<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>Hack a Day &#187; ccc</title>
	<atom:link href="http://hackaday.com/tag/ccc/feed/" rel="self" type="application/rss+xml" />
	<link>http://hackaday.com</link>
	<description>Fresh hacks every day</description>
	<lastBuildDate>Fri, 10 Feb 2012 09:25:07 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='hackaday.com' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://1.gravatar.com/blavatar/5560f98f805877b0e332f191cb9e0af3?s=96&#038;d=http%3A%2F%2Fs2.wp.com%2Fi%2Fbuttonw-com.png</url>
		<title>Hack a Day &#187; ccc</title>
		<link>http://hackaday.com</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://hackaday.com/osd.xml" title="Hack a Day" />
	<atom:link rel='hub' href='http://hackaday.com/?pushpress=hub'/>
		<item>
		<title>Watch all of the freshly published talks from 28c3</title>
		<link>http://hackaday.com/2012/01/02/watch-all-of-the-freshly-published-talks-from-28c3/</link>
		<comments>http://hackaday.com/2012/01/02/watch-all-of-the-freshly-published-talks-from-28c3/#comments</comments>
		<pubDate>Mon, 02 Jan 2012 20:00:37 +0000</pubDate>
		<dc:creator>Mike Szczys</dc:creator>
				<category><![CDATA[cons]]></category>
		<category><![CDATA[28c3]]></category>
		<category><![CDATA[ccc]]></category>
		<category><![CDATA[chaos communication congress]]></category>
		<category><![CDATA[Mitch Altman]]></category>

		<guid isPermaLink="false">http://hackaday.com/?p=64597</guid>
		<description><![CDATA[The 28th Annual Chaos Communications Congress just wrapped things up on December 31st and they&#8217;ve already published recordings of all the talks at the event. These talks were live-streamed, but if you didn&#8217;t find time in your schedule to see all that you wanted, you&#8217;ll be happy to find your way to the YouTube collection [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=64597&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignnone size-full wp-image-64598" title="2011-28c3-talk-videos" src="http://hackadaycom.files.wordpress.com/2012/01/2011-28c3-talk-videos.png" alt="" width="470" height="240" /></p>
<p>The 28th Annual Chaos Communications Congress just wrapped things up on December 31st and <a href="http://events.ccc.de/2011/12/31/recordings-of-29c3-talks-available/">they&#8217;ve already published recordings of all the talks</a> at the event. These talks were live-streamed, but if you didn&#8217;t find time in your schedule to see all that you wanted, you&#8217;ll be happy to find your way to <a href="http://www.youtube.com/user/28c3">the YouTube collection of the event</a>.</p>
<p>The topics span a surprising range. We were surprised to see a panel discussion on depression and suicide among geeks (hosted by [Mitch Altman]) which joins another panel called Queer Geeks, to address some social issues rather than just hardcore security tech. But there&#8217;s plenty of that as well with topics on cryptography, security within web applications, and also a segment on electronic currencies like Bitcoins.</p>
<p>There really is something for everyone and they&#8217;ve been thoughtful enough to include playlists for all talks, just the lightning talks, and lightning talks categorized by the day they occurred. Get those links from their YouTube channel description, or find them after the break.</p>
<p><span id="more-64597"></span></p>
<p>28c3 Playlist Links:</p>
<ul>
<li><a href="http://www.youtube.com/redirect?q=http%3A%2F%2Fbit.ly%2Furj0dk&amp;session_token=--ce8AqfpCYUkaYoTgBbMLbCDlt8MTMyNTYxMzcwNUAxMzI1NTI3MzA1">All Talks</a></li>
<li><a href="http://bit.ly/uuJOFM">Lightning Talks (all)</a></li>
<li><a href="http://bit.ly/rrX9MG">Lightning Talks Day 2</a></li>
<li><a href="http://bit.ly/tqnP7L">Lightning Talks Day 3</a></li>
<li><a href="http://bit.ly/toK1vC">Lightning Talks Day 4</a></li>
</ul>
<br />Filed under: <a href='http://hackaday.com/category/cons/'>cons</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackadaycom.wordpress.com/64597/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackadaycom.wordpress.com/64597/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackadaycom.wordpress.com/64597/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackadaycom.wordpress.com/64597/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackadaycom.wordpress.com/64597/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackadaycom.wordpress.com/64597/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackadaycom.wordpress.com/64597/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackadaycom.wordpress.com/64597/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackadaycom.wordpress.com/64597/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackadaycom.wordpress.com/64597/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackadaycom.wordpress.com/64597/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackadaycom.wordpress.com/64597/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackadaycom.wordpress.com/64597/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackadaycom.wordpress.com/64597/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=64597&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackaday.com/2012/01/02/watch-all-of-the-freshly-published-talks-from-28c3/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Mike Szczys</media:title>
		</media:content>

		<media:content url="http://hackadaycom.files.wordpress.com/2012/01/2011-28c3-talk-videos.png" medium="image">
			<media:title type="html">2011-28c3-talk-videos</media:title>
		</media:content>
	</item>
		<item>
		<title>GSM hacking with prepaid phones</title>
		<link>http://hackaday.com/2010/12/30/gsm-hacking-with-prepaid-phones/</link>
		<comments>http://hackaday.com/2010/12/30/gsm-hacking-with-prepaid-phones/#comments</comments>
		<pubDate>Thu, 30 Dec 2010 21:00:28 +0000</pubDate>
		<dc:creator>Mike Szczys</dc:creator>
				<category><![CDATA[cellphones hacks]]></category>
		<category><![CDATA[cons]]></category>
		<category><![CDATA[security hacks]]></category>
		<category><![CDATA[ccc]]></category>
		<category><![CDATA[gsm]]></category>
		<category><![CDATA[rainbow table]]></category>

		<guid isPermaLink="false">http://hackaday.com/?p=32242</guid>
		<description><![CDATA[Want to listen in on cellphone calls or intercept test messages? Well that&#8217;s a violation of someone else&#8217;s privacy so shame on you! But there are black-hats who want to do just that and it may not be quite as difficult as you think. This article sums up a method of using prepaid cellphones and [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=32242&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignnone size-full wp-image-32243" title="gsm-hacking" src="http://hackadaycom.files.wordpress.com/2010/12/gsm-hacking.jpg" alt="" width="470" height="270" /></p>
<p>Want to listen in on cellphone calls or intercept test messages? Well that&#8217;s a violation of someone else&#8217;s privacy so shame on you! But there are black-hats who want to do just that and it may not be quite as difficult as you think. <a href="http://arstechnica.com/gadgets/news/2010/12/15-phone-3-minutes-all-thats-needed-to-eavesdrop-on-gsm-call.ars">This article sums up a method</a> of using prepaid cellphones and some decryption technology to quickly gain access to all the communications on a cellular handset. Slides for the talk given at the Chaos Communications Congress by [Karsten Nohl] and [Sylvain Munaut] are <a href="http://events.ccc.de/congress/2010/Fahrplan/events/4208.en.html">available now</a>, but here&#8217;s the gist. They reflashed some cheap phones with custom firmware to gain access to all of the data coming over the network. By sending carefully crafted ghost messages the target user doesn&#8217;t get notified that a text has been received, but the phone is indeed communicating with the network. That traffic is used to sniff out a general location and eventually to grab the session key. That key can be used to siphon off all network communications and then decrypt them quickly by using a 1 TB rainbow table. Not an easy process, but it&#8217;s a much simpler method than we would have suspected.</p>
<p>[Thanks Rob]</p>
<br />Filed under: <a href='http://hackaday.com/category/cellphones-hacks/'>cellphones hacks</a>, <a href='http://hackaday.com/category/cons/'>cons</a>, <a href='http://hackaday.com/category/security-hacks/'>security hacks</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackadaycom.wordpress.com/32242/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackadaycom.wordpress.com/32242/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackadaycom.wordpress.com/32242/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackadaycom.wordpress.com/32242/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackadaycom.wordpress.com/32242/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackadaycom.wordpress.com/32242/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackadaycom.wordpress.com/32242/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackadaycom.wordpress.com/32242/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackadaycom.wordpress.com/32242/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackadaycom.wordpress.com/32242/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackadaycom.wordpress.com/32242/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackadaycom.wordpress.com/32242/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackadaycom.wordpress.com/32242/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackadaycom.wordpress.com/32242/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=32242&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackaday.com/2010/12/30/gsm-hacking-with-prepaid-phones/feed/</wfw:commentRss>
		<slash:comments>30</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Mike Szczys</media:title>
		</media:content>

