<?xml version="1.0" encoding="utf-8"?>
<?xml-stylesheet type="text/xsl" href="../../assets/xml/rss.xsl" media="all"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>LaForge's home page (Chaos Computer Club)</title><link>https://laforge.gnumonks.org/</link><description>Chaos Computer Club</description><atom:link href="https://laforge.gnumonks.org/blog/categories/ccc.xml" rel="self" type="application/rss+xml"></atom:link><language>en</language><lastBuildDate>Thu, 24 Oct 2024 20:08:49 GMT</lastBuildDate><generator>Nikola (getnikola.com)</generator><docs>http://blogs.law.harvard.edu/tech/rss</docs><item><title>Retronetworking / BBS-Revival setup at #36C3</title><link>https://laforge.gnumonks.org/blog/20200105-36c3-retronetworking/</link><dc:creator>Harald Welte</dc:creator><description>&lt;p&gt;After many years of being involved in various projects at the annual
Chaos Communication Congress (starting from the audio/vidoe recording
team at 15C3), I've finally also departed the GSM team, i.e. the people
who operate (Osmocom based) cellular networks at CCC events.&lt;/p&gt;
&lt;p&gt;The &lt;a class="reference external" href="https://events.ccc.de/camp/2019"&gt;CCC Camp&lt;/a&gt; in August 2019 was
slightly different: Instead of helping an Osmocom based 2G/3G network, I
decided to put up a nextepc-based LTE network and make that use the
2G/3G HLR (osmo-hlr) via a newly-written &lt;a class="reference external" href="http://git.osmocom.org/erlang/osmo_dia2gsup/"&gt;DIAMETER-to-GSUP proxy&lt;/a&gt;.  After lots of hacking
on that proxy and fixing various bugs in nextepc (see my
&lt;a class="reference external" href="https://github.com/laf0rge/nextepc/tree/laforge/cccamp19"&gt;laforge/cccamp2019 branch here&lt;/a&gt;)
this was working rather fine.&lt;/p&gt;
&lt;p&gt;For &lt;a class="reference external" href="https://events.ccc.de/congress/2019"&gt;36C3&lt;/a&gt; in December 2019 I had
something different in mind:  It was supposed to be the first actual
demo of the retronetworking / bbs-revival setup I've been working on
during past months.  This setup in turn is sort-of a continuation of my
talk at 34C3 two years ago: &lt;a class="reference external" href="https://media.ccc.de/v/34c3-9034-bbss_and_early_internet_access_in_the_1990ies"&gt;BBSs and early Intenet access in the 1990ies&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Rather than just talking about it, I wanted to be able to show people
the real thing:  Actual client PCs running (mainly) DOS, dialling over
analog modems and phone lines as well as ISDN-TAs and ISDN lines into
BBSs, together with early Interent access using SLIP and PPP over the
same dial-up lines.&lt;/p&gt;
&lt;p&gt;The actual setup can be seen at the
&lt;a class="reference external" href="http://osmocom.org/projects/retro-bbs/wiki/Dialup_Network_In_A_Box"&gt;Dialup Network In A Box&lt;/a&gt;
wiki page, together with the
&lt;a class="reference external" href="http://osmocom.org/projects/retro-bbs/wiki/36C3"&gt;36C3 specific&lt;/a&gt; wiki
page.&lt;/p&gt;
&lt;p&gt;What took most of the time was - interestingly - mainly two topics:&lt;/p&gt;
&lt;ol class="arabic simple"&gt;
&lt;li&gt;&lt;p&gt;A 1U rack-mount system with four E1 ports.  I had lots of old Sangoma
Quad-E1 cards in PCI form-factor available, but wanted to use a PC
with a more modern/faster CPU than those old first-generation Atom
boxes that still had actual PCI slots.  Those new mainboards don't
have PCI but PCIe.  There are plenty of PCIe to PCI bridges and
associated products on the market, which worked fine with virtually
any PCI card I could find, but not with the  Sangoma AFT PCI cards I
wanted to use.  Seconds to minutes after boot, the PCI-PCIe bridges
would always forget their secondary bus number.  I suspected
excessive power consumption or glitches, but couldn't find anything
wrong when looking at the power rails with a scope.  Adding
additional capacitors on every rail also didn't change it.  The
!RESET line is also clean.  It remains a mystery.  I then finally
decided to but a new (expensive) DAHDI 4-port E1 PCIe card to move
ahead.  What a waste of money if you have tons of other E1 cards
around.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Various trouble with FreeSWITCH.  All I wanted/needed was some simple
emulation of a PSTN/ISDN switch, operating in NT mode towards both
the Livingston Portmaster 3 RAS and the Auerswald PBX.  I would have
used &lt;a class="reference external" href="http://linux-call-router.de/"&gt;lcr&lt;/a&gt;, but it supports neither
DAHDI nor Sangoma, but only mISDN - and there are no mISDN cards with
four E1 ports :(  So I decided to go for FreeSWITCH, knowing it has
had a long history of ISDN/PRI/E1 support.  However, it was a big
disappointment.  First, there were some segfaults due to a &lt;a class="reference external" href="https://github.com/osmocom/freeswitch/commit/a341d58fbdf6b8bd7d1dd9509dc5319bee206168"&gt;classic pointer deref before NULL-check&lt;/a&gt;.
Next,  libpri and FreeSWITCH have a &lt;a class="reference external" href="https://github.com/osmocom/freeswitch/commit/5621e2a5edbbeec910988eca9446186f19790ab8"&gt;different idea how channel (timeslot) numbers are structured&lt;/a&gt;,
rendering any call attempt to fail.  Finally, FreeSWITCH decided to
&lt;a class="reference external" href="https://github.com/osmocom/freeswitch/commit/83f6bf5276cf70bb11b84615116b0e5cfc590b9d"&gt;blindly overwrite any bearer capabilities IE with 'speech'&lt;/a&gt;,
even if an ISDN dialup call (unrestricted digital information) was
being handled.  The FreeSWITCH documentation contains tons of
references on channel input/output variables related to that - but it
turns out their &lt;a class="reference external" href="https://github.com/osmocom/freeswitch/commit/2cd558502671b9902e0ed05e52d6b5ff10ecbb59"&gt;libpri integration doesn't set any of those&lt;/a&gt;,
nor use any of them on the outbound side.&lt;/p&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Anyway, after a lot more time than expected the setup was operational,
and we could establish modem calls as well as ISDN dialup calls between
the clients and the Portmaster3.  The PM3 in turn then was configured to
forward the dialup sessions via telnet to a variety of BBSs around the
internet.  Some exist still (or again) on the public internet.
