6 ms·
Where were people's favourite lectures? I attended 7 talks. My favourite talk by far was hacking the GPG. Brilliant, really: https://media.ccc.de/v/39c3-to-si
by neiman 9mo ago
Where were people's favourite lectures?
I attended 7 talks.
My favourite talk by far was hacking the GPG. Brilliant, really: https://media.ccc.de/v/39c3-to-sign-or-not-to-sign-practical-vulnerabilities-i https://media.ccc.de/v/39c3-to-sign-or-not-to-sign-practical...
The "In-house electronics manufacturing from scratch" was a very inspiring talk: https://media.ccc.de/v/39c3-in-house-electronics-manufacturing-from-scratch-how-hard-can-it-be https://media.ccc.de/v/39c3-in-house-electronics-manufacturi...
The rest were less good for me personally. Either over-dramatic and shallow (with a sexy-sounding topic) or too procedural in topics I'm not an expert in.
- SoylentBob 9mo agoThe one on the bluetooth headphone vulnerabilities was quite fun: https://media.ccc.de/v/39c3-bluetooth-headphone-jacking-a-key-to-your-phone https://media.ccc.de/v/39c3-bluetooth-headphone-jacking-a-ke...
- pamcake 9mo agoI also enjoyed the GPG talk. Other highlights: Not an Impasse: Child Safety, Privacy, and Healing Together: https://media.ccc.de/v/39c3-not-an-impasse-child-safety-privacy-and-healing-together https://media.ccc.de/v/39c3-not-an-impasse-child-safety-priv... APT Down and the mystery of the burning data centers: https://media.ccc.de/v/39c3-apt-down-and-the-mystery-of-the-burning-data-centers https://media.ccc.de/v/39c3-apt-down-and-the-mystery-of-the-... Bluetooth Headphone Jacking: A Key to Your Phone: https://media.ccc.de/v/39c3-bluetooth-headphone-jacking-a-key-to-your-phone https://media.ccc.de/v/39c3-bluetooth-headphone-jacking-a-ke...
- robingchan 9mo agoorder by personal rank: Sandstorm JP-8000 sawtooth DSP reversing https://www.youtube.com/watch?v=XM_q5T7wTpQ https://www.youtube.com/watch?v=XM_q5T7wTpQ Washing machines hacking https://www.youtube.com/watch?v=Q1S-PVo3GlA https://www.youtube.com/watch?v=Q1S-PVo3GlA AMD (ps5 sorta) security: https://www.youtube.com/watch?v=cVJZYT8kYsI https://www.youtube.com/watch?v=cVJZYT8kYsI cool demo for the BT headphones talk: https://www.youtube.com/watch?v=TK5Tz4Bt94Y https://www.youtube.com/watch?v=TK5Tz4Bt94Y precise time syncing with PTP: https://www.youtube.com/watch?v=dOt-zRIG5co https://www.youtube.com/watch?v=dOt-zRIG5co x86 > arm with intermediate: https://www.youtube.com/watch?v=3yDXyW1WERg https://www.youtube.com/watch?v=3yDXyW1WERg
- Linux-Fan 9mo ago> precise time syncing with PTP: https://www.youtube.com/watch?v=dOt-zRIG5co https://www.youtube.com/watch?v=dOt-zRIG5co I am not so much into videos but due to some extended interest in the matter I decided to watch the recording of that talk and I do not regret it. Much recommended to everyone who is interested in the state of the art of precision time synchronization over network. Also, in my opinion this talk is presented masterfully with most of the time actually spent on a convincing live demo. https://media.ccc.de/v/39c3-excuse-me-what-precise-time-is-it https://media.ccc.de/v/39c3-excuse-me-what-precise-time-is-i...
- rs_rs_rs_rs_rs 9mo agoThe one on bsd jails https://media.ccc.de/v/39c3-escaping-containment-a-security-analysis-of-freebsd-jails https://media.ccc.de/v/39c3-escaping-containment-a-security-... The one on whatsapp bugs https://media.ccc.de/v/39c3-dngerouslink-a-deep-dive-into-whatsapp-0-click-exploits-on-ios-and-samsung-devices https://media.ccc.de/v/39c3-dngerouslink-a-deep-dive-into-wh...
- weinzierl 9mo agoSomehow it did not get much attention, but Signal president Meredith Whittaker (together with Udbhav Tiwari) spoke about the risks and threats from AI-enabled systems. AI Agent, AI Spy https://media.ccc.de/v/39c3-ai-agent-ai-spy https://media.ccc.de/v/39c3-ai-agent-ai-spy I also found the talk about Asahi interesting, both from a technical standpoint but also as a nice update what the current status is. Asahi Linux - Porting Linux to Apple Silicon https://media.ccc.de/v/39c3-asahi-linux-porting-linux-to-apple-silicon https://media.ccc.de/v/39c3-asahi-linux-porting-linux-to-app... Finally, not recorded, but workshops like Foundation workshop: Hands-on, how does the Internet work? by Ingo Blechschmidt, is congress at its best. Getting a diverse set of people with various backgrounds and knowledge levels to ARP spoof in a little over an hour is art. https://events.ccc.de/congress/2025/hub/event/detail/foundation-workshop-hands-on-how-does-the-internet https://events.ccc.de/congress/2025/hub/event/detail/foundat...
