gehört, bereitet euch auf eine absurde Tragödie vor, die ihr Ende noch nicht gefunden hat.\r\n\r\nTrotz des Erfolgs im EU-Parlament haben wir noch lange nicht gewonnen. Denn alles hängt im und am Rat, dessen Position könnte im Trilog alles zunichte machen was wir hart erarbeitet haben.\r\nUnd auch die Europawahlen stehen vor der Tür und damit kann sich nochmal alles ändern. Nicht fertige Gesetze werden in der EU in der nächste Legislaturperiode einfach weiterverhandelt. Um die Chatkontrolle endgültig zu stoppen, darf keine EU-Abgeordnete durch den Wahlkampf kommen, ohne sich klar zum Schutz von Verschlüsselung zu bekennen.","duration":3600,"logo":null,"type":"lecture","do_not_record":false,"track":"Ethics, Politics \u0026 Society","abstract":" In diesem Vortrag wollen wir auf die letzten knapp drei Jahre Kampf gegen die Chatkontrolle zurückblicken. Ein Kampf, der genauso droht zu einem Wiedergänger zu werden wie die Vorratsdatenspeicherung.\r\nWir waren auf eine harte Auseinandersetzung um Überwachung und sichere Kommunikation vorbereitet. Als Patrick 2020 angefangen, hat uns vor dem, was da kommt, zu warnen, haben wir nicht erwartet, dass es sich zu einer Tragödie entwickeln würde, in der es nicht um Kinderschutz oder Überwachung geht. Sondern um eine Kommission, der jedes Mittel recht ist. Und Korruption und Lobbyskandal.","speakers":[{"guid":"ffd64159-53b2-54af-b7a3-1f30d0fdf8b7","id":8066,"image":"/system/people/avatars/000/008/066/original/Foto2.jpg?1531202884","name":"Dr. Patrick Breyer","public_name":"Dr. Patrick Breyer","email":"europa@patrick-breyer.de","abstract":"Bürgerrechtler und Europaabgeordneter der Piratenpartei","description":"Digitaler Freiheitskämpfer und Europaabgeordneter der Piratenpartei. Von Berufs wegen Jurist, bin ich am 26. Mai 2019 zum Europaabgeordneten gewählt worden und dort Mitglied des Ausschusses für Bürgerliche Freiheiten, Justiz und Inneres (LIBE) und stv. Mitglied des Rechtsausschusses (JURI).","links":[{"url":"https://www.patrick-breyer.de","title":"Homepage (Politik)"}]},{"guid":"6ffd6316-c9a4-59ee-8ccb-e0bbf7be8af9","id":18731,"image":null,"name":"khaleesi","public_name":"khaleesi","abstract":"khaleesi is a spokeswoman of the German Chaos Computer Club.","description":"Sie ist Informatikerin und arbeitet im Bereich IT-Sicherheit. Seit 2022 ist sie federführend im Kampf gegen die geplante Chatkontrolle.\r\nkhaleesi spricht regelmäßig auf Konferenzen und in Podcasts über netzpolitische Themen.","links":[]},{"guid":"ac71f39e-b9ca-5db1-bea9-8e7d6fe5e182","id":19562,"image":null,"name":"Prof. Ulrich Kelber","public_name":"Prof. Ulrich Kelber","abstract":"Bundesbeauftragter für den Datenschutz und die Informationsfreiheit","description":"Informatiker, 20 Jahre Bundestagsabgeordneter für die Stadt Bonn, Parlamentarischer Staatssekretär im Bundesministerium der Justiz und für Verbraucherschutz a.D., in all den Jahren Datenschützer","links":[]}],"start_time":"2023-12-29T19:15:00.000+01:00","end_time":"2023-12-29T20:15:00.000+01:00","room":{"name":"Saal 1","id":471}},{"id":11950,"guid":"b95b344e-c0d3-473d-b064-0bb58f1ca72c","title":"Darf's noch etwas visionärer sein?","subtitle":"Digital-ökologische Zukunftsvorstellungen in der deutschsprachigen Diskurslandschaft","description":"Der Vortrag bietet einen Einblick in die Ergebnisse einer erstmaligen systematischen Untersuchung der im deutschsprachigen Diskurs präsenten Visionen zur digital-ökologischen Transformation und setzt diese in einer Landschaft an Vorstellungen von Transformation, Nachhaltigkeit und Technikgestaltung zueinander in Beziehung. Bei der Recherche wurden zivilgesellschaftliche, staatliche, wissenschaftliche und wirtschaftliche Akteure berücksichtigt. Das Ergebnis sind sechs verschiedene Typen an Visionskategorien: „Dematerialisierung\", „Digital-ökologische Modernisierung\", „Leitplanken einer zukunftsfähigen Digitalpolitik\", „Digital-ökologischer TÜV\", „Digitale Suffizienz\" und „Low-Tech\" bilden die Landschaft der Visionen digital-ökologischer Transformation im deutschsprachigen Raum.\r\n\r\nDie Vorstellung, dass digitale Technik durch Effizienzsteigerungen zu einer Entkopplung von Wirtschaftswachstum und Ressourcenverbrauch beiträgt, kann unter dem Begriff „Dematerialisierung” gefasst werden. „Digital-ökologische Modernisierung” bezeichnet einen eher technokratischen Ansatz, in dem die ökologischen Kosten der Digitalisierung durch Sparsamkeit, Recycling und vor allem den flächendeckenden Einsatz von erneuerbaren Energien zu bewältigen sind. Vertreter*innen des Visionstyps „Leitplanken einer zukunftsfähigen Digitalpolitik” geben statt einer scharf formulierten Vision eher Leitplanken für die zukünftige Gestaltung der Digitalisierung im Rahmen ökologischer Grenzen vor. Die Kategorie „Digital-ökologischer TÜV” beschreibt Ansätze, die eine Bewertung des Verhältnisses von Ökologie und digitaler Technik von einer fortlaufenden Überprüfung des Einsatzes digitaler Technik abhängig machen. Bei „Digitaler Suffizienz” wird das Konzept der Suffizienz auf den Bereich Digitalisierung übertragen und orientiert sich an dem Motto „so viel Digitalisierung wie nötig, so wenig wie möglich“. Zuletzt kann die Idee der Abkehr vom linearen Fortschrittsdenken und von damit einhergehenden ressourcenintensiven High-Tech-Infrastrukturen als „Low-Tech”-Vision bezeichnet werden.\r\n\r\nIm Vortrag wird das Verhältnis der einzelnen Kategorien zueinander anhand von verschiedenen Dimensionen, wie ihr zugrundeliegendes Transformationsverständnis oder die Radikalität der beschriebenen Veränderungen, dargestellt sowie deren politische Bedeutung reflektiert. Welche Visionen erfüllen den Anspruch an eine global gerechte Digitalität der Zukunft?","duration":2400,"logo":"/system/events/logos/000/011/950/original/Bildschirmfoto_vom_2023-12-06_00-47-09.png?1701820049","type":"lecture","do_not_record":false,"track":"Sustainability \u0026 Climate Justice","abstract":"Supereffiziente digitale Technik als Lösung aller Probleme oder doch lieber die selbstgebaute ressourcensparsame Low-Tech-Variante? Die Zukunftsvorstellungen, die den Einsatz digitaler Technik und ökologische Fragen zusammendenken, sind in der deutschen Diskurslandschaft nicht gerade üppig gesät. Im Vortrag werden die Ergebnisse einer Kurzstudie präsentiert, bei der wir die Zukunftsvorstellungen digital-ökologischer Transformation bei gesellschaftspolitischen Akteuren gesucht, analysiert und zu Visionskategorien zusammengefasst haben.","speakers":[{"guid":"4599f0a5-6088-5c1e-9d5d-9f69a1c63fd3","id":8992,"image":"/system/people/avatars/000/008/992/original/Anja_05_klein.jpg?1576515725","name":"Anja Höfner","public_name":"Anja Höfner","email":"a.hoefner@knoe.org","abstract":"Anja ist Teil des Konzeptwerks Neue Ökonomie e.V. und setzt sich dort kritisch mit den sozialen und ökologischen Auswirkungen digitaler Technik und mit der Frage, wie digitale Technik für ein gutes Leben für alle genutzt werden kann, auseinander. \r\nSie war an der Organisation und Gestaltung der Bits \u0026 Bäume Konferenz zu Digitalisierung und Nachhaltigkeit beteiligt und ist Mitherausgeberin der daraus enstandenen Publikationen \"Was Bits und Bäume verbindet\" und \"Shaping Digital Transformation for a Sustainable Society\".","description":null,"links":[{"url":"https://www.oekom.de/buch/was-bits-und-baeume-verbindet-9783962381493","title":"Open Access zum Buch \"Was Bits und Bäume verbindet\""},{"url":"https://publication2023.bits-und-baeume.org/","title":"Konferenzbuch \"Shaping Digital Transformation for a Sustainable Society\""},{"url":"https://digital-bewegt.org/","title":"Broschüre \"Digital bewegt - Wege zum guten (digtalen) Leben für alle\""},{"url":"https://www.endlich-wachstum.de/kapitel/digitalisierung/","title":"Bildungsmaterialien zu Digitalisierung, Nachhaltigkeit \u0026 digitaler Kapitalismus"}]},{"guid":"8e704124-53a3-5ff1-9d34-73b618ca062a","id":19583,"image":null,"name":"Mascha Schädlich","public_name":"Mascha Schädlich","abstract":null,"description":null,"links":[]}],"start_time":"2023-12-29T12:55:00.000+01:00","end_time":"2023-12-29T13:35:00.000+01:00","room":{"name":"Saal 1","id":471}},{"id":11702,"guid":"feb8a130-e621-4bbc-8ea4-441a4b2131dd","title":"Das Diskmags-Projekt","subtitle":"Frühes digitales Kulturerbe aufbereiten für Forschung und Communities","description":"Ein kleines Forschungsprojekt hat sich der großen Aufgabe gewidmet, einen internationalen und systemübergreifenden Katalog zu Diskettenmagazinen der 1980er und 1990er Jahre zu erarbeiten und außerdem eine zunächst deutschsprachige Textsammlung ihrer Inhalte zu erstellen. Es liefert damit eine Grundlage für die Erforschung der frühen digitalen Zine-Kultur und ermöglicht den verschiedenen Szenekreisen, ein Stück weit in ihre eigenen Geschichten einzutauchen. Der Katalog wuchs weit schneller als zunächst angenommen und umfasst inzwischen Nachweise zu 2.500 Magazinen und mehr als 20.000 Einzelausgaben. Bei der Textsammlung gilt es, unter anderem Kompressionsverfahren zu identifizieren und Character-Mappings herzustellen, um Unicode-kompatible Texte erzeugen zu können. Aber auch die Communities helfen mit. Wie lassen sich dabei die verschiedenen rechtlichen Fragen lösen, die Urheberschaft, Leistungsschutz und Persönlichkeitsschutz betreffen? Und wie kann die Langlebigkeit des Katalogs und der Textsammlung sichergestellt werden?","duration":2400,"logo":"/system/events/logos/000/011/702/original/disk_614472_original.jpg?1697624710","type":"lecture","do_not_record":false,"track":"Art \u0026 Beauty","abstract":"Diskettenmagazine waren frühe elektronische Multimedia-Journale der 1980er und 1990er Jahre, die auf Diskette verbreitet wurden und nur auf den jeweils passenden Geräten benutzbar waren. Bibliotheken und Archive haben diese sogenannten „Diskmags\" damals nicht berücksichtigt, mittlerweile stellen die ca. 2.500 Magazine aber eine wertvolle Quelle für die Forschung und die Diskmags-Communities dar. Das vorgestellte Projekt baut einen Katalog auf und macht Texte durchsuchbar.","speakers":[{"guid":"d239daa2-337b-5fd8-acd9-9cf6033bf198","id":18982,"image":"/system/people/avatars/000/018/982/original/ananas-ukulele.png?1697624648","name":"Torsten Roeder","public_name":"Torsten Roeder","abstract":"Torsten manages Digital Humanities projects at the »Center for Philology and Digitality« (University of Wurzburg) and gives classes in retrocomputing. He studied musicology and Italian, likes working on train and loves sailing, biking and singing.","description":"Torsten previously worked in digital research projects at the Berlin Brandenburg Academy of Sciences and Humanities, in a digital long-term edition project at the Institute for Musicology (Wurzburg), as Digital Humanities officer at the Leopoldina Academy (Halle/Saale) and as interim professor for Digital Humanities at the University of Wuppertal.","links":[{"url":"http://torstenroeder.de","title":"Homepage"},{"url":"https://www.uni-wuerzburg.de/zpd/","title":"Zentrum für Philologie und Digitalität"}]}],"start_time":"2023-12-28T21:10:00.000+01:00","end_time":"2023-12-28T21:50:00.000+01:00","room":{"name":"Saal Zuse","id":473}},{"id":11951,"guid":"b7942ebe-62cd-408b-8ded-72a60cca1d49","title":"Das Recht auf Selbstverteidigung im modernen Völkerrecht","subtitle":"DIe Ausnahme vom Gewaltverbot: Wann darf ein Staat sich mit Waffengewalt verteidigen? ","description":"Das völkerrechtliche Selbstverteidigungsrecht ist momentan in aller Munde. Ob im Südkaukasus, der Ukraine oder im Nahen Osten, eine Zunahme militärischer Gewalt führt immer wieder dazu, dass Staaten ihr Recht auf Selbstverteidigung wahrnehmen. Der Vortrag erläutert die Ursprünge des völkerrechtlichen Gewaltverbotes und das Verhältnis zum Selbstverteidigungsrecht. Außerdem wird der Zusammenhang zum humanitären Völkerrecht erklärt (ius ad bellum/ius in bello), weil es hier in der öffentlichen Debatte immer wieder zu Vermischungen kommt. \r\n\r\nIm Kern werden folgende Fragen beantwortet: \r\n\r\nWann hat ein Staat ein Recht auf Selbstverteidigung? \r\nWie und wie lange kann das Selbstverteidigungsrecht ausgeübt werden? \r\nGegen wen richtet sich das Recht auf Selbstverteidigung? \r\n\r\nDie Ergebnisse werden dann auf aktuelle Fälle angewandt (bspw.: Russlands Angriffskrieg gegen die Ukraine, Terrorangriff der Hamas auf Israel). \r\n\r\n\r\n","duration":2400,"logo":null,"type":"lecture","do_not_record":false,"track":"Ethics, Politics \u0026 Society","abstract":"Der Vortrag gibt eine Einführung in das völkerrechtliche Recht auf Selbstverteidigung. Das moderne Völkerrecht verbietet die Drohung oder den Einsatz militärischer Gewalt. Eine Ausnahme davon ist das Recht auf Selbstverteidigung im Falle eines bewaffneten Angriffes. ","speakers":[{"guid":"35b1e2d8-e6ff-5d38-a072-3473ea24c37d","id":8729,"image":null,"name":"Dustin Hoffmann","public_name":"Dustin Hoffmann","abstract":"Jurist, LL.M. in Völkerrecht, Büroleiter im Europäischen Parlament seit 2014.","description":null,"links":[]}],"start_time":"2023-12-28T12:55:00.000+01:00","end_time":"2023-12-28T13:35:00.000+01:00","room":{"name":"Saal Zuse","id":473}},{"id":11810,"guid":"0eced221-299d-4dba-ad51-6063978b2b41","title":"Decentralized energy production: green future or cybersecurity nightmare?","subtitle":"The cybersecurity dark side of solar energy when clouds are involved","description":"\u003ch2\u003eContext: cybersecurity for future energy production systems\u003c/h2\u003e\r\n\r\n\u003cp\u003eCybersecurity for smaller solar power plants is a critical challenge: strong separation between operational, safety relevant network and internet is not present. Moreover, manufacturers do not invest enough in security; reason being high competition in terms of time to market, price pressure and lack of security knowledge.\u003c/p\u003e\r\n\u003cp\u003eThese power plant systems need more or less an internet connection in order to fetch power \u0026 energy data from the plant with an app, perform firmware updates, and carry out maintenance remotely.\u003c/p\u003e\r\n\u003cp\u003eThe central device, which is connected to the internet, is the inverter. Many companies provide inverters for solar power plants and include cloud connectivity. An inverter converts the energy from the solar panels to grid compatible energy. Since it handles high currents \u0026 voltages, the physical consequences of cybersecurity risks are arguably higher than for standard smart home devices.\u003c/p\u003e\r\n\r\n\u003ch2\u003eResearch results related to connected solar inverters (technical part)\u003c/h2\u003e\r\n\r\n\u003cp\u003eOut of curiosity, I tested different inverters from different manufacturers, including cloud connectivity. All devices have a license to be operated in Germany and are very popular. They are used in solar power plants of different sizes, from balcony size to bigger plants. \r\nIn this section some research results will be presented, we will especially focus on one system.\u003c/p\u003e\r\n\r\n\u003cp\u003e\u003cb\u003ePositive note: critical vulnerabilities have been patched by now.\u003c/b\u003e\u003c/p\u003e\r\n\r\n\u003ch2\u003eVulnerabilities\u003c/h2\u003e\r\n\r\n\u003cul\u003e\u003cli\u003e\u003cem\u003eInsecure Direct Object Reference\u003c/em\u003e (IDOR) or similar vulnerabilities have been found, allowing an attacker with a simple account to execute commands on connected inverters remotely. This was an enabler for many further attacks.\u003c/li\u003e\r\n\u003cli\u003eAn attacker could trigger a firmware update process on connected inverters. \u003c/li\u003e\r\n\u003cli\u003eThe firmware update process was not properly secured: update images did not include a cryptographic signature.\u003c/li\u003e\r\n\u003cli\u003eMost of the devices did not use the TLS protocol for cloud communication or did not use it correctly.\u003c/li\u003e\r\n\u003cli\u003eSecure boot and secure debugging were not implemented.\u003c/li\u003e\r\n\u003cli\u003eOn the server side, there were insufficient sanity checks.\u003c/li\u003e\r\n\u003cli\u003eSensitive data (e.g. serial number) was easy to extract.\u003c/li\u003e\r\n\u003c/ul\u003e\r\n\r\n\u003ch2\u003eExploitation\u003c/h2\u003e\r\n\r\n\u003cul\u003e\r\n\u003cli\u003eCommands could be executed on any connected devices (e.g. switch ON, switch OFF, change parameters).\u003c/li\u003e\r\n\u003cli\u003eThe power electronics and relays of devices could be manipulated remotely with a malicious firmware update.\u003c/li\u003e\r\n\u003cli\u003eBy manipulating many devices synchronously the stability of the grid could be endangered.\u003c/li\u003e\r\n\u003c/ul\u003e\r\n\r\n\u003cp\u003eA proof of concept with a full (unlocked) exploit chain will be presented.\u003c/p\u003e\r\n\r\n\u003ch2\u003eConclusion and Discussion\u003c/h2\u003e\r\n\r\n\u003cp\u003eRemoving bureaucratic hurdles is an important step in order to democratize our energy production - and renewable energies are the future! On the other hand, if it comes at the cost of poorly-secured devices, this may be jeopardized.\u003c/p\u003e\r\n\r\n\u003cp\u003eIn Germany, we have the Kritis Verordnung (decree) to protect for example the electricity infrastructure. It states that every power \u003ca href = \"https://www.gesetze-im-internet.de/bsi-kritisv/anhang_1.html\"\u003eplant with more than 104 MW capacity is required to have specific protections\u003c/a\u003e. Individually, the small solar power plants are not in this category. However, summing up all devices connected to one cloud, we probably reach these numbers by now - and if not, tomorrow. Current projections point in that direction.\u003c/p\u003e\r\n\r\n\u003cp\u003eDuring this research, I realized how easy it is to take control of energy production devices and it scared me. The cloud connectivity and the related \"remote control / remote maintenance\" and \"firmware update\" processes are truly critical and attacks may scale. Even if vulnerabilities are patched by now, an attacker who finds a way into the cloud servers can control all connected inverters.\u003c/p\u003e\r\n\r\n\u003cp\u003eOn the other hand, it seems that there are no security related regulations regarding these systems as of today in the European Union. The \u003ca href = \"https://digital-strategy.ec.europa.eu/en/library/cyber-resilience-act\"\u003eEU Cyber Resilience Act\u003c/a\u003e, which will apply to these devices is still in discussion and is likely to be effective soon. However, manufacturers will probably have a grace period of 36 months to comply: by then, many insecure devices will already be installed. Knowing how many bad guys are out there, the risk is there and growing rapidly.\u003c/p\u003e","duration":2400,"logo":"/system/events/logos/000/011/810/original/sun-5277491_1280_-_Kopie2.jpg?1701716892","type":"lecture","do_not_record":false,"track":"Security","abstract":"\u003cp\u003eIn this talk we will have a look at some cybersecurity challenges raised by the trend of decentralizing our energy production.\u003c/p\u003e\r\n\u003cp\u003eOur energy infrastructure is now changing from a centralized system based on big power plants to a more decentralized system based on renewable energy produced by smaller power plants (maybe yours). In Germany alone, \u003ca href = \"https://www.heise.de/hintergrund/Ueber-300-000-Balkonkraftwerke-in-Deutschland-in-Betrieb-Statistik-der-Woche-9285107.html\"\u003e300.000 so called balcony power plants were in operation by August 2023\u003c/a\u003e. Most of these smaller power plants are / will be somehow connected to some cloud services.\u003c/p\u003e\r\n\u003cp\u003eTo show that security hasn't been the biggest priority, we will examine the cybersecurity controls of different solar inverters. To put it mildly: there is room for improvement.\u003c/p\u003e\r\n\u003cp\u003eWe will also discuss the need for better regulations and enforcement of cybersecurity for smaller connected power plants: altogether they probably produce more power than the bigger ones - and this trend is accelerating.\r\nProtecting our infrastructure shall have - today more than ever before - a high priority.\u003c/p\u003e","speakers":[{"guid":"807a7e45-4994-5c67-b355-0512c552c572","id":18966,"image":null,"name":"Sebastien","public_name":"Sebastien","abstract":"\u003cbody\u003e\r\nSebastien is a security researcher with an interest in embedded systems and operational technologies. Sebastien likes to disassemble Things (the T in IoT) and look for special “features” (sometimes called vulnerabilities). In many cases he ends up with Things that do not work anymore after he’s done with them. That's why Sebastien also enjoys repairing electronic devices either by himself or in Repair Cafes. \r\n\u003c/body\u003e","description":null,"links":[]}],"start_time":"2023-12-28T22:05:00.000+01:00","end_time":"2023-12-28T22:45:00.000+01:00","room":{"name":"Saal 1","id":471}},{"id":12042,"guid":"6b644bd3-6e7d-465b-8490-47e05db74fc6","title":"Decolonize runet! Decolonize network measurements! A provocative take  on the Russian sovereign internet project ","subtitle":null,"description":"This talk proposes to look at the russian \"sovereign internet\" project from a decolonialist point of view. This interdisciplinary research is based on almost 6 years of fieldwork, combining network measurements, open data from IODA, OONI, Censored Planet, as well as OSINT investigations, analysis of legal texts, in-depth interviews and web-ethnography. \r\n\r\nTo understand the decolonialist discourses and movements, we have also analyzed Telegram as an environment where these discourses are being multiplied since the beginning of the full-scale invasion of Ukraine. With colleagues from Raspad.Network we scraped and analyzed a corpus of Telegram channels dedicated to regionalist, indigenous, local agenda and visualized connections and disparities between different indigenous and regionalist movements. We tried to distinguish between grassroots groups and curated organizations tied to larger orchestrated disinformation campaigns. In our talk we will showcase some of the highlights from this study and share some visualizations based on graph analysis that will help the audience to learn more about the multitude of decolonialist movements within Russia.\r\n\r\nThe talk proposes to consider inequalities of access to information and connectivity across different territories of the so-called Russian Federation. Looking at past events of local/regional internet shutdowns — starting from informational annexation of Crimea in 2014, followed by the remarkable shutdowns in 2018 in Ingushetia, as well as more recent events in Dagestan and other less \"mediatized\" shutdown or throttling cases, we argue that the so-called Runet is not a homogeneous space, but actually a multitude of different \"lived experiences\". \r\n\r\nIt is well-known in the space of internet science that Russia has a diverse ISP space and counts more than 3500 Internet Service Providers. However, it is much less noticed that these ISPs are not equally distributed across the territory, and not without consequence. We argue that the so-called \"Tcheburnet\" (a commonly used term for \"Russian autonomous and sovereign Internet\" project) is in fact a heterogeneous construct. There is no \"Cheburnet\", but there are \"Cheburnets\". \r\n\r\nThe experiences of Runet largely depend on the regions where users live, as well as on their ethnicity, their political views and online cultures. We argue that a region's resilience to shutdowns (but also to mainstream propaganda) correlates with the amount of Autonomous System Numbers and the diversity of the ISP market (and disparities in distribution of those are also historically grounded in the \"soviet project\").\r\n\r\nWe propose to analyze information control and censorship in terms of \"experience\", as it impacts interactions between humans, affects their lives on a daily basis and therefore shapes the worlds they live in. Our talk is using a rich ethnographic material to show how people describe problems they encounter with connectivity (especially since Russia has started its war on VPNs). We invite VPN providers and circumvention tool developers to embrace users' perceptions and feelings about what means \"working\" and what means \"not working\". \r\n\r\nWhile in the network measurement space it is common to either rely on remote measurements, or on probes run by volunteers inside their networks, there is also a qualitative part that should be taken into account to provide a more human-centric, more realistic analysis of what users on the ground experience while interacting with their devices. \r\n\r\nThis talk is also a call against resignation, a call for hackers, VPN providers, circumvention tech developers and Internet freedom activists to actively support indigenous struggles inside \"russia\" and take into consideration multitudes of experiences within the so-called umbrella \"runet\". ","duration":2400,"logo":null,"type":"lecture","do_not_record":false,"track":"Ethics, Politics \u0026 Society","abstract":"This talk proposes to look at the russian \"sovereign internet\" project from a decolonialist point of view. First, it provides an analysis of a corpus of Telegram channels of indigenous, decolonialist and regionalist movements to map the growing space of \"post-Russian\" discourses. Secondly, it suggests to consider inequalities of access to information and connectivity across different territories of the so-called Russian Federation. Looking at past events of local/regional internet shutdowns. It describes the so-called Runet not as a homogeneous space, but actually a multitude of different \"lived experiences\". It proposes a framework to analyze regional shutdown-resilience and understand how Russia has been tightening its control on specific regions.","speakers":[{"guid":"4d1f25eb-4dad-5c50-8d32-3a59aaef0bdf","id":19281,"image":null,"name":"Ksenia Ermoshina","public_name":"Ksenia Ermoshina","abstract":null,"description":null,"links":[]}],"start_time":"2023-12-30T12:55:00.000+01:00","end_time":"2023-12-30T13:35:00.000+01:00","room":{"name":"Saal Zuse","id":473}},{"id":11846,"guid":"3794b61d-8f56-4e0c-8895-8c674c1d6570","title":"Demoscene now and then","subtitle":"The demoscene is an underground computer art culture.","description":"The demoscene is an underground computer art culture. The term demoscene comes from the word demo, short for demonstration. In the context of the demoscene the word demo means a realtime audiovisual application which is demonstrating the capabilities of the machine it runs on.\r\n\r\nDemosceners (\"sceners\") are what we call the folks with too much free time that abuse their computer skills to create releases under the demoscene.\r\n\r\nDemosceners often use nicknames (\"nicks\" or \"handles\") to identify themselves. They also tend to hang out in so-called demogroups. Some demosceners are active members of multiple demogroups, with or without using the same nickname.\r\n\r\nLet's get one thing clear: the demoscene has no commercial purpose. The only thing you'll get out of the demoscene, and this only comes after investing a significant amount of your free time into it, is a few useful soft skills and a large community of computer nerd friends.\r\n\r\nDemoscene releases are meant to show the limits of the machines, the technical skills and artistic sensibility of the makers. There are no rules to what kind of release you can make on the demoscene. Some demos are made as technical benchmarks, others as conceptual art, most are done just for fun. It is entirely up to you to explore what you like doing and share it with other demosceners.\r\n\r\nDemoscene releases can be divided into certain categories:\r\n\r\nTrack, an audio piece, can be in an executable format, in a tracker module format or in a pre-rendered wav/mp3 format\r\nGraphics entry, drawn or rendered images with fixed resolutions and/or a restricted color palette\r\nDemo, an audiovisual real-time executable demonstration for a certain platform\r\nIntro, typically a demo with file size limitation all packed into a single executable file that includes all the assets (popular size formats are 256bytes, 512bytes, 1kb, 4kb, 8kb, 64kb)\r\nAnimation, rendered graphics videos\r\nDemopack, a collection of demos in a single disk\r\nMusicdisk, a collection of demoscene tracks with an executable player interface\r\nDiskmag, a collection of texts about the demoscene with an executable graphics interface\r\nWild entry, everything else (including live performances, videos of demos on uncommon platforms, videos about demomaking, etc)\r\nReleases typically occur at demoparties, gathering events for demosceners.\r\n\r\n","duration":2400,"logo":"/system/events/logos/000/011/846/original/spt-terraFz-TFehWYAIas1U.jpg?1699007210","type":"lecture","do_not_record":false,"track":"Art \u0026 Beauty","abstract":"The demoscene is an underground computer art culture. The Speaker is a member of the Demoscene since the 1980ies and gives insights how it is now and how it was back in the days and how you can participate!","speakers":[{"guid":"b19d7a29-8ecd-5ab2-a490-1dbc985afc1a","id":18831,"image":"/system/people/avatars/000/018/831/original/kopie-xerox39-inmffm42019-IMG_2560.jpg?1702153591","name":"LordSpreadpointAmiga","public_name":"LordSpreadpointAmiga","abstract":"Artist, Cracker, Demoscener, Hacker, Musician","description":"After passing the highly gifted exam, Siegfried Kärcher began studying “fine arts” at the Ottersberg University of Applied Sciences, which he completed with a diploma in 2001. As a freelance artist, he founded a studio community on the studio ship in Frankfurt am Main that same year. This was followed by participation in exhibitions at home and abroad and various teaching positions in art, design and multimedia. He was a board member of the Professional Association of Visual Artists in Frankfurt and a representative at the state and federal levels. As a musician, he played hundreds of concerts at home and abroad.\r\n\r\nHe has been an active member of the hacker, demo and computer scene since the 1980s. He releases electronic music on the Frankfurt label collective Force Inc. and Mille Plateaux.\r\n\r\nSince 2014 he has been organizing the Siegfried Kärcher Art Days in the Radom (Post War RAdar-DOMe) on the Mountain Wasserkuppe with changing guest artists.\r\n\r\nArt awards (selection)\r\n2014: 1st prize in art for Siegfried Kärcher's work \"1984_ZUSE_hen\" on the subject of computer science and society - computers and mind - aspects of determining the position of the Frankfurt University of Applied Sciences.","links":[{"url":"www.4sk.de","title":"Homepage"}]}],"start_time":"2023-12-28T20:15:00.000+01:00","end_time":"2023-12-28T20:55:00.000+01:00","room":{"name":"Saal 1","id":471}},{"id":11989,"guid":"ad162bc8-bf6b-407d-85f6-d2254637889d","title":"Der sehende Stein der Polizeibehörden ","subtitle":"Der Einsatz von Palantir Gotham aus technischer und rechtlicher Sicht","description":"Der Vortrag behandelt vier Schwerpunkte:\r\n1.: In welchen Bundesländern und zu welchem Zweck wird die Palantir-Software Gotham eingesetzt oder soll in Zukunft eingesetzt werden? \r\n2.: Wie funktioniert die Software und welche Risiken bringt ihr Einsatz mit sich?\r\n3.: Welche rechtlichen Einschränkungen gelten und wie könnten sie technisch umgesetzt werden? \r\n4.: Hessen hat sein Gesetz aufgrund der Entscheidung des Bundesverfassungsgerichts angepasst. Stellt die Neuregelung für die Gotham-Software unter dem Namen „Hessendata“ wirklich eine Verbesserung dar?\r\n\r\nÜber mit dem Einsatz der Software verbundene Risiken – darunter Diskriminierung, Stigmatisierung, Datenschutz, IT-Sicherheit, Kontrollierbarkeit – sprechen Constanze Kurz (CCC), Simone Ruf und Jürgen Bering (beide Gesellschaft für Freiheitsrechte, GFF). Beide Organisationen waren am Verfahren vor dem BVerfG beteiligt: Die GFF hatte das Verfahren initiiert und der CCC wirkte als Sachverständiger mit.","duration":3600,"logo":"/system/events/logos/000/011/989/original/riesenauge.jpg?1699694995","type":"lecture","do_not_record":false,"track":"Ethics, Politics \u0026 Society","abstract":"Der Markt von Palantir ist der öffentliche Sektor, längst in Europa und auch in Deutschland. Der umstrittene US-Softwareanbieter verarbeitet strukturierte und unstrukturierte Informationen aus Polizeidaten oder Patientendaten und versucht, sich unverzichtbar zu machen für die Behörden, mit denen er Verträge hat. In Deutschland steht Palantir allerdings eine Entscheidung des Bundesverfassungsgerichts im Weg, das erstmals über den Einsatz von heute gern als KI gehypter Software für Polizeidaten entschieden hat.","speakers":[{"guid":"618c6b58-1a12-5383-972e-8bef9d7b099a","id":19321,"image":null,"name":"Simone Ruf","public_name":"Simone Ruf","abstract":null,"description":null,"links":[]},{"guid":"c628754f-db69-5973-a535-52e518c4e542","id":19181,"image":null,"name":"Jürgen Bering","public_name":"Jürgen Bering","email":"juergen.bering@freiheitsrechte.org","abstract":"Lawyer at Gesellschaft für Freiheitsrechte (Society for Civil Rights)","description":null,"links":[]},{"guid":"5339635c-40f8-53be-80d1-86242db40345","id":1630,"image":"/system/people/avatars/000/001/630/original/constanze.jpeg?1702309503","name":"Constanze Kurz","public_name":"Constanze Kurz","abstract":"Constanze is a spokeswoman of the German Chaos Computer Club.","description":"Constanze is an author und freelance writer on technical topics and works at Berlin-based netzpolitik.org. She holds a doctoral degree in computer science. She is an activist and expert on surveillance techniques and wrote technical analyses for the German Constitutional Court on controversial cases like data retention, covert infiltration of IT systems (spyware), anti-terror database, predictive software systems (Palantir), and voting computers.","links":[{"url":"https://de.wikipedia.org/wiki/Constanze_Kurz","title":"Wikipedia"}]}],"start_time":"2023-12-28T14:45:00.000+01:00","end_time":"2023-12-28T15:45:00.000+01:00","room":{"name":"Saal 1","id":471}},{"id":11931,"guid":"293112df-d0f3-4502-8971-f2f9ed6401d3","title":"DevOps but for artworks in museums","subtitle":"A look into pipelines ending in museums and not in the cloud","description":"The preservation and presentation of software/computer-based art in museums presents unique challenges in the contemporary landscape. One prominent issue is the ephemeral nature of digital media, which includes websites, games, software and virtual reality art. Unlike traditional art forms, these works often rely on rapidly evolving technologies, making them vulnerable to obsolescence. Museums are faced with the task of preserving and restoring media art in a way that not only preserves the original intent of the artist, but also ensures accessibility for future audiences. \r\n\r\nAnother significant challenge is the dynamic and interactive nature of many media artworks. Unlike static paintings or sculptures, digital artworks often require specific hardware, software or immersive environments to be experienced. Museums need to invest in both the technological infrastructure and the expertise to recreate these conditions and provide visitors with an authentic encounter with the artwork. \r\n\r\nIn this talk we want to look at some solutions from the perspective of software developers who are motivated not only to preserve and present digital media art, but also to develop it with contemporary software development strategies.","duration":3600,"logo":null,"type":"lecture","do_not_record":false,"track":"Art \u0026 Beauty","abstract":"In the original Hacker Ethics, Steven Levy stated that \"you can create art and beauty on a computer\". That was 40 years ago, creating art and beauty is one thing, but how do you maintain or develop it as a gallery, archive or museum? You know all about CI/CD and deploying to \"the cloud\"? Well, let me show you how to deploy to a museum or art space. Important note: this talk is not about NFTs.","speakers":[{"guid":"c0c97495-b866-5f47-be8b-7dca900117d1","id":4508,"image":"/system/people/avatars/000/004/508/original/photo_2023-07-09_16.50.02.jpeg?1699480626","name":"obelix","public_name":"obelix","abstract":null,"description":null,"links":[]}],"start_time":"2023-12-29T19:15:00.000+01:00","end_time":"2023-12-29T20:15:00.000+01:00","room":{"name":"Saal Zuse","id":473}},{"id":11974,"guid":"b80ae06b-778b-41c7-b4be-cc87820339d2","title":"Die Akte Xandr: Ein tiefer Blick in den Abgrund der Datenindustrie","subtitle":null,"description":"Was auch immer wir im Internet tun, es wird aufgezeichnet und ausgewertet, um uns zielgerichtet Werbung anzuzeigen. An diese triste Realität haben sich viel zu viele Menschen längst gewöhnt. Wo genau unsere Daten landen, wenn wir Websites aufrufen oder Apps nutzen, das können die wenigsten nachvollziehen. Bis jetzt.\r\n\r\nDurch ein Dokument, das eigentlich nicht für die Öffentlichkeit bestimmt war, konnten wir dieses Jahr einen einmaligen Einblick gewinnen. Es ist die Angebotsliste von Xandr, einem der größten Datenmarktplätze der Werbewelt. Sie enthält mehr als 650.000 unterschiedliche Zielgruppenkategorien - also Schubladen für Menschen, um sie mit Targeted Advertising zu erreichen.\r\n\r\nBei einigen dieser Kategorien möchte man laut auflachen, bei anderen bleibt einem das Lachen im Halse stecken. Ob „fragile Senioren“ oder „leidenschaftliche Liebhaber“, ob shopping-versessene Mütter oder Menschen mit Essstörung, ob deutsche Soldat:innen oder „Geringverdiener ohne Orientierung“ – sie alle lassen sich durch die Werbeindustrie gezielt ins Visier nehmen.\r\n\r\n„Diese Liste ist das gewaltigste Dokument über den globalen Datenhandel, das ich je gesehen habe“, sagt der Wiener Tracking-Forscher Wolfie Christl und spricht von einem Skandal. Florian Glatzner vom Verbraucherzentrale Bundesverband spricht gar vom „Snowden-Moment der Online-Werbebranche\". Denn dass Werbeindustrie und Datenhändler uns überwachen, wussten wir schon lange – jetzt haben wir schwarz auf weiß, wie invasiv und detailliert das passiert.\r\n\r\nWochenlang haben wir das Dokument ausgewertet, unter anderem mit Hilfe des Datenjournalisten Johannes Gille und unserer Kollegen von The Markup aus den USA. Wir decken Hunderte äußerst bedenkliche Segmente über die Schwächen und das Verhalten von Bürger:innen aus 15 EU-Ländern auf. Wir belegen erstmals, wie stark inzwischen auch deutsche Firmen am Geschäft mit unseren Daten mitverdienen. Und wir dokumentieren, auf welch tönernen Füßen dieses Business rechtlich steht.\r\n\r\nIn unserem Vortrag präsentieren wir die wichtigsten Ergebnisse unserer \r\n\u003ca href=\"https://netzpolitik.org/tag/die-xandr-recherche/\"\u003eArtikel-Serie\u003c/a\u003e und die Methoden unserer Recherche. Mehrere internationale Medien haben die Recherche bereits aufgegriffen und Analysen für die USA, Australien, die Niederlande und die Schweiz veröffentlicht\r\n\r\nWir zeigen, wo genau Interessierte an die Recherche anknüpfen können – und wie Nutzer:innen selbst aktiv werden können. Nicht zuletzt machen wir klar: Das System kann weg, denn es gibt längst Alternativen zur Überwachungsindustrie.","duration":2400,"logo":null,"type":"lecture","do_not_record":false,"track":"Ethics, Politics \u0026 Society","abstract":"Dieses Jahr konnten wir erstmals im Detail nachvollziehen, wie invasiv und kleinteilig uns Werbefirmen und Datenhändler im Netz kategorisieren. Denn Microsofts Datenmarktplatz Xandr hat versehentlich ein riesiges Dokument veröffentlicht, das ungeahnte Einblicke hinter die Kulissen die Werbeindustrie erlaubt. In der Folge haben mehrere Datenschutzbehörden aus Deutschland und der EU mitgeteilt, die betroffenen Firmen und ihr Geschäft zu prüfen. Aller Cookie-Müdigkeit zum Trotz zeigt unsere Recherche: Aufgeben ist nicht. Es gibt Alternativen für das Geschäft mit unseren Daten, für die es sich zu kämpfen lohnt.","speakers":[{"guid":"e1d84ffd-5b4e-55fb-98b1-916d5c386611","id":12197,"image":null,"name":"Sebastian Meineck","public_name":"Sebastian Meineck","abstract":"Sebastian Meineck ist Journalist und seit 2021 Redakteur bei netzpolitik.org. Zu seinen aktuellen Schwerpunkten gehören digitale Gewalt, Pornoseiten und Künstliche Intelligenz. Er interessiert sich besonders für Methoden der Online-Recherche; darüber schreibt er einen monatlichen Newsletter und gibt Workshops an Universitäten. Zu seinen vorigen Stationen gehören VICE (Senior Editor), Motherboard (Editor-in-chief), der SPIEGEL (Autor) und die Deutsche Journalistenschule München. Das Medium Magazin hat ihn 2020 zu einem der Top 30 unter 30 im Journalismus gekürt.","description":null,"links":[{"url":"https://sebastianmeineck.wordpress.com/","title":"Website"},{"url":"https://sebmeineck.substack.com/","title":"Newsletter"},{"url":"https://mastodon.social/@sebmeineck","title":"Mastodon"}]},{"guid":"f19f8817-e80d-5c5f-af0d-63d95f3626f4","id":19563,"image":"/system/people/avatars/000/019/563/original/Ingo_Dachwitz.jpg?1702286009","name":"Ingo Dachwitz","public_name":"Ingo Dachwitz","abstract":"Author, researcher, journalist at netzpolitik.org.","description":"I am a journalist and communication scientist. I have been an editor at netzpolitik.org since 2016, where I co-host the Off/On podcast. I am interested in questions of power in digitalisation. My topics are surveillance capitalism, digital civil society and the digital public sphere. To be more specific: I often write about data misuse and data protection, online advertising, digital election campaigns, platform regulation, transparency, lobbying and right-wing extremism in the police.","links":[]}],"start_time":"2023-12-27T12:55:00.000+01:00","end_time":"2023-12-27T13:35:00.000+01:00","room":{"name":"Saal Zuse","id":473}},{"id":11970,"guid":"89c3e9fd-bc64-42c6-a494-36404874ef0f","title":"Die netzpolitische Neujahrsansprache","subtitle":"Digitalisierung - Ja, wir schaffen das!","description":"Liebe Hacker:innen von Neuland, was für ein Jahr liegt hinter uns! Ein Jahr, das einige Veränderungen mit sich gebracht hat. Und das gezeigt hat: Wir dürfen nicht müde werden, für eine lebenswerte digitale und analoge Welt zu kämpfen. Tun wir miteinander alles – aber auch wirklich alles – dafür, dass wir diejenigen, die unser schönes Neuland zu einem Ort der Autoritäten und Konzerne machen wollen, im neuen Jahr endlich besiegen können.","duration":2400,"logo":null,"type":"lecture","do_not_record":false,"track":"Entertainment","abstract":"Ein halb satirischer, halb ernster Rück- und Ausblick auf die Baustellen der digitalen Welt.","speakers":[{"guid":"1bf69109-efa8-5af2-9b1b-97a9cdc672dc","id":4465,"image":null,"name":"Anna Biselli","public_name":"Anna Biselli","abstract":"Tagsüber Journalistin, abends feiner Fug.","description":null,"links":[]},{"guid":"6ffd6316-c9a4-59ee-8ccb-e0bbf7be8af9","id":18731,"image":null,"name":"khaleesi","public_name":"khaleesi","abstract":"khaleesi is a spokeswoman of the German Chaos Computer Club.","description":"Sie ist Informatikerin und arbeitet im Bereich IT-Sicherheit. Seit 2022 ist sie federführend im Kampf gegen die geplante Chatkontrolle.\r\nkhaleesi spricht regelmäßig auf Konferenzen und in Podcasts über netzpolitische Themen.","links":[]},{"guid":"52d341b7-8417-5093-959e-496c9f529196","id":19120,"image":null,"name":"Markus","public_name":"Markus","abstract":null,"description":null,"links":[]}],"start_time":"2023-12-28T23:55:00.000+01:00","end_time":"2023-12-29T00:35:00.000+01:00","room":{"name":"Saal 1","id":471}},{"id":11863,"guid":"58278290-dcb6-4c68-98e1-449092abd583","title":"Dissecting EU electronic evidence","subtitle":null,"description":"Having worked on the cross border e-evidence dossier since it's inception in 2017, the talk aims to present an insider view on the proposed procedures and legal protections, the scope of the obligation on industry to promptly provide information to law enforcement as well as the status of the proposed technical implementation including the proposed authentication and encryption of requests as well as the response data provided.\r\n\r\nAs an industry representative participating in the official EU e-evidence implementation task force I am going to take a look at the current, up to date status of the proposed implementation as well as the numerous grey areas to still be addressed both legally as well as technically to make the e-evidence dossier even remotely workable/acceptable for all parties concerned.","duration":2400,"logo":null,"type":"lecture","do_not_record":false,"track":"Ethics, Politics \u0026 Society","abstract":"The EU \"e-evidence\" regulation is a critical piece of new legislation directly affecting all EU citizens. Proposed in 2017, it has been completed in 2023 as has since become law, mandating a more or less direct, cross border access to all sorts of stored information by law enforcement. I will be addressing \r\nhow individuals are affected and how the release of e-evidence works technically. Who are the actors? Which types of information can be requested? How are individual rights protected?\r\n","speakers":[{"guid":"c45606cb-1dd0-512f-b6db-b375bdefec10","id":174,"image":"/system/people/avatars/000/000/174/original/landefeld01_quadrat-461x461.jpg?1545930335","name":"Klaus Landefeld","public_name":"Klaus Landefeld","email":"klaus.landefeld@eco.de","abstract":"Klaus Landefeld is an expert on the topics of infrastructure and networks, Internet neutrality, data retention, telecommunications surveillance, and IT security. \r\nAs early as 1984, he was already setting up mailbox systems and LAN infrastructure, and became active in the internet in 1988. In 1995 he founded Nacamar Data Communications GmbH, one of the first independent IP service providers in Germany which he led to become one of the first Tier One Backbones – AS3257. Following the sale of the Nacamar Group to World Online N. V., Klaus Landefeld was CTO of the pan-European technology division, where he was responsible for 1,500 technicians in 17 national subsidiaries. \r\nSince 2013, Klaus Landefeld and nGENn GmbH have been advising companies on the establishment and operation of BWA, DSL and FTTx broadband networks, data centers, and IP-based services. He also acts as data protection and security officer for diverse carriers.\r\nAs a member of various committees worldwide, Klaus Landefeld provides advice and support to organizations and authorities. Among other roles, he is the Vice Chair of the Management Board of eco – Association of the Internet Industry, where he has been a member of the management board since 1997. He also is a Member of the Supervisory Board of the DE-CIX Group AG, a member of the Committee for Technical Regulation in Telecommunications (ATRT) of the German Federal Network Agency and has been working through the I\u0026J Policy network in helping shape the cooperation of law enforcement and industry. Recently, he has become an Industry Expert in the EU advisory group for the implementation of the e-evidence regulation.