6
0
Fork 0

Toevoegen talks

This commit is contained in:
Michael Boelen 2023-10-31 12:52:53 +01:00
parent 0a3ed92cc9
commit aeb774bbe3
4 changed files with 110 additions and 1 deletions

View file

@ -113,6 +113,7 @@ event_schedule:
talk:
speaker: Michael Boelen en Patrick Reijnen
title: Oops, we overhauled the website...
link: talks/michael-boelen-patrick-reijnen-oops-we-overhauled-the-website/
- row:
columns:
- column:
@ -160,6 +161,7 @@ event_schedule:
talk:
speaker: Bart van den Akker
title: "HomeComputerMuseum: What we are and how we share the history"
link: talks/bart-van-den-akker-homecomputermuseum/
- row:
columns:
- column:
@ -203,7 +205,7 @@ event_schedule:
talk:
speaker: Carlo Meijer
title: "All cops are broadcasting: Obtaining the secret TETRA primitives after decades in the shadows"
link:
link: talks/carlo-meijer-all-cops-are-broadcasting/
- column:
talk:
speaker: Jan Jacob Pebesma

View file

@ -0,0 +1,20 @@
---
categories:
date: 2023-10-31T11:21:01+02:00
description:
layout: event-talk
slug:
tags:
- history
title: "Bart van den Akker - HomeComputerMuseum: What we are and how we share the history"
speakers:
- bart-van-den-akker
---
## Abstract
The HomeComputerMuseum is an interactive computermuseum dedicated to preserve and share the history of the home computer. It opened its doors in 2018 and grew to become one of the largest and most influential computermuseums in the world. The museum is completely independent of subsidy or sponsors and remains in business by offering unique data recovery services, helping people with a distance to the labour market and helping other museums to follow the same example as the HomeComputerMuseum. One could argue, we are an open-source museum. The talk is about why we exist, how we exist today and why the HomeComputerMuseum is important.
## Biografie
Born in 1982, first computer in 1986 and founder of the HomeComputerMuseum. Can talk for hours without boring people.

View file

@ -0,0 +1,28 @@
---
categories:
date: 2023-10-31T11:21:01+02:00
description:
layout: event-talk
slug:
tags:
- cryptography
- radio
- reverse-engineering
title: "Carlo Meijer - All cops are broadcasting: Obtaining the secret TETRA primitives after decades in the shadows"
speakers:
- carlo-meijer
---
## Abstract
In this talk we will discuss the radio jailbreaking journey that enabled us to perform the first public disclosure and security analysis of the proprietary cryptography used in TETRA (Terrestrial Trunked Radio): a European standard for trunked radio globally used by government agencies, police, prisons, emergency services and military operators. Besides governemental applications, TETRA is also widely deployed in industrial environments such as factory campuses, harbor container terminals and airports, as well as critical infrastructure such as SCADA telecontrol of oil rigs, pipelines, transportation and electric and water utilities.
In this talk we will discuss the radio jailbreaking journey that enabled us to perform the first public disclosure and security analysis of the proprietary cryptography used in TETRA (Terrestrial Trunked Radio): a European standard for trunked radio globally used by government agencies, police, prisons, emergency services and military operators. Besides governemental applications, TETRA is also widely deployed in industrial environments such as factory campuses, harbor container terminals and airports, as well as critical infrastructure such as SCADA telecontrol of oil rigs, pipelines, transportation and electric and water utilities.
For over two decades, the underlying algorithms have remained secret and bound with restrictive NDAs prohibiting public scrutiny of this highly critical technology. As such, TETRA was one of the last bastions of widely deployed secret proprietary cryptography. We will discuss in detail how we managed to obtain the primitives and remain legally at liberty to publish our findings.
This journey has involved reverse-engineering and exploiting multiple zero-day vulnerabilities in the highly popular Motorola MTM5x00 TETRA radio and its TI OMAP-L138 trusted execution environment (TEE) and covers everything from side-channel attacks on DSPs, through writing decompilers headache-inducing DSP architectures, all the way to exploiting ROM vulnerabilities in the Texas Instruments TEE.
## Biografie
Carlo Meijer is a founding partner at Midnight Blue and a PhD candidate at Radboud University Nijmegen (RU). His research focuses on the analysis of cryptographic systems deployed in the wild. He is known for his work on the security of so-called Self-Encrypting Drives (SEDs). Furthermore, he is known for breaking a hardened variant of Crypto1, the cipher used in the Mifare Classic family of cryptographic RFID tags. Finally, he co-authored research into default passwords in consumer routers as deployed by ISPs in the Netherlands. All three studies have uncovered major security shortcomings with widespread impact.

