Video summary
The 28c3 Security Nightmares session provides a critical retrospective and forward-looking analysis of security trends, contrasting past hyped threats like Bluetooth range limitations or internet refrigerators that failed to materialize as feared against emerging realities such as the rise of startups leveraging location data. The discussion highlights severe risks associated with Internet of Things devices, where remote combustion incidents could cause real-world fires in appliances like printers and fridges, while also noting a significant drop in black market prices for stolen credit card details and account access. In response to these challenges, German authorities aim to eliminate zombie PCs through new initiatives, yet the session points out that government web servers are still cheaply available on illicit markets and that major failures continue globally, such as Israel's resident database compromise or Austria's struggles with health card data leaks following scandals involving flawed e-government models.
The conversation extends into the realm of mobile technology and cloud infrastructure, exposing vulnerabilities where users unknowingly accepted spyware like Carrier IQ under false pretenses to improve network quality, while carriers began removing it due to controversy. The structural integrity of internet security is questioned through the lens of SSL certificate authorities described as broken by design, allowing potential government infiltration, alongside concerns over IPv4 depletion which necessitates NAT usage despite delays caused by corporate inventory issues like Xerox's stockpiles. Furthermore, the session addresses the evolving nature of cloud computing, describing accessible botnets with superior support compared to shadowy alternatives and raising ethical questions about inter-cloud non-attack pacts between major providers following a denial-of-service attack originating from Amazon Cloud that targeted congressional networks.
Looking toward future developments in 2012, the speakers warn of widespread broken locks due to manufacturers' slow update cycles for chip standards like My Fair Classic, even as new technologies propose storing genetic data on identity documents or implementing DNA-based locking systems. A cultural clash emerges between hardware industries preferring physical replacements over software updates and users fighting to maintain ownership against devices becoming mere usage-rights vehicles restricted by corporate "city-states" controlling OS choices via UEFI/BIOS settings. The segment also touches upon privacy clashes involving self-conversations recorded in cars with AI assistants like Siri, which raise legal questions about telecommunication definitions, while battery life remains a limiting factor for surveillance applications despite rapid technological advancements and the ongoing transition challenges from IPv4 to IPv6 that could lead to network disruptions or expropriation scenarios.
Read the full video transcript
Yes, good
evening. As always, the last event
of the congress, "Security Nightmares."
We want to talk again about what
happened in 2011 and what will
happen in 2012. This time we have
a small change
because after 12 years, it's time for a bit of variety. Well,
not really a change. If you
look at the title, it says "
Brainstorming and
Hall Discussion." That's how we started, very well.
I think the
hall discussion aspect has diminished a bit
over the last few years,
at least that's my impression. And
we want to reintroduce it more strongly now.
Which means you can already start thinking about
what you
want to laugh at next year and what you think is likely to happen,
and slowly make your way
to the microphones.
The rule is a short
statement. So, one of the reasons why
we moved away from the discussion a
bit was that there was
obviously something in the
drinking water that led to such long
monologues.
And since we now—well, I
just got the consumption figures from MTE,
so I assume that most people are
drinking Mate— We've been
drinking and there's no drinking capacity, so
we assume that
this time you'll be able to limit yourselves to
very short, concise statements
at the microphones. Yes, we're
also counting on the fact that it's now four
days long and people simply wo
n't have the stamina for long
statements on the fourth day. This is the
second event; we notice this every
year with organizers. We also assume
that it won't be the last,
although the May calendar says
December 22nd next
year. So we simply assume that
it will
obviously be a mistake
because of the implementation.
The concepts will be fine, but
the implementation will, as always, have
errors. The agenda is, as always, about
the security nightmares we want to
talk about—not always seriously,
just the ones
we want because they might
change something and shake things up. We've
seen some interesting things
this year where you'd actually say, "
That was obvious anyway,"
but just because it's now
become clear in a certain way,
they will change things and then, of course, perhaps
think about
which security nightmares we don't want.
Because, as always, be forewarned and be
prepared. To be forewarned, where
being forewarned perhaps simply
means not being surprised, not being caught off guard
by
anything. That's why we do it this way.
And so, the general impression
we had looking back
on the year is that it's always moving forward, right? So,
really, always onward,
but actually not really forward, just
onward.
Exactly, let's do a little
audience survey. For whom is this
the second Security Nightmares
event? Okay, and who has secretly
seen some of the old recordings? Uh,
fans. Okay,
good, then the
fifth and the first. Okay, yeah, not
so bad. So, we
had a few twelve-year-olds here, but
I think less than a handful. A
few more five-year-olds, but that was only about
50 or so. And
we also had about 50 one-year-olds here. That
means the rest are less than 5 years old,
but more than a year old. Okay,
Melfeld, exactly. Good,
then we'll begin. As a
special highlight this year, we have
a retrospective on the year 2001
because, even if it might be surprising, that
's now... Ten years
ago, and we didn't accidentally see
all the
slides. Yes, we talked a lot about
wireless in 2001, like Bluetooth, Wi-Fi, and so on. Yeah,
that was the total hype. Or they talked
about Personal Area
Networks, and then what
came next: Body Area
Networks, City Area
Networks, and so on. And then the networks
always had these
three or four circles around them on the slides. Yeah, and it
was always funny how they looked like
circles, right? So you always
thought, so nicely enclosed,
finally. I mean, this
thing, this idea,
radio waves stop at the receiver.
Exactly,
that only goes 5 meters, definitely no further. Not even
if someone's holding a
Pringles can.
Yeah, internet refrigerators. Who among
you has an
internet refrigerator? They promised us
internet refrigerators. Well,
I actually
saw some once, but it
was really just that the
refrigerator had internet, for
its own amusement or something like that.
But somehow,
no one has
discovered how to actually do something like that yet.
Luckily. Yeah, that'll come with
smart... uh...
with. The smart home, no, with the
electrical ones, with these
smart meters, will
internet even reach the refrigerator? Yes, although
I'm somehow getting into these, so smart
meters, we'll get to that later. Yes, we've
already had printers this year,
oh, we have them, they're coming, yes,
excuse me, I skipped the
remote heating meter reading
because we
wanted to skip it, because there was absolutely nothing to
say about it, just a totally boring topic that you don't really need to deal with. There's absolutely
no need to
look into it any further.
So, printers/copiers with
LAN, there was this, that, a
lot has happened in the last 10 years, but
this year we had the highlight with
spontaneous remote
combustion. That's really
extreme, I think, when suddenly
the internet reality enters real
reality through flames.
So, especially if it doesn't just happen in the
basement of the nuclear control room,
it happens right there on the desk, right?
Exactly, so we know what's
coming when
internet refrigerators are finally available. Then it
depends on the content, what happens then? No, well, there
's a heat pump in there. It doesn't
pump, it can of course also
pump backwards, but then I don't get an
automatic oven, so
the feature is then called
pre-cooked. Yes, we were already dealing with mobile phones back in
2001, you
know, mobile phone premieres are like
the running GCK of this show. We
actually predict every year that
the mobile phone Trojan will
come, the big one, exactly. And
looking back, the
real joke was that we thought
Nokia and Microsoft would last that long, it's
amazing, isn't it, how
quickly something like that can happen. So, I
mean Nokia, we thought about
10 years ago that Nokia would somehow
start producing rubber boots again
or
something because it might be more profitable
than making phones. Yes, but 15
years ago there was a company—oh, now comes
the age test—15 years ago there was a
company that advertised itself
with "We are the past, present and future
of network computing," and they were
even right at the time. Who remembers
that? No, no,
what are they today? Did
n't they
buy Linux? I think they're
essentially patent holders. Yes, is that...