		<media:content url="http://hackadaycom.files.wordpress.com/2010/12/gsm-hacking.jpg" medium="image">
			<media:title type="html">gsm-hacking</media:title>
		</media:content>
	</item>
		<item>
		<title>PS3 hacking start-to-finish &#8211; CCC</title>
		<link>http://hackaday.com/2010/12/30/ps3-hacking-start-to-finish-ccc/</link>
		<comments>http://hackaday.com/2010/12/30/ps3-hacking-start-to-finish-ccc/#comments</comments>
		<pubDate>Thu, 30 Dec 2010 19:30:49 +0000</pubDate>
		<dc:creator>Mike Szczys</dc:creator>
				<category><![CDATA[cons]]></category>
		<category><![CDATA[playstation hacks]]></category>
		<category><![CDATA[security hacks]]></category>
		<category><![CDATA[ccc]]></category>
		<category><![CDATA[key]]></category>
		<category><![CDATA[otheros]]></category>
		<category><![CDATA[ps3]]></category>
		<category><![CDATA[sony]]></category>

		<guid isPermaLink="false">http://hackaday.com/?p=32258</guid>
		<description><![CDATA[Well it looks like the Play Station 3 is finally and definitively cracked. FailOverflow&#8217;s Chaos Communications Congress talk on console security revealed that, thanks to a flaw on Sony&#8217;s part, they were able to acquire the private keys for the PS3. These keys can be used to sign your own code, making it every bit [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=32258&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignnone size-full wp-image-32260" title="sony-ps3-security-cracked" src="http://hackadaycom.files.wordpress.com/2010/12/sony-ps3-security-cracked.jpg" alt="" width="470" height="347" /></p>
<p>Well it looks like the <a href="http://psgroove.com/content.php?581-Sony-s-PS3-Security-is-Epic-Fail-Videos-Within">Play Station 3 is finally and definitively cracked</a>. FailOverflow&#8217;s Chaos Communications Congress talk on console security revealed that, thanks to a flaw on Sony&#8217;s part, they were able to acquire the private keys for the PS3. These keys can be used to sign your own code, making it every bit as valid (to the machine anyway) as a disk licensed by the media giant. We&#8217;ve embedded the three-part video of the talk, which we watched in its entirety with delight. We especially enjoy their reasoning that <a href="http://hackaday.com/2010/04/29/sony-removes-ps3-linux-support-gets-sued-for-it/">Sony brought this upon themselves by pulling OtherOS support</a>.</p>
<p>We remember seeing a talk years back about how the original Xbox security was hacked. We looked and looked but couldn&#8217;t dig up the link. If you know what we&#8217;re talking about, leave the goods with your comment.</p>
<p><span id="more-32258"></span><span style="text-align:center; display: block;"><a href="http://hackaday.com/2010/12/30/ps3-hacking-start-to-finish-ccc/"><img src="http://img.youtube.com/vi/HEFMAP0mTvY/2.jpg" alt="" /></a></span></p>
<span style="text-align:center; display: block;"><a href="http://hackaday.com/2010/12/30/ps3-hacking-start-to-finish-ccc/"><img src="http://img.youtube.com/vi/X8ohOy8_XO4/2.jpg" alt="" /></a></span>
<span style="text-align:center; display: block;"><a href="http://hackaday.com/2010/12/30/ps3-hacking-start-to-finish-ccc/"><img src="http://img.youtube.com/vi/Eag0VyRTld8/2.jpg" alt="" /></a></span>
<p>[Thanks BoBeR182 via <a href="http://www.theregister.co.uk/2010/12/30/ps3_jailbreak_hack/">The Register</a>]</p>
<br />Filed under: <a href='http://hackaday.com/category/cons/'>cons</a>, <a href='http://hackaday.com/category/playstation-hacks/'>playstation hacks</a>, <a href='http://hackaday.com/category/security-hacks/'>security hacks</a>  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackadaycom.wordpress.com/32258/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackadaycom.wordpress.com/32258/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackadaycom.wordpress.com/32258/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackadaycom.wordpress.com/32258/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackadaycom.wordpress.com/32258/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackadaycom.wordpress.com/32258/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackadaycom.wordpress.com/32258/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackadaycom.wordpress.com/32258/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackadaycom.wordpress.com/32258/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackadaycom.wordpress.com/32258/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackadaycom.wordpress.com/32258/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackadaycom.wordpress.com/32258/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackadaycom.wordpress.com/32258/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackadaycom.wordpress.com/32258/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=32258&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackaday.com/2010/12/30/ps3-hacking-start-to-finish-ccc/feed/</wfw:commentRss>
		<slash:comments>93</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Mike Szczys</media:title>
		</media:content>

		<media:content url="http://hackadaycom.files.wordpress.com/2010/12/sony-ps3-security-cracked.jpg" medium="image">
			<media:title type="html">sony-ps3-security-cracked</media:title>
		</media:content>
	</item>
		<item>
		<title>Lightning Rod: keeps you safe from dirty Flashers</title>
		<link>http://hackaday.com/2010/01/01/lighting-rod-keeps-you-safe-from-dirty-flashers/</link>
		<comments>http://hackaday.com/2010/01/01/lighting-rod-keeps-you-safe-from-dirty-flashers/#comments</comments>
		<pubDate>Fri, 01 Jan 2010 20:00:13 +0000</pubDate>
		<dc:creator>Mike Szczys</dc:creator>
				<category><![CDATA[security hacks]]></category>
		<category><![CDATA[26c3]]></category>
		<category><![CDATA[adobe]]></category>
		<category><![CDATA[ccc]]></category>
		<category><![CDATA[chaos communications congress]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[flash]]></category>
		<category><![CDATA[lightning rod]]></category>
		<category><![CDATA[vulnerability]]></category>

		<guid isPermaLink="false">http://hackaday.com/?p=20152</guid>
		<description><![CDATA[A new open source package called Lightning Rod will help to close security exploits in Adobe&#8217;s dirty Flash code. A presentation made at the 26th Chaos Communication Congress showed that the package does its job by reviewing incoming code before the browser executes it. Heise Online is reporting that this method can block over 20 [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=20152&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignnone size-full wp-image-20155" title="flash-code-protection" src="http://hackadaycom.files.wordpress.com/2010/01/flash-code-protection1.jpg" alt="" width="470" height="313" /></p>
<p>A new <a href="http://translate.googleusercontent.com/translate_c?hl=en&amp;ie=UTF-8&amp;sl=de&amp;tl=en&amp;u=http://blitzableiter.recurity.com/&amp;prev=_t&amp;rurl=translate.google.com&amp;twu=1&amp;usg=ALkJrhh5zwOnDLBaBo0ceaZm16eP0mgabw">open source package called Lightning Rod</a> will help to close security exploits in Adobe&#8217;s dirty Flash code. A presentation made at the <a href="http://events.ccc.de/congress/2009/wiki/Welcome">26th Chaos Communication Congress</a> showed that the package does its job by reviewing incoming code before the browser executes it. <a href="http://translate.google.com/translate?js=y&amp;prev=_t&amp;hl=en&amp;ie=UTF-8&amp;layout=1&amp;eotf=1&amp;u=http%3A%2F%2Fwww.heise.de%2Fnewsticker%2Fmeldung%2F26C3-Schutz-gegen-Flash-Sicherheitsluecken-893588.html&amp;sl=de&amp;tl=en">Heise Online is reporting</a> that this method can block over 20 different known attacks and can even be used to filter out <a href="http://news.zdnet.com/2100-1009_22-138733.html">malicious JPG</a> attacks. As more vulnerabilities are discovered they can be added to Lightning Rod to close the breach. This amounts to a virus scanner for Flash code. It&#8217;s great to have this type of protection but why can&#8217;t Adobe handle its security problems?</p>
<p>[<a href="http://thebsreport.wordpress.com/2009/11/14/flasher-causes-bus-to-hit-police-station/">Photo Credit</a>]</p>
<p>[Thanks das_coach]</p>
<br />Posted in security hacks  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackadaycom.wordpress.com/20152/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackadaycom.wordpress.com/20152/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackadaycom.wordpress.com/20152/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackadaycom.wordpress.com/20152/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackadaycom.wordpress.com/20152/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackadaycom.wordpress.com/20152/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackadaycom.wordpress.com/20152/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackadaycom.wordpress.com/20152/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackadaycom.wordpress.com/20152/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackadaycom.wordpress.com/20152/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackadaycom.wordpress.com/20152/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackadaycom.wordpress.com/20152/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackadaycom.wordpress.com/20152/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackadaycom.wordpress.com/20152/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=20152&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackaday.com/2010/01/01/lighting-rod-keeps-you-safe-from-dirty-flashers/feed/</wfw:commentRss>
		<slash:comments>9</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">Mike Szczys</media:title>
		</media:content>