Some others were explicitly (re)created by 36C3 participants for this
very BBS-Revival setup.&lt;/p&gt;
&lt;p&gt;My personal favorite was finding &lt;a class="reference external" href="http://blackflag.acid.org/acid-underworld-on-searchlight.html"&gt;ACiD Underworld 2.0&lt;/a&gt;, one
of the few BBSs out there today who support RIPscrip, a protocol used to
render vector graphics, text and even mouse-clickable UI via modem
connection to a DOS/EGA client program called RIPterm.  So we had one
RIPterm installation on Novell DOS7 that was just used for dialling into
ACiD Underworld 2.0.&lt;/p&gt;
&lt;p&gt;Among other things we also tested interoperability between the 1980ies
CCC DIY accoustic coupler "Datenklo" and the Portmaster, and confirmed
that Windows 2000 could establish multilink-PPP not only over two
B-channels (128 kbps) but also over 3 B-Channels (192).&lt;/p&gt;
&lt;p&gt;Running this setup for four days meant 36C3 was a quite different
experience than many previous CCC congresses:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;p&gt;I was less stressed as I wasn't involved in operating a service that
many people would want to use (GSM).&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;I got engaged with many more people with whom I would normally not
have entered a conversation, as they were watching the exhibits/demos
and we got to chat about the technology involved and the 'good old
days'.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;So all in all, despite the &lt;a class="reference external" href="https://twitter.com/LaF0rge/status/1210463996282884096"&gt;last minute FreeSWITCH-patching&lt;/a&gt;,
it was a much more relaxing and rewarding experience for me.&lt;/p&gt;
&lt;p&gt;Special thanks to&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;p&gt;Sylvain "tnt" Munaut for spending a lot of time with me at the
retronetworking assembly.  The fact that I had an E1 interface around
was a good way for him to continue development on his ICE40 based
bi-directional E1 wiretap.  He also helped with setup and teardown.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;miaoski and evanslify for reviving two of their old BBSs from Taiwan
so we could use them at this event&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The retronetworking setup is intended to operate at many other future
events, whether CCC related, Vintage Computing or otherwise.  It's
relatively small and portable.&lt;/p&gt;
&lt;p&gt;I'm very much looking forward to the next incarnations.  Until then, I
will hopefully have more software configured and operational, including
a variety of local BBSs (running in VMs/containers), together with the
respective networking (FTN, ZConnect, ...) and point software like
CrossPoint.&lt;/p&gt;
&lt;p&gt;If you are interested in helping out with this project: I'm very much
looking for help.  It doesn't matter if you're old and have had BBS
experience back in the day, or if you're a younger person who wants to
learn about communications history.  Any help is appreciated.  Please
reach out to the &lt;a class="reference external" href="mailto:bbs-revival@lists.osmocom.org"&gt;bbs-revival@lists.osmocom.org&lt;/a&gt; mailing list, or directly
to me via e-mail.&lt;/p&gt;</description><category>bbs</category><category>ccc</category><category>osmocom</category><category>retro</category><guid>https://laforge.gnumonks.org/blog/20200105-36c3-retronetworking/</guid><pubDate>Sat, 04 Jan 2020 16:00:00 GMT</pubDate></item><item><title>Some thoughts on 33C3</title><link>https://laforge.gnumonks.org/blog/20161230-33c3/</link><dc:creator>Harald Welte</dc:creator><description>&lt;p&gt;I've just had the pleasure of attending all four days of &lt;a class="reference external" href="https://events.ccc.de/congress/2016/wiki/Main_Page"&gt;33C3&lt;/a&gt; and have returned
home with somewhat mixed feelings.&lt;/p&gt;
&lt;p&gt;I've been a regular visitor and speaker at CCC events since &lt;a class="reference external" href="https://events.ccc.de/congress/1998/"&gt;15C3 in
1998&lt;/a&gt;, which among other things
means I'm an old man now.  But I digress ;)&lt;/p&gt;
&lt;p&gt;The event has come extremely far in those years.  And to be honest, I
struggle with the size.  Back then, it was a meeting of like-minded
hackers.  You had the feeling that you know a significant portion of the
attendees, and it was easy to connect to fellow hackers.&lt;/p&gt;
&lt;p&gt;These days, both the number of attendees and the size of the event make
you feel much rather that you're in general public, rather than at some
meeting of fellow hackers.  Yes, it is good to see that more people are
interested in what the CCC (and the selected speakers) have to say, but
somehow it comes at the price that I (and I suspect other old-timers)
feel less at home.  It feels too much like various other technology
related events.&lt;/p&gt;
&lt;p&gt;One aspect creating a certain feeling of estrangement is also the venue
itself.  There are an incredible number of rooms, with a labyrinth of
hallways, stairs, lobbies, etc.  The size of the venue simply makes it
impossible to simply _accidentally_ running into all of your fellow
hackers and friends.  If I want to meet somebody, I have to make an
explicit appointment.  That is an option that exits most of the rest of
the year, too.&lt;/p&gt;
&lt;p&gt;While &lt;a class="reference external" href="http://blog.fefe.de/?ts=a69b7946"&gt;fefe is happy about the many small children attending
the event&lt;/a&gt;, to me this seems
somewhat alien and possibly inappropriate.  I guess from teenage years
onward it certainly makes sense, as they can follow the talks and
participate in the workshop.  But below that age?&lt;/p&gt;
&lt;p&gt;The range of topics covered at the event also becomes wider, at least I
feel that way.  Topics like IT security, data protection, privacy,
intelligence/espionage and learning about technology have always been
present during all those years.  But these days we have bloggers sitting
on stage and talking about bottles of wine (seriously?).&lt;/p&gt;
&lt;p&gt;Contrary to many, I also really don't get the excitement about shows
like 'Methodisch Inkorrekt'.  Seems to me like mainstream
compatible entertainment in the spirit of the 1990ies &lt;a class="reference external" href="https://en.wikipedia.org/wiki/Die_Knoff-Hoff-Show"&gt;Knoff Hoff Show&lt;/a&gt; without much
potential to make the audience want to dig deeper into (information)
technology.&lt;/p&gt;</description><category>ccc</category><guid>https://laforge.gnumonks.org/blog/20161230-33c3/</guid><pubDate>Thu, 29 Dec 2016 17:00:00 GMT</pubDate></item><item><title>29C3.  The end of an era?</title><link>https://laforge.gnumonks.org/blog/20121218-29c3/</link><dc:creator>Harald Welte</dc:creator><description>&lt;p&gt;
When I first heard that the annual CCC congress was moved to Hamburg, my
immediate reaction was: Fine, but I wouldn't want to be involved in it.
For the last 15 years I've been attending the CCC congress every year,
in most years as a speaker, and in many years in some (small)
contributing role, first in the team doing the video recordings, and in
the last couple of years setting up a GSM network.   Contributing to an
event is easy if your home/lab is within 20minutes, so if you need
another strange cable/adapter/tool/whatever, you can just go and grab
it.  Doing that at an event that's multiple hours of driving away, in a
new/unknown venue is an entirely different story.  I have more than
enough stress already with (paid) work and the various FOSS projects
that I'm leading or involved in.
&lt;/p&gt;
&lt;p&gt;
I have no interest in "just" attending the event.  That never was a
primary reason for me.  In all those years, I've probably attended an
average of one talk each year.  The event for me was about being able to
contribute something actively.
&lt;/p&gt;
&lt;p&gt;
Now, months after those thoughts and my decision not to attend, there is
a schedule for the 29C3 available.  And to say the least, I am shocked.
The entire event seems to have turned into a SIGINT, rather than an
xxC3.  Lots of talks on politics and society, and lots of German talks.
&lt;/p&gt;
&lt;p&gt;
The debate on implications of technology on society, culture, politics,
etc. is an important debate, there is no doubt.  And so far I always had
the feeling that the xxC3 had a pretty good balance between hard-core
technical talks and those non-technical talks.  But if I look at the
schedule this year, it really looks like an incarnation of the SIGINT
conference.  With too many German talks you are scaring off the
international community.  And with focussing on non technical topics,
you scare away the die-hard technical hackers.  So why move to a larger
venue, if you at the same time seem to limit the scope of the event?
&lt;/p&gt;
&lt;p&gt;
Meanwhile I have heard of a number of friends and colleagues who seem to
share this view.  A number of people who have attended in previous years
are not interested in attending this year due to the issues mentioned
above.
&lt;/p&gt;
&lt;p&gt;
It's sad to see, but I somehow have the feeling that 29C3 might be the
end of an era.  The end of a highly successful series of events with
exceptionally strong technical talks.  To me, xxC3 has always been
unique and special.  No other event would ever compare to it.  Who will
fill the gap for the die-hard technical topics?  I am feeling quite sad,
up to the point that I want to start mourning about "the good old
times".