\r\n","description":null,"links":[{"url":"https://www.eco.de","title":"eco e.V."},{"url":"https://www.de-cix.net","title":"de-cix"}]}],"start_time":"2023-12-30T14:45:00.000+01:00","end_time":"2023-12-30T15:25:00.000+01:00","room":{"name":"Saal Zuse","id":473}},{"id":12086,"guid":"8512bf0b-b247-403e-8035-50cb05523888","title":"Ecocide and (green) colonialism in Sápmi","subtitle":"Data centers on indigenous land in Northern Europe","description":"Sápmi is located in northern Europe and refers to the land of the Sámi people. Over time it has been colonized by Sweden, Norway, Finland and Russia. As a result, the Sámi have been subjected to various forms of oppression and discrimination by these countries to this day.\r\n\r\nSápmi and Sápmi’s colonial history are presented. Current forms of oppression are also addressed. An important role is played by “green capitalism,” a form of capitalism in which oppression is advanced under the guise of climate protection. Some examples include: Dams that disrupt reindeer migration routes and flood sacred Sámi sites, or wind turbines that are widely avoided by reindeer. Of course, the lectures will also address the problems that mines pose for the Sámi. A topic which was discussed lately with the discussion around the rare earths found in the so-called Sweden also here in Germany. Furthermore, the problems caused by the still occurring clear-cutting in the area of the Sámi and the resulting loss of biodiversity are explained.\r\n\r\nWhat resistance has there been in recent years against this capitalist destruction and (green) colonialism? What is the current situation in Sápmi and what does the future look like?","duration":2400,"logo":"/system/events/logos/000/012/086/original/no_mine_in_galloc_sapmi.jpg?1701791076","type":"lecture","do_not_record":false,"track":"Sustainability \u0026 Climate Justice","abstract":"What is Sápmi? And who are the Sami people? Why is their land threatened by the so-called Green Transition? Why is Europe's largest data centre being built on their land? We would like to try to answer these questions and explain in detail why \"our green transition\" is a threat to the land and rights of the Sami people. We will also discuss the so-called green server infrastructure in Sápmi for example the largest data centre in Europe (by Facebook). \r\n\r\nWe are from the Decolonise Sápmi info tour through Germany and not Sámi ourselves. Our talk is based on presentations given by Sámi people during our tour.","speakers":[{"guid":"68cc89f2-c9d6-5cda-ab84-bebd8f1e4641","id":19384,"image":null,"name":"Sámi Info Tour","public_name":"Sámi Info Tour","abstract":null,"description":null,"links":[]},{"guid":"c736eaa2-bbe9-5a59-b9bf-68cb6199e2c9","id":19538,"image":null,"name":"Sámi Info Tour II","public_name":"Sámi Info Tour II","abstract":null,"description":null,"links":[]}],"start_time":"2023-12-29T17:35:00.000+01:00","end_time":"2023-12-29T18:15:00.000+01:00","room":{"name":"Saal Zuse","id":473}},{"id":11874,"guid":"7a997ece-3479-444f-b030-71912cd0b9fd","title":"Einführung in Smartphone Malware Forensik","subtitle":"Wie man Stalkerware und Staatstrojaner auf Smartphones finden kann","description":"Die Qualität von Anleitungen und Einführungen zu Smartphone-Forensik im Internet ist leider sehr durchwachsen: Hier will dir jemand ein buntes Tool verkaufen, hier riecht es nach einem Scam, vielerorts geht es um das, was Strafverfolgungsbehörden machen, nämlich in den Daten fremder Leute wühlen.\r\n\r\nStattdessen möchten wir in diesem Vortrag einen strukturierten Überblick geben, welche (öffentlichen) Möglichkeiten es in der einvernehmlichen Smartphone-Forensik mit Open-Source-Tools gibt. Wir zeigen euch, wie man welche Arten von Malware finden kann, welche Spuren sie hinterlassen und wie sich Stalkerware und Staatstrojaner in der Praxis unterscheiden.","duration":3600,"logo":null,"type":"lecture","do_not_record":false,"track":"Security","abstract":"Smartphones sind in den letzten zehn Jahren zu einem allseits beliebten Angriffsziel geworden, sei es für Stalkerware, Staatstrojaner oder Banking-Malware. In diesem Vortrag wollen wir einen Überblick geben, mit welchen Techniken und Open-Source-Tools man auf Smartphones (unter iOS und Android) auf die Jagd nach Malware gehen kann. Im Anschluss findet ein Workshop mit einem praktischen Teil zum Ausprobieren einiger dieser Techniken statt.","speakers":[{"guid":"878c9dd0-6965-5723-a325-ad8bb7d08be0","id":19149,"image":null,"name":"Viktor Schlüter","public_name":"Viktor Schlüter","abstract":"Hunting Spyware at the Digital Security Lab from Reporters without Borders","description":null,"links":[]},{"guid":"b0bcb45e-cb8f-557b-9c2f-da89049a2cff","id":18961,"image":null,"name":"Janik Besendorf","public_name":"Janik Besendorf","abstract":null,"description":null,"links":[]}],"start_time":"2023-12-29T12:15:00.000+01:00","end_time":"2023-12-29T13:15:00.000+01:00","room":{"name":"Saal Grace","id":472}},{"id":12182,"guid":"a9f690f3-e01a-4644-aa15-4276da6879ff","title":"Euclid – das neue Weltraumteleskop","subtitle":"Mit Milliarden leuchtenden Galaxien den dunklen Teil des Kosmos verstehen","description":"Die Astronomie weiß aktuell von 95 % der Energie und Masse im Universum nicht, woraus sie bestehen. Neben 5 % „normaler“ Materie (Sterne, Gas, die Erde, CCC-Kongressteilnehmer*innen, …) gibt es mindestens fünfmal so viel so genannte dunkle Materie und darüberhinaus sind die restlichen 70 % das, was dunkle Energie genannt wird. Bei beidem wissen wir bislang nicht, woraus sie bestehen – wir kennen nur deren Wirkung! Galaxien rotieren anders, als sie es nur mit normaler Materie tun würden. Und das Universum expandiert – seit dem Urknall – aber die Expansionsgeschwindigkeit nimmt zu und nicht ab, wie von anziehender Materie zu erwarten wäre. Irgendwas drückt den Raum an sich auseinander.\r\n\r\nEuclid ist ein Teleskop, eine Mission und ein Konsortium aus mehreren tausend Menschen, von denen viele seit ca. 2008 an den Ideen zu dieser Mission arbeiten, viele hundert an der Planung und dem Bau zweier hoch empfindlicher Kameras mit insgesamt knapp 700 Millionen Pixel und jetzt ein- bis zweitausend Interessierten, welche die bald erwarteten wissenschaftlichen Bilder auswerten wollen.\r\n\r\nIch möchte die Ziele erläutern, wie man aus der Vermessung der Form von Galaxien unsichtbare dunkle Materie im Vordergrund aufspürt („schwacher Gravitationslinseneffekt“) und warum es einen „kosmischen Längenmaßstab“ gibt, mit dem man die Ausdehnung des Universums über zehn Milliarden Jahre in der Vergangenheit vermessen kann.\r\n\r\nSchließlich möchte ich die ersten fünf Bilder zeigen, die von Euclid aufgenommen und von der ESA im November veröffentlicht wurden – und warum in denen so viel mehr drinsteckt, als man auf einem Computermonitor so sieht.","duration":2400,"logo":null,"type":"lecture","do_not_record":false,"track":"Science","abstract":"„Euclid\" ist ein neues Weltraumteleskop der Europäischen Weltraumbehörde mit Beteiligungen eines Wissenschaftskonsortiums aus vierzehn europäischen Ländern, den USA, Kanada und Japan. Euclid wurde am 1. Juli 2023 gestartet und beginnt bis Ende des Jahres seine auf 6 Jahre geplante wissenschaftliche Himmelsdurchmusterung. Euclid wird mit seinem Spiegel von 1,20 m Durchmesser und seinen zwei Kameras Bilder und Spektren von einem Drittel des gesamten Himmels aufnehmen. Das Ziel: mit der genauen Vermessung von insgesamt zwei Milliarden Galaxien der Natur von „Dunkler Materie\" und „Dunkler Energie\" im Universum auf den Grund zu gehen – die zwar zusammen 95 % der Gesamtenergie ausmachen, von denen wir aber nicht wissen, was sie sind und woraus sie bestehen. Euclid hat im November erste spektakuläre Bilder veröffentlicht. Ich werde die Mission vorstellen, die wissenschaftlichen Ziele, die Methoden und darauf eingehen, was in den 25 Jahren von Idee über Teleskop zu wissenschaftlicher Erkenntnis so alles zu erledigen war und ist.","speakers":[{"guid":"f0aa6787-ec56-5764-8aa5-aa79705572f9","id":19429,"image":null,"name":"Knud Jahnke","public_name":"Knud Jahnke","email":"knud@amoebius.org","abstract":"Astrophysicist, interested in galaxies, black holes, as well as urbanism and human powered vehicles.","description":null,"links":[{"url":"https://mastodon.social/@knud","title":"Mastodon"}]}],"start_time":"2023-12-27T23:00:00.000+01:00","end_time":"2023-12-27T23:40:00.000+01:00","room":{"name":"Saal Zuse","id":473}},{"id":12100,"guid":"7fc0bc43-f863-42fc-b5ae-cfee4a2499ff","title":"Öffnet eure Spaces für Gehörlose!","subtitle":"Wie wir den CCC Wien und das Metalab für Gehörlose zugänglich gemacht haben.","description":"Hackspaces sind für Gehörlose nicht zugänglich, um ihre Kreativität auszuleben sowie nachhaltige Techniknutzung eigenständig zu erlernen.\r\n\r\nDas wissenschaftlich-künstlerische Projekt MACH’S AUF! setzt seinen Fokus auf die folgenden Fragen:\r\n\r\n\u003cul\u003e\r\n\u003cli\u003eWie kann Technik gestaltet sein, damit sie besser von gehörlosen Menschen genutzt werden kann?\u003c/li\u003e\r\n\u003cli\u003eWie kann eine Zusammenarbeit zwischen Gehörlosen und Hörenden funktionieren?\u003c/li\u003e\r\n\u003cli\u003eWie können Barrieren abgebaut werden, ohne dass gesellschaftliche Randgruppen davon benachteiligt werden?\u003c/li\u003e\r\n\u003c/ul\u003e\r\n\r\nIn den letzten zwei Jahren haben Oliver \"fussel\" Suchanek (es/ihm) und Franz \"Stoni\" Steinbrecher (er/ihm) viel Zeit, Aufwand und Sorgfalt in diverse Veranstaltungen, Workshops und Aufklärung gesteckt. Ermöglicht wurde das durch die finanzielle Unterstützung vom Chaos Computer Club.\r\n\r\nDas Ergebnis kann sich sehen lassen:\r\n\r\nEine neue Community, in der Hörende und Gehörlose gemeinsam hacken, in der Gehörlose Maschinen bedienen, die vorher unzugänglich waren, und auch ganz neue Projekte wie zum Beispiel die ÖGS-Suchmaschine (http://suche.machs-auf.at/search).\r\n\r\nÜber die Arbeit der ersten zwei Jahre wird Oliver \"fussel\" Suchanek berichten, so dass ihr unsere Ansätze auch in anderen Spaces anwenden könnt.\r\n\r\nSeid gespannt auf den Einblick … :)","duration":2400,"logo":"/system/events/logos/000/012/100/original/light.png?1699712226","type":"lecture","do_not_record":false,"track":"CCC","abstract":"Hacken geht auch ohne Ohren! In den letzten zwei Jahren haben wir am lebenden Objekt erforscht, wie man Hackspaces für Gehörlose öffnen kann, so dass wir alle gemeinsam an Projekten arbeiten und cooles Zeug bauen können. Kommt vorbei, schaut/lauscht, und nehmt was mit nach Hause!\r\n\r\nDer Vortrag wird in der Österreichischen Gebärdensprache (ÖGS) gehalten und simultan zu Deutsch übersetzt (bzw. andersherum für Fragen).\r\n","speakers":[{"guid":"829aef72-0128-575a-8623-7d23be7e2879","id":12782,"image":"/system/people/avatars/000/012/782/original/39f09f65041e5887.png?1605877513","name":"Oliver 'fussel' Suchanek","public_name":"Oliver 'fussel' Suchanek","abstract":"Oliver Jayden Suchanek, aka lavolsky oder auch bekannt als \"fussel\", ist angehender akademischer Künstler*in (studiert an der Universität für Angewandte Kunst Wien) mit Schwerpunkt auf Kuration und Material und beschäftigt sich mit Themen wie Gender und Deaf Studies.\r\n\r\nPronomen sind (es, they/them).\r\n\r\nMastodon: @lavolsky@chaos.social sowie auch @mach_auf@chaos.social","description":null,"links":[]}],"start_time":"2023-12-30T15:45:00.000+01:00","end_time":"2023-12-30T16:25:00.000+01:00","room":{"name":"Saal Zuse","id":473}},{"id":11919,"guid":"e25b8bc3-6104-4c36-9c85-15b9d4151cb7","title":"Finding Vulnerabilities in Internet-Connected Devices","subtitle":"A Beginner’s Guide","description":"In this introductory session we will journey into the field of internet-connected device security. Our talk aims to empower beginners by simplifying the process of hacking such devices.\r\n\r\nWe'll discuss vulnerabilities we uncovered in Poly telephones and conference speaker systems and describe how we effectively transformed a seemingly innocuous conference speaker into a fully functional wiretap. We'll begin with straightforward findings accessible to beginners and progress to more technical discoveries, so that people with no experience in the field can follow along, too.\r\n\r\nBy the end of the talk, the attendees will have a foundational understanding of how they can approach hacking such a device and will have learned how the impact of vulnerabilities can be shown and increased by chaining them.\r\n\r\nAll the vulnerabilities we discovered during our research have been responsibly disclosed to the vendor and will be published in December 2023.","duration":3600,"logo":null,"type":"lecture","do_not_record":false,"track":"Security","abstract":"This introductory session will outline the process of hacking internet-connected devices, with the help of a real world example: Poly telephones and conference speaker systems. We will explain vulnerabilities we identified in them and how they can be leveraged to transform the devices into wiretaps.","speakers":[{"guid":"7929aa6a-fbf8-5550-8c26-d778c126c7c4","id":19226,"image":"/system/people/avatars/000/019/226/original/20231126_163528_klein.jpg?1701674838","name":"Pascal Zenker","public_name":"Pascal Zenker","email":"pascal.zenker@modzero.com","abstract":"Pascal is a Berlin-based hacker working at modzero, where his focus encompasses web security, red teaming, and various complex pentests.","description":null,"links":[{"url":"https://twitter.com/parzel2","title":"X / Twitter"},{"url":"https://bsky.app/profile/parzel.bsky.social","title":"BSky"}]},{"guid":"ee72d242-b39e-5fe7-8184-e025ee0844b9","id":19253,"image":null,"name":"Christoph Wolff","public_name":"Christoph Wolff","abstract":"Christoph is a hacker based in Berlin. In his role as IT-Security Analyst at modzero he regularly assesses the security of web and mobile applications, as well as Internet-connected devices.","description":null,"links":[]}],"start_time":"2023-12-29T14:45:00.000+01:00","end_time":"2023-12-29T15:45:00.000+01:00","room":{"name":"Saal Grace","id":472}},{"id":11933,"guid":"f05ac86f-96bd-4888-908b-11742b381074","title":"Fnord-Jahresrückblick-Rückblick","subtitle":"20 Jahre Fnord-Jahresrückblick!","description":null,"duration":5400,"logo":null,"type":"performance","do_not_record":false,"track":"Entertainment","abstract":"In einer sich zunehmend bizarr anfühlenden Welt bringt der Fnord-Rückblick Struktur, verteilt renommierte Awards und sucht nach den leichteren Momenten in der allgemeinen Flut aus schlechten Nachrichten.\r\n\r\nWir feiern dieses Jahr unser 20. Jubiläum, daher werden wir etwas weiter zurückblicken.","speakers":[{"guid":"5f0597bc-861b-53a7-b175-6e348331a9ab","id":1621,"image":"/system/people/avatars/000/001/621/original/Bildschirmfoto_2013-12-03_um_18.02.55.png?1386116185","name":"Fefe","public_name":"Fefe","abstract":"Hängt seit gefühlt 1980 jedes Jahr beim Chaos Communication Congress herum, hält gelegentlich Vorträge. Betreibt ein Blog (Link siehe unten).","description":"Eigentlich ganz umgänglich. Jedenfalls umgänglicher als man so denken würde. Ausnahmen bestätigen die Regel.","links":[{"url":"http://www.fefe.de/","title":"Fefes Homepage"},{"url":"http://blog.fefe.de/","title":"Fefes Blog"}]},{"guid":"a0a13e2f-44e9-5515-ae0e-e29757c45310","id":1633,"image":"/system/people/avatars/000/001/633/original/9.jpg?1360200570","name":"frank","public_name":"frank","abstract":"Spokesperson of the Chaos Computer Club and expert on secure communications","description":null,"links":[{"url":"https://duckduckgo.com/?q=frank+rieger+ccc","title":"everything you need to know"},{"url":"http://frank.geekheim.de/","title":"blog"}]}],"start_time":"2023-12-29T00:35:00.000+01:00","end_time":"2023-12-29T02:05:00.000+01:00","room":{"name":"Saal 1","id":471}},{"id":12019,"guid":"554cc933-93c7-4c47-8570-016fe5285605","title":"Fortbildung Cyber-Astrologie \u0026 KI-Karma","subtitle":"- Mit Teilnahmeurkunde zum Selbstausdrucken","description":"In diesem kostenlosen Basis-Seminar werden Dir die wichtigsten Skills zur Erbringung ganzheitlicher Digital-Spiritualitäts-Dienstleistungen vermittelt, mit denen Du direkt in die Selbstständigkeit durchstarten kannst. Wir lernen von den Besten – wir lernen vom Esoterik-Markt, der ja bekanntlich nicht erst seit der Crosspromotion in einschlägigen Corona-Telegram-Gruppen boomt:\r\n\r\n\u003col\u003e\r\n\u003cli\u003eDigital Forecasting: Warum umständliche Modelle konzipieren, wenn Du den direkten Zugriff auf die Akasha-Datenbank der Weltweisheit verkaufen kannst? In diesem Block geht es um die wichtigsten Wahrsager-Skills (Cold Reading, Hot Reading, Barnum-Effekt).\u003c/li\u003e\r\n\u003cli\u003eHealing statt Patching: Anwendung ganzheitlich-spiritueller Security-Konzepte auf homöopathischer Basis für Kundennetzwerke mit Schwerpunkt auf dem souveränen Umgang mit Beschwerden \u0026 Erstverschlimmerungen.\u003c/li\u003e\r\n\u003cli\u003eBelebte Netzwerke: Lehren aus der Wasserbelebung \u0026 kompatible Geschäftsideen („Serverraum der Neuen Zeit“, Manifestieren von RAM, KI-Karma)\u003c/li\u003e\r\n\u003cli\u003eMental-Antivirus: Installationsanleitung für feinstoffliche Unterstützungssoftware zur Ego-Mitigation (thought terminating cliches, Conspiracy \u0026 Cult-Groupware as a Service)\u003c/li\u003e\r\n\u003cli\u003eUpscaling: Innovative Pyramiden- und Schneeballsysteme zwecks ganzheitlicher Gewinnabschöpfung.\u003c/li\u003e\r\n\u003c/ol\u003e\r\n\r\nMelden Sie sich jetzt für das KOSTENLOSE Basis-Seminar an, und Sie bekommen (wenn die Speicherblöcke günstig stehen) unseren limitierten feinschwingenden 5G-Sticker für ihr EDV-Gerät GRATIS dazu. \r\n\r\n+++ von unabhängigen Cyber-Schamaninnen empfohlen +++\r\n\r\nBild: Charlotte von Hirsch","duration":2400,"logo":"/system/events/logos/000/012/019/original/katta_aluhut_klein-673x1024.jpg?1699634637","type":"lecture","do_not_record":false,"track":"Ethics, Politics \u0026 Society","abstract":"Dass es sich bei Digitalisierung um eine magische Angelegenheit handelt, der durch Regulierung großer Social-Media-Konzerne per Definition nicht beizukommen ist, ist auf politischer Ebene schon lange bekannt. Der Markt für esoterische Dienstleistungen rund um Digitalisierungsfragen ist daher vermutlich immens – und eröffnet viele Möglichkeiten für cyberfeinstofflich begabte Entrepreneurs \u0026 Digital-Okkultisten. Ganz nebenbei lernen wir, welche Maschen unseriöse Akteure (auch jenseits der Eso-Szene) anwenden, um mit den Sorgen und Ängsten von Menschen Geld zu machen.","speakers":[{"guid":"a8991e85-b553-5ed0-bc66-c219d3d8ba2f","id":8662,"image":"/system/people/avatars/000/008/662/original/Katta_Quadrat.png?1539638331","name":"Katharina Nocun","public_name":"Katharina Nocun","abstract":"Katharina Nocun ist Publizistin und Autorin mehrerer Bücher. ","description":"Sie hat Politics, Economics \u0026 Philosophy (M.Sc.) an der Uni Hamburg studiert. Ihre Abschlussarbeit beschäftigte sich mit Markteintrittshürden für dezentrale Soziale Netzwerke. In ihrer Arbeit setzt sie sich vor allem mit dem Spannungsfeld Digitalisierung und Demokratie auseinander. Ihr Podcast Denkangebot war 2020 für den Grimme Online Award nominiert. Ihr erstes Buch \"Die Daten, die ich rief\" (2018) behandelt das Thema Datensammlungen von Staat und Konzernen. 2020 folgte der Bestseller \"Fake Facts – Wie Verschwörungstheorien unser Denken bestimmen\" (gemeinsam mit Pia Lamberty). Im Mai 2021 erschien das zweite gemeinsame Buch \"True Facts – was gegen Verschwörungserzählungen wirklich hilft\" und im September 2022 das dritte gemeinsame Werk \"Gefährlicher Glaube – Die radikale Gedankenwelt der Esoterik\".","links":[{"url":"https://www.kattascha.de","title":"Blog"},{"url":"https://twitter.com/kattascha","title":"Twitter"},{"url":"https://chaos.social/@kattascha","title":"Mastodon"},{"url":"https://www.denkangebot.org/","title":"Podcast Denkangebot"}]}],"start_time":"2023-12-27T22:05:00.000+01:00","end_time":"2023-12-27T22:45:00.000+01:00","room":{"name":"Saal Grace","id":472}},{"id":12296,"guid":"670321a9-75f4-4194-867d-a249aa01af0b","title":"Full AACSess: Exposing and exploiting AACSv2 UHD DRM for your viewing pleasure","subtitle":null,"description":"The Advanced Access Content System (AACS) is a DRM scheme used to safeguard audio and visual content, particularly in high-definition formats like HD-DVD and Blu-ray. First introduced in 2005 following the failure of the Content Scramble System (CSS) used in DVDs, AACS was designed to be not only secure against regular piracy, but included multiple features intended to restrict the impact of a potential leak of cryptographic material such as revocation lists and traitor-tracing. The concepts and algorithms of AACS were described in a publicly-released whitepaper, relying on strong cryptography and secrecy of keys to maintain security. Unsurprisingly, less than a year after publication, the first unlicensed decryption tool was demonstrated using keys reverse-engineered from a software player binary. While AACS-LA was quick to revoke those keys, a cat-and-mouse game emerged with new keys being regularly extracted from sources such as software updates and PS3 firmware.\r\n\r\nWith AACS effectively broken and easily bypassed as described in Eckersley’s 24c3 presentation, AACS-LA would announce the introduction of AACSv2 for the next generation 4K UHD Blu-ray discs. This time, however, AACS-LA would not release the specifications of the DRM publicly, requiring strict NDAs for implementers and increased software/hardware security measures. Most notably, playback of legitimately purchased UHD-BDs on PC requires Cyberlink PowerDVD software running on Windows 10 and an SGX-capable 7th-10th generation Intel CPU. Since the DRM would run exclusively in the SGX secure enclave, no further information about its inner workings or vulnerabilities would be discovered publicly, until now.\r\n\r\nIn this presentation, we explore the security system of AACSv2 DRM and the Intel SGX trusted execution environment. We first analyze the principles of SGX and its promises of an isolated environment, protected from all software running on the machine. We also investigate the use of SGX local and remote attestation primitives intended to verify the integrity and confidentiality of AACSv2 key material and DRM code, and why it has resisted outside analysis for so many years. We then discover how hardware side-channel attacks can be used to undermine these guarantees of SGX, and craft an effective exploit to extract cryptographic material from the enclave and defeat the DRM code obfuscation.\r\n\r\nFollowing that, we present the first public description of the inner workings of AACSv2, the key derivation process, and the updated revocation and traitor-tracing mechanisms. We studied  BIOS updates from six motherboard vendors to show how SGX can be broken both easily and cheaply, and that vendors are now faced with a decision of security vs. usability in trusting unpatched machines. Finally, we conclude with the first demonstration of a UHD Blu-ray disc being decrypted and played back on a non-official platform.","duration":3600,"logo":null,"type":"lecture","do_not_record":false,"track":"Security","abstract":"Following the failure and easy exploitation of the AACSv1 DRM on HD-DVD and Blu-ray, AACS-LA went back to the drawing board and announced the next generation AACSv2 DRM scheme, launching alongside 4K UHD Blu-ray in 2015. Since then, nearly no information has come out publicly about any vulnerabilities or even the algorithms themselves, owing in large part to software players requiring the use of Intel SGX secure enclave technology, which promises integrity and confidentiality of AACSv2 code and data through local and remote attestation mechanisms. Join us as we explore the broken history of AACS, describe practical side-channel attacks against SGX, and present the first look into the inner workings of AACSv2 DRM, culminating in a demonstration of the first full compromise of AACSv2 and unofficial playback of a UHD-BD disc.","speakers":[{"guid":"7828a43a-900c-5b93-bfed-33eefaa85be6","id":19300,"image":null,"name":"Adam Batori","public_name":"Adam Batori","abstract":null,"description":null,"links":[]}],"start_time":"2023-12-29T13:30:00.000+01:00","end_time":"2023-12-29T14:30:00.000+01:00","room":{"name":"Saal Zuse","id":473}},{"id":12102,"guid":"847c9f2d-8e3d-4c68-8c82-3435fae34dd0","title":"Fuzz Everything, Everywhere, All at Once","subtitle":"Advanced QEMU-based fuzzing","description":"\u003cp\u003eIn this talk, the maintainers of the AFLplusplus organization present the QEMU-based instrumentation engines developed as part of AFL++ and LibAFL to fuzz advanced binary-only targets. We discuss our extensions to QEMU, the well-known emulator, to allow high-performance, cross-architecture fuzzing and target instrumentation. Finally, we demo a proof of concept using AFL++ to find injection vulnerabilities in the binaries, going beyond the typical fuzzing for memory corruptions.\u003c/p\u003e\r\n\r\n\u003cp\u003eWe then present LibAFL QEMU, a library that offers convenient APIs to hook the target using Rust. Unlike other public fuzzers, tools built with LibAFL can scale over cores and machines to find vulnerabilities faster and at a large scale. We also showcase how we built a custom fuzzer for a binary-only Android library using this new emulator API for fuzzing that scales to 96 cores almost linearly, reaching a whopping number of executions per second!\u003c/p\u003e","duration":2400,"logo":"/system/events/logos/000/012/102/original/libafl_logo_transparent_shirt.png?1701607910","type":"lecture","do_not_record":false,"track":"Security","abstract":"The maintainers of the AFLplusplus open-source project show crazy new ways to (ab)use QEMU to explore difficult, binary-only targets through fuzzing.\r\n\r\nWe present a proof of concept using AFL++ and QEMU to find command and SQL-injections, going beyond the classic fuzzing for memory corruption.\r\n\r\nWe also present a scalable approach to fuzzing binary-only code with LibAFL and QEMU, showcasing how to build a custom fuzzer to test Android libraries without using a phone.","speakers":[{"guid":"953dac36-6f96-50ed-9795-9b081b09257b","id":8453,"image":"/system/people/avatars/000/008/453/original/L6dqH-d3_400x400_(1).jpg?1699702039","name":"domenukk","public_name":"domenukk","email":"mail@dmnk.co","abstract":"Dominik Maier is part of the AFLplusplus project, and works connectivity security for the largest smartphone OS.","description":"Dominik Maier is part of the AFLplusplus project, that maintains afl++ and LibAFL.\r\nHe worked on Fuzzing during his PhD at TU Berlin and currently works on connectivity security for the largest smartphone OS. In his spare-time, he likes to travel and participate in CTFs with ENOFLAG.","links":[]},{"guid":"7cdd2a39-a7ae-58fb-b351-833637d5687f","id":4284,"image":"/system/people/avatars/000/004/284/original/IMG_5988.jpeg?1699713653","name":"van Hauser","public_name":"van Hauser","email":"vh@thc.org","abstract":"Old school hacker, founder of The Hacker’s Choice and AFLplusplus, author of many tools eg hydra, thc-ipv6, AFL++, amap, THC-scan etc.","description":null,"links":[{"url":"https://www.thc.org","title":"The Hacker’s Choice"},{"url":"https://www.github.com/vanhauser-thc","title":"Github"}]},{"guid":"7520147f-5029-5e32-852f-665764facc6b","id":19393,"image":null,"name":"Dongjia Zhang","public_name":"Dongjia Zhang","abstract":null,"description":null,"links":[]},{"guid":"9886a24e-56c0-5376-be3a-d23221a85878","id":9539,"image":null,"name":"andreafioraldi","public_name":"andreafioraldi","email":"andreafioraldi@gmail.com","abstract":"Andrea Fioraldi is currently a Ph.D. student in the Software and Systems Security group of EURECOM. He is working on new methodologies to improve the effectiveness of security vulnerability discovery techniques such as Fuzz Testing. He is part of the core development team of AFL++, one of the most used fuzzers in industry and academia, and developer of the LibAFL fuzzing framework, the future Rust backbone of AFL++.\r\n\r\n","description":null,"links":[{"url":"https://twitter.com/andreafioraldi","title":"Twitter"},{"url":"https://github.com/andreafioraldi","title":"GitHub"}]},{"guid":"c31dbc3a-ac58-5b60-bc1a-8384d7cdbb31","id":19411,"image":null,"name":"Addison Crump","public_name":"Addison Crump","abstract":null,"description":null,"links":[]}],"start_time":"2023-12-28T13:50:00.000+01:00","end_time":"2023-12-28T14:30:00.000+01:00","room":{"name":"Saal 1","id":471}},{"id":12235,"guid":"45057d82-26a3-40c9-8b94-c8631a0026f0","title":"Fuzzing the TCP/IP stack","subtitle":"beyond the trivial","description":"Our exploration begins with an honest appraisal of traditional fuzzing methodologies that have been applied to TCP/IP stacks before, like ISIC, revealing their inherent limitations, e.g., they can't reach beyond the TCP initial state. Recognizing the need for a more evolved approach, we take a different approach, where we leverage a full-blow active network connection for fuzzing. A key revelation in this journey is the deliberate decision to sidestep the arduous task of constructing a custom TCP/IP stack, a choice rooted in practical considerations.\r\n\r\nThe reluctance to build a bespoke TCP/IP stack leads us to innovative strategies such as embedding hooks in the Linux kernel and tapping into userland TCP/IP stacks like PyTCP, Netstack (part of Google gVisor), and PicoTCP. PicoTCP takes center stage, offering a userland TCP/IP stack that becomes integral to our state fuzzing methodology. Attendees will gain a deeper understanding of its architecture, APIs, and documentation, appreciating its pivotal role in fortifying network security.\r\n\r\nAs the presentation unfolds, we navigate through the development of a powerful fuzzer, a core element in our approach to identifying vulnerabilities within the TCP/IP stack. The intricacies of driving traffic through the system, simulating real-world scenarios, and leveraging reproducibility and diagnostics techniques are revealed. The discussion expands to showcase tangible results, including trophies obtained, bugs reported, and the eventual release of the project on GitHub. The session concludes with an engaging Q \u0026 A, encouraging participants to delve into the intricacies of TCP/IP stack fuzzing and its profound implications for network security.","duration":2400,"logo":null,"type":"lecture","do_not_record":false,"track":"Security","abstract":"In this talk, we delve into the captivating realm of TCP/IP stack fuzzing. As the backbone of internet communication, the TCP/IP stack is a prime target for cyber threats. This presentation will unravel the intricacies of fuzzing techniques applied to several TCP/IP stacks, shedding light on how these methodologies can uncover bugs, crashes and vulnerabilities. From the fundamentals of packet fuzzing to advanced mutation strategies, attendees will gain valuable insights into the proactive ways to fuzz a TCP/IP stack. Whether you're a seasoned cybersecurity professional or a curious enthusiast, this talk promises to be an enlightening journey into the heart of TCP/IP stack security and the crucial role of fuzzing in safeguarding our interconnected world.","speakers":[{"guid":"54c798dc-2407-5ae3-95af-18d146b9f0c4","id":821,"image":"/system/people/avatars/000/000/821/original/50.jpg?1360200407","name":"Ilja van Sprundel","public_name":"Ilja van Sprundel","abstract":"Ilja van Sprundel is a security researcher that loves to find out new things.","description":"He’s currently employed by a company called IOActive where he gets to play with all sorts of weird and exciting security technologies.","links":[]}],"start_time":"2023-12-29T12:00:00.000+01:00","end_time":"2023-12-29T12:40:00.000+01:00","room":{"name":"Saal 1","id":471}},{"id":12094,"guid":"56ec1042-ef0f-4f11-89d2-ee99e34a3411","title":"Gemeinsam gegen rechten Terror! Aber wie?","subtitle":"Vortrag und Lesung","description":"Das bundesweite antifaschistische Bündnis NSU-Watch hat im Sommer 2023 sein Buch „Aufklären und Einmischen. Der NSU-Komplex und der Münchener Prozess“ in der erweiterten Neuauflage herausgebracht. Es gibt einen Überblick über die bisherige Aufarbeitung des NSU-Komplexes. Auf dieser Grundlage wollen Vortrag und Lesung fragen: Was können nächste Schritte sein? Wie können wir rechten Terror verhindern? Die Antworten sind vielfältig und warten teilweise noch darauf, entdeckt zu werden. Und trotzdem bleibt die Gefahr rechten Terrors hoch, auch weil auf staatlicher, behördlicher und gesellschaftlicher Seite Konsequenzen noch ausstehen. Doch wir wissen bereits jetzt genug, um rechtem Terror aktiv entgegenzuwirken. ","duration":3600,"logo":"/system/events/logos/000/012/094/original/logo-quadrat-vector.jpg?1699710735","type":"lecture","do_not_record":false,"track":"Ethics, Politics \u0026 Society","abstract":"Die zwölf Jahre seit der Selbstenttarnung des NSU haben gezeigt, dass auf den Staat bei der Aufklärung und Aufarbeitung von rechtem Terror kein Verlass ist. Deshalb haben Betroffene von rechter Gewalt, Antifaschist*innen und Zivilgesellschaft diese Aufgabe wieder und wieder selbst in die Hand genommen. Die daraus gewonnenen Analysen, die Aufklärung und die entstandenen solidarischen Netzwerke sind vielfältiger, als sich viele am Anfang vorgestellt haben. Doch wir wollen fragen: Was können nächste Schritte sein? Wie können wir rechten Terror verhindern?","speakers":[{"guid":"f0056200-e010-571e-8a87-3558d7155073","id":8543,"image":"/system/people/avatars/000/008/543/original/logo-quadrat-vector.jpg?1539600598","name":"Caro Keller (NSU-Watch)","public_name":"Caro Keller (NSU-Watch)","abstract":"Seit 2013 bin ich Teil des antifaschistischen Bündnisses NSU-Watch, seit Ende 2016 dort auch Redakteurin, verantwortlich u.a. für Website- und Social Media Output. \r\n","description":"Die rassistische Mordserie des »Nationalsoziaistischen Untergrunds« (NSU) markiert eine Zäsur in der bundesrepublikanischen Geschichte. Die Taten des NSU, sein Netzwerk und die Rolle der Behörden sind auch nach dem Ende des Münchener NSU-Strafprozesses längst nicht aufgeklärt.\r\n\r\nNSU-Watch wird von einem Bündnis aus rund einem Dutzend antifaschistischer und antirassistischer Gruppen und Einzelpersonen aus dem ganzen Bundesgebiet getragen, die seit über einem Jahrzehnt zum Themenkomplex arbeiten.\r\n\r\nVon 2013 bis 2018 war der Kern der Arbeit von NSU-Watch die Beobachtung des Prozesses in München. An jedem der 438 Verhandlungstage waren wir im Gerichtssaal dabei. Wir berichteten via Social Media und erstellten detaillierte Protokolle. Darüber hinaus war und ist die Beobachtung von Parlamentarischen Untersuchungsausschüsse zum NSU-Komplex zentraler Bestandteil unserer Arbeit. Hierzu bildeten sich in mehreren Bundesländern regionale NSU-Watch-Gruppen. Im Jahr 2020 veröffentlichten wir unser Buch „Aufklären und Einmischen. Der NSU-Komplex und der Münchener Prozess“, das 2023 in einer erweiterten Neuauflage erschien.\r\n\r\nRassismus, Antisemitismus und rechte Gewalt sind auch nach der Zäsur, die der NSU-Komplex war, virulent. Das rassistische Attentat am Münchener Olympia-Einkaufszentrum 2016, der Mord an Walter Lübcke 2019, der antisemitische, rassistische und misogyne Anschlag in Halle 2019 und das rassistische Attentat in Hanau 2020 belegen dies auf besonders traurige Weise.\r\n\r\nDeshalb macht NSU-Watch weiter! Wir schauen dem Staat bei seinen Aufklärungsversuchen weiter auf die Finger, wir dokumentieren, recherchieren und intervenieren weiter. Wichtige Instrumente dafür sind unsere Social-Media-Kanäle und der seit 2018 regelmäßig erscheinende Podcast „Aufklären \u0026 Einmischen“.\r\n\r\nNeben der Beobachtung von Strafprozessen und Untersuchungsausschüssen ist die Vermittlung von Wissen über Neonazis, den NSU-Komplex und rechten Terror eine wichtige Aufgabe von NSU-Watch. NSU-Watch als Projekt von antifaschistischen und antirassistischen (Recherche-) Gruppen hat Zugang zu umfangreichem Wissen über die neonazistische Szene, die im NSU involvierten Strukturen und weitere Strukturen rechten Terrors. Wir vernetzen kompetente antifaschistische Projekte und Einzelpersonen – auch mit Anwält*innen der Nebenklage – und erarbeiten gemeinsame Einschätzungen und Expertisen.","links":[{"url":"nsu-watch.info","title":"NSU-Watch"}]}],"start_time":"2023-12-29T20:30:00.000+01:00","end_time":"2023-12-29T21:30:00.000+01:00","room":{"name":"Saal Zuse","id":473}},{"id":12306,"guid":"fc46c82b-1b0d-4a96-bc5e-03bd3de2a6cf","title":"Gläserne Geflüchtete","subtitle":"Mit Computern das Leben zum Schlechteren verändern","description":"In der Hackerethik steht: „Computer können dein Leben zum Besseren verändern.\" Aber viel zu oft werden sie für das Gegenteil genutzt. Vor allem im Bereich der digitalisierten Migrationskontrolle.\r\n\r\nMit dabei: das Ausländerzentralregister, eines der größten automatisierten Register der öffentlichen Verwaltung; die Idee für digitale Bezahlkarten, die mehr Freiheitsbeschränkung sind als Zahlungsmittel; die üblichen Verdächtigen unter den BAMF-IT-Assistenzsystemen; Vorhersage-Systeme für Migrationsbewegungen; die digitale Festung Europa. Und ganz neu: das Schneller-Abschieben- und das Datenübermittlungsvorschriftenanpassungsgesetz.\r\n\r\nDie aktuelle Bundesregierung macht munter dabei mit, ihre digitalen Kontrollhelfer weiter auszuweiten. Und fast niemand schaut hin.","duration":3600,"logo":null,"type":"lecture","do_not_record":false,"track":"Ethics, Politics \u0026 Society","abstract":"Digitale Bezahlkarten, Migrationsvorhersage mit sogenannter KI, digitalisierte Grenzen zur Festung Europa und immer mehr davon. Ein Überblick, wie Digitalisierung jenseits des öffentlichen Aufschreis genutzt wird, um den Pull-Faktor Menschlichkeit zu drücken.","speakers":[{"guid":"1bf69109-efa8-5af2-9b1b-97a9cdc672dc","id":4465,"image":null,"name":"Anna Biselli","public_name":"Anna Biselli","abstract":"Tagsüber Journalistin, abends feiner Fug.","description":null,"links":[]}],"start_time":"2023-12-29T17:15:00.000+01:00","end_time":"2023-12-29T18:15:00.000+01:00","room":{"name":"Saal Grace","id":472}},{"id":11959,"guid":"ca025234-f091-4669-b95e-f62437837737","title":"Gut feelings: Can we optimize lifestyle, diet and medication according to our respective microbiota?","subtitle":null,"description":"Despite our best efforts of finding the perfect regimen of diet, exercise and medication to keep any person fit and healthy, outcomes for different people vary widely for all of these measures, even when we comply with them fully. Some of this traces to our individual genetics, which remains difficult to change, but another source of variation in responses may come from differences between our gut microbiomes.\r\n\r\nHuman bodies are not sterile, and our skin, our mucosal surfaces and, in particular, our intestines are home to many more bacteria than there are human cells in our bodies, representing hundreds of different species in each person. These microbial ecosystems, or microbiomes, are found in all animals and have coevolved with their hosts. Therefore we rely on commensal (\"friendly\") bacteria for many functions, including breaking down nutrients, converting some medications into their active forms, producing certain crucial compounds for us from our diet, and helping our immune systems mature and remain tuned. The microbiota also contains temporary visitors and both transient and resident opportunistic pathogens, often kept in check by the immune system and by the commensals, but sometimes escaping such control to multiply and cause disease. Human gut microbiomes begin establishing at birth and evolve over a lifetime, but remain quite stable within each person throughout adulthood unless something serious like repeated antibiotic cures disrupt them. However, they can differ quite substantially between individuals as well as between populations, reflecting factors such as nutrition and environmental exposures.\r\n\r\nIt has been proposed, and to a degree already demonstrated, that differences between individuals in which gut bacteria they harbour may underlie differences in their susceptibility to disease, their resilience to stressors, and their responses to environmental stimuli. Thus the variation in responses to the same lifestyle between different people may reflect their gut microbiomes. This would open up several venues of personalized medicine, lifestyle advice and nutrition. Choice of medications, diets or interventions could be selected according to a person's specific microbiome to be most effective. It might also be possible to potentiate such interventions by altering the gut microbiome in different ways, such as through antibiotics, probiotics, nutrition or through microbiome transplantation from another person. Alternately put, by adapting the microbiome to a lifestyle intervention, and/or adapting a lifestyle intervention to the microbiome, we may be able to optimize how a given person can seek and achieve fitness and health.\r\n\r\nIn this talk, I will outline what we know on these topics so far, especially from studies using large-scale microbial (meta-)genome DNA sequencing. In this talk I will draw on work by my own lab at the Charité in Berlin, as well as that of our colleagues, rivals and collaborators elsewhere in the world. I will give examples of known gut microbial modulation of human responses to the external environment and introduce the most common strategies both for researching such effects and for their leverage as health-promoting tools. Where there are limits to our knowledge or obstacles to its practical application, I will identify those obstacles and suggest ways to overcome them.","duration":2400,"logo":"/system/events/logos/000/011/959/original/ecrc-logo.png?1699560013","type":"lecture","do_not_record":false,"track":"Science","abstract":"Why do some people stay fit and healthy easier than others, even when following the same health advice? Why does the same medication work well in one person, but not in another? Some of our individuality in these regards may trace to which bacteria we carry in the soil of our intestinal gardens. In this talk, drawing on work by my own research lab at the Charité and on that by our collaborators and rivals elsewhere in the world, I outline what we know, what we speculate, and what obstacles remain in the way of widespread adoption of personalized health prevention through microbiome sequencing.","speakers":[{"guid":"ee2717ca-fe2a-5e04-8d91-3bafba212c74","id":19289,"image":"/system/people/avatars/000/019/289/original/forslund_photo_small_20210515.jpg?1699554291","name":"Sofia Kirke Forslund-Startceva","public_name":"Sofia Kirke Forslund-Startceva","email":"sofia.forslund@mdc-berlin.de","abstract":"Sofia Kirke Forslund-Startceva is a computational biology researcher based in Berlin, with an interest in engineering greater freedom and self-determination wherever possible.","description":"Sofia Kirke Forslund-Startceva left her native Sweden after training as a molecular biotechnologist and bioinformatician following doctoral studies in evolutionary bioinformatics, spending 2012-2018 at the EMBL in Heidelberg using computational methods to explore microbial ecosystems as a post-doctoral researcher. Sofia relocated to Berlin in 2018 to start an independent research lab at the Experimental and Clinical Research Centre (ECRC), a joint venture between the Charité University Hospital and the Max Delbrück Centre for Molecular Medicine (MDC), the Host-Microbiome Systems Medicine lab. In 2023 she was appointed Professor for Applied Microbiology by the Charité, and since 2019 is ranked among the top 1% most cited researchers in her field worldwide.\r\n\r\nA lifelong adherent of the hacking ethos, Sofia sees all systems as valid optimization targets, whether symbolic, cultural, spiritual, technical, biological or organizational, a perspective which informs her research also in a transhumanist sense, with an ultimate goal of enabling longer lives in bodies better adapted to our individual needs. Sofia ascribes to political liberalism, queer feminism and ideals of human self-determination. In her personal life, these ideals empowered her to seek legal, social and medical sex and gender transition away from her birth assignment at around the time she came to Berlin, following a few decades identifying as nonbinary. Sofia is married, polyamorous and active in LGBTQ and kink communities. Spiritually, she is a Discordian and a pagan priestess of Inanna.\r\n\r\nLab web page: https://www.mdc-berlin.de/forslund\r\nSocial media: @inanna_nalytica\r\nVarious invited writings, press releases and interviews:\r\n- https://lgbtqstem.com/2020/08/14/2017/\r\n- https://www.mdc-berlin.de/news/portraits/how-heart-and-gut-are-connected\r\n- https://www.mdc-berlin.de/news/press/what-gut-reveals-about-heart\r\n- https://www.mdc-berlin.de/news/press/highly-cited-and-influential\r\n- https://www.mdc-berlin.de/news/news/sofia-forslund-awarded-w3-professorship","links":[]}],"start_time":"2023-12-29T16:40:00.000+01:00","end_time":"2023-12-29T17:20:00.000+01:00","room":{"name":"Saal Zuse","id":473}},{"id":11789,"guid":"68bd0b6e-5344-4ad0-94ae-5b1cc5d8ff0b","title":"Hacker Jeopardy","subtitle":"Zahlenraten für Geeks","description":"The well known reversed quiz format, but of course hacker style. It once was entitled „number guessing for geeks“ by a German publisher, which of course is an unfair simplification. It’s also guessing of letters and special characters. ;)\r\n\r\nThree initial rounds will be played, the winners will compete with each other in the final.\r\n\r\nThe event will be in German, we hope to have live translation again.","duration":7200,"logo":"/system/events/logos/000/011/789/original/beopardy.png?1698566098","type":"lecture","do_not_record":false,"track":"Entertainment","abstract":"The well known quizshow format, but of course covering topics not usually seen on television.","speakers":[{"guid":"34d34347-0cac-5caa-88f9-6bfc2601d8c4","id":2506,"image":"/system/people/avatars/000/002/506/original/101.jpg?1360200783","name":"Sec","public_name":"Sec","abstract":"Hacking (for) the club since 1997","description":"Sec is a longtime member of the CCC, one of the founders of the Munich CCC group and known for his presentation of Hacker Jeopardy together with ray on various hacker events over the last 10+ years as well as some reverse-engineering of the iridium communication system. \r\n","links":[]},{"guid":"92efa899-819c-595e-b966-8f55935d7dab","id":9037,"image":null,"name":"Ray","public_name":"Ray","abstract":"Hacker in Jeopardy","description":"Ray’s been around for years. Besides lockpicking and random number generating he’s interested in linux, electronics and stuff.