BEGIN:VCALENDAR VERSION:2.0 CALSCALE:GREGORIAN PRODID:-//Pentabarf//Schedule//EN BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 1 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4302.en.html DTSTART;TZID=Europe/Berlin:20101227T113000 UID:4302@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION: SUMMARY:27C3 Keynote - We come in Peace STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 1 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4299.en.html DTSTART;TZID=Europe/Berlin:20101230T183000 UID:4299@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION: SUMMARY:Abschlussveranstaltung STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 2 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4244.en.html DTSTART;TZID=Europe/Berlin:20101229T113000 UID:4244@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:The objective of the session is to provide a critical overview of "privacy research" within computer science. The mechanisms proposed in t he last ten year include mechanisms for anonymous communications\, censorsh ip resistance\, selective disclosure credentials (and their integration in identity management systems)\, as well as privacy in databases. All of thes e system are meant to shield the user from different aspects of on-line sur veillance either through allowing a user to keep some of her data "confiden tial" or by allowing her to assert "control" over her data. We will illustr ate using concrete examples\, why some paradigms came to dominate the field\ , their advantages\, but also their blind spots\, and unfulfilled promises given the conditions of our surveillance societies. SUMMARY:A Critical Overview of 10 years of Privacy Enhancing Technologies STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 1 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4245.en.html DTSTART;TZID=Europe/Berlin:20101227T230000 UID:4245@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:There has been many publications on the topic of Stuxnet and it s "sophistication" in the mainstream press. However\, there is not a comple te publication which explains all of the technical vulnerability details an d how they were discovered. In this talk\, you will get a first-hand accoun t of the entire story. SUMMARY:Adventures in analyzing Stuxnet STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 2 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4057.en.html DTSTART;TZID=Europe/Berlin:20101228T214500 UID:4057@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:Monitoring and reporting about elections in a war zone is a com plex and dangerous task. While crisis mapping carried out via sms and emai l proved highly successful with the use of Ushahidi in situations like post -election violence in Kenya\, tracking crime in Atlanta\, or earthquake rec overy in Haiti\, could it prove useful in such a complex situation as the A fghan political process? This year a team of people set out to do just tha t with three different Ushahidi mapping projects for national media\, natio nal election observers\, and international observers. The following presen tation is about the challenges we faced\, successes we did or did not have\ , and the lessons learned for the future of crisis mapping. SUMMARY:Adventures in Mapping Afghanistan Elections - The story of 3 Ushahi di mapping and reporting projects. STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT0H30M LOCATION:Saal 2 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4168.en.html DTSTART;TZID=Europe/Berlin:20101230T143000 UID:4168@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:We demonstrate that automated\, architecture-independent gadget search is possible. Gadgets are code fragments which can be used to build unintended programs from existing code in memory. Our contribution is a fra mework of algorithms capable of locating a Turing-complete gadget set. SUMMARY:A framework for automated architecture-independent gadget search - CCC edition STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 3 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4046.en.html DTSTART;TZID=Europe/Berlin:20101227T183000 UID:4046@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:Starting in the beginning of August 2010 and lasting until the mid of November\, the project AllColoursAreBeautiful by the Munich chapter of the Chaos Computer Club was serving as a platform for interested people on the world to illuminate\, animate and interact with the front of a vacan t department store in Munich. SUMMARY:AllColoursAreBeautiful - interactive light installation inspired by blinkenlights STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 2 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4114.en.html DTSTART;TZID=Europe/Berlin:20101229T171500 UID:4114@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:Popular contactless systems for physical access control still r ely on obscurity. As we have shown\, time and time again\, proprietary encr yption systems are weak and easy to break. In a follow-up to last year's pr esentation we will now demonstrate attacks on systems with 'proper' cryptog raphic algorithms. SUMMARY:Analyzing a modern cryptographic RFID system - HID iClass demystifi ed STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 3 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4151.en.html DTSTART;TZID=Europe/Berlin:20101229T171500 UID:4151@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:We introduce a new forensic technique that allows to collect us ers' past locations on most current Android phones\, within a few seconds. It becomes possible to tell where the user was at a given time\, or where a phone call took place over the last few hours or days. SUMMARY:Android geolocation using GSM network - "Where was Waldroid?" STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 3 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4144.en.html DTSTART;TZID=Europe/Berlin:20101228T160000 UID:4144@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:The birth of the modern science of acoustics was directly inter twined with the desires to surveill and communicate\, either in secret or t o everybody at once. Acoustics was not just about 'learning more about natu re\,' right from the start it was an applied science\, driven by very clear notions of who has the right\, and thus should have the possibility\, of l istening in on others\, who needs to be able to converse in private\, and w ho should be heard by everybody if he wishes to. How are these historical i deas related to those of today? SUMMARY:A short political history of acoustics - For whom\, and to do what\ , the science of sound was developed in the 17th century STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 3 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4160.en.html DTSTART;TZID=Europe/Berlin:20101227T160000 UID:4160@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:In this talk I demonstrate our research and the implementation of methods to detect cryptographic algorithms and their parameters in softw are. Based onour observations on cryptographic code\, I will point out seve ral inherent characteristics to design signature-based and generic identifi cation methods. SUMMARY:Automatic Identification of Cryptographic Primitives in Software STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 1 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4061.en.html DTSTART;TZID=Europe/Berlin:20101228T171500 UID:4061@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:The Reverse Engineer occasionally faces situations where even h is most advanced commercial tools do not support the instruction set of an arcane CPU. To overcome this situation\, one can develop the missing disass embler. This talk is meant to be a tutorial on how to approach the task\, w hat to focus on first and what surprises one may be in for. The primary foc us will be on the transformation of byte code back into mnemonic representa tion where only the reverse transformation is available (i.e. you have the respective assembler). It also covers how to integrate your new disassemble r into your reverse engineering tool chain. SUMMARY:Building Custom Disassemblers - Instruction Set Reverse Engineering STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT2H00M LOCATION:Saal 1 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4298.en.html DTSTART;TZID=Europe/Berlin:20101229T113000 UID:4298@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:Wir berichten über vergangene Veranstaltungen\, Erfa-Aktivitäte n\, Demonstrationen\, Hacks\, Medienkontakte\, Gerichtsverhandlungen\, Lobb yarbeit sowie weiteres Erfreuliches und Ärgerliches des Jahres 2010 keinesf alls objektiv\, sondern mit der gewohnten Hackerperspektive. SUMMARY:CCC-Jahresrückblick 2010 STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 1 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4211.en.html DTSTART;TZID=Europe/Berlin:20101229T203000 UID:4211@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:EMV is the dominant protocol used for smart card payments world wide\, with over 730 million cards in circulation. Known to bank customers as “Chip and PIN”\, it is used in Europe\; it is being introduced in Canada \; and there is pressure from banks to introduce it in the USA too. EMV sec ures credit and debit card transactions by authenticating both the card and the customer presenting it through a combination of cryptographic authenti cation codes\, digital signatures\, and the entry of a PIN. In this paper w e describe and demonstrate a protocol flaw which allows criminals to use a genuine card to make a payment without knowing the card’s PIN\, and to rema in undetected even when the merchant has an online connection to the bankin g network. SUMMARY:Chip and PIN is Broken - Vulnerabilities in the EMV Protocol STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 2 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4096.en.html DTSTART;TZID=Europe/Berlin:20101227T124500 UID:4096@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:Optimization algorithms present an effective way for removing m ost obfuscations that are used today. Much of the compiler theory can be ap plied in removing obfuscations and building fast and reliable deobfuscation systems. By understanding traditional optimization problems and techniques it is possible to develop and customize compiler optimization algorithms f or usage in binary deobfuscation/analysis. SUMMARY:Code deobfuscation by optimization STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 3 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4276.en.html DTSTART;TZID=Europe/Berlin:20101228T203000 UID:4276@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:Experience firsthand some of the most interesting\, surprising\ , and perspective-changing findings from cognitive and social neuropsycholo gy. With perceptual illusions\, priming\, biases\, heuristics\, and unconsc ious influences\, humans have tons of firmware "bugs". All have exploits\; some even have patches.Learn how to improve your own thinking\, use others' bugs to your advantage\, and gain new perspective on the unconscious and o ften illusory processes involved in your perceptions. SUMMARY:Cognitive Psychology for Hackers - Bugs\, exploits\, and occasional patches STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 1 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4087.en.html DTSTART;TZID=Europe/Berlin:20101229T160000 UID:4087@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:Over 70 million Wiis\, over 40 million Xbox 360s and over 35 mi llion Playstation 3s have been sold in the last few years. That makes over 145 million embedded devices out there and most of them are just used to pl ay games. But what can you do with them if you don't like playing games? Yo u hack them to make them run your own code of course! We're going to talk a bout the various hacks that you can use to gain control of your hardware an d make it do what you want it to do. SUMMARY:Console Hacking 2010 - PS3 Epic Fail STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 2 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4140.en.html DTSTART;TZID=Europe/Berlin:20101227T140000 UID:4140@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:This talk will provide a summary of recently discovered methods which allow to break the Internet's privacy and anonymity. SUMMARY:Contemporary Profiling of Web Users - On Using Anonymizers and Stil l Get Fucked STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 1 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4103.en.html DTSTART;TZID=Europe/Berlin:20101227T124500 UID:4103@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:ACTA\, upcoming criminal enforcement directive\, filtering of c ontent... The entertainment industries go further and further into their cr usade against sharing. They not only attack our fundamental freedoms\, but also the very essence of the Internet.This session is a panorama of the cur rent and upcoming battles\, campaigns and actions. Everyone can help defeat the motherf#§$ers! SUMMARY:Copyright Enforcement Vs. Freedoms - ACTA\, IPRED3 and other upcomi ng battles of the crusade against sharing STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT0H30M LOCATION:Saal 2 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4003.en.html DTSTART;TZID=Europe/Berlin:20101230T130000 UID:4003@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:Lightning talk on biohacking\, complete with cyborg speaker\, i mplant demonstrations\, and knowledge of how to hack your own perception of electromagnetic radiation for approximately thirty Euros. SUMMARY:Cybernetics for the Masses - implants\, sensory extension and silic on - all for you! STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 3 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4067.en.html DTSTART;TZID=Europe/Berlin:20101228T171500 UID:4067@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:Network traffic grows faster than monitoring and analysis tools can handle. During the last two years a couple of appliances hit the marke t which help in finding the “bits of interest”. Recently installed strategi es and solutions for carriers\, banks or lawful interception organizations will be discussed as examples. SUMMARY:Data Analysis in Terabit Ethernet Traffic - Solutions for monitorin g and lawful interception within a lot of bits STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 3 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4231.en.html DTSTART;TZID=Europe/Berlin:20101228T214500 UID:4231@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:Data recovery has always been an area of myths. This lecture wi ll lift some of their covers. SUMMARY:Data Recovery Techniques - Fun with Hard Drives STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 1 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4190.en.html DTSTART;TZID=Europe/Berlin:20101227T203000 UID:4190@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:2011 will again be a crucial year in the battle against data re tention and blanket surveillance. The EU Commission is planning to publish its review of the directive in December (right in time before 27C3)\, and t he lobbying and PR battle has already begun. In six months from now\, we wi ll see the legislative proposal from the EU commission for the revision of data retention.The talk will give a full picture of the legal state of play \, what is going on in Brussels\, what is already being done and of course where you can help. The speakers are closely involved in the process on the European and national level. SUMMARY:Data Retention in the EU five years after the Directive - Why the t ime is now to get active STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 2 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4123.en.html