&lt;/p&gt;
&lt;p&gt;
I'm not writing this to put blame on anyone.  It just reflects my
personal and highly subjective view.  Let's see what people will say
after 29C3 has actually happened.  Let's see how successful it is in
terms of number of attendees, and in terms of feedback from
participants.  I'd like to explicitly thank the many organizers and
volunteers (a lot of whom I know in person) for putting up their time and
energy to make 29C3 happen.
&lt;/p&gt;</description><category>ccc</category><guid>https://laforge.gnumonks.org/blog/20121218-29c3/</guid><pubDate>Mon, 17 Dec 2012 19:00:00 GMT</pubDate></item><item><title>Chaosradio Express 151: ARM CPU Architecture (German)</title><link>https://laforge.gnumonks.org/blog/20100428-chaosradio_arm_architecture/</link><dc:creator>Harald Welte</dc:creator><description>&lt;p&gt;
I'm a bit late with this:
The &lt;a href="http://chaosradio.ccc.de/"&gt;Chaosradio&lt;/a&gt; Express 
&lt;a href="http://chaosradio.ccc.de/cre151.html"&gt;#151 podcast on the ARM CPU
architecture has been released a week ago&lt;/a&gt;.  I had a most pleasant
experience spending about 90 minutes getting interviewed by &lt;a href="http://en.wikipedia.org/wiki/Tim_Pritlove"&gt;Tim Pritlove&lt;/a&gt;.
&lt;/p&gt;
&lt;p&gt;
I'm sorry for all the non-German-speakers.  But Chaosradio Express is
a German medium, made by and for German hackers :)
&lt;/p&gt;</description><category>ccc</category><guid>https://laforge.gnumonks.org/blog/20100428-chaosradio_arm_architecture/</guid><pubDate>Tue, 27 Apr 2010 19:00:00 GMT</pubDate></item><item><title>German Constitutional Court hearing on data retention law</title><link>https://laforge.gnumonks.org/blog/20091215-bverfg_vorratsdaten/</link><dc:creator>Harald Welte</dc:creator><description>&lt;p&gt;
Today I've taken one day off work in order to attend the publich hearing
of &lt;a href="http://www.bundesverfassungsgericht.de/"&gt;Germany's constitutional
c ourt&lt;/a&gt; on several constitutional complaints against a German national law
on data retention of telecommunications data.  As the topic is likely only
relevant to Germans, and due to the fact that I am not very confident with
my English legalese outside of copyright law, I'll switch to German for
this blog post - which I believe is unprecedented in this blog so far.
&lt;/p&gt;
&lt;br&gt;
&lt;p&gt;
Tja, da war ich also heute einer der wenigen auserkorenen Besucher beim
BVerfG.  Immerhin haben mehr als 34.000 Leute Verfassungsbeschwerde eingelegt,
auch wenn rein formal heute nur eine Hand voll exemplarische Beschwerden
verhandelt wurden.  Diesen Trick hat sich das BVerfG wohl ausgedacht, um nicht
vor dem Problem zu stehen dass jeder Beschwerdefuehrer sicher ein Recht haette,
persoenlich vor Gericht anwesend zu sein.
&lt;/p&gt;
&lt;p&gt;
Der Gerichtssaal des BVerfG ist sehr klein.  So klein, dass bei besonders
bedeutungsvollen Verfahren kaum mehr Platz fuer Besucher ist.  Der eigentliche
Gerichtssaal war schon durch die Beschwerdefuehrer, die zahlreichen Vertreter
des Gesetzgebers und der Behoerden und Amstraeger (BKA, Polizeipraesidenten,
Richter an diversen Gerichten, Bundes- und Landesdatenschutzbeauftragte,
Mitglieder des Bundestags und nicht zuletzt die zahlreichen wissenschaftlichen
Mitarbeiter des Bundesverfassungsgerichts selbst belegt.  Hinten waren noch zwei
Reihen fuer Besucher frei.  
&lt;/p&gt;
&lt;p&gt;
Diese beiden Reihen wurden durch Studentengruppen belegt - oder vielleicht
koennte man fast sagen "verschwendet".  Ein nicht unerheblicher Teil dieser
Studenten (u.a. der TU Darmstadt) hatte tatsaechlich geschlafen.  Was fuer eine
Ungeheuerlichkeit, nicht nur ein Mangel an Respekt gegenueber dem hoechsten
Gericht des Landes und dem Thema gegenueber - sondern auch eine
unverschaemtheit gegenueber den vielen vmtl. hunderten von interessierten
Buergern die gerne der Verhandlung beigewohnt haetten, aber einfach keinen Platz mehr bekommen haben.  Freunde von mir haben am 2. Tag nach der Terminankuendigung
versucht noch einen Platz zu bekommen - vergebens.
&lt;/p&gt;
&lt;p&gt;
Da haben wir also die nahezu perverse Situation, dass das hoechste Gericht zwar
faktisch von jedem Buerger angerufen werden kann, dies auch eine fuenfstellige
Zahl an Buergern wahrnimmt - dann aber die eigentliche Verhandlung nur fuer
eine kleine Elite zugaenglich ist, und Aufzeichnungen oder Uebertragungen nicht
gestattet sind.  Das erscheint mir doch irgendwie ungerecht.
&lt;/p&gt;
&lt;p&gt;
Doch nun zur Sache:
&lt;/p&gt;
&lt;p&gt;
Der 1. Senat unter dem Vorsitzenden Richter Papier hat die Anhoerung im
Allgemeinen sehr souveraen geleitet.  Es gab ein paar amuesante Momente,
als z.B. die Vertreterin des Justizministeriums das Wort an den
Prozessbevollmaechtigten der Bundesregierung uebergeben hat, obwohl doch das
Gericht normalerweise das Wort erteilt, und nicht andersherum ;)
&lt;/p&gt;
&lt;p&gt;
Wie auch schon bei der letzten Verhandlung: Die Beitraege der geladenen
Sachverstaendigen waren bisweilen der interessanteste Teil, vor allem eben
die diversen Fragen des Gerichts.  Diese Fragen erlauben einerseits einen
Blick hinter die Ueberlegungen der Richter - andererseits aber auch in wie
weit die technischen Zusammenhaenge und deren Folgen vom Gericht bereits
verstanden werden.  Das jetzt bitte nicht falsch verstehen: Ich habe tiefsten
Respekt vor dem Gericht, und es ist i.d.R. sehr erstaunlich wie weit sich die
Richter in das jeweilige Fachgebiet einarbeiten.  Wie auch schon bei der
Verhandlung zu den Wahlcomputern lassen die Vertreter der Regierung bzw. der
untergeordneten Behoerden da oft deutlich weniger umfassende Kenntnisse
durchblicken.
&lt;/p&gt;
&lt;p&gt;
Die ganze Debatte zur VDS (Vorratsdatenspeicherung) ist verzwickt.  Wir haben
da historisch einen Bundestag, der keine VDS will, einen Rat der
EU-Innenminister der das dann einfach als EU-Richtlinie beschliesst, und einen
Bundestag, der in Folge die exzellente Ausrede hat, dass er die Richtline ja
umsetzen muesse, um von der EU kein Verfahren angehaengt bekommt.
&lt;/p&gt;
&lt;p&gt;
Die EU-Richtline heisst nun eben auch, dass das BVerfG nun nicht nur in der
Sache zur VDS entscheiden kann, sondern sich eben noch mit der Frage
beschaeftigen muss, was denn passiert wenn eine EU-Richtline mit dem Deutschen
Grundgesetz in Konflikt steht.
&lt;/p&gt;
&lt;p&gt;
Ein paar voellig ungeordnete aber fuer mich bemerkenswerte Punkte der
Verhandlung heute:
&lt;/p&gt;&lt;ul&gt;
&lt;li&gt;
Es gibt keine empirisch/wissenschaftliche  Grundlage die belegt, dass die VDS
zur bekaempfung von Terroristischen Anschlaegen geeignet ist (das war ja nach
Dem 11.9. sowie den Anschlaegen von Madrid und London die Begruendung).