Right
answer, good, yes, the SA, the thing with
the smartphones, um, we thought it would
happen with smartphones.
Who among you has ever had a
mobile phone Trojan on their
phone? Okay, wrong, wrong question. Who
among you has a friend who has ever had
a
mobile phone Trojan? Well, actually,
two or three. If the
story is funny, then the
microphones are good. And
family support cases about mobile phone
Trojans. Who here still doesn't have a
smartphone? That's practically a
quarter. Not so bad. Do
you feel
safer then? How nice for
you. Yes, that's what you
believe. Yes, one of the things we
thought would happen in 2001 was location-
based spam. So, you're walking around, you go "
B" and up
ahead you can
buy some coffee or something. And
interestingly, it hasn't really come true so far. There are
a few
startups, like forosquare, that are working
hard to finally make this
prediction come true. So, we
also look at it with great sympathy because we
always like to be able to
say so, even if it's 15 years
later. Yes, back then we thought the
The carrier will be Bluetooth, that
obviously didn't work at all, but
now there's low-energy
Bluetooth, Bluetooth 40 or Low, yeah,
but I don't think so, no, no, if anything, it'll work
via the central network. More
hope for near-
frequency
NFC, so in my opinion,
NFC offers a lot of hope, so
you can definitely say there's a
lot to be gained there, especially with
the NFC Android stacks. You can
certainly look at a lot if you have a long winter
afternoon to spare. It's
also funny, the
story isn't about a long
winter afternoon, or um,
I was so bored on Sunday
afternoon, but the story is
now my girlfriend left me
and I was in a bad mood.
Yeah, and with this NFC, you can also
somehow get
the money to do something about the
bad mood,
me. By the way, when was that about putting
an RFID chip in every
banknote?
Yeah, that was in 2001, banknote chips, banknote chips.
Nothing happened,
or something. Obviously, there are still
enough people who
want real cash or something. Yeah, one
thing we had in 2001 was
GPS. Boofing and
yes, TMS boofing, GM boofing—both
happen. We had an
impressive use case this year.
Not threatening to shoot down drones in the
desert or over water, because the last
rumor was that they
had, and well, yes, TMS boofing
has also been produced here and there, even
a few
years ago at the congress. But that
implies that such
a drone from the Americans has a sensor
they trust less, or I
mean this drone from Per for €100, it
has an ultrasonic sensor facing downwards. Yes,
and if you were to install GPS
and then say that GPS is more accurate
than the
ultrasonic sensor, well, then at least it would
n't fly away over clumps of grass like it does now.
Okay, you have to
set priorities, yes, but well, yes, as for how
exactly this whole boofing story went down, there are still
several stories and
rumors. The actual
truth probably won't be known, at least not for a
while. They say it takes about
15 years for it to come out, and probably
no one will care anymore because it's totally normal for
some drones to be boofed. police drones or
similar things get away and/or fly somewhere else,
fly long distances where they
shouldn't really be flying, yeah, so maybe we'll finally get one, um,
anti-drone, yeah, also Malchen, yeah, another
hobby of ours
was cross-platform worms, there were
some interesting
approaches that didn't really
materialize until
JavaScript came along,
and there's still a
lot of hope there, yeah, but not that, yeah,
not an operating system, or so
that was a bit optimistic,
I think, yeah, maybe, yeah, and 25
years ago the first PCVUS was developed as protection
against pirated copies, you have to remember that again, that's
funny
because
then 5 years ago there was this Sony
rootkit story and this year there was
Carrier
IQ, so that's not against piracy,
but of course for, what do
you call it
today,
quality assurance, and then there was
this scare, yeah, with this
gaming platform
thingy, where they, where, some kind of game
rootkit, Origin, oh yeah, Origin, exactly, yeah, the one that
was there at first, but then they did, they did a lot of
things
They were just relying on
people installing it anyway
because they want to play Halo, as always.
Mine was another classic
example of how
the gaming industry always manages to ensure that
pirates get much better
software quality than if they buy it.
I've always seen this when
Fefe
starts saying around Christmas, "Yeah, I'm going to buy
a few more games." Oh God, now
he'll probably be in a bad mood for weeks. I already
know that.
You can just leave it at that.
Then, exactly, the
internet normality comes
from figures from 2011 and partly from the end of
2010, just to show how
things are right now on the
internet. You can now
buy normal website hacks for $9.99.
Account access data costs between $80 and
$700 depending on
creditworthiness. The same goes for credit card data,
$2 to $90 depending on creditworthiness. Recently,
the price was high again due to
oversupply. That's
exactly what I found funny. Oh, he
has some for 10
cents, and how much is that? How much is there,
uh, 10 cents for Visa Gold? We
have
inflation, that means we're talking about
pharmacy prices here,
you say, or maybe they're
just quality providers you've chosen. Then
I found
the purchase via
straw man funny, $100 if you don't
enter your own address with the stolen
credit card, but that of a
straw man. Because I think we didn't have the
topic of straw men for internet purchases
in our list, in our
preview for new
professions. Yes, that was an oversight. Yes, yes,
I also found an
ATM nice, so a special
ATM with extra
features, but otherwise in the original for
35,000, and please place it wherever
you
want.
Yes, and there are still people who
pull things out of the
wall.
Yes, also exciting. Government web server.
Rest, the account on a silver platter for
49,
but more like
smaller countries,
or I think it was the US government
web. Yes, yes, there's nothing to be gained there, right? Oh,
you, so account access data up to
$700, government route.
500, they're just in debt, right?
Maybe more than that, just a decorative item, a luxury item, a luxury
item, yeah, yeah, you have to, what should
I take now, the iPad or the USB drive?
Okay, yeah, the infection rate is supposedly
relatively high, no idea, does this
number come from an
antivirus developer
or something? Yeah, of course, sure, sure. So,
31% of all EU citizens had to deal
with a virus in 2000 or what, in 2010.
That fluctuated, of course.
Germany was, I think,
22%, which I found rather high or something.
But then there's also the other
number, namely one government
cyberattack per week, and according to our
Interior Minister, those are the
successful ones, so one successful
government cyberattack per week.
So, if we calculate backwards from the number of successfully
installed Truana,
I think
both... You mean they're parting out as they
plug in? Yeah, that may be. No, the question
I'm asking myself is, of course, what does "
success" mean? How far did it go to
call it success? Does that mean that an
employee's computer somehow
registered with the botnet command and control?
Has or what, well, probably, so
yes,
and we're supposed to have between 350,000 and
500,000 zombie PCs in Germany,
according to the BSI, but of course that's supposed to be down to
zero in two years because of the AB
Center. Yes, I actually think it's good that
my government is somehow preparing for
the zombie apocalypse.
Exactly, and because it
's so terribly bitter, maybe there will be
extes with a BSI engraving or
something. And because it's so terribly bitter, there's also
the fact that in 2011 there was only one
mobile phone manufacturer that
could do patch updates over the air without having to consider carriers,
and actually did it.