		<media:content url="http://hackadaycom.files.wordpress.com/2010/01/flash-code-protection1.jpg" medium="image">
			<media:title type="html">flash-code-protection</media:title>
		</media:content>
	</item>
		<item>
		<title>ToorCamp 2009 to be held at missile silo</title>
		<link>http://hackaday.com/2009/02/03/toorcamp-2009-held-at-missile-silo/</link>
		<comments>http://hackaday.com/2009/02/03/toorcamp-2009-held-at-missile-silo/#comments</comments>
		<pubDate>Wed, 04 Feb 2009 01:22:18 +0000</pubDate>
		<dc:creator>Eliot</dc:creator>
				<category><![CDATA[cons]]></category>
		<category><![CDATA[news]]></category>
		<category><![CDATA[ccc]]></category>
		<category><![CDATA[cccamp]]></category>
		<category><![CDATA[cccamp2007]]></category>
		<category><![CDATA[har]]></category>
		<category><![CDATA[har2009]]></category>
		<category><![CDATA[missile]]></category>
		<category><![CDATA[missile silo]]></category>
		<category><![CDATA[silo]]></category>
		<category><![CDATA[titan 1]]></category>
		<category><![CDATA[titan i]]></category>
		<category><![CDATA[titan1]]></category>
		<category><![CDATA[toorcamp]]></category>
		<category><![CDATA[toorcon]]></category>
		<category><![CDATA[washington]]></category>
		<category><![CDATA[wth]]></category>
		<category><![CDATA[wth2005]]></category>

		<guid isPermaLink="false">http://hackaday.com/?p=8322</guid>
		<description><![CDATA[After running a successful hacker convention for ten solid years, the people who brought you ToorCon are planning a new event to shake up the US hacker scene. ToorCamp will be held July 2nd-5th, 2009 at a former missile silo in central Washington state. Hackers will camp on-site for two days of talks followed by [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=8322&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignnone size-full wp-image-8323" title="toorcamp" src="http://hackadaycom.files.wordpress.com/2009/02/toorcamp.jpg" alt="toorcamp" width="450" height="243" /></p>
<p>After running a successful hacker convention for ten solid years, the people who brought you <a title="Hack a Day" href="http://hackaday.com/?s=toorcon">ToorCon</a> are planning a new event to shake up the US hacker scene. <a title="ToorCamp" href="http://www.toorcamp.org/">ToorCamp</a> will be held July 2nd-5th, 2009 at a former missile silo in central Washington state. Hackers will camp on-site for two days of talks followed by two days of workshops. Art and music events are planned for every night. Camps like this are already help biannually in Europe: <a title="Some post-conference highlights  - Hack a Day" href="http://hackaday.com/2005/08/26/what-the-hack-some-post-conference-highlights/">What the Hack in 2005</a>, <a title="Chaos Communication Camp 2007 - Welcome" href="http://events.ccc.de/camp/2007/Intro/">Chaos Communication Camp 2007</a>, and <a href="https://har2009.org/">Hacking at Random 2009</a>, coming this fall. The complex is one of three <a title="Titan I - Wikipedia, the free encyclopedia" href="http://en.wikipedia.org/wiki/Titan_I">Titan 1</a> missile complexes in the Moses Lake area. The sites were in operation <a title="Titan I Missile Site Coordinates" href="http://asuwlink.uwyo.edu/~jimkirk/titan1.html">less than three years</a> between 1962 and 1965. The former missile command center has been converted to a <a title="Titan Ultra Secure Data Center" href="http://www.titanone.com/intro.html">secure data center run by Titan I, LLC</a>. ToorCamp promises to be a very unique experience and we&#8217;re looking forward to attend this and future years.</p>
<br />Posted in cons, news  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackadaycom.wordpress.com/8322/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackadaycom.wordpress.com/8322/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackadaycom.wordpress.com/8322/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackadaycom.wordpress.com/8322/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackadaycom.wordpress.com/8322/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackadaycom.wordpress.com/8322/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackadaycom.wordpress.com/8322/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackadaycom.wordpress.com/8322/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackadaycom.wordpress.com/8322/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackadaycom.wordpress.com/8322/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackadaycom.wordpress.com/8322/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackadaycom.wordpress.com/8322/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackadaycom.wordpress.com/8322/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackadaycom.wordpress.com/8322/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=8322&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackaday.com/2009/02/03/toorcamp-2009-held-at-missile-silo/feed/</wfw:commentRss>
		<slash:comments>12</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">RobotSkirts</media:title>
		</media:content>

		<media:content url="http://hackadaycom.files.wordpress.com/2009/02/toorcamp.jpg" medium="image">
			<media:title type="html">toorcamp</media:title>
		</media:content>
	</item>
		<item>
		<title>Dismantling the Storm Worm botnet</title>
		<link>http://hackaday.com/2009/01/16/dismantling-the-storm-worm-botnet/</link>
		<comments>http://hackaday.com/2009/01/16/dismantling-the-storm-worm-botnet/#comments</comments>
		<pubDate>Sat, 17 Jan 2009 04:30:16 +0000</pubDate>
		<dc:creator>Eliot</dc:creator>
				<category><![CDATA[news]]></category>
		<category><![CDATA[security hacks]]></category>
		<category><![CDATA[25c3]]></category>
		<category><![CDATA[botnet]]></category>
		<category><![CDATA[ccc]]></category>
		<category><![CDATA[german]]></category>
		<category><![CDATA[isp]]></category>
		<category><![CDATA[malware]]></category>
		<category><![CDATA[nat]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[storm worm]]></category>
		<category><![CDATA[stormfucker]]></category>
		<category><![CDATA[xor]]></category>
		<category><![CDATA[zero-day]]></category>

		<guid isPermaLink="false">http://hackaday.com/?p=7931</guid>
		<description><![CDATA[Zero Day has an interview with German researchers who have found a way to take down the Storm Worm botnet. Their program, Stormfucker, takes advantage of flaws in Storm&#8217;s command network: Nodes that are NAT&#8216;d only use a four-byte XOR challenge. Nodes that aren&#8217;t NAT&#8217;d are only using a trivial 64bit RSA signature. Their solution [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=7931&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignnone size-full wp-image-7486" title="malware" src="http://hackadaycom.files.wordpress.com/2009/01/malware.jpg" alt="malware" width="450" height="132" /></p>
<p>Zero Day has an interview with German researchers who have found a way to <a title="Zero Day mobile edition" href="http://blogs.zdnet.com/security/?p=2396">take down the Storm Worm botnet</a>. Their program, <a title="Owning the Storm Botnet" href="http://events.ccc.de/congress/2008/Fahrplan/events/3000.en.html">Stormfucker</a>, takes advantage of flaws in Storm&#8217;s command network: Nodes that are <a href="http://en.wikipedia.org/wiki/Network_address_translation">NAT</a>&#8216;d only use a four-byte <a href="http://en.wikipedia.org/wiki/XOR_gate">XOR</a> challenge. Nodes that aren&#8217;t NAT&#8217;d are only using a trivial 64bit RSA signature. Their solution can clean infected machines and also distribute to other nodes. Unfortunately, installing software without the user&#8217;s consent is the exact same behavior as malware. Don&#8217;t expect to see this in any sort of widespread use. The researchers did point out that some ISPs have moved to shutting off service for infected customers until their machines are cleaned.</p>
<br />Posted in news, security hacks  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackadaycom.wordpress.com/7931/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackadaycom.wordpress.com/7931/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackadaycom.wordpress.com/7931/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackadaycom.wordpress.com/7931/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackadaycom.wordpress.com/7931/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackadaycom.wordpress.com/7931/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackadaycom.wordpress.com/7931/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackadaycom.wordpress.com/7931/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackadaycom.wordpress.com/7931/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackadaycom.wordpress.com/7931/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackadaycom.wordpress.com/7931/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackadaycom.wordpress.com/7931/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackadaycom.wordpress.com/7931/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackadaycom.wordpress.com/7931/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=7931&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackaday.com/2009/01/16/dismantling-the-storm-worm-botnet/feed/</wfw:commentRss>
		<slash:comments>23</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">RobotSkirts</media:title>
		</media:content>