View file

@ -0,0 +1,59 @@
---
categories:
date: 2023-10-31T11:21:01+02:00
description:
layout: event-talk
slug:
tags:
- hugo
- website
title: "Michael Boelen en Patrick Reijnen - Oops, we overhauled the website..."
speakers:
- michael-boelen
- patrick-reijnen
---
## Abstract
What does it take to migrate a website that is 15 years old? And not just some website, but our most precious one!
In this talk, we look at how we redesigned and redefined our website. We will cover the technical design decisions, the importance of structure, and the technical components involved. The talk will include learned lessons and even some mistakes made along the way. Other topics include the (lack of) graphical design and a glimpse into the future. Why? Because this initial work is just the start.
Some examples include automatic image generation for social media, the use of workflows, documentation about the website (on the website) itself, and how you can help. All information is shared with one goal: at the end, you will know every possible secret about the website, except the secret keys.
Involved technologies:
* Hugo website generator
* HTML5 and semantics
* Style sheet processing (SCSS)
* Performance optimization
* Search Engine Optimization (SEO)
* Sitemaps
* IndexNow
* Integration with social media
* Automatic image generation
* Image format webp
* RSS and JSON feeds
* Structured data (schema.org)
* Nginx tuning
* Canaries
* Easter eggs?
Although this talk features the migration NLUUG website, almost all aspects will apply to any website migration or provide insights for new websites.
## Biografie
### Michael Boelen
Michael Boelen worked previously as a consultant for several Fortune 500 companies like Philips and ASML. In 2013, Michael started his own company CISOfy, focusing on Linux and UNIX security.
Next to software development, Michael is interested in technical auditing, system hardening, and compliance. He developed several open-source security tools, including Rootkit Hunter (rkhunter) and Lynis. Over the years, he created several websites and blogs, from raw HTML files to ones with PHP, Django, WordPress, and Hugo. Michael has a personal website, which is located at michaelboelen.com. Other projects include linux-audit.com, linuxsecurity.expert, and meereco.nl. Michael also enjoys woodworking, DIY projects, and chess.
### Patrick Reijnen
Om de kost te verdienen, is Patrick na bijna 26 jaar detachering bij vele bedrijven via Capgemini zo'n 3 jaar geleden overgestapt naar een vast dienstverband binnen de Kamer van koophandel. In zijn werk, en ook al tijdens zijn studie, is Patrick altijd bezig geweest met Open Source en Open Standaarden, zowel vanuit hobby als professioneel. Open Source en Open Standaarden staan niet op zichzelf en moeten, zeker in een professionele omgeving, ingebed worden in bestaande infrastructuren met vaak de nodige legacy en proprietary software zoals Microsoft gebaseerde omgevingen. Vanuit rollen als beheerder, projectmedewerker, ontwerper, en architect heeft Patrick bij vele bedrijven meegewerkt aan deze inbedding.
In zijn vrije tijd is Patrick een aantal jaren bestuurslid en voorzitter van NLUUG geweest. Tegenwoordig is Patrick actief in een aantal NLUUG commissies.
Tijdens zijn studie en de periode daarna is Patrick betrokken geweest bij het schrijven van de Linux Hardware Howto en de Term Howto, en was hij actief binnen het Linux Counter project.