DTSTART;TZID=Europe/Berlin:20101228T183000 UID:4123@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:The security model of our current computer architectures - kern el in ring 0\, processes in ring 3 - goes back to the early 70s. However\, science hasn't stopped. SUMMARY:Defense is not dead - Why we will have more secure computers - tomo rrow STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 2 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4017.en.html DTSTART;TZID=Europe/Berlin:20101227T203000 UID:4017@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:Time to take a look back and under the hood of the current stat e of FOSS based desktops: The Good\, The Bad and The Ugly – Bloat\, strange APIs\, too much complexity. SUMMARY:Desktop on the Linux... (and BSD\, of course) - you're doing it con fused? weird? strange? wrong? STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 1 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4297.en.html DTSTART;TZID=Europe/Berlin:20101227T214500 UID:4297@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:Für den neuen elektronischen Personalausweis sind drei verschie dene Lesegeräteklassen spezifiziert\, von denen die einfachste bereits eini ge Kritik erfahren hat. Nach der Diskussion um die Sicherheit des Personala usweises stellt sich die Frage: Können zertifizierte Lesegeräte den neuen A usweis schützen? SUMMARY:"Die gesamte Technik ist sicher" - Besitz und Wissen: Relay-Angriff e auf den neuen Personalausweis STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 2 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4085.en.html DTSTART;TZID=Europe/Berlin:20101229T203000 UID:4085@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:Hartz IV-Empfangende brauchen keine internetfähigen Computer\, weil sie Fernseher haben. Dieser Ansicht sind deutsche Sozialgerichte und f orcieren damit eine digitale Spaltung per Gesetz. Im Zeitalter der digitale n Informations- und Kommunikationsgesellschaft mutet dieser Umstand absurd an\, aber eine breite öffentlichkeitswirksame Debatte steht bisher aus. SUMMARY:Digitale Spaltung per Gesetz - Das Internet und geschaffene soziale Ungleichheit im Alltag von Erwerbslosen STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 2 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4203.en.html DTSTART;TZID=Europe/Berlin:20101228T113000 UID:4203@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:In 1998\, the EFF built "Deep Crack"\, a machine designed to pe rform a walk over DES's 56-bit keyspace in nine days\, for $250.000. With t oday's FPGA technology\, a cost decrease of 25x can be achieved\, as the co pacobana project has shown. If that's still too much\, two approaches shoul d be considered: Recycling hardware and distributed computing. This talk wi ll be about combining both approaches for the greater good. SUMMARY:Distributed FPGA Number Crunching For The Masses - How we obtained the equivalent power of a Deep Crack for a fistful of dollars - and how the community can benefit from this STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 2 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4006.en.html DTSTART;TZID=Europe/Berlin:20101229T160000 UID:4006@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:At least if you have used all the features of a synthesizer\, y ou probably ask the questions: "How can I modify it? How can I build a synt hesizer myself? What features do I personally need?"This talk covers this t opic from a theoretical and technical point of view. SUMMARY:DIY synthesizers and sound generators - Where does the sound come f rom? STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 2 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4111.en.html DTSTART;TZID=Europe/Berlin:20101227T160000 UID:4111@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:Neben einer kurzen Einführung in die Problematik des Zensus 201 1\, soll es in dem Vortrag auch über die CCC Stellungnahmen für mehrere Lan detage gehen. Weiterhin geht es auch um die mittlerweile abgewiesene Verfas sungsbeschwerde des AK Zensus sowie weitere Möglichkeiten "was zu machen". SUMMARY:Eins\, zwei\, drei - alle sind dabei - Von der Volkszählung zum Bun desmelderegister STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 1 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4099.en.html DTSTART;TZID=Europe/Berlin:20101228T113000 UID:4099@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:Are you ready to wake up from the cult of Arduino? Tired of plu gging together black-box pre-built modules like a mindless drone\, copying and pasting in code you found on Hackaday? You've soldered together your TV -Be-Gone\, built your fifth Minty Boost\, and your bench is awash with disc arded Adafruit packaging and Make magazines. It's time to stop this passive consumption. It's time to create something that is truly yours. It's time\ , my friend\, to design your first circuit board. And you'll need a machine to print it. SUMMARY:File -> Print -> Electronics - A new circuit board printer will lib erate you from the Arduino-Industrial Complex STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 1 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4070.en.html DTSTART;TZID=Europe/Berlin:20101229T214500 UID:4070@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:Auch dieses Jahr werden wir uns wieder bemühen\, Euch mit einem Rückblick auf die Fnords des Jahres zu unterhalten. SUMMARY:Fnord-Jahresrückblick 2010 - von Atomausstieg bis Zwangsintegration STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 1 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4032.en.html DTSTART;TZID=Europe/Berlin:20101228T214500 UID:4032@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:Many Canon DSLR cameras (and all mid- and high-end models) can generate authenticity information for images taken with it. This informatio n (called ‘Original Decision Data’) can be later used to detect if the pict ure is authentic\, was it altered\, retouched\, edited or otherwise forged. It also protects image metadata\, most important being GPS timestamp and c oordinates. SUMMARY:Forging Canon Original Decision Data STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 2 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4164.en.html DTSTART;TZID=Europe/Berlin:20101227T171500 UID:4164@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:Bundesdeutscher und kirchlicher Datenschutz führen eine Paralle lexistenz. Während das Bundesdatenschutzgesetz von der Öffentlichkeit wahrg enommen und kritisch begleitet wird\, ist den Wenigsten überhaupt klar\, da ss es auch einen vom BDSG losgelösten Datenschutz innerhalb der Kirchen gib t\, der sich in einigen wichtigen Punkten vom staatlichen unterscheidet. Di eser Vortrag soll das Bewusstsein für ein Recht wecken\, von dem sechzig Pr ozent der Deutschen betroffen sind – oft ohne es zu wissen. Praxisbeispiele und Tipps inbegriffen. SUMMARY:Friede sei mit Euren Daten - Ein datenschutzrechtlicher Ausflug in ein kirchliches Parelleluniversum STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 3 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4175.en.html DTSTART;TZID=Europe/Berlin:20101227T124500 UID:4175@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:Today\, hacking is reserved for the microscopic fraction of the population who manage to shake themselves free of the suppressive educatio n regime. Student Robotics is the beginning of the solution. By fostering creativity through competition to solve engineering challenges\, we provid e the inspiration society desperately needs. We develop an open platform f or robotics and provide it to schools to open students' minds to the world of hacking. SUMMARY:From robot to robot - Restoring creativity in school pupils using r obotics STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 2 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4018.en.html DTSTART;TZID=Europe/Berlin:20101229T230000 