		<media:content url="http://hackadaycom.files.wordpress.com/2009/01/malware.jpg" medium="image">
			<media:title type="html">malware</media:title>
		</media:content>
	</item>
		<item>
		<title>25C3: Nokia exploit stops all inbound SMS</title>
		<link>http://hackaday.com/2008/12/30/25c3-nokia-exploit-stops-all-inbound-sms/</link>
		<comments>http://hackaday.com/2008/12/30/25c3-nokia-exploit-stops-all-inbound-sms/#comments</comments>
		<pubDate>Tue, 30 Dec 2008 18:51:32 +0000</pubDate>
		<dc:creator>Eliot</dc:creator>
				<category><![CDATA[cellphones hacks]]></category>
		<category><![CDATA[news]]></category>
		<category><![CDATA[security hacks]]></category>
		<category><![CDATA[25c3]]></category>
		<category><![CDATA[ccc]]></category>
		<category><![CDATA[fh]]></category>
		<category><![CDATA[nokia]]></category>
		<category><![CDATA[s60]]></category>
		<category><![CDATA[symbian]]></category>
		<category><![CDATA[tobias engel]]></category>

		<guid isPermaLink="false">http://hackaday.com/?p=7372</guid>
		<description><![CDATA[[Tobias Engel] released a serious Nokia vulnerability today. By using a specially crafted SMS message, you can block the recipient from getting any future SMS messages. The attacker changes their Protocol Identifier to &#8220;Internet Electronic Mail&#8221; and then uses any email address 32 characters or more in their message. The recipient will receive no indication [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=7372&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignnone size-full wp-image-7373" title="nokia" src="http://hackadaycom.files.wordpress.com/2008/12/nokia.jpg" alt="nokia" width="450" height="243" /></p>
<p>[Tobias Engel] released a <a href="http://berlin.ccc.de/~tobias/cos/s60-curse-of-silence-advisory.txt">serious Nokia vulnerability today</a>. By using a specially crafted SMS message, you can block the recipient from getting any future SMS messages. The attacker changes their Protocol Identifier to &#8220;Internet Electronic Mail&#8221; and then uses any email address 32 characters or more in their message. The recipient will receive no indication that they got the message and no other messages will be allowed until the phone is factory reset. <a href="http://berlin.ccc.de/~tobias/cos/">You can see a demo video here</a>. This affects many different varieties of S60 phones and no fix is known.</p>
<p>[Thanks fh]</p>
<br />Posted in cellphones hacks, news, security hacks  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackadaycom.wordpress.com/7372/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackadaycom.wordpress.com/7372/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackadaycom.wordpress.com/7372/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackadaycom.wordpress.com/7372/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackadaycom.wordpress.com/7372/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackadaycom.wordpress.com/7372/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackadaycom.wordpress.com/7372/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackadaycom.wordpress.com/7372/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackadaycom.wordpress.com/7372/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackadaycom.wordpress.com/7372/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackadaycom.wordpress.com/7372/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackadaycom.wordpress.com/7372/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackadaycom.wordpress.com/7372/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackadaycom.wordpress.com/7372/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=7372&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackaday.com/2008/12/30/25c3-nokia-exploit-stops-all-inbound-sms/feed/</wfw:commentRss>
		<slash:comments>21</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">RobotSkirts</media:title>
		</media:content>

		<media:content url="http://hackadaycom.files.wordpress.com/2008/12/nokia.jpg" medium="image">
			<media:title type="html">nokia</media:title>
		</media:content>
	</item>
		<item>
		<title>25C3: Hackers completely break SSL using 200 PS3s</title>
		<link>http://hackaday.com/2008/12/30/25c3-hackers-completely-break-ssl-using-200-ps3s/</link>
		<comments>http://hackaday.com/2008/12/30/25c3-hackers-completely-break-ssl-using-200-ps3s/#comments</comments>
		<pubDate>Tue, 30 Dec 2008 17:40:41 +0000</pubDate>
		<dc:creator>Eliot</dc:creator>
				<category><![CDATA[cons]]></category>
		<category><![CDATA[security hacks]]></category>
		<category><![CDATA[25c3]]></category>
		<category><![CDATA[alex soritov]]></category>
		<category><![CDATA[berlin]]></category>
		<category><![CDATA[CA]]></category>
		<category><![CDATA[ccc]]></category>
		<category><![CDATA[certificate authority]]></category>
		<category><![CDATA[collision]]></category>
		<category><![CDATA[hacker]]></category>
		<category><![CDATA[hacker conference]]></category>
		<category><![CDATA[hype]]></category>
		<category><![CDATA[jake apelbaum]]></category>
		<category><![CDATA[md5]]></category>
		<category><![CDATA[playstation]]></category>
		<category><![CDATA[playstation 3]]></category>
		<category><![CDATA[rapidssl]]></category>
		<category><![CDATA[sha]]></category>
		<category><![CDATA[sha-1]]></category>

		<guid isPermaLink="false">http://hackaday.com/?p=7367</guid>
		<description><![CDATA[A team of security researchers and academics has broken a core piece of internet technology. They made their work public at the 25th Chaos Communication Congress in Berlin today. The team was able to create a rogue certificate authority and use it to issue valid SSL certificates for any site they want. The user would [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=7367&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p style="text-align:center;"><img class="size-full wp-image-7368 aligncenter" title="ps31" src="http://hackadaycom.files.wordpress.com/2008/12/ps31.jpg" alt="ps31" width="300" height="400" /></p>
<p>A team of security researchers and academics has broken a core piece of internet technology. They made their work public at the <a title="25c3  - Hack a Day" href="http://hackaday.com/tag/25c3">25th Chaos Communication Congress</a> in Berlin today. The team was able to create a <a title="Creating a rogue CA certificate" href="http://phreedom.org/research/rogue-ca/">rogue certificate authority and use it to issue valid SSL certificates</a> for any site they want. The user would have no indication that their HTTPS connection was being monitored/modified.</p>
<p><span id="more-7367"></span></p>
<p>This attack is possible because of a flaw in MD5. MD5 is a hashing algorithm; each unique file has a unique hash. In 2004, a team of Chinese researchers demonstrated creating two different files that had the same MD5 hash. In 2007, another team showed theoretical attacks that took advantage of these collisions. The team focused on SSL certificates signed with MD5 for their exploit.</p>
<p>The first step was doing some broad scans to see what <a title="Certificate authority - Wikipedia, the free encyclopedia" href="http://en.wikipedia.org/wiki/Certificate_Authority">certificate authorities</a> (CA) were issuing MD5 signed certs. They collected 30K certs from Firefox trusted CAs. 9K of them were MD5 signed. 97% of those came from <a title="SSL Certificate Free SSL Certificates RapidSSL Certificate Authority" href="http://www.rapidssl.com/">RapidSSL</a>.</p>
<p>Having selected their target, the team needed to generate their rogue certificate to transfer the signature to. They employed the processing power of 200 Playstation 3s to get the job done. For this task, it&#8217;s the equivalent of 8000 standard CPU cores or $20K of Amazon EC2 time. The task takes ~1-2 days to calculate. The tricky part was knowing the content of the certificate that would be issued by RapidSSL. They needed to predict two variables: the serial number and the timestamp. RapidSSL&#8217;s serial numbers were all sequential. From testing, they knew that RapidSSL would always sign six seconds after the order was acknowledged. Knowing these two facts they were able to generate a certificate in advance and then purchase the exact certificate they wanted. They&#8217;d purchase certificates to advance the serial number and then buy on the exact time they calculated.</p>
<p>The cert was issued to their particular domain, but since they controlled the content, they changed the flags to make themselves an intermediate certificate authority. That gave them authority to issue any certificate they wanted. All of these &#8216;valid&#8217; certs were signed using SHA-1.</p>
<p>If you set your clock back to before August 2004, you can <a href="http://i.broke.the.internet.and.all.i.got.was.this.t-shirt.phreedom.org/">try out their live demo site</a>. This time is just a security measure for the example and this would work identically with a certificate that hasn&#8217;t expired. There&#8217;s a <a title="Creating a rogue CA certificate" href="http://phreedom.org/research/rogue-ca/">project site</a> and a much <a title="MD5 considered harmful today" href="http://www.win.tue.nl/hashclash/rogue-ca/">more detailed writeup than this</a>.</p>
<p>To fix this vulnerability, all CAs are now using SHA-1 for signing and Microsoft and Firefox will be blacklisting the team&#8217;s rogue CA in their browser products.</p>
<br />Posted in cons, security hacks  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackadaycom.wordpress.com/7367/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackadaycom.wordpress.com/7367/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackadaycom.wordpress.com/7367/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackadaycom.wordpress.com/7367/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackadaycom.wordpress.com/7367/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackadaycom.wordpress.com/7367/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackadaycom.wordpress.com/7367/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackadaycom.wordpress.com/7367/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackadaycom.wordpress.com/7367/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackadaycom.wordpress.com/7367/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackadaycom.wordpress.com/7367/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackadaycom.wordpress.com/7367/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackadaycom.wordpress.com/7367/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackadaycom.wordpress.com/7367/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=7367&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackaday.com/2008/12/30/25c3-hackers-completely-break-ssl-using-200-ps3s/feed/</wfw:commentRss>
		<slash:comments>76</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">RobotSkirts</media:title>
		</media:content>