- aberoham 9mo agoMeredith's talk was extremely scripted, not very original and then she ducked out of taking any audience questions. Udbhav awkwardly stood there but seemed like he could have had much more to say. It was hard to watch. Mona Wang's talk early on Day 2 wasn't recorded but was the polar opposite -- Original, off-the-cuff, engaging, and just fun to witness. https://fahrplan.events.ccc.de/congress/2025/fahrplan/event/protecting-the-network-data-of-one-billion-people-breaking-network-crypto-in-popular-chinese-mobile-apps https://fahrplan.events.ccc.de/congress/2025/fahrplan/event/... https://m0na.net/papers/wirewatch.pdf https://m0na.net/papers/wirewatch.pdf
- weinzierl 9mo agoTo be fair, I believe they answered questions after the talk. At least there was a sizable gathering near the stage.
- Phelinofist 9mo agoThe Asahi talk was good, but the video switched waaaayyyyy too often between slide only -> slide + speaker -> stage -> only speaker. Made me kinda uncomfortable.
- Alconicon 9mo agoI think the blue team ctf ai talk was a good benchmark were we at right now https://media.ccc.de/v/39c3-breaking-bots-cheating-at-blue-team-ctfs-with-ai-speed-runs https://media.ccc.de/v/39c3-breaking-bots-cheating-at-blue-t...
- lmeyerov 9mo agoThank you, and happy to answer questions on that, it's been a crazy time! Maybe of relevance to non-security people here: 1. Most of it is about AI investigating event data in general, not just SOC/IR: cyber, intel, fraud, SRE, and we're even messing with customer 360 & social media data 2. For anyone into vibes coding or building agents, I encourage jumping to the "self-writing AI" section where we're finding we are moving internally from vibes coding -> vibes engineering -> and finally now to eval-driven AI coding loops And, for anyone in security, doing careful evals here has indeed strongly colored my view on the market :)
- tmsbrg 9mo agoHey, I just saw your talk and for someone who's not really up to date with the latest AI developments it's eye opening what you got going in SoC investigations. I personally work as pentester and we're still doing a lot of manual work with AI simply as a better version of Google, but seeing the BOTS presentation I feel we can do better. Do you have any idea if anyone's working on something similar to Louie in pentesting space, or if Louie could work with pentesting workflows?
- lmeyerov 9mo agoCompanies like xbow and horizon are using agents that talk to symbolic tools to automate more red teaming flows for different domains, so very much so. As shown in my talk, modern models are quite capable, and they aren't doing investigation-level scenario depth, more like scans, so seems like becoming the new expectation that everyone can & will do. Companies like trail of bits are more interesting to me here, because they historically do deeper analysis. A place to look there is the darpa cc x ai (?) competition that finished at blackhat last year. If in the US, we may be looking for a pen testing partner on an upcoming agentic AI contract, so feel free to msg - Leo @ graphistry
- Beretta_Vexee 9mo ago"Liberation of the Freebox", A slightly crazy Frenchman embarks on a quest to find exploit and write a complex exploit chain, using PrDoom and the Linux HFS+ driver to gain root privileges on his set-top box. All this in order to unlock the recording of somewhat rubbish TV channels such as TF1 and M6. And he waited almost ten years and the retirement of the hardware to reveal it because he didn't want it to be patched. If you are into hardware emulation "From silicon to Darude sand-storm" is fun. the https://media.ccc.de/v/39c3-from-silicon-to-darude-sand-storm-breaking-famous-synthesizer-dsps https://media.ccc.de/v/39c3-from-silicon-to-darude-sand-stor...
- g-mork 9mo agoJust for sheer geekery's sake probably the ISDN talk. For OMG eye opening factor the FreeBSD jails talk (how the hell is this thing still so buggy?) and the talk on unencrypted satellite links For excellent follow-along value and dedication to ridiculously pointless cause the Freebox talk. "Technically I don't own this box so instead of risking damaging it I'm going to take the extremely long and entertaining route around, somehow involving Doom WAD files" For showmanship probably the Tegra talk
- jacquesm 9mo ago> For OMG eye opening factor the FreeBSD jails talk (how the hell is this thing still so buggy?) Because everything that complex is going to be that buggy. With the bugs they found fix a constant number of them still remains.
- pantalaimon 9mo agoLinus said 'many eyes make all bugs shallow', but compared to Linux, there are not many eyes looking at FreeBSD.
- jacquesm 9mo agoLinus has said a lot of stuff over the years and not all of it was on the money. Still, he did a lot of good and I'm very grateful for it, Linux has been my daily driver for almost two decades now (basically from when I stopped using SGI because there was no point any more). But bugs in large codebases will always be a thing, and even though the eyes looking at FreeBSD are very, very good eyes, indeed there are not enough of them. The more interesting thing here is that they picked a really hard target. If they had done the same with Linux I would expect the number of bugs to be quite a bit higher.