UID:4018@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:Cold boot attacks are a major risk for the protection that Full -Disk-Encryption solutions provide. FrozenCache is a general-purpose soluti on to this attack for x86 based systems that employs a special CPU cache mo de known as "Cache-as-RAM". Switching the CPU cache into a special mode for ces data to held exclusively in the CPU cache and not to be written to the backing RAM locations\, thus safeguarding data from being obtained from RAM by means of cold boot attacks. SUMMARY:FrozenCache - Mitigating cold-boot attacks for Full-Disk-Encryption software STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT2H00M LOCATION:Saal 1 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4141.en.html DTSTART;TZID=Europe/Berlin:20101229T230000 UID:4141@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:The Hacker Jeopardy is a quiz show. SUMMARY:Hacker Jeopardy - Number guessing for geeks STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT2H00M LOCATION:Saal 3 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4333.en.html DTSTART;TZID=Europe/Berlin:20101229T230000 UID:4333@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:The Hacker Jeopardy is a quiz show. SUMMARY:Hacker Jeopardy (english translation) - Number guessing for geeks STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT0H30M LOCATION:Saal 2 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/3983.en.html DTSTART;TZID=Europe/Berlin:20101230T134500 UID:3983@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:Although most academics and industry practitioners regard "hack ing" as mostly ad-hoc\, a loose collection of useful tricks essentially ran dom in nature\, I will argue that hacking has in fact become a "distinct re search and engineering discipline" with deep underlying engineering ideas a nd insights. Although not yet formally defined as such\, it are these ideas and insights that drive the great contributions that hacking has been maki ng to our understanding of computing\, including the challenges of handling complexity\, composition\, and security in complex systems. I will argue t hat hacking uncovers and helps to understand (and teach) fundamental issues that go to the heart of Computer Science as we know it\, and will try to f ormulate several such fundamental principles which I have learned from hack er research. SUMMARY:Hackers and Computer Science STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 3 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4176.en.html DTSTART;TZID=Europe/Berlin:20101227T203000 UID:4176@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION: SUMMARY:Hacking iButtons STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 2 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4265.en.html DTSTART;TZID=Europe/Berlin:20101227T183000 UID:4265@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:There's been a fair bit written and presented about smartphone' s\, and yet\, when it comes to the attack surface of the operating systems running on them\, and the applications running on top of those\, much still has to be explorer. This talk will dive a bit deeper into that attack surf ace. SUMMARY:hacking smart phones - expanding the attack surface and then some STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 3 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4193.en.html DTSTART;TZID=Europe/Berlin:20101230T171500 UID:4193@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:A lot of people are interested and involved in voice over IP se curity. Most of the effort is concentrated on the security of the signallin g protocols. This talk is focussing on the security of the voice part invol ved in todays voice over IP world. It is the result of the questions that I had to ask myself while i was debugging audio quality problems of customer s and implementing a RTP stack from scratch. SUMMARY:Having fun with RTP - „Who is speaking???“ STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 1 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4295.en.html DTSTART;TZID=Europe/Berlin:20101228T203000 UID:4295@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:Are you writing a program that sends data through the Internet? Are you sending the data through HTTP\, or SMTP\, or simply TCP\, leaving it vulnerable to espionage\, corruption\, and sabotage by anyone who owns a machine connected to the same network?You can use SSH and IPsec to protect communication with your own machines\, but how do you talk to the rest of the Internet? You can use TCPcrypt to protect yourself against attackers to o lazy to forge packets\, but how do you protect yourself against serious a ttackers? You can use HTTPS for low-frequency communication\, but how do yo u handle heavy network traffic\, and how do you protect yourself against th e security flaws in HTTPS? Today's Internet cryptography is slow\, untrustw orthy\, hard to use\, and remarkably unsuccessful as a competitor to good o ld unprotected TCP.This talk will present a different approach to high-secu rity Internet cryptography. This approach is easy for users\, easy for syst em administrators\, and\, perhaps most importantly\, easy for programmers. The main reason that the approach has not been tried before is that it seem s to involve very slow cryptographic operations\; this talk will show that the approach is extremely fast when it is done right. SUMMARY:High-speed high-security cryptography: encrypting and authenticatin g the whole Internet STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 1 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4301.en.html DTSTART;TZID=Europe/Berlin:20101230T160000 UID:4301@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:On the Internet one tends to think that one is pretty much safe from poking eyes. Taps in most countries can only be established after a j udge has issued a warrant\, thus upto such a tap is succesfully deployed o ne might think one is pretty much in the clear. SUMMARY:How the Internet sees you - demonstrating what activities most ISPs see you doing on the Internet STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 1 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4089.en.html DTSTART;TZID=Europe/Berlin:20101230T124500 UID:4089@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:Der Vortrag zeigt auf\, wie sich Politiker rechtfertigen\, wenn sie gegen ihre Argumentation und die Überzeugungen entscheiden oder handel n\, für die sie stehen. Es ergibt sich dabei eine extreme Zwangslage\, denn es ist oft nicht so einfach möglich\, die zuvor vorgebrachten Argumente au fzugeben. Also muss auf Leerformeln\, Nebelkerzen\, Scheinargumente und spe zielle grammatische Mittel zurückgegriffen werden\, die die Regresspflicht mindern (Konjunktive\, doppelte Verneinungen\, Modalpartikeln usw.)