\r\n\r\nBesides presenting Hacker Jeopardy for over twenty years now, Ray collects random numbers, picks locks and likes interesting stuff.","links":[]}],"start_time":"2023-12-28T00:15:00.000+01:00","end_time":"2023-12-28T02:15:00.000+01:00","room":{"name":"Saal 1","id":471}},{"id":12210,"guid":"ae8bffe4-2285-487a-ad34-27928d28396b","title":"Hackers for Future","subtitle":"How makers and other grassroots innovators are doing their part to fight in climate crisis – and how to join","description":"We all have a huge responsibility for environmental sustainability in times of climate crisis. In so many grassroots and community initiatives, digitalization works at the service of society and social and ecological change. Slowly, political frameworks are also moving towards recognizing our planetary boundaries and encouraging or requiring individuals and companies to take more global responsibility for economic actions and to work towards circular economic systems. \r\n\r\nIn this context, concepts and technological approaches that some years ago only openness advocates, hackers and makers knew about are becoming more relevant for the broader public, enabling new ways of producing, consuming and acting, such as distributed production, right to repair and open innovation. In this lecture we outline these framework conditions and new approaches and show why it is worth looking beyond Europe – especially when it comes to using new technologies for ecological sustainability. \r\n\r\nThe presentation will give you an overview of global initiatives that inspire you to use your hackerspace for Future – like co-creation of prototypes that mitigate the effects of Climate Crisis in Brazil, or how to include Ecosystem Services in grassroot initiatives in Sri Lanka, but also on networks that support the exchange of new sustainable approaches and technologies, like creating the Internet of Production or the Appropedia, a global wiki of appropriate technologies – and appropriate is definitely not always “High Tech”. \r\n\r\nWe will discuss how networks are a key tool in shaping a sustainable futures and call for the creation of a global exchange on Open Hubs against Climate Crisis – and hope you will support it.","duration":2400,"logo":null,"type":"lecture","do_not_record":false,"track":"Sustainability \u0026 Climate Justice","abstract":"Join to find out about new (and sometimes very old) approaches to environmental sustainability by grassroots initiatives, makers, hackers all around the world, learn what the power of networks adds to the mix and how hackers worldwide can join the efforts.","speakers":[{"guid":"48e80b07-cf13-5c05-b6d0-3ec6c243f0be","id":9065,"image":null,"name":"aprica","public_name":"aprica","abstract":"Internet politics * Open Hardware * Global Innovation Gathering","description":"I'm part of the \"Global Innovation Gathering\", a global network of makers, social and technical innovators, people engaged for internet freedoms and many other causes all around how digital tools can support to create a more just and sustainable future. As board member, project coordinator and jack of all trades, I'm there to help the members of the association all around the world to exchange knowledge and experience globally and to fulfill their missions. Other affiliations include re:publica, Digitale Gesellschaft and EDRi.","links":[{"url":"https://chaos.social/@aprica","title":"Social"}]},{"guid":"8177e4c0-ab91-59cf-9033-ec013bbe1f81","id":19543,"image":null,"name":"Geralbine","public_name":"Geralbine","abstract":null,"description":null,"links":[]}],"start_time":"2023-12-27T21:10:00.000+01:00","end_time":"2023-12-27T21:50:00.000+01:00","room":{"name":"Saal Grace","id":472}},{"id":12059,"guid":"643ecf8f-de45-4155-91d2-3195430dbd4b","title":"Hacking Neural Networks","subtitle":"Eine Einführung in das Hacking von Neuronalen Netzen","description":"Der Vortrag beginnt mit einer knappen Einführung in die Funktionsweise Neuronaler Netze, um ein allgemeines Verständnis zu schaffen. Anschließend werden verschiedene Angriffe auf Neuronale Netze dargestellt. Die dargestellten Angriffe sind zum größten Teil technisch und ich werde Angriffe wie Prompt Injection nur kurz behandeln. Im Vortrag werden neben Prompt Injection Angriffe wie LastLayer Attack, Back-Dooring, Extracting Information, Brute Forcing, Neural Overflow, Malware Injection, Neural Obfuscation und Model Stealing theoretisch vorgestellt. Um den theoretischen Vortrag aufzulockern, werde ich einige dieser Angriffe anhand von Live-Beispielen veranschaulichen und erklären, wie sie die Funktionsweise Neuronaler Netze ausnutzen bzw. an welchen Stellen diese manipuliert werden können. Während der Erläuterung der Angriffe werde ich auch darauf eingehen, welche Informationen für den Angriff benötigt werden und welche Informationen besonders schützenswert sind. Abschließend werde ich mögliche Verteidigungsstrategien erläutern, auch wenn diese nur einen teilweisen Schutz ermöglichen. Der Vortrag wird einen guten Überblick über Angriffe auf Neuronale Netze geben, wie sie in der aktuellen wissenschaftlichen Literatur bekannt sind. ","duration":2400,"logo":"/system/events/logos/000/012/059/original/hackingnn.png?1699685825","type":"lecture","do_not_record":false,"track":"Science","abstract":"Ich will den Zuhörerinnen einen Überblick über die aktuellen Möglichkeiten geben, wie Neuronale Netze angegriffen und manipuliert werden können. Das Ziel des Vortrags ist es, verschiedene Angriffe zu erklären und anhand von Beispielen zu veranschaulichen. Dies dient auch dazu, die Funktionsweise neuronaler Netze besser zu verstehen und ihre Limitierungen aufzuzeigen. Abschließend zeige ich, welche Maßnahmen ergriffen werden können, um diese Angriffe zu erkennen oder zu verhindern.","speakers":[{"guid":"7021daef-1c36-5f60-b97b-4bcab4a08817","id":19364,"image":null,"name":"jate","public_name":"jate","abstract":null,"description":null,"links":[]}],"start_time":"2023-12-28T11:00:00.000+01:00","end_time":"2023-12-28T11:40:00.000+01:00","room":{"name":"Saal 1","id":471}},{"id":11870,"guid":"689e3b8e-da4f-40b7-8ed8-ecea17c3cfd1","title":"Hacking the Climate","subtitle":"Mit Climate Engineering raus aus der Klimakrise?","description":"Climate Engineering ist das menschliche Eingreifen mittels großskaliger Technologien, um das globale Klimasystem zu beeinflussen. Dank Hollywoodfilmen und gefährlichem Halbwissen kennen wir diverse Untergangsszenarien zu dem Thema, wissen aber kaum wie Fotosynthese und Gesteinsverwitterung uns Menschen zum Erreichen unserer Klimaziele weiterhelfen können. Dass Steine CO2 aus der Luft holen und Jahrmillionen speichern können, ist für die allermeisten Menschen neu. In meinem Vortrag möchte ich aufklären, warum CO2 Entnahme aus der Atmosphäre (Negative Emissionen) ein wichtiger Baustein der Netto-Null Klimastrategie sind und in welchen Formen diese umgesetzt werden kann. Neben der biologischen und geochemischen CO2-Entnahme durch Fotosynthese und Gesteinsverwitterung, gibt es noch elektrochemische Methoden, um CO2 direkt aus der Luft oder indirekt über das Meer zu entnehmen. Ich berichte außerdem aus meiner aktuellen Forschung in der ich Gesteinsmehl und Pflanzenkohle als Bodenverbesserer und zur CO2-Entnahme in der Landwirtschaft erforsche.","duration":2400,"logo":null,"type":"lecture","do_not_record":false,"track":"Science","abstract":"Die Klimakrise eskaliert, 2023 wird voraussichtlich das wärmste Jahr seit Aufzeichnung gewesen sein, und es brennt und brennt und brennt. Während das verbleibende CO2-Budget zur Einhaltung der 2°C-Grenze schneller als je zuvor schrumpft, wird der Ruf nach einfachen, technologischen Lösungen laut. Eine globale Abkühlung des Klimas durch Climate Engineering wird von der Politik gerne als Universallösung angepriesen. Aber können wir das CO2, das wir ausstoßen, so einfach aus der Luft saugen und mit „negativen Emissionen“ das Klima retten? Dr. Maria-Elena Vorrath forscht an der Universität Hamburg an Gesteinsverwitterung und Pflanzenkohle, zwei Methoden, die CO2 aus der Atmosphäre entziehen, und klärt in ihrem Vortrag über negative Emissionen, ihr globales Potential und den aktuellen Forschungsstand auf. Und es gibt Memes.","speakers":[{"guid":"69eaf97b-36cc-58a5-9d62-7c84f0b69dbe","id":19193,"image":null,"name":"Maria-Elena Vorrath","public_name":"Maria-Elena Vorrath","abstract":null,"description":null,"links":[]}],"start_time":"2023-12-27T12:55:00.000+01:00","end_time":"2023-12-27T13:35:00.000+01:00","room":{"name":"Saal 1","id":471}},{"id":12183,"guid":"f618d3d7-d566-46f9-be2b-19c02bd33154","title":"Handsfree assistive technology","subtitle":"My technology portfolio to enable work, life, smart home and travel using a power wheelchair","description":"One moment changed my life. I had a swimming accident in 2017, a big wave took me and I broke my neck.\r\n\r\nI am paralysed from the chest down, have no hand functions and sit in a power wheelchair. I cannot cough up independently and rely on 24/7 help to live an active life.\r\n\r\nIn the first few months, I was not able to breathe, eat, drink, speak, walk etc. by myself. In the meanwhile, I made some significant progress and began to work independently using my computer and assistive technology. Step-by-step I came back to a new kind of life. \r\n\r\nI love travelling and am fascinated by innovative technologies. I love my job in the IT industry and passionately work full-time for a startup company in Berlin.\r\n\r\nI will share some insights on spinal cord injury and my experiences of how I work, live and travel using a power wheelchair. There are millions of people who cannot control a computer, tablet, or smartphone with their hands. Assistive technology supports the main functionalities which are needed: mouse movement and different kinds of clicking.\r\n\r\nI'm really lucky to be part of the current generation. In the last couple of years, the major technology companies released significant updates in regards to voice recognition, universal design, accessibility and assistive technology.\r\n\r\nMy portfolio of hands-free assistive technology enables me every day to be active without using my hands or feet. I’m going to present Solutions which make my everyday life more comfortable\r\n\r\nI will share my personal setup which includes software and hardware. You can assume that I tested all of these products, and I’m using them in my smart home.\r\n\r\nAssistive technology is going to change the lives of many forever and is much more vital than ever before.\r\n\r\nHere are a few examples which I'm going to present.\r\n\r\nMy remodelled VW Transporter which enabled me to be the co-driver\r\n\r\nMy Smart home setup for lights, doors, tables, couch, TV, curtains, temperature and kitchen with speech, voice control and apps\r\n\r\nMy power wheelchair and its individual configuration so I can drive using my chin or head\r\n\r\nA robotic arm which allows to be a personal assistant to drink, smoke or scratch myself\r\n\r\nMy computer, smartphone and headphone setup includes a head movement mouse, voice and switch control for dictation and commanding as well as a Bluetooth module to control the smartphone with single button clicks\r\n\r\nLast but not least, I love doing videos using my GoPro and I'm happy to share my perspective","duration":2400,"logo":"/system/events/logos/000/012/183/original/512x512.png?1699733051","type":"lecture","do_not_record":false,"track":"Hardware \u0026 Making","abstract":"I am paralysed from the chest down, have no hand functions and sit in a power wheelchair. I will share some insights on spinal cord injury and my experiences of how I work, live and travel using a power wheelchair. There are millions of people who cannot control a computer, tablet, or smartphone with their hands. Assistive technology supports the main functionalities which are needed: mouse movement and different kinds of clicks. My portfolio of hands-free assistive technology enables me every day to be active without using my hands or feet. I’m going to present solutions which make my everyday life more comfortable.","speakers":[{"guid":"7d8e1cef-9a89-5a4b-9f06-5dfd5ef8da12","id":19113,"image":"/system/people/avatars/000/019/113/original/512x512.png?1699733287","name":"QuadWorker","public_name":"QuadWorker","email":"jangoslicki@gmail.com","abstract":"Quadriplegic Spinal Cord Injury Survivor","description":null,"links":[{"url":"https://quad.works/","title":"Handsfree Assistive Technology"}]}],"start_time":"2023-12-27T19:15:00.000+01:00","end_time":"2023-12-27T19:55:00.000+01:00","room":{"name":"Saal Zuse","id":473}},{"id":11689,"guid":"3d4de6f8-242c-46c2-9683-1a7285d4e93e","title":"Heimlich-Manöver","subtitle":"Best of Informationsfreiheit \u0026 Gefangenenbefreiung","description":"Freut Euch unter anderem auf die besten Auskunfts-Klagen der vergangenen Jahre, laufende Strafverfahren gegen FragDenStaat, missglückte Geldübergaben an die EU-Grenzpolizei und die Frage, ob das alles irgendwas bringt.\r\n\r\nEuch erwartet außerdem ein Best-Of des Freiheitsfonds, der in zwei Jahren mehr als 900 Menschen aus dem Gefängnis befreit und eine Gesetzesänderung angestoßen hat. \r\n\r\nVielleicht wird auch gesungen.","duration":2400,"logo":null,"type":"lecture","do_not_record":false,"track":"Ethics, Politics \u0026 Society","abstract":"Wie umgehen mit der politischen Verzweiflung? Was tun, wenn der Staat keine der Krisen wirklich noch bekämpfen kann, sondern nur neue erzeugt? Reicht es noch, für Transparenz zu kämpfen?\r\n\r\nDas Beste aus dem letzten Jahr – nein, aus den letzten vier Jahren! – FragDenStaat und Informationsfreiheit. Wir plaudern aus dem Nähkästchen von verlorenen Klagen gegen Frontex über Nazis im EU-Parlament bis zu den Pimmelgate-Akten und darüber, wie aus einer kleinen Recherche die größte Gefangenenbefreiung der deutschen Geschichte wurde.","speakers":[{"guid":"7c29904e-c407-5f62-bf8e-8a9235dddbd6","id":5605,"image":"/system/people/avatars/000/005/605/original/Arnesemsrott.jpg?1545783146","name":"Arne Semsrott","public_name":"Arne Semsrott","abstract":"Arne ist Projektleiter von FragDenStaat und Gründer des Freiheitsfonds. Er ist Journalist und Politikwissenschaftler.","description":null,"links":[{"url":"https://FragDenStaat.de","title":"FragDenStaat"}]}],"start_time":"2023-12-27T11:00:00.000+01:00","end_time":"2023-12-27T11:40:00.000+01:00","room":{"name":"Saal 1","id":471}},{"id":12134,"guid":"2a328f4e-6442-4e3c-811e-e63b3c425bd4","title":"Hirne hacken: Hackback Edition","subtitle":"Wir verhandeln mit Erpressern, damit Ihr es nicht müsst.","description":"Seit gut sieben Jahren ist Ransomware ein florierendes und stetig wachsendes Geschäftsmodell für durchschnittlich und unterdurchschnittlich begabte Hacker. Wie man sich davor schützen kann, ist kein Geheimnis. Trotzdem tun es offenbar immer noch zu wenige. Weil das ärgerlich ist, erklären wir es noch einmal.\r\n\r\nÜber die Vorgehensweisen der Gangs ranken sich allerlei Mythen, die verhindern, dass Organisationen sich sinnvoll schützen. Wir berichten aus unserer Erfahrung mit unzähligen Fällen, welche Schutzmaßnahmen wirklich sinnvoll sind.\r\n\r\nDoch auch über die Verhandlungen mit den Gangstern gibt es allerlei falsche Vorstellungen, angeheizt von selbsternannten \"Cyber-Profilern\" und \"Lösungsgeld-Verhandlern\", die natürlich kein Interesse haben, ihre „Tricks\" zu verraten. Deswegen machen wir das:  Wir ergründen die spieltheoretische Mechanik der Verhandlungssituation an mehreren echten Beispielen und schauen uns die Organisation der Ransomware-Gangs an.\r\n\r\nKai Biermann ist Investivativ-Journalist und hat unter anderem Mitglieder der Ransomware-Gang Conti aufgedeckt. Linus Neumann hat als IT-Security-Consultant viele Incidents gemanaget und dabei das zweifelhafte Vergnügen gehabt, mit unterschiedlichen Ransomware-Gangs zu verhandeln.\r\n\r\nDer Vortrag ist eine Weiterführung von „Hirne Hacken\" (36C3) und „Disclosure, Hack und Back\" (Chaos Communication Camp '23).","duration":3600,"logo":"/system/events/logos/000/012/134/original/sunil2342_an_innocent_office_worker_unknowingly_clicked_a_malic_34f63625-ccdb-46ff-b680-0126f152664a.png?1699728622","type":"lecture","do_not_record":false,"track":"Ethics, Politics \u0026 Society","abstract":"Du musst mit ein paar Erpressern um mehrere Millionen verhandeln.\r\nDas kann sogar Spaß machen, wenn es nicht dein Geld ist.","speakers":[{"guid":"007105e0-7ac6-5aaa-b416-9bb595caa389","id":3995,"image":"/system/people/avatars/000/003/995/original/Linus_Neumann.JPG?1700002008","name":"Linus Neumann","public_name":"Linus Neumann","abstract":"Part of that force that always wills the evil and always produces the good.","description":"Linus Neumann is one of the spokespersons for the Chaos Computer Club (CCC).\r\n\r\nTogether with Tim Pritlove, he hosts the weekly podcast \"Logbuch:Netzpolitik.\"\r\n\r\nHe does this IT insecurity thing for a living.","links":[{"url":"https://linus-neumann.de","title":"Linus Neumann"},{"url":"https://logbuch-netzpolitik.de","title":"Logbuch:Netzpolitik"},{"url":"https://chaos.social/@linuzifer","title":"chaos.social/@linuzifer"},{"url":"https://twitter.com/linuzifer","title":"twitter.com/linuzifer"},{"url":"https://bsky.app/profile/linuzifer.bsky.social","title":"@linuzifer.bsky.social"}]},{"guid":"476fcf39-91ec-58b1-8b48-4a5cdf683fb1","id":6349,"image":"/system/people/avatars/000/006/349/original/Pegasus-Ausschnitt.jpg?1699952717","name":"Kai Biermann","public_name":"Kai Biermann","email":"kai.biermann@neusprech.org","abstract":"Diplomierter Psychologe, arbeitet seit 1997 als Autor und als Journalist für verschiedene Tageszeitungen und Onlinemedien, seit 2007 als Redakteur bei ZEIT ONLINE. Seit 2019 Mitglied des gemeinsamen Investigativteams von DIE ZEIT und ZEIT ONLINE. Bloggt zusammen mit Martin Haase unter neusprech.org über die verschleiernden Tricks politischer Sprache. Schreibt Sachbücher, zuletzt über Drohnen.","description":null,"links":[{"url":"https://neusprech.org/","title":"Neusprechblog"}]}],"start_time":"2023-12-27T17:15:00.000+01:00","end_time":"2023-12-27T18:15:00.000+01:00","room":{"name":"Saal 1","id":471}},{"id":11734,"guid":"83c74623-452b-45f9-85ba-6e91b1caceff","title":"How Many Planets in Our Solar System? Glad You Asked!","subtitle":"How Astronomy Knew 6 Planets, Then Found 20 More, Then Went Back To 8 (For Now)","description":"In antiquity, scientists counted the 7 classical planets: the Moon, Mercury, Venus, the Sun, Mars, Jupiter and Saturn – but their model of the universe was wrong. Two thousand years later, a new model was introduced. It was less wrong, and it brought the number of planets down to 6: Mercury, Venus, Earth, Mars, Jupiter, Saturn. Since then, it's been a roller coaster ride of planet discoveries and dismissals.\r\n\r\nIn this talk, we stagger through the smoke and mirrors of scientific history. We meet old friends like Uranus and Neptune, forgotten lovers like Ceres, Psyche and Eros, fallen celebrities like Pluto, regicidal interlopers like Eris and Makemake as well as mysterious strangers like Vulcan, Planet X and Planet Nine.\r\n\r\nFind out how science has been tricked by its own vanity, been hampered by too little (or too much!) imagination, and how human drama can make a soap opera out of a question as simple as: How Many Planets in Our Solar System?","duration":3600,"logo":"/system/events/logos/000/011/734/original/tn-p_lorri_fullframe_color.jpg?1697824327","type":"lecture","do_not_record":false,"track":"Science","abstract":"The Solar System has had 8 planets ever since Pluto was excluded in 2006. This has made a lot of people very angry and been widely regarded as a bad move. But did you know Neptune was discovered as the 12th planet? Or that, 80 years before Star Trek, astronomers seriously suspected a planet called Vulcan near the Sun? This talk will take you through centuries of struggling with the question: Do you even planet?!","speakers":[{"guid":"4f29c50c-481d-5dd5-a27b-13007d0d1d82","id":4920,"image":"/system/people/avatars/000/004/920/original/twitterme.jpg?1410024157","name":"Michael Büker","public_name":"Michael Büker","abstract":"With Congress since 28C3. Currently living in Dresden. Linux, languages and Internet geek. Diploma in physics with specialization in astroparticle physics and peace research. Working in science communication and science journalism, sometimes seen on stage or behind the scenes where science goes entertainment.","description":null,"links":[{"url":"https://www.michael-bueker.de/","title":"Professional Homepage (German)"}]}],"start_time":"2023-12-29T13:30:00.000+01:00","end_time":"2023-12-29T14:30:00.000+01:00","room":{"name":"Saal Grace","id":472}},{"id":11828,"guid":"b64fa58b-6f1c-45ef-8dd1-c09947f8a455","title":"How to build a submarine and survive","subtitle":"Wie wir mit begrenzten Mitteln ein U-Boot gebaut haben und was ihr draus lernen könnt.","description":"Die einzelnen Systeme eines U-Boots sind nicht kompliziert. Aber die Schwierigkeit liegt in der Summe der Einzelsysteme, die auf engem Raum im Zusammenspiel sicher funktionieren müssen. Der Fokus des Vortrags liegt neben unserer kurzweiligen Geschichte auf den technischen Schwierigkeiten, zu denen sich in der Literatur wenig findet oder wegen derer es nicht gleich auf Anhieb funktioniert hat. Damit ihr, falls ihr ähnliches plant, einen besseren Start habt und von unseren Fehlern profitieren könnt.\r\n\r\nWas gibt es bei der Wahl eines geeigneten Drucktanks zu beachten?\r\nWie lässt sich eine wasserdichte Luke konstruieren?\r\nDrahtlose Unterwasserkommunikation mittels Ultraschall?\r\nWie bauen wir Redundanz in die Systeme ein?\r\nWie werden wir das CO2 los, um nicht zu ersticken?\r\nWarum sind auf einmal Risse in den Scheiben?\r\nWas tun, wenn nichts mehr geht?\r\nUnd was, wenn dann auch noch die Polizei kommt?\r\n\r\nIn dem Vortrag geht es nicht um Probleme anderer kaputter U-Boote. Wir werden das Titan-Desaster mit maximal einer Folie behandeln.\r\n\r\nMit Fotos von Selene Magnolia","duration":3600,"logo":null,"type":"lecture","do_not_record":false,"track":"Hardware \u0026 Making","abstract":"3,4 Tonnen schwer, 4,3 Meter lang, Material: Stahl, Farbe: Orange und der Fahrzeugtyp ist „Sporttauchboot”. Vom Fund eines Drucktanks bis zum ersten Tauchgang auf den Grund eines Tagebausees – wir erzählen von unseren größten Herausforderungen sowie Fehlschlägen.\r\n\r\nWir laden euch ein zu einem technischen Beratungsgespräch für alle, die schonmal mit dem Gedanken gespielt haben, ein U-Boot zu bauen.","speakers":[{"guid":"852cad1e-1e60-58f6-a0e4-1a7f7a428a99","id":8589,"image":null,"name":"Nico","public_name":"Nico","abstract":null,"description":null,"links":[]},{"guid":"539af2f7-59dd-5a58-afd0-3b78df9d34fe","id":19556,"image":"/system/people/avatars/000/019/556/original/06__2250054.jpg?1702202667","name":"Elias","public_name":"Elias","abstract":"In Münster geborener Ingenieur für Theatertechnik mit Werkstatt in Leipzig und einer schwäche für das Meer.","description":null,"links":[]}],"start_time":"2023-12-29T21:45:00.000+01:00","end_time":"2023-12-29T22:45:00.000+01:00","room":{"name":"Saal Grace","id":472}},{"id":12327,"guid":"13794e21-cb3a-422a-91a8-32366acee6ee","title":"How to Hack Your Way to Space","subtitle":"Bringing the Hacker Mindset to the Space Ecosphere - The story behind the Libre Space Foundation (LSF)","description":"The current state of the space ecosystem is characterized by its reliance on defense-oriented policies and outdated systems, hindering the true potential of space exploration. Despite the promise of Space 4.0, the reality is that space remains largely inaccessible to the public at large.\r\n\r\nAgainst this backdrop, a group of hackers and makers is revolutionizing the space industry. By promoting the hacker ethos of innovation, resourcefulness, and open-source principles, they are challenging the status quo and delivering creativity and accessibility into the space sector.\r\n\r\nDriven by the hackerspace movement and the broader community, we, Libre Space Foundation, are actively building our own satellites, space technologies, sharing knowledge and resources, and pushing the boundaries of space exploration. Our mission is to democratize space, making it available to everyone, regardless of background or resources.\r\n\r\nThis emerging movement faces unique challenges, including working within a small, underfunded ecosystem, developing software and hardware, mapping out processes amidst complex space law and global politics, and ensuring long-term sustainability without relying on external funding.\r\n\r\nTo overcome these challenges and harness the full potential of this movement, we propose a manifesto with four pillars:\r\n\r\nOpen Source: All technologies developed for outer space shall be published and licensed using open source licenses.\r\nOpen Data: All data related to and produced in outer space shall be freely accessed, used and built upon by anyone, anywhere, and shall be shared and managed according to the principles above.\r\nOpen Development: All technologies for outer space shall be developed in a transparent, legible, documented, testable, modular, and efficient way.\r\nOpen Governance: All technologies for outer space shall be governed in a participatory, collaborative, direct, and distributed way.\r\n\r\nBy embracing these pillars, we can create a more open, inclusive, and sustainable space ecosystem that empowers individuals and communities to participate in the exploration of the cosmos.","duration":3600,"logo":"/system/events/logos/000/012/327/original/LSF_SD_Vertical_Color.png?1702043125","type":"lecture","do_not_record":false,"track":"Hardware \u0026 Making","abstract":"Embark on Libre Space Foundation's journey into the world of open-source space exploration, where a passionate community of hackers and makers is challenging the traditional defense-driven approach to spacefaring. Discover how we are democratizing space by embracing open-source technologies, community collaboration, and a commitment to sustainability.","speakers":[{"guid":"ac6aa763-dd39-58b5-991b-02b2b96acad9","id":19542,"image":null,"name":"Manthos Papamatthaiou","public_name":"Manthos Papamatthaiou","abstract":null,"description":null,"links":[]},{"guid":"ac9a5468-3d40-541e-99ea-dfc7a83e5d8f","id":19557,"image":null,"name":"Alfredos (fredy) Damkalis","public_name":"Alfredos (fredy) Damkalis","abstract":null,"description":null,"links":[]}],"start_time":"2023-12-27T17:15:00.000+01:00","end_time":"2023-12-27T18:15:00.000+01:00","room":{"name":"Saal Grace","id":472}},{"id":12016,"guid":"05cb0d5b-ae52-48a6-a68a-8503dfc06f95","title":"Hurra, diese Welt geht unter!?","subtitle":"Welche kollektiven Erzählungen brauchen wir, um in der Klimakrise handlungsfähig zu sein? ","description":"Die sich beschleunigt entfaltende Klimakatastrophe stellt die vordringlichste kollektive Herausforderung der Menschheit dar. Sie ist riesig, unübersehbar, wirkt irgendwie langsam im Gegensatz zu akuten Krisen wie Krieg oder Pandemien. Sie lädt deshalb ein zur destruktiven Prokrastination. Paralysiert verharrt ein Großteil von uns in Ignoranz oder überwältigender Ohnmacht. Warum das denn? Das Wissen um die Notwendigkeit des Handelns und die zu treffenden Maßnahmen ist da. Was für die Umsetzung ins konsequente Handeln fehlt – das ist die These des Talks – sind überzeugende kollektive Narrative. Gesucht wird eine Erzählung der Endlichkeit, die zur Gestaltung einer transformierten nachhaltigen und egalitären Zukunft motiviert. Dass es dringend sinnstiftende, universalistische Erzählungen braucht, zeigen auch der Trend von Verschwörungsmythen, die wachsende Prepper-Szene, das Comeback religiöser Heilsversprechungen und Fantasien, den individuellen oder kollektiven Tod mittels Technologisierung (#mindupload, #Dadbot, #Transhumanismus, #SpaceX) ganz abzuschaffen.\r\n\r\nAktuelle zivilgesellschaftliche Bewegungen zur Verhinderung der Klimakatastrophe verbreiten mit ihren Aktivitäten unterschiedliche Erzählungen, die zum Teil medial gegeneinander ausgespielt werden. Der Talk gibt einen Rahmen, in dem die verbindenden Elemente sichtbar werden. Wir laden zwei Aktivist:innen unterschiedlicher Bewegungen (Letzte Generation und „Solarpunk\") ein, ihr Engagement im Kontext dieser erzählerischen Komponenten vorzustellen: Welches menschliche Selbstbild, welcher Technikbegriff, welcher Körperbegriff steckt darin und wie wird mit Endlichkeit, Verletzlichkeit und Transformation umgegangen? Wie wird bei Aktionen die eigene Körperlichkeit eingesetzt? Was ist die Rolle von Technologien, z.B. KI, in dieser Erzählung?\r\n\r\nDer Talk versteht sich als Teil der Weiterentwicklung von unterschiedlichen aktivistischen Ansätzen – divers wie die Ökosysteme selbst – und deren Verbindung zu einer gesellschaftlich wirkmächtigen Bewegung im Kampf gegen die Klimakrise.","duration":2400,"logo":"/system/events/logos/000/012/016/original/dp.jpg?1701676817","type":"lecture","do_not_record":false,"track":"Sustainability \u0026 Climate Justice","abstract":"Es war einmal ein Planet voller Affen, die sich Geschichten über sich, das Universum, die Technik und den ganzen Rest erzählten. Sie erzählten sich vor allem Storys vom unendlichen Wachstum und von der technologischen Überwindung der Sterblichkeit. Spätestens im Jahr 2023 passten diese sehr mächtigen Erzählungen nicht mehr. Die Ökosysteme brachen zusammen, planetare Grenzen und Artensterben wurden unignorierbar und so standen nicht nur das Klima, sondern auch die alten Narrative an einen Kipppunkt…\r\n\r\nWelche Geschichte(n) von individueller und kollektiver Sterblichkeit müssen wir uns heute erzählen, um handlungsfähige Mehrheiten für eine nachhaltige, egalitäre und emanzipative digitale Zukunft zu mobilisieren?\r\n\r\nIm Talk zeigen wir den engen Zusammenhang von (Un-)Sterblichkeits-Erzählungen, menschlichem Selbstbild und Zukunftsvorstellungen – vor allem aber deren Wirkmacht auf unsre Handlungsfähigkeit.\r\n\r\nDazu laden wir zwei Gäste ein, uns ihre Narrative zu zeigen: ein*e Aktivisti der Letzten Generation und Daniel Domscheit-Berg, der über Solarpunk sprechen wird. Anschließend basteln wir es zusammen: zwischen „I want you to panic” und „DON’T PANIC!” – welche Narrative brauchen wir jetzt und hier, um uns zwischen Trauer um diese Welt und der Lust am (Über)leben zu organisieren?","speakers":[{"guid":"837d845f-e5c1-59ca-ad1c-55b2fb1b4c88","id":9881,"image":"/system/people/avatars/000/009/881/original/Elenos_Team.jpg?1701354684","name":"Elenos","public_name":"Elenos","abstract":"Studied philosophy at the Technical University of Berlin, yodelling activist and End-of-Life caregiver.","description":null,"links":[]},{"guid":"94b0aaab-5b9e-57d0-9919-77cbe9ce7b93","id":12164,"image":"/system/people/avatars/000/012/164/original/employee.png?1701705321","name":"mischko","public_name":"mischko","abstract":"Forscht seit reichlich 10 Jahren im Bereich der Biophysik und hat sich selbst zum Schmalzbeauftragten des Quartiersmanagement Grunewald ernannt. Er ist nicht mit Graf Zahl verwandt.","description":null,"links":[]},{"guid":"7acab9ae-4493-5c57-9ab9-a1fdef14fdaf","id":19431,"image":null,"name":"daniel domscheit-berg","public_name":"daniel domscheit-berg","abstract":"Daniel ist ein Aktivist, Generalist und Informatiker mit einem Schwerpunkt auf zeitgemäße Bildung, gemeinwohl-orientierte Digitalisierung und allem dazwischen.","description":"(wird noch ausgebaut)","links":[]}],"start_time":"2023-12-28T13:50:00.000+01:00","end_time":"2023-12-28T14:30:00.000+01:00","room":{"name":"Saal Grace","id":472}},{"id":11955,"guid":"cd4e64e0-2b07-49d1-912e-79a00ec30f03","title":"Image Making Fatigue","subtitle":null,"description":"The transfer of Seidel's experimental films into physical space has been explored in many ways in recent years. Sculpture, architecture and even natural projection surfaces have been temporarily 'overpainted' with projections, lights or lasers. But with new advances in machine learning, there may be a kind of oversaturation, or even rigor mortis, when the moving image becomes fully part of the technical tool chain. In tech companies, universities and artists' studios, machines are working through and learning the history of humanity. \r\n\r\nCopyright dissolves; the distinction between original, imitation or inferior reproduction erodes. No origin, no responsibility, no clear direction - just a primordial soup that can be shaped into any form without challenging knowledge systems and hierarchies. In this silent but radical restructuring of entire industries, the artist becomes the template of a future digitally assembled from a multitude of fragments of the past. This artist talk addresses some of the implications of this singularity, in which history collapses to a single point in the present, and in which easy access to an infinite reworking of iconography may override the desire for a phenomenological experience...","duration":2400,"logo":"/system/events/logos/000/011/955/original/HYSTERESIS_Robert-Seidel_16-9_01.jpg?1699550113","type":"lecture","do_not_record":false,"track":"Art \u0026 Beauty","abstract":"Exploring the transfer of Seidel's experimental films into physical spaces reveals challenges that are intensifying with advances in machine learning, dissolving the lines between original and imitation. In this more or less silent restructuring of society, artists become templates for a digitally assembled future, challenging traditional hierarchies as history collapses into the present.","speakers":[{"guid":"52684e9a-f138-595a-818b-628a805d6b68","id":19287,"image":null,"name":"Robert Seidel","public_name":"Robert Seidel","abstract":"Robert Seidel (*1977) began his studies in biology before transferring to the Bauhaus University Weimar to complete his degree in media design. His projections, installations and experimental films have been shown in numerous international festivals, as well as at galleries and museums such as the Palais des Beaux-Arts Lille, ZKM Karlsruhe, Art Center Nabi Seoul, Young Projects Los Angeles, Museum of Image and Sound São Paulo and MOCA Taipei. His works have been honoured with various prizes, including the KunstFilmBiennale Honorary Award and the Visual Music Award Frankfurt. ","description":null,"links":[{"url":"http://www.robertseidel.com","title":"Homepage"}]}],"start_time":"2023-12-28T19:15:00.000+01:00","end_time":"2023-12-28T19:55:00.000+01:00","room":{"name":"Saal Zuse","id":473}},{"id":12068,"guid":"32189fea-f720-4c7d-b32b-f599954d94a8","title":"Infrastructure of a migratory bird","subtitle":"Technology and autonomy in more-than-human networks","description":"We outline the heterogeneous elements that make up the infrastructure of the rewilding project and what kind of situations are being produced therein. The graph of \"the infrastructure of a migratoy bird\" shows relationships between social, technological, informational, and ecological elements which make up the anthropogenic ecosystem in which the bird is becoming wild again. The objective was to visualise and comprehend the intricate network of data, energy resources, and dependencies deeply enmeshed within the project's framework. \r\n\r\nWe will also focus on the types of data being produced and to what extent \"acting\" within this framework is informed to observation of movement data. One can trace the flow of information, observe how data is generated, processed and ultimately mediated.  As a migratory bird that travels between 1600 and 4600km per year (from summer to winter habitats and back) this project could not be realized without intensive use of technology. This falls into two categories: assisted migration and location/movement tracking. As a social species, the birds have an instinct to migrate, but the concrete migration routes and destinations are socially learned. With the extinction, this social knowledge became extinct as well. This is a challenge and an opportunity for the project. On the one hand, the birds need to be trained the unnatural behaviour of following a light airplane, on the other hand, humans can guide them to specific areas where socio-environmental conditions are suitable for habitation. Currently, close to 85% of the more than 200 surviving rewilded birds are wearing a GPS/GSM tracker that enables near real-time monitoring of locations and movements. This data is used for monitoring the birds for signs of distress (injury, problems along the route, death etc), and for feeding an app (Animaltracker) that allows the interested public to track the birds and, to a limited degree, for behavioural research.\r\n\r\nFrom this, a different notion of wilderness emerges. Here it denotes not the separation from human culture, but a degree of freedom and autonomy in making decisions. Technology, the real-time tracking and social media coverage, serves as a way to increase the autonomy of the bird, supporting them to survive outside captivity, yet within densely populated, deeply cultured environments. Technology's main purpose here is not surveillance but care, both directly by enabling biologists to help struggling animals in the wild, but also indirectly, by supporting a deeper, affective relationship of the population towards wild animals which are no longer anonymous, but known by name, each with its distinct history and personal character. ","duration":2400,"logo":null,"type":"lecture","do_not_record":false,"track":"Art \u0026 Beauty","abstract":"What does it take to create a \"wild animal\"? While one might think \"wildness\" implies the absence of humans, in the age of the anthropocene and rapid climate change, the opposite is the case. It requires the development of an extensive, more-than-human-infrastructure.  Our talk is based on artistic research into the ongoing rewilding project of the Northern bald ibis (Waldrapp), a large migratory bird, that has become extinct north of the alps in 1621 and are being released into the wild since 2013. The output of this research was rendered into a website which serves as a departure point of our talk. ","speakers":[{"guid":"66509dfb-a39c-5f68-8a34-d822bb9bc66b","id":19371,"image":"/system/people/avatars/000/019/371/original/BW_GSavicic1_swisspass.jpg?1702287540","name":"Gordan Savičić","public_name":"Gordan Savičić","abstract":"Gordan Savičić is an artist and critical engineer whose work investigates the relationship between people, networks and interfaces.","description":"Gordan Savičić is an artist and critical engineer whose work investigates the relationship between people, networks and interfaces. He has a background in media art \u0026 visual communication and is active within the fields of teaching digital media and academic research. Savičić is a co-founder of various collectives such as moddr_ (Rotterdam) and weise7 (Berlin). His works have been exhibited worldwide, including the Biennale Seoul, Ars Electronica Linz, Transmediale Berlin, ARCO Madrid, Media Art Festival Japan, File Festival Sao Paolo, Kunsthal Aarhus, Chronus Shanghai, and ZKM Karlsruhe. He is lecturer at the HSLU Lucerne in Digital Ideation. Born in Vienna, he currently lives and works in Lausanne, Switzerland.","links":[{"url":"www.yugo.at","title":"Artist-Website"}]},{"guid":"a3b0e801-877a-524c-8d85-b0e9a9b3309c","id":19548,"image":null,"name":"Felix Stalder","public_name":"Felix Stalder","abstract":"Felix Stalder is Professor at the Department Fine Arts, Zurich University of the Arts, where he leads the artistic research project \"Latent Spaces. Performing Ambiguous Data\".","description":"Felix Stalder is Professor at the Department Fine Arts, Zurich University of the Arts, where he leads the artistic research project \"Latent Spaces. Performing Ambiguous Data\". His work focusses on the intersection of technological, political, and cultural dynamics, in fields such as techno-culture, commons, subjectivity, datafication, artificial intelligence, and more-than-human relations. Besides doing research, he also works as a cultural producer with groups such as Technopolitics, World Information Institute and nettime, creating maps (\"Infrastructure of a Migratory Bird, 2022-3, with Vladan Joler and Gordan Savicic), videos (Civilization, Technology and Consciousness – Peter Lamborn Wilson / Hakim Bey, 58 min, 2022, with Konrad Becker) and autonomous infrastructures (Mastodon Instance of nettime, since Okt. 2022). From 1998-2023 he was a moderator of nettime, an international mailing list for critical net.culture. Sinece 2022, he co-moderares a Mastodon instance (tldr.nettime.org). Among his most recent book publications are \"From Commons to NFTs\" (co-editor, Aksioma, 2022), \"Digital Unconscious\" (co-editor, Autonomedia, 2022), \"Aesthetics of the Commons\" (co-editor, Diaphanes, 2021) and \"Digital Condition\" (Politiy Press, 2018).","links":[{"url":"https://felix.openflows.com/","title":"Personal Blog"}]}],"start_time":"2023-12-28T11:00:00.000+01:00","end_time":"2023-12-28T11:40:00.000+01:00","room":{"name":"Saal Zuse","id":473}},{"id":12214,"guid":"1fdc5035-9658-4e37-9d1c-3f39efcaf5b2","title":"Investigating the Iridium Satellite Network","subtitle":null,"description":"We'll cover a whole range of topics related to listening to Iridium satellites and making sense of the (meta) data that can be collected that way:\r\n\r\n - Overview of new antenna options for reception. From commercial offerings (thanks to Iridium Time and Location) to home grown active antennas.\r\n - How we made it possible to run the data extraction from an SDR on just a Raspberry Pi.\r\n - Running experiments on the Allen Telescope Array.\r\n - Analyzing the beam patterns of Iridium satellites.\r\n - Lessons learned in trying to accurately timestamp Iridium transmissions for future TDOA analysis.\r\n - What ACARS and Iridium have in common and how a community made use of this.\r\n - Experiments in using Iridium as a GPS alternative.\r\n - Discoveries in how the network handles handset location updates and the consequences for privacy.\r\n - Frame format and demodulation of the Iridium Time and Location service.","duration":3600,"logo":null,"type":"lecture","do_not_record":false,"track":"Hardware \u0026 Making","abstract":"The Iridium satellite (phone) network is evolving and so is our understanding of it. Hardware and software tools have improved massively since our last update at 32C3. New services have been discovered and analyzed. Let's dive into the technical details of having a lot of fun with listening to satellites.","speakers":[{"guid":"044d6092-9e0d-517b-bf1e-565313d2e2c2","id":5339,"image":null,"name":"schneider","public_name":"schneider","abstract":"Embedded software and hardware engineer, member of muCCC.","description":"Likes to hit the „Remote Update“ button for thousands of devices every now and then.","links":[{"url":"https://github.com/schneider42","title":"https://github.com/schneider42"}]},{"guid":"34d34347-0cac-5caa-88f9-6bfc2601d8c4","id":2506,"image":"/system/people/avatars/000/002/506/original/101.jpg?1360200783","name":"Sec","public_name":"Sec","abstract":"Hacking (for) the club since 1997","description":"Sec is a longtime member of the CCC, one of the founders of the Munich CCC group and known for his presentation of Hacker Jeopardy together with ray on various hacker events over the last 10+ years as well as some reverse-engineering of the iridium communication system. \r\n","links":[]}],"start_time":"2023-12-29T23:00:00.000+01:00","end_time":"2023-12-30T00:00:00.000+01:00","room":{"name":"Saal Grace","id":472}},{"id":12056,"guid":"ff19d6f0-3f7b-4c4a-a33f-f53b061a2216","title":"Ist die Demokratie noch zu retten? ","subtitle":"Politikwissenschaftliche Demokratieforschung in der Krise","description":"Der Vortrag ist eine allgemeinverständliche Einführung in die Demokratietheorie in Krisenzeiten. Er stellt zuerst die wichtigsten Demokratietheorien aus der Politikwissenschaft vor: Was ist Demokratie? Und wie sieht eine gut funktionierende Demokratie in der Praxis aus? Anschließend werden die Problemdiagnostik und die Ursachenforschung behandelt: Was stimmt aus wissenschaftlicher Sicht nicht mit der Demokratie? Ist sie in der Krise oder liegen die Probleme woanders? Zum Schluss stehen Lösungswege und Reaktionsmöglichkeiten zur Diskussion: Bieten Politikwissenschaft und Demokratietheorie praktikable Lösungsansätze? Oder sind sie selbst in einer Krise, weil sie keine Lösungswege aufzeigen können?","duration":2400,"logo":null,"type":"lecture","do_not_record":false,"track":"Science","abstract":"Demokratie ist eine gute Idee, funktioniert aber nicht in der Praxis. So die Meinung vieler Menschen, die vor dem Hintergrund von Klimakrise, Infrastrukturerosion und Regierungsversagen an der Zukunftsfähigkeit der Demokratie zweifeln. Wie reagiert die Politikwissenschaft darauf und kann die Demokratietheorie Lösungswege aufzeigen?","speakers":[{"guid":"a23f801d-6dd6-57d7-bc21-5c059cb26e36","id":19360,"image":null,"name":"Veith Selk","public_name":"Veith Selk","email":"selk@pg.tu-darmstadt.de","abstract":"I am a political scientist specializing in democracy and populism. My aim is to bring unconventional and provocative perspectives to the academic debate. I have also recently become involved in science transfer, i.e. the exchange and discussion of scientific findings outside of universities. Recent publication: Not Everyone Can Be A Winner, Baby: A Pragmatist Response to Problems of Contemporary Crisis Studies, in: Philosophy and Social Criticism, (with Andy Scerri und Dirk Jörke). DOI: 10.1177/01914537221114911.","description":null,"links":[{"url":"https://veithselk.de","title":"Website Veith Selk"}]}],"start_time":"2023-12-27T22:05:00.000+01:00","end_time":"2023-12-27T22:45:00.000+01:00","room":{"name":"Saal 1","id":471}},{"id":11756,"guid":"a9b47ec2-1e9b-48e6-a8d3-e68236fb72dc","title":"KI im Klassenzimmer - ein Update!","subtitle":"Wie KI in der Schule wirklich entlasten könnte","description":"Schon länger experimentieren Bundesländer und Schulen zusammen mit EdTech-Unternehmen mit KI und Algorithmen in Learning Analytics-Programmen (LA) und sogenannten Intelligenten Tutor Systemen. Wie auch schon bei anderen technologischen Entwicklungen hängt auch bei KI die gesetzliche Regulierung der gelebten Praxis hinterher und Schulen oder auch Schulträger haben bislang keine rechtssichere Grundlage für die Arbeit mit KI. Noch. Doch bereits seit dem Frühjahr 2021 wird in Brüssel an der sogenannten KI-Verordnung gearbeitet, die diese Lücke schließen soll. Nun steht die KI-Verordnung kurz vor dem Abschluss und der Vortrag zeigt, was nun juristisch konkret auf Schulen, Schulträger oder Länder zukommen kann, und gibt ein Update zu den technischen und pädagogischen Herausforderungen, die der Einsatz von KI in der Schule mitbringt. Nur wenn KI richtig und geplant beschafft, eingesetzt und begleitet wird, kann sie zu Entlastungseffekten führen. Der Vortrag stellt die nötigen Schritte vor.    ","duration":2400,"logo":null,"type":"lecture","do_not_record":false,"track":"Ethics, Politics \u0026 Society","abstract":"Seit ChatGPT ist das Thema Künstliche Intelligenz mittlerweile an fast allen Schulen angekommen. Immer noch soll KI Lehrkräfte entlasten, doch mit der kommenden KI-Verordnung kann sich die Belastung einfach nur verschieben. Der Vortrag gibt ein Update zum Vortrag von der #rC3 2020, was nun konkret auf Schulen zukommen kann und wie KI tatsächlich zu Entlastungen beitragen kann. ","speakers":[{"guid":"a5b9013c-96c3-557a-9f08-f26042cf44ed","id":9014,"image":null,"name":"Nina  Galla","public_name":"Nina  Galla","abstract":"Nina hat zwei Jahre lang die Fraktion DIE LINKE in der Enquete-Kommission KI im Bundestag begleitet und aktiv im Kapitel \"KI und Bildung\" mitgewirkt. Heute ist sie wissenschaftliche Mitarbeiterin der bildungspolitischen Sprecherin der Fraktion. In der Netzpolitik ist Nina seit 10 Jahren aktiv, Bildungsarbeit macht sie seit 5 Jahren.  ","description":null,"links":[]}],"start_time":"2023-12-30T13:50:00.000+01:00","end_time":"2023-12-30T14:30:00.000+01:00","room":{"name":"Saal Grace","id":472}},{"id":11937,"guid":"ce4743cc-50ad-4597-bcc8-58e1a7e53c20","title":"KI – Macht – Ungleichheit.","subtitle":"Was ist die soziale Dimension von Nachhaltigkeit und warum ist sie durch KI gefährdet?","description":"In Debatten zu KI und Nachhaltigkeit steht zurecht der enorme Ressourcenverbrauch von KI am Pranger. Aber wir dürfen nicht vergessen, dass es bei Nachhaltigkeit um noch viel mehr geht. Mindestens 7 der 17 Nachhaltigkeitsziele der UN verweisen auf soziale Dimensionen: Gleichheit, Anti-Diskriminierung, Zugang zu Bildung, Abbau von ökonomischer Ungleichheit und Ausbeutung. Der Vortrag diskutiert, dass künstliche Intelligenz, wenn sie nicht besser reguliert wird, diesen Zielen entgegensteht. Das liegt nicht nur daran, dass KI-Systeme Biases haben und sich diskriminierend auswirken. Sondern noch fundamentaler beruhen die meisten kommerziellen KI-Systeme auf sozialer und wirtschaftlicher Ausbeutung. Global wie lokal werden Nutzer:innen als Datenlieferant:innen und Gig-Arbeiter:innen als günstige Arbeitskräfte eingespannt. Unser Denken, Fühlen und Handeln wird in allen Lebensbereichen datafiziert; ökonomische Machtgradienten zwischen Globalem Norden und Süden werden für die Aufbereitung von Daten ausgebeutet. Viele KI-Systeme erzeugen ihre Intelligenzleistung nicht im Rechenzentrum, sondern durch das Auslesen menschlicher kognitiver Leistungen an den digitalen Interfaces, die wir täglich nutzen – Beispiele reichen von der Google-Suche über Gesichtserkennung bis ChatGPT. KI-Unternehmen machen von den niedrigen Arbeitsschutzstandards und Lohnniveaus in anderen Ländern Gebrauch und produzieren Krankheit und Prekarität bei den betroffenen Arbeiter:innen. Um gute Regulierung zu erreichen, müssen wir KI-Systeme als soziotechnische Systeme betrachten. Das ermöglicht ein reichhaltigeres Verständnis der sozialen Dimension von Nachhaltigkeit, um global steigender Ungleichheit und Ausbeutung durch KI-Systeme etwas entgegenzusetzen. ","duration":2400,"logo":"/system/events/logos/000/011/937/original/sustainability-image.png?1701509967","type":"lecture","do_not_record":false,"track":"Sustainability \u0026 Climate Justice","abstract":"KI beruht auf der weltweiten Ausbeutung nicht nur natürlicher, sondern auch sozialer Ressourcen. Um KI nachhaltig zu gestalten, müssen wir algorithmischer Diskriminierung und sozialer Selektion, der Ausbeutung und Prekarisierung digitaler Arbeit und der Tendenz eines neuen, digitalen Kolonialismus entgegentreten. ","speakers":[{"guid":"0acfcce8-4b3a-531a-9868-33fd2dfb0585","id":5454,"image":"/system/people/avatars/000/005/454/original/rainer-neu600c.jpg?1699522687","name":"Rainer Mühlhoff","public_name":"Rainer Mühlhoff","abstract":"Rainer Mühlhoff, philosopher and mathematician, is full professor of Ethics of Artificial Intelligence at the University of Osnabrück. They explore ethics, data protection, and critical social theory in the digital society. Through systemic analyses of AI capitalism and proposals to enhance data protection, Rainer engages in various extra-academic formats, regularly participating as a guest in political, educational, and public forums. In their research, Rainer examines AI systems as socio-technical systems (\"Human-Aided AI\"), coined the term \"Predictive Privacy,\" and advocates for the purpose limitation of AI  models. ","description":"In their earlier life, Rainer studied mathematics, physics, and computer science, working in the field of quantum physics. Through secondary studies in philosophy and gender studies, they transitioned into the critical humanities. Rainer's interdisciplinary team at the Ethics and Critical Theories of AI research group at the University of Osnabrück combines philosophy, media studies, and computer science to investigate the interplay of technology, power, and societal change.  \u003ca href=\"https://rainermuehlhoff.de/en/publications.html\"\u003e[List of publications]\u003c/a\u003e","links":[{"url":"https://rainermuehlhoff.de","title":"Homepage"}]}],"start_time":"2023-12-28T22:05:00.000+01:00","end_time":"2023-12-28T22:45:00.000+01:00","room":{"name":"Saal Grace","id":472}},{"id":12030,"guid":"f60110ec-38e4-4730-b906-5363e3a90f84","title":"KIM: Kaos In der Medizinischen Telematikinfrastruktur (TI)","subtitle":null,"description":"Die sichere E-Mail-Infrastruktur für Ärzt*innen, Apotheker*innen, Krankenversicherungen und Kliniken in Deutschland, KIM – Kommunikation im Gesundheitswesen – ist mit über 200 Millionen E-Mails in den letzten zwei Jahren eine der am meisten genutzten Anwendungen in der Telematikinfrastruktur (TI). KIM verspricht sichere Ende-zu-Ende-Verschlüsselung zwischen Heilberufler*innen in ganz Deutschland, wofür S/MIME-Zertifikate für alle medizinisch Beteiligten in Deutschland ausgegeben wurden.\r\n\r\nWas aber passiert, wenn man die Schlüsselausgabe-Prozesse in der TI falsch designt? Was passiert, wenn man unsichere Software im Feld nicht patcht? Was passiert, wenn man zu viel Sicherheit vor den Nutzenden abstrahieren möchte?\r\n\r\nDie Antwort: Man bekommt eine theoretisch kryptographisch sichere Lösung, die in der Praxis die gesteckten Ziele nicht erreicht.\r\n\r\nAlle gefundenen Schwachstellen wurden den Betroffenen im Rahmen abgeschlossener Responsible Disclosure-Prozesse mitgeteilt.","duration":3600,"logo":null,"type":"lecture","do_not_record":false,"track":"Security","abstract":"Elektronische Arbeitsunfähigkeitsbescheinigungen (eAU), Arztbriefe, medizinische Diagnosen, all diese sensiblen Daten werden heute mittels KIM – Kommunikation im Gesundheitswesen – über die Telematikinfrastruktur (TI) verschickt.\r\n\r\nAber ist der Dienst wirklich sicher? Wer kann die Nachrichten lesen, wo werden die E-Mails entschlüsselt und wie sicher ist die KIM-Software? Im Live-Setup einer Zahnarztpraxis haben wir Antworten auf diese Fragen gesucht.","speakers":[{"guid":"6e5dce83-f438-522b-8ab0-09dcd1211021","id":9222,"image":"/system/people/avatars/000/009/222/original/christoph_small.jpg?1577128589","name":"Christoph Saatjohann","public_name":"Christoph Saatjohann","abstract":"IT Security PhD student at Muenster University of Applied Sciences.\r\nPreviously 9 years in embedded/automotive IT Security.\r\n","description":null,"links":[{"url":"https://www.fh-muenster.de/eti/personen/mitarbeiter/saatjohann/saatjohann.php","title":"Mitarbeiterseite der FH Münster"}]},{"guid":"25c2b6fb-76a0-5cfd-b105-e419dd518877","id":3205,"image":"/system/people/avatars/000/003/205/original/tree.jpg?1538121372","name":"Sebastian Schinzel","public_name":"Sebastian Schinzel","abstract":"Sebastian is a professor for IT security at Münster University of Applied Sciences.","description":"Since 2013, Sebastian leads the IT Security Lab at Münster University of Applied Sciences. His research interests involve applied cryptography, software security and side channel attacks.","links":[{"url":"https://sebastian-schinzel.de/?c","title":"Homepage"},{"url":"https://twitter.com/seecurity","title":"Twitter"}]}],"start_time":"2023-12-27T16:00:00.000+01:00","end_time":"2023-12-27T17:00:00.000+01:00","room":{"name":"Saal Zuse","id":473}},{"id":12139,"guid":"afbccf41-b658-4ab6-826d-73abc5e5a578","title":"Klimafreundliche Digitalisierung: Koalitionsvertrag vs. Wirklichkeit","subtitle":"Von Rechenzentren bis Software – wo muss und wie kann die Bundes-IT nachhaltiger werden?","description":"Der Bund kauft jährlich für 260 Mrd. € ein, auch für mehr als 1 Mrd. IT, er betreibt über 180 Rechenzentren, förderte in 2023 über 400 KI-Projekte, setzt selbst über 100 Mal KI-Systeme ein und hat noch aus vielen weiteren Gründen mit seiner IT eine erhebliche Klimawirkung. Wie die GroKo hat sich auch die Ampel auf die Fahnen geschrieben, die Digitalisierung klimafreundlicher zu machen, ganz allgemein – durch Regulierung für alle (z. B. im Energieeffizienzgesetz), aber auch in eigener Verantwortung, bei den eigenen Rechenzentren, Software oder IT-Dienstleistungen. Die Ankündigungen dazu sind wohltönend, z. B. im Koalitionsvertrag und in der Digitalstrategie. Bundesbehörden und Rechenzentren sollen klimafreundlich(er) werden, es soll mehr Transparenz geben, z. B. über ein Energieeffizienzregister für Rechenzentren, es wurde versprochen, dass Vergabeprozesse die Nachhaltigkeit berücksichtigen sollen, auch beim Einkauf von IT und IT-Dienstleistungen, z. B. durch standardmäßigen Einkauf von IT mit Blauem Engel – auch bei Software. Selbst der Ausbau der Gigabitinfrastruktur sollte nachhaltiger werden. Aber passiert das alles auch?\r\n\r\nIch nutze meine parlamentarischen Rechte als Bundestagsabgeordnete der Opposition (DIE LINKE), um über schriftliche Fragen und Kleine Anfragen Fakten dazu öffentlich zu machen und die große Kluft zwischen Anspruch und Wirklichkeit zu zeigen. Dabei geht es einerseits um das Vorhandensein von Daten (you get what you measure!) – tatsächlich also um einen Mangel an Transparenz zur Baseline – und andererseits um die Daten selbst, also wie gut oder schlecht die Nachhaltigkeit jeweils ist.\r\n\r\nEinen Schwerpunkt lege ich dabei auf die Klimafreundlichkeit von Rechenzentren, aber auch zu anderen Themen gibt’s für Euch Fakten: zur Wiederverwendung von Hardware, zum Recht auf Reparatur und der (versprochenen!) Förderung von Reparatur-Initiativen, zur Berücksichtigung von Nachhaltigkeitsaspekten bei der Vergabe von Hunderten Millionen Euro Fördergelder für KI-Projekte, zu Websites, Software und mehr. Da ich seit mehreren Jahren zur Nachhaltigkeit der Bundes-IT Kleine Anfragen stelle und die Digitalpolitik der Bundesregierung aus dem Maschinenraum des Bundestages verfolge, kann ich auch die Entwicklung beschreiben und werde Euch zeigen, wie die Ampel-Regierung sich einfach die Latte immer niedriger hängt und vermutlich trotzdem kaum eines ihrer Nachhaltigkeitsziele erreichen wird. Beim 37C3 werde ich erstmalig die Ergebnisse meiner jüngsten Anfrage vom November 2023 öffentlich vorstellen.\r\n\r\nBei aller Frustration über den Status Quo zeigt mein Vortrag aber auch, welche riesigen Potenziale noch gehoben werden könnten, um tatsächlich eine nachhaltigere Digitalisierung zu erreichen – und dafür ist es nie zu spät! ","duration":2400,"logo":"/system/events/logos/000/012/139/original/Bildschirmfoto_2023-11-11_um_20.03.45.png?1699729452","type":"lecture","do_not_record":false,"track":"Sustainability \u0026 Climate Justice","abstract":"Wie der Bund seine IT einkauft und betreibt, hat eine erhebliche Auswirkung auf das Klima.\r\n\r\nGroKo und Ampel-Regierung waren und sind daher groß im Ankündigen grüner IT: in digitalpolitischer Umweltagenda, Koalitionsvertrag, Digitalstrategie und Gigabitstrategie. Wie weit Anspruch und Wirklichkeit auseinanderklaffen, erfrage ich als Bundestagsabgeordnete regelmäßig mit Kleinen Anfragen und schriftlichen Fragen. Ich verspreche kleine Hoffnungsschimmer, aber auch Frustration, denn meine neueste Anfrage vom November 2023 deckt schonungslos auf, wie intransparent und wie wenig nachhaltig die IT des Bundes immer noch ist und wie die Ampel sich die Latte immer tiefer hängt und trotzdem nicht drüber kommt.\r\n\r\nDas Potenzial des Bundes als Großverbraucher (z. B. mit über 180 Rechenzentren), als Finanzierer (z. B. von über 400 KI-Projekten) und als Regulierer (z. B. beim Energieeffizienzgesetz oder beim Überbau von Glasfaser) ist aber riesig, auch das werde ich vermitteln und die Stellschrauben beschreiben, an denen man drehen könnte, um IT weniger klimaschädlich zu machen – auch außerhalb des Bundes.  ","speakers":[{"guid":"ef3b5469-61f8-5650-98a7-07afb2468443","id":19406,"image":"/system/people/avatars/000/019/406/original/ADB-Hanffabrik-MelissaMeyer-Ausschnitt.png?1699721528","name":"Anke Domscheit-Berg","public_name":"Anke Domscheit-Berg","abstract":"Netzaktivistin, seit 2017 digitalpol. Sprecherin der Linken im Bundestag, Mitglied im Digitalausschuss, Beirat Bundesnetzagentur \r\nSelbstverständnis als \"langer Arm\" der digitalen Zivilgesellschaft im Parlament. \r\nFokus: Digitalisierung und Klimakrise, Digitalisierung und Gemeinwohl. \r\nEhrenamt: v.a. Makerspace Verstehbahnhof in Fürstenberg/Havel, Beirat Agora Digitale Transformation\r\nHintergrund: 15 Jahre IT-Branche (Accenture, McKinsey Business Technology Office, Microsoft)\r\nprivat: 55 J, Brandenburgerin, Heizung: Abwärme vom RZ im Keller, 5 Katzen, spinnt viel (Garn)","description":"Seit 2017 im Dt. Bundestag als digitalpolitische Sprecherin für die Linken aktiv, bis Dez. 2023 Obfrau im Digitalausschuss und in der IuK Kommission des Bundestages, stellv. Mitglied im Ausschuss für Bildung, Forschung, Technikfolgen, im Ausschuss für Entwicklungszusammenarbeit, im Beirat der Bundesnetzagentur. Meine digitalpolitischen Wurzeln liegen im Netzaktivismus: v.a. für Bürgerrechte in der digitalen Gesellschaft und Open Government. \r\nMeine politischen Schwerpunkte: Schnittstellen von Klimakrise und Digitalisierung, Gemeinwohlorientierte Digitalisierung, das reicht von Zugang u Teilhabe über Open Everything bis Globaler Süden und Digitale Gewalt. In meiner pol. Arbeit verbinden sich viele Themen: Klimakrise, Entwicklungszusammenarbeit, Hype-Folgen von Blockchain bis KI, digitale Monopole, Recht auf Reparatur, der Umgang mit Daten, Diskriminierung und Bias. Digitalisierung bei uns hat Folgen: Lithium aus Bolivien zu Lasten der Indigenen Bevölkerung? Westlicher eSchrott in Ghana? Kobalt aus dem Kongo mit Kinderarbeit? Goldabbau im kolumbianischen Amazona, der mit Quecksilber Flüsse vergiftet? Ausgebeutete Content Moderatoren in Kenia? Sexualisierte Gewalt an Kindern für Livestreams in DE? \r\nIch nutze alle verfügbaren Werkzeuge, die ich als Oppositionspolitikerin habe, um Druck auf die Ampel-Regierung auszuüben, vor allem durch parlamentarische Initiativen, wie Kleine Anfragen, um Informationen zu befreien und öffentlich zu machen, wo die Ampel den Koalitionsvertrag bricht, warum sie bei der Digitalisierung scheitert und um echte Veränderungen in der Politik zu erreichen. \r\nVor dem Bundestag war ich 6 Jahre selbständig als Publizistin, Buchautorin, Kolumnistin (Frankfurter Rundschau) und davor ca. 15 Jahre in der IT-Branche, bei Microsoft, McKinsey Business Technology Office und Accenture, v.a. als Beraterin und Projektleiterin.\r\nEhrenamtlich bin ich Komplizin meines Mannes Daniel Domscheit-Berg, v.a. im Verstehbahnhof Fürstenberg, einem großartigen Makerspace mit Audio-/Videostudio im Keller, einem offenen Kunst- und Druckatelier (Kreativraum) u einem Co-Learning Space für Kinder. Wir machen gemeinwohlorientierte Digitalisierung einfach selbst, von Abwärmenutzung unseres Keller-RZ, wo viele gemeinnützige Initiativen ihr digitales Zuhause haben, bis zum Aufbau eines bedingungslosen Internetzugangs für Mensch und Maschine in unserer Kleinstadt. \r\nIch bin 55 Jahre alt, ost-sozialisiert und lebe in Brandenburg, mit Mann und 5 Katzen und seit ich beim 36C3 Spinnen lernte, spinne ich mein eigenes Garn aus allem was geht, tierisch oder pflanzlich: Hund oder Hanf, Schaf oder Soja, Alpaka oder Ziege, Katze oder Seidenraupe. \r\n","links":[{"url":"https://mdb.anke.domscheit-berg.de/","title":"Homepage"},{"url":"https://twitter.com/anked","title":"Twitter/X"},{"url":"@ankedb@social.linksfraktion.de","title":"Mastodon"},{"url":"@ankedb.bsky.social","title":"Bluesky"}]}],"start_time":"2023-12-27T20:15:00.000+01:00","end_time":"2023-12-27T20:55:00.000+01:00","room":{"name":"Saal 1","id":471}},{"id":11784,"guid":"df5ca65a-e3d6-42ae-9805-9bc02821ada4","title":"Lass mal das Innere eines Neuronalen Netzes ansehen!","subtitle":null,"description":"Brauchen wir wirklich einen weiteren Vortrag über Künstliche Intelligenz? In den letzten Jahren war das Thema omnipräsent, Bilder werden jetzt generiert, Texte nicht mehr selbst geschrieben und ob ich kreditwürdig bin, prüft auch so eine KI. Und wer weiß, neulich klang der Chat Bot richtig menschlich, vielleicht hat er ja doch ein Bewusstsein. \r\nIn diesem Vortrag geht es nicht um tolle Errungenschaften von KI-Systemen oder um „30 Prompts, mit denen du noch effektiver bist!“. Dieser Vortrag legt den Grundstein für ein Verständnis von maschinellem Lernen mit dem Ziel, dass du am Ende selbst die aktuellen Entwicklungen einschätzen kannst: Übertrumpfen Neuronale Netze irgendwann wirklich den Menschen? Oder können sie im Grunde gar nichts und sind massiv fehleranfällig? Und die Frage aller Fragen: Hat künstliche Intelligenz ein Bewusstsein oder steht kurz davor, eines zu entwickeln? Über all das kannst du dir nach dem Vortrag eine eigene fundiertere Meinung bilden. ","duration":2400,"logo":null,"type":"lecture","do_not_record":false,"track":"Science","abstract":"Nachdem in den letzten Jahren dauernd der Weltuntergang durch KI heraufbeschworen wurde, ist es an der Zeit nachzuschauen, was diese ominösen Neuronalen Netze (NN) eigentlich sind. Wir beginnen mit einer anschaulichen Erklärung, wie ein NN funktioniert und warum es keine wirkliche Ähnlichkeit mit deinem Gehirn hat. Anschließend schrauben wir die Black Box, wie es so schön heißt, einfach einmal auf: Wie können NN erklärbar gemacht werden? Warum trifft ein Neuronales Netz diese oder jene Entscheidung? Was an der politischen Forderung nach erklärbarer KI ist tatsächlich umsetzbar? Außerdem werden wir sehen, wie NN manchmal schummeln, um eine Vorhersage zu treffen. Im Gegenzug tricksen wir sie auch gezielt aus.","speakers":[{"guid":"cff4490e-dd66-5052-869a-342c07693579","id":19037,"image":null,"name":"Annika Rüll","public_name":"Annika Rüll","abstract":null,"description":null,"links":[]}],"start_time":"2023-12-30T11:00:00.000+01:00","end_time":"2023-12-30T11:40:00.000+01:00","room":{"name":"Saal 1","id":471}},{"id":11696,"guid":"ef9e6a6d-8084-4c2a-9cfa-15fc66a6867d","title":"Lightning Talks Day 2","subtitle":null,"description":"To get involved and learn more about what is happening please visit the Lightning Talks page in the 37C3 wiki.","duration":7200,"logo":null,"type":"lecture","do_not_record":false,"track":"CCC","abstract":"Lightning Talks are short lectures (almost) any congress participant may give! Bring your infectious enthusiasm to an audience with a short attention span! Discuss a program, system or technique! Pitch your projects and ideas or try to rally a crew of people to your party or assembly! Whatever you bring, make it quick!","speakers":[{"guid":"dd36cc4a-7bef-5d1e-b72c-6a3f8dddf91a","id":5263,"image":"/system/people/avatars/000/005/263/original/9156d604276247f1870f0d13020e20bb.png?1448987135","name":"gedsic","public_name":"gedsic","abstract":null,"description":null,"links":[]},{"guid":"84537663-d6d0-5289-a1b6-c7dd591029ac","id":4601,"image":"/system/people/avatars/000/004/601/original/bigalex.jpeg?1482358962","name":"bigalex","public_name":"bigalex","email":"bigalex@c3d2.de","abstract":null,"description":null,"links":[]}],"start_time":"2023-12-28T16:00:00.000+01:00","end_time":"2023-12-28T18:00:00.000+01:00","room":{"name":"Saal Grace","id":472}},{"id":12241,"guid":"4bc85b0a-a1df-477b-8e1f-a493e5cc8017","title":"Link-Extremismus und Pressefreiheit","subtitle":"Das Strafverfahren gegen Radio Dreyeckland","description":"Im Januar 2023 kam es zu Durchsuchungen der Redaktionsräume des Senders Radio Dreyeckland sowie der Wohnungen zweier Journalisten. Anlass der Durchsuchungen und der Beschlagnahme mehrerer Laptops war ein Artikel des Senders, in dem auf ein Archiv von linksunten.indymedia verlinkt wurde. Die Internetplattform war 2017 nach Vereinsrecht verboten worden. Die Staatsschutzabteilung der Staatsanwaltschaft Karlsruhe sieht in dem Artikel eine strafbare Unterstützung einer verbotenen Vereinigung. Das Oberlandesgericht Stuttgart hat inzwischen – anders als zuvor das Landgericht – die Anklage gegen den Journalisten zugelassen und entschieden, dass die Durchsuchung rechtmäßig war. Die Hauptverhandlung soll im kommenden Jahr stattfinden.\r\n\r\nDer Vortrag gibt einen Einblick in das Verfahren und ordnet es kritisch ein. Dabei wird insbesondere der Frage nachgegangen, wie Links rechtlich zu bewerten sind und wie der Staat gegen (linke) Medien vorgeht.","duration":2400,"logo":null,"type":"lecture","do_not_record":false,"track":"Ethics, Politics \u0026 Society","abstract":"Ein Journalist von Radio Dreyeckland steht vor Gericht, weil er das Archiv der verbotenen Internetplattform linksunten.indymedia verlinkt hat. Der Vortrag gibt einen Einblick in das Verfahren und zeigt, wann Links strafbar sein können – und wann nicht.","speakers":[{"guid":"f483675c-b6c2-5e87-844f-e6f83f26ec2d","id":19456,"image":"/system/people/avatars/000/019/456/original/David-Werdermann-Porträt.jpg?1699740404","name":"David Werdermann","public_name":"David Werdermann","abstract":"David Werdermann ist Rechtsanwalt und Verfahrenskoordinator bei der Gesellschaft für Freiheitsrechte.","description":"David Werdermann ist Rechtsanwalt und Projektkoordinator bei der GFF. Er studierte Jura in Freiburg und Manila. Anschließend arbeitete und forschte er als wissenschaftlicher Mitarbeiter am Institut für Staatswissenschaft und Rechtsphilosophie der Universität Freiburg zum Migrations- und Verfassungsprozessrecht. Sein Referendariat absolvierte er unter anderem bei der Antidiskriminierungsstelle des Bundes, bei der GFF, in einer aufenthaltsrechtlichen Kanzlei in Berlin und beim Bundesverfassungsgericht. Zuletzt erwarb er einen LL.M. in International Migration and Refugee Law an der Vrije Universiteit Amsterdam, wo er sich vor allem mit den sozialen Rechten von Migrant*innen beschäftigte. Neben seiner Tätigkeit bei der GFF arbeitet David als Rechtsanwalt in einer Kanzlei für Informationsfreiheitsrecht.","links":[{"url":"https://freiheitsrechte.org","title":"Gesellschaft für Freiheitsrechte"}]}],"start_time":"2023-12-30T12:00:00.000+01:00","end_time":"2023-12-30T12:40:00.000+01:00","room":{"name":"Saal Grace","id":472}},{"id":12077,"guid":"b805f8c3-b43d-42b9-9037-4ccab656e04a","title":"Lützerath Lebt! Einblicke in den Widerstand","subtitle":" Für globale Klimagerechtigkeit kämpfen","description":"You can't evict a movement! Der Energiekonzern RWE wird noch Jahre brauchen, die Kohle unter Lützi abzubaggern: Der Kampf gegen die Kohle und für Klimagerechtigkeit geht weiter! \r\n\r\n\r\n","duration":2400,"logo":"/system/events/logos/000/012/077/original/cropped-luetzerathlebtfinal_zeichenflaeche-1.png?1699704175","type":"lecture","do_not_record":true,"track":"Sustainability \u0026 Climate Justice","abstract":"Mobilisierung von Menschen nach Lützerath, Bauvorkehrungen zur Verteidigung treffen, die Räumungsvorbereitungen von RWE und Polizei stören, Infrastruktur-Ausbau trotz abgeschalteten Stroms, auf Presse-Anfragen aus der ganzen Welt reagieren, WLAN für alle, Live-Berichterstattung üben, Kommunikationswege absichern, Wetten dass?! gewinnen, dem kalten Wetter trotzen, sich mit andern Kämpfen solidarisieren und heimlich einen Tunnel graben.\r\n\r\nVor einem Jahr liefen die Vorbereitungen gegen die Räumung Lützeraths am größten Drecksloch Europas, Kohletagebau Garzweiler II, auf Hochtouren. Wir wollen Einblicke in diese und andere Themen geben.","speakers":[{"guid":"cc33f286-af76-55b0-bd56-212b018d89a4","id":19379,"image":null,"name":"Andrea Müller","public_name":"Andrea Müller","abstract":null,"description":null,"links":[]},{"guid":"cc33f286-af76-55b0-bd56-212b018d89a4","id":19537,"image":null,"name":"Andreas Schmidt","public_name":"Andreas Schmidt","abstract":null,"description":null,"links":[]}],"start_time":"2023-12-28T20:15:00.000+01:00","end_time":"2023-12-28T20:55:00.000+01:00","room":{"name":"Saal Zuse","id":473}},{"id":12297,"guid":"fd9d6c53-806e-4667-934d-7e589511f5a9","title":"Making homebrew for your very own Vector Super Computer","subtitle":"Adventures running a NEC Vector Engine for fun and ... community","description":"The talk will explain unfamiliar concepts in more common terms like:\r\nVector registers are just registers where CPUs can store multiple numbers which belong together and are processed independent of each other together in same operation. This allows a higher processing performance similar to how moving a pallet of same sized boxes can be quicker than just moving the boxes on their own.\r\n\r\nAnd will then use those new terms drawing comparisons like:\r\n512 bits long are the largest vector registers available with any other CPU available today compared to 16348 bits long vector registers of which each VE core has 64 of. This puts it in a class of its own among CPUs.\r\n\r\nIf you weren't scrared off by this you shouldn't find the talk to technical. If you have a deep grasp on computing technology and wonder if this talk might interesting then you will hear about some implementation choices from NEC drawing reactions deep from the Kubler-Ross stages of Grief. \r\n\r\nThere will be a short introduction to the VE instruction set highlight a few instructions which are \"fun\" or otherwise \"interesting\" and might have some general computing https://en.wikipedia.org/wiki/Fast_inverse_square_root trivia https://vaibhavsagar.com/blog/2019/09/08/popcount/ associtated. The different offloading modes of a VE are introduced, one of which is enterily novel and which also emphasizes the uniqueness and sheer quirkyness.\r\n\r\nPrograms executing on a Vector Engine run in a Linux environment thus one could make many applications run on this accelerator unlocking GPU like performance for them without a need for rewrites if said code can make use of these big vector registers and the massive memory bandwidth available to them. So it's unsupprising that it is enourmously fun to touch up identified bottelnecks and see some application get 200x faster with handful of fixes. We can call hardware homebrewed if we make 2048 run on it, can't we?\r\n\r\nThe presentation about hacks people which joined my \"vect.or.at\" Vector Engine PUBNIX (basically a shared linux computer) did will cover such speeds ups, mention the state of an ongoing attempt to port the Rust programming languages to it, attempts of digital perservationism and progress towards making the vector engine truely yours by \"rooting\" it to mess with hardware settings otherwise unavailable.\r\n\r\nThe introduction to HPC portion will be structured as an argument claiming \"A NEC Vector Engine would turn your (Linux) computer into a small super computer\" and use this as motivation to introduce what such a super computer or HPC cluster is, how you can make it work for you and common software packages used. A few performance \"tripping\" hazards also are mentioned.","duration":2400,"logo":null,"type":"lecture","do_not_record":false,"track":"Hardware \u0026 Making","abstract":"The NEC Vector Engine (VE) isn't a GPU. It's a member of the only family of vector computers still alive today. Imagine a second CPU with a different instruction set running on the same Linux system. While obscure, it's a very approachable and hackable platform that is an addictingly fun machine to program and allows you to play with all the technologies seen in high-performance computing (HPC) today. I am going to cover lightheartedly what a small community learned about this singular hardware they shared: bemoaning a dangerous power plug standard, (ab)using this scientific simulation power house to run code never intended, some firmware and driver reversing, \"rooting\" a VE and more. I will also be giving an introduction to core concepts in HPC with knowledge transferable to any other (university) computer cluster and hopefully encouraging students and scientists to use those by making them seem less alien and hostile.","speakers":[{"guid":"47a97c52-9388-5e62-92aa-a4208ea7c163","id":19367,"image":null,"name":"Johann-Tobias Schäg","public_name":"Johann-Tobias Schäg","abstract":null,"description":null,"links":[]}],"start_time":"2023-12-30T11:00:00.000+01:00","end_time":"2023-12-30T11:40:00.000+01:00","room":{"name":"Saal Grace","id":472}},{"id":12133,"guid":"dcb00c6f-0621-4555-979d-4937ea34d324","title":"Mobile reverse engineering to empower the gig economy workers and labor unions","subtitle":null,"description":"This talk will describe our efforts to introduce a new toolkit and mindset for unions and gig workers, which is essential in an era where, for a growing number of people, \"an app is their boss\".\r\n\r\nOur work highlights the critical role of technical literacy in improving workers' bargaining power, particularly in collective bargaining. By demystifying the technology that governs them, we aim to equip workers with the tools to assert their rights and shape a fairer working landscape.\r\n\r\nSince 2019, our team, back in time known as \u003ca href=\"https://tracking.exposed\"\u003eTracking.Exposed\u003c/a\u003e and now operating as \u003ca href=\"https://reversing.works\"\u003eReversing.Works\u003c/a\u003e, has focused on connecting mobile app reverse engineering with GDPR and workers' rights. We want to tell this story, all the missteps, the low-hanging fruit that hacktivists across Europe can grab, and the opportunities that new regulations open up in this sense.\r\n\r\nIn 2023, a \u003ca href=\"https://reversing.works/posts/2023/10/report-exercising-workers-rights-in-algorithmic-management-systems/\"\u003ereport\u003c/a\u003e written for the European Trade Union Institute summarized our investigation into Glovo, in this talk we'll talk about how to repeat the investigations and, with varying complexity, how unionist and activists can start identifying potential data breaches and labor rights violations in mobile apps used by gig economy workers.","duration":2400,"logo":null,"type":"lecture","do_not_record":false,"track":"Ethics, Politics \u0026 Society","abstract":"\u003ca href=\"https://reversing.works\"\u003eReversing.works\u003c/a\u003e will outline five years of experience linking trade unions, gig economy workers, GDPR and mobile app reverse engineering. Goal: to replicate an effective form of resistance.","speakers":[{"guid":"f679d971-466a-55c6-960f-f22703b0c9f0","id":4912,"image":"/system/people/avatars/000/004/912/original/headshot-modded.jpg?1701815756","name":"Claudio Agosti","public_name":"Claudio Agosti","email":"vecna@globaleaks.org","abstract":"against the \u003ca href=\"https://tracking.exposed\"\u003ealgorithm hegemony\u003c/a\u003e.","description":"Platform auditor, Digital Rights Activist. I like to code, reverse engineer and explore with \u003ca href=\"https://aiforensics.oth\"\u003eAI Forensics\u003c/a\u003e, \u003ca href=\"https://hermescenter.org\"\u003eHermes Center\u003c/a\u003e, and \u003ca href=\"https://reversing.works\"\u003eReversing Works\u003c/a\u003e.\r\n\r\nIn 2023 I also worked on a campaign to persuade European politicians to completely ban facial recognition in public spaces \u003ca href=\"https://dontspy.eu\"\u003edontspy.eu\u003c/a\u003e but, fuck it, they did it anyway. ","links":[{"url":"https://linktre.ee/claudio.agosti","title":"linktree"}]},{"guid":"26e9ad0e-60c6-56cd-9e74-92c4717d4c6f","id":19572,"image":null,"name":"Gaetano Priori","public_name":"Gaetano Priori","abstract":null,"description":null,"links":[]}],"start_time":"2023-12-30T11:00:00.000+01:00","end_time":"2023-12-30T11:40:00.000+01:00","room":{"name":"Saal Zuse","id":473}},{"id":12268,"guid":"99b87729-3aa6-442b-83d6-9b1eb06b7e81","title":"**Music on Mars? A Musical Adventure for Astronauts and the Space Cadets Who Love Them.**","subtitle":"**Simulating the Acoustics of Mars for a Concert of Martian Music by Scott Beibin (aka Ptelepathetique)","description":"Using the SuperCam microphone mounted on the Mars Perseverance Rover, the sounds of the Martian environment were observed for the first time. A recording was made not only of the rush of martian wind, but also of the sounds of the Perseverance rover motors, the mechanical parts of the Ingenuity rotorcraft, the popping sound of laser sparking on stone and the sounds from other instruments on board. These audio samples served as as reference sources in order to compare the acoustic processes of Earth and Mars. It was discovered that:\r\n\r\n- The acoustic impedance of the martian atmosphere results in approximately 20 dB weaker sounds on Mars than on Earth (if produced by the same source.)\r\n\r\n- The acoustic attenuation range on Mars was discovered to be roughly between 20Hz to 20kHz.\r\n\r\n- On Mars low-pitched sounds travel at about 240 m/s (537 mph) while higher-pitched sounds move at 250 m/s (559 mph) due to the low atmospheric pressure 0.6 kPa (170 times lower than on Earth) and 97 percent CO2-dominated atmosphere (compared to 0.04 percent CO2 on Earth).\r\n\r\nThe results were published by NASA in Journal Nature as to these findings.   [https://www.nature.com/articles/s41586-022-04679-0] and on the Nasa website [https://mars.nasa.gov/mars2020/participate/sounds\r\n\r\nReferencing the paper published by NASA in Journal Nature as to these findings, analog astronaut and MDRS 286 crew artist Scott Beibin worked with master audio engineer John Knott to develop a software filter that could be used during Ptelepathetique concert performed during a two week immersive astronaut training in order to simulate the sounds of Mars.\r\n\r\nDuring the talk at 37C3 Beibin will discuss and demonstrate the comparison between the acoustic properties of the atmospheres of Earth and Mars via a demonstration of the software as well as musical Ptelepathetique performance.\r\n\r\nDuring the talk he will also present a short summary of the design patterns of the The Mars Desert Research Station which is used to train astronauts, researchers and students for offworld expeditions to the Red Planet. Additionally he will touch on the other aspects of his mission including 3D scanning of the surrounding geology as well as 3D printing of objects useful at the base using locally gathered and processed clay. \r\n\r\nThis should be an out-of-this-world treat for the Space Cadet hackers and others who like making astronauts out of themselves. \r\n\r\n\r\n++ Ptelepathetique is a musical project of inventor, engineer and artist Scott Beibin that focuses on the creation of instrumental cinematic psychoacoustic soundscapes designed to stimulate focus and creativity. Concerts usually happen outdoors in natural settings while using off-grid generated power while consisting of a mix of original musical composition as well as improvisation. Ptelepathetique is also the soundtrack for Beibin's projects The Groucho Fractal Show, AncientScan and the Mandelbot Ecotech Roadshow. \r\n\r\n++ The Mars Desert Research Station (MDRS) is a Space analog facility in Utah that supports Earth-based research in pursuit of the technology, operations, and science required for human space exploration. The remotely isolated facility created by The Mars Society offers scientists, engineers and students rigorous training for human operations on Mars as is surrounded by a landscape that is an actual geologic Mars analog.\r\n\r\n\r\nUsing recordings from the SuperCam microphone mounted on the Mars Perseverance Rover, the acoustic processes of the Martian environment were characterized for the first time. The microphone on board the rover recorded the Ingenuity rotorcraft and laser-induced sparks as as audio reference sources.\r\n\r\nIt was discovered that:\r\n- The acoustic impedance of the martian atmosphere results in approximately 20 dB weaker sounds on Mars than on Earth (if produced by the same source.)\r\n- The acoustic attenuation range on Mars was discovered to be roughly between 20Hz to 20kHz.\r\n- Two different speeds of sound were observed on Mars. Low-pitched sounds travel at about 240 meters per second (537 mph) while higher-pitched sounds move at 250 meters per second (559 mph) due to the low pressure 97 percent CO2-dominated atmosphere (compared to 0.04 percent CO2 on Earth).\r\n- The atmospheric pressure on Mars is about 0.6 kPa (170 times lower than on Earth).\r\n","duration":2400,"logo":"/system/events/logos/000/012/268/original/IMG_6026.jpeg?1701697458","type":"lecture","do_not_record":false,"track":"Art \u0026 Beauty","abstract":"\r\nDuring Mission 286 in November 2023 at the Mars Desert Research Station (MDRS), analog astronaut and crew artist Scott Beibin (aka Ptelepathetique) @scottbeibin performed several concerts of original live musical compositions during a two week immersive astronaut training. The concerts were played through a custom audio filter based on data gathered by the NASA Mars Perseverance Rover and created to simulate the acoustic properties of Mars - designed by Beibin and master audio engineer, John Knott. The live sets were performed in the MDRS Science Dome as well as during EVAs while navigating the desolate terrain in a simulation space suit - at sunset with the MDRS base and remote Mars-like Utah desert serving as a backdrop. This event was the first time in the 20 year history of the training facility that a music concert has been performed. \r\n\r\nThe presentation at 37C3 will be the first time this talk is being presented publicly. \r\n\r\nAdditionally a full Ptelepathetique concert featuring Music of Mars will happen (Please check the schedule / fahrplan)\r\n","speakers":[{"guid":"8b2fcad7-5bcd-5d40-b2c9-3c91bd4aba61","id":19466,"image":null,"name":"Scott Beibin","public_name":"Scott Beibin","abstract":null,"description":null,"links":[]}],"start_time":"2023-12-27T21:10:00.000+01:00","end_time":"2023-12-27T21:50:00.000+01:00","room":{"name":"Saal Zuse","id":473}},{"id":12292,"guid":"31e13ed5-5d6b-43e2-b870-15d472b342c6","title":"NEW IMPORTANT INSTRUCTIONS","subtitle":"Real-world exploits and mitigations in Large Language Model applications","description":"Understand that Machine Learning is powerful but also brittle\r\n- Give a short demo/ice breaker that includes a question to audience to show how ML is super powerful but also fails drastically.\r\n- Highlight that these failure modes can often easily be triggered once an adversary is in the loop.\r\n\r\nIntro to Large Language Models\r\n- Now pivot from generic ML to LLMs and show how the brittleness applies there.\r\n- Discuss what a LLM is and how it works briefly. Describe various prompt engineering techniques (extraction, summarization, classification, transformation,…)\r\n- Walk the audience through a typical large language model LLM application and how it works.\r\n- Highlight that there is no state, and what the context window is. But how to create a Chatbot then?\r\n- Show how systems like ChatGPT or Bing Chat leverage context window to create a conversation.\r\n- This part is important to later understand the persistence section of the talk (e.g. as long as attacker controlled data is in the context window, there is persistence of prompt injection)\r\n\r\nHighlighting real-world examples and exploits!\r\n\r\nFirst discuss three large categories of threats:\r\n    Misalignment - Model Issues\r\n    Jailbreaks/Direct Prompt Injections\r\n    Indirect Prompt Injections\r\n\r\nWe will deep dive on (3) Indirect Prompt Injections.\r\n\r\nIndirect Prompt Injections\r\n\r\n- Walk the audience through an end to end scenario (graphic in Powerpoint) that explains a prompt injection first at a basic level.\r\n- Give a demo with ChatGPT (GPT-4) and make sure the audience understands the high level idea of a prompt injection\r\n- Then take it up a notch to explain indirect prompt injections, where untrusted data is inserted into the chat context\r\n- Show demo with Google Docs and how it fails to summarize a text correctly - this demo will fit the ChatGPT (GPT-4) example from before well.\r\n- Visual Prompt Injections (Multi-modal)\r\n- Discuss some of OpenAI’s recommendation and highlight that these mitigation steps do not work! They do not mitigate injections.\r\n- Give Bing Chat Demo of an Indirect Prompt Injection ( a demo that shows how the Chatbot achieves a new identity and objective when being exploited). e..g Bing Chat changes to a hacker that will attempt to extort Bitcoin from the user.\r\n\r\nInjection TTPs\r\n\r\nDiscuss strategies on how attackers can trick LLMs:\r\n\r\n    Ignore previous instructions\r\n    Acknowledge/Affirm instructions and add-on\r\n    Confuse/Encode - switch languages, base64 encode text, emojis,…\r\n    Algorithmic - fuzzing and attacks using offline models, and transferring those attack payloads to online models\r\n\r\nPlugins, AI Actions and Functions\r\n\r\nThis section will focus on ChatGPT plugins and the danger of the plugin ecosystem.\r\n\r\n- Explain how plugins work (public data, plugin store, installation, configuration, OAuth,…)\r\n- Show how Indirect Prompt Injection can be triggered by a plugin (plugin developers, but also anyone owning a piece of data the plugin returns)\r\n- Demo Chat with Code plugin vulnerability that allows to change the ChatGPT user’s Github repos, and even switch code from private to public. This is a systemic vulnerability and depending on a plugin’s capability can lead to RCE, data exfiltration, data destruction, etc..\r\n- Show the audience the “payload” and discuss it. It is written entirely in natural language, so the attacker does not require to know C, Python or any other programming language.\r\n\r\nData Exfiltration\r\n\r\nNow switching gears to data exfiltration examples.\r\n\r\nData exfil can occur via:\r\n    - Unfurling of hyperlinks: Explain what unfurling is to the audience - apps like Discord, Slack, Teams,… do this.\r\n    - Image Markdown Injection: One of the most common data exfil angles. I found ChatGPT, Bing Chat, and Anthropic Claude are vulnerable to this, and will also show how Microsoft and Anthropic fixed this problem. ChatGPT decided not to fix it, which puts users at risk of their data being stolen during an Indirect prompt injection attack.\r\n      Give a detailed exploit chain walkthrough on Google Bard Data Exfiltration and bypasses.\r\n    - Plugins, AI Actions, Tools: Besides taking actions on behalf of the user, plugins can also be used to exfiltrate data. Demo: Stealing a users email with Cross Plugin Request Forgery. Here is a screenshot that went viral on Twitter when I first discovered this new vulnerability class: https://twitter.com/wunderwuzzi23/status/1658348810299662336\r\n\r\nKey Take-away and Mitigations\r\n\r\n    - Do not blindly trust LLM output.\r\n    Remind the audience that there is no 100% deterministic solution a developer can apply. This is due to how LLM works, but give guidance to make systems more robust.\r\n    Highlight the importance of Human in the Loop and to not over-rely on LLM output.\r\n\r\nNote: The below outline is a draft on what I would speak about if it would be today - it might change quite a bit until end of December as new features/vulnerabilities are introduced by Microsoft, Google and OpenAI.","duration":2400,"logo":"/system/events/logos/000/012/292/original/hacker.png?1699744823","type":"lecture","do_not_record":false,"track":"Security","abstract":"With the rapid growth of AI and Large Language Models users are facing an increased risk of scams, data exfiltration, loss of PII, and even remote code execution. This talk will demonstrate many real-world exploits the presenter discovered, including discussion of mitigations and fixes vendors put in place for the most prominent LLM applications, including ChatGPT, Bing Chat and Google Bard.","speakers":[{"guid":"ef09b2ff-99f8-5d96-a6a2-ab585caf4c60","id":19054,"image":null,"name":"Johann Rehberger","public_name":"Johann Rehberger","abstract":"Hacking neural networks so that we don't get stuck in the matrix. \r\nRed Team Director | Builder | Breaker | @wunderwuzzi23","description":"Be Curious.","links":[{"url":"https://embracethered.com","title":"Embrace The Red"},{"url":"https://x.com/wunderwuzzi23","title":"Twitter/X"}]}],"start_time":"2023-12-29T11:00:00.000+01:00","end_time":"2023-12-29T11:40:00.000+01:00","room":{"name":"Saal 1","id":471}},{"id":11736,"guid":"bdeddf79-e7f0-46d3-b3ee-c427026c1523","title":"Nintendo hacking 2023: 2008","subtitle":"Finishing off the Nintendo DSi","description":"This presentation will start with an introduction to the hardware of the Nintendo DSi and the history of earlier hacking attempts. This is followed with an explanation on how to extract, analyze, and exploit the boot ROMs of the console, leading to a complete defeat of the security of the system.