DEFCON 16: Toying with Barcodes

  Рет қаралды 370,397

Christiaan008

Christiaan008

Күн бұрын

Speaker: "FX" Felix Lindner, Head of Recurity Labs
The talk focuses on 1D and 2D barcode applications with interference possibilities for the ordinary citizen. Ever wondered what is in these blocks of squares on postal packages, letters and tickets? Playing with them might have interesting effects, reaching from good old fun to theft and severe impact.
Barcodes have been around for ages, but most of the time were used as simple tags with a number. The rise of 2D barcodes started to put them into customer hands as authentication, authorization, payment method and other arbitrary data transport. The implicit trust in them is enormous. The talk gives a very quick intro into barcodes and then proceeds to review the contents of selected samples, including their usage in the real world. This is going to be fun, tool release included.
For more information visit: bit.ly/defcon16_information
To download the video visit: bit.ly/defcon16_videos

Пікірлер: 355
@tzokke
@tzokke 4 жыл бұрын
Defcon 16: Clear audio quality, slides and video at the same time, with good proportions. Defcon 27: Shit audio quality, switching between slides and video (if slides even work) and constant other audio and video issues.
@jsihavealotofplaylists
@jsihavealotofplaylists 4 жыл бұрын
I hate how true this is.
@theapexsurvivor9538
@theapexsurvivor9538 4 жыл бұрын
Like all good things, they get bogged down with more bloatware and poorly patched code with every update...
@mydemon
@mydemon 4 жыл бұрын
Why is the name on the slides NOT the name of the person talking. #confuses
@Kovac22
@Kovac22 4 жыл бұрын
yeah a lot of these panels with mega experts donn't have working audio??
@BangBangBang.
@BangBangBang. 4 жыл бұрын
Now all presentations are geared towards low attention meme viewers with a video clip or gif in the presentation just like how KZfaq videos are turning
@grendelum
@grendelum 4 жыл бұрын
I want that little book of evil barcodes he’s carrying around...
@heroslippy6666
@heroslippy6666 4 жыл бұрын
yes, and I also want to make my own
@Kelsi-2014
@Kelsi-2014 4 жыл бұрын
"In '69 " Nice.
@JohnRunyon
@JohnRunyon 4 жыл бұрын
"why WOULDN'T you want to be able to encode control characters in your barcodes?" - someone, somewhere, creating Code 128
@itchykami
@itchykami 4 жыл бұрын
"Hmm... I read this barcode, and part of it says 'DROP ALL TABLES', I wonder what that means?" *scans *
@ayuchanayuko
@ayuchanayuko 4 жыл бұрын
I wanna try this but don't wanna ruin our expensive investments lol
@LiEnby
@LiEnby 4 жыл бұрын
Especially when readers act like a keyboard- what could go wrong!
@JNCressey
@JNCressey 2 жыл бұрын
Presumably they saw ASCII had a few different versions and wouldn't want to block out a character code and then have ASCII change again and need to use a code they left out.
@KingofJ95
@KingofJ95 4 жыл бұрын
Was he talking to an empty room? He made some damn fine jokes and the room made no noise.
@lemax6865
@lemax6865 4 жыл бұрын
I could hear faint noise. It may just be good audio filtering.
@keysersoze9518
@keysersoze9518 4 жыл бұрын
Must have been early
@TJGermany
@TJGermany 4 жыл бұрын
No, his jokes were very pretentious.
@mydemon
@mydemon 4 жыл бұрын
good directional mics don't pick up sound from anything but the speaker
@Dtr146
@Dtr146 4 жыл бұрын
he had to have been. I thought he was pretty good. I heard a to chuckles that died out because nobody else in the room was laughing
@DeeWeext
@DeeWeext 8 жыл бұрын
the url was a rick roll....
@calebkirschbaum8158
@calebkirschbaum8158 7 жыл бұрын
... You went to a url given to you by a hacker...
@alimmi9
@alimmi9 5 жыл бұрын
@@calebkirschbaum8158 He didn't say he instantly pasted it into internet explorer.