\; dabei sind Kunstgriffe nötig\, die über die inzwischen hinlänglich bekannte Leye n-Rhetorik hinausgehen. SUMMARY:Ich sehe nicht\, dass wir nicht zustimmen werden - Die Sprache des politischen Verrats und seiner Rechtfertigung STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 3 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4149.en.html DTSTART;TZID=Europe/Berlin:20101228T140000 UID:4149@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:Unsafe languages and an arms race for new bugs calls for an add itional line of defense in software systems. User-space virtualization uses dynamic instrumentation to detect different attack vectors and protects fr om the execution of malicious code. An additional advantage of these virtua lization systems is that they can be used to analyze different exploits ste p by step and to extract the exploit code from a running program.This talk explains the concept of different attack vectors (stack buffer overflows\, format string attacks\, return to libc attacks\, race attacks / TOCTTOU\, i nteger overflows\, heap buffer overflows\, and code anomalies). For each of these attack vectors we show possible exploits and explain how the virtual ization system is able to detect and prevent the exploit. SUMMARY:I Control Your Code - Attack Vectors Through the Eyes of Software-b ased Fault Isolation STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT0H30M LOCATION:Saal 2 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4084.en.html DTSTART;TZID=Europe/Berlin:20101229T134500 UID:4084@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:This paper explores the challenges of being proactive with exis ting and future data mining possibilities when facing the realities of inst itutional expectations for assessment and when facing the fact that one’s o wn understanding of cyber capabilities is less than ideal. This paper disc usses the current assessment cyber resources\, trends\, and pressures withi n USA academic institutions and the challenges of reactive/proactive labor in the midst of multiple levels of technological/informational literacies a mongst administrators. SUMMARY:Ignorance and Peace Narratives in Cyberspace - Cloud Computing\, As sessment\, and Fools like Me. STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 2 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4237.en.html DTSTART;TZID=Europe/Berlin:20101229T183000 UID:4237@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:INDECTThe acronym stands for Intelligent Information System Sup porting Observation\, Searching and Detection for Security of Citizens in U rban Environment. A total of 17 partners in nine member states are developi ng an infrastructure for linking existing surveillance technologies to form one mighty instrument for controlling the people. They are laying the foun dation of a European police state\, since INDECT's results serve to increas e the effectiveness of police operation on the national and European level. INDECT is funded under the European Commission's Seventh Framework Programm e (FP7)\, the security-related research of which provides € 1.4 billion Eur o for more than 60 partly interlaced projects. SUMMARY:INDECT - an EU-Surveillance Project STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 2 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4236.en.html DTSTART;TZID=Europe/Berlin:20101230T160000 UID:4236@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:Concepts of sovereignty\, freedom\, privacy and intellectual pr operty become amorphous when discussing territories that only exists as far as the Internet connects. International cyber jurisdiction is supported by a complicated web of international law and treaties. Jurisdiction hopping\ , a technique that is becoming popular for controversial content\, is one w e have used for the U.S. 1st Amendment censorship-resistant and non-profit hosting company\, Project DOD\, by using PRQ's services in Sweden. This te chnique is used to place assets in a diverse\, but accessible\, web of coun tries in which that content may be legal in the hosting country\, but may h ave legal complications in the country in which it is accessed. As ownershi p and protection of property becomes a concept that is difficult to maintai n across boundaries that are not easily distinguishable\, can the U.S. "kil l-switch" parts of the Internet and under what authority can it be done? Si milarly\, the geographic challenges to international cyber criminal law – a nd the feasibility of new sovereign nations – will be analyzed. SUMMARY:International Cyber Jurisdiction - Kill Switching” Cyberspace\, Cyb er Criminal Prosecution & Jurisdiction Hopping STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 2 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4121.en.html DTSTART;TZID=Europe/Berlin:20101228T160000 UID:4121@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:The EFF SSL Observatory has collected a dataset of all TLS/HTTP S certificates visible on the public web. We discuss this dataset - what we have learned from it\, how you can use it\, and how intend to offer a live \, continually updated version of it. SUMMARY:Is the SSLiverse a safe place? - An update on EFF's SSL Observatory project STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 3 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4011.en.html DTSTART;TZID=Europe/Berlin:20101227T140000 UID:4011@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:Bring your target. Will release a slew of simple tools that exp lore attack surfaces and explain of how to use: jtag/serial scanners\, para llel flash dumper\, DePCB board routing analysis. So\, crossover from softw are RE and start hacking/improving like its 1996 again. (full documentation and reference at: http://events.ccc.de/congress/2010/wiki/Embedded_Analysi s) SUMMARY:JTAG/Serial/FLASH/PCB Embedded Reverse Engineering Tools and Techni ques - a dump of simple tools for embedded analysis at many layers STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 3 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4296.en.html DTSTART;TZID=Europe/Berlin:20101228T124500 UID:4296@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:4 minutes for every speaker. Learn about the good\, the bad\, a nd the ugly - in software\, hardware\, projects\, and more. SUMMARY:Lightning Talks - Day 2 - 4 minutes of fame STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT2H15M LOCATION:Saal 3 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4239.en.html DTSTART;TZID=Europe/Berlin:20101229T113000 UID:4239@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:4 minutes for every speaker. Learn about the good\, the bad\, a nd the ugly - in software\, hardware\, projects\, and more. SUMMARY:Lightning Talks - Day 3 - where is my community? STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT2H15M LOCATION:Saal 3 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4300.en.html DTSTART;TZID=Europe/Berlin:20101230T113000 UID:4300@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:4 minutes for every speaker. Learn about the good\, the bad\, a nd the ugly - in software\, hardware\, projects\, and more. SUMMARY:Lightning Talks - Day 4 - where is my community? STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 2 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4195.en.html DTSTART;TZID=Europe/Berlin:20101228T171500 UID:4195@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:Ein literarischer Abend im Quartett. SUMMARY:Literarischer Abend STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT0H30M LOCATION:Saal 2 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4073.en.html DTSTART;TZID=Europe/Berlin:20101228T143000 UID:4073@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:Ein kurzer Überblick über mechanische und strömungstechnische L ogikschaltungen und Computer SUMMARY:Logikschaltungen ohne Elektronik - logische Schaltungen mit Pneumat ik STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT0H30M LOCATION:Saal 2 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4210.en.html DTSTART;TZID=Europe/Berlin:20101228T130000 UID:4210@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:Distributed Hash Tables implement Routing and Addressability in large P2P networks. In the Kademlia adaption for Bittorrent a peer's addre ss (NodeID) is to be generated randomly\, or more appropriate: arbitrarily. Because randomness isn't verifiable\, an implementation can advertise itse lf with popular NodeIDs or even change them on a per-packet basis. SUMMARY:Lying To The Neighbours - Nasty effects with tracker-less BitTorren t STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 3 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4081.en.html DTSTART;TZID=Europe/Berlin:20101228T113000 UID:4081@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:Die Mediennutzung\, aber auch ihre Verwaltung und Vergütung\, a lso ihr Management\, müssen an eine digitale Netzwelt angepasst werden. Wie ist der Stand der juristischen Auseinandersetzung