&lt;/li&gt;
&lt;li&gt;
Der Chef der Bundesnetzagentur hat mehrfach ganz unuebersehbar nicht auf eine
wiederholte Frage des BVerfG geantwortet: Gibt es Unternehmen, die gesetzlich
zur VDS verpflichtet sind, aber andererseits keinerlei Verpflichtung zur
erstellung oder Abgabe eines Sicherheitskonzepts zur Sicherheit dieser Daten
haben? (Meine Auffassung: Ja, die gibt es!)
&lt;/li&gt;
&lt;li&gt;
Die Bundesnetzagentur macht, wie sie selbst sagt, im wesentlichen Pruefungen
der Sicherheitskonzepte am Schreibtisch.  Das muss ja mit der Realitaet in den Unternehmen nicht viel zu tun haben.
&lt;/li&gt;
&lt;li&gt;
Einer der Beschwerdefuehrer, Minister A.D. Dr. Burkhard Hirsch hat wohl
die lebhaftesten und unverbluemtesten Redebeitraege gehalten; sehr erfrischend.
&lt;/li&gt;
&lt;li&gt;
Der Polizeipraesident von Muenchen wurde gebeten, konkret zu begruenden,
wie die VDS der polizeilichen Ermittlungsarbeit in Muenchen hilft.  Fast alle
seiner Beispiele waren ungeeignet, da sie auch ohne VDS aber z.B. mittels
einer telefonischen Fangschaltung oder einer Verbindungsdatenspeicherung nach
expliziter Aufforderung durch die Polizei (und nicht auf Vorrat) moeglich
gewesen weaeren.  Zwei seiner Beispiele haben sich zudem generell als falscher
Alarm herausgestellt (Journalist macht einn Testanruf; gelangweilter Schueler
kuendigt aus Spass Amoklauf an).  Das klang alles eher nach
Stammtischgeschichten als nach fundierter Ermittlungsarbeit in wichtiger Sache.
&lt;/li&gt;
&lt;li&gt;
Die Sicherheitsanforderungen an die Speicherung der VDS-Daten ist derzeit
offensichtlich nicht hoeher als an alle anderen Daten innerhalb des
Fernmeldegeheimnisses insgesamt.  Also der gleiche Sicherheitslevel, der uns
zu den Datenschutzskandalen wie z.B. bei der Telekom gefuehrt hat.  Das ist
ja mal echt vertrauenerweckend.
&lt;/li&gt;
&lt;li&gt;
Der Chef der Bundesnetzagentur spricht gerne vom "bill shock", was laut ihm
eine ueberhoehte Telefonrechnung nach unabsichtlicher Nutzung der teuren
Auslandsroaming-Tarife im Mobilfunk ist.
&lt;/li&gt;
&lt;li&gt;
Ein kleiner Schmunzler am Rande war dann noch Burkhard Hirsch's "Blueberry", als
er den Blackberry meinte ;)  Ja, klar, jeder weiss was er meint und niemand
nimmt es ihm uebel - aber es zeigt einfach, wie unsicher die "alte Garde"
mit den Begrifflichkeiten der heutigen Alltagswelt umgeht.
&lt;/li&gt;
&lt;li&gt;
Die qualitaet der Richterlichen Anordnungen laesst offensichtlich sehr zu
wuenschen uebrig.  Es ist aufgabe des jeweiligen Richters, einzuschraenken
genau welche Daten denn vom TK-Dienstleister uebergeben werden sollen.
Laut dem Vertreter des Verbands der Internetwirtschaft (eco e.V.) kommen
hier anscheinend recht allgemeine Anordnungen im Stil von "geben Sie uns mal
alles was Sie haben" vor.  Das geht so natuerlich nicht!
&lt;/li&gt;
&lt;li&gt;
Es kam zur Sprache, dass deutlich mehr Leute jetzt ihre eigenen e-mail Server
betreiben wollen (privat und bei Firmen), weil man sich damit der e-mail VDS
entziehen kann.  Ist ja schoen, dass es den Trend gibt, und gut dass das
auch mal auf dieser Ebene zur Sprache kommt.  (Fuer mich kaeme etwas anderes
niemals in Frage.  Meine Daten gehoeren mir.  Ich wuerde weder die Speicherung
meiner Mails noch jeglicher anderer Daten jemals einer anderen Person
anvertrauen, weder einem Privatunternehmen noch einer staatlichen Stelle).
Das ist genau einer der vielen Tricks, mit denen die "digitale Elite" (und
garantiert auch die vermeintlich zu bekaempfende organisierte Kriminalitaet
oder der Terrorismus) arbeitet.  Letztlich trifft man dann nur den
Otto-Normalverbraucher, und benutzt die Daten dann fuer harmlose
Beleidungsdelikte oder Urheberrechtsverletzungen im privaten Bereich.
&lt;/li&gt;
&lt;/ul&gt;
&lt;br&gt;</description><category>ccc</category><guid>https://laforge.gnumonks.org/blog/20091215-bverfg_vorratsdaten/</guid><pubDate>Mon, 14 Dec 2009 19:00:00 GMT</pubDate></item><item><title>deDECTed.org receives massive number of hits</title><link>https://laforge.gnumonks.org/blog/20090121-dedected-dos/</link><dc:creator>Harald Welte</dc:creator><description>&lt;p&gt;
One of the projects that I'm hosting (and which I've helped to initiate) on &lt;a href="http://gnumonks.org/"&gt;gnumonks.org&lt;/a&gt; is the &lt;a href="http://dedected.org/"&gt;deDECTed.org&lt;/a&gt; project about security research and
analysis of the DECT protocols.
&lt;/p&gt;
&lt;p&gt;
Like I've pointed out in many of my presentations and here in this blog, there
are many communication systems in use today which don't even remotely receive
as much scrutiny as TCP/IP, the Internet and the PC world.  RFID is one of
them, which is why I helped to get &lt;a href="http://www.openpcd.org/"&gt;OpenPCD&lt;/a&gt;, &lt;a href="http://www.openpcd.org/openpicc.0.html"&gt;OpenPICC&lt;/a&gt;, librfid and other
projects started.  My recent work on GSM protocol analysis as well as &lt;a href="http://openbsc.gnumonks.org/"&gt;OpenBSC&lt;/a&gt; are of similar nature.  And
deDECTEd.org is doing the long-neccessarry scrutiny to evaluate practical DECT
cordless telephone security.
&lt;/p&gt;
&lt;p&gt;
As it seems, the news about the insecurity of most cordless phones has made its
way into mainstream news, and the website is now getting thrashed quite a bit,
despite running on a dual-core Opteron with quite a bit of RAM and fast SCA
disks.  Which is good.  This means that people are indeed caring about the
confidentiality of their cordless phones.  It's a pity that the industry missed
that fact and is shipping outdated technology way beyond todays
state-of-the-art in IT security.  Proprietary symmetric ciphers, weak RNGs,  no
user indication if the protocol
falls back to no encryption, etc.
&lt;/p&gt;
&lt;p&gt;
I've changed one of my e-mail signatures a couple of years back to a quote from
the ETSI DECT spec: "&lt;b&gt;Privacy in residential applications is a desirable
marketing option&lt;/b&gt;".  A Marketing option. Not something anyone would have to
give much thought about.  I hope the hardware vendors will now get sufficient
public pressure to get their act together...
&lt;/p&gt;
&lt;p&gt;
It's also great to see Patrick McHardy of netfilter.org fame now work on
&lt;a href="http://lists.gnumonks.org/pipermail/dedected/2009-January/000269.html"&gt;implementing a DECT protocol stack for the Linux kernel&lt;/a&gt;.  Very exciting work.