		<media:content url="http://hackadaycom.files.wordpress.com/2008/12/ps31.jpg" medium="image">
			<media:title type="html">ps31</media:title>
		</media:content>
	</item>
		<item>
		<title>25C3: CTF dominated by iphone-dev team, HackMii</title>
		<link>http://hackaday.com/2008/12/30/25c3-ctf-dominated-by-iphone-dev-team-hackmii/</link>
		<comments>http://hackaday.com/2008/12/30/25c3-ctf-dominated-by-iphone-dev-team-hackmii/#comments</comments>
		<pubDate>Tue, 30 Dec 2008 14:00:54 +0000</pubDate>
		<dc:creator>Eliot</dc:creator>
				<category><![CDATA[cellphones hacks]]></category>
		<category><![CDATA[cons]]></category>
		<category><![CDATA[iphone hacks]]></category>
		<category><![CDATA[nintendo hacks]]></category>
		<category><![CDATA[security hacks]]></category>
		<category><![CDATA[wii hacks]]></category>
		<category><![CDATA[25c3]]></category>
		<category><![CDATA[ccc]]></category>
		<category><![CDATA[ctf]]></category>
		<category><![CDATA[hackmii]]></category>
		<category><![CDATA[iphone]]></category>
		<category><![CDATA[iphone dev team]]></category>
		<category><![CDATA[nintendo]]></category>
		<category><![CDATA[nintendo wii]]></category>
		<category><![CDATA[wii]]></category>

		<guid isPermaLink="false">http://hackaday.com/?p=7352</guid>
		<description><![CDATA[While we had been excited about 25C3&#8242;s CTF competition, we couldn&#8217;t even venture a guess as to who would win. It seems the iphone-dev team weren&#8217;t satisfied to just give an amazing talk. They teamed up with the Wii hackers from HackMii to win the competition. You can see their progress during the eight hour [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=7352&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignnone size-full wp-image-7353" title="25c3ctf" src="http://hackadaycom.files.wordpress.com/2008/12/25c3ctf.jpg" alt="25c3ctf" width="450" height="337" /></p>
<p>While we had been excited about <a title="25C3 international Capture the Flag  - Hack a Day" href="http://hackaday.com/2008/12/23/25c3-international-capture-the-flag/">25C3&#8242;s CTF competition</a>, we couldn&#8217;t even venture a guess as to who would win. It seems the <a title="Dev-Team Blog" href="http://blog.iphone-dev.org/">iphone-dev</a> team weren&#8217;t satisfied to just give <a title="Hacking the iPhone  - Hack a Day" href="http://hackaday.com/2008/12/28/25c3-hacking-the-iphone/">an amazing talk</a>. They teamed up with the Wii hackers from <a title="HackMii — Notes from inside your Wii" href="http://hackmii.com/">HackMii</a> to <a title="Dev-Team Blog - CTF fun at 25C3" href="http://blog.iphone-dev.org/post/67400821/ctf-fun-at-25c3">win the competition</a>. You can see their progress during the eight hour competition above in red. It&#8217;s impressive to see hardware hackers jumping over to network security AND completely killing at it.</p>
<br />Posted in cellphones hacks, cons, iphone hacks, nintendo hacks, security hacks, wii hacks  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackadaycom.wordpress.com/7352/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackadaycom.wordpress.com/7352/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackadaycom.wordpress.com/7352/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackadaycom.wordpress.com/7352/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackadaycom.wordpress.com/7352/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackadaycom.wordpress.com/7352/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackadaycom.wordpress.com/7352/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackadaycom.wordpress.com/7352/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackadaycom.wordpress.com/7352/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackadaycom.wordpress.com/7352/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackadaycom.wordpress.com/7352/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackadaycom.wordpress.com/7352/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackadaycom.wordpress.com/7352/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackadaycom.wordpress.com/7352/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=7352&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackaday.com/2008/12/30/25c3-ctf-dominated-by-iphone-dev-team-hackmii/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">RobotSkirts</media:title>
		</media:content>

		<media:content url="http://hackadaycom.files.wordpress.com/2008/12/25c3ctf.jpg" medium="image">
			<media:title type="html">25c3ctf</media:title>
		</media:content>
	</item>
		<item>
		<title>25C3: Hacking the iPhone</title>
		<link>http://hackaday.com/2008/12/28/25c3-hacking-the-iphone/</link>
		<comments>http://hackaday.com/2008/12/28/25c3-hacking-the-iphone/#comments</comments>
		<pubDate>Sun, 28 Dec 2008 21:59:38 +0000</pubDate>
		<dc:creator>Eliot</dc:creator>
				<category><![CDATA[cellphones hacks]]></category>
		<category><![CDATA[cons]]></category>
		<category><![CDATA[iphone hacks]]></category>
		<category><![CDATA[macs hacks]]></category>
		<category><![CDATA[25c3]]></category>
		<category><![CDATA[apple]]></category>
		<category><![CDATA[apple iphone]]></category>
		<category><![CDATA[ccc]]></category>
		<category><![CDATA[iphone]]></category>
		<category><![CDATA[iphone dev team]]></category>
		<category><![CDATA[musclenerd]]></category>
		<category><![CDATA[planetbeing]]></category>
		<category><![CDATA[pytey]]></category>
		<category><![CDATA[yellowsn0w]]></category>