um die Rechte von Urhebe rn\, Verwertern und Nutzern von Medieninhalten? Wie und wo setzen sich star ke Wirtschaftsinteressen mit Lobbygruppen durch? SUMMARY:Netzmedienrecht\, Lobbyismus und Korruption - Wie wirkt die Lobby v on Medienkonzernen? STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H30M LOCATION:Saal 1 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4094.en.html DTSTART;TZID=Europe/Berlin:20101227T183000 UID:4094@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:Geht es mit der Netzneutralität zu Ende? Was haben wir den Lobb yisten und PR-Leuten der Telekommunikationsunternehmen argumentativ entgege nzusetzen? Was sind die Fakten\, was gehört ins Reich der Mythen? SUMMARY:Netzneutralität und QoS - ein Widerspruch? - Fakten auf den Tisch STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 2 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4261.en.html DTSTART;TZID=Europe/Berlin:20101230T171500 UID:4261@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:In this paper\, we present several weaknesses in the stream cip her RC4.First\, we present a technique to automatically reveal linearcorrel ations in the PRGA of RC4. SUMMARY:News Key Recovery Attacks on RC4/WEP STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT0H30M LOCATION:Saal 2 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4142.en.html DTSTART;TZID=Europe/Berlin:20101228T134500 UID:4142@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:Node.js is a library that provides non-blocking I/O for Google' s V8 JavaScript engine. This talk explores node's suitability for a diverse range of networking applications. SUMMARY:Node.js as a networking tool STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 1 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4221.en.html DTSTART;TZID=Europe/Berlin:20101230T113000 UID:4221@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:Ambiguities in the PDF specification means that no two PDF pars ers will see a file in the same way. This leads to many opportunities for e xploit obfuscation. SUMMARY:OMG WTF PDF - What you didn't know about Acrobat STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 1 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4143.en.html DTSTART;TZID=Europe/Berlin:20101228T160000 UID:4143@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:The Part-Time Scientists is an international team of Scientists and Engineers participating in the first private race to the moon\, the Go ogle Lunar X-Prize. Our approach to win this competition is quite unique as everyone involved really is a part-time scientist.In our presentation we w ill present our latest lunar rover\, lander\, electronic and communications developments. SUMMARY:Part-Time Scientists - One year of Rocket Science! STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 1 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4253.en.html DTSTART;TZID=Europe/Berlin:20101228T001500 UID:4253@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:Out of the news section of the [C3D2](http://www.c3d2.de "CCC D resden") [radio programme](http://www.pentamedia.org/pentaradio Pentaradio2 4) we've compiled an entertaining game show\, an Internet-based multiplayer "Who becomes millionaire?" challenge. The audience and folks on the peace missions are asked to help the players. SUMMARY:Pentanews Game Show - Your opponents will be riddled as well STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 1 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4326.en.html DTSTART;TZID=Europe/Berlin:20101229T140000 UID:4326@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:Radio – das ist eine der wenigen elektronischen Medientechnolog ien\, die den Sprung in die digitale Ära noch nicht richtig geschafft hat. Während die Fernsehverbreitung schon fast vollständig per volldigitalen Sys temen wie DVB-T stattfindet\, bleiben die Radiosender dem guten alten Analo g-Funk auf UKW treu. SUMMARY:Radio der Zukunft - Was kommt nach dem analogen Radio? STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 2 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/3957.en.html DTSTART;TZID=Europe/Berlin:20101227T214500 UID:3957@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:New protocol features have been proposed and implemented in the last 5 years and ISPs are now slowly starting to deploy IPv6. This talk st arts with a brief summary of the issues presented five years ago\, and then expands on the new risks.Discovered implemention security issues in Window s 7/2008\, Linux and Cisco will be shown too. Comes with a GPL'ed toolkit: thc-ipv6 SUMMARY:Recent advances in IPv6 insecurities STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 3 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4036.en.html DTSTART;TZID=Europe/Berlin:20101229T203000 UID:4036@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:How to reverse engineer the data format of a real-world RFID ba sed debit card system. SUMMARY:Reverse Engineering a real-world RFID payment system - Corporations enabling citizens to print digital money STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 1 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4159.en.html DTSTART;TZID=Europe/Berlin:20101228T124500 UID:4159@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:The MOS 6502 CPU\, which was designed in 1975 and powered syste ms like the Apple II\, the Atari 2600\, the Nintendo NES and the Commodore 64 for two decades\, has always been subject to intense reverse engineering of its inner workings. Only recently\, the Visual6502.org project has conv erted a hi-res die-shot of the 6502 into a polygon model suitable for visua lly simulating the original mask at the transistor level. This talk will pr esent the way from a chip package to a digital representation\, how to simu late transistors in software\, and new insights gained form this research a bout 6502 internals\, like "illegal" opcodes. SUMMARY:Reverse Engineering the MOS 6502 CPU - 3510 transistors in 60 minut es STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 3 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4082.en.html DTSTART;TZID=Europe/Berlin:20101227T230000 UID:4082@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:SAP systems are the heart of many enterprises. Most critical bu siness functions run on SAP Applications and the complexity of these system s makes it very difficult to protect against attackers. Default setups\, fo rgotten/unimplemented security configurations\, weak password management an d change processes that apply to one ‘unimportant’ system can result in com plete compromise of the SAP landscape. SUMMARY:Rootkits and Trojans on Your SAP Landscape - SAP Security and the E nterprise STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 1 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/3952.en.html DTSTART;TZID=Europe/Berlin:20101229T183000 UID:3952@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:In recent years\, we have seen several Free Software projects i mplementing the network side of the GSM protocol. In 2010\, OsmocomBB was s tarted to create a free software implementation of the telephone-side. SUMMARY:Running your own GSM stack on a phone - Introducing Project Osmocom BB STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 3 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4183.en.html DTSTART;TZID=Europe/Berlin:20101229T160000 UID:4183@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:In maritime shipping accurate positioning is vital to preserve damage to life\, ship\, and goods. Today\, we might tend to think that this problem is sufficiently solved yet because of the existence of electronic positioning systems like\, most notably\, the Global Positioning System (GP S) or the Russian counterpart GLONASS. This is wrong. Positions in terms of latitude and longitude just make sense together with an accurate sea chart (and of course\, together