logo FEDIDEVS

38C3 2024

Jared Naude (140)

Power over Ethernet? 🧐

(Photo @leah)

32 10 3

Identity theft, credit card fraud and cloaking services – how state-sponsored propaganda makes use of the cyber criminal toolbox by Alexej Hock & Max Bernhard

Research by CORRECTIV and Qurium has revealed that the Russian state relies on the toolbox of internet fraudsters for the dissemination of propaganda and fakes. A talk on the state's possible alliance with the criminal world - and on possibilities and limitations of countering it.

🧵

9 10 2

Over 6 Mhw of power was used through the event or the equivalent of 5 bitcoin transactions. The Yolo colo and Pizza Plaza used the most power.

15 11 2

TNSecurity aka "Evil Empire" was thought to be Latvian but was actually revealed to be Russian. A lot of the "bullet proof" hosting providers allow Phishing, Crypto scams and Stealers, botnets, etc but it can't target bodies of the Russian Federation.

3 1 2

Next up is the Heaven / Angel team.
Stats:
- 4691 Angels arrived and 3481 angels that worked at least 1 shift.
- Around 4 years of planned shifts + 2.18 years of worklogs
- 6653 Shifts in the System
- 114 Locations, 67 Angel types and 134 shift types.

Most of the new shift types were the result of the new evacuation requirement.

10 1 2

Attack Mining: How to use distributed sensors to identify and take down adversaries by Lars König

Buckle up for a deep dive into the constant battle to protect systems on the internet against adversaries gaining access, and how you can help make the internet a safer place!

🧵

8 3 2

We've not been trained for this: life after the Newag DRM disclosure by Michał Kowalczyk (@redford), q3k, Jakub Stepniewicz

18 11 1

The third challenge is selective disclosure where a user can choose which data is sent however when it comes to digital signatures, the data cannot be edited or changed. The fourth challenge is unlinkability, where transactions cannot be chained together to track / profile people.

0 0 1

There are many use cases like opening a bank account to using SAAS services. The law has already been passed but should be implemented by 2026, however there are some issues.

0 0 1

EU Governments as part of eIDAS will be offering wallets to citizens that will have many capabilities to allow signing documents, identifying yourself among others.

1 0 1