		<guid isPermaLink="false">http://hackaday.com/?p=7296</guid>
		<description><![CDATA[As promised in their yellowsnow demo, [pytey], [MuscleNerd], and [planetbeing] from the iphone-dev team presented at 25C3 on their work Hacking the iPhone. The team originally formed in 2007 and this is the most comprehensive presentation on how the iPhone was compromised to date. You can find the full talk embedded above. They opened with [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=7296&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<span style='text-align:center;display:block;'><object width='400' height='330' type='application/x-shockwave-flash' data='http://video.google.com/googleplayer.swf?docId=713763707060529304'><param name='allowScriptAccess' value='never' /><param name='movie' value='http://video.google.com/googleplayer.swf?docId=713763707060529304'/><param name='quality' value='best'/><param name='bgcolor' value='#ffffff' /><param name='scale' value='noScale' /><param name='wmode' value='opaque' /></object></span>
<p>As promised in their <a href="http://hackaday.com/2008/12/21/iphone-3g-unlock-video/">yellowsnow demo</a>, [pytey], [MuscleNerd], and [planetbeing] from the <a href="http://blog.iphone-dev.org/">iphone-dev team</a> presented at <a href="http://hackaday.com/tag/25c3">25C3</a> on their work <a href="http://events.ccc.de/congress/2008/Fahrplan/events/2976.en.html">Hacking the iPhone</a>. The team originally formed in 2007 and this is the most comprehensive presentation on how the <a href="http://www.mahalo.com/IPhone_3G">iPhone</a> was compromised to date. You can find the full talk embedded above.</p>
<p><span id="more-7296"></span></p>
<p>They opened with a few stats about how popular their software is. Our favorite by far is that at least 180 people with Apple corporate IPs update their phones using the dev-team&#8217;s software on a regular basis. From there the talk was split into two sections: jailbreaking the S5L application processor and unlocking the S-Gold baseband processor.</p>
<p>The phone relies on a chain of trust to guarantee that only Apple&#8217;s code is being run on it. All of userland is signature checked by the kernel. The kernel is checked when loaded by iboot. The iboot image is checked when loaded by LLB. LLB is loaded from the NOR by the lowest piece of code, the bootrom. That&#8217;s where things fall apart; the bootrom does not check the signature of the LLB. To take advantage of this, the team found what they describe as a classic stack buffer overflow in DFU mode. DFU is Device Firmware Upgrade mode, a state that the phone can be forced into after the bootrom loads. Their exploit forces the certificate check to return &#8216;true&#8217;. They are then able to patch all of the subsequent signature checks out of the phone&#8217;s system.</p>
<p>The baseband processor proved to be much more difficult simply because it doesn&#8217;t have any sort of recovery mode; bricking a phone was always a possibility. The S-Gold is a complete system-on-chip and has a unique ID on each phone. The NOR also has a unique ID on each phone. These two IDs are used to sign the secpack, which in turn enforces the SIM carrier lock. These unique IDs are why you can&#8217;t just take an officially unlocked phone and copy the secpack off of it to unlock another phone. Everything else is identical: the firmware, the baseband, the bootroom are all the same. On the second generation iPhone, the bootrom checks the bootloader. The bootloader then verifies the bootrom before checking and then loading the firmware. The firmware enforces the carrier lock. The team decided that it wasn&#8217;t worth attempting to break the chain of trust. The SIM unlock code they developed is divided into two sections. The first part is the actual software unlock. They patch the firmware while it&#8217;s running in RAM. Their patch modifies the firmware&#8217;s decision tree about whether to enforce the carrier lock. The second half is the exploit that allows them to inject the code. The team knows that Apple can and probably will patch the exploit hole, but their RAM patching code will always work, so it&#8217;s just a matter of finding another hole to apply it through. In order to do a permanent unlock solution (like on the first generation iPhone), they&#8217;d need to analyze the actual bootrom code.</p>
<p>The team mentioned several things Apple did that actually helped them in their efforts. Security was gradually rolled out, so they were able to look at things that would eventually be hidden. The firmware was initially unencrypted. Earlier versions trusted iTunes, something they could easily modify. All userland apps originally ran as root meaning any application exploit gave root level access.</p>
<p>The iphone-dev team has truly put in a tremendous amount of effort and we look forward to the yellowsn0w release on New Year&#8217;s Eve.</p>
<a class="DiggThisButton DiggMedium" href="http://digg.com/submit?url=http%3A%2F%2Fhackaday.com%2F2008%2F12%2F28%2F25c3-hacking-the-iphone%2F&amp;title=25C3%3A+Hacking+the%26nbsp%3BiPhone"></a>
<br />Posted in cellphones hacks, cons, iphone hacks, macs hacks  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackadaycom.wordpress.com/7296/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackadaycom.wordpress.com/7296/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackadaycom.wordpress.com/7296/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackadaycom.wordpress.com/7296/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackadaycom.wordpress.com/7296/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackadaycom.wordpress.com/7296/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackadaycom.wordpress.com/7296/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackadaycom.wordpress.com/7296/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackadaycom.wordpress.com/7296/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackadaycom.wordpress.com/7296/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackadaycom.wordpress.com/7296/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackadaycom.wordpress.com/7296/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackadaycom.wordpress.com/7296/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackadaycom.wordpress.com/7296/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=7296&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackaday.com/2008/12/28/25c3-hacking-the-iphone/feed/</wfw:commentRss>
		<slash:comments>13</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">RobotSkirts</media:title>
		</media:content>
	</item>
		<item>
		<title>25C3: Power line communication</title>
		<link>http://hackaday.com/2008/12/28/25c3-power-line-communication/</link>
		<comments>http://hackaday.com/2008/12/28/25c3-power-line-communication/#comments</comments>
		<pubDate>Sun, 28 Dec 2008 17:00:28 +0000</pubDate>
		<dc:creator>Eliot</dc:creator>
				<category><![CDATA[cons]]></category>
		<category><![CDATA[home hacks]]></category>
		<category><![CDATA[25c3]]></category>
		<category><![CDATA[ccc]]></category>
		<category><![CDATA[faifa]]></category>
		<category><![CDATA[homeplug av]]></category>
		<category><![CDATA[hub]]></category>
		<category><![CDATA[intellon]]></category>
		<category><![CDATA[network]]></category>
		<category><![CDATA[plc]]></category>
		<category><![CDATA[power line communication]]></category>

		<guid isPermaLink="false">http://hackaday.com/?p=7289</guid>
		<description><![CDATA[[Florian] and [Xavier Carcelle] started the day at 25C3 by covering power line communication. PLC technology is not widespread in the US, but has gained popularity in countries like France where it&#8217;s included in set-top boxes. PLC lets you create a local network using the AC wires in your wall. The team started exploring PLC [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=7289&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignnone size-full wp-image-7290" title="plc" src="http://hackadaycom.files.wordpress.com/2008/12/plc.jpg" alt="plc" width="450" height="288" /></p>
<p>[Florian] and [Xavier Carcelle] started the day at <a href="http://hackaday.com/tag/25c3">25C3</a> by <a href="http://events.ccc.de/congress/2008/Fahrplan/events/2901.en.html">covering power line communication</a>. <a href="http://en.wikipedia.org/wiki/Power_line_communication">PLC</a> technology is not widespread in the US, but has gained popularity in countries like France where it&#8217;s included in set-top boxes. PLC lets you create a local network using the AC wires in your wall. The team started exploring PLC because despite being newer technology, it had a few principles that made it similar to old networks. There&#8217;s no segmentation in the wiring, which means it behaves like a layer 2 hub. You get to see all of the traffic unlike a switched network. Most power meters don&#8217;t filter out the signal, so it&#8217;s possible that you might see your next-door neighbor&#8217;s traffic on your line. [Florian] reports having seen all the traffic in a six-story building just by plugging in. The wiring also acts as a large antenna so you could employ tempest attacks.</p>
<p><span id="more-7289"></span></p>
<p>The technology involved is certainly interesting, but they found a lack of tools to work with it. They wrote <a href="https://dev.open-plc.org/">FAIFA</a> to fill this gap. It&#8217;s currently a command line tool for probing and configuring Intellon-based PLC devices (Intellon is the majority chip supplier for PLC). You can query devices and it even has a sniffer mode. Sniffing may not seem interesting  since devices that support the <a href="http://en.wikipedia.org/wiki/HomePlug_Powerline_Alliance">HomePlug AV</a> standard use encryption, but they&#8217;re all shipping from the factory with the same default key. In the future, they hope to build their own open source FPGA based PLC device to take even more control of the system.</p>
<br />Posted in cons, home hacks  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackadaycom.wordpress.com/7289/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackadaycom.wordpress.com/7289/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackadaycom.wordpress.com/7289/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackadaycom.wordpress.com/7289/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackadaycom.wordpress.com/7289/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackadaycom.wordpress.com/7289/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackadaycom.wordpress.com/7289/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackadaycom.wordpress.com/7289/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackadaycom.wordpress.com/7289/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackadaycom.wordpress.com/7289/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackadaycom.wordpress.com/7289/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackadaycom.wordpress.com/7289/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackadaycom.wordpress.com/7289/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackadaycom.wordpress.com/7289/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=7289&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackaday.com/2008/12/28/25c3-power-line-communication/feed/</wfw:commentRss>
		<slash:comments>13</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">RobotSkirts</media:title>
		</media:content>

		<media:content url="http://hackadaycom.files.wordpress.com/2008/12/plc.jpg" medium="image">
			<media:title type="html">plc</media:title>
		</media:content>
	</item>
		<item>
		<title>25C3: State of the art wearable computing</title>
		<link>http://hackaday.com/2008/12/28/25c3-state-of-the-art-wearable-computing/</link>
		<comments>http://hackaday.com/2008/12/28/25c3-state-of-the-art-wearable-computing/#comments</comments>
		<pubDate>Sun, 28 Dec 2008 15:00:31 +0000</pubDate>
		<dc:creator>Eliot</dc:creator>
				<category><![CDATA[cellphones hacks]]></category>
		<category><![CDATA[cons]]></category>
		<category><![CDATA[wireless hacks]]></category>
		<category><![CDATA[25c3]]></category>
		<category><![CDATA[ccc]]></category>
		<category><![CDATA[kai kunze]]></category>
		<category><![CDATA[wearable]]></category>
		<category><![CDATA[wearable computing]]></category>

