A review of 34c3 talks

This is my personal review/notes of the 34c3 talks.

Enjoy !

Favorites

Gamified Control

Link

I’m starting by this talk since it’s a must watch in my opinion.

China has implemented their new Social Credit System (SCS) throught the use of big data and surveillance. This system will rate the online and offline behavior of the citizen to assess them and give them a score. Depending how well you perform, you will get bonuses or penalities. More important, the score is determined by you friend’s score.

China has gamified being an obedient citizen, using social pressure.

Notes:

Forensic Architecture

link

An independant research agency investigating new methods in forensics to undertake human rights abuse.

They reconstructed a 3D scene from pictures, and videos from multiples angles to determine exactly when and where a missile hit the floor, which building were affected, etc

Really impressive !

Spy vs. Spy: A Modern Study Of Microphone Bugs Operation And Detection

Link

What’s the status of security research to detect hidden spy microphones ?

The researchers present a state-of-the-art study of microphone bugs, as well as a tool called Salamandra to detect and locate hidden microphones !

Notes:

Bringing Linux back to server boot ROMs with NERF and Heads

Link

Replacing proprietary vendor boot firmware by an open source Linux runtime.

Notes:

How to drift with any car

link

They describe how the various electronic components that control your car are communicating with each over, and how you can listen to the BUS and send your own messages.

The funny part was when they plugged this with a XBox controller, and played a video game using the car’s wheel as a controler input… :)

Notes:

Briar

link

Briar is a new P2P, resilient messaging system.

And it works even without internet (Wifi, Bluetooth, etc…)

I loved the talk, very good speaker and presentation.

OONI: Let’s Fight Internet Censorship, Together!

link

Another talk that i really appreciated, the OONI project aims to watch internet censorship by probing websites availability in different countries in the world.

Anyone can install an OONI probe and contribute !

How risky is the software you use ?

link

What’s the real state of the software security you use everyday ?

Can we evaluate it, and give it a score ?

CITL: Improve the state of software security by providing the public with accurate reporting on the security of popular software

Notes:

Protecting Your Privacy at the Border

link

What could happen to your digital devices if you cross a border.

You better be prepared, upload everything to the cloud in case the border patrols seize your laptop, and know your rights !

Notes:

Surveillance

Uncovering British spies’ web of sockpuppet social media personas

link

The JTRIG (GCHQ) had to create sockpuppet accounts and fake content on social media for their missions.

How easy it is to unmask them ? :)

Policing in the age of data exploitation

link

How the police and law enforcement are collecting data and exploiting them for their investigations

Notes:

Security

Inside Intel Management Engine

link

The Intel ME vulnerability to run unsigned code

I have to go throught the presentation again, because i didn’t catch everything on my first watch …

Notes:

Intel ME: Myths and reality

link

Clear the FUD and understanding the true purposes of Intel ME.

Notes:

Are all BSDs created equally?

link

A survey of BSD vulnerablities.

Destroying the myth, that because it’s BSD, it’s more secure and there no vulnerabilities compared to Linux

Notes:

Hardening Open Source Development

link

It’s really easy to use a software developer environement and transform it into an attack vector.

This talk review the possible vulnerabilities and how to exploit the everyday tools that software developers uses

Notes:

AI

Deep-learning blindspots

link

The state of the art research of adversarial learning and how to fool them.

Researchers have found blindspots.

Example: a turtle recognized as … a rifle.

Arts

Humans as software extensions

link

Notes:

Misc

Organisational Structures for Sustainable Free Software Development

link

How to manage your free software project ?

What organizational structures exists to sustain the development ?

What about the funding ?

Notes: