PlayStation News [Replays added] The 36th Chaos Communication Congress (#36C3) - Everything you need to know!

Year after year, many Hackers and Developers around the Globe come together for a "Meet&Greet" at the City of Leipzig, Germany, where they share and discuss their newest Achievements with Hacking and other Security Subjects leading the way. Since you are a trustfully reader of this Site, you shouldn't be suprised anymore that like for last year, we decided to give you the full coverage about this years Chaos Communication Congress again - stylized as "36C3 - RESOURCE EXHAUSTION" by it's host. Last years Congress (35C3) was already an impressive one, which showed us many new Achievements, especially for both the PlayStation 4 and the PlayStation Vita. Indeed, speaking about the PSVita, the stages at 35C3 led to various new Exploits and Homebrew Releases afterwards, which you are already familiar about and probably downloaded a thousand times. This years Congress will also show us the newest Achievements in the Console Scene and since your own demand was already so high for the last year, we had a reason more to keep you informed for the full coverage of this years 36C3. So, the only thing you need to do like you did last year is to keep this Article bookmarked, since we keep this Article updated after each new presentation. So you won't miss anything!​

36C3.jpg

Logo of this years Chaos Communication Congress with their slogan: "Resource Exhaustion"


  • The 36th Chaos Communication Congress (36C3) is the 2019 edition of the annual four-day conference on technology, society and utopia organised by the Chaos Computer Club (CCC) and volunteers.

    The Congress offers lectures and workshops and various events on a multitude of topics including (but not limited to) information technology and generally a critical-creative attitude towards technology and the discussion about the effects of technological advances on society.

    Like for last year, the Congress takes place at

    More Information


    Streams/Replays


  • Following his announcement about a month ago, Developer @oct0xor will show us his newest and latest Achievements in "Hacking Sony PlayStation Blu-ray Drives" with the Goal to get Code Execution on both the Blu-ray Drives of both the PlayStation 3 and the PlayStation 4. This sounds very interesting since there wasn't always such a high demand for the Blu-ray Drives in the past for both the PS3 and the PS4, so this Talk should be a guarantee that we will definitely learn something new, which will be maybe useful for someone.

    oct0xor.jpg
    Lecture: Hacking Sony PlayStation Blu-ray Drives [Presenter: oct0xor]
    Xbox 360 video game console had a number of widely known hacks for firmware of its optical disc drives. However, it was never the case with Blu-ray disc drives of Sony PlayStation video game consoles. In fact, up until recently there was no much information available on this subject publicly. In this presentation, I would like to share my journey of delving deep into internals and security of Sony PlayStation Blu-ray disc drives. As games are distributed within optical media, those embedded devices were intended to contain the best security possible. I will demonstrate a multiple hardware hacks and several software vulnerabilities that allowed me to dump firmware and get code execution on multiple models of Sony PlayStation Blu-ray disc drives.


    In this presentation, I would like to change that and I will shed a light on internals and security of Sony PlayStation Blu-ray disc drives.

    In this presentation, I will share the following:
    1. I will provide in-depth analysis of vulnerabilities and their exploitation to achieve code execution on multiple models of Sony PlayStation Blu-ray disc drives
    2. I will discuss problems that I've encountered while reverse engineering the firmware and how I solved (some of) them
    3. I will talk about security features of Sony PlayStation Blu-ray disc drives
    4. I will explain what engineers did right and how achieving code execution on the drive doesn't lead to full compromise of security


    General
    • Day: 2019-12-28
    • Start Time: 10:10 PM Local Time (4:10 PM Eastern Time / 1:10 PM Pacific Time)
    • Duration: 01:00
    • Room: Borg
    • Language: en
    • iCalendar

    Livestream

    Replay

  • But not only the PlayStation is represented at the stages of 36C3. If you are also interested in Handheld Consoles, especially made from Nintendo, then you will be familiar with known Developer @nba::yoh, who already showed his Experiences in tinkering with the Nintendo 3DS. He will be also presenting his own Talk at 36C3: "It's not safe on the streets... especially for your 3DS!" - by presenting his Achievements in Reverse Engineering an "Undocumented Communication Protocol" to get Code Execution for possible Exploits. Even when the 3DS isn't supported by Nintendo anymore, this Talk will be very interesting if you still own one!