		<guid isPermaLink="false">http://hackaday.com/?p=7286</guid>
		<description><![CDATA[[Kai Kunze] from the Embedded Systems Lab at Passau came to 25C3 to talk about Cyborgs and Gargoyles: State of the Art in Wearable Computing. There have been a lot of homebrew wearable computing solutions, but [Kai] covered specifically projects that could see everyday use in the real world. The first was a prototype system [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=7286&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignnone size-full wp-image-7285" title="wearable-1" src="http://hackadaycom.files.wordpress.com/2008/12/wearable-1.jpg" alt="wearable-1" width="450" height="288" /></p>
<p>[Kai Kunze] from the <a href="http://esl.fim.uni-passau.de/page/">Embedded Systems Lab</a> at Passau came to 25C3 to talk about <a href="http://events.ccc.de/congress/2008/Fahrplan/events/2892.en.html">Cyborgs and Gargoyles: State of the Art in Wearable Computing</a>. There have been a lot of homebrew wearable computing solutions, but [Kai] covered specifically projects that could see everyday use in the real world.</p>
<p><span id="more-7286"></span></p>
<p>The first was a prototype system they built for use in hospitals. The doctor wore a belt buckle sized linux computer under his coat which was attached to an RFID reader on his wrist. He would read the patients RFID wrist band, which would display their chart on the screen. He could then scroll and select using a capacitive sensor built into the coat. Notes could be taken using a bluetooth headset. The system kept the doctor&#8217;s hands free for examining the patient while still providing as much information as possible. They actually ran this system for 30 days in a hospital.</p>
<p>The next example was a joint project with the car manufacturer Skoda. Quality assurance (QA) testing can be a long process with many more steps than assembly operations. The team attached sensors to the worker to determine where the worker was in relation to the car and to get direct measurement of the object being tested. The use of wearable technology meant they got more data than they normally would with standard QA testing and they could quickly prompt the worker if they missed a step.</p>
<p>[Kai] identified a couple projects that would make developing your own system much quicker. <a title="CRN Toolbox" href="http://crnt.sf.net">Context Recognition Network Toolbox</a> helps you identify what actions are being performed. They&#8217;ve used it to build systems like an automated kung-fu trainer that can recognize poses. There&#8217;s also a <a title="The Official Context Logger Blog" href="http://contextlogger.blogspot.com/">context logger app</a> for the iPhone that can be trained using accelerometer data to recognize different activities. He also suggested a program developed with Zeiss for <a title="jwoz - A Wizard of Oz GUI for Manuals - Project Web Hosting - Open Source Software" href="http://jwoz.sf.net">visually prompting workers as they performed tasks</a>. In testing, it was 50% faster than text instructions and 30% faster than voice.</p>
<p>One of the more bizarre/interesting ideas we saw was a <a href="http://esl.fim.uni-passau.de/~kkunze/papers/ubicomp07.pdf">phone locator based on resonance</a> (PDF). Designed for a Symbian device, it would play a sound and then record the result that had been modified by the surroundings. Each surface had its own signature so you could query the phone and it would report where it was i.e. on the desk, on the sofa, in the drawer. This resonance sampling can also be employed using the vibration motor.</p>
<p>The final point [Kai] touched on was privacy. If you&#8217;re wearing a sensor, you&#8217;re potentially giving away personal data. He showed an example of how systems could be designed to keep this information to users. The first part was a camera recording the movement of people in a room. It could identify where the faces were, but not who they were. One of the participants had an accelerometer recording their movements. That user could use the camera&#8217;s data to figure out his own movement in the space by correlating the data, but no one else would see the full picture.</p>
<br />Posted in cellphones hacks, cons, wireless hacks  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackadaycom.wordpress.com/7286/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackadaycom.wordpress.com/7286/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackadaycom.wordpress.com/7286/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackadaycom.wordpress.com/7286/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackadaycom.wordpress.com/7286/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackadaycom.wordpress.com/7286/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackadaycom.wordpress.com/7286/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackadaycom.wordpress.com/7286/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackadaycom.wordpress.com/7286/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackadaycom.wordpress.com/7286/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackadaycom.wordpress.com/7286/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackadaycom.wordpress.com/7286/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackadaycom.wordpress.com/7286/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackadaycom.wordpress.com/7286/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=7286&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackaday.com/2008/12/28/25c3-state-of-the-art-wearable-computing/feed/</wfw:commentRss>
		<slash:comments>7</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">RobotSkirts</media:title>
		</media:content>

		<media:content url="http://hackadaycom.files.wordpress.com/2008/12/wearable-1.jpg" medium="image">
			<media:title type="html">wearable-1</media:title>
		</media:content>
	</item>
		<item>
		<title>25C3: Solar-powering your gear</title>
		<link>http://hackaday.com/2008/12/27/25c3-solar-powering-your-gear/</link>
		<comments>http://hackaday.com/2008/12/27/25c3-solar-powering-your-gear/#comments</comments>
		<pubDate>Sat, 27 Dec 2008 16:19:23 +0000</pubDate>
		<dc:creator>Eliot</dc:creator>
				<category><![CDATA[cons]]></category>
		<category><![CDATA[peripherals hacks]]></category>
		<category><![CDATA[solar hacks]]></category>
		<category><![CDATA[25c3]]></category>
		<category><![CDATA[atmega8]]></category>
		<category><![CDATA[AVR]]></category>
		<category><![CDATA[ccc]]></category>
		<category><![CDATA[con]]></category>
		<category><![CDATA[eeprom]]></category>
		<category><![CDATA[kill a watt]]></category>
		<category><![CDATA[nokia]]></category>
		<category><![CDATA[peltier]]></category>
		<category><![CDATA[script]]></category>
		<category><![CDATA[solar]]></category>
		<category><![CDATA[solar panel]]></category>
		<category><![CDATA[solar power]]></category>
		<category><![CDATA[thinkpad]]></category>

		<guid isPermaLink="false">http://hackaday.com/?p=7271</guid>
		<description><![CDATA[The 25th Chaos Communication Congress is underway in Berlin. One of the first talks we dropped in on was [script]&#8216;s Solar-powering your Geek Gear. While there are quite a few portable solar products on the market, we haven&#8217;t seen much in the way of real world experience until now. [script] selected a four segment folding [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=7271&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignnone size-full wp-image-7272" title="solar" src="http://hackadaycom.files.wordpress.com/2008/12/solar.jpg" alt="solar" width="450" height="288" /></p>
<p>The <a title="Welcome - 25C3 Public Wiki" href="http://events.ccc.de/congress/2008/">25th Chaos Communication Congress</a> is underway in Berlin. One of the first talks we dropped in on was [script]&#8216;s <a title="Solar-powering your Geek Gear" href="http://events.ccc.de/congress/2008/Fahrplan/events/2904.en.html">Solar-powering your Geek Gear</a>. While there are quite a few portable solar products on the market, we haven&#8217;t seen much in the way of real world experience until now.</p>
<p><span id="more-7271"></span></p>
<p>[script] selected a four segment folding solar panel after some research. He pointed out that solar is currently more of a necessity technology than money saving since the panels can be very expensive. For connectors, he recommended ones that were safe, polarized, and difficult to short, like the <a title="RIA CONNECT manufactures terminal blocks, modular jacks and USB ports." href="http://www.riaconnect.com/">RIA connect</a> 230 series he used. Most of the device plugs were easily purchasable, but some had to be salvaged from old AC adapters. A key component of his setup was the <a title="Universal-Step-up / Step-down-Spannungswandler USW 525, Komplettbausatz | ELV-Elektronik" href="http://www.elv.de/Universal-Step-up-Step-down-Spannungswandler-USW-525,-Komplettbausatz/x.aspx/cid_74/detail_10/detail2_14231">adjustable voltage regulator</a>. It&#8217;s based on the LTC3780 buck-boost controller which is 98% efficient and can be adjusted from 4V to 25V.</p>
<p>[script] covered some of the problems he ran into in use. The first was an Nokia that refused to charge until a resistor was added to reduce the current delivered. Less sensitive devices like portable <a title="Hack a Day" href="http://hackaday.com/?s=peltier">peltier</a> fridges will work without any issue. For laptop use, he ran into problems with demand spikes killing the power delivery. He added a large cap normally used in car audio systems to make power delivery more consistent. Laptops can consume as little as 15W during normal use, but when they&#8217;re charging the battery, the draw can jump to 50W. On his ThinkPad, he was able to turn off charging to prevent this. He monitored the performance of the panel by building a <a title="Kill A Watt teardown  - Hack a Day" href="http://hackaday.com/2008/11/10/kill-a-watt-teardown/">Kill A Watt</a> style device using an ATmega8 to measure current and voltage and log it to EEPROM.</p>
<p>In conclusion, [script] stated that he was happy with his experience, but that it was still impractical to use the portable panel in anything other than direct sunlight.</p>
<br />Posted in cons, peripherals hacks, solar hacks  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackadaycom.wordpress.com/7271/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackadaycom.wordpress.com/7271/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackadaycom.wordpress.com/7271/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackadaycom.wordpress.com/7271/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackadaycom.wordpress.com/7271/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackadaycom.wordpress.com/7271/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackadaycom.wordpress.com/7271/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackadaycom.wordpress.com/7271/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackadaycom.wordpress.com/7271/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackadaycom.wordpress.com/7271/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackadaycom.wordpress.com/7271/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackadaycom.wordpress.com/7271/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackadaycom.wordpress.com/7271/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackadaycom.wordpress.com/7271/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=7271&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackaday.com/2008/12/27/25c3-solar-powering-your-gear/feed/</wfw:commentRss>
		<slash:comments>10</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">RobotSkirts</media:title>
		</media:content>