&lt;/p&gt;
&lt;p&gt;
The only sad thing is that all I can do is sit back and watch.  I so much wanted
to work on this project, but never got a chance.  There are too many high-priority
things going on, and I'm basically spending all my time in exciting (but
unpaid) GSM protocol related work right now.
&lt;/p&gt;</description><category>ccc</category><guid>https://laforge.gnumonks.org/blog/20090121-dedected-dos/</guid><pubDate>Tue, 20 Jan 2009 19:00:00 GMT</pubDate></item><item><title>If you're at the 25C3: Don't miss the DECT talk</title><link>https://laforge.gnumonks.org/blog/20081228-25c3-dect/</link><dc:creator>Harald Welte</dc:creator><description>&lt;p&gt;
If you're at the 25C3, I strongly recommend visiting &lt;a href="http://events.ccc.de/congress/2008/Fahrplan/events/2937.en.html"&gt;the DECT
security talk&lt;/a&gt;.  Trusty me, you won't be disappointed.
&lt;/p&gt;
&lt;p&gt;
It's one of the most exciting thigs that I've been seeing happening recently.
Finally, some more people transcending beyond boring Internet security and
moving into other areas of communications security that are desperately needing
more research.
&lt;/p&gt;</description><category>ccc</category><guid>https://laforge.gnumonks.org/blog/20081228-25c3-dect/</guid><pubDate>Sat, 27 Dec 2008 19:00:00 GMT</pubDate></item><item><title>Blinkenlights is back (stereoscope)</title><link>https://laforge.gnumonks.org/blog/20081004-blinkenlights_stereoscope/</link><dc:creator>Harald Welte</dc:creator><description>&lt;p&gt;
Some of you might remember the famous &lt;a href="http://www.blinkenlights.de/"&gt;blinkenlights&lt;/a&gt; installations of the &lt;a href="http://www.ccc.de/"&gt;CCC&lt;/a&gt; in Berlin at Alexanderplatz some years back.  Basically
they used a matrix of windows on a building for a low-resolution display to
play pong and display all kinds of animations and text.
&lt;/p&gt;
&lt;p&gt;
After a long break, they're back, even bigger with &lt;a href="http://www.blinkenlights.net/stereoscope/"&gt;blinkenlights stereoscope&lt;/a&gt;,
a massive installation spanning 960 windows of &lt;a href="http://blinkenlights.net/stereoscope/toronto-city-hall"&gt;Toronto City Hall&lt;/a&gt;.  The entire backend technology
has been re-implemented based on &lt;a href="http://www.openbeacon.org/"&gt;OpenBeacon&lt;/a&gt;
, specifically the &lt;a href="http://wiki.openbeacon.net/Blinkenlights_WMCU"&gt;WMCU&lt;/a&gt; and the &lt;a href="http://wiki.openbeacon.net/Blinkenlights_WDIM"&gt;WDIM&lt;/a&gt; units.
&lt;/p&gt;</description><category>ccc</category><guid>https://laforge.gnumonks.org/blog/20081004-blinkenlights_stereoscope/</guid><pubDate>Fri, 03 Oct 2008 19:00:00 GMT</pubDate></item><item><title>Chaosradio on Software Defined Radio</title><link>https://laforge.gnumonks.org/blog/20080517-chaosradio-sdr/</link><dc:creator>Harald Welte</dc:creator><description>&lt;p&gt;
I've had the pleasure of being invited to &lt;a href="http://chaosradio.ccc.de/chaosradio_express.html"&gt;Chaosradio Express&lt;/a&gt;
maker Tim Pritlove to talk about Software Defined Radio in general, and
gnuradio plus USRP specifically.  You can listen to the &lt;a href="http://chaosradio.ccc.de/cre087.html"&gt;resulting 2+ hours of podcast (in
German)&lt;/a&gt;.
&lt;/p&gt;
&lt;p&gt;
It's been a great experience, and I have a good feeling that it was possible for
us to explain this fairly detailed subject to our already at least moderately
technical audience.
&lt;/p&gt;
&lt;p&gt;
SDR is really hard since it combines aspects of traditional radio, i.e. physics
of electric waves, electrical engineering both analog and digital, digital
signal processing and software.  The biggest part is really advanced
mathematics, and at least from all the subjects that I've seen, it's probably
the most direct and close-to-theory incarnation of applied math.
&lt;/p&gt;
&lt;p&gt;
Luckily, a fairly high-level understanding of the algorithms and principles
involved are already sufficient to do a lot, since most of the deep-down
mathematical details of many algorithms have already been implemented as
building blocks for gnuradio.  Still, I assume the number of developers who
are actually able to use gnuradio is far too low.  If you're looking for an
interesting field of software right now, I suggest going for digital signal
processing.  It's in every area of communications, ranging from analog modems
over ISDN, DSL, WiFi, USB2, Bluetooth, GSM, UMTS, DECT, ZigBee, Ethernet, VoIP
and probably any other communication technology that we use today.
&lt;/p&gt;</description><category>ccc</category><guid>https://laforge.gnumonks.org/blog/20080517-chaosradio-sdr/</guid><pubDate>Fri, 16 May 2008 19:00:00 GMT</pubDate></item><item><title>My personal favourite from 24C3: Xbox 360 hacking</title><link>https://laforge.gnumonks.org/blog/20080101-24c3-xbox360/</link><dc:creator>Harald Welte</dc:creator><description>&lt;p&gt;
I've seen quite a number of presentations live at &lt;a href="http://events.ccc.de/congress/2007/"&gt;24C3&lt;/a&gt; as well as recorded ones in
the days following the event.  While many of them cover important subjects,
there is one lecture that is outstanding: &lt;a href="http://events.ccc.de/congress/2007/Fahrplan/events/2279.en.html"&gt;"Deconstructing Xbox 360 Security"&lt;/a&gt;.
&lt;/p&gt;
&lt;p&gt;
The level of technicality of this presentation was just right. Finally
something that went deep down into the technical details.  Explaining what kind
of flaws they found in the disassembled power PC object code. 
&lt;/p&gt;
&lt;p&gt;
I definitely want to see more lectures/presentations like this.  Don't be
afraid to overload the audience with technical details.   Just go ahead with it :)
&lt;/p&gt;
&lt;p&gt;
Also, this presentation has shown how far advanced the game console hacking is
compared to mobile phone hacking (at least from what I've seen in the ETC
(Ada-developers) and and Motorola hacker communities).  The problems are
similar: Completely undocumented hardware, cryptographic authentication of code
by the boot loader (sometimes down to mask ROM), ...
&lt;/p&gt;
&lt;p&gt;
So I hope that the mobile phone hacker community will grow and more people with
this skillet, attitude and time will join.  Free your phones!
&lt;/p&gt;</description><category>ccc</category><guid>https://laforge.gnumonks.org/blog/20080101-24c3-xbox360/</guid><pubDate>Mon, 31 Dec 2007 19:00:00 GMT</pubDate></item><item><title>Personal reflection on the 24th annual Chaos Communication Congress</title><link>https://laforge.gnumonks.org/blog/20071229-24c3/</link><dc:creator>Harald Welte</dc:creator><description>&lt;p&gt;
It's great to be at &lt;a href="http://events.ccc.de/congress/2007/"&gt;24C3&lt;/a&gt;, the
24th incarnation of the &lt;a href="http://www.ccc.de/"&gt;Chaos Computer Club&lt;/a&gt;s
annual congress in Berlin.
&lt;/p&gt;
&lt;p&gt;
In fact, this is my 10th anniversary at this congress, i.e. the first one I
visited was 15C3.  I ended up at 15C3 as somewhat of a coincidence by just
following a fellow Linux hacker from the Linux User Group Nuernberg to whom
I've since lost all contact.