- craftkiller 9mo agoThat "many eyes" theory has failed us many times. For example, OpenSSL's heartbleed or the recent React RCEs.
- weinzierl 9mo agoDemystifying Fuzzer Behaviour https://m.youtube.com/watch?v=h3UcecN5fvQ https://m.youtube.com/watch?v=h3UcecN5fvQ
- xorcist 9mo agoAbsolutely Cory Doctorow's, for the showmanship alone. Lovely background slides. The message itself might not resonate with everyone. The talk "Look Up" about unencrypted data over DVB satellite links was also though provoking, both in presentation and in technical content. If there's that much data unencrypted over a mainstream IP link, imagine how much is still on legacy protocols in 2025.
- nickslaughter02 9mo agoThe Last of Us - Fighting the EU Surveillance Law Apocalypse https://media.ccc.de/v/39c3-the-last-of-us-fighting-the-eu-surveillance-law-apocalypse https://media.ccc.de/v/39c3-the-last-of-us-fighting-the-eu-s...
- sunbum 9mo agohttps://media.ccc.de/v/39c3-css-clicker-training-making-games-in-a-styling-language https://media.ccc.de/v/39c3-css-clicker-training-making-game... The CSS clicker talk was really entertaining as well as just technological amazing!
- jacquesm 9mo agoThat in-house electronics one is gold.
- lskkgklglw 9mo agoThe biggest problem with ccc is that: 0. They are releasing too few tickets. 1. They are releasing the tickets too late. 3. Still not able to pay with card? I live somewhat nearby, but can’t book or plan a visit because of this. I appreciate that they are releasing videos shortly afterwards though.
- neiman 9mo agoYou can pay with a card, but there is an additional 5 Euros fee (which is fair enough). I booked a refundable hotel already in the summer, in case I won't get the tickets. But getting the ticket this year was relatively easy (though maybe I just got lucky).
- deleted 9mo ago[deleted]
- atoav 9mo agoAd too few tickets: I happen to live close by the venue (CCH in Hamburg) they fill up. And they do fill it up. That is the limiting factor. Some person that wanted to get a ticket not getting one is bad, but what is worse is to have more visitors than you or the venue can safely handle. This and of course you still want it to work for the type of event you're doing, with multiple stages, parallel talks, ideally minimum walking distances, not a lot of extra tech to rent in terms of projection, sound etc. To my knowledge the 3C congresses have been a story of growth and having to move to the next-bigger venue throughout the years.
- Beretta_Vexee 9mo agoAt the time when this took place in Berlin, in the Berlin Congress Center, which was rather small, there were only a few hundred seats available, and most of them had already been allocated before they even went on sale. It was also a great excuse to spend New Year's Eve in Berlin.
- cguess 9mo agoThere wasn't even enough assembly space this year, it was bursting at the seams. Sadly I think CCH is just too small for this conference. There's a much bigger conference space space down the street, but the rumor is that going back to Leipzig (where it was held during the renovation of CCH) is back in discussion. That place was too big though.
- rft 9mo agoI still have to go through my watch list, the age old issue of not having my slides done before congress... The 10 year of Dieselgate is interesting just from a "how bad is it really?" PoV, I saw the part about curves and other defeat devices already [1]. The Rowhammer talk is likely going to be great as well, I like Daniel's work [2]. The practical Cross-VM Spectre was interesting to show this is still a problem [3]. The opensource secure element was good for trying such a thing, but I wasn't that impressed with the content [4]. [1] https://cfp.cccv.de/39c3/talk/7MSRA7/ https://cfp.cccv.de/39c3/talk/7MSRA7/ https://media.ccc.de/v/39c3-10-years-of-dieselgate https://media.ccc.de/v/39c3-10-years-of-dieselgate [2] https://cfp.cccv.de/39c3/talk/3JXAJJ/ https://cfp.cccv.de/39c3/talk/3JXAJJ/ https://media.ccc.de/v/39c3-rowhammer-in-the-wild-large-scale-insights-from-flippyr-am https://media.ccc.de/v/39c3-rowhammer-in-the-wild-large-scal... [3] https://cfp.cccv.de/39c3/talk/ATYLN9/ https://cfp.cccv.de/39c3/talk/ATYLN9/ https://media.ccc.de/v/39c3-spectre-in-the-real-world-leaking-your-private-data-from-the-cloud-with-cpu-vulnerabilities https://media.ccc.de/v/39c3-spectre-in-the-real-world-leakin... [4] https://cfp.cccv.de/39c3/talk/9DYZXG/ https://cfp.cccv.de/39c3/talk/9DYZXG/ https://media.ccc.de/v/39c3-lessons-from-building-an-open-architecture-secure-element https://media.ccc.de/v/39c3-lessons-from-building-an-open-ar...
- pseudohadamard 9mo agoThe Deutschlandticket talk was pretty cool. As Malcolm Tucker would say, "what a catastrofuck". Miele washing machine hacking, very nice, I was going to say I'd be waiting to see someone integrate it into HA... and then looked up the Github repo and there's HA integration already there.
- dkga 9mo agoThe WhiteDate talk was pretty cool!