@cryingwater
@cryingwater 4 жыл бұрын
@@calebkirschbaum8158 yeah, could be worse
@Reichstaubenminister
@Reichstaubenminister 2 жыл бұрын
@@calebkirschbaum8158 Yeah, what is he going to do now? Mess around with my German IP address?
@xeno._yt
@xeno._yt 6 жыл бұрын
The airport thing could get you through security, but you would never get on a plane. At the gate they have a list over all the booked passengers and when you scan the ticket barcode the system simply marks your name as boarded. If your name is not on the list, it would tell the gate staff that the scanned name is not on the list. The gate staff will probably check your booking number, but you do not have a valid one, so you will be denied on the plane. Barcodes in this case is mostly used for making the boarding process quicker, in the way that the gate staff don't have to write your boarding number every time. A barcode is useless if the printed information does not match the information in the system.
@whtwolf100
@whtwolf100 4 жыл бұрын
Maybe buy a coach ticket, then change yourself to first class?
@TJGermany
@TJGermany 4 жыл бұрын
@@whtwolf100 so you can board using the fast lane, but you won't have a reservation for a first class seat. Only really interesting if it grants you access to some kind of airport lounge.
@justion337
@justion337 4 жыл бұрын
Unless your target is the people in the terminal.
@Blue3agle
@Blue3agle 4 жыл бұрын
Also there is the tax free shopping places that price goods differently depending on destination or point of origin.
@TJGermany
@TJGermany 4 жыл бұрын
@@Blue3agle good point!
@LiEnby
@LiEnby 4 жыл бұрын
This sounds like loads of fun tbh Especially that "it loops to the keyboard" part
@iPelaaja1
@iPelaaja1 4 жыл бұрын
Wait i thought this was a new video because all the comments are from few hours ago or 1 day old. Then he showed the “Nokia phone which can read 2D barcodes” and looked at the upload date... wtf youtube? :D
@NoTraceOfSense
@NoTraceOfSense 4 жыл бұрын
MK First time, huh?
@Blue3agle
@Blue3agle 4 жыл бұрын
Still a good talk, though.
@alzukey
@alzukey 11 ай бұрын
Video is uploaded in 2011 but defcon 16 happened in 2008, so its even older haha.
@mikhailzaruykin663
@mikhailzaruykin663 5 жыл бұрын
In my local shops the barcodes on the bottle-recycling printouts are session tokens and the actual amount is stored in the memory of the machine (for about 1 year), it Is connected to the register, and it's really hard to mess with it
@jessicawhite768
@jessicawhite768 2 жыл бұрын
Cray cray I appreciate your comment
@mikhailzaruykin663
@mikhailzaruykin663 2 жыл бұрын
@@jessicawhite768 However they are serialised, so stealing somebody else's money is fairly easy
@jessicawhite768
@jessicawhite768 2 жыл бұрын
@@mikhailzaruykin663 that is so genius I have no clue how you are so eloquent expressing it or how I even understood enough to thank you for writing it today I understood it tho I took computer manufacturing. So all the theft was buying something more expensive with a false token saying it's cheaper. Wondering if the mark can be tricked so we don't have to get it
@bike4aday
@bike4aday 8 жыл бұрын
This guy has a funny subtle sense of humor xD great talk
@soko45
@soko45 8 жыл бұрын
+bike4aday too bad its mostly "insider" okes which they cant understand...the airport one...the government representive etc ^^
@B3Band
@B3Band 7 жыл бұрын
You might be the only one having difficulty understanding the jokes. Just saying...
@isaaccool3183
@isaaccool3183 6 жыл бұрын
What about using your phone to decode barcodes
@jake-san
@jake-san 5 жыл бұрын
@@isaaccool3183 that would be now the case, but this talk is 7 years old.
@mydemon
@mydemon 4 жыл бұрын
Like that time when he called recycling efforts 'retarded' *HAHAHAHAHAHA*
@kd1s
@kd1s 7 жыл бұрын
Actually the parking garage at a local mall doesn't even bother with the tickets anymore. When you roll in it snaps a picture of your registration plate, and same when you roll out. It's pretty interesting.