    3DS.jpg
    Lecture: It's not safe on the streets... especially for your 3DS! [Presenter: nba::yoh]
    The 3DS is reaching end of life but has not revealed all its weaknesses yet. This talk will go through the process of reverse engineering an undocumented communication protocol and show how assessing hard-to-reach features yields dangerous results, including remote code execution exploits!


    Embedded Devices are all around us, talking to each other in ways we often don't even realize. In this talk, we discuss how one such communication mechanism in the 3DS remained unexplored for over seven years as well as the vulnerabilities that were lying dormant as a result.

    We will explore specific features of the 3DS and talk about their low-level implementation details and about why they were not tested before. Besides, we will walk through the (lengthy) dev process involved in putting together this exploit, and the significant risks involved in devices (even game consoles) having this kind of vulnerability.

    Finally, we will demonstrate the attack in action.

    Since the talk will be a bit technical some basic knowledge about network protocols and software exploitation techniques is recommended, but it is aimed to be enjoyable for non-technical audiences as well.
    One might also take a look at previous talks (32c3 and 33c3) about the 3ds for more in-depth background knowledge.


    General
    • Day: 2019-12-27
    • Start Time: 2:10 PM Local Time (8:10 AM Eastern Time / 5:10 AM Pacific Time)
    • Duration: 01:00
    • Room: Dijkstra
    • Language: en
    • iCalendar

    Livestream

    Replay

  • Other than speaking about Console Talks only, you will get the chance to see two very known Developers on the stages, who worked on several PlayStation Consoles among other things in the past, namely @naehrwert - who was already on the stage at both 33C3 and 34C3 in the past tinkering with various Nintendo Consoles - and @quertyoruiop - which he will held his very first Talk on the big stages of CCC. Although their Talks won't be Console Related in General, it is still nice to see how this whole Congress can give the Developers a platform to introduce their skills in Hacking and Security. And I think they would appreciate it if you turn on their Talks as well.

    Lecture: (Post-Quantum) Isogeny Cryptography [Presenter: naehrwert]
    There are countless post-quantum buzzwords to list: lattices, codes, multivariate polynomial systems, supersingular elliptic curve isogenies. We cannot possibly explain in one hour what each of those mean, but we will do our best to give the audience an idea about why elliptic curves and isogenies are awesome for building strong cryptosystems.


    It is the year 2019 and apparently quantum supremacy is finally upon us [1,2]. Surely, classical cryptography is broken? How are we going to protect our personal communication from eagerly snooping governments now? And more importantly, who will make sure my online banking stays secure?

    The obvious sarcasm aside, we should strive for secure post-quantum cryptography in case push comes to shove. Post-quantum cryptography is currently divided into several factions. On the one side there are the lattice- and code-based system loyalists. Other groups hope that multivariate polynomials will be the answer to all of our prayers. And finally, somewhere over there we have elliptic curve isogeny cryptography.

    Unfortunately, these fancy terms "supersingular", "elliptic curve", "isogeny" are bound to sound magical to the untrained ear. Our goal is to shed some light on this proposed type of post-quantum cryptography and bring basic understanding of these mythical isogenies to the masses. We will explain how elliptic curve isogenies work and how to build secure key exchange and signature algorithms from them. We aim for our explanations to be understandable by a broad audience without previous knowledge of the subject.

    [1] https://www.quantamagazine.org/john-preskill-explains-quantum-supremacy-20191002/
    [2] https://www.nature.com/articles/d41586-019-02936-3

    For the detailed schedule of naehrwert's Talk, please click here.



    .
    Lecture: The One Weird Trick SecureROM Hates [Presenter: quertyoruiop]
    Checkm8 is an unfixable vulnerability present in hundreds of millions of iPhones' SecureROM. This is a critical component in Apple's Secure Boot model and allows security researchers and jailbreakers alike to take full control over the application processor's execution.


    This talk will detail how we built an iOS jailbreak from the ground up - quite literally - by using an use-after-free in Apple's SecureROM. This is key code which is designed to bring up the application processor during boot but also exposes a firmware update interface over USB called DFU.
    By abusing this vulnerability it is possible to unlock full control of the application processor, including enabling debugging functionalities such as JTAG, helping security researchers look for security vulnerabilities in Apple devices more effectively.
    We will analyse the root-cause and techniques used for exploitation, as well mention some of the hurdles we encountered while trying to turn this into a reliable jailbreak and plans for the future of this project.

    For the detailed schedule of quertyoruiop's Talk, please click here.