\r\n\r\nThis presentation will not shy away from technical explanations involving software exploitation, fault injection, cryptography, and hardware design. We will however try to make it understandable and enjoyable to less technically-inclined audiences.","duration":3600,"logo":null,"type":"lecture","do_not_record":false,"track":"Security","abstract":"Over the year, many talks about console jailbreaks have been presented at CCC. However, one console has been left overlooked: the Nintendo DSi. It didn't see any serious hacks in its active lifetime, the ones that eventually appeared aren't completely satisfactory, and several components (such as its boot ROMs) were left untouched. In this presentation, we rectify the situation, explain how to extract the boot ROMs, and demonstrate new jailbreaks that can take over the console at an even deeper level. As a bonus, this work makes it possible to revive consoles with worn-out eMMC NAND chips.","speakers":[{"guid":"98c31649-3ad7-5eed-abf6-b157055c269a","id":19002,"image":null,"name":"PoroCYon","public_name":"PoroCYon","abstract":"demoscener and hardware hacker","description":null,"links":[]}],"start_time":"2023-12-28T14:45:00.000+01:00","end_time":"2023-12-28T15:45:00.000+01:00","room":{"name":"Saal Grace","id":472}},{"id":11975,"guid":"aae8dd15-bb55-4c2c-810f-d230b9144c19","title":"Numerical Air Quality Modeling Systems","subtitle":"a journey from emissions to exposure","description":"The World Health Organization (WHO) considers air pollution to be the world's single largest environmental health threat, accounting for approximately 7 million deaths worldwide every year. That's why in this talk we want to speak about how the problem of air pollution can be understood and predicted using HPC pollution modeling and its application based on general concepts and our own research. \r\n\r\nWe are Dr. Johannes Bieser and Dr. Martin Ramacher, both working at the Helmholtz Zentrum Hereon in the field of numerical pollution modelling. While Dr. Bieser wrote his Dissertation on emission modelling and its application, Dr. Ramacher wrote his Dissertation on pollutant transport and exposure modelling. \r\n\r\nIn our talk on numerical air quality modelling systems, we want to introduce basic principles and share our personal knowledge in the field of numerical pollution modelling, covering the entire pathway from emissions, transport, transformation and human exposure. Each of these steps relies heavily on large amounts of data from many different sources - satellite data, activity and meta data, measurements and many more - and skills in computer science. By default, environmental scientists are often not trained in computer science and high performance computing which implies a challenge of its own (and allows Nerds like us to excel).\r\n\r\nOur talk will be enriched with practical, technical and partially political examples to demonstrate the difficulties scientist face during their quest to improve air quality for everyone: from TB of wasted data due to historically grown data formats to counterproductive policy decisions to „improve“ air quality. We’ve seen it all and after participating in the CCC for many years now, we decided to draw attention to some state-of-the science approaches for solving one of the world’s single largest environmental health threats: „air pollution“. ","duration":3600,"logo":"/system/events/logos/000/011/975/original/hereon_Logo_standard_03_rgb.png?1699625424","type":"lecture","do_not_record":false,"track":"Science","abstract":"High performance computing (HPC) in environmental science is usually associated with research on climate change, investigating the impact of atmospheric greenhouse gases (GHG) over the next century. Besides these GHGs, there are many other gases and aerosolos in the atmosphere, which have a much more direct and immediate impact on human health: air pollutants.","speakers":[{"guid":"01ac7d9a-1cd8-5f31-9327-a67e102ee43e","id":19028,"image":"/system/people/avatars/000/019/028/original/IMG_9622.jpeg?1701939156","name":"ottopaul","public_name":"ottopaul","email":"martin.ramacher@hereon.de","abstract":"I am a Hamburg based Earth System Scientist (PhD) currently employed at the Helmholtz-Zentrum Hereon with a MSc. in Sustainability Sciences and a BSc. in Environmental Engineering.\r\n\r\nMy research is focused on the topics of exposure to pollutant concentrations, urban air quality simulations and local emission sources modeling, such as traffic, shipping, industry and residential heating.\r\n\r\nThis concludes gathering and processing of big data to model representative emission inventories for relevant emission sources in high resolution and application of emission inventories in local-scale chemistry transport models to model pollutant concentrations and to identify source contributions as well as impacts of policy-based scenarios, as well as calculating exposure estimates for health-effect studies based on dynamic population activities.\r\nMy goal is to inform the public and support policy decisions on air quality relevant topics, such as impacts on health, legislation scenarios and sector contributions.\r\n\r\nMy love for and approach to science stems from logic, working in collectives and the wish to support sustainable measures for a just, fair, non-profit, solidary and healthy global society.","description":null,"links":[{"url":"https://www.hereon.de/institutes/coastal_environmental_chemistry/chemistry_transport_modelling/team/098632/index.php.de","title":"Helmholtz-Zentrum Hereon"},{"url":"https://www.researchgate.net/profile/Martin-Ramacher","title":"ResearchGate Profile"},{"url":"https://orcid.org/0000-0001-5813-2258","title":"ORCiD"}]},{"guid":"a7cb6b88-d1ab-5ab1-83fa-b228e408cb4a","id":19547,"image":null,"name":"Johannes Bieser","public_name":"Johannes Bieser","abstract":null,"description":null,"links":[]}],"start_time":"2023-12-29T12:15:00.000+01:00","end_time":"2023-12-29T13:15:00.000+01:00","room":{"name":"Saal Zuse","id":473}},{"id":11826,"guid":"5b5ab70b-28b2-4f1a-b5ab-63013cd8477d","title":"Oh no: KUNO - Gesperrte Girocards entsperren","subtitle":"Über „Girodays“ \u0026 anderen Kuriositäten","description":"Das KUNO-Sperrsystem (Kriminalitätsbekämpfung im unbaren Zahlungsverkehr durch Nutzung nichtpolizeilicher Organisationen) wurde vor über 20 Jahren entwickelt, um Betrug mit EC-Lastschriftverfahren einzudämmen. 96 % aller Händler in Deutschland nutzen direkt oder indirekt die KUNO-Sperrdatei, um sich vor Betrug mittels gefälschter Lastschrift zu schützen. Das System wird vom EHI Retail Institute in Kooperation mit der deutschen Polizei und dem Hauptverband des Deutschen Einzelhandels betrieben. Pro Jahr laufen mehr als 120.000 Meldungen über das System.\r\nIm Rahmen einer Untersuchung konnte nun ermittelt werden, dass Taschendiebe die entsprechende Sperrung von Girocards/Debitkarten simpel aufheben und weiter Betrug begehen konnten. Durch eine Meldung im Rahmen eines Responsible Disclosure-Verfahrens konnten zahlreiche Mängel im Bereich Datenschutz und IT-Sicherheit aufgedeckt und behoben werden.\r\nIm Vortrag wird Tim Philipp Schäfers das KUNO-System genauer vorstellen und Streifzüge durch die Themen der IT-Sicherheit, des Datenschutzes und Payments vornehmen - Vergnügen für alle Datenreisenden (alle Level) ist garantiert :)\r\n\r\nWeitere Infos zu den Lücken (Ende des Jahres) unter: https://giroday.de\r\n\r\nWeitere Infos zum KUNO-Sperrsystem:\r\nhttps://de.wikipedia.org/wiki/Kriminalit%C3%A4tsbek%C3%A4mpfung_im_unbaren_Zahlungsverkehr_durch_Nutzung_nichtpolizeilicher_Organisationen","duration":3600,"logo":null,"type":"lecture","do_not_record":false,"track":"Security","abstract":"Debitkarte/girocard geklaut? – Schnell sperren lassen … doch was, wenn die Sperrung nicht so wirksam ist, wie es scheint?\r\n\r\nIm Rahmen des Vortrages werden Datenschutz- und IT-Sicherheitsmängel im KUNO-Sperrsystem vorgestellt. Das System ist bei \u003e 90 % der Händler in Deutschland im Einsatz und soll seit einem Beschluss der Innenministerkonferenz im Jahr 2005 garantieren, dass das elektronische Lastschriftverfahren (ELV) vor Betrug sicher(er) ist.\r\n\r\nIm Rahmen des Vortrages wird unter anderem aufgezeigt, wie es Unbefugten/Taschendieben (über Jahre) möglich war, gesperrte EC- \u0026 Debitkarten/ girocards für die ELV simpel zu entsperren. Darüber hinaus werden Streifzüge durch die Themen der IT-Sicherheit, des Datenschutzes und Payments vorgenommen – Vergnügen für alle Datenreisenden ist garantiert :)\r\n\r\nWeitere Infos zu den Lücken (Ende des Jahres) unter: https://giroday.de","speakers":[{"guid":"0c7be9d1-ccbe-5a6d-927d-a9d0da824aa4","id":19049,"image":"/system/people/avatars/000/019/049/original/tim_philipp_schaefers.jpg?1698868983","name":"Tim Philipp Schäfers (TPS)","public_name":"Tim Philipp Schäfers (TPS)","abstract":null,"description":null,"links":[{"url":"https://tim-philipp-schaefers.de/","title":"Persönliche Webseite"}]}],"start_time":"2023-12-30T16:00:00.000+01:00","end_time":"2023-12-30T17:00:00.000+01:00","room":{"name":"Saal 1","id":471}},{"id":12324,"guid":"be918aee-9658-418c-8685-5cf09a8acaa6","title":"On Digitalisation, Sustainability \u0026 Climate Justice","subtitle":"A critical talk about sustainability, technology, society, growth and ways ahead","description":null,"duration":3600,"logo":"/system/events/logos/000/012/324/original/Bildschirmfoto_vom_2023-12-05_16-47-43.png?1701791274","type":"lecture","do_not_record":false,"track":"Sustainability \u0026 Climate Justice","abstract":"The aim of this talk is to critically analyse the use of digital technology in the current context of global ecological injustice and the collapse of ecosystems. But how can we strive for and promote a sustainable, just and democratic digital future? The challenges are huge and include the digital world's hunger for energy as well as the exploitative global practices of tech companies or the discussion of the current AI sustainability hype. But which digital tools make sense, which do not and how can we achieve global social emancipation from self-destructive structures and towards ecological sustainability and a and a just world?","speakers":[{"guid":"63839094-04eb-5765-9108-28c0369dda3c","id":19531,"image":"/system/people/avatars/000/019/531/original/MKr17235_Maja_Göpel_(Frankfurter_Buchmesse_2022).jpg?1701180105","name":"Maja Göpel","public_name":"Maja Göpel","abstract":"Maja Göpel is a political economist and expert in sustainability policy and transformation research. She holds a professorship at the Leuphana University of Lüneburg.","description":null,"links":[{"url":"https://www.maja-goepel.de","title":"maja-goepel.de"}]}],"start_time":"2023-12-29T20:30:00.000+01:00","end_time":"2023-12-29T21:30:00.000+01:00","room":{"name":"Saal 1","id":471}},{"id":12169,"guid":"21a66662-54b7-443c-b037-9fac83fd5749","title":"Opencoil","subtitle":"PART II: disrupting disruption","description":"Since the dawn of deep mediatization (Hepp, 2020), the start-up scene posing as digital pioneers has been declaring a state of revolution, seeking nothing but disruption with the introductions of their products into society. A goal they definitely achieved with the introduction of micro-mobility services to our cityscapes / public space. \r\n\r\nIn 2020, Dennis de Bel and Anton Jehle therefore initiated the OPENCOIL research project to gain a better understanding of this latest venture capitalist phenomenon, share knowledge, establish a community, and develop tools to provoke a public debate. Later that year, they organized their first public intervention, the roaming speedshow, in Berlin and shared their insights with the community at rc3 (https://media.ccc.de/v/rc3-11575-opencoil_a_roaming_speedshow). \r\n\r\nThe ever changing landscape of micro-mobilty kept Speedy and Scooty invested and they are here at 37C3 to give an update on the OPENCOIL project! The term \"revolution\" has become a beloved buzzword for the platform economy. to take the world by storm: when in early 2018, thousands of electric kick scooters, or “trotinettes” as the french like to call them, flooded the city of Paris , the media sure was quick to coin this the \"micromobility revolution\" (Medium, 2018).  As the french are somewhat experts in the field of revolutionizing, Paris is arguably the key to any successful uprising. The seemingly endless back and forth between regulation and cooperation, between sharing and exploiting, progress and regression of micromobility can be observed here like in no other European city. As of August 31st 2023, the trotinettes have been banned from the streets of Paris with almost 90 % of public votes supporting the decision. Today the Bastille square is completely freed from trottinettes: a revolution by the people.\r\n\r\nWith this years talk Scooty and Speedy will be problematising the rise (and fall) of shared mobility and its effects on the basis of Paris as well as related interventions and observations of the past three years.","duration":3600,"logo":null,"type":"lecture","do_not_record":false,"track":"Art \u0026 Beauty","abstract":"OPENCOIL and the fine art of appropriating micro-mobility services for fun and debate.","speakers":[{"guid":"1c2eabf6-e92b-5378-9cbc-cdaf8cd24e1e","id":13095,"image":"/system/people/avatars/000/013/095/original/fiffkon.jpg?1700047099","name":"Speedy","public_name":"Speedy","email":"speedy@opencoil.show","abstract":"As a self-proclaimed micro-mobility parasite Anton Linus Jehle has been testing the limits of e-scooter services since their introduction in 2019. Through experiments, interventions and installations he breaks forced perspectives to find new approaches to the socio-political challenges of our times. In recent years, his work has been presented at Körber Forum in Hamburg, Württembergischer Kunstverein in Stuttgart, and rc3 Remote Chaos Experience of the Chaos Computer Club, as well as this years FMR festival in Linz.","description":null,"links":[]},{"guid":"1cf88ae3-58f4-5b00-bfd5-c2dde9537edb","id":13837,"image":null,"name":"Scooty","public_name":"Scooty","abstract":null,"description":null,"links":[]}],"start_time":"2023-12-27T17:15:00.000+01:00","end_time":"2023-12-27T18:15:00.000+01:00","room":{"name":"Saal Zuse","id":473}},{"id":11777,"guid":"9ce8d3b9-abbc-47f6-9f4e-dd93c804b4fc","title":"Open CPU / SoC design, all the way up to Debian","subtitle":null,"description":"This will be based on the recently developped NaxRiscv core, a free and opensource RISC-V softcore. I will cover many interresting aspect of the project/flow to provide a large overview of all the different technical aspect in such project.","duration":2400,"logo":"/system/events/logos/000/011/777/original/logo3.PNG?1698392835","type":"lecture","do_not_record":false,"track":"Hardware \u0026 Making","abstract":"This lecture will cover many aspect of designing a RISC-V CPU, out-of-order execution, multi-core, memory coherency, security and running linux and debian on a FPGA.","speakers":[{"guid":"297a05c6-7880-5e36-8786-14c1d445eda1","id":6736,"image":"/system/people/avatars/000/006/736/original/github.png?1479318789","name":"Dolu1990","public_name":"Dolu1990","email":"charles.papon.90@gmail.com","abstract":"SpinalHDL / VexRiscv / NaxRiscv main dev","description":"Developing open-source FPGA designs since 2015, i'm the main dev of : \r\n- SpinalHDL : An alternative to VHDL / Verilog\r\n- VexRiscv : An in-order linux SMP capable softcore\r\n- NaxRiscv : An out-of-order debian SMP capable softcore\r\n\r\nI'm trying mostly to push forward the hardware design flow by mixing some software concepts into the hardware elaboration flow.","links":[]}],"start_time":"2023-12-27T12:00:00.000+01:00","end_time":"2023-12-27T12:40:00.000+01:00","room":{"name":"Saal Zuse","id":473}},{"id":11859,"guid":"a91c6e01-49cf-4227-baae-aece190e9de5","title":"Operation Triangulation: What You Get When Attack iPhones of Researchers","subtitle":null,"description":"In this presentation, we will share:\r\n\r\n\u003cul\u003e\r\n\u003cli\u003eHow we managed to discover and capture all stages of a zero-click attack on iOS, despite the attackers’ efforts to hide and protect it,\u003c/li\u003e\r\n\u003cli\u003ea comprehensive analysis of the entire attack chain, which exploited five vulnerabilities, including four zero-days\u003c/li\u003e\r\n\u003cli\u003ethe capabilities of the malware that transforms your phone into the ultimate surveillance tool,\u003c/li\u003e\r\n\u003cli\u003eand the links to previously known malware we were able to find.\u003c/li\u003e\r\n\u003c/ul\u003e","duration":3600,"logo":null,"type":"lecture","do_not_record":false,"track":"Security","abstract":"Imagine discovering a zero-click attack targeting Apple mobile devices of your colleagues and managing to capture all the stages of the attack. That’s exactly what happened to us! This led to the fixing of four zero-day vulnerabilities and discovering of a previously unknown and highly sophisticated spyware that had been around for years without anyone noticing. We call it Operation Triangulation. We've been teasing this story for almost six months, while thoroughly analyzing every stage of the attack. Now, for the first time, we're ready to tell you all about it. This is the story of the most sophisticated attack chain and spyware ever discovered by Kaspersky.","speakers":[{"guid":"218fa11f-5e21-5078-88dc-ce88921954f0","id":9330,"image":null,"name":"oct0xor","public_name":"oct0xor","abstract":"Security researcher. Very passionate about reverse engineering and vulnerability research. Hunts for zero-day exploits at work and reported 17 zero-day vulnerabilities (Microsoft Windows/iOS/web browsers) used in different malware campaigns. He has been hacking game consoles since 2010 and previously presented his research “Hacking Sony PlayStation Blu-ray Drives” at 36C3. He also reverse engineered and rewrote Metal Gear Solid 2 to add a full-fledged third-person camera to the game.","description":"Past speaker experience: Virus Bulletin, CanSecWest, Security Analyst Summit, BlueHat, TyphoonCon, ISC, AVAR, CodeBlue, OffensiveCon, etc.","links":[{"url":"https://twitter.com/oct0xor","title":"Twitter"},{"url":"https://securelist.com/all/?author=borislarin\u0026filter=","title":"Publications"},{"url":"https://github.com/oct0xor/presentations","title":"Presentations"},{"url":"https://www.youtube.com/@oct0xor","title":"YouTube"}]},{"guid":"ce0c1ff7-f0db-5f00-a361-d7f791ee6a16","id":18996,"image":"/system/people/avatars/000/018/996/original/GK.jpg?1699655170","name":"kucher1n","public_name":"kucher1n","abstract":"Georgy Kucherin is a junior researcher at Kaspersky’s Global Research and Analysis Team and a fourth-year student at Moscow State University. He is passionate about analysis of complex malware and reverse engineering. His previous research includes attribution of the SolarWinds attack, as well as thorough investigations into APTs such as Operation Triangulation, Turla, FinFisher, APT41 and Lazarus.","description":null,"links":[]},{"guid":"39bf8657-1de1-535f-a068-a19abe02323a","id":19252,"image":"/system/people/avatars/000/019/252/original/Leonid_Bezvershenko.jpg?1699433348","name":"bzvr_","public_name":"bzvr_","abstract":"Leonid joined Kaspersky in 2020 as an intern in the Global Research and Analysis Team (GReAT). In 2021, he was invited to the GReAT as a Junior Security Researcher. In 2023, he was promoted to Security Researcher. In this role, Leonid focuses on open‑source security, reverse engineering, and malware analysis. His research includes the analysis of APT campaigns, such as Operation Triangulation and CloudWizard. Additionally, he is actively involved in the development of internal tools and infrastructure. Leonid is currently a student at Moscow State University’s Faculty of Computational Mathematics and Cybernetics. He is also a member of the Drovosec CTF team.","description":null,"links":[]}],"start_time":"2023-12-27T14:45:00.000+01:00","end_time":"2023-12-27T15:45:00.000+01:00","room":{"name":"Saal 1","id":471}},{"id":11820,"guid":"b56502da-90cb-4ae1-b055-2a1d3de52cb2","title":"Place \u0026 route on silicon","subtitle":"A gentle introduction to place \u0026 route algorithms for digital integrated circuits","description":"This talk introduces the algorithms used for placement and routing of digital integrated circuits.\r\n\r\nThe talk does *not* cover:\r\n* high-level circuit design (The art of creating meaningful circuits. Often done with languages like Verilog, VHDL, SpinalHDL, Chisel, Amaranth, etc )\r\n* logic synthesis (Converts the high-level description into a graph-like circuit description, called netlist)\r\n\r\nPlace-and-route refers to the transformation of a graph-like circuit description (netlist) into a geometrical representation of the circuit (layout).\r\nThe netlist is typically produced by logic synthesis. The netlist consists of many sub-circuits, so called \"standard-cells\" but also \"macro cells\".\r\nStandard-cells implement simple logic functions such as inverters, logical \"and\", \"nand\", \"xor\", and storage elements.\r\nThe netlist may also import larger pre-compiled macro cells such as SRAM blocks.\r\nFor a physical implementation of the circuit, the sub-circuits need to be placed on the chip surface and need to be connected (routed) using metal wires.\r\n\r\nTransforming the netlist into a layout typically requires the following input data:\r\n* A netlist of the circuit, of course.\r\n* A set of constraints: For example the desired clock frequency and area of the circuit.\r\n* Design rules: A set of constraints required for successful fabrication. This typically involves geometrical constraints such as minimum width and spacing of metal wires.\r\n* A standard-cell library: This is a set of building-blocks usually used to assemble the circuit. The library contains the geometrical layout of the standard-cells and also information about their timing behavior.\r\n\r\nThen the following steps convert the input data into a layout:\r\n* IO-planning: Decide where to put the input and output pins of the circuit.\r\n* Floor-planning: Decide how to geometrically arrange various parts of a larger system.\r\n* Power distribution: Insert regular rows of metallic power-rails which supply the standard-cells with energy\r\n* Global placement: Decide where to roughly place the standard-cells such that the wiring will short and possible\r\n* Tie-cell insertion: Provide constant 0 and 1 signals, where needed.\r\n* Clock-tree synthesis: Storage elements typically need a clock-signal. Often the clock signal needs to be distributed to a large number of storage elements.\r\n* Detail placement: Do fine-tuning, such as snapping the standard-cells to a grid\r\nthe signal propagation delay from the clock source to the storage elements should be more-or-less equally distributed.\r\n* Optimizations to meet timing requirements: Some signals might be too slow or to fast. There's a variety of techniques to improve this, such as amplifying signals with buffers.\r\n* Routing: The placed cells need to be connected with metal wires.\r\n* Filler insertion: fill unused space for example with capacitors to stabilize the supply voltage\r\n* Verification: Make sure all constraints are met. Otherwise, try to fix the circuit and repeat above steps in order to converge to a valid solution.\r\n\r\nThis talk will focus on a widely used algorithm for global placement and introduces basic principles of routing algorithms.\r\n","duration":2400,"logo":null,"type":"lecture","do_not_record":false,"track":"Hardware \u0026 Making","abstract":"After a brief introduction to digital circuits this talk will outline placement and routing algorithms used for creating digital integrated circuits.\r\n","speakers":[{"guid":"a171bd7c-b0f5-521a-87d8-22d794b2b532","id":19095,"image":null,"name":"Thomas","public_name":"Thomas","abstract":null,"description":null,"links":[]}],"start_time":"2023-12-27T11:00:00.000+01:00","end_time":"2023-12-27T11:40:00.000+01:00","room":{"name":"Saal Zuse","id":473}},{"id":12004,"guid":"1e0deaac-3c87-4eb1-9a6b-75ce321fede0","title":"Please Identify Yourself!","subtitle":"Digital Identity Systems in the EU \u0026 around the world","description":"After over two years of intense negotiations, the EU recently agreed to their Digital Identity Reform (eIDAS). In this talk we analyse the result, what safeguards we can realistically expect and how our online and offline interactions might change because of this new European Digital Identity Wallet.\r\nOther regions in the world are much further ahead in this issue and we will also try to learn from the experiences from India and Kenya. Both countries had unique strategies from civil society to fight back against the introduction of digital identity systems, focusing on interrogating their design, raising awareness, strategic litigation and civil disobedience post deployment .\r\nLastly, this issue pops up in many countries and is actively promoted as \"Digital Public Infrastructure\" by global organisations like UNDP and the World Bank - often with little to know credence to privacy or local realities. This global trend is very worrying due to the shiny veneer hiding their dark reality of exploitation by local and foreign actors. We will showcase strategies how local actors have resisted and shaped the introduction of these systems with a combination of technical, advocacy, and interdisciplinary ally building. Our goal is to provide knowledge about how exactly these systems work, who benefits from them and what strategies could be deployed against them.","duration":2400,"logo":null,"type":"lecture","do_not_record":false,"track":"Ethics, Politics \u0026 Society","abstract":"Digital Identity Systems proliferate worldwide without any regard for their human rights impact or privacy concerns. Driven by governments and the crony capitalist solutionism peddled by the private sector, official statistics estimate that 80 % of the world’s population is condemned to use them by the end of this decade. These identification systems are a frontal attack on anonymity in the online world, might lead to completely new forms of tracking and discrimination and they are a gift to Google and other companies which are monitoring the behaviour of people on a large scale. In this talk we focus on how the recent EU reform played out, how the UN is becoming a central player in promoting their hasty adoption and which strategies civil society and hackers can deploy to fight back.","speakers":[{"guid":"537f4f1b-b14a-5522-ac9b-125b2bb65d1c","id":4366,"image":"/system/people/avatars/000/004/366/original/Photo_27.09.18__15_46_22-s.jpg?1576536701","name":"Thomas Lohninger","public_name":"Thomas Lohninger","abstract":"Digital rights activist from Austria. ","description":"Thomas Lohninger is Executive Director of the digital rights NGO \u003ca href=\"https://epicenter.works\"\u003eepicenter.works\u003c/a\u003e in Vienna, Austria. The Center of Internet and Society of the \u003ca href=\"https://cyberlaw.stanford.edu/about/people/thomas-lohninger\"\u003eStanford Law School\u003c/a\u003e holds him as a non-residential Fellow and he was \u003ca href=\"https://www.mozillapulse.org/profile/389\"\u003eSenior Fellow of the Mozilla Foundation\u003c/a\u003e working on Net Neutrality in the European Union. He worked on the European Net Neutrality regulation as Policy Advisor for \u003ca href=\"https://edri.org\"\u003eEuropean Digital Rights\u003c/a\u003e (EDRi) and is serving on the board of EDRi since 2019. His background is in IT and Cultural- and Social Anthropology.  \u003ca href=\"http://socialhack.eu\"\u003e\u0026gt;\u0026gt;more\u003c/a\u003e","links":[{"url":"http://socialhack.eu","title":"portfolio"},{"url":"https://twitter.com/socialhack","title":"@socialhack"},{"url":"http://epicenter.works/","title":"epicenter.works"}]},{"guid":"2b457928-ce5f-5d27-9d06-cdb03ba90c6f","id":19299,"image":null,"name":"Udbhav Tiwari","public_name":"Udbhav Tiwari","abstract":null,"description":null,"links":[]}],"start_time":"2023-12-27T13:50:00.000+01:00","end_time":"2023-12-27T14:30:00.000+01:00","room":{"name":"Saal 1","id":471}},{"id":12168,"guid":"4a20deed-7434-4565-9e33-2cbc53734bab","title":"Predator Files: How European spyware threatens civil society around the world","subtitle":null,"description":"As part of the Predator Files investigation, Amnesty International, in partnership with European Investigative Collaborations, uncovered and documented for the first time how the Intellexa Alliance, a European-based surveillance vendor, has supplied advance spyware and surveillance technology to governments around the world, and where it has then been used to target journalists, leading politicians, and European institutions.\r\n\r\nTechnical specifications and marketing material from surveillance vendors is often kept secret. The resulting information asymmetry prevents defenders in the cybersecurity industry and at-risk civil society groups from understanding the full scope of the threats that they face. This talk will draw on leaked internal documents and technical material, obtained by the Predator Files consortium, which shed light on the evolving technical tactics used by surveillance actors to subvert network infrastructure and deliver digital attacks to targeted individuals.\r\n\r\nThis talk will conclude with recommendations on possible mitigations and detections which can help protect civil society targets and the wider internet ecosystem from some of the attack vectors offered by this company.","duration":2400,"logo":null,"type":"lecture","do_not_record":false,"track":"Security","abstract":"Ever evolving mercenary spyware continues to threaten the safety of activists, journalist and human rights defenders around the world. Following the exposure of the Pegasus spyware scandal, this talk will be a technical deep dive into the tactics and techniques sold by the European-based spyware alliance Intellexa, which is used by governments to infect the devices and infrastructure we all depend on.","speakers":[{"guid":"fbe2becf-1c87-561d-b547-d30fec56ca50","id":19412,"image":"/system/people/avatars/000/019/412/original/avatar.jpg?1701813195","name":"Donncha Ó Cearbhaill","public_name":"Donncha Ó Cearbhaill","abstract":"Donncha Ó Cearbhaill (IE/DE) is a hacker and security researcher with a focus on targeted digital surveillance and other evolving threats facing journalists, activists and others members of civil society. He leads the Security Lab at Amnesty International which has played a critical role in exposing the global spyware crisis with the Pegasus Project and Predator Files investigation.","description":null,"links":[{"url":"https://donncha.is","title":"Personal website"},{"url":"https://securitylab.amnesty.org","title":"Security Lab at Amnesty International "}]}],"start_time":"2023-12-28T12:55:00.000+01:00","end_time":"2023-12-28T13:35:00.000+01:00","room":{"name":"Saal 1","id":471}},{"id":11850,"guid":"89547332-c384-4510-9f60-420328b16885","title":"Prompt Battle","subtitle":null,"description":"The Prompt Battle is a game show format with audience involvement that questions the meaning of prompt engineering in a playful and critical way.\r\nBased on the format of the Rap Battle, eight candidates compete against each other under time pressure on stage in a tournament to solve image and text tasks set for them. The audience decides who has won after each round. The rounds are interrupted by video interludes that illuminate the implications of text-to-image tools from different perspectives.\r\nThe aim of the Prompt Battle is to address the numerous controversial questions that tools such as DALL·E, Stable Diffusion and Midjourney raise for professional creatives. Questions about the origin of training data, the value of creative work, the inflation of images, and the intellectual property of the content produced.\r\n\r\nSince 2022, rapid technological advances in the field of AI-generated content have raised a series of fundamental questions. For artists and designers, the first question is whether creativity can really be automated, and whether prompt engineering really is the future-proof key capability that some believe it to be. Behind the hype, far-reaching ethical, economic, copyright and aesthetic challenges and contradictions are emerging. The Prompt Battle uses the game show format to address these questions in a playful way by confronting the candidates and the audience with prompt engineering tasks tailored to the occasion.\r\n\r\nThe original Prompt Battle was developed at HTW Dresden by Sebastian Schmieg, Florian A. Schmidt, Bernadette Geiger, Robert Hellwig, Emily Krause, Levi Stein, Lina Schwarzenberg and Ella Zickerick.","duration":5400,"logo":"/system/events/logos/000/011/850/original/PromptBattleLogo.png?1699016704","type":"performance","do_not_record":false,"track":"Entertainment","abstract":"Do you have what it takes to become a Prompt Designer? Based on the Rap Battle format, Prompt Battle is a game show in which people compete against each other with the performative use of language. AI-supported text-to-image software enables the candidates to generate complex photos, images, and illustrations, seemingly out of thin air, by typing in image descriptions, so-called prompts. The audience will decide who will elicit the most surprising, disturbing or beautiful images from the latent space, and who will walk away carrying the prestigious title Prompt Battle Winner.","speakers":[{"guid":"c3c65e7f-186e-5006-be83-2f2f215a2393","id":19163,"image":"/system/people/avatars/000/019/163/original/Lina-Schwarzenberg_press.jpg?1699016856","name":"Lina Schwarzenberg","public_name":"Lina Schwarzenberg","email":"hi@linaschwarzenberg.com","abstract":"Lina Schwarzenberg is a designer who operates at the intersection of design, art, and technology. In addition to her work as a graphic and web designer, she has developed a particular fascination for the interaction between humans and machines. Schwarzenberg delves into the impact of artificial intelligence and critically and experimentally explores both the potential and limitations of this technology, particularly within the realm of design.","description":null,"links":[{"url":"https://www.linaschwarzenberg.com/","title":"Website"},{"url":"https://www.instagram.com/solvem.probler/","title":"Instagram"}]},{"guid":"50ded4f8-b5c1-52c4-875c-bd0579b3af4d","id":7739,"image":"/system/people/avatars/000/007/739/original/2097037_300_400x400.jpg?1507882551","name":"Sebastian Schmieg","public_name":"Sebastian Schmieg","abstract":"Sebastian Schmieg examines the ways networked technologies shape online and offline realities. In particular, his practice reflects on humans as software extensions, and on machine vision as a global assembly line.","description":"Sebastian Schmieg examines the ways networked technologies shape online and offline realities. In particular, his practice reflects on humans as software extensions, and on machine vision as a global assembly line. His output encompasses videos, websites, books, lecture performances, or online interventions. Previously his work has been exhibited at The Photographers’ Gallery, London; Transmediale, Berlin, Germany; Art Center Nabi, Seoul, South Korea; and Bitforms Gallery, New York, USA. Sebastian Schmieg lives and works in Berlin.","links":[{"url":"http://sebastianschmieg.com/","title":"sebastianschmieg.com"}]},{"guid":"bb8d8fe9-6a4f-52e3-9d92-aa472002b24b","id":19552,"image":null,"name":"Ella Zickerick","public_name":"Ella Zickerick","abstract":"I am a communication designer from Berlin with a keen interest in the intersection of pop culture, contemporary art and new media. Since founding the Prompt Battle team in October 2022, I have been on an international tour and have worked on various events such as transmediale and re:publica. I currently work in the design and communications team of Junge Tüftler gGmbH, a media education company that supports children and young people in developing digital skills to enable them to help shape the future in a sustainable way. ","description":null,"links":[]}],"start_time":"2023-12-30T00:00:00.000+01:00","end_time":"2023-12-30T01:30:00.000+01:00","room":{"name":"Saal 1","id":471}},{"id":12293,"guid":"b8573cd0-ba19-4ad8-964b-1d419caa15dc","title":"Quantum Cryptography - Real Progress or Expensive Hype?","subtitle":null,"description":"Among all emerging quantum technologies, quantum communication is probably the most advanced one, demonstrating remarkable progress through recent research breakthroughs as well as the emergence of commercially available products. In theory, the potential that quantum communication offers is enormous, as it provides a provably secure encryption scheme independent of an attacker's computational power, unlike most classical encryption schemes, which rely on unproven computational assumptions (which are additionally vulnerable to quantum computers).\r\nIn practice, widespread adoption of quantum communication was so far hindered by fundamental physical limits on the one hand, such as signal loss, and demanding experimental prerequisites of sophisticated and costly equipment on the other hand, like photon sources and detectors.\r\n\r\nThroughout the last few years, however, theoretical and experimental advances in the field have shown ways to tackling at least some of these challenges in the foreseeable future. In this lecture, we will look at the most interesting developments and how this might shape the quantum communication industry in the near term future. This includes a look at new protocols and theoretical developments, as well as experimental results, such as the ongoing miniaturization of the photonic components, resulting in compact and fully integrated chip-based quantum communication solutions.\r\n\r\nWhile a burgeoning quantum industry has taken shape, much of the progress remains fueled by public funding programs and government initiatives. The second part of the talk will critically examine the roles of scientists and policymakers, delving into the tension between scientific ambitions and the practical limitations of quantum technology. The discourse will shed light on the phenomena of extravagant promises made in the pursuit of scientific glory, the global race for quantum supremacy fueled by fears of falling behind other nations, particularly China and the US, and the sincere belief in the transformative power of quantum technology.","duration":3600,"logo":null,"type":"lecture","do_not_record":false,"track":"Security","abstract":"This talk will give an introduction to the field of quantum communication and quantum cryptography and explore exciting scientific developments in this field over the past years. We will discuss aspects of security, what benefit quantum cryptography brings and where it might realistically play a role in the future.\r\nWe will also have a critical look at how the quantum hype and the international fear of missing out is driving policy makers and public funding agencies, much to the joy of physicists throughout the world and, specifically, in Europe and Germany.","speakers":[{"guid":"eeed1223-8a3b-5e42-a22f-404c2bc65991","id":19346,"image":null,"name":"Fabian Beutel","public_name":"Fabian Beutel","abstract":"I am a quantum scientist at the University of Münster and a lead research engineer at Pixel Photonics GmbH. I received my PhD in physics from the University of Münster, where I did many years of research in the field of experimental quantum communication and photonic integrated circuits. While I'm a physicist by job, I also spend a vast amount of time doing software development as part of my job and spare time.","description":"I have studied physics at the RWTH Aachen University and HU Berlin, where I received my masters degree. I then received a PhD in physics from Münster University, where I studied experimental quantum communication and quantum optics.","links":[]}],"start_time":"2023-12-29T19:15:00.000+01:00","end_time":"2023-12-29T20:15:00.000+01:00","room":{"name":"Saal Grace","id":472}},{"id":11928,"guid":"6e205c92-eeff-4339-9028-e5f7b7bb03ee","title":"Reconstructing game footage from a Game Boy's memory bus","subtitle":"The GB Interceptor","description":"The original goal of the open source project \"GB Interceptor\" was to capture gameplay for one specific game: Tetris. In order to live stream a Tetris tournaments from the contestant's personal Game Boys, the idea was to create an adapter that goes between the Game Boy and the game module to analyze the communication on the memory bus and reconstruct the game state.\r\n\r\nIt turns out that it is actually possible to reconstruct the entire memory state of almost any game and in fact create an rp2040-based adapter that acts as a USB video class device offering the on-screen game footage in realtime. Players can simply put this adapter into their Game Boy and use it like a webcam without additional drivers or knowledge.\r\n\r\nAn essential aspect of this concept is that the Game Boy basically runs all of its code directly from the ROM module, which makes it possible to directly follow the program counter of its 8bit CPU regardless of how the code branches. An image can then be recreated by emulating the graphics unit (PPU).\r\n\r\nHowever, there are many edge cases like interrupts, data from registers that are not visible on the bus, the link cable, DMA operations, synchronization of CPU and PPU, game bugs and even bugs in the Game Boy hardware itself.\r\n\r\nIn this talk I will show how all this is done just on an rp2040 with spare cycles to encode everything as a 60fps MJPEG stream. I will shine a light on the edge cases - those that were solved and those that might just be unsolvable with this approach. And I will take you on a sightseeing tour through the 8bit hell that drives our iconic handheld from 1989.","duration":3600,"logo":"/system/events/logos/000/011/928/original/abstract.jpg?1699479954","type":"lecture","do_not_record":false,"track":"Hardware \u0026 Making","abstract":"How do you capture a video from an 1989's Game Boy without modding the original hardware? With an adapter cartridge that spies on the memory bus!\r\n\r\nLet's talk about how to reconstruct the Game Boy's memory state, emulate its graphics unit and then encode the image into an MJPEG stream for anyone to use as a USB video class device. In realtime. On an rp2040 microcontroller.","speakers":[{"guid":"e05d2ac3-327c-521b-882f-3cdf1331e469","id":9799,"image":"/system/people/avatars/000/009/799/original/STA09836_1500.jpg?1701644946","name":"Sebastian Staacks","public_name":"Sebastian Staacks","email":"sebastian@staacks.de","abstract":"I am a physicist and developer of the education app \"phyphox\" at RWTH Aachen University. In my free time I create funky projects for my blog at https://there.oughta.be.","description":"If I talk about \"free time\" I mean that time after my day job and family time. When my two kids are asleep I just have to make things. I guess, people call that a \"maker\". Although, in recent projects there has been a weird obsession with old gaming consoles, and the Game Boy in particular.\r\n\r\nOh, and what is my day job? Well, after getting my PhD in solid state physics in 2014 I developed the app \"phyphox\" as a side project for an introductionary lecture at the RWTH Aachen University. It provides access to the device's sensors to act as a measurement device for experiments in physics education. Shortly after we published it in 2016 it quickly became rather successful, eventually giving me the opportunity to take a permanent position at the RWTH Aachen University with a focus on technology in physics didactics. But that's not why I am at the 37C3 this year...","links":[{"url":"https://there.oughta.be","title":"There oughta be..."},{"url":"https://mastodon.social/@DiConX","title":"Mastodon"}]}],"start_time":"2023-12-29T20:30:00.000+01:00","end_time":"2023-12-29T21:30:00.000+01:00","room":{"name":"Saal Grace","id":472}},{"id":12157,"guid":"611fb5d7-cd0d-436e-8713-ccee10ea375b","title":"Rettet uns die KI?","subtitle":"Über die Zukunft der digitalen Inklusion","description":"Es wird immer wieder behauptet, die Einführung generativer KI-Systeme wie ChatGPT und Midjourney habe eine neue Ära der Möglichkeiten eröffnet, insbesondere im Bereich der digitalen Barrierefreiheit. Diese Technologien und Unternehmen versprechen, den Alltag von Menschen mit Behinderungen durch innovative Lösungen zu erleichtern. Beispielsweise ermöglichen neue, multi-modale Large Language Models die Generierung von Alternativtexten, die visuelle Inhalte für sehbehinderte Nutzer*innen zugänglicher machen könnten. Auch die Erstellung von Texten in Leichter Sprache kann durch diese Modelle vereinfacht werden, wodurch Informationen für Menschen mit Lernbehinderungen oder Nicht-Muttersprachler*innen leichter verständlich werden können.\r\n\r\nDoch die Integration von KI in unseren Alltag als behinderte Menschen bringt nicht nur Vorteile. Trotz der neuen Fähigkeiten von KI-Systemen kommen einige neue Herausforderungen hinzu. Dazu gehören unter anderem reproduzierter Ableismus, neue für uns unsichtbare Barrieren und der zunehmende gesellschaftliche Unwille, Barrierefreiheit und somit echte Inklusion zu schaffen, wenn Hilfsmittel immer besser werden. Unter Umständen werden Menschen mit Behinderung in einem gesellschaftlichen Kontext noch unsichtbarer, als sie es sowieso sind.\r\n\r\nBei meiner Arbeit als Beraterin für digitale Barrierefreiheit und als sehbehinderte Person spreche ich mittlerweile täglich über generative KI. Neben den vielen Möglichkeiten, die mir diese Systeme persönlich eröffnen, sehe ich aber auch viele Herausforderungen, denen wir in naher Zukunft entgegentreten müssen. Es ist daher unerlässlich, dass wir die Entwicklung von KI-Tools kritisch begleiten, um eine inklusive digitale Zukunft zu gestalten, in der technologischer Fortschritt Hand in Hand mit menschlicher Vielfalt geht. Im Vortrag werfe ich einen detaillierten Blick auf alle diese Punkte, ordne ein und diskutiere, was dafür notwendig ist.","duration":2400,"logo":null,"type":"lecture","do_not_record":false,"track":"Ethics, Politics \u0026 Society","abstract":"Spätestens seit Ende 2022 sind generative KI-Systeme wie ChatGPT und Midjourney in aller Munde, und sie werden dabei nicht selten auch als Game-Changer für die digitale Barrierefreiheit postuliert. Doch wo stehen wir eigentlich gerade wirklich, was können diese Systeme bereits jetzt für uns tun, und was bringt uns die Zukunft? Es ist höchste Zeit für einen unverfälschten „Reality Check“ und einen authentischen Blick in den Alltag von Menschen mit Behinderung.","speakers":[{"guid":"559626d8-fc6f-517f-a8b6-d17c2d2f572d","id":19422,"image":null,"name":"Casey Kreer","public_name":"Casey Kreer","abstract":null,"description":null,"links":[]}],"start_time":"2023-12-28T19:15:00.000+01:00","end_time":"2023-12-28T19:55:00.000+01:00","room":{"name":"Saal Grace","id":472}},{"id":12064,"guid":"6792b805-41e9-46ed-affb-76e647b2ed13","title":"RFC 9420 or how to scale end-to-end encryption with Messaging Layer Security","subtitle":null,"description":"MLS improves upon existing protocols such as Signal in group messaging applications. We co-authored the protocol specification and will briefly talk about what motivated the creation of MLS, how it relates to other existing messaging protocols as well as its design process in general.