No, there's nothing to
applaud, there's nothing to applaud,
that's obviously far too few. And
I would have, and two others
at least have the infrastructure to do it too,
and at least one would have understood,
I think. Think for a second,
think for a second. What really gets to me is
that it's
not Microsoft. Yes, the popular category "
government progress." Yes,
you know how we measure that, so
government. We measure e-government progress
in the
past primarily by looking at
how much
data a government has lost.
The logic is quite simple: if there's more
data, more data is lost. So, the more government you have, the more
data is lost, meaning more data
loss.
Logically speaking, progress... The clear winner
this year is definitely Israel, as
their complete resident
registration database (ABH) has been compromised.
There were rumors at one point
that the complete census data had been
lost in England, but that
apparently wasn't the
case, or at least they were able to
successfully contain it. And since
the voting machine massacre in Latvia in
recent years
was quite excessive, and we also have
a setback in e-government,
Austria
has also issued a
corresponding ruling. They are
now moving away from
these countries and trying to implement it
elsewhere. So, it's clear
that if it no longer works in countries like
Germany and Austria,
you have to put
the
junk somewhere. And now, as we've recently seen
in Russia, I was shown
pictures of Mr. Putin yesterday. The election,
where his side went into this thing that looked kind of
shredder-like, we thought, well,
maybe it was just
consistent, it shredded right away,
but no, it's an
optical scanner,
so that means you throw it through
this optical scanner into the ballot box
and then you have an electronic and
paper result. But there were also
touchscreen voting machines, which means,
interestingly, the OECD
department that was actually supposed to take care of the
election review had absolutely
nothing to criticize at this point.
So we can definitely
hope for further progress, if
not in K, but definitely around it.
Yes, cyberweather, we've already had that, so quite
clearly we had
an incredible number of cyberweather
exercises this year, and
they were all a complete success. Yes, that's
no mistake, which is why there were so
many reports about the
complete success of these exercises. What exactly they practiced
remains a bit
unclear. I have this
idea of something like that: standing in front of a
large map of Europe, pushing
small plastic figures around with
virtual bombs,
and digital
tanks, are there? A pincer attack via
USNET or
something, yeah, but we're still waiting, as I said, for leaks
of the
images. Then there were those... uh,
yeah...
last year, at this point, we had
this topic: Research in Motion versus
India, Saudi Arabia, what was that... nought
Arab something, Emirates, and things like that. Of
course, by now
you can put any government on any
platform where
information is exchanged. But
the only ones who still managed to
shoot themselves in the foot again, without any PR issues, were Research in Motion.
Because they managed to
produce headlines in
England like that they
will help suppress the protests there and the
organization of the same via Blackberry
Messaging, uh,
yes, to suppress them, to suppress them,
yes, so the PR department
of RIM must have real
specialists sitting there,
the health card was enforced, um,
that means there is more data to be
obtained, exactly, progress, that is
progress,
h, but look, you first have to
enforce such a platform, right? And then
people get used to it, then you can
build on that, then you can
build on that, and then the data can be
removed, exactly, that is
always the natural course
of things, and they had an innovative
story, I don't know, was it
confirmed that
actually on some
health cards of people who did not
submit pictures,
data actually ended up with the registration authorities, uh,
but wasn't it actually said
that the registration authorities do not store the
digitized pictures from the
identity card,
well, okay, so anyway,
we definitely have significantly more
progress to record,
if there is already a network
of health insurance companies and Registration authorities exist
to guarantee access to images;
one can only
speak of progress there, yes,
one has to keep an eye on it, no question, certainly much is still to come.
Customs is also thoroughly
digitized, but then there was this
small incident where their system, called
Patras,
fell victim to a somewhat lengthy hacking attack where, among other things, data
on GPS tracking of suspects was to be
obtained. So it was obvious,
if one can believe the reconstruction of this
attack, that it was rather extensive, something like
Trujana on an employee's computer
and from there the various
servers owned and
read along for quite some time. Also very successful. This
year the Federal Finance Agency was involved in
digitization, but we had to
point out a tiny little problem to them, although to
this day we are not really sure if it is not
a feature. No,
I thought you could
get loans for that, especially for
people in higher government offices. Do you think so
or not? Yes, so
it was probably just a special
access route. Oh, we now have
a Cyber Security Council, that's also a
card with Plastic figures and stuff like that, which
I took down again,
we'll save for now. The
Data Security Foundation, data protection, data
protection foundation, not
much has happened there yet. Yes, although you could
perhaps call that progress
because they
rammed a path and now do absolutely
nothing. So, they did do something, but nothing happens. It
's good if nothing happens in the area of
data protection for
progress, you mean? Yes, yes, yes. There have
also been setbacks.
Internet radio, unfortunately, didn't work out.
Elena also
failed provisionally. ePerso, unfortunately, also
failed provisionally for now, but
ePerso could still come. It's still a
candidate
for... yes, as I said, Warcuter in Austria. The
Constitutional Court is obviously
not very open to the idea of progress in e-government.
Another very nice product,
namely the stat trojan, which ca
n't really be used right now. A
serious setback for
government.
And yes, open data, yes, very, very bad
news, probably. There is a
declaration of intent from the
federal government regarding open data, i.e.,
government open data, like data.gov in
the USA, to be transferred to the stat in Germany by 2013.
Bring it up, and
if you haven't looked at data.gov yet,
then you should, it
's extremely interesting. Rumor has it that he started something
in the US
three or four years ago,
and it essentially
helps the authorities themselves
because they no longer have to
ask another agency if they
can have their data, and then
the political games begin. Instead,
they now have to export all their data to
data.gov and can
then import it from there.
We now have this letter of intent,
which is also good because then you don't have to do
anything for the time being.
What we don't have is a right to
a machine-readable government. Yes,
we still don't have that. And
so one of the things we actually
want, along with this
open data thing, where it's still a
bit unclear what the
real results are, is
actually a license that ensures
that the results are made just as open
as the data. Because currently,
we have the situation that with all
open data initiatives where there is...
Real estate data and similar information
primarily benefit people, specifically those who already
benefit economically within this society. Therefore, if
such open data
initiatives are to be implemented, they should be tied to a license that
ensures, for example,
that the results
obtained from computing this data are
available to everyone, such as a CC attribution and derivatives license
. When I saw goov back then, I
thought, "Oh wow, yes,
in two years at the latest, we'll
see incredible things because all the
data will be there, everyone will be able to access it,
and then there will be enough
statistics freaks
who will absorb all of that and then
tell the United States government things they have
n't even come up with
themselves yet. And that will
catapult them so far ahead that we here
in Europe will be left completely in the dust."
That's what I thought.
And then nothing happened in the
last four years. Now, of course, you can
excuse that by saying, "Yes, they
still have to
normalize and harmonize everything and agree on
all the units
and whatnot."
But I think what I want to see is so that when you have to
ask, "What did you actually
do with the data?" I want to
see which IP addresses,
which data, and how often they
query. That also has to be published.