  • And if you get the chance to visit 36C3 by travelling to Leipzig, you will get the opportunity to get "in touch" with the Developers on-site. Like last year, the Congress will give Developers without a specific Talk to create those mentioned "Assembly Rooms", where the Developers will be able to discuss their own Achievements on a smaller Stage, either with other Developers or even with you. Those Developers can teach you in older Hacks and Exploits, they can show you what happens at a Developer "Behind the Scenes" or you can just come over and send an warmful "Hi" to them (don't worry they won't bite you ^^). And especially, if you are a Developer by your own, you are welcome to show them your own tricks and tips. :)

    fail0verflow
    d
    Like the previous years, console hackers and team fail0verflow are getting together for 36C3. We hope to have some table space at the Hackcenter to set up our consoles, show off our hacks, and teach people about them! The topic extends to many aspects of video game consoles and embedded devices, both software and hardware. This includes breaking the security, using homebrew software, modifying their existing software, hardware modifications and improvements, using custom hardware peripherals with consoles, using console peripherals with custom hardware, and anything else that's related to video game consoles.

    A lot of what goes on behind the scenes only happens once or twice, so here's your chance to learn what it really means to hack a game console, hands-on. If you always wanted to learn how the Wii's security was broken using a pair of tweezers, how to reverse engineer the Wii Remote's extension encryption and make your own, or why using a real random number generator is be very important, you might want to stop by and say hi! :)

    Before registering as fail0verflow we usually registered under the "Console Hacking" group, and members include people who have worked on the iPhone Dev Team and the Nintendo Wii hacking group Team Twiizers. We will also have a number of guests sitting with us.
    Source: fail0verflow's Assembly Room


    Nintenbros★
    .
    Anything console hacking
    Source: Nintenbros★' Assembly Room

    Emulation Assembly
    .
    Developers and friends of the game console emulators Dolphin, XQEMU, Orbital, Mikage, and more
    Source: Emulation Assembly's Assembly Room


We hope you are enjoying this years News Coverage from the stages at 36C3.
Tell us in the Comments Section for which Talk you are most excited for!
 
Last edited:
Year after year, many Hackers and Developers around the Globe come together for a "Meet&Greet" at the City of Leipzig, Germany, where they share and discuss their newest Achievements with Hacking and other Security Subjects leading the way. Since you are a trustfully reader of this Site, you shouldn't be suprised anymore that like for last year, we decided to give you the full coverage about this years Chaos Communication Congress again - stylized as "36C3 - RESOURCE EXHAUSTION" by it's host. Last years Congress (35C3) was already an impressive one, which showed us many new Achievements, especially for both the PlayStation 4 and the PlayStation Vita. Indeed, speaking about the PSVita, the stages at 35C3 led to various new Exploits and Homebrew Releases afterwards, which you are already familiar about and probably downloaded a thousand times. This years Congress will also show us the newest Achievements in the Console Scene and since your own demand was already so high for the last year, we had a reason more to keep you informed for the full coverage of this years 36C3. So, the only thing you need to do like you did last year is to keep this Article bookmarked, since we keep this Article updated after each new presentation. So you won't miss anything!​

View attachment 21420
Logo of this years Chaos Communication Congress with their slogan: "Resource Exhaustion"


  • The 36th Chaos Communication Congress (36C3) is the 2019 edition of the annual four-day conference on technology, society and utopia organised by the Chaos Computer Club (CCC) and volunteers.

    The Congress offers lectures and workshops and various events on a multitude of topics including (but not limited to) information technology and generally a critical-creative attitude towards technology and the discussion about the effects of technological advances on society.

    Like for last year, the Congress takes place at

    More Information


    Streams/Replays


  • Following his announcement about a month ago, Developer @oct0xor will show us his newest and latest Achievements in "Hacking Sony PlayStation Blu-ray Drives" with the Goal to get Code Execution on both the Blu-ray Drives of both the PlayStation 3 and the PlayStation 4. This sounds very interesting since there wasn't always such a high demand for the Blu-ray Drives in the past for both the PS3 and the PS4, so this Talk should be a guarantee that we will definitely learn something new, which will be maybe useful for someone.