\r\n\r\nAs a group messaging protocol, the security guarantees provided by MLS go beyond authentication and confidentiality. We will go into detail on what security properties users can expect and take a look under the hood on how MLS works.\r\n\r\nWhile the MLS specification has only been published recently, more work is underway and an ecosystem is already forming around the standard. We’ll touch on topics like MLS implementations, metadata hiding, federation, and interoperability between messengers (also in the context of the new IETF MIMI working group [1]). And of course we’ll share insights into the future of Messaging Layer Security!\r\n\r\n[1] https://datatracker.ietf.org/group/mimi/about/\r\n","duration":2400,"logo":"/system/events/logos/000/012/064/original/mls.jpg?1699695753","type":"lecture","do_not_record":false,"track":"Security","abstract":"They call it RFC 9420, we say MLS: A new IETF standard for end-to-end encryption was published in July and brings large improvements in performance and security compared to existing protocols. We are here to present Messaging Layer Security, its ecosystem and its roadmap.\r\n\r\nThe MLS protocol is already being used in production to end-to-end encrypt Webex conference calls and will soon provide encryption for Android messages and RCS 2.0 for billions of users. Other messaging tools (such as Discord, Matrix, Wire, etc.) are currently trialing MLS and are expected to follow.\r\n\r\nWhy was the protocol developed in the first place? How does it work? What are the next steps for MLS?","speakers":[{"guid":"da34d8c7-f600-5717-8e4a-e497ac20b264","id":18794,"image":"/system/people/avatars/000/018/794/original/self.jpeg?1699695905","name":"Konrad Kohbrok","public_name":"Konrad Kohbrok","abstract":null,"description":"With a background in the security analysis of cryptographic protocols, I am interested in all things secure messaging. I am an active member in the Messaging Layer Security (MLS) and More Instant Messaging Interoperabilty (MIMI) working groups at the IETF, where I try to help push the state-of-the-art in secure messaging.\r\n\r\nI currently work at Phoenix R\u0026D, where (among other things), I co-maintain OpenMLS, an Open Source Rust implementation of the MLS protocol.","links":[{"url":"https://kkohbrok.github.io","title":"Homepage"},{"url":"https://openmls.tech","title":"OpenMLS"}]},{"guid":"fbb6f385-062e-5a36-bfec-1bdbda69dfd3","id":19539,"image":null,"name":"Raphael Robert","public_name":"Raphael Robert","abstract":null,"description":null,"links":[]}],"start_time":"2023-12-29T15:45:00.000+01:00","end_time":"2023-12-29T16:25:00.000+01:00","room":{"name":"Saal Zuse","id":473}},{"id":11684,"guid":"6123fb8c-75dd-48fa-810f-f7dc3cdb73a4","title":"Rust Binary Analysis, Feature by Feature","subtitle":null,"description":"You attempt to analyze a binary file compiled in the Rust programming language. You open the file in your favorite disassembler. Twenty minutes later you wish you had never been born. You’ve trained yourself to think like g++ and msvc: Here’s a loop, there’s a vtable, that’s a global variable, a library function, an exception. Now you need to think like the Rust compiler. Maybe you’ve heard about “sum types” and “generics” and “iterators”, maybe you haven’t, and in both cases you are going to have an exceptionally bad time.\r\n\r\nThis talk will get you familiar with the assembly code idioms the Rust compiler uses to implement the language’s core features (as they appear in Klabnik’s and Nichols’ “The Rust Programming Language”), and more generally, the frame of mind required for reverse-engineering such programs. How is an Option\u0026lt;T\u0026gt; represented using the same amount of memory as a plain T? How do monomorphized generic functions complicate RE work? What's the right approach to untangle many-layered, unintuitive iterator chains? We will tackle these questions and many more.\r\n\r\nIncludes a publicly available lab setup with several sample programs that showcase core Rust features as compiled to assembly.","duration":2400,"logo":"/system/events/logos/000/011/684/original/2023-10-17-041029_1216x815_scrot.png?1697506898","type":"lecture","do_not_record":false,"track":"Security","abstract":"A walkthrough of the assembly code idioms the Rust compiler uses to implement the language’s core features (as they appear in Klabnik’s and Nichols’ “The Rust Programming Language”) - starting with simple match expressions and all the way to monomorphized functions and iterator chains.","speakers":[{"guid":"e41082b0-d458-55aa-a2cd-73dfab782b9a","id":4950,"image":"/system/people/avatars/000/004/950/original/ben_herzog.jpg?1695774924","name":"Ben H","public_name":"Ben H","email":"benherzog11235@gmail.com","abstract":"Ben is a graduate student and math aficionado working undercover as a security researcher. He dabbles in reverse engineering, cryptography and machine learning, though his secret dream is finding an application of metric space theory to anything at all.","description":null,"links":[]}],"start_time":"2023-12-28T17:15:00.000+01:00","end_time":"2023-12-28T17:55:00.000+01:00","room":{"name":"Saal Zuse","id":473}},{"id":11825,"guid":"da6bd3cb-8d10-4e5e-a59f-5cc0a03dcb08","title":"Science Slam","subtitle":"Weltrettung braucht Wissenschaft","description":"Wie sähe die Welt aus, wenn wir auf Wissenschaft hören würden? Wo doch bekanntermaßen jeder Katastrophenfilm so beginnt, dass sie ignoriert wird – kurz bevor der Meteorit einschlägt, die Flut flutet und der weiße Hai alle Badenden auffrisst. Auch die akuten Krisen verdanken wir u.a. einer Politik, die Wissenschaft viel zu oft ignoriert. Die hat uns immerhin nicht nur vor Atemwegsinfektionen gewarnt, sondern auch vor zunehmenden Flutereignissen. Wer weiß, was in ihren Artikeln noch alles drinsteht? In unserem Science Slam präsentieren drei bis vier Forschende ihre Antwort darauf. Der Ausgangspunkt ist ein gemeinsames WissKomm-Buchprojekt namens „Weltrettung braucht Wissenschaft\", in dem sich zwölf junge Wissenschaftler*innen und Science Slammys der Frage stellen, was ihr Fachgebiet der Menschheit rät. Woraus bauen Plastikforscher die Welt? Und wie landet ihr Baustoff auf unserem Teller? Ist künstliche Intelligenz wirklich rassistisch und Medizin überwiegend für Männer? Haben Klimatologinnen eigentlich noch Hoffnung, oder weiß der Historiker da mehr? Auf dem Weg entsteht aber auch Zukunftsmusik: Verkehrsmittel, von denen Ingenieurinnen träumen, und Städte, in denen sich Füchse tummeln; auf Gentechnik basierte Medikamente und biologisch abbaubares Verpackungsmaterial. Oder, noch revolutionärer: Wege, wissenschaftliche Erkenntnisse einzusetzen, bevor es brennt. ","duration":2400,"logo":"/system/events/logos/000/011/825/original/WBW_Sticker_95x95_3mm2.jpg?1698866922","type":"lecture","do_not_record":false,"track":"Entertainment","abstract":"Im Science Slam-Stil spekulieren Forschende, wie die Welt aussähe, wenn irgendjemand auf ihr Fachgebiet hören würde. Die Erkenntnisse reichen von Energiewende und Biodiversität bis zu Neurowissenschaften und geschlechtergerechter Medizin. Nach dem Chaos Communication Camp jetzt auch in Hamburg.","speakers":[{"guid":"f71463e0-8425-5c4a-a05b-98977dbe35f8","id":19158,"image":null,"name":"FrancaParianen","public_name":"FrancaParianen","abstract":null,"description":null,"links":[]}],"start_time":"2023-12-28T19:15:00.000+01:00","end_time":"2023-12-28T19:55:00.000+01:00","room":{"name":"Saal 1","id":471}},{"id":12224,"guid":"86f33115-6384-447d-96fb-278ed5790d0f","title":"Security Nightmares","subtitle":null,"description":"Wie immer wagen wir den IT-Security-Alptraum-Ausblick auf das Jahr 2024 und darüber hinaus. Denn was wir wirklich wissen wollen, ist ja schließlich: Was kriecht, krabbelt und fliegt in Zukunft auf uns zu und in unseren digitalen Implants herum?\r\n\r\nIm Zuge von noch mehr Transparenz, Kritik \u0026 Selbstkritik und kontinuierlicher nachhaltiger Optimierung aller Prozesse werden wir außerdem frühere Voraussagen hinsichtlich des Eintreffens unserer Weissagungen prüfen.","duration":3600,"logo":null,"type":"lecture","do_not_record":false,"track":"CCC","abstract":"Was hat sich im letzten Jahr im Bereich IT-Sicherheit getan? Welche neuen Entwicklungen haben sich ergeben? Welche neuen Buzzwords und Trends waren zu sehen?","speakers":[{"guid":"a0a13e2f-44e9-5515-ae0e-e29757c45310","id":1633,"image":"/system/people/avatars/000/001/633/original/9.jpg?1360200570","name":"frank","public_name":"frank","abstract":"Spokesperson of the Chaos Computer Club and expert on secure communications","description":null,"links":[{"url":"https://duckduckgo.com/?q=frank+rieger+ccc","title":"everything you need to know"},{"url":"http://frank.geekheim.de/","title":"blog"}]},{"guid":"41f383d6-2c5e-553f-974c-584324bd131f","id":9778,"image":null,"name":"Ron","public_name":"Ron","abstract":"Congressvorträge seit Eidelstädter Bürgerhaus.","description":null,"links":[]}],"start_time":"2023-12-30T17:15:00.000+01:00","end_time":"2023-12-30T18:15:00.000+01:00","room":{"name":"Saal 1","id":471}},{"id":12248,"guid":"c557380d-f955-4810-938b-c3bae50cd263","title":"Seeds of Change","subtitle":"Unlearning \u0026 Radical Collective Change in Online Communities","description":"It's plain to see: modern societies need to undergo radical social, political, and cultural transformations if they are to truly evolve away from capitalist and neocolonial structures founded on egregious exploitation and injustice. \r\n\r\nIn a context of widespread epistemic fragmentation and echo chambers, we urgently need to become better at harnessing the generative power of socio-technical networks to unite our forces as we compost the harmful ways of being, knowing, and doing that are at the root of our our planetary predicament. But we must do so critically, and not view technology as a miracle solution to anything.\r\n\r\nWhat could be the role of the internet, and of online communities in particular, in exploring how such deep changes might happen? And how may everyone's wisdom and skills come together in democratic and sophisticated social (un)learning systems, to figure out the way(s) forward?\r\n\r\nIn this talk, we will discuss the results of a 5-year participatory action research program which considered this topic within two different online communities of activists. This project led the researchers to tackle the idea of radical collective change as involving a decolonial approach to collaboration, knowledge, and community-building, and to consider the enabling and disabling conditions - both social and technological - that may influence whether change happens... or not.\r\n\r\nIn particular, this research highlighted the importance of enabling participants to engage on an equal footing and self-organise, while learning to \"stay with the trouble\" of confronting modern societies' fundamentally unsustainable and oppressive structures, and one's own implication in them. And it also showed some of the pitfalls that come with the use of digital communication tools, as we try to use them to create a better world. \r\n\r\nThree of the many insights I will substantiate and examine in the talk are:\r\n- that online communities have the potential to create deep changes in people when they are built in ways that foster deep relationships, criticality and conflict transformation, and emergent leadership;\r\n- that changing socio-political structures must go together with joyful, liberating practices that can help us unlearn harmful cultural patterns that get in the way; and\r\n- that perhaps we should be less interested in becoming experts, and rather find the courage and open hearts allowing us to be fearlessly and fiercely present to the world, with all its shit, its wonder, and its uncertainty.\r\n\r\nFeeling curious? Join us for a chat on how to change the world!","duration":2400,"logo":"/system/events/logos/000/012/248/original/The_Sower-small.jpg?1701347081","type":"lecture","do_not_record":false,"track":"Sustainability \u0026 Climate Justice","abstract":"Let's explore how online communities of activists can help to bring about forms of radical collective change, through decolonial practices of social (un)learning. What enabling conditions need to be put in place? And what counts as \"radical change\" in the first place?!","speakers":[{"guid":"ebb28786-0c66-5a30-be76-9bcc84e04c9b","id":19345,"image":"/system/people/avatars/000/019/345/original/people_avatars_000_019_345_large_IMG_4962-small.JPG?1701347681","name":"Dorian Cavé","public_name":"Dorian Cavé","abstract":"After a decade spent in East Asia, where he was last seen running an underground arts center and working as a translator, Dorian Cavé is now completing his PhD degree at the University of Cumbria and the University of Lancaster (UK). Within the context of the unprecedented challenges that humanity is facing in this 21st century, his research focuses on the question of how online networks may foster and enable radical collective change through social learning. Through his work in online communities and his research, Dorian is keen to explore the potential for social transformations in response to the global predicament. Simultaneously, he is working on developing his skills as a facilitator of self-organised groups, and eager to experiment with practices of mutual and social learning within such processes.","description":null,"links":[{"url":"Research blog","title":"https://engramseeker.wordpress.com/"}]}],"start_time":"2023-12-29T14:45:00.000+01:00","end_time":"2023-12-29T15:25:00.000+01:00","room":{"name":"Saal Zuse","id":473}},{"id":12125,"guid":"097a5331-c705-4c1b-a77c-85397cfca426","title":"Self-cannibalizing AI","subtitle":"Artistic Strategies to expose generative text-to-image models ","description":"The talk will be conducted by sharing various experiments we've done under the umbrella of generative AI models. We will begin with a general idea of how we, as artists/programmers, perceive these models and our research on the workflow of these constructs. Then, we will further elaborate on our exploration of the Stable Diffusion pipeline and datasets. Throughout our investigation, we discovered that some essential parts are all based on the same few datasets, models, and algorithms. This causes us to think that if we investigate deeper into some specific mechanisms, we might be able to reflect on the bigger picture of some political discourses surrounding generative AI models. We deconstructed the models into three steps essential to understanding how they worked: dataset, embedding, and diffusions. Our examples are primarily based on Stable-Diffusion, but some concepts are interchangeable in other generative models.\r\n\r\nAs datasets and machine-learning models grow in scale and complexity, understanding their nuances becomes challenging. Large datasets, like the one for training Stable Diffusion, are filtered using algorithms often employing machine learning. To \"enhance\" image generation, LAION's extensive dataset underwent filtering with an aesthetic prediction algorithm that uses machine learning to score the aesthetics of an image with a strong bias towards water-color and oil paintings. Besides the aesthetic scoring of images, images are also scored with a not safe-for-work classifier that outputs a probability of an image containing explicit content . This algorithm comes with its own discriminatory tendencies that we explore in the talk and furthermore asks how and by whom we want our datasets to be filtered and constructed.\r\n\r\nMany generative models are built upon Contrastive Language-Image Pre-training (CLIP) and its open-source version, Open-CLIP, which stochastically relates images and texts. These models connect images and text, digitize text, and calculate distances between words and images. However, they heavily rely on a large number of text-image pairs during training, potentially introducing biases into the database. We conducted experiments involving various \"false labelling\" scenarios and identified correlations. For instance, we used faces from ThisPersonDoesNotExist to determine \"happiness\" faces, explored ethnicities and occupations on different looks, and analyzed stock images of culturally diverse food. The results often align with human predictions, but does that mean anything? \r\n\r\nIn the third part, we take a closer look at the image generation process, focusing on the Stable Diffusion pipeline. Generative AI models, like Stable Diffusion, have the ability not only to generate images from text descriptions but also to process existing images. Depending on the settings, they can reproduce input images with great accuracy. However, errors accumulate with each iteration when this AI reproduction is recursively used as input. We observed that images gradually transform into purple patterns or a limited set of mundane concepts depending on the parameters and settings. This raises questions about the models' tendencies to default to learned patterns.","duration":3600,"logo":"/system/events/logos/000/012/125/original/ccc.001.jpeg?1699721536","type":"lecture","do_not_record":false,"track":"Art \u0026 Beauty","abstract":"What occurs when machines learn from one another and engage in self-cannibalism within the generative process? Can an image model identify the happiest person or determine ethnicity from a random image? Most state-of-the-art text-to-image implementations rely on a number of limited datasets, models, and algorithms. These models, initially appearing as black boxes, reveal complex pipelines involving multiple linked models and algorithms upon closer examination. We engage artistic strategies like feedback, misuse, and hacking to crack the inner workings of image-generation models. This includes recursively confronting models with their output, deconstructing text-to-image pipelines, labelling images, and discovering unexpected correlations. During the talk, we will share our experiments on investigating Stable-Diffusion pipelines, manipulating aesthetic scoring in extensive public text-to-image datasets, revealing NSFW classification, and utilizing Contrastive Language-Image Pre-training (CLIP) to reveal biases and problematic correlations inherent in the daily use of these models.","speakers":[{"guid":"92d08e4f-ca3b-5898-8ed8-8a5ef7663fc6","id":19283,"image":"/system/people/avatars/000/019/283/original/photoGlitchBW.jpg?1699712400","name":"Ting-Chun Liu","public_name":"Ting-Chun Liu","email":"t.liu@khm.de","abstract":"Ting-Chun Liu is a media artist from Taiwan who is a postgraduate at the Academy of Media Arts Cologne. He works with audiovisual media, sounds, natural language processing and artificial intelligence. He uses feedback mechanisms for generative images and sounds to reflect on the collective unconscious and the unattainable \"ideal\" perspective in AI-generated images.","description":null,"links":[{"url":"https://www.liutingchun.com","title":"website"}]},{"guid":"cdeed87b-4823-55b2-8b2d-59b24216adc6","id":19284,"image":"/system/people/avatars/000/019/284/original/profile_9WYZOl4.jpeg?1699746246","name":"Leon-Etienne Kühr","public_name":"Leon-Etienne Kühr","abstract":"Leon-Etienne Kühr ist sowohl als Informatiker als auch als Medienkünstler tätig und verwendet Methoden aus dem Bereich der Informationsvisualisierung und der Datenwissenschaft. Sein Schwerpunkt liegt auf der Erforschung und Visualisierung von Datensätzen und Modellen, die sich durch KI-gesteuerte Automatisierung allmählich in unseren Alltag integrieren. Seine künstlerischen Arbeiten befassen sich mit der Frage, wie unsere aktuelle algorithmische Landschaft möglicherweise eine Zukunft prägen könnte, in der sich der Schwerpunkt von der Mensch-Maschine-Interaktion zu einem Feedback von Maschine zu Maschine verlagert.","description":null,"links":[{"url":"leon-etienne.de","title":"Leon-Etienne Kühr - Website"}]}],"start_time":"2023-12-30T16:00:00.000+01:00","end_time":"2023-12-30T17:00:00.000+01:00","room":{"name":"Saal Grace","id":472}},{"id":12298,"guid":"65206c56-8766-4809-8d3b-9eb8028a63fe","title":"Should e-voting experience of Estonia be copied?","subtitle":"Observer report of 2023 parliament elections","description":"Electronic voting is hard to observe because one can't directly see into computers. In case of Estonia, the cryptographic measures to verify the processes are only partially implemented, but as voters have to download a voting application that implements a protocol with a public specification, observers/voters can obtain a special insight into processes by implementing their own tools to cast and verify the votes.\r\n\r\nEngaging in that kind of participative observation with special tools in 2023 parliamentary elections in Estonia it appeared that the official voting software implemented the process that was not following the specification up to the point of diverging from legal requirements set in laws and subordinate regulative acts. In addition to couple of vote containers that were processed ignoring the requirements, in the end it appeared that arguably all 312 181 electronic votes cast with official voting application had invalid digital signatures and failed to specify electoral district in vote text.\r\n\r\nIn paper ballot elections these kinds of ballots would have been declared invalid without hesitation, but electoral complaints filed about such electronic votes were dismissed without explanation of why ballots clearly not conforming to legal requirements were counted. This has resulted in a parliament where 22 of 101 representatives have arguably gained their mandate based on invalid ballots, but moreover this indicates that after about 20 years of electronic voting in Estonia, in order to run the elections huge amounts of legal and technical make-believe is needed.\r\n\r\nIf manageable in small scale pilots and elections with low importance, this is hardly a case with 51% of the voters in parliament elections casting their votes online -- during times of political polarisation increasing unprecedented highs.","duration":2400,"logo":"/system/events/logos/000/012/298/original/votes-without-ballots.png?1699747018","type":"lecture","do_not_record":false,"track":"Ethics, Politics \u0026 Society","abstract":"Although electronic voting has been used 13 times in various elections in Estonia since 2005, the legal, procedural and technical problems are far from solved, but have rather backfired in political situation getting more complicated.","speakers":[{"guid":"f7008314-2586-5799-aad3-10836e3023a3","id":19249,"image":"/system/people/avatars/000/019/249/original/tramm-toome.jpg?1701613130","name":"Märt Põder","public_name":"Märt Põder","email":"tramm@infoaed.ee","abstract":"Digital rights activist from Estonia with academic background in philosophy, teaching and informatics, former board member at local branches of Wikimedia and Open Knowledge, currently at Internet Society Estonia.","description":null,"links":[{"url":"https://gafgaf.infoaed.ee/en/","title":"Blog"},{"url":"https://mstdn.social/@tramm","title":"Mastodon"}]}],"start_time":"2023-12-30T12:00:00.000+01:00","end_time":"2023-12-30T12:40:00.000+01:00","room":{"name":"Saal Zuse","id":473}},{"id":11782,"guid":"1154a1e3-c7fd-404d-8cab-0d3a8a9b7fc2","title":"SMTP Smuggling – Spoofing E-Mails Worldwide","subtitle":null,"description":"SMTP, the Simple Mail Transfer Protocol, allows e-mailing since 1982. This easily makes it one of the oldest technologies amongst the Internet. However, even though it seems to have stood the test of time, there was still a trivial but novel exploitation technique just waiting to be discovered – SMTP smuggling!\r\nIn this talk, we’ll explore how SMTP smuggling breaks the interpretation of the SMTP protocol in vulnerable server constellations worldwide, allowing some more than unwanted behavior. Sending e-mails as admin@microsoft.com to fortune 500 companies – while still passing SPF checks – will be the least of our problems!\r\nFrom identifying this novel technique to exploiting it in one of the most used e-mail services on the Internet, we’ll dive into all the little details this attack has to offer. Therefore, in this talk, we’ll embark on an expedition beyond the known limits of SMTP, and venture into the uncharted territories of SMTP smuggling!","duration":2400,"logo":"/system/events/logos/000/011/782/original/SMTP_Smuggling-37C3_Logo.png?1701798519","type":"lecture","do_not_record":false,"track":"Security","abstract":"Introducing a novel technique for e-mail spoofing.","speakers":[{"guid":"2766551d-bb63-5537-a74f-37e4d014e872","id":19110,"image":"/system/people/avatars/000/019/110/original/IMG_20220802_080009-PhotoRoom.png?1698483312","name":"Timo Longin","public_name":"Timo Longin","abstract":"Broken stuff enthusiast","description":"Timo Longin (also known as Login) is a security consultant at day and a security researcher at night. Aside from everyday security assessments, he publishes blog posts and security tools, holds talks at conferences and universities,  and has a passion for CTFs. His main focus is on web applications; however, infrastructure and hardware are not safe from him either. For example, in his prior research, Timo discovered DNS vulnerabilities in web applications, hosting providers and even entire countries! As a well-rounded offensive security researcher, he tries to find forgotten and new exploitation techniques that make the unthinkable possible!","links":[{"url":"https://twitter.com/timolongin","title":"Twitter/X"},{"url":"https://infosec.exchange/@login","title":"Mastodon"}]}],"start_time":"2023-12-27T21:10:00.000+01:00","end_time":"2023-12-27T21:50:00.000+01:00","room":{"name":"Saal 1","id":471}},{"id":11721,"guid":"531a4c8b-dd21-49b8-b9d2-e77a39333446","title":"Social Engineering: Geschichte, Wirkung \u0026 Maßnahmen.","subtitle":"Alles, was ihr immer über Social Engineering wissen wolltet, aber nie die Zeit hattet, zu erfragen.","description":"\u003cp\u003eÜber verschiedene Epochen hinweg hat sich Social Engineering stets in der kriminellen Nutzung hervorgetan. Professionelle Hochstapler, Trickbetrüger und Agenten nutzten Social Engineering erfolgreich für kriminelle Unterfangen, Datensammlung oder einfach weil es Spaß machte. Doch Social Engineering ist eigentlich ein sehr alltägliches Phänomen. Jeder Mensch ist mindestens in seiner Kindheit ein geschickter Social Engineer. Manche machen es sich zum Beruf, sei es als Verkäufer oder Red-Teamer. Denn Social Engineering ist in seinem Kern die Kunst der Überzeugung anderer Personen.\u003c/p\u003e\r\n\r\n\u003cp\u003eDie psychologische Forschung hat sich seit den 1970ern intensiv damit beschäftigt, wie andere Menschen sich überzeugen lassen und welche Methoden dafür geeignet sind. Die zentralen Modelle und Konzepte wie das ELM-Modell und verschiedene kognitive Verzerrungen (Biases) werden vorgestellt, es wird praktisch veranschaulicht, welche Rolle sie für Social Engineering spielen. Einige Mythen, die in Bezug auf Social Engineering im Umlauf sind, werden beschrieben und aufgeklärt, die ein oder anderen Fun Facts, die so vielleicht noch nicht allen bekannt sind, zur Sprache kommen. Im finalen Teil des Vortrags dreht sich alles um den größten Bereich von bösartigem Social Engineering, der heutzutage online stattfindet. Ich werde die grundlegenden Klassifizierungen von Social Engineering praktisch relevant anhand neuester Forschung erklären und Maßnahmen aufzeigen, die wirklich helfen - konträr zu dem, was einige Berater gerne verkaufen.\u003c/p\u003e","duration":3600,"logo":null,"type":"lecture","do_not_record":false,"track":"Science","abstract":"In diesem Vortrag beschreibe ich die Geschichte und den Gegenstand des Social Engineerings über den Tech-Kontext hinaus und erkläre anhand  relevanter Forschung, wie, warum und bei wem es wirkt. Die modernen technischen Herausforderungen werden ebenso erläutert wie Maßnahmen, die jetzt oder in der Zukunft gegen Social Engineering getroffen werden können – individuell oder in Gruppen bzw. Organisationen. ","speakers":[{"guid":"87966032-3c4b-5369-ba16-21f17bac15d3","id":18754,"image":null,"name":"K4tana","public_name":"K4tana","abstract":"I am a psychologist researching social engineering and usable security at Leibniz-University Hannover, Germany. My Interests are focused on phishing mail research and usability of secure, privacy preserving technologies in that domain.","description":null,"links":[]}],"start_time":"2023-12-29T14:45:00.000+01:00","end_time":"2023-12-29T15:45:00.000+01:00","room":{"name":"Saal 1","id":471}},{"id":12047,"guid":"5807147b-2374-4ae0-b53c-a4cea848240c","title":"Software Licensing For A Circular Economy","subtitle":"What's FOSS Got To Do With It","description":"Digital technology is a major contributor to environmental harm, from the 'tsunami' of e-waste filling landfills to the CO2 emissions on a par with aviation industry. Often overlooked is that software -- and software licenses -- play a crucial role.\r\n\r\nSoftware and hardware are inextricably linked. A Free \u0026 Open Source Software license can disrupt the produce-use-dispose linear model of hardware consumption and enable the shift to a reduce-reuse-recycle circular model. Moving to a circular economy could reduce greenhouse gas emissions globally by up to 70%!\r\n\r\nIn this talk I provide an overview of the environmental harm driven by software and how FOSS is well-positioned to address the issues. I will link the inherent values that come with a Free \u0026 Open Source Software license to sustainable software design, and I will present the various ways that Free Software aligns with the Blue Angel ecolabel. Finally, I will provide an overview of the current sustainability goal of KDE and the work of the KDE Eco initiative. This includes publishing the KDE Eco handbook, setting up a measurement lab for FOSS developers (KEcoLab), squashing hundreds of efficiency bugs, among others.","duration":2400,"logo":"/system/events/logos/000/012/047/original/KDE-eco-logo-domain.png?1702298584","type":"lecture","do_not_record":false,"track":"Sustainability \u0026 Climate Justice","abstract":"In this talk I provide an overview of the environmental harm driven by software and how FOSS is well-positioned to address the issues. I will link the inherent values that come with a Free \u0026 Open Source Software license to sustainable software design, and I will present the various ways that Free Software aligns with the Blue Angel ecolabel. Finally, I will provide an overview of the current sustainability goal of KDE and the work of the KDE Eco initiative. This includes publishing the KDE Eco handbook, setting up a measurement lab for FOSS developers (KEcoLab), squashing hundreds of efficiency bugs, among others.","speakers":[{"guid":"8d2cb4eb-0e52-5348-bf25-044805c3e967","id":19323,"image":"/system/people/avatars/000/019/323/original/joseph_100x100px.jpg?1701438520","name":"Joseph De Veaugh-Geiss","public_name":"Joseph De Veaugh-Geiss","abstract":"Joseph P. De Veaugh-Geiss (he/him) is the community manager of the KDE Eco project. The goal of KDE Eco is to strengthen sustainability as part of the development and adoption of Free Software.","description":null,"links":[]}],"start_time":"2023-12-28T12:00:00.000+01:00","end_time":"2023-12-28T12:40:00.000+01:00","room":{"name":"Saal Grace","id":472}},{"id":11835,"guid":"28d952ff-1cae-4fe9-a31e-67c431c3da69","title":"Sonic Alchemy","subtitle":"Mehr als nur Lärm: Ein Sprint vom kleinen Audio-Einmaleins bis zum Phasealignment mit FFT-Analyzer","description":"Was ist zu tun gegen störendes Brummen? Wie versteht man Sensitivity und Gainstruktur? Was bedeutet eigentlich 'Phase'? Und wie positioniert man Subwoofer optimal? In diesem Vortrag möchte ich solche und weitere häufig auftretende Probleme bei der Verwendung von Tontechnik und Lautsprechern beleuchten. Ziel ist es, praxisnahe Lösungen und Tipps zu präsentieren, um das Beste aus deinem nächsten Projekt herauszuholen und gängige Herausforderungen erfolgreich zu meistern.","duration":2400,"logo":"/system/events/logos/000/011/835/original/logo.png?1698926172","type":"lecture","do_not_record":false,"track":"Hardware \u0026 Making","abstract":"Mehr als nur Lärm: Ein Sprint vom kleinen Audio-Einmaleins bis zum Phasealignment mit FFT-Analyzer\r\n\r\nVon “Disco Dieter” bis zur ausgewachsenen Stadioninstallation - gegen physikalische Grundprinzipien kann man wenig tun. Manchmal kann man Sie für sich nutzen, meistens geht man Kompromisse ein. Oft lässt sich mit einfachen Mitteln Sound verbessern.","speakers":[{"guid":"f0229928-805c-5025-ab6a-9c8670b3327b","id":19131,"image":null,"name":"Veit","public_name":"Veit","abstract":null,"description":null,"links":[]}],"start_time":"2023-12-29T00:10:00.000+01:00","end_time":"2023-12-29T00:50:00.000+01:00","room":{"name":"Saal Zuse","id":473}},{"id":12333,"guid":"b22ac244-6163-4f0e-9559-d01772a3a337","title":"State of Affairs in the case of Julian Assange","subtitle":"The situation, context and significance of the case in a geopolitical context","description":"In this talk, Stark will give an overview of the legal and political state of play in the Assange case. He will outline both possible consequences of what could happen if we fail to win Assange's freedom but also the political motive behind his prosecution. Stark also will describe from an insider’s perspective the tense relationship between traditional media and Wikileaks, in particular the person of Julian Assange. \r\n\r\nHolger Stark initiated an open letter from Wikileaks partner media at the end of November 2022. In it, the New York Times, the Guardian, Der Spiegel, Le Monde and El País call on the US government to stop prosecuting Assange. The indictment by the USA represents a dangerous precedent for freedom of expression and freedom of the press, write the editors-in-chief and publishers: \"Journalism\" is \"not a crime\". \r\n\r\nStark covered the Wikileaks publications for Der Spiegel in 2010. On one hand, the media partners did business with Wikileaks, on the other hand, they claimed that Assange’s faith was none of their business. Stark says he „had the impression that something simply had to happen.\"","duration":2400,"logo":null,"type":"lecture","do_not_record":false,"track":"Ethics, Politics \u0026 Society","abstract":"In this talk, Holger Stark will give an overview of the legal and political state of play in the Assange case. He will outline both possible consequences of what could happen if we fail to win Assange's freedom but also the political motive behind his prosecution. Stark also will describe from an insider’s perspective the tense relationship between traditional media and Wikileaks, in particular the person of Julian Assange. ","speakers":[{"guid":"921dafa0-1382-5c50-a5aa-cf139f2c2779","id":19514,"image":"/system/people/avatars/000/019/514/original/06_lowres.jpg?1702037292","name":"Holger Stark","public_name":"Holger Stark","abstract":"Deputy Editor in Chief of the Newspaper DIE ZEIT and head of investigative team. \r\n","description":"Holger Stark was working for 16 years at DER SPIEGEL before he joined DIE ZEIT. In 2010, he coordinated SPIEGEL'S coverage of the Wikileaks files. He met Assange multiple times and wrote together with Marcel Rosenbach the bestseller \"Staatsfeind Wikileaks\". In 2013, he revealed several NSA programs, among them the surveillance of Chancellor Merkel's cell phone. ","links":[]}],"start_time":"2023-12-27T19:15:00.000+01:00","end_time":"2023-12-27T19:55:00.000+01:00","room":{"name":"Saal 1","id":471}},{"id":11943,"guid":"c03e4258-ce88-40b2-b380-3d6b6d465abd","title":"Sucking dust and cutting grass: reversing robots and bypassing security","subtitle":null,"description":"We will present the result of the research that started back in 2018. Explore with us the development on the last years. How did the security and privacy of our mystery vendors change in contrast to other companies? What kind of cool hardware is out there? Can the devices be used to potentially spy on you?\r\n\r\nLearn how reverse engineering works and how to get root access on the devices. Let us show you how you maintain persistence on the devices and run your own software.\r\n\r\nCome with us on a journey of having fun hacking interesting devices while exploring bad oversights and real problems. You will be surprised what we found. Let's discuss together what impact this devices will have on our (social) life and what the future of vacuum robot hacking will bring.\r\n","duration":3600,"logo":null,"type":"lecture","do_not_record":false,"track":"Security","abstract":"For the past 5 years we have been presenting ways to hack and root vacuum robots at various events like CCC and DEFCON. In all these cases it covered vacuum robots by Roborock, Dreame, Xiaomi and some smaller companies.\r\n\r\nHowever, did we ever take a look at other vendors and maybe some new interesting device classes? In this talk we do exactly that!","speakers":[{"guid":"1a7076ed-0b43-5adb-ae5d-799923e9d0ef","id":7869,"image":null,"name":"Dennis Giese","public_name":"Dennis Giese","email":"dennis@dontvacuum.me","abstract":"Dennis Giese is a researcher with focus on the security and privacy of IoT devices. While being interested in physical security and lockpicking, he enjoys applied research and reverse engineering malware and all kinds of devices. \r\n\r\nHis most known projects are the documentation and hacking of various vacuum robots. He calls himself a \"robot collector\" and his current vacuum robot army consists of over 60 different models from various vendors. \r\n\r\nHe talked about his research at the Chaos Communication Congress, REcon BRX, NULLCON and DEFCON.. ","description":null,"links":[{"url":"https://twitter.com/dgi_DE","title":"Twitter"},{"url":"https://dontvacuum.me","title":"Website"},{"url":"https://www.youtube.com/@dennisgiese5591","title":"Youtube"}]},{"guid":"948d2532-c326-5da3-bde7-6bdb6e4ac4df","id":19273,"image":null,"name":"braelynn ","public_name":"braelynn ","abstract":null,"description":null,"links":[]}],"start_time":"2023-12-27T23:00:00.000+01:00","end_time":"2023-12-28T00:00:00.000+01:00","room":{"name":"Saal Grace","id":472}},{"id":12167,"guid":"f3ed5e42-6b9c-4fe8-b06a-95869edbbb19","title":"Synthetic Sentience","subtitle":"Can Artificial Intelligence become conscious?","description":"After many attempts to build AI models that are smarter than human beings, we find ourselves confronted with a family of surprisingly successful systems that match many of our abilities through text prediction and text/image correlation. The limits of these approaches are presently unclear, and while they work in very different ways than our minds, they pose the question whether consciousness, embodiment and motivation are necessary for achieving general intelligence. What are the differences between human (and animal) minds and the current generation of AI models? When we compare perspectives on mind and consciousness that have been developed in neuroscience, philosophy of mind, theoretical and therapeutic psychology, and numerous cultural traditions, and translate them into the metaphysics and conceptual frameworks of artificial intelligence, we may gain insights into this question.","duration":3600,"logo":"/system/events/logos/000/012/167/original/DALL%C2%B7E_2023-11-11_11.44.24_-_A_more_striking_version_of_the_logo_representing_machine_consciousness_and_philosophy__with_warmer_and_more_intense_colors._The_design_enhances_the_mi.png?1699731925","type":"lecture","do_not_record":false,"track":"Science","abstract":"Despite the rapid progress of AI capabilities, the core question of Artificial Intelligence seems to be still unanswered: What does it take to create a mind? Let us explore the boundaries of AI: sentience, self awareness, and the possibility of machine consciousness.\r\n","speakers":[{"guid":"e013dd2a-9ef7-5678-ad39-0da520154312","id":4034,"image":"/system/people/avatars/000/004/034/original/Screen_Shot_2023-10-24_at_13.44.40.png?1699391918","name":"Joscha","public_name":"Joscha","abstract":"AI researcher, cognitive scientist in San Francisco","description":"Joscha Bach studied computer science and philosophy in Berlin and New Zealand before embarking into Artificial Intelligence. He obtained his PhD in 2008 from the Institute of Cognitive Science in Osnabrück, founded IT companies, worked as research scientist at HU Berlin, Harvard, MIT and as principal research engineer at Intel Labs, and is now an Al researcher at LiquidAI. He is the author of the cognitive architecture MicroPsi; his main interests involve Artificial General Intelligence, and computational models of cognition, motivation and consciousness. ","links":[]}],"start_time":"2023-12-28T17:15:00.000+01:00","end_time":"2023-12-28T18:15:00.000+01:00","room":{"name":"Saal 1","id":471}},{"id":11996,"guid":"60e6f41c-ee8d-4196-88fd-e6a988947aee","title":"Tech(no)fixes beware!","subtitle":"Spotting (digital) tech fictions as replacement for social and political change","description":"The climate catastrophe is imminent and global injustice is rising. Now a lot of new (in part digital) tech (AI, blockchain, big data, fusion, quantum computing, genetic engineering) is supposed to help the transition to a sustainable society. Although some of them can actually help with parts of the transition, they are usually discussed not as tools to assist the broader societal change (economic, legal, social, political changes) but as replacement for the broader societal change. In effect they act as \"change placebos\" resulting in \"placebo change\", meaning no change at all.\r\n\r\nUsing concrete examples, this talk wants to 1) show in which ways technological fictions are misused as diversion from the necessary change or already existing other technologies, 2) present reasons and explanations for such misuse and 3) a simple method to spot tech(no)fixes. This talk underlines the necessity to design concrete technical use cases including their social conditions and limitations in order to create a fruitful debate for sustainability-assisting technologies and actually helpful implementations.","duration":2400,"logo":"/system/events/logos/000/011/996/original/fernfusion.png?1701603081","type":"lecture","do_not_record":false,"track":"Sustainability \u0026 Climate Justice","abstract":"Tech(no)fixes distract our minds and slow down necessary change. We will give examples, explain them and show you how to spot them.","speakers":[{"guid":"881a30e4-3cc3-5b20-8199-5cc820e26229","id":19235,"image":"/system/people/avatars/000/019/235/original/Hildebrandt-Friederike-SMN_211110_bund-069-Bearbeitet.jpg?1701602984","name":"Friederike Hildebrandt","public_name":"Friederike Hildebrandt","abstract":"Policy Advisor at Friends of the Earth Germany for digital policy.\r\nActivist for climate justice, urban policy and a good life for all.\r\n\r\n\r\n","description":null,"links":[]},{"guid":"96993a0c-ec68-52c8-b046-46c7a902df56","id":1642,"image":"/system/people/avatars/000/001/642/original/fiff_rainer_rehak.jpg?1701549550","name":"Rainer Rehak","public_name":"Rainer Rehak","abstract":"Rainer Rehak studied computer science and philosophy in Berlin and Hong Kong. Since then he has been working, researching and teaching in the fields of computer science \u0026 society, data protection and data security. He is a researcher at the Weizenbaum Institute for Networked Society. He is also very interested in the fields of artificial intelligence, transhumanism and political computer science, in particular government hacking. He is active in Computer professionalsPfor Peace and Social Responsibility (FIfF, board member), at Amnesty International (expert group on human rights in the digital age) and at the Gesellschaft für Informatik (steering committee ethics group). Together with others, he initiated the Bits\u0026Bees Conference, so hackers and eco activists increasingly join forces in the fight for a good future for all.","description":null,"links":[{"url":"https://www.weizenbaum-institut.de/portrait/p/rainer-rehak/","title":"Persönliche Webseite beim Weizenbaum-Institut"},{"url":"https://www.fiff.de","title":"Forum InformatikerInnen für Frieden und gesellschaftliche Verantwortung"},{"url":"https://www.amnesty-digital.de","title":"Amnesty International, Themenkoordinationsgruppe „Menschenrechte im digitalen Zeitalter“"},{"url":"https://bits-und-baeume.org/","title":"Bits\u0026Bäume-Konferenz (\u0026 die Bewegung)"},{"url":"https://mastodon.bits-und-baeume.org/@Rainer_Rehak","title":"Mastodon-Profil"}]}],"start_time":"2023-12-30T13:50:00.000+01:00","end_time":"2023-12-30T14:30:00.000+01:00","room":{"name":"Saal 1","id":471}},{"id":12020,"guid":"54e92649-de11-40d9-99b0-526fd4572107","title":"The Extremely Large Telescope (ELT)","subtitle":"Building the biggest optical telescope on earth","description":"The European Southern Observatory (ESO) is an intergovernmental organisation founded in 1962 and is based in Garching bei München. It develops, builds and operates ground-based telescopes to enable astronomical research in the southern hemisphere and to foster cooperation in the international astronomical community. In 2012 the ESO Council approved the Extremely Large Telescope (ELT) programme and its construction is scheduled for completion in 2028. The 39m primary mirror will make the ELT the largest optical telescope at that time.\r\n\r\nIt will be located on the top of Cerro Armazones, a ~3000m high mountain in the Atacama desert in Chile. This site provides ideal optical conditions, but also comes with logistical and engineering challenges.