@GaryCameron780
@GaryCameron780 10 жыл бұрын
For $200 or the modification of two bytes. lol
@douro20
@douro20 10 жыл бұрын
Big Lots uses a proprietary compressed barcode format which is encoded using Code 39. There is a lot which can be extracted from those barcodes for someone who manages to crack the string format...which is why they are so protective of it (to this day barcode scanning can get you thrown out of their stores).
@heroslippy6666
@heroslippy6666 4 жыл бұрын
At one point in time wasn't their a kids toy that scanned barcodes?
@Fries_Land
@Fries_Land 4 жыл бұрын
@@heroslippy6666 That here was! it was called Skannerz!
@johnalexander2349
@johnalexander2349 4 жыл бұрын
Wish I'd gone to Defcon 16, not 26... 10 years, and all the good stuff's been sanitised from the con. Nothing but a money grab now.
@omc
@omc 4 жыл бұрын
The 3DS could be hacked with barcodes, search "NinjHax". A game used QR for something and hackers exploited.
@moth.monster
@moth.monster 4 жыл бұрын
It's not that the code itself was vulnerable, it's that the code was used to store level data and the level data format was exploitable.
@ilonachan
@ilonachan 4 жыл бұрын
Indeed, I think the vulnerability was kinda similar to what they later did by encoding exploits in very long Unicode names for audio files. Nintendo Audio did not appreciate that.
@83hjf
@83hjf 4 жыл бұрын
@@ilonachan this is the real reason why the Switch doesn't support bluetooth headphones, doesn't play netflix or youtube, etc. Nintendo wants to reduce the attack surface as much as they can.
@ilonachan
@ilonachan 4 жыл бұрын
@@83hjf Oh I see, never looked at it that way, but it's possible. Still, they're gonna have to strike a balance between making the thing as secure as possible and providing features the customer expects. IMHO removing "basic" functionality can't really be the solution in that case. But hey Nintendo, you do you eh?
@FennecTECH
@FennecTECH 4 жыл бұрын
we actually hacked the 3ds using buffer overflows on QR code reader in a badly written game.
@n3rdy11
@n3rdy11 7 жыл бұрын
"20$ will be like 3,50€ next year" Good times back then, now... not so much.
@jackkraken3888
@jackkraken3888 8 жыл бұрын
Interesting fact: One of the earliest forms of barcodes were in the shape of a bull's eye. Also the barcode was actually inspired by someone overhearing a conversation of a retail company wanting to find a way to speed up the checkout process , but it would take years for it to be used in retail.
@error.418
@error.418 7 жыл бұрын
"One of the earliest forms of barcodes were in the shape of a bull's eye." The guy who invented the first barcodes just thought it would be easier to scan if you could do it in any direction. So he made a linear version and a radial version, which I guess you could say looks like a bullseye. Also, the "bullseye" style code proved to have a serious problem; the printers would sometimes smear ink, rendering the code unreadable in most orientations. However, a linear code was printed in the direction of the stripes, so extra ink would simply makes the code "taller" while remaining readable. So that's why the linear code won in the end.
@jackkraken3888
@jackkraken3888 7 жыл бұрын
Yes. :)
@MikeL13
@MikeL13 11 жыл бұрын
Australia…no Austria…no wait, I know that cross, it's Swiss. >__> Still a great talk!!
@smileman66
@smileman66 8 жыл бұрын
Funny statement about the can recycling... we have deposits for cans here but no machines. The return process is much worse than simply feeding them into a machine. You have to show up when the grocery store is taking returns, place your bottles and cans into a cardboard flat at the grocery store, then an employee counts them, then dumps them into a bin and you get your five cents :/
@error.418
@error.418 7 жыл бұрын
that actually sounds much easier... you hand them to someone else who counts them and gives you money. feeding them in one at a time is such a hassle that I would just throw my shit away instead of recycling it.
@dnb5661
@dnb5661 9 ай бұрын
Where I live, you dump the container into a carousel thing, that lifts containers to the top. It has some sort of system to automatically determine what type of bottle it is. An attendant watches over the machine as you put your containers into it. The attendant manually tallies glass containers.