		<media:content url="http://hackadaycom.files.wordpress.com/2008/12/solar.jpg" medium="image">
			<media:title type="html">solar</media:title>
		</media:content>
	</item>
		<item>
		<title>Surviving a hacker conference</title>
		<link>http://hackaday.com/2008/12/25/surviving-a-hacker-conference/</link>
		<comments>http://hackaday.com/2008/12/25/surviving-a-hacker-conference/#comments</comments>
		<pubDate>Fri, 26 Dec 2008 05:35:24 +0000</pubDate>
		<dc:creator>Eliot</dc:creator>
				<category><![CDATA[downloads hacks]]></category>
		<category><![CDATA[pcs hacks]]></category>
		<category><![CDATA[security hacks]]></category>
		<category><![CDATA[25c3]]></category>
		<category><![CDATA[ccc]]></category>
		<category><![CDATA[dynamic]]></category>
		<category><![CDATA[dynamic forwarding]]></category>
		<category><![CDATA[hacker conference]]></category>
		<category><![CDATA[hacker convention]]></category>
		<category><![CDATA[hackercon]]></category>
		<category><![CDATA[hardware]]></category>
		<category><![CDATA[security]]></category>
		<category><![CDATA[security4all]]></category>
		<category><![CDATA[ssh]]></category>
		<category><![CDATA[tunnel]]></category>

		<guid isPermaLink="false">http://hackaday.com/?p=7226</guid>
		<description><![CDATA[With another hacker conference looming in front of us, it&#8217;s time to start thinking about hardware security. Hacker conventions have the most hostile network you&#8217;ll ever encounter. [Security4all] points out that 25C3 already has an extensive page on securing your hardware. It starts from the ground up with physical security, BIOS passwords, and locking down [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=7226&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignnone size-full wp-image-7227" title="concrowd" src="http://hackadaycom.files.wordpress.com/2008/12/concrowd.jpg" alt="concrowd" width="450" height="188" /></p>
<p>With another hacker conference looming in front of us, it&#8217;s time to start thinking about hardware security. Hacker conventions have the most hostile network you&#8217;ll ever encounter. [Security4all] <a title="Preparing your laptop for a security conference | Security4all - Dedicated to digital security, enterprise 2.0 and presentation skills" href="http://blog.security4all.be/2008/12/preparing-your-laptop-for-security.html">points out</a> that <a title="25c3  - Hack a Day" href="http://hackaday.com/tag/25c3/">25C3</a> already has an <a title="How To Survive - 25C3 Public Wiki" href="http://events.ccc.de/congress/2008/wiki/How_To_Survive">extensive page on securing your hardware</a>. It starts from the ground up with physical security, BIOS passwords, and locking down bootloaders. There&#8217;s a section on securing your actual OS and session. Finally, they cover network usage. It mentions using <a title="Julius Plenz - Tunnel everything through SSH" href="http://www.plenz.com/tunnel-everything">SSH for dynamic forwarding</a>, which we feel is a skill everyone should have. We&#8217;ve used it not just for security, but for bypassing brainless bandwidth restrictions too. There&#8217;s also the more trick <a title="[Solutions] secure outside communication in insecure environments - The TechSucks TechBlog - blog.crash-override.net" href="http://blog.crash-override.net/index.php/206">transparent version</a>. Every piece of data you bring with you, you risk losing, so they actually recommend just wiping your iPhone and other devices before attending. It&#8217;s important to remember that it&#8217;s not just your own data at risk, but everyone/thing you communicate with as well.</p>
<br />Posted in downloads hacks, pcs hacks, security hacks  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackadaycom.wordpress.com/7226/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackadaycom.wordpress.com/7226/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackadaycom.wordpress.com/7226/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackadaycom.wordpress.com/7226/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackadaycom.wordpress.com/7226/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackadaycom.wordpress.com/7226/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackadaycom.wordpress.com/7226/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackadaycom.wordpress.com/7226/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackadaycom.wordpress.com/7226/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackadaycom.wordpress.com/7226/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackadaycom.wordpress.com/7226/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackadaycom.wordpress.com/7226/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackadaycom.wordpress.com/7226/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackadaycom.wordpress.com/7226/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=7226&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackaday.com/2008/12/25/surviving-a-hacker-conference/feed/</wfw:commentRss>
		<slash:comments>14</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">RobotSkirts</media:title>
		</media:content>

		<media:content url="http://hackadaycom.files.wordpress.com/2008/12/concrowd.jpg" medium="image">
			<media:title type="html">concrowd</media:title>
		</media:content>
	</item>
		<item>
		<title>25C3 international Capture the Flag</title>
		<link>http://hackaday.com/2008/12/23/25c3-international-capture-the-flag/</link>
		<comments>http://hackaday.com/2008/12/23/25c3-international-capture-the-flag/#comments</comments>
		<pubDate>Tue, 23 Dec 2008 17:00:17 +0000</pubDate>
		<dc:creator>Eliot</dc:creator>
				<category><![CDATA[cons]]></category>
		<category><![CDATA[security hacks]]></category>
		<category><![CDATA[25c3]]></category>
		<category><![CDATA[berlin]]></category>
		<category><![CDATA[capture the flag]]></category>
		<category><![CDATA[ccc]]></category>
		<category><![CDATA[chaos communication congress]]></category>
		<category><![CDATA[competition]]></category>
		<category><![CDATA[contest]]></category>
		<category><![CDATA[ctf]]></category>
		<category><![CDATA[virtual machine]]></category>
		<category><![CDATA[vm]]></category>
		<category><![CDATA[vpn]]></category>

		<guid isPermaLink="false">http://hackaday.com/?p=7154</guid>
		<description><![CDATA[Capture the Flag (CTF) is a long running tradition at hacker conventions. It pits teams of security researchers against each other on the same network. Every team gets an identical virtual machine image. The VM has a set of custom written services that are known to be vulnerable. The teams work to secure their image [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=7154&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></description>
			<content:encoded><![CDATA[<p><img class="alignnone" title="trinity" src="http://hackadaycom.files.wordpress.com/2008/06/had_trinity.jpg?w=450&#038;h=110" alt="" width="450" height="110" /></p>
<p>Capture the Flag (<a title="ctf  - Hack a Day" href="http://hackaday.com/tag/ctf">CTF</a>) is a long running tradition at hacker conventions. It pits teams of security researchers against each other on the same network. Every team gets an identical virtual machine image. The VM has a set of custom written services that are known to be vulnerable. The teams work to secure their image while simultaneously exploiting services on the machines of other teams. A scoring server monitors the match as it progresses and awards points to teams for keeping their services up and also for stealing data from their competitors.</p>
<p>The Chaos Communication Congress in Berlin December 27-30, 2008 will <a title="CTF - 25C3 Public Wiki" href="http://events.ccc.de/congress/2008/wiki/CTF">host a CTF competition</a>. Most CTF matches are done head to head in the same room. While 25C3 will have local teams, it will also be wide open for international teams to compete remotely. Remote teams will host their own images on a VPN with the other competitors. Now is a good time to register and familiarize yourself with the scoring system. It will certainly be interesting to see how this competition plays out now that teams that can&#8217;t make the trip can still compete.</p>
<br />Posted in cons, security hacks  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/hackadaycom.wordpress.com/7154/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/hackadaycom.wordpress.com/7154/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godelicious/hackadaycom.wordpress.com/7154/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/delicious/hackadaycom.wordpress.com/7154/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gofacebook/hackadaycom.wordpress.com/7154/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/facebook/hackadaycom.wordpress.com/7154/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gotwitter/hackadaycom.wordpress.com/7154/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/twitter/hackadaycom.wordpress.com/7154/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gostumble/hackadaycom.wordpress.com/7154/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/stumble/hackadaycom.wordpress.com/7154/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/godigg/hackadaycom.wordpress.com/7154/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/digg/hackadaycom.wordpress.com/7154/" /></a> <a rel="nofollow" href="http://feeds.wordpress.com/1.0/goreddit/hackadaycom.wordpress.com/7154/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/reddit/hackadaycom.wordpress.com/7154/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=hackaday.com&amp;blog=4779443&amp;post=7154&amp;subd=hackadaycom&amp;ref=&amp;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://hackaday.com/2008/12/23/25c3-international-capture-the-flag/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
	
		<media:content url="" medium="image">
			<media:title type="html">RobotSkirts</media:title>
		</media:content>

		<media:content url="http://hackadaycom.files.wordpress.com/2008/06/had_trinity.jpg" medium="image">
			<media:title type="html">trinity</media:title>
		</media:content>
	</item>
	</channel>
</rss>