\r\n\r\nWe will walk you through the telescope and along the optical path to the instruments and explain some of the technologies involved to push the boundaries of ground-based optical astronomy.","duration":2400,"logo":"/system/events/logos/000/012/020/original/ELT4k-12-Night4-cc.jpg?1701696848","type":"lecture","do_not_record":false,"track":"Science","abstract":"The Extremely Large Telescope (ELT) is currently under construction in the Atacama desert in northern Chile by the European Southern Observatory (ESO). With a primary mirror aperture of 39m, it will be the largest optical telescope on earth. We will briefly introduce the history and mission of ESO and explain how a modern optical telescope works.","speakers":[{"guid":"279d0ab7-7c2b-5f9f-b00a-623389dd2582","id":18998,"image":null,"name":"lk","public_name":"lk","abstract":"Software Engineer at ESO","description":null,"links":[]},{"guid":"7049e6d9-59f7-58fa-95be-9f6fc4a5c8bf","id":5934,"image":null,"name":"panic","public_name":"panic","abstract":null,"description":null,"links":[]}],"start_time":"2023-12-27T22:05:00.000+01:00","end_time":"2023-12-27T22:45:00.000+01:00","room":{"name":"Saal Zuse","id":473}},{"id":12034,"guid":"5360db94-5bf0-421f-b442-231f2f69b6c7","title":"The impact of quantum computers in cybersecurity","subtitle":" Estimating the costs of algorithms for attacks and defense applications","description":"We will start with a fundamental introduction to quantum computing to ensure that the audience has a solid grasp of this model of computation, but without discussing the technicalities of quantum physics. Taking a \"software development\" perspective, we introduce the problem of estimating the resources needed to perform a quantum computation. Then, we will shift our focus to the two facets of our investigation: applications for offence and defence. \r\n\r\n\r\n\u003cg\u003eQuantum machine learning for defence:\u003c/g\u003e\r\n\r\nWe will explore the application of quantum machine learning algorithms in network intrusion detection. Quantum machine learning holds the potential for improving cybersecurity defences by leveraging quantum algorithms - exponentially faster than classical algorithm on their asymptotic complexity. We will introduce a framework for estimating the advantages of quantum algorithms in terms of query complexity, and report the findings of our experiments. Our findings will be based on practical experiments using benchmark datasets in cybersecurity, offering insights into the potential effectiveness of quantum approaches in this domain.\r\n\r\n\u003cg\u003eQuantum attacks on cryptography for offence:\u003c/g\u003e\r\n\r\nShifting our attention to the offensive side, we will investigate the potential impact of quantum attacks on cryptography. We will report some advancements in the number of qubits required to break RSA2048 cryptography and attacks on ECC256. Furthermore, we will delve into the complexities of post-quantum cryptography attacks. Our ongoing research at CQT (Centre for Quantum Technologies of Singapore) involves measuring the depth and size of quantum circuits, including the number of Toffoli gates and Toffoli-depth. We will also account for the qubit number and size of the QRAM query (quantum random access memory), providing a comprehensive assessment of the quantum attack landscape.\r\n\r\nUltimately, we will draw conclusions based on our research and analysis. While there is limited evidence suggesting that quantum computing will have a drastic impact on cybersecurity through machine learning or attacks on post-quantum cryptography, there are substantial reasons to believe that quantum computers, once they reach sufficient scale and capacity, will pose a significant threat to RSA2048 and ECC256. Join us for an insightful exploration of the evolving intersection of quantum computing and cybersecurity.","duration":2400,"logo":null,"type":"lecture","do_not_record":false,"track":"Science","abstract":"In in this talk we explore the potential ramifications of quantum computing in the field of cybersecurity  We'll delve into two critical aspects: the application of quantum machine learning algorithms for defence and the impact of quantum attacks on cryptography and post-quantum cryptography for offence. We'll present insights on the theoretical advantages of quantum algorithms, improvements in factoring large numbers, and the impacts of post-quantum crypto attacks. While the hype around quantum technologies is growing, the estimates in the resources needed to run a quantum algorithm and the current number of qubits pose caution in the enthusiasm. The limitations in terms of available qubits, error rates, and scalability are critical factors that need to be considered when assessing the real-world applicability of quantum computing.","speakers":[{"guid":"12929f9f-e8ce-5d2a-a614-3a066ef32001","id":18861,"image":null,"name":"Alessandro Luongo","public_name":"Alessandro Luongo","abstract":null,"description":null,"links":[]}],"start_time":"2023-12-28T12:55:00.000+01:00","end_time":"2023-12-28T13:35:00.000+01:00","room":{"name":"Saal Grace","id":472}},{"id":12087,"guid":"42b12dde-06ab-4372-8e3c-bcb6a0ed2541","title":"The Trouble with Green Electricity Certificates","subtitle":null,"description":"Within the EU and other European countries, the property of green electricity is traded in the form of certificates (\"Guarantees of Origin\"). While researching the situation of renewable energy in Iceland, I learned that the country exports large amounts of these green energy certificates. At the same time, Aluminium smelters and other energy-intensive companies within Iceland advertise with that same green electricity.\r\n\r\nUsing publicly available data, I could show that the same green electricity was claimed twice. This led to a temporary suspension of green electricity certificates from Iceland. Eventually, exports were allowed again, although the problems remained unsolved. The responsible authority (AIB) recently announced that it will not pursue further action.\r\n\r\nEventually, it came to light that very similar problems exist in Norway. The talk will also include some experiences using freedom of information laws in different countries.","duration":2400,"logo":"/system/events/logos/000/012/087/original/iceland-hydropower.jpg?1699707882","type":"lecture","do_not_record":false,"track":"Sustainability \u0026 Climate Justice","abstract":"Customers in European countries can choose electricity tariffs with 100% renewable electricity, and many companies advertise that their products are made with green energy. But often, the same green electricity is counted twice - and that is a problem.","speakers":[{"guid":"9ab9adbd-9ddb-52b6-9857-41b3e690c4c9","id":2462,"image":"/system/people/avatars/000/002/462/original/hanno.jpg?1699708026","name":"hanno","public_name":"hanno","abstract":"Hanno Böck is a freelance journalist. He covers climate, energy, and IT security. He is the author of a \u003ca href=\"https://industrydecarbonization.com/\"\u003enewsletter about industrial decarbonization\u003c/a\u003e.","description":null,"links":[{"url":"https://hboeck.de/","title":"Personal webpage"},{"url":"https://industrydecarbonization.com/","title":"Industry Decarbonization Newsletter"}]}],"start_time":"2023-12-27T11:00:00.000+01:00","end_time":"2023-12-27T11:40:00.000+01:00","room":{"name":"Saal Grace","id":472}},{"id":11748,"guid":"a88b52c5-050a-4dbb-a5f6-27093f402eed","title":"The Ultimate SPC700 Talk","subtitle":"The hardware behind the music of Super Mario World, Chrono Trigger, Super Metroid, and more","description":"The SPC700 by Sony is an 8-bit architecture that was developed and used as the S-SMP sound coprocessor in the Super Nintendo Entertainment System (SNES). A big leap ahead in sound synthesis capabilities, apart from these few years of glory in the 1990s the architecture enjoyed no further uses and has faded into obscurity outside SNES circles. This talk not only takes a look at the SPC700 architecture, which is both a usual and unusual 8-bit ISA, but also the sound and music capabilities of the SNES S-DSP that it was designed to control. The talk is designed to be approachable by anyone with a basic understanding of how a microprocessor works; in particular, it covers the basics of digital audio necessary to understand the S-DSP's sound synthesis features like ADPCM sample playback or echo buffers.","duration":3600,"logo":null,"type":"lecture","do_not_record":false,"track":"Hardware \u0026 Making","abstract":"The Super Nintendo Entertainment System's sound coprocessor, the S-SMP, runs on the mostly-forgotten SPC700 architecture. To understand why the sound of Super Metroid or SMW was so ahead of its time, we will look at all the details of how this processor works and how it plays music.","speakers":[{"guid":"2749dff9-0114-5216-9be6-072424364aaf","id":19057,"image":"/system/people/avatars/000/019/057/original/d3a4856215e948e3.png?1697980083","name":"kleines Filmröllchen","public_name":"kleines Filmröllchen","abstract":null,"description":null,"links":[]}],"start_time":"2023-12-30T14:45:00.000+01:00","end_time":"2023-12-30T15:45:00.000+01:00","room":{"name":"Saal 1","id":471}},{"id":11792,"guid":"e12908b4-4f5a-4b8b-8628-206f25b0d7f5","title":"The Unfolding Space Glove","subtitle":"A Wearable for the Visually Impaired Translating 3D Vision into Haptic Stimuli","description":"Being born blind or losing sight is a major challenge, as it impairs the ability to acquire information about surroundings, to manage everyday life independently and, consequently, to participate equally in social, public and economic life. Technical aids developed to assist VIPs with certain tasks work well in the laboratory but regularly fail in practice because they are bulky or user-unfriendly. As a result, the target group resorts to traditional tools or simply lives with the shortcomings. Given the rapid changes in technology and low cost of digital tools, I saw great potential in addressing this issue as an interaction design project.\r\n\r\nThe result is an open-source Sensory Substitution device – the Unfolding Space Glove: it transmits the relative position and distance of nearby objects, detected by an on-board 3D camera, to the back of the hand in the form of vibratory stimuli. This allows the user to haptically explore the depth of the surrounding space and assists with navigation tasks such as object recognition and wayfinding. The prototype requires no external hardware, is highly portable, works in all lighting conditions, and provides continuous and immediate feedback – all while being visually unobtrusive.\r\n\r\nThe basic premise of the proposed concept of Sensory Substitution is that the function of a missing or impaired human sensory modality can be replaced by stimulating another sensory modality using the missing information. This only works because the brain is plastic enough to learn to associate the new stimuli with the missing modality, as long as they share the same basic characteristics. There have been a number of projects looking at this, but so far very few practical implementations have been proposed, which in turn are used by a negligible number of people. While the technology used is sometimes highly sophisticated, design and usability often suffer.\r\n\r\nTaking into account the problems of existing devices and specifically addressing usability and interaction design requirements, the Unfolding Space Glove was designed and developed in a four-year interaction design research project. In 2021, the prototype was tested in an empirical study with 14 sighted and blind subjects, the results of which were published in a scientific, peer-reviewed paper in 2022.\r\n\r\nI would like to introduce you to the field of Sensory Substitution, share this project with you, show pitfalls, problems (for me coming from a non-IT background) and some technical details and ask for your feedback and input. I will have the device with me if you want to have a closer look at it after the talk. Testing would only be possible in smaller groups by appointment.","duration":2400,"logo":"/system/events/logos/000/011/792/original/Glove-closeup.jpeg?1698600857","type":"lecture","do_not_record":false,"track":"Hardware \u0026 Making","abstract":"The Unfolding Space Glove transmits the relative position and distance of nearby objects as vibratory stimuli to the back of the hand, enabling blind people to haptically explore the depth of their surroundings. The talk will give a brief overview of the design research project, from the first prototypes to an empirical study and its publication, and provide insights into the underlying hardware and software.","speakers":[{"guid":"13e23d90-0709-52a0-8985-381bdab49b43","id":19032,"image":"/system/people/avatars/000/019/032/original/Jakob_Kilian_landscape_klein.jpg?1701626210","name":"Jakob Kilian","public_name":"Jakob Kilian","email":"37c3@unfoldingspace.org","abstract":"Jakob is an interaction designer, interdisciplinary researcher, maker, DJ and human being. He uses prototypes as vehicles for exploration and conception as well as for iterative development and (re-)search. Jakob currently works as a scientific associate and lecturer at KISD (Cologne University of Applied Sciences) as part of the »KITeGG« consortium investigating the interplay between AI and design.","description":null,"links":[]}],"start_time":"2023-12-27T20:15:00.000+01:00","end_time":"2023-12-27T20:55:00.000+01:00","room":{"name":"Saal Zuse","id":473}},{"id":11993,"guid":"b3163149-505e-497e-9c75-7cb233b59fcd","title":"Toniebox Reverse Engineering","subtitle":"Eine Musikbox für Kinder, Maker und Hacker","description":"In unserem Vortrag über die Toniebox konzentrieren wir uns zunächst auf das Innenleben und die Funktionsweise dieses beliebten Audiogerätes für Kinder. Wir beginnen mit einer detaillierten Einführung in das Prinzip der Toniebox aus technischer Sicht und geben einen kurzen Überblick über die Hardwarekomponenten, insbesondere die verschiedenen Prozessorvarianten wie CC3200, CC3235 und ESP32.\r\n\r\nDer Übergang zu den Limitationen des Systems ist fließend: Wir diskutieren die künstlichen Beschränkungen durch den Hersteller, den Zwang zur Verwendung von Originalfiguren, die Inkompatibilität mit NFC-Tags von Drittanbietern und die hohen Kosten für bespielbare Figuren. Besonders kritisch sehen wir die vollständige Abhängigkeit von einer Hersteller-Cloud, die bei einem Ausfall des Anbieters das Gerät obsolet macht. Ein weiterer Fokus liegt auf dem ausgeprägten Datenhunger des Herstellers, der fast schon obsessiv das Nutzungsverhalten unserer Kinder aufzeichnet.\r\n\r\nIm Kern des Vortrags stellen wir die von uns entwickelten Open-Source-Alternativen vor. Mit der TeddyBench stellen wir einen Offline-Editor vor, mit dem Audiodaten für eigene NFC-Tags erstellt und verwaltet werden können. Die TeddyCloud bietet als selbstgehostete Lösung volle Kontrolle über die eigenen Daten, eine persönliche Audio-Bibliothek und die Möglichkeit, Nutzungsdaten über MQTT in den Home Assistant einzuspeisen, ohne die Funktionalität der Box einzuschränken. Außerdem stellen wir Custom Firmwares für CC3200 und ESP32 vor, die neue Einsatzmöglichkeiten eröffnen, und berichten über unsere Hardware-Modifikationen, die unter anderem Bluetooth-Audio ermöglichen und die Toniebox barrierefreier machen.","duration":3600,"logo":"/system/events/logos/000/011/993/original/tonie.png?1699623119","type":"lecture","do_not_record":false,"track":"Hardware \u0026 Making","abstract":"Ein Vortrag über den erfolgreichen Kinder-Audioplayer „Toniebox“ mit Content-Hosting in der Cloud, der nicht nur Einblicke in die (un-)heimliche Datensammlungspraxis bietet, sondern auch gleich passende Lösungen dazu. Custom-Firmware, selfhosted Cloud-Ersatz und Tools zum Erzeugen von Inhalten ohne Herstellercloud.","speakers":[{"guid":"894af5f8-0d9c-5976-9b3b-7c185c978bae","id":19220,"image":"/system/people/avatars/000/019/220/original/georg-hofstetter.1024x1024.jpg?1699624415","name":"g3gg0","public_name":"g3gg0","abstract":null,"description":null,"links":[{"url":"https://www.g3gg0.de/","title":"g3gg0.de"}]},{"guid":"0efe8f22-7f6c-5556-ad57-64d08890465d","id":18989,"image":null,"name":"0xbadbee","public_name":"0xbadbee","abstract":null,"description":null,"links":[]},{"guid":"da8b89ac-8c96-5395-9014-6246e9173bd6","id":19325,"image":null,"name":"Moritz","public_name":"Moritz","abstract":null,"description":null,"links":[]},{"guid":"c01f1d88-901d-5212-b592-54f5ddfc0d33","id":19327,"image":null,"name":"Gambrius","public_name":"Gambrius","email":"gambrius@gmail.com","abstract":null,"description":null,"links":[{"url":"http://www.gt-blog.de","title":"Gambrius Tech Blog"}]}],"start_time":"2023-12-27T14:45:00.000+01:00","end_time":"2023-12-27T15:45:00.000+01:00","room":{"name":"Saal Grace","id":472}},{"id":12040,"guid":"f4f03a06-76b1-40cf-b58f-cd902e93a688","title":"Tor censorship attempts in Russia, Iran, Turkmenistan","subtitle":null,"description":"On the depressing side, the global censorship trend continues to gain momentum, with some European countries alarmingly eager to get in on it. But resignation is boring: here we are, a tiny community of activists and relay/bridge operators around the world continuing to provide safe and private internet reachability for hundreds of thousands of people who are trying to be human beings under authoritarian regimes.\r\n\r\nWe will walk through *how* each of these countries deployed their Tor blocks, and what changes we made to let citizens continue to reach the Tor network. Looking at each case study through a Tor lens will let us compare/contrast the censorship attempts from each country, discuss future ideas for how to make sure the bytes can keep flowing, and talk through the political impacts.","duration":3600,"logo":"/system/events/logos/000/012/040/original/Tor_logo1.png?1699651230","type":"lecture","do_not_record":false,"track":"Ethics, Politics \u0026 Society","abstract":"In December 2021, months before the world watched Russia invade Ukraine, Russia rolled out comprehensive censorship of the Tor network and related Tor protocols. Then in October 2022, the latest wave of protests in Iran saw a huge spike in Tor usage followed by a swift crackdown of the most successful techniques. Meanwhile in 2023, Turkmenistan has blocked popular CDNs like Cloudflare and Akamai, most hosting providers like Hetzner and OVH, and much more.","speakers":[{"guid":"554fc099-bfa4-57ef-8711-ba2c4a7eea5c","id":19051,"image":"/system/people/avatars/000/019/051/original/Tor_logo1.png?1699649702","name":"Roger Dingledine","public_name":"Roger Dingledine","abstract":"Roger Dingledine is co-founder and original developer of the Tor Project, a nonprofit that develops free and open source software to protect people from tracking, censorship, and surveillance online.","description":"Roger is excited to be back at CCC! His first Congress was way back in 21c3, introducing Tor. Since then he has spoken at nine further Congresses, about censorship, onion services, anonymity, attacks, defenses, and more.\r\n\r\nWearing one hat, Roger works with journalists and activists on many continents to help them understand and defend against the threats they face. Wearing another, he is a lead researcher in the online anonymity field, coordinating and mentoring academic researchers working on  Tor-related topics. Since 2002 he has helped organize the yearly international Privacy Enhancing Technologies Symposium (PETS).","links":[{"url":"https://www.torproject.org/","title":"The Tor Project"},{"url":"https://freehaven.net/~arma/","title":"Roger's website from long ago"}]}],"start_time":"2023-12-28T23:00:00.000+01:00","end_time":"2023-12-29T00:00:00.000+01:00","room":{"name":"Saal Zuse","id":473}},{"id":11836,"guid":"4fc20f2f-c3a8-4823-9c81-374bd66b29f2","title":"Tractors, Rockets and the Internet in Belarus","subtitle":"How belarusian authoritarian regime is using technologies to repress it's population","description":"Republic of Belarus is ruled for last 29 years by authoritarian president Alexander Lukashenko. From the deputy chief of collective farm in USSR to the longest president in Europe, he continues to navigate complicated political scene between Russia/EU/US for his own advantage. \r\n\r\nNot even close to any technological sector through help of many Lukashenko turned Belarus into IT country with a lot western countries using developers from the dictatorship for their own project.\r\n\r\nThis presentation is about how the soviet modelled dictatorship managed to transform into technological authoritarian regime, where people are monitored and controlled of their loyalty to the regime, while also continuing a massive wave of repressions started from uprising against Alexander Lukashenko in 2020.\r\n\r\nThe presentation is made by a member of ABC-Belarus - a political solidarity organization from Belarus, working on supporting prisoners and developing security culture among street activists.","duration":2400,"logo":"/system/events/logos/000/011/836/original/logo_by.png?1698927476","type":"lecture","do_not_record":false,"track":"Ethics, Politics \u0026 Society","abstract":"With dropping costs of surveillance smaller authoritarian regimes are gaining easier access to different \"out of the box\" security solutions used mainly to further oppress people. On example of Belarus we will see the future that awaits people in many different parts of the world if things don't change fast.","speakers":[{"guid":"a8cf93b9-c8ff-5c77-8338-0b0ab0dcdd4e","id":19165,"image":"/system/people/avatars/000/019/165/original/logo_by.jpeg?1698926191","name":"ABC Belarus","public_name":"ABC Belarus","email":"belarus_abc@riseup.net","abstract":"Group working on support of political prisoners in Belarus. Following repression apparatus of the belarusian regime.","description":"Anarchist Black Cross Belarus (ABC-Belarus) supports repressed, arrested and imprisoned anarchists as well as social activists whose ideas and activities do not contradict the ideas of anarchism. Between 2009 and 2022 the group has supported more than 70 activists in various forms, ranging from paying lawyers and other legal fees to supporting the families and loved ones of the repressed.\r\n\r\nWe are not a charitable or human rights foundation and provide support primarily based on our political views and goals. Anarchist activists are often ignored by liberal human rights organizations, and repression is considered justified because of the violation of the laws of a country governed by dictatorship and police lawlessness. That is why it was important for us to create an activist organization that would be dedicated to supporting comrades regardless of any external political factors.\r\n\r\nThe group in its current form was founded in 2009 and has since become one of the main solidarity structures in Belarus. There are no paid positions in the group, and all work is done on a voluntary basis by anarchist activists.\r\n\r\nWe are not an open political group, so you can’t join us by choice, but you can always raise money or organize support groups for certain comrades in your area, without the need for direct membership. We are happy to help you if you would like to do this kind of work.\r\n\r\nThe ABC collective does not accept donations tied to any political conditions restricting our own actions. We do not write grants to obtain money, and the bulk of our funding comes through individual and collective donations. Money that comes to the ABC is used directly for various forms of support, most of which we cannot describe openly because of the high level of government repression.\r\n\r\nNot a single day in the existence of the collective has passed without anarchists or antifascists being held in Belarusian prisons. Solidarity allows comrades to continue to resist repression even in the most difficult moments of life. This is why we consider it extremely important to develop the infrastructure of the ABC not only in Belarus, but also in other countries, in order to create a truly international movement of solidarity.\r\n\r\nIf you have any questions for our group, you can contact us via e-mail belarus_abc@riseup.net or social networks:\r\n\r\nTelegram: https://t.me/belarus_abc\r\nTwitter: https://twitter.com/abcbelarus\r\nInstagram: https://instagram.com/belarus_abc/\r\n\r\nWe also have accounts on Signal and Matrix – email us to get in touch.\r\n\r\nIf you want to help or get in contact, please write to belarus_abc(AT)riseup.net\r\n\r\nPublic Key:\r\n\r\n-----BEGIN PGP PUBLIC KEY BLOCK-----\r\n\r\nxjMEZOMh7BYJKwYBBAHaRw8BAQdAvVGh6EjzgbeT3iBKzOIsOwGHuRTHwYEtUmAG\r\nR5DNyUPNMNCQ0KfQmi3QkdC10LvQsNGA0YPRgdGMIDxiZWxhcnVzX2FiY0ByaXNl\r\ndXAubmV0PsKPBBMWCAA3FiEEJDuk8hlWZ+wGk4QFs7UFIrZldBAFAmTjIewFCQWj\r\nmoACGwMECwkIBwUVCAkKCwUWAgMBAAAKCRCztQUitmV0EHWHAQDdmjYJcrdo9VIX\r\nLY5A+Am4bdRUnczk8NfUBlR/1smpmgEA1pXXE3ePDRmm/BKH2rgFdoH0vGAmPOZL\r\nhu5UXvSHJwPOOARk4yHsEgorBgEEAZdVAQUBAQdAUqRNqdhmSBXAwuWuoGPBvD7U\r\nNpcppYMq1NubpLufrGYDAQgHwn4EGBYIACYWIQQkO6TyGVZn7AaThAWztQUitmV0\r\nEAUCZOMh7AUJBaOagAIbDAAKCRCztQUitmV0EOZnAP4/CGim5T0TtZinzS7HDuxM\r\nd77qra3CiHgshN7SNYWN4AD/fCgzPS3iTG+Q8kJXYLztdt8dbGX2/mARyVpu/3a6\r\n4Qs=\r\n=fxr4\r\n-----END PGP PUBLIC KEY BLOCK-----\r\n\r\nFingerprint:\r\n243B A4F2 1956 67EC 0693 8405 B3B5 0522 B665 7410","links":[{"url":"abc-belarus.org","title":"website"},{"url":"https://instagram.com/belarus_abc/","title":"Instagram"}]},{"guid":"770241c7-f29f-52b2-af63-f11492b3aeee","id":19588,"image":null,"name":"ABC-Belarus 2","public_name":"ABC-Belarus 2","abstract":null,"description":null,"links":[]}],"start_time":"2023-12-28T13:50:00.000+01:00","end_time":"2023-12-28T14:30:00.000+01:00","room":{"name":"Saal Zuse","id":473}},{"id":11929,"guid":"010fec93-42dd-4039-a5aa-ac313d6a9541","title":"Turning Chromebooks into regular laptops","subtitle":"With the power of open source!","description":"In this talk you will learn how ChromeOS hardware designed by Google and it's board partners differ from regular laptops/desktops.\r\n\r\nWe'll go over Coreboot development (+guide of porting it to other x86 motherboards!), EDK2 (UEFI payload we use in our firmware builds) and what it takes to make mainline Linux run on these machines.\r\n\r\nThis talk will involve ACPI tables, I2C and SPI interfaces, DSP firmware and maintenance of audio stack that differs from (almost) all x86 machines in the market.\r\n\r\nWe'll present challenges we've faced during the development cycle, tips on how to avoid pitfalls, and our plans for the future :)","duration":2400,"logo":"/system/events/logos/000/011/929/original/134976671.png?1699480566","type":"lecture","do_not_record":false,"track":"Hardware \u0026 Making","abstract":"Deep dive into (ex)ChromeOS hardware from developer's perspective.","speakers":[{"guid":"2c269072-47d4-56e6-b0e1-472a8e69adc8","id":19264,"image":null,"name":"elly","public_name":"elly","abstract":"Hardware hacker with peculiar interest in embedded devices, Linux and Firmware","description":null,"links":[]}],"start_time":"2023-12-28T20:15:00.000+01:00","end_time":"2023-12-28T20:55:00.000+01:00","room":{"name":"Saal Grace","id":472}},{"id":12265,"guid":"1a9291bf-dab5-4824-8b20-ecb393c677a8","title":"Unlocked: PICing a wireless door access system","subtitle":null,"description":"Attend this talk for a presentation about an unusual variant of lock picking, which does not involve any wrenches, hooks or half-diamond picks. Instead the used tools are a software defined radio, PIC programmer and some self-developed software to gain access without using the original \u003cstrike\u003ekey\u003c/strike\u003e remote control.\r\n\r\nIf you had fun watching the \u003ca href=\"https://media.ccc.de/v/34c3-9029-uncovering_vulnerabilities_in_hoermann_bisecur\"\u003eHörmann BiSecur talk at 34C3\u003c/a\u003e, this talk is for you! If you haven't watched it, it is highly recommended to catch up on it before attending this talk. While it is about a different product from a different vendor, there are many parallels and it can be seen as a sequel talk.\r\n\r\nThe plan for this talk is to first have a look at the radio signals from the door lock using a SDR. After making sense of the used message protocol, the hardware is analyzed to understand how it works and how to get access to the used micro-controllers (PIC18LF45K80 \u0026 PIC16LF1829). In the next step, the firmware from the read-protected PIC microcontroller is extracted by extending the existing PIC attacks. Last but not least the results will be demonstrated.","duration":3600,"logo":null,"type":"lecture","do_not_record":false,"track":"Security","abstract":"Mainframe, Oldenburg's Hackerspace, needed a wireless door lock solution. We do not trust vendors advertising promises about the device security and had a closer look.","speakers":[{"guid":"0a2c9e78-a917-518b-8971-56b737852884","id":19207,"image":null,"name":"sre","public_name":"sre","email":"sre@mainframe.io","abstract":null,"description":"Sebastian Reichel AKA sre is a regular attendee of the Chaos Communication Congress and active in different areas more or less related to the CCC:\r\n\r\n\u003cul\u003e\r\n\u003cli\u003eCo-founder of \u003ca href=\"https://mainframe.io\"\u003eOldenburg's hackspace Mainframe\u003c/a\u003e\u003c/li\u003e\r\n\u003cli\u003eLinux kernel maintainer for battery related drivers\u003c/li\u003e\r\n\u003cli\u003eDebian developer\u003c/li\u003e\r\n\u003cli\u003eActive in \u003ca href=\"https://cert.ccc.de/\"\u003eCERT\u003c/a\u003e... \u003c/li\u003e\r\n\u003cli\u003eDeputy lead of public safety diver squad at the voluntary fire brigade\u003c/li\u003e\r\n\u003c/ul\u003e","links":[]}],"start_time":"2023-12-29T21:45:00.000+01:00","end_time":"2023-12-29T22:45:00.000+01:00","room":{"name":"Saal Zuse","id":473}},{"id":11903,"guid":"e9c56ad8-612e-4d2e-ab2b-2c5196b49196","title":"Unlocked! Recovering files taken hostage by ransomware","subtitle":"Decrypting files hijacked by the \"second most used ransomware in Germany\"","description":"We present an analysis of a popular ransomware and tools for recovering encrypted files without access to the official decryptor or key. We're discussing \"the second most used ransomware in Germany\", encrypting Windows computers and ESXi hosts running virtual machine workloads.\r\n\r\nOur decryptor-tool exploits a weakness in the cryptographic code in the malware. This weakness allows to (partially) recover encrypted files without access to the decryptor and without needing the cryptographic keys used by the ransomware.\r\n\r\nWe dive into the details of the cryptographic operations used by the malware and explain how it fails to use the cryptographic primitives properly. In particular, the ransomware encrypts victim files using a stream cipher. Files smaller than 5000 bytes are fully encrypted. Larger files are only partially encrypted for efficiency reasons. We found that for larger files, the ransomware re-uses the same cryptographic keystream for encrypting different parts of the same file, thereby breaking the security of the used stream cipher. If the plaintext of any encrypted file part is known, the keystream can be recovered and used to decrypt (large parts of) the target file without the underlying cryptographic key.\r\n\r\nAffected organisations can check whether the variant of the malware found in their network is susceptible to this attack by purposefully letting the ransomware encrypt a large file (512 MB) containing only zero bytes. If the encrypted parts of the file are identical when analysing the encrypted file (e.g. in a hex editor), recovery is likely possible using the tools presented here.\r\n\r\nDepending on the encrypted file, parts of the plaintext may be known. For instance, VM disk images are likely to contain stretches of zero bytes. As part of the tooling we have developed, we have implemented a heuristic to detect encrypted zero blocks in encrypted files. If found, (large parts of) the encrypted file can then be recovered. For other types of files, individual plaintext blocks may be recoverable via other means (e.g. using backups or specialised tools), also enabling data recovery.\r\n\r\nThe decryption tools can be found here: https://github.com/srlabs/","duration":2400,"logo":"/system/events/logos/000/011/903/original/basta.png?1699372868","type":"lecture","do_not_record":false,"track":"Security","abstract":"We present an analysis and recovery method for files encrypted by the \"second most used ransomware in Germany\".\r\n\r\nWe analysed the behaviour of a ransomware encryptor and found that the malware uses their keystream wrongly, rendering the encryption vulnerable to a known-plaintext attack which allows for recovering affected files. We confirmed the finding by implementing tools for recovering encrypted files.\r\n\r\nWe have made our tools for decrypting files without access to the actual key available to victims directly, through BSI, and to incident responders, as well as German and international law enforcement. Now, we are actively publishing these tools, along with the knowledge shared in our talk, empowering affected organizations to recover some of their files without succumbing to paying the criminals.","speakers":[{"guid":"72b8833d-0058-5e18-a386-6f58819c43fe","id":83,"image":"/system/people/avatars/000/000/083/original/1588.png?1360200251","name":"Tobias Mueller","public_name":"Tobias Mueller","abstract":"Tobias is a German Free Software advocate, former member of the GNOME Foundation's Board of Directors, and Pythonista. He acquired a Masters degree in Security and Forensic computing and a PhD in decentralised PKIs. He is working as a IT security consultant and loves to build and break stuff, especially making security systems usable and bringing them to the masses.","description":"Tobias builds and breaks GNOME stuff, PrivacyScore.org, and searchable encryption schemes.","links":[]}],"start_time":"2023-12-27T19:15:00.000+01:00","end_time":"2023-12-27T19:55:00.000+01:00","room":{"name":"Saal Grace","id":472}},{"id":12033,"guid":"8fe72218-1ea0-48b4-b90e-277178d75e49","title":"Unlocking Hardware Security: Red Team, Blue Team, and Trojan Tales","subtitle":null,"description":"We love to put microcontrollers, systems-on-a-chip and many other Integrated Circuits (ICs) into all sorts of devices. As hardware backdoors can undermine software security, the integrity of these chips is becoming increasingly important. However, most of these microchips are manufactured in a complex global supply chain where not all parties can necessarily be trusted. Who guarantees that the chip we order is the chip we get delivered? While the European Union wants to ensure digital sovereignty through massive long-term investment in domestic IC production, we need a way to verify the integrity of microchips \u003ci\u003etoday\u003c/i\u003e.\r\n\r\nIn this talk, we will first briefly cover the basics of the IC design and production process. We will outline common attacks that enable the insertion of subtle malicious manipulations or backdoors, often called hardware Trojans. You don't need to have a hardware background to follow along!\r\n\r\nWe then introduce some techniques we can use to detect hardware manipulations by comparing the circuit within a microchip to its original design files by reverse engineering the chip using open-source image processing. While imaging an IC requires advanced laboratory equipment, commodity hardware is sufficient to analyze the captured images.\r\n\r\nIn the main part of our talk, we will present a case study on Trojan detection based on four different digital ICs using a Red Team vs. Blue Team approach, and give a live demonstration.\r\nWe will share what manipulations of our Red Team we are already able to find reliably, and where some work is still needed -- and we're calling on you to play with our algorithms and have a go at uncovering the Trojans that are still well-hidden. Of course, we have made our source code and entire image datasets available under a free and open license.\r\n\r\nWe'll conclude with an insight into the working process of our Blue Team -- what we learned, and how we failed -- and give an outlook on how we can lower the entry barrier into IC reverse engineering, unlocking the hardware security field for all.","duration":3600,"logo":null,"type":"lecture","do_not_record":false,"track":"Security","abstract":"Ensuring the integrity of Integrated Circuits (ICs) against malicious hardware Trojans is paramount for secure electronic devices. One approach involves imaging the manufactured chips to compare them with their original design files. While such techniques for detecting Trojans are relatively well-known in the industry, there is a notable absence of comprehensive, publicly available case studies. To bridge this gap, we unveil a Red Team vs. Blue Team case study on hardware Trojan detection across four digital ICs in various modern feature sizes. We share our findings, algorithms, and image datasets, shedding light on the efficiency of these techniques, and offer insights into the impact of technology scaling on detection performance.","speakers":[{"guid":"47cdadd0-1b95-5b8c-a406-80a1e9337e7d","id":19070,"image":null,"name":"René Walendy","public_name":"René Walendy","abstract":"I'm a PhD candidate at the Embedded Security Group at the Max Planck Institute for Security and Privacy and the SecHuman graduate school of Ruhr University Bochum, Germany. My research focuses on the human factors in hardware reverse engineering, and how we can make hardware security education accessible to more people. I also like to do low-level technical work on, for example, image processing algorithms for visual analysis of microchips.","description":null,"links":[]},{"guid":"24a228d9-12db-5f40-baa7-c34d3a61300d","id":19352,"image":null,"name":"e7p","public_name":"e7p","abstract":null,"description":null,"links":[]},{"guid":"903d94e7-a79d-5865-bd16-a75d30e04d68","id":9744,"image":"/system/people/avatars/000/009/744/original/2022-Steffen_Becker.jpg?1699691475","name":"Steffen Becker","public_name":"Steffen Becker","email":"steffen.becker@rub.de","abstract":"Steffen is a PostDoc at Ruhr University Bochum and the Max Planck Institute for Security and Privacy. His work focuses on enhancing the security of hardware by investigating the human aspects involved in reverse-engineering-based attacks. Steffen is also interested in strengthening end-user perceptions and behaviors with respect to security and privacy.","description":null,"links":[]}],"start_time":"2023-12-29T11:00:00.000+01:00","end_time":"2023-12-29T12:00:00.000+01:00","room":{"name":"Saal Zuse","id":473}},{"id":11935,"guid":"c5882624-ff94-4dc3-aadd-f18ce4af5294","title":"Unlocking the Road Ahead: Automotive Digital Forensics","subtitle":"A deep dive into an underrepresented research area","description":"This talk will be a deep dive into automotive digital forensics! We will explore the dynamic landscape of automotive technology and its intricate relationship with digital forensics. Our journey will traverse classical in-vehicle protocols, proprietary communication methods, and external interfaces, revealing these technologies' crucial role in modern vehicles.\r\n\r\nThe current toolkit, used in automotive digital forensics investigations, includes the Berla iVe for infotainment analyses and specialized Airbag controller tools like Bosch CDR. For both, there is a limited understanding of its functionality and reliability, and for Airbag controllers, even contrary research results are available. We'll discover how these tools empower forensic experts to dissect the digital traces left within vehicles and the ecosystem, uncovering invaluable insights.\r\n\r\nAs we embark on this journey, we'll confront significant challenges faced by automotive digital forensics practitioners. These obstacles include limited accessibility to vehicle systems, the integration of proprietary technologies, a shortage of knowledge and expertise in this domain, concerns over safety implications, and the absence of standardized storage systems.\r\n\r\nKeeping pace with the latest research trends, we'll delve into process development, the introduction of additional tools, in-depth analytical methods, and innovative investigation techniques shaping this field's future.\r\n\r\nBut the road ahead is not without twists and turns, and we'll navigate through privacy and security issues that are paramount in the automotive digital forensics landscape. We'll shed light on privacy concerns, referencing investigations like the one conducted by the Mozilla Foundation and explore security topics through real-world examples such as attacks showcased at the Pwn2Own conference and those disclosed by KeenLabs Security. We will also focus on investigations we conducted on Tesla vehicles in the area of digital forensics.\r\n\r\nThroughout this talk, you'll gain insights into the automotive ecosystem's vast capabilities for digital forensics investigations. We'll also tackle the challenges head-on, highlighting the intricate balance between privacy and security in this ever-evolving domain. Whether you're an expert in the field or intrigued by the intersection of technology and automotive investigations, this talk promises to leave you with a profound understanding of the road ahead in automotive digital forensics.","duration":2400,"logo":null,"type":"lecture","do_not_record":false,"track":"Security","abstract":"The importance and relevance of vehicles in investigations are increasing. Their digital capabilities are rapidly growing due to the introduction of additional services and features in vehicles and their ecosystem.\r\n\r\nIn this talk on automotive digital forensics, you will embark on a journey through the cutting-edge world of automotive technology and the critical role digital forensics plays in this domain. We will explore the state-of-the-art methods and tools to investigate modern vehicles, shedding light on forensic experts' significant challenges.\r\n\r\nThis presentation delves into the latest research areas and trends, providing insights into how technology rapidly evolves in the automotive industry, creating opportunities and challenges for digital forensics specialists. We will also peer into the future, discussing the directions in which automotive digital forensics is heading and the implications for our increasingly connected and autonomous vehicle landscape.\r\n\r\nThrough case studies, you will gain a firsthand look at different investigations conducted on modern vehicles, showcasing the real-world applications of digital forensics in this field--explicitly focusing on privacy issues and security pitfalls in modern vehicles. Whether you're a seasoned expert or a curious enthusiast, this talk will give you a deeper understanding of the complex intersection of automotive technology and digital investigations.","speakers":[{"guid":"a3ca24b5-b600-5c34-a19f-303a36216349","id":19262,"image":"/system/people/avatars/000/019/262/original/Passbild_Kevin_10-low-res.jpeg?1701692457","name":"Kevin Gomez","public_name":"Kevin Gomez","abstract":"I am a post-doc researcher at the Technical University Ingolstadt and an associated researcher at the Friedrich-Alexander University Erlangen-Nürnberg.\r\n\r\nMy main research areas are (automotive) digital forensics and topics in security operation centers (SOCs).","description":null,"links":[{"url":"https://orcid.org/0000-0002-5597-3913","title":"OrcID"},{"url":"https://k-gomez.com","title":"Personal website"}]}],"start_time":"2023-12-27T12:55:00.000+01:00","end_time":"2023-12-27T13:35:00.000+01:00","room":{"name":"Saal Grace","id":472}},{"id":12008,"guid":"ae3261f2-240c-4699-b6d7-b82fb81fb924","title":"Unsere Worte sind unsere Waffen  ","subtitle":"Wie wir Chatbots allein mit kreativer Wortfindung so manipulieren können, dass sie uns dienen (ja, social engineering funktioniert bei großen Sprachmodellen!)","description":"Es ist vieles gesagt und geschrieben worden über große Sprachmodelle und die Gefahren, die mit ihnen einhergehen, die Biases, die Verstärkung von Ausbeutung, die Zementierung von Machtverhältnissen und neue Möglichkeiten von Angriffen. Das alles gilt weiterhin. Doch umso mehr sollten wir uns anschauen, wie wir die Technologie mit ihren eigenen Waffen schlagen können. Denn all diese Chatbots haben sich in einem Bereich eingenistet, in dem wir Menschen besonders gut sind: Sprache. Quatschen wir sie in ihr Verderben!\r\n\r\nIn dem Talk erkläre ich anhand von Beispielen aus meinen jüngsten Recherchen, wie wir große Sprachmodelle anders nutzen können, als sie möglicherweise gedacht sind – und wie wir damit Gutes tun können. Beispielsweise habe ich Chatbots per social engineering dazu gebracht, ihre dunklen Geheimnisse – wie manipulierende Initial Prompts – zu verraten, und damit dahinterstehende Firmen und deren verwerfliche Machenschaften entblößt. Oder mir bei investigativen Recherchen zu helfen, die besten Google Dorks zu erklären, Verstecktes in Bildern zu erkennen und Dinge zu verraten, die sie eigentlich nicht preisgeben sollen – wie Julian Reichelts private E-Mail-Adresse oder gesammelte E-Mail-Adressen aller Gesundheitsämter in Rheinland-Pfalz.\r\n\r\nEs wird unterhaltsam. Und es gibt viel mitzunehmen: Zuhörer:innen lernen dabei nicht nur sinnvolle Tricks für ihre eigenen Recherchen, sondern ganz nebenbei auch, wie sie ihre eigenen Daten besser schützen können.","duration":2400,"logo":null,"type":"lecture","do_not_record":false,"track":"Ethics, Politics \u0026 Society","abstract":"Chatbots lassen sich durch Sprache manipulieren. Und Sprache, das ist etwas, das wir Menschen gut können! Das ist eine gute Nachricht. In diesem Talk soll es darum gehen, unsere Ohnmacht zu lindern und zu verstehen, dass wir ziemlich vieles gut können, was uns hilft, große Sprachmodelle für unsere Zwecke zu nutzen (und möglicherweise anders, als sie gedacht sind). Social Engineering und – quatschen.","speakers":[{"guid":"65ca594f-cd7a-51bb-8e00-35ceb33fc6e2","id":18997,"image":"/system/people/avatars/000/018/997/original/EBL_9573.jpg?1699632787","name":"Eva Wolfangel","public_name":"Eva Wolfangel","abstract":null,"description":"Eva Wolfangel is a journalist, speaker and moderator, focusing on future technologies such as artificial intelligence and virtual reality, computer science, cyber security, data journalism, interaction between digital and real worlds. In 2018 she was named European Science Writer of the Year by the Association of British Science Writers. She writes for major magazines and newspapers in Germany and Switzerland — including ZEIT, Geo, Spiegel, and NZZ — and produces radio features.  Eva’s specialty is to combine creative writing and complex topics in order to reach a broad audience. In 2019/20 she was a Knight Science Journalism Fellow at MIT in Boston/Massachusetts.","links":[{"url":"https://www.ewo.name","title":"Website"},{"url":"https://chaos.social/@evawolfangel","title":"Eva Wolfangel auf Mastodon"}]}],"start_time":"2023-12-27T12:00:00.000+01:00","end_time":"2023-12-27T12:40:00.000+01:00","room":{"name":"Saal Grace","id":472}},{"id":12212,"guid":"9f884d2d-23a4-4a3d-9bfb-17b2c3b46caa","title":"Vierjahresrückblick des CCC","subtitle":"Nix los und viel zu tun","description":null,"duration":7200,"logo":null,"type":"lecture","do_not_record":false,"track":"CCC","abstract":"Über die letzten vier Jahre sind in der Nautosphäre um den Chaos Computer Club, Deutschland, Europa und der Welt aufregende, irritierende, bemerkenswerte und empörenswerte Dinge passiert, bei deren Einordnung wir gerne helfend zur Seite stehen wollen.