<?xml version="1.0" encoding="UTF-8"?> <rss
version="2.0"
xmlns:content="http://purl.org/rss/1.0/modules/content/"
xmlns:wfw="http://wellformedweb.org/CommentAPI/"
xmlns:dc="http://purl.org/dc/elements/1.1/"
xmlns:atom="http://www.w3.org/2005/Atom"
xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
> <channel><title>gHacks Technology News &#124; Latest Tech News, Software And Tutorials &#187; chaos computer club</title> <atom:link href="http://www.ghacks.net/tag/chaos-computer-club/feed/" rel="self" type="application/rss+xml" /><link>http://www.ghacks.net</link> <description>A technology news blog covering software, mobile phones, gadgets, security, the Internet and other relevant areas.</description> <lastBuildDate>Sat, 11 Feb 2012 09:52:46 +0000</lastBuildDate> <language>en</language> <sy:updatePeriod>hourly</sy:updatePeriod> <sy:updateFrequency>1</sy:updateFrequency> <generator>http://wordpress.org/?v=3.3.1</generator> <atom:link rel="hub" href="http://pubsubhubbub.appspot.com"/><atom:link rel="hub" href="http://superfeedr.com/hubbub"/> <item><title>Detect Alleged German State-Sponsored Trojan On Your PC</title><link>http://www.ghacks.net/2011/10/10/detect-alleged-german-state-sponsored-trojan-on-your-pc/</link> <comments>http://www.ghacks.net/2011/10/10/detect-alleged-german-state-sponsored-trojan-on-your-pc/#comments</comments> <pubDate>Mon, 10 Oct 2011 12:52:49 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[Windows]]></category> <category><![CDATA[chaos computer club]]></category> <category><![CDATA[portable software]]></category> <category><![CDATA[seganos]]></category> <category><![CDATA[trojan]]></category> <category><![CDATA[windows software]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=51346</guid> <description><![CDATA[I have monitored news about the alleged German state-sponsored trojan closely ever since the German Chaos Computer Club posted information about it online. While there is not a definitive proof that it is indeed malware designed and operated by German police forces, it is definitely something that computer users need to be aware of. I [...]]]></description> <content:encoded><![CDATA[<p>I have monitored news about the alleged German state-sponsored trojan closely ever since the German Chaos Computer Club <a
href="http://www.ccc.de/en/updates/2011/staatstrojaner">posted</a> information about it online. While there is not a definitive proof that it is indeed malware designed and operated by German police forces, it is definitely something that computer users need to be aware of.</p><p>I do not want to get into to many details at this point in time and suggest you read the long post over at the club&#8217;s website to get a better understanding of what it can and cannot do. A binary version of the program has been uploaded to the club&#8217;s website as well.</p><p>Only that much. The so called Bundestrojaner (federal trojan) works in its detected form on 32-bit Windows operating systems. The trojan targets software used for communication. This includes Skype, ICQ or the MSN Messenger but also web browsers. It acts as a keylogger and contains functionality to download and execute code from remote locations. It can furthermore take screenshots, record audio and supports remote updating.</p><p>The core issue here is not that such a trojan exists as it was openly discussed in Germany, but that the trojan is capable of going beyond what the German Federal Constitutional Court allowed police forces to do with it.</p><p>While it appears to be more of a local German issue, it is not completely out of the question that the trojan was planted on computer systems of foreign nationals.</p><p>Security company Steganos has released a first version of the &#8211; German only &#8211; Anti-Bundestrojaner, a software to detect the trojan on 32-bit Windows systems. The software is free and portable, and can be downloaded <a
href="https://www.steganos.com/de/produkte/gratis-fuer-sie/anti-bundestrojaner/uebersicht/">from the</a> Steganos website with a click on the Jetzt Herunterladen button.</p><p>All that you need to do is to run the program and click on the Analyse starten&#8230; button in the interface. This starts the system scan.</p><p><img
src="http://www.ghacks.net/wp-content/uploads/2011/10/steganos-anti-bundestrojaner.jpg" alt="steganos anti bundestrojaner" title="steganos anti bundestrojaner" width="600" height="415" class="alignnone size-full wp-image-51347" /></p><p>The security software scans the system and will display findings in the interface. It will scan the system for drivers and libraries, and try to make a connection to the remote servers of the trojan. A red icon in front of a line followed by the word Kritisch (critical) means that it has detected a file belonging to the trojan.</p><p>If that is the case a popup will be displayed prompting the user to either selected Ja (yes) to delete the identified files or Nein (no) to leave them on the system.</p><p>If you select yes you are asked to reboot the system after the deletion completes. Select ja to reboot right away or nein to reboot at a later time.