Yes, regarding data crimes, uh,
yes, what was very common this year was... well, getting
away... Excuse me, I
have one more setback we should
n't leave unmentioned. A
terrible setback! We still have
this serious security vulnerability because
we don't have data retention. It's an
unbelievable
step backwards that really shouldn't go
unmentioned. Just the
potential for data loss alone—what's that? It's
truly
regrettable. One can only complain about it,
which some of our politicians are
doing. This year,
all sorts of databases have been compromised. It's practically de rigueur these days
when
linking to hacked websites, not just the
page itself, but also
the entire data set.
And what's interesting is what's in there. These days, it's impossible to keep track of everything that's been
hacked. Another
webshop, another webshop, another webshop, another
webshop, another dating portal. Oh,
okay, there could be another webshop, another
webshop, another dating portal. And now there are
other statistics, namely the
relationship-finding statistics in
Germany. How many, what percentage of
all singles meet
online? I think we've
already exceeded 50%, haven't we?
I still have that in my head. I mean,
maybe I didn't get it from any source,
but over 50%, especially the
younger generations, or something like that. The other day
I was
sitting in a café and at the next table
two middle-aged women were talking
and they were saying that hanging out in bars is
n't worth it anymore, the guys there are
all totally jaded. You have to go
online. I've done that too. Oh wow, yeah, so that's where
we are now. Okay, so whatever
the number is, I have over 50% in my
head. If it's a third, that's still a
lot, and it's increasing.
That means people are all going into
these kinds of portals, posting
their stuff there. That's because
it's public,
they'll all hold back a bit,
but things get serious in
the chats, in
the private messages. Yes, private
messages, so in the initial contact
after reading some interesting
profile.
And that's going to disappear, okay? That means
you can tell everyone who's doing that, there will be more and
more people doing it,
and it's going to disappear. That
means we'll all
Regarding post-privacy passives, there are
still people who
actively engage in it; these are the
activists.
But then you get labeled a post-
privacy advocate.
The
argument is that once it happens to
everyone, it ca
n't be embarrassing anymore, and it can certainly be used against you.
The interesting realization is that
there are always people who say, "I have
nothing to hide." Right? You
certainly don't have anything to hide, or
never have. Who wouldn't I be hiding from? If I were
sitting here, would I have something to
hide? The question is
always, "From whom?" And we will have to
discuss this more intensively in the near future because what's
behind it all is, of course,
the question of power. Who has
the power over this data? Who
concentrates it? Who can access it?
And
what are the consequences?
This very question arose
with the topic of Carrier IQ, the
mobile phone spyware, which has sparked lengthy debates
about what it actually
spies on, what data is
transmitted, and why. And what
I found interesting about it was that my
American friends
occasionally made the accusation, "Yeah..." Well, don't be so silly.
If they did
n't do that, they would
n't be able to improve network quality. That's what they were saying.
The
last time I was in the US, there were these
huge posters advertising "Now with fewer dropped calls," you know,
for
fewer dropped calls. The
last time I had a dropped
call was when I was going 180 km/h on the
highway and entering a tunnel.
Maybe the
problem lies elsewhere, and not in the fact
that this
software hasn't been installed on mobile phones in Europe yet,
but possibly in
shoddy infrastructure.
Yeah, I definitely found
the reaction interesting, that there were apparently
a lot of
people who just blindly
accepted it, saying, "Yeah, that's just how it is, that's how it has to be,
because otherwise
the carriers can't improve their networks." It's
fascinating, though, that you can see
they all totally
need the Carrier IQ software,
that they're all so attached to it.
No, that's not true at all.
Sprint is just dumping it everywhere now.
The network quality will
definitely plummet. Yeah, tomorrow,
exactly tomorrow. Yeah, well,
we don't need anything. To continue,
SSL certificate authorities have
fallen left and right, and uh, I
think we'll get to that in
a bit more detail later. I don't know,
we'll get to that later. So, the ones
I'm talking about, SSL, are kind of broken
by design, and uh,
now they've made it a total disaster.
But it only really became a
total disaster when
not only the governments that already
own and infiltrate these certificate issuers gained
access,
but suddenly Iran did too. At that
moment, everyone realized, oh, now
it's really
broken, because now the
others, who actually... well, the principle
behind it is... uh, it's
abbreviated in the intelligence world
as "Nobody But Us,"
and something similar seems to have been at work with
these SSL certificates as well. In
any case, it's clear that
all these PKI structures... yes, we
built on pretty much quicksand.
And the interesting question that concerned us was,
these are systems
broken by design, with some kind of
central authority. One of the
last major systems that fell into this
category was
GSM, so also kind of flawed from the beginning,
so that the
government could somehow eavesdrop. SSL was also
broken by design from the start. If you
look at how the
development of SSL and SSH
diverged, SSH was developed by the Nords
so they
could log into secure machines.
SSL was designed in a way that allowed them to
simulate security, which could then be
suppressed or hidden if needed. And what
we were wondering about, but have
n't quite figured it out yet, is what
the next broken-by-
design technologies will be. Does
anyone have any
ideas? Tetra is already broken, isn't it? Well,
Tetra Crypto is
just a derivative, isn't it? No one has any ideas?
Well, it's broken if no one
uses it. You mean broken in this
case. It was definitely one of the things we're looking at this year,
because it was a
fairly large-scale,
extensive attack
whose consequences still haven't been
fully resolved. What was the situation in the
industry? Did
people buy new tokens?
You don't need new
tokens, there wasn't a problem with the old ones.
Oh, so there
was no problem, yes, but they
still shipped new tokens starting in December
because they had a better design, I mean,
nicer plastic, or no,
the old ones weren't broken, and the
new ones weren't broken either, so there was absolutely
no problem. Did
n't you read the press release? I
read... ah, there was no problem. Okay, so
everything, but there were still new tokens.
So there was still a point in time when
new tokens were shipped,
but no problem.
Yes, that's good. Problems are always
annoying, aren't they?
It was, it was, it was... well, yes, well,
anyway, they never sent the people
to the crisis PR training because
none of them were there, or they
still have the folder shrink-wrapped on the
shelf and never
looked at it and then could
n't find it in the rush or something. You mean they went there
and were just drinking and chatting?
Yeah, sure, what to do at the training, right?
Yeah, T Stream
NAG on the
internet, that thing with the airgap, or that thing
with the
airgap. Has anyone ever seen an airgap system?
Yes, yes, I have. Yes, yes, good, yes, okay, fair enough.
Has anyone ever seen Ergt systems
that don't Ergt
The question of whether airgap is valid was very
justified, but I don't think Wi-Fi counts
as
airgap. Does anyone know someone who's
seen an airgap system that
wasn't really airgap? Well, I'll
keep all that to myself. Yeah, those SCADA numbers,
or that was probably something like that.
Yeah, the technician always has to go there to
reboot it. Ca
n't we at least put a tiny little
button on it? And then there was that
great case where they were
ventilating for five days
because the water
pump control of some
waterworks in the USA said SCADA attack.
And then it turned out that it was
just the technician who
logged in from his vacation to
check if everything was
okay
from the
internet cafe. I think, I think
he was on vacation in Russia, so I guess it
's a cyberattack. Yes, bring
out the tanks, cyberattack!
Well, yeah,
now I'm so torn.
Or I initially thought we'd get
a round of applause. Microsoft
shut down Autoran for XP this year after all. Yeah, so... A
round of
applause, and now you can all shout out
your hatred again that it took so long.