&lt;/p&gt;
&lt;p&gt;
What's actually worth mentioning is that this is the first CCC congress that I
visit as a pure guest.  I have no lecture, and I am not actively involved with
any of the things I have been involved before, such as the video
recording/streaming team or the &lt;a href="http://www.openbeacon.org/"&gt;Sputnik&lt;/a&gt; RFID location system.
&lt;/p&gt;
&lt;p&gt;
Interestingly, I felt the first day much more tiring than usually, despite
having slept more than in any of the previous years.  Apparently the lack of
constant adrenaline caused by last-minute-problem-solving has its impact..
&lt;/p&gt;
&lt;p&gt;
The congress is a lot of fun, I've been talking to many old friends, colleagues
and fellow hackers from all over the world, involved in all of the projects
and/or companies that I've remotely had any contact throughout that ten year
time period.
&lt;/p&gt;
&lt;p&gt;
It's a very nice feeling.  I doubt there is any other event or occasion where I
would feel more at home than at this annual congress.  This is my culture.
This is where I belong.  Here are people who understand, or rather: understood.
&lt;/p&gt;</description><category>ccc</category><guid>https://laforge.gnumonks.org/blog/20071229-24c3/</guid><pubDate>Fri, 28 Dec 2007 19:00:00 GMT</pubDate></item><item><title>Looking forward to the Chaos Camp 2007</title><link>https://laforge.gnumonks.org/blog/20070804-happy_to_go_to_camp_2007/</link><dc:creator>Harald Welte</dc:creator><description>&lt;p&gt;
In about 24 hours I'll be on my flight 'back' to Germany.  In fact it's not
really a flight back to Germany, but more like a temporary break of my extended
stay in Taipei for the sake of &lt;a href="http://www.openmoko.com/"&gt;OpenMoko&lt;/a&gt;.
&lt;/p&gt;
&lt;p&gt;
The main reason for this trip is to attend the &lt;a href="http://events.ccc.de/events/camp/2007/"&gt;Chaos Camp 2007&lt;/a&gt; of the &lt;a href="http://www.ccc.de/"&gt;CCC&lt;/a&gt;.  I've so far dropped every conference or other technical
event this year to concentrate on my work for OpenMoko, but I'm not able to compromise
on the camp. 
&lt;/p&gt;
&lt;p&gt;
On the one hand, I'm looking forward to finally not having any official function at
a CCC event. More than one year after vacating my task as leader of the video
documentation effort, and after my somewhat minor involvement with the &lt;a href="http://www.openbeacon.org/"&gt;sputnik RFID tracking project&lt;/a&gt; at the congress last
December, this is not really the first CCC event which I'll visit as a pure
visitor.  I haven't even submitted any paper.
&lt;/p&gt;
&lt;p&gt;
So the camp will be holiday.  Time to relax, talk with fellow hackers.  Sure,
lots of the German OpenMoko guys (roh, stefan, alphaone, and our newcomer
gismo) will be there.  So there will definitely be some kind of productive
outcome for the OpenMoko project, too.  But in a very different setting.  Doing
thighs that are fun, rather than all the things that have to be done :)
&lt;/p&gt;</description><category>ccc</category><guid>https://laforge.gnumonks.org/blog/20070804-happy_to_go_to_camp_2007/</guid><pubDate>Fri, 03 Aug 2007 19:00:00 GMT</pubDate></item><item><title>Chaos Communication Camp 2007</title><link>https://laforge.gnumonks.org/blog/20070126-ccc_camp_2007/</link><dc:creator>Harald Welte</dc:creator><description>&lt;p&gt;
The &lt;a href="http://events.ccc.de/2007/01/24/chaos-communication-camp-2007/"&gt;date and location for the 2007 Chaos Communication Camp have been announced&lt;/a&gt;, which is really good news.
&lt;/p&gt;</description><category>ccc</category><guid>https://laforge.gnumonks.org/blog/20070126-ccc_camp_2007/</guid><pubDate>Thu, 25 Jan 2007 19:00:00 GMT</pubDate></item><item><title>First two days of 23C3</title><link>https://laforge.gnumonks.org/blog/20061228-23c3_first_days/</link><dc:creator>Harald Welte</dc:creator><description>&lt;p&gt;
I'm currently at the &lt;a href="http://events.ccc.de/congress/2006/"&gt;23rd annual
Chaos Communication Congress&lt;/a&gt; in my home town Berlin, Germany.
&lt;/p&gt;
&lt;p&gt;
After having dropped out of my usual volunteer work in the Audio/Video
recording team, I thought that this year would be slightly more relaxing.
Then came the &lt;a href="http://www.openbeacon.org/59.0.html#opbc_sputnik"&gt;Sputnik&lt;/a&gt; system,
which suddenly started to eat some of my time weeks and months before the
congress, as well as the last couple days before the congress, during the
build-up.  In fact, given my many other projects, I was close to going crazy
and thus dropped out of the project and disappeared completely from the
congress for about one day.  Sorry about that, but I just needed to relax and
calm down.
&lt;/p&gt;
&lt;p&gt;
After a very stressful 26th of December, the team actually managed to set the
whole back-end and middleware system up on the first day of the event, and the
3D visualization was running by 4am of the second day.
&lt;/p&gt;
&lt;p&gt;
Now I'm back to normal mode, present at the event almost all day, which I
intend to do for the next two days, too.
&lt;/p&gt;</description><category>ccc</category><guid>https://laforge.gnumonks.org/blog/20061228-23c3_first_days/</guid><pubDate>Wed, 27 Dec 2006 19:00:00 GMT</pubDate></item><item><title>CCC Berlin now proud owner of USRP</title><link>https://laforge.gnumonks.org/blog/20060803-cccb-gnuradio/</link><dc:creator>Harald Welte</dc:creator><description>&lt;p&gt;
Finally the &lt;a href="http://berlin.ccc.de/"&gt;Berlin Section&lt;/a&gt; of the &lt;a href="http://www.ccc.de/"&gt;CCC&lt;/a&gt; has managed to obtain some donations
(courtesy of &lt;a href="http://gpl-violations.org/"&gt;) for the purchase
of a &lt;/a&gt;&lt;a href="http://www.comsec.com/wiki?UniversalSoftwareRadioPeripheral"&gt;USRP&lt;/a&gt;
with all major front-ends (BasicRX, BasicTX, RFX2400, RFX1800, RFX900, DBSRX,
..).
&lt;/p&gt;
&lt;p&gt;
I sincerely hope that this device will be able to fuel even more interest in RF
communications and research of security aspects of popular RF systems such as
DECT.  At least a bunch of interested hackers now have all the tools they need :)
&lt;/p&gt;</description><category>ccc</category><guid>https://laforge.gnumonks.org/blog/20060803-cccb-gnuradio/</guid><pubDate>Wed, 02 Aug 2006 19:00:00 GMT</pubDate></item><item><title>Chaosradio 114: Software project management</title><link>https://laforge.gnumonks.org/blog/20060626-chaosradio-114/</link><dc:creator>Harald Welte</dc:creator><description>&lt;p&gt;
Tomorrow I'll again be participating in &lt;a href="http://www.chaosradio.de/"&gt;Chaosradio&lt;/a&gt;. This months &lt;a href="http://www.chaosradio.de/cr114.html"&gt;Chaosradio 114&lt;/a&gt; issue is about 
software project management, both in the proprietary and FOSS world.