@BrendanOrr
@BrendanOrr 7 жыл бұрын
At work, at least until a few years ago, the barcode on the back of the badges was encoded to our social security number. Thankfully they have moved to an arbitrary numerical number as a form of identification.
@Gunbudder
@Gunbudder 8 жыл бұрын
Fortunately, my local airport JUST got a new system that links your luggage to your ticket through a network, and not through tthe barcode. In fact, if you don't check a bag, and someone tries to check a bag for you, they will see an error. Vice versa, if you check a bag, then decide you do not want to check after all, they will stop you at the security checkpoint saying you need go either check a bag, or remove the checked bag from your ticket. none of this uses the barcode (finally)
@kiddy1992
@kiddy1992 6 жыл бұрын
odd, i don't quite recall the avarage power of phones (and their camera resolution) around 2010, but couldn't you have made an app?
@grendelum
@grendelum 4 жыл бұрын
I helped build one of those DOS based POS systems he’s talking about when I was in high school... I’m actually quite proud it’s still in use.
@Merrsharr
@Merrsharr 4 жыл бұрын
now I wonder if I can make a x1000 payback points coupon edit: after a cursory look, it appears the codes are just sequential numbers checked against a database
@Lolo5
@Lolo5 4 жыл бұрын
Gimme da code now! 4real plz
@Merrsharr
@Merrsharr 4 жыл бұрын
@@Lolo5 there ain't one, the content of the coupon is not in the barcode
@Lolo5
@Lolo5 4 жыл бұрын
@@Merrsharr oh lol sry me stoopid
@danpowell806
@danpowell806 4 жыл бұрын
Sequential, therefore predictable?
@B3Band
@B3Band 7 жыл бұрын
3:48 UPS uses Maxicode, not Aztec. Worked there since 2011.
@grantcivyt
@grantcivyt 7 жыл бұрын
This talk was given in 2008.
@DaveDablave
@DaveDablave 7 жыл бұрын
grantcivyt lol pwned
@Robertkopp84
@Robertkopp84 7 жыл бұрын
So the information he uses must be from around 2004. I see recycling coupons rejected every day since they are in use.
@TJGermany
@TJGermany 4 жыл бұрын
@@grantcivyt Ah, I thought it was from 2011...and was wondering why he's presenting such old information, cause I think I saw his talk on 24c3 in 2007 in Berlin. Now everything makes sense.
@whtwolf100
@whtwolf100 4 жыл бұрын
Wonder if you could make the walmart registers download and display images
@suricrasia
@suricrasia 7 жыл бұрын
there is an error in the slides at 28:10, FNC2 is "append this to the next message", FNC4 is "use extended character set for next character"
@nqkoisi123
@nqkoisi123 7 жыл бұрын
:|
@maximalgamingnl9954
@maximalgamingnl9954 4 жыл бұрын
You're (were) about ten years late, and I am 3 years late to tell you, gotta love them KZfaq comments
@theosmid8321
@theosmid8321 2 жыл бұрын
thank you. Very educative!
@kurtmayer2041
@kurtmayer2041 4 жыл бұрын
i actually tried scanning the code on my DB bahn ticket and it was completely unintelligible i guess they have to get points somehow
@TrekkerMoto
@TrekkerMoto 6 жыл бұрын
Pretty sure that is exactly how the recycling facilities in the US function. The turn in area is in a train container out back of the store. If I remember correctly it is printed on regular printer paper too.
@matvei8829
@matvei8829 4 жыл бұрын
Hi, I’m from 2020 and I wonder whether at least California is still catching up on the beer bottle recycling
@jody5661
@jody5661 7 жыл бұрын
the video is not high enough quality for me to scan the QR code.
@Larsi1997
@Larsi1997 7 жыл бұрын
well if your eyes are good enough you could recreate the bar code by hand and then scan it
@desolderingpump2010
@desolderingpump2010 7 жыл бұрын
"...they can make luggage illegal ..." (2011). Now in 2017, you can't bring your laptop ... :P
@LordMardur
@LordMardur 4 жыл бұрын
You can bring it, but it must be scanned separately. Reason is, that it is really hard to distinguish between laptops and bombs, or laptops and laptops with bombs inside them, or batteries in laptops and bombs inside the battery compartment of a laptop. It is a technical limitation of image quality in x-ray scanners.