Oh yes, then we have to point out
the biggest phishing campaign ever. You
might have come across it
as Verified by Visa or Mastercard 3D
Secure. Look at those pop-up
windows that keep appearing and
look so incredibly fishy.
It actually
happened to me. I was just about to
buy something from a webshop,
and then I thought, "How do I show this?" Oh,
credit card, no problem. So
I clicked here, and
then this thing popped up that was
somehow tacked onto the website with those stupid
flashing things.
And then
the graphics weren't scaled
properly; it looked totally
fake. Yeah, I thought, "They're trying to scam me, right? You can't
be serious that if I enter
my credit card number here, they
want to force me to
enter some kind of PIN for the first
time using some absurd form, which is supposed to secure my transaction..."
For the next 100 times,
yes, of course I couldn't see
whether it was SSL or not, so not
simply by looking for where
that lock is, but the lock is
n't visible anymore anyway, I've
removed it now, the one under the
AdBlock button.
Frank Ron here, hello over here, sorry,
other page about the verified Visa. Have
you noticed that all the data you have to
enter to verify your card is
on the card itself for the first time?
Yes, yes, so that's the
scary part, I mean, it
looks like I'm sitting there from a shop I do
n't really trust anyway.
Then some other things pop up that look as
trustworthy as
anything but trustworthy, and then you can of course
say, okay, forget it, may I, may I?
Just a quick note from the
specifications: this isn't entirely
correct. There are different ways to
implement it, and there are
also different methods
specified by the individual
institutions or by Visa and Mastercard
themselves, but it's definitely the case that you
also have to enter other parameters. There are
various banks in Germany
that, for example... Integrating your date of birth into it,
or other verification
methods,
yes, it's just as ridiculous, but hey, it's
job security for all of us for the
next 30 years, don't get upset,
and if not for us, then for the
Fischers
people. Yes, but we would like to point out again
that the real scandal is
not these usability issues,
but that you always get new terms and
conditions, and the terms and conditions
simply shift the blame onto you.
Yes, exactly. So, while it has been the case so far that
you
are usually relatively well off, especially with credit card payments, if you
have some kind of problem or the webshop has
messed up the data, these
verification methods, just like
the PIN for credit card
payments in real life, are
primarily intended to
transfer part of the liability to the customer.
And you have to
look very closely at that. There's also this thing you have to
look very closely at: what's
this obscure thing called,
instant payment or something, where you have to
enter your account details in some kind of fishy format? I know. No, and
a fir tree, or yes, yes, yes, and the fir trees,
so it's just completely, completely unbelievable, really great, yes, as I
said before,
source repositories were quite
a significant trend in 2011, uh,
a lot of things disappeared,
and which brings us to the interesting question of how
much of it was open source
repositories. Who
actually still reads this source code? Who among you
actually reads
source code? At least... okay, and now
hands down, PP source code
reading,
okay,
nobody understands. Yes, yes, okay, yes,
drone use in Germany, threat
hacking, we'll
certainly have a few more of those who...
okay, the hijacking, we've already had that. What was
also exciting
is that, I think, for the first time this
year, a US drone was used in Germany. It became
known that it was
used... it's been used for a while now,
yes, exactly, the first time.
Headlines about it, and in Europe
it will soon be the same. So,
in the Bundestag, the first reading of a
law was discussed.
Yes, at Kastel, they
used these small drones that threatened
various other threats, so what...
yes, quadcopter style, is what they're
talking about now, they're really big.
So, these are drones in the 150-kilo class
or larger, for which they
want to change the airspace regulations so they can be
used. These are
things that
can circle for several hours and don't
necessarily need an operator with
a radio remote control. There's another
new development with these
drones: it's become known for the first time
that autonomous drones have engaged in
friendly fire and
killed their own people. Yes, that's true,
that was previously
reserved for pilots, but now it's also possible with autonomous drones.
So, we see there's
technological progress.
Although, it must be said that
many of these drones aren't even necessarily
armed. But the type
of reconnaissance they conduct has a lot to do with
looking for patterns. A group of
people moving in a certain way is then
identified as a target. I expect
that will
happen to us domestically soon. Yes, we
already heard yesterday that they're using Facebook for
Mafia Wars, which I believe happened in their
drone control centers.
Yeah, they're just computers, right?
So, they have PCs and lots of
screens there, and sometimes you do
n't need all the screens, and then it
might get boring when you have to
fly such long distances. You know how it is in
other
games when you have to walk such long distances,
so you do something
else on the other
screen. And if you have Wi-Fi,
then you also have an air gap.
Gaddafi, I think it's
just a new day now,
somehow. With Gaddafi,
drones were
used in his assassination, and with
Osama, Obama, the use of drones
was
crucial,
right? So, I changed the release standard for
the targets. There were
also some nice videos of
demonstrations in Moscow, wasn't it
Moscow, where the demonstrators
used drones to show how many of them there were?
Yes, yes, that will clearly increase. So,
this is simply this
topic of counter-publicity or something like that. Drones are
extremely
valuable. Oh, so, Hash algorithm
collision denial of service.
How's the fallout? Has anyone
heard anything? Is the internet
already shut down?
No, it's... Okay, just listen up to
the microphones, listen up to the microphones, listen up to the
microphones
for the keywords for 2012. We do
n't want to do this alone, but let's start with what
we thought would happen with
smart meters
this year, since they
're mandatory
in Germany, at least since the beginning of the
year. You can opt out, though,
and by the end of last
year, the first providers were already available where you could
buy a smart meter. It
only cost a few hundred euros to
install, and then just a few hundred euros
more to have and
use it, saving you a
few cents.
Accordingly, it was a
resounding success, so successful
that Google
and Microsoft withdrew from the business.
Therefore, we don't have
much hope that the "
blinking light" for city districts will happen at the
smart meter level. We're
actually relying more
on Skadar. That sounds
plausible, yes. So, in the FAQs about
smart meters from the
manufacturers, the question is also raised: how?
We didn't patch that, he
answered yes, over the airgap or something
similar, over the
airgap and
successfully, no, that's how he
answered, how they
patch it, they know they
probably have to patch it, yes, so
the last time
I did remote updates, that's
good, they just think they can do remote
updates,
it's probably SSL
secured and we also have a A
certificate, so SSL secured, yes,
definitely. Not last time,
it's not SSL
secured. The last time I looked at such a
power meter, admittedly about
three years ago, it had the
design specification that it had an approximately
8 megabyte firmware image, and
they had roughly
between 5 and 7 kilobits of
data bandwidth for this electricity meter and wanted to do online
updates.
I found that a very bold
design specification. Nowadays,
these things want quite a lot of
GSM, so I do
n't think we need to
say much about GSM network infrastructure, or do we have someone on the microphone? Yes,
I would like to see for 2012 that
people like state secretaries or
employees in political
offices are exposed via Facebook,
like those who do astrurf with things
like J Stylo, which we saw here yesterday at 4
p.m., this authorship
detection. Yes, you mean copy-paste
detection in
government documents. Yes, so that
we can see, aha, these and
these linguistic features, that's so-
and-so employee from so-and-so
political office who's doing astrurf here.
Yes. That would be a useful
application, yes, let's
try it. Regarding GSM, I don't think we need to say much more,
it's been sufficiently covered.