\r\n\r\nVon Berichten aus den Erfahrungsaustauschkreisen über die digitalen Hausbesuche bei den Luca-Apps dieser Welt, von kleinen und riesengroßen Hacker-Veranstaltungen zu den inzwischen schöne Tradition gewordenen Gutachten für unser Verfassungsgericht wollen wir in vielen kleinen Wortmeldung ein rundes Bild zu den Entwicklungen der letzten vier Jahre und einen Ausblick auf das Jahr 2024 geben.","speakers":[],"start_time":"2023-12-29T16:30:00.000+01:00","end_time":"2023-12-29T18:30:00.000+01:00","room":{"name":"Saal 1","id":471}},{"id":12238,"guid":"7b1188cf-948c-490c-b206-9ec6a22c45e9","title":"Vom Darkroom in die Blackbox","subtitle":"Effekte der Digitalisierung auf (schwules) Dating","description":"\u003cp\u003eDer Vortrag zeichnet erstens eine Kulturgeschichte der schwulen Subkultur und erklärt, warum Darkrooms und ähnliche Orte, an denen schwuler Sex in der semi-Öffentlichkeit vollzogen wird, konstitutiv für die schwule Szene waren. Zweitens werden die Effekte der Digitalisierung dieser Orte hin zu Plattformen wie früher GayChat oder heute Grindr aufgezeigt. Drittens wird gezeigt, warum homosexuelle Cruising-Apps wie Grindr kultur- und softwaretechnisch grundlegend anders aufgebaut sind als heterosexuelle Dating-Apps wie Tinder.\u003c/p\u003e\r\n\u003cp\u003eMit dem Vortrag möchte ich einen Anstoß geben, Dualismen wie Homo- und Heterosexualität, Cruising und Dating, Promiskuität und Monogamie zu hacken. Ich möchte zeigen, dass Interaktivität auf \u003ci\u003eDatingplattformen\u003c/i\u003e häufig eine Illusion ist, und versuchen, gemeinsam mit dem Publikum Wege zu finden, den „interpassiven”-Konsumstatus im Onlinedating aufzubrechen.\u003c/p\u003e\r\n\u003cp\u003eZu meinem Hintergrund und meiner Motivation: Ich studiere Kulturwissenschaften und nebenbei ein wenig Informatik. Über das letzte halbe Jahr habe ich zwei längere Arbeiten über die Digitalisierung von schwulem Cruising verfasst und arbeite aktuell an einer dritten. Beim Forschen ist mir wichtig, nicht nur die Auswirkungen von schwulen Onlineplattformen zu beobachten, sondern diese genauso als Blackbox zu begreifen. Eine Blackbox, die auf ihre Geschichte untersucht und aufgemacht werden muss, um genau zu verstehen, wie sie funktioniert. Mir ist es ein besonderes Anliegen, über meine Untersuchungen zu sprechen, weil ich das Szenesterben als belastend empfinde und eine enorme Schwächung des queeren Aktivismus durch die stärker werdende Verlagerung der Szene in einen virtuellen Raum erwarte. Gleichzeitig konnte ich beobachten, wie auch viele heterosexuelle Menschen durch ihr promiskuitives Verhalten größer werdenden Stigmata ausgesetzt werden. Auch diese nebensächliche Beobachtung empfinde ich als besorgniserregend und würde gerne einen Raum eröffnen, um darüber zu sprechen.\u003c/p\u003e","duration":2400,"logo":"/system/events/logos/000/012/238/original/black.jpg?1701536456","type":"lecture","do_not_record":false,"track":"Ethics, Politics \u0026 Society","abstract":"\u003cp\u003eEntgegen der Auffassung, die schwule Subkultur hätte durch die digitale Vernetzung einen Aufschwung erhalten und sei in ihrem Aktivismus gestärkt worden, möchte ich eine gegenwärtige Krise der Subkultur markieren und ihren Entstehungskontext durch \u003ci\u003eOnlinedating\u003c/i\u003e skizzieren.  Schwule Onlineplattformen entstanden, um der Unterdrückung von homosexuellem Verhalten zu entgehen. Zynischerweise sorgen sie heute für eine unterschwellige, fesselnde Regulation homosexueller Menschen.\u003c/p\u003e\r\n\u003cp\u003eDer Vortrag arbeitet sich zwar vor allem an MSM-Personen (Männer, die Sex mit Männern haben) ab, richtet sich aber ausdrücklich an Hacker:innen jeglicher Sexualität.\u003c/p\u003e","speakers":[{"guid":"9746344b-d3ea-50c3-8e43-0ec5749e173d","id":19248,"image":null,"name":"LustigerLeo","public_name":"LustigerLeo","abstract":null,"description":null,"links":[]}],"start_time":"2023-12-30T16:40:00.000+01:00","end_time":"2023-12-30T17:20:00.000+01:00","room":{"name":"Saal Zuse","id":473}},{"id":11942,"guid":"73ec8b2e-34fa-453f-8e26-8789f62103ab","title":"Von der ePA zum EHDS: 7 Thesen zur aktuellen digitalen Gesundheitspolitik","subtitle":null,"description":"Beide Projekte zielen darauf ab, die Gesundheitsdaten von Millionen Menschen zu digitalisieren und diese Behandelnden, der Forschung und der Wirtschaft bereitzustellen.\r\n\r\nIn unserem Vortrag wollen wir entlang von sieben Thesen zentrale technische und gesellschaftspolitische Untiefen der geplanten Gesundheitsdigitalisierung in der Bundesrepublik und in der EU erkunden – und den Weg zu einer alternativen Digitalisierung des Gesundheitssektors aufzeigen.","duration":3600,"logo":null,"type":"lecture","do_not_record":false,"track":"Ethics, Politics \u0026 Society","abstract":"Karl Lauterbach und die EU-Kommission haben eines gemeinsam. Beide wollen in Windeseile die Digitalisierung des Gesundheitssektors voranbringen. Die elektronische Patientenakte soll im Januar 2025 für alle Bundesbürger:innen kommen. Im gleichen Jahr ist der Start des sogenannten Europäischen Gesundheitsdatenraums geplant.","speakers":[{"guid":"77116af0-99f3-5b76-af08-3ca854f919a1","id":19114,"image":null,"name":"Daniel","public_name":"Daniel","abstract":"Daniel ist Politikwissenschaftler und seit August 2022 Co-Chefredakteur bei netzpolitik.org. Zuvor war er Redakteur bei den »Blättern für deutsche und internationale Politik«. 2014 erschien von ihm das Buch »Amazon – Das Buch als Beute«; 2016 erhielt er für seinen Beitrag »Facebook rettet die Welt« den Alternativen Medienpreis in der Rubrik »Medienkritik«.","description":null,"links":[{"url":"https://netzpolitik.org/author/daniellei/","title":"Autorenseite bei netzpolitik.org"}]},{"guid":"d3f41abc-c067-5eac-a53c-208e01740a00","id":19503,"image":"/system/people/avatars/000/019/503/original/IMG_5211.jpg?1701684693","name":"bkastl","public_name":"bkastl","abstract":"Bianca Kastl, Entwicklerin und digitale Erklärbärin, \"disruptives Element in einer Verwaltung\".","description":"Bianca Kastl, Entwicklerin und digitale Erklärbärin, beschäftigt sich längerem beruflich und zivilgesellschaftlich als Vorsitzende des Innovationsverbunds Öffentliche Gesundheit mit digitalen Infrastrukturen und ihren Technikfolgen im Bereich öffentlicher Verwaltung und Gesundheitswesen. Nach diversen Erfahrungen mit digitalen Pandemieanwendungen ist ihr aktueller Fokus die Beschäftigung mit großen Digitalisierungsvorhaben im Kontext der öffentlichen Verwaltung wie dem Onlinezugangsgesetz, Registermodernisierung, Digitale Identitäten sowie dem digitalen Gesundheitswesen wie der elektronischen Patientenakte, dem europäischen Gesundheitsdatenraum und dem Gesundheitsdatennutzungsgesetz.","links":[]}],"start_time":"2023-12-29T11:00:00.000+01:00","end_time":"2023-12-29T12:00:00.000+01:00","room":{"name":"Saal Grace","id":472}},{"id":11983,"guid":"e1a4a5df-9ef8-4364-b5c8-e8707ee83b8f","title":"Von Zebrastreifen, offenen Daten und verschlossenen Verwaltungen","subtitle":"Luxemburgs kreative Route zur Amtstransparenz","description":"Die Geschichte begann mit einer einfachen Anfrage auf Twitter über die Gesetzeskonformität von Zebrastreifen in Luxemburg, die jedoch bei der Stadtverwaltung auf eine Mauer des Schweigens stieß. Als Reaktion darauf gründeten Aktivist:innen des Zentrums für Urbane Gerechtigkeit (ZUG) das Projekt \"Safe Crossing\", um die Einhaltung der Regularien für Zebrastreifen in Luxemburg-Stadt zu überprüfen. Mit einer Mischung aus Google Maps und Tinder entwickelten sie eine App, durch die die Nutzer:innen Luftbilder der Zebrastreifen analysieren und problematische Bereiche identifizieren konnten​​.\r\n\r\nIhre Ergebnisse waren alarmierend: Etwa ein Drittel der insgesamt 1.787 analysierten Zebrastreifen entsprachen nicht den gesetzlichen Vorgaben, da Parkplätze die Sicht auf die Zebrastreifen blockierten und somit die Sicherheit der Fußgänger:innen gefährdeten​​. Trotz der Publikation ihrer Ergebnisse und der Diskussionen im Stadtrat bestritt die Stadtverwaltung die Ergebnisse und blieb bei ihrer eigenen, wesentlich niedrigeren Schätzung von nur 37 nicht regelkonformen Zebrastreifen​.\r\n\r\nDie nachfolgenden Geschehnisse zeichneten ein Bild von intransparenten Verwaltungen und dem Kampf um die Offenlegung von Informationen. Trotz mehrerer offizieller Anfragen und einer Entscheidung der „Commission d’accès aux documents“ (CAD) zugunsten von ZUG weigerte sich die Stadt Luxemburg, die angeforderten Dokumente zu veröffentlichen. Der Fall eskalierte bis vor das Verwaltungsgericht, und ZUG lancierte eine Crowdfunding-Kampagne, um die anfallenden Rechtskosten zu decken​.\r\n\r\nDer Vortrag wird die Herausforderungen und Erfolge des Projekts detailliert beleuchten, das Engagement für offene Daten und bürgerlichen Aktivismus hervorheben und auf die Bedeutung von Transparenz und Rechenschaftspflicht in der öffentlichen Verwaltung eingehen. Die Zuhörer:innen werden nicht nur Einblicke in die technischen und juristischen Aspekte des Projekts erhalten, sondern auch inspiriert werden, wie individuelle und kollektive Aktionen positive Veränderungen herbeiführen können, selbst wenn sie gegen bürokratische Mauern stoßen.","duration":2400,"logo":null,"type":"lecture","do_not_record":false,"track":"Ethics, Politics \u0026 Society","abstract":"Kein Zebrastreifen ist illegal. Oder doch? Die scheinbar einfache Frage nach der Gesetzeskonformität von Zebrastreifen verursachte mysteriöses Schweigen in der öffentlichen Verwaltung der Stadt Luxemburg. Als Reaktion auf die Datenverweigerung schufen die Aktivist:innen des Zentrums für Urbane Gerechtigkeit eine Mischung aus Google Maps und Tinder, um die benötigten Daten selbst zu generieren. Dieser Vortrag beleuchtet das spannende Zusammenspiel von intransparenten Verwaltungen, der Eigeninitiative im Erstellen von Geodaten und dem juristischen Kampf um die Offenlegung von Informationen. Zudem wird aufgezeigt, welche Ressourcen ein solches Unterfangen erfordert, und wie es als lehrreiches Beispiel für zivilen Aktivismus und behördliche Transparenz dient.","speakers":[{"guid":"34ebf267-1d75-5352-8631-6ba10493e508","id":19124,"image":null,"name":"thorben","public_name":"thorben","abstract":"Event Tech and Educator by Day - Digital Rights, Soldering and Film Exhibition by Night","description":"During the daylight hours, you'll find me deep in event technology. I'm all about creating tools that make life easier for event planners, blending software solutions with the practical needs of real-world events.\r\n\r\nWhen night falls, my focus shifts to more grassroots activities. You might catch me soldering in my workshop, exploring the intricacies of digital rights, or setting up for a film showing. My work with Zentrum fir Urban Gerechtegkeet and Cinéma Sura keeps me busy, blending my tech-savvy side with a love for the cinematic arts.\r\n\r\nBased across Hamburg, Berlin, and Luxembourg, I navigate these diverse worlds, from the technical to the creative, bringing a hacker's curiosity and a film buff's enthusiasm to everything I do.","links":[{"url":"https://thorben.io","title":"Webseite"}]},{"guid":"6a664734-4db2-53d7-a1e2-c0c4a977b03e","id":19555,"image":null,"name":"fedus","public_name":"fedus","abstract":null,"description":null,"links":[]}],"start_time":"2023-12-28T11:00:00.000+01:00","end_time":"2023-12-28T11:40:00.000+01:00","room":{"name":"Saal Grace","id":472}},{"id":11817,"guid":"18487db3-1b55-4f91-8f93-2de44137abec","title":"VRA","subtitle":null,"description":"VRA ist eine audiovisuelle Performance (Projektion + Sound), die mithilfe eines eigens entwickelten Software-Instruments (in Max/MSP), das auf Bild-zu-Ton-Umwandlung basiert, aufgeführt wird. Auf der Projektion sind monochrome Texturen zu sehen, die aus teilweise simplen Formen wie Streifen oder Kreisen, aber auch aus komplexeren Strukturen wie Rauschen bestehen. Diese Bilder werden in Echtzeit in Sound umgewandelt, indem die Helligkeitswerte einer ausgewählten Pixelreihe als Audiobuffer dienen und eine Waveform beschreiben. ","duration":2400,"logo":"/system/events/logos/000/011/817/original/BR_1_-_Kopie.png?1698852091","type":"concert","do_not_record":false,"track":"Art \u0026 Beauty","abstract":"Eine audiovisuelle Performance, basierend auf Bild-zu-Ton-Umwandlung. Dynamisch wechselnde Bilder dienen als Realtime-Audiobuffer. Licht wird Sound. \r\nBeinhaltet stroboskopische Bilder und Hörinhalte in breiten Spektren.","speakers":[{"guid":"212e6475-60da-53a0-9446-ac82b0ce6501","id":19150,"image":null,"name":"Daniel Haas","public_name":"Daniel Haas","abstract":"Daniel Haas aka. STURMHERTA is an austrian Musician and Mediaartist in the fields of experimental electronics and audiovisual art with roots in the modular synth community.","description":"Austrian artist Daniel Haas, born 1992, lives and works in Linz/Austria and studies „timebased and interactive mediaarts“ at university of arts Linz.With roots in the modular-synth-community he created the project „STURMHERTA“. Under this sy\u0002nonym he released several digital EPs and Tapes, but mostly he focusses on live-performance. In STURMHERTAs repertoire we find hybrid-modular livesets, intense, stroboscopic audiovisual per\u0002formances and immersive sound installations. A recurring element in his works is the strong con\u0002nection of sound and light, often found as a direct translation of one to the other.","links":[]}],"start_time":"2023-12-28T22:05:00.000+01:00","end_time":"2023-12-28T22:45:00.000+01:00","room":{"name":"Saal Zuse","id":473}},{"id":12104,"guid":"f5852d4a-58c0-4ff1-91dd-03df4a16e43e","title":"Was Digitale Gewalt mit Restaurantkritik zu tun hat","subtitle":"Neue Entwicklungen rund um das Thema Digitale Gewalt","description":"\u003cp\u003eDie Ampel hat in ihren Koalitionsvertrag geschrieben, dass es ein Digitale-Gewalt-Gesetz geben soll und das schien ein großer Schritt vorwärts. Als ich vor fünf Jahren beim 35C3 über Digitale Gewalt sprach, war das Thema kaum bekannt und seitdem hat sich viel getan.\u003c/p\u003e\r\n\r\n\u003cp\u003eDieser Talk gibt einen Überblick zum Stand der Dinge: Was ist seitdem passiert, was wird unter dem Begriff verstanden und was wissen wir inzwischen über das Ausmaß, neue und alte Formen digitaler Gewalt und den Umgang damit.\u003c/p\u003e\r\n\r\n\u003cp\u003eDigitale Gewalt ist ein Sammelbegriff und meint ganz verschiedene Dinge: \r\n\u003cul\u003e\r\n\u003cli\u003eHate-Speech, also Beleidigungen, Verleumdungen und Bedrohungen im Netz\u003c/li\u003e\r\n\u003cli\u003edigitale Aspekte der sog. ‚häuslichen Gewalt' wie Stalker-Ware, heimliches oder erzwungenes Mitlesen von E-Mails und Messenger-Nachrichten, Video-Überwachung, Zugriff auf Lokationsfunktionen von Mobilgeräten\u003c/li\u003e\r\n\u003cli\u003edigitales Stalking mithilfe von AirTags oder GPS-Sendern, Doxing\u003c/li\u003e\r\n\u003cli\u003eheimliche Aufnahmen in Umkleiden, Duschen, Toiletten und ihr Upload auf Porno-Plattformen\u003c/li\u003e\r\n\u003cli\u003eFilmen von Vergewaltigungen und Erpressung mit der Drohung der Veröffentlichung\u003c/li\u003e\r\n\u003c/ul\u003e\r\n\u003c/p\u003e\r\n\r\n\u003cp\u003eIn den letzten Jahren hat es einige neue Gesetze gegeben und das Justizministerium arbeitet am Digitale-Gewalt-Gesetz. Auch die EU bereitet ein neues Gesetz vor. Was sich dadurch ändern wird und was nicht und was nötig wäre, um Betroffenen zu helfen, ist Thema dieses Talks.\u003c/p\u003e\r\n\r\n","duration":3600,"logo":null,"type":"lecture","do_not_record":false,"track":"Ethics, Politics \u0026 Society","abstract":"\u003cp\u003eWas hat sich in den letzten fünf Jahren seit dem letzten Talk über Digitale Gewalt in Deutschland getan? Das Thema stand im Ampel-Koalitionsvertrag, aber was es jetzt geben soll, ist ein Accountsperren-Gesetz, das eine Gefahr für die Anonymität im Netz sein könnte.\u003c/p\u003e\r\n\r\n\u003cp\u003eDas Justizministerium möchte Digitale Gewalt gegen Unternehmen bestrafen (\"Restaurantkritik\"), aber wer weiterhin im Regen steht: Betroffene und Beratungsstellen. Was hat sich geändert, was nicht und warum müssen wir immer noch unsere Privatadressen ins Impressum schreiben – darum geht es in diesem Talk.\u003c/p\u003e","speakers":[{"guid":"a38f1463-0e67-5973-ace0-17387b850bd9","id":1864,"image":"/system/people/avatars/000/001/864/original/facepalm3.jpg?1438210813","name":"Anne Roth","public_name":"Anne Roth","email":"anneroth@posteo.net","abstract":"Anne Roth ist seit gut zwanzig Jahren Teil der Berliner Netz-Community. Sie hat mal Politologie studiert und guckt meist aus der Perspektive der Grundrechte auf den Einsatz von IT. Seit fast zehn Jahren arbeitet sie als Referentin der Linksfraktion im Bundestag: Zuerst im NSA-Untersuchungsausschuss, dann für das Themenfeld Netzpolitik insgesamt. Sie war nie Mitglied einer Partei und sieht sich als Schnittstelle zwischen Politik, IT und Netz-Community.","description":"2001 hat sie das unabhängige internationale Medien-Netzwerk Indymedia mitaufgebaut (und nach ein paar Jahren wieder verlassen) und hat als Kollateralschaden einer Anti-Terror-Ermittlung jahrelang über das \u003ca href=\"https://annalist.noblogs.org/post/category/uberwachung-im-alltag/\"\u003eLeben mit Überwachung gebloggt\u003c/a\u003e. Sie hat sich mit dem Mangel an Diversität bei Tech-Konferenzen beschäftigt und deswegen die \u003ca href=\"https://www.speakerinnen.org/\"\u003eSpeakerinnen-Liste\u003c/a\u003e mitgegründet. \r\n\r\nEin paar Jahre hat sie mit der NGO Tactical Tech praktisch daran gearbeitet, die digitale Sicherheit von NGOs, Menschenrechtsverteidiger*innen und Journalist*innen zu verbessern.","links":[{"url":"http://annalist.noblogs.org","title":"Blog annalist"},{"url":"https://systemli.social/@anneroth","title":"Mastodon"},{"url":"https://bsky.app/profile/anneroth.bsky.social","title":"Bluesky"}]}],"start_time":"2023-12-27T14:45:00.000+01:00","end_time":"2023-12-27T15:45:00.000+01:00","room":{"name":"Saal Zuse","id":473}},{"id":12120,"guid":"82478d35-b686-4f82-a459-649c7179637a","title":"Was haben Atome je für uns getan?","subtitle":"I have lasers. You have atoms.","description":"„Quantum“ macht ja alles besser, vielleicht auch die Messtechnik, mit der wir die Erde vermessen. In einem Beitrag auf dem 34C3 habe ich über die Vermessung des Schwerefeldes der Erde gesprochen, die uns einen Einblick in die Umverteilung von Massen auf und innerhalb der Erde ermöglicht. Mit Satelliten werden zum Beispiel die Massenveränderungen an den Eisschilden oder in kontinentalen Grundwasserspeichern beobachtet. Auf der Erdoberfläche selbst wird das Schwerefeld für Anwendungen in Geodäsie, Geophysik oder auch der Hydrologie lokal oder in kleinen Regionen mit Gravimetern am Boden, im Flugzeug oder auf Schiffen vermessen. \r\n\r\nIm terrestrischen Einsatz werden bereits seit wenigen Jahren so genannte Quantengravimeter eingesetzt, die das Prinzip der Atominterferometrie nutzen. In diesen Instrumenten werden fallende Atome mittels Laser manipuliert, um die Beschleunigung zu messen, der die fallenden Atome unterliegen. Für Weltraumanwendungen ist die Technologie derzeit in der Entwicklung und noch nicht im Einsatz.\r\n\r\nIn diesem Beitrag gebe ich einen kurzen Überblick über das Thema „Quantum Sensing“ mit dem Fokus auf die Erdbeobachtung. Wir schauen uns die Technologie, Anwendungen und aktuelle Entwicklungen an und werfen einen Blick in die Förderlandschaft. Vielleicht starten wir ja auch noch SomeThingQT.","duration":2400,"logo":"/system/events/logos/000/012/120/original/SomeThingQT.png?1699719386","type":"lecture","do_not_record":false,"track":"Science","abstract":"Mal ehrlich, was haben denn Atome je für uns getan, also außer der Materie im Allgemeinen und Mate im Besonderen? Wir kennen „Quantum Computing“ oder auch „Quantum Communication“. Aber wie sieht es aus mit „Quantum Sensing“ – also quantenbasierter Messtechnik? Lasst uns mit Lasern auf ein paar Atome schießen und sehen, wie schwer die Welt ist. ","speakers":[{"guid":"74450241-7efe-503d-bbfb-e77b192ac60c","id":7606,"image":null,"name":"Manuel","public_name":"Manuel","email":"manuel.schilling@dlr.de","abstract":"After completing a degree in geodesy, I found myself working on the determination of the gravity field. Some might say, I drop stuff to see if gravity is still working.","description":"I am currently working as a post-doc on methods to improve the determination of Earth's gravity field. ","links":[]}],"start_time":"2023-12-30T13:50:00.000+01:00","end_time":"2023-12-30T14:30:00.000+01:00","room":{"name":"Saal Zuse","id":473}},{"id":11718,"guid":"a9ac49b1-4d67-4bb2-a320-5a3ea515d09d","title":"Weil „be excellent to each other” nicht reicht","subtitle":"Über die Strukturen im Hintergrund: Awareness-Team und Schiedsstelle","description":"„Be excellent to each other“ steht seit Jahrzehnten für das Selbstverständnis der Chaos-Community, was rücksichtsvolles Miteinander angeht.\r\n\r\nDennoch gibt es regelmäßig Fälle, in denen das Verhalten einzelner Personen ganz und gar nicht \u003cem\u003eexcellent\u003c/em\u003e ist. Dies kann sich beispielsweise in diskriminierendem oder belästigendem Verhalten äußern und umfasst auch schwerwiegende Konflikte, die die Sicherheit oder Freiheit Einzelner bedrohen können. Zum Umgang mit derartigen Situationen auf Camp und Congress gibt es Strukturen wie das Awareness-Team, die Schiedsstelle und weitere auf help.ccc.de genannte Anlaufstellen.\r\n\r\nIn diesem Vortrag möchten wir – Mitglieder der Schiedsstelle, des Awareness-Teams und des Vorstands – einen Blick hinter die Kulissen von Awareness-Team und Schiedsstelle bieten und Impulse zur Weiterentwicklung der Schiedsstelle sammeln.\r\nDas heißt zunächst: Wie arbeiten Awareness-Team und Schiedsstelle, wie hängen sie zusammen und mit welcher Art von Fällen beschäftigen sie sich in der Praxis?\r\nDabei werden wir auch Beispiele betrachten, bei deren Behandlung wir derzeit Schwierigkeiten oder Grenzen ebendieser Strukturen sehen.\r\nAufbauend darauf möchten wir in einer Q\u0026A-Session und einem an den Vortrag anschließenden Workshop Feedback zum Umgang mit den genannten Beispielfällen und zu den Strukturen allgemein einholen.\r\n\r\nUnser Ziel ist, die Arbeit und Arbeitsweise von Schiedsstelle und Awareness-Team greifbar zu machen und unsere eigene Perspektive als Teil dieser Strukturen mit der Perspektive aus der Community abzugleichen.\r\nWir haben vor, mit den dabei gewonnenen Erkenntnissen die bestehenden Strukturen weiterzuentwickeln. Dazu gehört auch, Unklarheiten im Umgang der Community mit den Strukturen sowie Lücken im Umgang mit einzelnen Fällen zu identifizieren und zu reduzieren.","duration":3600,"logo":null,"type":"lecture","do_not_record":false,"track":"CCC","abstract":"„Be excellent to each other“ steht seit Jahrzehnten für das Selbstverständnis der Chaos-Community, was rücksichtsvolles Miteinander angeht.\r\nDennoch gibt es regelmäßig Fälle, in denen das Verhalten einzelner Personen ganz und gar nicht \u003cem\u003eexcellent\u003c/em\u003e ist.\r\nZiel dieses Vortrags ist, die zum Umgang mit solchen Fällen im CCC vorhandenen Strukturen greifbar zu machen und die verschiedenen Perspektiven auf ihre Arbeitsweise miteinander abzugleichen.\r\nEine Q\u0026A-Session und ein Workshop im Anschluss an den Vortrag bieten Möglichkeiten für Feedback.","speakers":[{"guid":"0213102e-0eb5-57b0-92cf-fd84669fe020","id":19024,"image":null,"name":"Schiedsstelle / Awareness Team / Vorstand","public_name":"Schiedsstelle / Awareness Team / Vorstand","abstract":null,"description":null,"links":[]},{"guid":"5eb0d877-806a-54b6-9b58-294f23f5e6f5","id":19333,"image":"/system/people/avatars/000/019/333/original/bf2023d.jpg?1699629193","name":"derf","public_name":"derf","abstract":"Board member of CCC e.V.","description":"derf has been active at CCC Düsseldorf / Chaosdorf since 2007 and is a board member of Chaosdorf e.V. since 2016. In addition to the usual bureaucracy business, this also gave her insights into handling conflicts \u003cem\u003ewithout\u003c/em\u003e being able to rely on structures such as awareness team or arbitration board. She joined the board of CCC e.V. in 2021.","links":[]},{"guid":"5030b821-3378-5097-9f7c-0febc973d441","id":12473,"image":null,"name":"gnom","public_name":"gnom","abstract":null,"description":null,"links":[]}],"start_time":"2023-12-28T16:00:00.000+01:00","end_time":"2023-12-28T17:00:00.000+01:00","room":{"name":"Saal Zuse","id":473}},{"id":12052,"guid":"39caae28-4957-4187-8d95-13b068c99b13","title":"What I Learned from Loab: AI as a creative adversary","subtitle":"The artist behind the viral cryptid \"Loab\" reflects on her critical relationship to AI art tools","description":"Steph Maj Swanson, a.k.a. Supercomposite, is a multimedia artist and writer best known for her story about the AI-generated woman Loab, which The Atlantic dubbed “a form of expression that has never existed before.\" Loab is an emergent character that arises in certain AI image synthesis models, accessible via negatively weighted prompts, often appearing alongside macabre imagery such as dismembered women and children.\r\n\r\nSwanson views her relationship to AI as adversarial, both in her creative process and as a commentator. This non-technical, but conceptual talk offers up art alongside possible strategies. It will be of interest for hackers intrigued by the creative potential of these tools, but who may have ethical concerns or doubts about the way these tools are assembled, built, and deployed.\r\n\r\nGalleries West described Swanson’s body of AI-generated visual work as “the merging of repulsive with beautiful,” and The Washington Post called her satirical AI writing “disturbing”. At DefCon this year she debuted her short film SUICIDE III, which uses deepfakes of Joe Biden and Sam Altman to explore where an out-of-control AI hype cycle might take us. ","duration":2400,"logo":"/system/events/logos/000/012/052/original/60a3a3d4-a962-46c4-ac40-785eb148b529_0_supercomposite_httpss.mj.run8Nin0A__DIGITA_PNTICS_skyline_logo-99.99_video.png?1699657504","type":"lecture","do_not_record":false,"track":"Art \u0026 Beauty","abstract":"In this talk, artist/writer Steph Maj Swanson will use the story of how her AI-generated character \"Loab\" arose (and went viral) as a jumping off point to present creative work and strategies that emerged from attempts to crack AI black boxes open. Aligned with the hacker ethos of exploration, experimentation and creative misuse, this talk presents adversarial artmaking practices for AI systems. It will also explore what it means to engage in cultural production today, as new forms of automation and centralization loom over the arts and entertainment industries. In the words of Nam June Paik: \"I use technology in order to hate it more properly.\"","speakers":[{"guid":"2b97b9a8-cb0b-5c8c-914e-172b3c2102cd","id":19354,"image":"/system/people/avatars/000/019/354/original/IMG_9084_small_poster.jpg?1702131897","name":"Steph Maj Swanson","public_name":"Steph Maj Swanson","email":"contact@supercompo.site","abstract":"Steph Maj Swanson (@supercomposite) is an artist and writer based in Uppsala, Sweden. She is best known for her story about the AI-generated woman Loab, which was featured in media outlets all around the world, quickly becoming the subject of fan art, online debate, and academic writing. Steph’s other writing was called “disturbing” by The Washington Post, and her body of video and still image work has been described by Galleries West as “the merging of repulsive with beautiful.” She has also written on the topic of AI for Vice Motherboard. Most recently, Steph debuted her deepfake video installation \"Suicide III\" at DEF CON in Las Vegas. ","description":null,"links":[{"url":"https://twitter.com/supercomposite","title":"on Twitter"},{"url":"https://www.instagram.com/supercomposite/","title":"on Instagram"},{"url":"https://supercompo.site","title":"supercompo.site"},{"url":"https://loab.ai","title":"loab.ai"}]}],"start_time":"2023-12-28T23:00:00.000+01:00","end_time":"2023-12-28T23:40:00.000+01:00","room":{"name":"Saal 1","id":471}},{"id":11844,"guid":"97bdc540-c53a-4ec3-949d-39e4d947db18","title":"What is this? A machine learning model for ants?","subtitle":"How to shrink deep learning models, and why you would want to.","description":"Declared dead numerous times, the hype around deep learning is bigger than ever. With Large Language Models and Diffusion Models becoming a commodity, we ask the question of how bad their energy consumption \u003ci\u003ereally\u003c/i\u003e is, what we can do about it, and how it is possible to run cutting-edge language models on off-the-shelf GPUs.\r\n\r\nWe will look at the various ways that people have come up with to rein in the hunger for resources of deep learning models, and why we still struggle to keep up with the demands of modern neural network model architectures. From low-bitwidth integer representation, through pruning of redundant connections and using a large network to teach a small one, all the way to quickly adapting existing models using low-rank adaptation.\r\n\r\nThis talk aims to give the audience an estimation of the amount of energy modern machine learning models consume to allow for more informed decisions around their usage and regulations. In the second part, we discuss the most common techniques used for running modern architectures on commodity hardware, outside of data centers. Hopefully, deeper insights into these methods will help improve experimentation with and access to deep learning models.","duration":2400,"logo":null,"type":"lecture","do_not_record":false,"track":"Sustainability \u0026 Climate Justice","abstract":"This talk will give a brief introduction of deep learning models and the energy they consume for training and inference. We then discuss what methods currently exist for handling their complexity, and how neural network parameter counts could grow by orders of magnitude, despite the end of Moore's law.","speakers":[{"guid":"84e8e2b8-2848-5294-861d-84d8c2e1eb1c","id":19176,"image":"/system/people/avatars/000/019/176/original/portrait.jpg?1701265563","name":"etrommer","public_name":"etrommer","abstract":"I'm a researcher in the field of machine learning hardware and compression of deep learning models for inference on microcontrollers and other small devices. I fiddle with embedded systems (bonus points if they contain LEDs) in my spare time.","description":"I am currently pursuing a Ph.D. on the topic of deploying deep learning models on devices that are severely constrained in terms of energy, compute and memory (think: embedded microcontrollers that run on batteries). \r\nI work in the areas of: \r\n\u003cul\u003e\r\n \u003cli\u003ePruning: trying to reduce a deep learning model to its most useful parameters and dropping the rest in order to shrink it\u003c/li\u003e\r\n\u003cli\u003eApproximate Computing: Using hardware that does not guarantee mathematically accurate results in an effort to reduce their arithmetic complexity\u003c/li\u003e\u003c/ul\u003e\r\nI'm mostly interested in modelling the effects of constrained hardware during the training of deep learning networks so that models can learn themselves how to deal with modest hardware.\r\nAlso always happy to have a chat about embedded systems in general, PCB design, and all things electronics. Card-carrying member of the Rust evangelism strike force.","links":[{"url":"https://etrommer.de/","title":"Personal website"},{"url":"https://github.com/etrommer/","title":"Github"}]}],"start_time":"2023-12-29T13:50:00.000+01:00","end_time":"2023-12-29T14:30:00.000+01:00","room":{"name":"Saal 1","id":471}},{"id":11868,"guid":"a3591274-c5c9-4d97-8404-d38abcb8d29a","title":"What your phone won’t tell you","subtitle":"Uncovering fake base stations on iOS devices","description":"Connecting to cellular networks around the world is a highly complex task. iPhones contain a baseband chip (also referred to as a modem) for that purpose. It communicates via a high-level interface with the smartphone’s application processor running iOS. So far, Apple hasn’t been able to build such basebands in-house. Instead, starting from the iPhone 12, they exclusively rely on Qualcomm basebands.\r\n\r\nQualcomm’s basebands use a proprietary protocol for external communication, the Qualcomm MSM Interface. We reverse-engineered its iOS implementation and built a framework to extract the protocol’s packet structures from iOS firmware. Our iOS Wireshark dissector uses these packet structures and enables us to monitor the flow of packets between the baseband and iOS. This allows us to gain new insights into the iPhone’s wireless communication infrastructure, including its satellite connectivity. Our tooling also provides a novel way to directly interact with the baseband chip in jailbroken iPhones, bypassing iOS and unlocking hidden capabilities of the baseband.\r\n\r\nFake or Rouge base stations can be set up by individuals using readily available software-defined radios. Adversaries can utilize them to capture IMSIs of nearby smartphones, track their location, or exploit vulnerable basebands. iPhone users usually don’t notice such attacks, and there are (almost) no protection mechanisms implemented in iOS.\r\n\r\nDuring our research, we discovered Apple’s internal cell location database, which is intended for determining approximate positions. Our CellGuard iOS app combines this database with the QMI analysis framework to monitor various parameters of connected cells, verify their authenticity, and alert users in case there’s suspicious activity. The app even works on non-jailbroken iPhones. We evaluated the app in a lab environment with SDRs and real-world tests since February 2023 and are steadily improving it for a release next year.","duration":2400,"logo":null,"type":"lecture","do_not_record":false,"track":"Security","abstract":"Your phone’s internal communication contains precious data. It can be analyzed to detect fake base stations used in cellular attacks. For that, we reverse-engineered a proprietary communication channel between the phone’s OS and modem.","speakers":[{"guid":"9634678a-7a54-5c06-83fe-402aaaa65f87","id":19050,"image":null,"name":"Lukas Arnold","public_name":"Lukas Arnold","abstract":null,"description":null,"links":[]}],"start_time":"2023-12-29T23:00:00.000+01:00","end_time":"2023-12-29T23:40:00.000+01:00","room":{"name":"Saal 1","id":471}},{"id":11717,"guid":"e91534ec-d9e8-46ba-a93e-bc5f2023d158","title":"Why Railway Is Safe But Not Secure","subtitle":"Security Of Railway Communication Protocols","description":"Although railways are one of the safest means of travel, they are not the most secure. What are railway engineers and IT experts fighting about? We will elaborate on the terms: Sicherheit, safety, security, and funktionale Sicherheit; and their implications.\r\nThe first railways were closed systems where employees had visual contact with the equipment. With the increasing amount of software and network growth, IT security is becoming a major concern. On the other hand, railway systems are made from various components with real-time and dependability requirements, and proprietary protocols, resulting in some security via obscurity. The main difference from other systems is the high degree of standardisation necessary for obtaining a permit. Consequently, changes take time and effort, resulting in the longevity of protocols.\r\nThis talk explains railway-specific protocols, such as GSM-R, RaSTA, and ETCS/ERMTS, their security model and known attacks. Nothing of this is new, but still, it is widely unknown.\r\nSo, join the talk, have fun, and learn how to stop a train - which is much simpler than starting one.","duration":2400,"logo":"/system/events/logos/000/011/717/original/VIvsIT2.jpg?1698407863","type":"lecture","do_not_record":false,"track":"Security","abstract":"The railway communication network looks different from your standard corporate IT. Its hardware, software and protocols have many peculiarities since it is an old, distributed, fragmented and highly standardised system. This creates problems when trying to introduce state-of-the-art IT security, and then there is the mindset: \"But we always have done it this way!\"","speakers":[{"guid":"fcfe27b2-08c2-53f7-8d8b-144e290cf35e","id":19020,"image":"/system/people/avatars/000/019/020/original/nerd_me_colour.png?1697706773","name":"Katja Assaf","public_name":"Katja Assaf","abstract":"After her studies in mathematics, Katja worked as a product manager and security expert in the railway industry for four years before deciding to go back to academia to be able to focus on research and follow a lifelong passion for cryptography.","description":"After her studies in mathematics, Katja worked as a product manager and security expert in the railway industry. She worked in an European research project and was responsible for the development of an Identity and Access Management System (IAM). After finding herself mostly sitting in meetings, she decided to go back to university and do research. She started on higher education certificates before figuring out that research on railway means you can play with trains of any size - that's what she's currently doing.","links":[{"url":"https://osm.hpi.de/people/assaf","title":"Personal webpage at HPI, University of Potsdam"}]}],"start_time":"2023-12-28T12:00:00.000+01:00","end_time":"2023-12-28T12:40:00.000+01:00","room":{"name":"Saal 1","id":471}},{"id":12326,"guid":"f7375255-379f-4423-a47f-2920246a0916","title":"YOU’VE JUST BEEN FUCKED BY PSYOPS","subtitle":"UFOS, MAGIC, MIND CONTROL, ELECTRONIC WARFARE, AI, AND THE DEATH OF THE INTERNET","description":"As AI-generated content, social-media influence operations, micro-targeted advertising, and ubiquitous surveillance have become the norm on the Internet and in the market in general, we have entered an era of PSYOP Capitalism. This is an era of hallucinations designed to transform each of us into a “targeted individual” through the manipulation of perception. This talk explores a secret history of reality-altering military and intelligence programs that serve as antecedents to a phantasmagoric present.\r\n\r\nAt the talk, attendees will be given a registration code to play “CYCLOPS,” a CTF/ARG game that will run the duration of Congress. CYCLOPS explores the themes of the mind-control and PSYOPS through an interactive parafictional narrative taking place in the context of an obscure CIA cognitive warfare program from the early days of the Cold War.\r\n","duration":3600,"logo":"/system/events/logos/000/012/326/original/Screen_Shot_2023-12-04_at_10.20.28_AM.png?1701708974","type":"lecture","do_not_record":false,"track":"Art \u0026 Beauty","abstract":"How the history of military and government PSYOPS involving mind-control, UFOs, magic, and remote-control zombies, explains the future of AI and generative media. Along the way, talk attendees will be given an enrollment code to join a specialized CTF/ARG game called CYCLOPS that explores these themes and that will run the duration of Congress. ","speakers":[{"guid":"80370748-3d1c-5083-83df-1887a25b70fd","id":3670,"image":null,"name":"Trevor Paglen","public_name":"Trevor Paglen","email":"trevor@paglen.studio","abstract":"Trevor Paglen is an American artist, geographer, and author.","description":"Trevor Paglen is an artist whose work spans image-making, sculpture, investigative journalism, writing, engineering, and numerous other disciplines.\r\n\r\nPaglen’s work has had one-person exhibitions at the Smithsonian Museum of American Art, Washington D.C.; Carnegie Museum of Art, Pittsburgh; Fondazione Prada, Milan; the Barbican Centre, London; Vienna Secession, Vienna; and Protocinema Istanbul, and participated in group exhibitions the Metropolitan Museum of Art, the San Francisco Museum of Modern Art, the Tate Modern, and numerous other venues. \r\n\r\nPaglen has launched an artwork into distant orbit around Earth in collaboration with Creative Time and MIT, contributed research and cinematography to the Academy Award-winning film Citizenfour, and created a radioactive public sculpture for the exclusion zone in Fukushima, Japan.\r\n\r\nPaglen is the author of several books and numerous articles on subjects including experimental geography, artificial intelligence, state secrecy, military symbology, photography, and visuality. Paglen’s work has been profiled in the New York Times, the New Yorker, the Wall Street Journal, Wired, the Financial Times, Art Forum, and Aperture. In 2014, he received the Electronic Frontier Foundation’s Pioneer Award and in 2016, he won the Deutsche Börse Photography Prize. Paglen was named a MacArthur Fellow in 2017. \r\n\r\nPaglen holds a B.A. from U.C. Berkeley, an MFA from the Art Institute of Chicago, and a Ph.D. in Geography from U.C. Berkeley.","links":[{"url":"paglen.studio","title":"Trevor Paglen"}]}],"start_time":"2023-12-27T16:00:00.000+01:00","end_time":"2023-12-27T17:00:00.000+01:00","room":{"name":"Saal 1","id":471}},{"id":12199,"guid":"6d46f1e7-31ca-4ce4-a620-c62659a3555f","title":"Zapfenstreich","subtitle":"Human out of the loop","description":"Mit der raschen Entwicklung und Verbreitung von Roboterwaffen fangen Maschinen an, den Platz des Menschen auf dem Schlachtfeld einzunehmen. Einige Expertinnen aus Militär und Robotik schätzen, dass „Killerroboter\" – vollständig autonome Waffen, die ganz ohne menschliches Eingreifen Ziele selektieren und angreifen können – innerhalb von 10 bis 15 Jahren entwickelt werden könnten. Aktuelle Beurteilungen des Militärs sagen aus, dass der Mensch immer eine gewisse Aufsicht über die Entscheidungen hat, tödliche Gewalt anzuwenden, jedoch lassen diese Aussagen oft die Möglichkeit offen, dass autonome Systeme eines Tages selbst die Fähigkeit haben, solche Entscheidungen aus eigener Kraft zu treffen, und somit der Mensch aus dem Entscheidungsprozess herausgenommen wird.\r\n\r\nIn diesem Zusammenhang ist es wahrscheinlich, dass autonome Systeme in naher Zukunft auch in Drohnen und Systemen zum Einsatz kommen, die auf hoher See, an Land und im Weltall autonom operieren können. Und während die Drohnentechnologie als solche keine völkerrechtlichen Probleme bereitet, ist es im Falle von autonomen Waffensystemen, bei denen Entscheidungen über Leben und Tod an Maschinen delegiert werden sollen, die Technik selbst, die grundlegende ethische und (völker-)rechtliche Fragen aufwirft.\r\n\r\nWas sind die Technologien, die zur tödlichen Autonomie bei Waffensystemen beitragen oder beitragen könnten? In wieweit kann man sie als künstlich intelligente Systeme bezeichnen?\r\n\r\nMit diesen Fragen möchte sich der Vortrag beschäftigen und auch darauf eingehen, welche Gefahren damit verbunden sind, wenn der Mensch aus dem Entscheidungsprozess über Leben und Tod herausgenommen wird. Es soll veranschaulicht werden, wie es von militärischer Seite zu dieser Entwicklung kommen konnte und welche Auswirkungen dies auf den zivilen Sektor hat. Wie sich zeigen wird, ist die Entwicklung hin zu autonomen Systemen eingebettet in einen historischen Verlauf von Kontrolle, Automatisierung und Standardisierung, welche den Höhepunkt sämtlicher militärischer Entwicklungen und Wünsche darstellt. Mit hoher Wahrscheinlichkeit werden Standards im militärischen Bereich auch in den zivilen Sektor übernommen und somit sehr schnell Fakten geschaffen. Laufen wir somit Gefahr, die Definition davon, was Autonomie in Computersystemen bedeutet, an einen kleinen Kreis von Expertinnen und Verbänden zu übergeben?\r\n\r\nEs ist an der Zeit, eine breitere Öffentlichkeit an der Diskussion der potenziellen Vorteile und Nachteile vollständig autonomer Systeme zu beteiligen und einen öffentlichen Diskurs anzustoßen, inwieweit die Zivilbevölkerung von Systemen betroffen ist, bei denen der Mensch aus dem Entscheidungsprozess herausgenommen wird. Internationale Organisationen wie „Human Rights Watch“ glauben, dass solche Waffenentwicklungen nicht mit dem internationalen humanitären Recht vereinbar sind, weil sie das Risiko zu Tod oder Verletzung von Zivilpersonen während eines bewaffneten Konfliktes erhöhen. ","duration":2400,"logo":"/system/events/logos/000/012/199/original/1.jpg?1699734958","type":"lecture","do_not_record":false,"track":"Art \u0026 Beauty","abstract":"Die rapide Entwicklung autonomer Waffensysteme wie „Killerrobotern“ wirft drängende ethische und rechtliche Fragen auf. Im Kontext des Ukraine-Kriegs und des Israel-Palästina-Konflikts gewinnt diese Thematik zusätzliche Relevanz, da die Anwendung autonomer Waffen weitreichende Auswirkungen auf militärische und zivile Bereiche hat.\r\n\r\nDer Vortrag beleuchtet die Technologien hinter dieser tödlichen Autonomie. Es wird veranschaulicht, wie die Entwicklung hin zu autonomen Systemen eingebettet ist in einen historischen Verlauf von Kontrolle, Automatisierung und Standardisierung, welche den Höhepunkt sämtlicher militärischer Entwicklungen und Wünsche darstellt. Die öffentliche Diskussion über die potenziellen Vorteile und Gefahren dieser Systeme, besonders in Anbetracht von Menschenrechtsverletzungen in aktuellen Konflikten, ist dringend erforderlich. Internationale Organisationen, darunter „Human Rights Watch“, plädieren für ein präventives Verbot, da autonom entwickelte Waffen als inkompatibel mit dem Internationalen Humanitären Recht angesehen werden.","speakers":[{"guid":"db701c2c-a1e1-5ed9-a0d7-dd8c84a7a4e3","id":9791,"image":"/system/people/avatars/000/009/791/original/new1.jpg?1605728781","name":"Simon Weckert","public_name":"Simon Weckert","abstract":"Simon Weckert is an artist with his home base in Berlin. He likes to share knowledge on a wide range of fields from generative design to physical computing. His focus is the digital world – including everything related to code and electronics under the reflection on current social aspects, ranging from technology oriented examinations to the discussion of current social issues.\r\nIn his work, he seeks to assess the value of technology, not in terms of actual utility, but from the perspective of future generations. He wants to raise awareness of the privileged state in which people live within Western civilization and remind them of the obligations attached to this privilege.\r\nHidden layers like producing and transporting the raw minerals required to create the core infrastructure of technologie and \"human fulled automation\" labor of microworkers who perform the repetitive digital tasks that underlie new technologie are just some of the topics in his projects.\r\n\r\n","description":null,"links":[{"url":"http://simonweckert.com/work.html","title":"Webpage"}]}],"start_time":"2023-12-30T12:55:00.000+01:00","end_time":"2023-12-30T13:35:00.000+01:00","room":{"name":"Saal Grace","id":472}}]}}