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2011/10/10/detect-alleged-german-state-sponsored-trojan-on-your-pc/feed/</wfw:commentRss> <slash:comments>14</slash:comments> </item> <item><title>New German, Swiss Identification Cards Not As Secure As Claimed</title><link>http://www.ghacks.net/2010/09/22/new-german-swiss-identification-cards-not-as-secure-as-claimed/</link> <comments>http://www.ghacks.net/2010/09/22/new-german-swiss-identification-cards-not-as-secure-as-claimed/#comments</comments> <pubDate>Wed, 22 Sep 2010 07:08:15 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Security]]></category> <category><![CDATA[chaos computer club]]></category> <category><![CDATA[Germany]]></category> <category><![CDATA[id card]]></category> <category><![CDATA[identification card]]></category> <category><![CDATA[switzerland]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=35073</guid> <description><![CDATA[The new product XYZ is completely secure and hack-proof. Have you heard that from politicians or companies before? It usually turns out very soon that the claims are bogus, and that the product is not as secure as claimed. Germany is on the brink of introducing new biometric identification cards. Those new IDs not only [...]]]></description> <content:encoded><![CDATA[<p>The new product XYZ is completely secure and hack-proof. Have you heard that from politicians or companies before? It usually turns out very soon that the claims are bogus, and that the product is not as secure as claimed.</p><p>Germany is on the brink of introducing new biometric identification cards. Those new IDs not only replace the old cards, but can also be used for identification online, for instance to contact public authorities.</p><p>That sounds great on paper. The system uses a similar concept as the well known banking standard HBCI. Users get a chip reader with their cards for online use. They put the chip into the card and need to enter a pin for security reasons whenever they sign an application or need to identify themselves online.</p><p><a
href="http://www.ccc.de/en/updates/2010/sicherheitsprobleme-bei-suisseid-und-epa">Members</a> of the German Chaos Computer Club, in cooperation with Swiss security experts, have demonstrated that the security on the new ID cards is not hack-proof.</p><p>They have identified several weaknesses, including:</p><ul><li>Attacking computers with trojans or man in the middle attacks. Card owners with basic card readers (without a physical numpad to enter the pin) are affected by this. More advanced card readers are still prone for other attacks, including man in the middle. A million of those basic kits were ordered by the German authorities.</li><li>Card contents and identities can be copied.</li><li>No application standards for signing legal documents. The experts demonstrated that with a PDF and JavaScript contents. The JavaScript contents were not displayed to the signer of the contract, while they were displayed in Adobe&#8217;s PDF reader. This means that legally binding contracts can be signed by ID card owners without them seeing all contents on the contracts.</li></ul><p>What can users do to protect their cards against abuse? Germans can get an old identification card until October this year. If a new ID card is the only option, users should make sure to either get a more advanced card reader with numpad to protect against the most basic attack forms, or make the chip on the card invalid.</p><p>How this can be done was demonstrated by a ninth grade school class some weeks ago. Brave new world, here we come..</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2010/09/22/new-german-swiss-identification-cards-not-as-secure-as-claimed/feed/</wfw:commentRss> <slash:comments>2</slash:comments> </item> <item><title>German interior minister&#8217;s fingerprint replicated</title><link>http://www.ghacks.net/2008/03/30/german-interior-ministers-fingerprint-replicated/</link> <comments>http://www.ghacks.net/2008/03/30/german-interior-ministers-fingerprint-replicated/#comments</comments> <pubDate>Sun, 30 Mar 2008 08:48:20 +0000</pubDate> <dc:creator>Martin Brinkmann</dc:creator> <category><![CDATA[Hacking]]></category> <category><![CDATA[Knowledge]]></category> <category><![CDATA[biometric]]></category> <category><![CDATA[chaos computer club]]></category> <category><![CDATA[fingerprint]]></category> <category><![CDATA[german interior minister]]></category> <guid
isPermaLink="false">http://www.ghacks.net/?p=3658</guid> <description><![CDATA[What&#8217;s a good way of catching the attention of someone who is advocating the use of biometrics? German interior minister Wolfgang Schäuble is pushing biometrics and data collection in Germany all for the sake of security and the fight against terrorism. The Chaos Computer Club, a renowned and popular club of hackers and privacy advocates, [...]]]></description> <content:encoded><![CDATA[<p>What&#8217;s a good way of catching the attention of someone who is advocating the use of biometrics? German interior minister Wolfgang Schäuble is pushing biometrics and data collection in Germany all for the sake of security and the fight against terrorism.</p><p>The Chaos Computer Club, a renowned and popular club of hackers and privacy advocates, decided to let the minister taste some of his own medicine by replicating the fingerprint of the minister and publishing that fingerprint in their magazine.</p><p>The fingerprint was available as a print in the magazine and on transparency slide ready to be put on the fingers of the readers of it. The sample was apparently taken from a glass that Schäuble was drinking at a panel discussion in Berlin.</p><p><span
id="more-3658"></span>The club also published a step by step instruction on how they managed to replicate the fingerprints. The process itself requires only a handful of common materials, a computer and laser printer, nothing that can&#8217;t be acquired in a regular tools store.</p> ]]></content:encoded> <wfw:commentRss>http://www.ghacks.net/2008/03/30/german-interior-ministers-fingerprint-replicated/feed/</wfw:commentRss> <slash:comments>2</slash:comments> </item> </channel> </rss>