The point with the
GSM network infrastructure is that the
modernization backlog, or whatever it's called,
the innovation bottleneck, isn't really the issue. The
standards are
written, but they aren't
implemented. So, the standards
that would ensure the infrastructure would
last another year, they simply are
n't implemented. I think that's what
we're taking home from this congress,
and it's becoming less and less fun.
And then there was also a question about
whether a censored network
is actually worse than a
shut-down network, or
vice versa. That will probably keep us busy. Does
anyone have a strong
opinion on... well, um, as for
V4? The story that
really worried me about V4 was when someone
told me that people who are very
intensively involved with this V4 to V6
transition, that
at least some of them are now
learning practical professions, like...
not
bank clerks, that's how it was
described. Well, you can see that... A
tanker truck drives past you at a
relatively high speed, and
it's apparently full. After
a while, it comes back, and
the driver jumps out and runs.
What do you do then? Do you
stay put or do you run
too? Anyway, for
2012, I think we could say that
we need to take a closer look at this V4 to V6 situation. There could still be some
interesting
disruptions. Yes, there's still potential. Of course,
you can always kill it all off;
that's one option. The next
option is perhaps expropriation. Those who
have large Class A networks that
could theoretically be rerouted could be
expropriated, at least their IP addresses.
Communism, yes, yes, if the
Hamburg-Berlin
ICE line was made faster,
then in such cases, a little bit of expropriation is always necessary.
Yes, and this is
a railway line, and then I'm reminded of
the data highways.
You mean building rights for the
data highway in... Creating IP space, yes,
freedom of construction is probably the key word.
Yes, Xerox, for example, I think still has relatively
large inventories, but well, it will probably
only
delay things a little more, but maybe by
the crucial amount, so by the
crucial amount. Anyway, our
recommendation is definitely that if you're
still building anything that needs IPv4, make sure
it works with NAT.
Yes, Claud, one of the
interesting news items from the nokwa,
when I
asked about the incidents earlier, which I
'll report on in a moment at the
closing event, was that we
actually had a denial-of-service attack
on the congress, uh,
from the Amazon Cloud.
Yes, and and and and now the question is, now
we have to
find the culprit, so
someone will have messed up the non-attack pact,
presumably, and whoever did
n't sign it and
fax it away. The exciting question is, does
the Amazon Cloud actually have a
non-attack pact with the Google Cloud?
Yes, so, what does such a cloud
actually look like? So, are there
lightning bolts there? Didn't someone say yesterday that
Only
Google, only with Google, can you only
make Google disks with Google's resources? How does that work? Amazon versus
Google, who would win? I think
Google,
but Microsoft is the answer.
So yeah, we were discussing a bit
about what actually
happens with all these clouds. I mean,
a cloud is like
Steve Ballmer with a suitcase
chained to his hand, to his wrist, with a
red
button. So a cloud is actually
nothing more than a botnet, which
you can buy much more conveniently than if
you buy a botnet yourself. You know, with
botnets,
yeah, botnets are much cheaper, but you have to kind of
descend into shadowy corners of the network, and then
you don't know what's behind your
credit card number. That's a
bit of a thing, and they're so inconsistent. Well,
you can, of course, just
buy a credit card number to buy
botnets, that's possible, but
you can also go with this credit card number
and just
buy Amazon quality service with
support. Well, so
we see this
whole topic of cloud, so,
putting aside the stupid term,
you can also A whole lot to do with it,
and with a T at the end, yeah, oh,
I already said, the
congress, now four days, lasts
a few years, and it doesn't pass by unnoticed either.
But since we're on the subject of
spelling,
someone recently told me the reason why
we're seeing more and more "idiot
spaces" in the German
language, you know, words that are actually written together with
spaces in between.
The reason is actually
T9, right? So, when you
tap on your phone,
this speech correction, whether you
use T9 or just the
normal input correction, does
n't work with compound German words. And what you
type all day and then correct,
the computer corrects
for you, right? So, the computer says, "
No, you can't put that
together like that," so it must
be wrong. And accordingly, more and
more people are starting to write like
Ron sometimes
does. Okay, the token apocalypse, exactly, tokens.
We all know them. The bank
sends you, usually one or two
a year, some kind of plastic thing where
you have to insert chip cards and
tap on them somehow.
Displays show information or are
directly connected,
then communicate via SSL directly with the
bank, supposedly, and it's hardware, right?
Hardware has to be secure.
Hardware authentication tokens are
somehow the last resort against the
nasty Trojans on computers,
we all know them, and we say that in 2012 there will
probably be a slight readjustment in the perception of
security
because these tokens, if you
look inside, well, they
usually just contain a processor
on which software runs, and PHP—did
someone say PHP? Exactly. So, one of
the quotes that came from
someone researching in this area
was that it gives the impression that
the P-code has now arrived at the
hardware level.
Also, an interesting detail:
we already talked about the
new identity card earlier. The electronic identity card, the new identity card, is
now called the new personal ID card.
We
think we've also somewhat
blurred the term,
and the electronic identity card,
or new identity card, or new
electronic identity card, is
actually, when you think about it,
when you consider these features...
Unlocking a kind of single
sign-on token, a thing that allows
secure hardware access
to services, is
interesting because even people
from government agencies
responsible for anti-illegal matters are quite concerned.
They think, "Well, then
you have all identities pooled on one of
these documents, and if that gets
cloned, captured,
or otherwise
misused,
it's about as good as getting
rid of fingerprint biometrics."
Because you only have one record, and
everything then becomes intertwined. Another thing
we definitely expect to see some
very interesting developments in 2012 is the
new identity card. There's another
e-government advancement coming, maybe
not for 2012, but
perhaps for 2015, because they finally
want to store genetic data from subcutaneous samples in the newly available data fields. We can look forward
to further progress there. And then
the term "toen" takes on a
double meaning... Since you
only have DNA once, how does that work?
Like the Berlin police license plate and
Eisbein (pork knuckle)? We don't
know yet; it's still in the
early stages of research. Hopefully, we'll
see the SPE (Single Perimeter Encryption) system, where they briefly insert the ID card
into the shoulder for sample collection,
or something like that. So,
before we have DNA-based locking systems, they'll be
making a quick prick every time someone enters.
We'll have fun with electronic
locking systems. There's
a pretty large proliferation of
chip card systems that have already been cracked,
like My Fair Classic and
others, which are suddenly appearing in apartment
and office doors. So, dealing
with these standards is something you
always think, "No, you hear
at conferences and talks, like, My Fair
Classic, which was broken four years ago
or so, is
long gone, you don't have to worry about it anymore.
No one will ever use it anyway." Do you think it's
something like a security guard? No, it lasts
forever, and so on.
These
locking system manufacturers are similar. They have
such long lead times that they're still
installing things like My Fair Classic in locks they're
selling new these days, the ones that are just coming onto the market.
Consequently, we'll
probably see a whole bunch of
broken locking systems in 2012. What's
interesting is how they'll
patch it, how they'll deal with it.
The lock industry is
used to saying, "Well, if
it's broken, you just have to buy a new one," while
the computer industry says, "
Okay, it's an update."