with a navigator that is able to translate chart ing data into reality). SUMMARY:Safety on the Open Sea - Safe navigation with the aid of an open se a chart. STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 2 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4138.en.html DTSTART;TZID=Europe/Berlin:20101228T230000 UID:4138@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:Auditive steganography allows for various usage scenarios. In o ur project we focused on hidden communications in VoIP and GSM in which voi ce data is typically compressed and transmitted in realtime. A framework ha s been developed to meet these requirements\, providing interfaces for robu st steganographic algorithms. SUMMARY:Secure communications below the hearing threshold - Improved approa ches for auditive steganography STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 1 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4230.en.html DTSTART;TZID=Europe/Berlin:20101230T171500 UID:4230@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:Was hat sich im letzten Jahr im Bereich IT-Sicherheit getan? We lche neuen Entwicklungen haben sich ergeben? Welche neuen Buzzwords und Tre nds waren zu sehen? SUMMARY:Security Nightmares STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT0H30M LOCATION:Saal 2 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4181.en.html DTSTART;TZID=Europe/Berlin:20101229T143000 UID:4181@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:The SIP home gateway -- which combines a NAT router\, a SIP pro xy\, and analogue phone adapters -- is the weakest link in a Voice over IP network. SIP's numerous source routing mechanisms share the well-known secu rity weaknesses of IP source routing. The talk discusses possible exploits and countermeasures. SUMMARY:SIP home gateways under fire - Source routing attacks applied to SI P STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 1 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4060.en.html DTSTART;TZID=Europe/Berlin:20101227T171500 UID:4060@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:Smart phones\, everybody has a smart phone! No! Just about 16% of all mobile phones are smart phones! Feature phones are the most common t ype of mobile phone in the world. Some time ago we decided to investigate t he security of feature phones. In this talk we show how we analyzed feature phones for SMS security issues. We show our results and the kind of attack s that are possible with our bugs. SUMMARY:SMS-o-Death - From analyzing to attacking mobile phones on a large scale. STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 2 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4125.en.html DTSTART;TZID=Europe/Berlin:20101227T230000 UID:4125@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:Dreieinhalb Jahre nach dem Talk '21st Century digital Bikes' au f dem Camp 2007 ist einiges in der Welt der elektrischen Fortbewegung passi ert. Ende 2010 ist ein guter Zeitpunkt\, den Stand der Dinge aufzurollen\, die Neuigkeiten darzustellen und über eine mehr unschärfer als klarer werde nde Zukunft der elektrischen Mobilität zu sprechen. SUMMARY:Spinning the electronic Wheel - Still the bicycles for the 21th cen tury STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 3 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4145.en.html DTSTART;TZID=Europe/Berlin:20101229T140000 UID:4145@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:Getting the interfaces right to computers controlling complex a nd dangerous machines such as commercial airliners is crucial. I will prese nt a successful accident analysis method and talk about interface design pr oblems\, ideas for solutions\, methods for understanding causal control flo w. There will be some spectacular aviation accident videos and stories of b ad luck\, bad design\, bad decisions\, and a hero that managed to turn a ne ar-catastrophe into an accident without fatalities. SUMMARY:"Spoilers\, Reverse Green\, DECEL!" or "What's it doing now?" - Tho ughts on the Automation and its Human interfaces on Airplanes STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 1 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4184.en.html DTSTART;TZID=Europe/Berlin:20101229T001500 UID:4184@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:Man kennt ihn als einen der wichtigsten Science-Fiction-Autoren des zwanzigsten Jahrhunderts. Aber Lem war mehr als das: Als Philosoph und Wissenschaftler konnte er technische Entwicklungen der Menschheit und ihre Auswirkungen sogar voraussehen. Als solcher prägte er viele heute geläufig e Begriffe für technische Errungenschaften\, die seinerzeit noch gar nicht existierten. Seine teils utopische\, teils humoristische und selbstironisch e Art zu schreiben\, brachte ihm weltweit große Popularität ein\, seine Büc her erreichten eine Auflage von mehr als 45 Millionen und wurden zum Teil v erfilmt. SUMMARY:Stanislaw Lem - Der enttäuschte Weltverbesserer - Ein audiovisuelle s Live-Feature STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 3 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4097.en.html DTSTART;TZID=Europe/Berlin:20101228T183000 UID:4097@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:Der Vortrag soll Techniken aufzeigen\, mit denen man Netzwerk-P rotokolle identifizieren kann\, die in Layer 7 des OSI-Modells angesiedelt sind. Alle Techniken - darunter auch die Deep Packet Inspection (DPI) - wer den technisch erläutert und kritisch bewertet. SUMMARY:Techniken zur Identifizierung von Netzwerk-Protokollen STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 2 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4055.en.html DTSTART;TZID=Europe/Berlin:20101229T123000 UID:4055@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:Telecommunications data retention (TDR) has become a reality in mostWestern countries. Protagonists claim that the collection of massiveam ounts of data on the communication behavior of all individualswithin a coun try would enable law enforcement agencies to exploitpatterns in the stored data to uncover connections between suspects. SUMMARY:Terrorists Win - Exploiting Telecommunications Data Retention? STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 2 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4090.en.html DTSTART;TZID=Europe/Berlin:20101228T203000 UID:4090@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:Attack scenarios against mobile phones have thus far concentrat ed on the application processor. The operating systems running on these pro cessors are getting hardened by vendors as can be seen in the case of Apple 's iOS -- the current release uses data execution prevention and code signi ng. In contrast\, the GSM stack running on the baseband processor is neglec ted. The advent of open-source solutions such as OpenBSC and OpenBTS for ru nning GSM base stations is a game-changer: Malicious base stations are not within the attack model assumed by the GSMA and ETSI. SUMMARY:The Baseband Apocalypse - all your baseband are belong to us STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 1 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4201.en.html DTSTART;TZID=Europe/Berlin:20101228T183000 UID:4201@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:Corey Cerovsek and Julien Quentin\, accomplished musicians know n worldwide for their classical recital performances\, present something th at's not quite an ordinary concert\, to draw attention to the importance of the public domain in centuries of classical music tradition. It's both mor e — and less — than what you might expect to see and hear at a classical co ncert. SUMMARY:"The Concert" - a disconcerting moment for free culture STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 3 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4174.en.html DTSTART;TZID=Europe/Berlin:20101228T230000 UID:4174@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:Want to persistently