&lt;/p&gt;</description><category>ccc</category><guid>https://laforge.gnumonks.org/blog/20060626-chaosradio-114/</guid><pubDate>Sun, 25 Jun 2006 19:00:00 GMT</pubDate></item><item><title>Upcoming Chaosradio show on encryption</title><link>https://laforge.gnumonks.org/blog/20060322-chaosradio-111/</link><dc:creator>Harald Welte</dc:creator><description>&lt;p&gt;
After quite some time of absence, I'm finally going to participate in
&lt;a href="http://chaosradio.ccc.de/cr111.html"&gt;Chaosradio&lt;/a&gt; again. The subject
of the upcoming show is encryption for personal use, mostly focusing on hard
disk and email encryption.
&lt;/p&gt;</description><category>ccc</category><guid>https://laforge.gnumonks.org/blog/20060322-chaosradio-111/</guid><pubDate>Tue, 21 Mar 2006 19:00:00 GMT</pubDate></item><item><title>22C3 is over</title><link>https://laforge.gnumonks.org/blog/20060102-22c3-over/</link><dc:creator>Harald Welte</dc:creator><description>&lt;p&gt;
Two days ago, &lt;a href="http://events.ccc.de/congress/2005/"&gt;22C3&lt;/a&gt; was
closed. This years incarnation of Europe's largest hacker conference can be
seen as a full success. Some 3000 attendees, about 180 lectures, a 10Gigabit
Internet Uplink and our own /16.
&lt;/p&gt;
&lt;p&gt;
The video recordings have turned out fine.  We've had working WMV live streams,
and somewhat intermittently working MPEG2 and MPEG4 live streams, as well as
working OGG and MP3 audio streams of all four lecture tracks.
&lt;/p&gt;
&lt;p&gt;
For archival, we have MPEG2Video (5Mbit) as well as the original DV tapes, and
a FLAC audio recocrding.
&lt;/p&gt;
&lt;p&gt;
Looking at the tremendous amount of work that went into the A/V recordings, and
the fact that I'm involved with the A/V team since seven years, I'm actually
thinking about looking for some other area where I can get involved next year.
&lt;/p&gt;
&lt;p&gt;
My two lectures (on OpenEZX and librfid/libmrtd) went fine, even though they
both had very little preparation ;)
&lt;/p&gt;
&lt;p&gt;
In the next couple of days I'll be cutting the fourth day of the video
recording, and then slowly getting back into netfilter and OpenEZX related
development.  Oh yes, and I'll also promise more blog updates.
&lt;/p&gt;
&lt;p&gt;
For some strange reason, my git tree seems to have become corrupted over the last two weeks, so I first need to sort this out before getting any reasonable work done.
&lt;/p&gt;</description><category>ccc</category><guid>https://laforge.gnumonks.org/blog/20060102-22c3-over/</guid><pubDate>Sun, 01 Jan 2006 19:00:00 GMT</pubDate></item><item><title>22C3 preparations</title><link>https://laforge.gnumonks.org/blog/20051222-22ce-preparations/</link><dc:creator>Harald Welte</dc:creator><description>&lt;p&gt;
The main reason why this blog has been so quite since my return from Bangalore:
I'm spending every free minute in preparations for &lt;a href="http://events.ccc.de/congress/2005/"&gt;22C3&lt;/a&gt;, the annual Chaos
Communication Congress.  As usual, my job is to take care of the audio and
video recording and streaming.
&lt;/p&gt;
&lt;p&gt;
So for the last days I've been hunting numerous bugs related to this, mainly in
ffmpeg, but also radeonfb, vlc, Debian ffmpeg / x264 packages, etc.
&lt;/p&gt;
&lt;p&gt;
I'll be back on track after 22C3 is over. More blog updates then, I promise.
&lt;/p&gt;</description><category>ccc</category><guid>https://laforge.gnumonks.org/blog/20051222-22ce-preparations/</guid><pubDate>Wed, 21 Dec 2005 19:00:00 GMT</pubDate></item><item><title>Lecture on privacy and data protection issues at Potsdam University</title><link>https://laforge.gnumonks.org/blog/20051109-privacy-dataprotection-potsdam2005/</link><dc:creator>Harald Welte</dc:creator><description>&lt;p&gt;
Today I had the honour of holding a guest lecture at the &lt;a href="http://emw.fh-potsdam.de/"&gt;Institute of European Media Studies&lt;/a&gt; of the
University of Applied Sciences in Potsdam.   The lecture was entitled "Privacy,
Data Protection and Surveillance - Risks and side effects of modern
communication technology".
&lt;/p&gt;
&lt;p&gt;
To my big surprise, the lecture was very well received, and members of the
institute have suggested that they are interested in some follow-up lectures on
other topics such as copyright / software patent / GPL issues.
&lt;/p&gt;</description><category>ccc</category><guid>https://laforge.gnumonks.org/blog/20051109-privacy-dataprotection-potsdam2005/</guid><pubDate>Tue, 08 Nov 2005 19:00:00 GMT</pubDate></item><item><title>Big Brother Awards 2005</title><link>https://laforge.gnumonks.org/blog/20051028-bigbrother/</link><dc:creator>Harald Welte</dc:creator><description>&lt;p&gt;
Today, the &lt;a href="http://www.bigbrotherawards.de/en/2005/"&gt;sixth "Oscar
awards for data leeches"&lt;/a&gt; will be awarded.  The BBA is a "negative award"
or "anti award" for persons, organizations, companies, government agencies that 
disrespect civil liberties, data protection and privacy.
&lt;/p&gt;
&lt;p&gt;
I've always been a big fan of those awards (which are now even awarded in a
number of countries outside of Germany, too).  They provide an excellent
opportunity to publicly point at (and rant about) those who further restrict
the [digital] freedom of individuals.
&lt;/p&gt;
&lt;p&gt;
This year I'm going to be present at the ceremony for the first time.
&lt;/p&gt;</description><category>ccc</category><guid>https://laforge.gnumonks.org/blog/20051028-bigbrother/</guid><pubDate>Thu, 27 Oct 2005 19:00:00 GMT</pubDate></item><item><title>Chaosradio on ePassport and Biometrics</title><link>https://laforge.gnumonks.org/blog/20050928-chaosradio-biometrics/</link><dc:creator>Harald Welte</dc:creator><description>&lt;p&gt;
Due to the importance of the subject, we will do the second &lt;a href="http://chaosradio.ccc.de/"&gt;Chaosradio&lt;/a&gt; show
this year dedicated to electronic passports and biometric identification.
&lt;/p&gt;
&lt;p&gt;
Germany will issue them starting with November this year... so now is about the
last possible time to apply for a brand new, shiny, glossy, cheap "old-style"
passport that doesn't contain any biometric information.
&lt;/p&gt;</description><category>ccc</category><guid>https://laforge.gnumonks.org/blog/20050928-chaosradio-biometrics/</guid><pubDate>Tue, 27 Sep 2005 19:00:00 GMT</pubDate></item><item><title>Chaosradio 105: Embedded Systems</title><link>https://laforge.gnumonks.org/blog/20050831-chaosradio/</link><dc:creator>Harald Welte</dc:creator><description>&lt;p&gt;
This month's &lt;a href="http://www.chaosradio.de/"&gt;Chaosradio&lt;/a&gt; show (held
today) will be looking into the plethora of embedded devices that are present
in todays world.
&lt;/p&gt;
&lt;p&gt;
CCC "residents" will be Tim Pritlove and myself.
&lt;/p&gt;
&lt;p&gt;
The main focus will be on consumer embedded systems, especially those running
free operating systems and those with good "hack value".
&lt;/p&gt;</description><category>ccc</category><guid>https://laforge.gnumonks.org/blog/20050831-chaosradio/</guid><pubDate>Tue, 30 Aug 2005 19:00:00 GMT</pubDate></item><item><title>Chaosradio on Electronic Health Card</title><link>https://laforge.gnumonks.org/blog/20050726-chaosradio-ehc/</link><dc:creator>Harald Welte</dc:creator><description>&lt;p&gt;
Today I'll be moderating this months' episode of &lt;a href="http://chaosradio.ccc.de/"&gt;Chaosradio&lt;/a&gt; on the upcoming 
German Gesundheitskarte (Electronic Health Card, EHC).