This culture clash is going to be
very interesting. They're
all talking wirelessly to each
other now, aren't they? And
how does that
relate to NFC in the new
phones? Well, there will also be phones
that you can use as access control tokens. I already mentioned that earlier.
The question is, doesn't Apple know not
only how many Wi-Fi networks I
've walked past, but also how
many doors I've gone through? And they'll tell me what I've
moved through?
Yeah, you can
write a nice application for that, like "Computer Door
Opener." But... I think since... Since...
Since this... This week,
Siri will also be available in the Android
Market from [company name], and the publisher
is the official
app. You mean for
family emergencies with Android TR, which
we missed earlier?
Yes, install it,
then you can get in touch.
Yes, another topic we've been
dealing with for a while:
corporate franchise city-
states. What we mean by that is, the
future is clear: you eventually choose your
city-state, either by being born there or by rebelling and moving out, in which you
want to live. Of course, it's corporate-sponsored,
or something like that. Facebook state,
Google state, Apple state—look it up.
What's the literature on it? The
beautiful one here by Neil
Stevenson,
Snow Cash, and so on. And there we see
the precursors, so that's what C
ST 10. We already said last year
that
's Apple Camp, and the Android Camp, and
the Facebook Camp. And Amazon
also made a massive push this year. So,
Google with Google Plus, that's clear. Then
they bought Motorola, but of
course, they don't have any plans for that. There's
nothing to see there. Move
along.
And so, first leave
your real name, but then please move along.
Exactly, and one of the Things that are
very much in that direction, also as a
talk at this congress, namely the
abolition or threat of
general-purpose computing. What we're seeing
is that more and more devices—things that
used to be called computers but do
n't really deserve the name anymore
because they're now just like
pets or something—are
coming onto the market, and you'll increasingly have to
search if you want a
real computer,
something you can program,
where you can easily
get a shell, and which you can
actually still
control to some extent.
And of course, these corporate
franchise city states have a great interest in this.
The interesting
question, sorry, is this
general-purpose computing thing. I mean, I
have a computer here, and
I can install whatever I want on it.
I can only do that for historical reasons.
If they could,
they would only sell us hardware where
we can download things from the Apple Store or
Android Market or whatever.
The reason they don't do that in some places yet is that,
historically, it can't be any other way. And
now that's all being shut down,
and then this will happen. New
BIOS technology, what's it called again?
Something with an egg,
something like EFI,
UEFI, right? That means
they also want to include what we still call
laptop PC bells and whistles,
and that has consequences, of course.
For support within the family,
it might be
advantageous, but for everything else...
and the interesting question
is when, if, and how many people will
still be left who
demand this unrestricted access when
ordering, saying, "I'd like
a
priest box cutter." Yes, a
priest box cutter, that's something, isn't it? What
a break we might
also experience is tolerance
and Grab Crypto, because Grab... with Grab, they
want the GPL,
and for that, all the
hardware keys have to be publicly available.
That will keep us quite busy, too.
Yes, you mean Boot Crypto, yes,
exactly. Or there are these great
statements from, I think it was Gigabyte
or MSI, who simply said, "Yes, whatever,
you want to have other operating systems besides
Windows on it."
Yes, who would want that anyway?
Although, by now, you
get the impression that as a Windows 8 user, you
're somehow already more... So, in such a,
such a, yes,
fringe group operating systems,
users, I think what we have to learn
is that hackers are no longer
the majority of computer users,
such a huge fringe group, a very
small group compared to all the people who want to
use computers. Therefore,
the needs we have are
becoming less important for
manufacturers. Well, what does that mean? What's the
message? Buy me computers so we
become more important
than... No, the message is quite clear: we
simply have to ensure that the
devices we buy remain our property.
That means everything related to
jailbreaking, uh,
free BOSS, and similar things will become increasingly
important.
Access to this hardware
will be crucial. So, that means
maintaining and supporting it so that we
can continue programming on it as we want, and the
hardware remains ours if we
bought it and doesn't just become a usage
rights vehicle that we
rented after putting down a
few euros. We definitely have to
work hard on that in the coming years. Yes, everyone wants to become a platform,
um, everyone will become a
platform. Everyone will choose their
platform, and for others, the
platform chooses. The
user often enough also both, right?
So if you're a citizen in, I don't know,
Apple City State, then it's still possible
that you still have
a small, pariah-like citizenship in
a Battle.net City State.
Yes,
yes, as we've seen in
recent weeks and days, and at the
congress, there's something where you have to proceed
with a bit of caution.
So, where we somehow thought there were
definitely people
who were responsible for the air gaps, and these
are all things that
move large amounts of mechanical energy
and are still controlled by computers, so
you should perhaps exercise a little
caution. So, if
you see something on the other side of the terminal
that might look like
it could be
a train or a ship or something,
maybe briefly assume that it might
not be a simulation.
But we can learn from the future; we
all know how it will go, because it's already happened.
You don't see that on
Starship Enterprise, it's
such a thing, it's clearly always
traveling in enemy territory, often enough,
and yet you can
just tear off the panels at every corner. Yes, then
you only have to... If you turn the dial deeply, do
you have something where you can
hack the encrypted board codes
to take over the on-board computer?
Is that
appropriate? And now I'm wondering, of
course, what does that mean if
I'm sitting on the train with my square
drive? Only if I have a floppy disk am
I a danger to the train, or
at least to the seat
reservation display. Is that
still the case on the ICE? Okay, so we
hereby demand... we hereby demand... uh,
no, we point out... we... we... we
are quite modest... we point out
that... computer nerds... and I
recently... Tim recently tweeted and
said that, in
his opinion, the BahnCard
100 is now a status symbol for nerds.
That makes me very nervous... so many
nerds on trains...
resistance... we point out that
nerds are distracted as long as the Wi-Fi
works. It
was a very bad idea to
switch it off again on airplanes. Another short tip from
practice: if the Wi-Fi costs money,
they also like to occupy themselves with
exactly that...
yes, that's an important
safety notice... is correct...
yes... hello... hello... I also wanted to say... yes...
everyone We all, or rather, every single
person in Germany, has a
car. I don't know if you know this, but there's
a computer in there,
or two, or three, or even 80, and, um, yeah, it
runs. These are also... The
aim is to get the same operating system installed,
and perhaps the
new updates for the Priority should
also be
examined more closely. Maybe there's something to be gained from ST. There's
nothing to be gained there,
it's all SSL
secured. Exactly, BMWs are now connected to the
internet via an iPhone anyway.
Such a wise decision, no, it saves a lot of
work, it's called Connected
Drive. Yes, dear people, what we will
see in 2012 are PGP-encrypted
or signed spam
emails to bypass the spam filter.
This will in turn have the effect that
encrypted emails are simply
filtered out as bad, which
has the effect that no more
encryption will be done. Now we ask ourselves
who initially sends the spam emails.
I've already seen signed spam, but
the signatures were
broken. Then we have the, uh,
new professional field of social network
relationships. I wanted to
add something else about encrypted emails. De-Mail
should actually be
considered a step backwards in progress. It does
n't work, does it? Well,
technically it probably works,
but
nobody uses it. So actually, we considered it a step forward
because it It's progressing, isn't it?
I mean, there was some kind of
press release, some
ministers who said something about it, and some
providers who felt compelled
to support it somehow. People are writing
emails, the emails are being
stored, do we already have millions of
users?