    General
    • Day: 2019-12-28
    • Start Time: 10:10 PM Local Time (4:10 PM Eastern Time / 1:10 PM Pacific Time)
    • Duration: 01:00
    • Room: Borg
    • Language: en
    • iCalendar

    Livestream
    • HD (.webm)
    • HD (.m3u8)
    • SD (.webm)
    • SD (.m3u8)
    • Audio (.mp3)
    • Audio (.opus)
    • Slides (.webm)
    • Slides (.m3u8)

    Replay
    Insert YouTube Embedded Link HERE
    • Uncompressed Stream Dump
    • Uncompressed Stream Dump (.mp4) [please "Jump" to Minute ??:??]
    • Full Release
    • Download 1080p (.mp4)
    • Download 1080p (.webm)
    • Download 576p (.mp4)
    • Download 576p (.webm)
    • Audio (.mp3)
    • Audio (.opus)
    • Slides (.mp4)

  • But not only the PlayStation is represented at the stages of 36C3. If you are also interested in Handheld Consoles, especially made from Nintendo, then you will be familiar with known Developer @nba::yoh, who already showed his Experiences in tinkering with the Nintendo 3DS. He will be also presenting his own Talk at 36C3: "It's not safe on the streets... especially for your 3DS!" - by presenting his Achievements in Reverse Engineering an "Undocumented Communication Protocol" to get Code Execution for possible Exploits. Even when the 3DS isn't supported by Nintendo anymore, this Talk will be very interesting if you still own your 3DS!




    General
    • Day: 2019-12-27
    • Start Time: 2:10 PM Local Time (8:10 AM Eastern Time / 5:10 AM Pacific Time)
    • Duration: 01:00
    • Room: Dijkstra
    • Language: en
    • iCalendar

    Livestream
    • HD (.webm)
    • HD (.m3u8)
    • SD (.webm)
    • SD (.m3u8)
    • Audio (.mp3)
    • Audio (.opus)
    • Slides (.webm)
    • Slides (.m3u8)

    Replay
    Insert YouTube Embedded Link HERE
    • Uncompressed Stream Dump
    • Uncompressed Stream Dump (.mp4) [please "Jump" to Minute ??:??]
    • Full Release
    • Download 1080p (.mp4)
    • Download 1080p (.webm)
    • Download 576p (.mp4)
    • Download 576p (.webm)
    • Audio (.mp3)
    • Audio (.opus)
    • Slides (.mp4)

  • Other than speaking about Console Talks only, you will get the chance to see two very known Developers on the stages, who worked on several PlayStation Consoles among other things in the past, namely @naehrwert - who was already on the stage at both 33C3 and 34C3 in the past tinkering with various Nintendo Consoles - and @quertyoruiop - which he will held his very first Talk on the big stages of CCC. Although their Talks won't be Console Related in General, it is still nice to see how this whole Congress can give the Developers a platform to introduce their skills in Hacking and Security. And I think they would appreciate it if you turn on their Talks as well.



    For the detailed schedule of naehrwert's Talk, please click here.
    Insert YouTube Embedded Link HERE​




    For the detailed schedule of quertyoruiop's Talk, please click here.
    Insert YouTube Embedded Link HERE​

  • And if you get the chance to visit 36C3 by travelling to Leipzig, you will get the opportunity to get "in touch" with the Developers on-site. Like last year, the Congress will give Developers without a specific Talk to create those mentioned "Assembly Rooms", where the Developers will be able to discuss their own Achievements on a smaller Stage, either with other Developers or even with you. Those Developers can teach you in older Hacks and Exploits, they can show you what happens at a Developer "Behind the Scenes" or you can just come over and send an warmful "Hi" to them (don't worry they won't bite you ^^). And especially, if you are a Developer by your own, you are welcome to show them your own tricks and tips. :)

    fail0verflow
    dSource: fail0verflow's Assembly Room

    Nintenbros★
    .Source: Nintenbros★' Assembly Room

    Emulation Assembly
    .Source: Emulation Assembly's Assembly Room


We hope you are enjoying this years News Coverage from the stages at 36C3.
Tell us in the Comments Section for which Talk you are most excited for!

Wow can't wait an see what new secrets and hacks come to life will be cheering for every one have a Merry Christmas thanks for letting me know what's lies ahead can't wait an see love y'all ALL have a good day ☮️
 
Thanks @Roxanne for the great coverage :)

Your welcome. Luckily it's more chillin' this year, unlike last year where I needed to translate a whole talk. That was stressful. :)

Replays for yesterdays important Talks where now added as well (EDIT: Now mostly all are added)!
 
Last edited:
Wow that talk from Boris was amazing. I didn't understand to much of it but that guy knows his way around some tech. Let's hope his research furthers the dev wiki in many ways. Thanks for the coverage roxy
 

Featured content

Trending content

Back
Top