&lt;/p&gt;
&lt;p&gt;
This is the latest incarnation of the ever-increasing number of large-scale IT
projects in public atministration.  Following-up infamous examples such as
TollCollect, the ALG2 software, INPOL-NEU, ELSTER, and last but not least the
RFID enabled electronic Passport.  And it will affect the data privacy and data
protection of even more German citizens than any of the beforementioned
systems!
&lt;/p&gt;
&lt;p&gt;
I'm very pleased to announce Thomas Maus (ThoMaus), one (if not the) most
prominent critical experts on the EHC as a live guest in the radio studio.
&lt;/p&gt;
&lt;p&gt;
This subject is actually one that I think fits best into the idea of
Chaosradio: Technical, but with vast implications on society.  
Even more than my last "favourite" data retention, but less than the upcoming
Chaosradio show on "voting machines".
&lt;/p&gt;
&lt;p&gt;
From my point of view there are too many issues currently at this border
between technology, politics and society that need to be adressed.  Too many to
just talk about geeky technological stuff that is certainly also happening and woth covering it in Chaosradio.
&lt;/p&gt;</description><category>ccc</category><guid>https://laforge.gnumonks.org/blog/20050726-chaosradio-ehc/</guid><pubDate>Mon, 25 Jul 2005 19:00:00 GMT</pubDate></item><item><title>Chaosradio 100: Energy consumption of the IT industry</title><link>https://laforge.gnumonks.org/blog/20050330-chaosradio-energyconsumption/</link><dc:creator>Harald Welte</dc:creator><description>&lt;p&gt;
Today we again had our monthly &lt;a href="http://chaosradio.ccc.de/"&gt;chaosradio&lt;/a&gt; live show.  The subject that we picked from the list of suggested topics, and it definitely was worth doing a 3 hour show on it.
&lt;/p&gt;
&lt;p&gt;
Computers always get faster.  The downside of this is that they always consume
more energy.  From 1W of a 80386 to 15W of a Pentium I, we've now arrived at
more than 100W for the latest PC CPU generations.  The PowerPC architecture was
quite promising for some time, but at least since the G5, power consumption is
almost equal with the Intel world.  About the only promising figures come from
ARM based CPU designs at the moment - something that you will find in PDA's and embedded devices, but not in desktop machines.
&lt;/p&gt;
&lt;p&gt;
Apart from the power consumption we're also talking a bit about the ecology in
general, like the amount of energy and raw materials required to build a new
PC.  It is quite considerable, especially taking into account that most PC's
are not used for more than two to three years.
&lt;/p&gt;
&lt;p&gt;
In case you're now interested (and understand German):  A recording of the live is available for &lt;a href="ftp://ftp.ccc.de/chaosradio/cr100"&gt;download&lt;/a&gt;.
&lt;/p&gt;</description><category>ccc</category><guid>https://laforge.gnumonks.org/blog/20050330-chaosradio-energyconsumption/</guid><pubDate>Tue, 29 Mar 2005 19:00:00 GMT</pubDate></item><item><title>CCCeBIT negative award for Bundesdruckerei</title><link>https://laforge.gnumonks.org/blog/20050315-cccebit-bundesdruckerei/</link><dc:creator>Harald Welte</dc:creator><description>&lt;p&gt;
The &lt;a href="http://www.ccc.de/"&gt;CCC&lt;/a&gt; has presented it's 2005 CCCeBIT
&lt;a href="http://www.ccc.de/updates/2005/cccebit2005"&gt;negative award&lt;/a&gt; to the &lt;a href="http://www.bundesdruckerei.de/"&gt;Bundesdruckerei&lt;/a&gt;, the formerly
state-owned now-privatized company in charge of printing passports in Germany.
&lt;/p&gt;
&lt;p&gt;
They are one of the strong forces in Germany behind the announced introduction
of biometric information in passports.  To understand this, you have to know
that the law still requires passports being produced by Bundesdruckerei, even
though they're now a private company.
&lt;/p&gt;</description><category>ccc</category><guid>https://laforge.gnumonks.org/blog/20050315-cccebit-bundesdruckerei/</guid><pubDate>Mon, 14 Mar 2005 19:00:00 GMT</pubDate></item><item><title>Our Agilest 54622D mixed signal oscilloscope arrived</title><link>https://laforge.gnumonks.org/blog/20050302-oscilloscope-arrived/</link><dc:creator>Harald Welte</dc:creator><description>&lt;p&gt;
Due to the generous donation of &lt;a href="http://www.tomtom.com"&gt;TomTom&lt;/a&gt;, we
were finally able to purchase a second hand digital oscilloscope.
&lt;/p&gt;
&lt;p&gt;
The 54622D has two analog channels with 100MHz bandwidth (200Ms/s) and 16
digital channels with 200/400MS/s.  The really nice features include stuff like
CAN-, I2C-, USB- and SPI trigger modes :)
&lt;/p&gt;
&lt;p&gt;
Let's see how this new toy is getting used to explore yet more technology...
&lt;/p&gt;</description><category>ccc</category><guid>https://laforge.gnumonks.org/blog/20050302-oscilloscope-arrived/</guid><pubDate>Tue, 01 Mar 2005 19:00:00 GMT</pubDate></item><item><title>Allnet donates network switches to CCC Berlin</title><link>https://laforge.gnumonks.org/blog/20050122-switches-allnet-donation/</link><dc:creator>Harald Welte</dc:creator><description>&lt;p&gt;
In very short amount of time, two 19" rack-mountable Ethernet switches went
dead at the &lt;a href="http://berlin.ccc.de/"&gt;Berlin Chaos Communication
Club&lt;/a&gt;.  
&lt;/p&gt;
&lt;p&gt;
The chairman of the friendly company &lt;a href="http://www.allnet.de/"&gt;Allnet&lt;/a&gt;
was immediately willing to donate two replacements.  Very kind of him :)
&lt;/p&gt;</description><category>ccc</category><guid>https://laforge.gnumonks.org/blog/20050122-switches-allnet-donation/</guid><pubDate>Fri, 21 Jan 2005 19:00:00 GMT</pubDate></item><item><title>Chaosradio 99 - Telekommunikationsueberwachungsverorndung</title><link>https://laforge.gnumonks.org/blog/20050122-chaosradio-tkuev/</link><dc:creator>Harald Welte</dc:creator><description>&lt;p&gt;
After about four months, the first &lt;a href="http://chaosradio.ccc.de/"&gt;Chaosradio&lt;/a&gt; radio show that I was
participating in.  Subject of the show was the telecommunications surveillance
act (TKUeV) and the corresponding technical directive.  Starting from 1st
January 2005, any "provider of telecommunication services" has to provide
lawful interception interfaces for government and police authorities.
&lt;/p&gt;
&lt;p&gt;
The big issue is that it isn't only about providers, but about anybody who runs
more than 1000 mailboxes on an email server, even if it is non-for-profit.
&lt;/p&gt;
&lt;p&gt;
If you're interested in the full show, you can &lt;a href="ftp://ftp.ccc.de/chaosradio/cr99/chaosradio_99.ogg"&gt;download&lt;/a&gt; it from the usual location on ftp.ccc.de.
&lt;/p&gt;</description><category>ccc</category><guid>https://laforge.gnumonks.org/blog/20050122-chaosradio-tkuev/</guid><pubDate>Fri, 21 Jan 2005 19:00:00 GMT</pubDate></item></channel></rss>