GB? Oh - postal mail, exactly. Yes, well, who are you coming from? You always get a
bit confused by it all.
Yes, well, the social network
relationship, yes, the new business area,
obviously, that you can now
buy relationships. Does
anyone know how many relationships
you have to maintain to make a
living from it?
Who has friends,
and so on, the answer is the
right one.
Yes, exactly, and
quite, yes, then, oh yes, that was very
nice, wasn't it? So, in the USA, there was this
little mini-scandal or something, where
if you ask Siri where the nearest
abortion clinic is, you often don't get an
answer
because none of the clinics in the
area are called abortion clinics,
and they don't have it stated anywhere
in their service description that they perform abortions. Instead, it says
something like, I don't know what it says.
Yes, anyway, the profession, and
yes, something like that. It says
pregnancy optimization, but it does
n't say abortion. No. That was clear,
and that's why we'll urgently
need metadata
optimizers who
are able to optimize the relevant
data so that it can actually be
found. Yes, that's something you can
definitely do. Virtual sock puppet
crowd
juilp. I don't know what
100 well-intentioned Wikipedia
users cost. There's already a
price list for that, isn't there? Oh well, not
relevant.
Yes, one thing we'll
certainly see in 2012, in the wake of the
general economic crisis, is that
a lot of companies will simply go bankrupt
because they no longer
earn enough money, but they still
operate services that people still
want. And that's
probably how it will be, we see it, the
new business field of keeping zombies alive, of keeping things, or rather
companies, alive somehow. Yes,
we already had trend sports. The
metadata optimizer, but what do I mean? Is that
the metadata optimizer in
quotation marks, who then
optimizes the metadata so that when you
search for abortion clinic, you end up at the CDU
headquarters?
Yes, data hygiene in 2012 is getting more and more
difficult. Yes, I think so. It's crazy that
people are still
worrying about whether it's
okay to somehow store location data, especially since
smartphones
are practically
medical devices these days. They have a
motion sensor that's incredibly
sensitive. If you
pick it up in the morning to check
what's been happening on Twitter for
the last
four to eight hours, it can
actually tell from the trembling of your hand
how low your blood sugar is,
or still is. And of
course, you can use that to create
trends.
The thing knows where you are, how you're
moving, which direction you're
looking, and so on and so
forth. These things have a metal frame; there's absolutely
no reason why you should
n't be able to
measure galvanic skin response, or skin resistance, through that metal frame.
That means you've got
your lie detector built right in. Um, what?
Oh yeah, there was that great
proof of concept where someone
put a smartphone next to a keyboard. I don't know, it was
never an IBM 101, but one that went clack-clack
and then vibrated.
You can draw conclusions
about the password used,
so these sensors are
already pretty powerful, and
we haven't even seen what you can do with them yet.
Some things will
cost so much battery power, a
pain
station, exactly. Yes, well, a
quick note about the zombie
companies, life support. As I see it, that
already exists, that's the
bank bailout package.
Yes, you also had that video Barbie, no,
no, that one, yes, yes, God. Well, I was
n't actually finished yet. My
always-on speech recognition is the
next thing. What's coming up? That thing with
Ice Cream Sandwich, where you
can log in with your phone's face? That's a
joke compared
to what would actually be possible
if you just shook your phone around a
bit. Then
you slowly get 3D, and there's
much more possible, as we saw
with the Kinect FusionTalk,
which was really quite
impressive. Infrared sensors
for distance are also possible today, and at
some point, it will also be possible to read the heatmap for the
face,
which will certainly be exciting
when you get this data in addition to the
image.
So, the
discussion about whether you might
The position is already problematic, but
what else is possible becomes
interesting, and then you remember
the video Barbie from December
2010. Buy your child a Barbie with a
built-in video camera to
record unguarded moments. Early training is key, and there
will be progress in biometrics too.
We already have
the first prototypes of biometrics
in cars that also capture the rear
body shape to identify the right
driver—yeah, exactly, the drive-by butt
print. And well,
I mean, it's always a relatively
unchanging characteristic, so
not so bad, but you'll have to start paying attention
to
which seats you sit in, right? Because the next thing
you
can imagine is
Starbucks coming along and building
custom inflatable cushions that you
can cut underneath yourself to hitchhike other people's
cars.
Okay, yes,
we've already talked a bit about privacy expectations,
but it will probably come to pass in 2012
that we see more clashes between
what is actually technically
implemented and the expectations
people have regarding the privacy
offered by a platform or technology, and these
clashes are also likely to be
significant. More important than
formal legal violations because it's about what
people think
actually happens to them, and the
interesting thing is that there was
a discussion about this this year.
Apparently, there was this one
person whose wife
disappeared without a trace, and they
bugged him. They bugged his car
and recorded his conversations with himself,
where he apparently made
suspicious remarks to
himself. So, he wasn't on the phone; he was talking to himself
in the car while
driving. Then there was a discussion, and this was
recorded. Now the
question is, can this be used against him? Um,
because he wasn't on the phone, which is what they're allowed to
eavesdrop on in
quotes?
But is it a conversation with himself, the same as
thinking or not?
And I don't know, it raises
the question for me: if a tree falls in the forest
and the tree can assume that it wo
n't be heard,
can that be used against it?
So, it's already getting
philosophical, or perhaps the law will be derived from it. Um,
yes, that was one of the questions that
was very significant in the city's discussion: what constitutes telecommunication
and what doesn't, and whether
telecommunication also exists between people.
and machines can take place, and the
question, for example, whether Siri still counts as a machine
or not will also be
interesting, right? So,
these are exactly the questions
we'll be dealing with quite intensively next year,
namely,
how the legal framework will be
structured, what kind of communication can be made
available to the state,
under what circumstances. We're then dealing
with this construct of the legal
construct, also the legal construct of the
average educated citizen,
and what can they expect, the ability to
talk to themselves,
and where they're only in the car, and
what is a soliloquy
if I, if I, if you open a window
with yourself?
Yes, all of this leads us to the
realization that, at least until these
questions are clarified and a
technical
implementation is possibly found,
the battery life of, for example, a
mobile phone is the actual
limiting factor for all these
surveillance applications. That is to say,
we all actually want more
battery life on our phones,
but do we really want that right now,
or would we rather take
a little more
time because everything else is
developing faster and
faster, but battery life seems to be the limiting factor.
I'm currently feeling a bit down,
which might be a good
thing.
In that vein, does anyone have
something really important? We're a little
behind schedule with the ISC. The IC is asking for a
vote, sort of a survey, about
what kind of encryption is used in
the WLAN networks.
Which networks have access points in the WLAN networks in recent days? It's about this;
apparently, it was also done last year.
What percentage? Ask the
audience. Yes, I know the question:
How many networks do you see when
you open your computer at home? Those who don't
see any, raise your hand.
Wow, those are the
farmers. Five people who don't see any WLAN when they open
their laptop at home.
Who sees more
than
50? Okay, those are the insiders.
Okay, who has more than three?
About everyone.
Everyone who sees WLAN. Who
still sees any
unencrypted networks? And who sees
ones where the SSID makes a political or
religious statement?
Okay, even
30.
Yes, okay. Well, if no
one else has something really important, 3,
2, 1. Then thank you very much.