backdoor a laptop? Backdooring the BIOS is out of the question since your target can dump and diff it? Planting hardw are is out of the question as well? Shhhhhhh.. I have something for you: SUMMARY:The Hidden Nemesis - Backdooring Embedded Controllers STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 1 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4263.en.html DTSTART;TZID=Europe/Berlin:20101228T230000 UID:4263@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:My name is Nicholas Merrill and I was the plaintiff in a legal case in the US court system where I challenged the FBI’s policy of using a feature of the so-called USA PATRIOT act - what are called “National Securi ty Letters” - to bypass the American Constitution's system of checks and ba lances and in violation of the United Nations Universal Declaration of Huma n Rights - in order to obtain protected personal information and to unmask anonymous Internet users. I spent over 6 years not able to speak to anyon e (other than my lawyers) about my case - forced to lie to those closest to me due to an FBI gag order that carried a possible 10 year prison sentence for violating it. However the lawsuit resulted in the establishment of t wo key legal precedents and made changes that affect every Internet worker and Telephone worker in America. I would like to speak to the 27C3 audie nce in order to tell about my experience and to challenge (and offer my sup port and assistance to) those individuals who are in a position to challeng e government surveillance requests to follow their consciences and do so.Pe ople who work at Internet Service Providers and Telephone companies as well as IT workers at Universities and private businesses are increasingly like ly to encounter government attempts at surveillance. I would like to speak to the CCC regarding my experiences in resisting a National Security Lette r and also a “Grand Jury Subpoena” as well as my experience of being gagged by the FBI for nearly 7 years - unable to speak on the subject or identify myself as the plaintiff in the NSL lawsuit. SUMMARY:The importance of resisting Excessive Government Surveillance - Joi n me in exposing and challenging the constant violations of our right to pr ivacy STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 1 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4124.en.html DTSTART;TZID=Europe/Berlin:20101230T140000 UID:4124@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:Print media are dying\, but what is rising up to take their pla ce? In this presentation\, I'll answer that question by describing three ne w kinds of jobs for journalists that do not exist in mainstream print media . These jobs are: hacker journalist\, data-mining reporter\, and crowd engi neer. I'll be describing what these jobs entail\, and current examples of o rganizations already employing people to do them. SUMMARY:Three jobs that journalists will do in 2050 - Why future media may be more powerful (and more subversive) than ever before STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 2 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4098.en.html DTSTART;TZID=Europe/Berlin:20101230T113000 UID:4098@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:The Internet began as state-sponsored anarchy\, but it is now t he tool of first resort for dissidents and propagandists alike. The poster- child project of the Free Software Movement runs on the authority of a sing le person\; the rest clash over the very definition of the word 'free'. A c ompany which pictured itself as smashing Big Brother is now seen as one of the perceived secretive and authoritarian in the industry\; and for another \, 'Don't Be Evil' is proving to be a challenging motto to live by. SUMMARY:Tor is Peace\, Software Freedom is Slavery\, Wikipedia is Truth - T he political philosophy of the Internet STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 3 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4234.en.html DTSTART;TZID=Europe/Berlin:20101227T171500 UID:4234@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:Learn about the benefits and limitations of Universal Serial Bu s\, how communication works on the bus\, how and why the right (and sometim es wrong?) driver can be loaded automatically by the operating system\, and find out the easiest way to add USB to your washing machine\, toaster\, or other favorite appliance. SUMMARY:USB and libusb - So much more than a serial port with power STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 1 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4252.en.html DTSTART;TZID=Europe/Berlin:20101227T140000 UID:4252@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:Nach Zensursula kam Censilia und das Kindernet: 2010 brachte na ch den hitzigen Diskussionen um Internet-Sperren und das Zugangserschwerung sgesetz einige neue Entwicklungen – und die Rundfunkkommission der Länder w ollte mal wieder den Jugendschutz im Internet angehen. SUMMARY:Von Zensursula über Censilia hin zum Kindernet - Jahresrückblick ru nd um Internet-Sperren\, Sendezeitbegrenzungen im Internet und vermeintlich en Jugendschutz STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 1 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4185.en.html DTSTART;TZID=Europe/Berlin:20101227T160000 UID:4185@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:Whistleblowing als universelles Konzept für mehr Transparenz – oder: über die Rückeroberung der Dunkelräume in Wirtschaft und Politik auch jenseits von Wikileaks. SUMMARY:Whistleblowing - Licht ins Dunkel! STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 1 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4208.en.html DTSTART;TZID=Europe/Berlin:20101228T140000 UID:4208@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:GSM is still the most widely used security technology in the wo rld with a user base of 5 billion and a quickly growing number of critical applications. 26C3's rainbow table attack on GSM's A5/1 encryption convince d many users that GSM calls should be considered unprotected. The network o perators\, however\, have not woken up to the threat yet. Perhaps the new c apabilities to be unleashed this year – like wide-band sniffing and real-ti me signal processing – will wake them up. SUMMARY:Wideband GSM Sniffing STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 3 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4187.en.html DTSTART;TZID=Europe/Berlin:20101229T183000 UID:4187@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:The past century our infrastructure has seen both massive expan sion and heavy centralization. When it fails\, it fails big -- this is the reality of our modern interconnectedness. We live in a world of crumbling bridges and bankrupt states\, and our infrastructure will kill us. The pe ople we’re relying on to keep us safe are trying to accomplish long-term ri sk management with short-term thinking. So\, what now? We can't opt out\, but we can become more resilient\, and we can start thinking about risk di fferently. SUMMARY:Your Infrastructure Will Kill You STATUS:CONFIRMED END:VEVENT BEGIN:VEVENT DURATION:PT1H00M LOCATION:Saal 3 SEQUENCE:0 URL:http://events.ccc.de/congress/2010/Fahrplan/events/4209.en.html DTSTART;TZID=Europe/Berlin:20101229T214500 UID:4209@27C3@pentabarf.org DTSTAMP:20101227T114851 CATEGORIES:Lecture DESCRIPTION:The dynamic memory allocator is a fundamental component of mode rn operating systems\, and one of the most important sources of security vu lnerabilities. In this presentation\, we emphasize on a particular weakness of the heap management that has proven to be the root cause of many escala tion of privilege bugs in the windows kernel and other critical remote vuln erabilities in user-land applications. SUMMARY:Zero-sized heap allocations vulnerability analysis - Applications o f theorem proving for securing the windows kernel STATUS:CONFIRMED END:VEVENT END:VCALENDAR