@MintyFarts
@MintyFarts 4 жыл бұрын
That medical one. I've used a few instruments that use those racks. The tech infrastructure for medical systems is really... not great... but these are made by other companies and leased/contracted/sold with service plans from really large and profitable companies, and could be something labs and hospitals could demand a change on..
@goodsocksproductions9397
@goodsocksproductions9397 4 жыл бұрын
God damn that was an impossibly tough crowd! Or impossibly aggressive isolation, which would be dumb because it makes it seem like it's an impossibly tough crowd
@marc-andreservant201
@marc-andreservant201 4 жыл бұрын
Another possible scam is bottle returns in adjacent jurisdictions: grab non-refund bottles or cans from random garbage bins in the jurisdiction with no bottle return laws, stick on a barcode with a UPC number that does qualify for a refund, then cross the bridge and stick the bottles/cans into the recycling machine. It doesn't matter if the receipt is digitally signed, because the crusher ate a piece of metal shaped like a can with a UPC code for a refundable deposit matching the weight of the empty can, so it will sign off on your cash register slip. This may or may not be fraud, because you took something that was in someone's garbage bin (legal: abandoned property) and sold it to a recycler who will get paid per kilogram on returned cans, so they don't lose money. Also, what may have ended up in a landfill is now being recycled instead. Depending on your jurisdiction, the deposit may be worth more than the metal content (this is the case in Quebec), so they charge you 20¢ extra at the cash register when you buy a full beer can, and then refund the 20¢ when you return an empty beer can. If the metal value is less than 20¢, you are defrauding the government and it would be illegal.
@WillPhoneman
@WillPhoneman 11 жыл бұрын
I like the way this guy thinks! I love barcode systems, after all, I am THE scannerman! When people use them for authentication with no other system in place, you're asking for trouble!
@DaVince21
@DaVince21 4 жыл бұрын
The wiki link at the end of the video is dead now. :(
@Rednesswahn
@Rednesswahn 5 жыл бұрын
You can also put the bottle recycling label bar codes on non-recycling bottles.
@Merrsharr
@Merrsharr 4 жыл бұрын
only within limit, since the machine does check the weight (and possibly size) of the bottle
@mewwew411
@mewwew411 9 жыл бұрын
so uh How do I fuck up the bar code kiosks at like target
@statinskill
@statinskill 4 жыл бұрын
I already had a lot of fun with that. Back in the day, I was once tasked with selecting a handheld scanner for packaging stations. This is how I got my hands on a bunch of configuration cards for scanners from various manufacturers. It turns out the gas station I often went to had one of these scanners, so I went and prepared four barcodes: 1. Enter Config 2. Disable 3. UPC 4. Exit Config. So, I went to the gas station and tried to get the guy to scan those codes. First I put them as stickers on 4 items but he just grabbed them from me and started scanning them out of sequence. I told to go back and rescan them. He asks me why, and I have no good answer. Then he looks at the bag of chips and goes "Hey wait a minute, what are you putting stickers on my stuff for?". And that's when I lost all patience and just grabbed the scanner from him. He looks at me and then suddenly came running around the counter and ripped the scanner out of my hands. Are you nuts he asked me and that's when I suckerpunched him in the hopes of knocking him out so I can get the scanner. Got him good too, right on the chin, but it wasn't good enough. In fact it just really pissed him off and so he started beating me with the cable of the scanner which had pulled off. There's a 9 pin serial connector on that cable, hit me straight in the face with it. And then it was on! First he was beating the crap out of me, then I was begging the crap out of him to please stop! And then the police came and pulled him off me. First I got medical attention, then I got legal attention. I was put before a bond judge and my mother bailed me out for $23,000. That was a big deal and a lot in my family don't want me to come around anymore. Anyway they had just passed new computer crime laws and I was sitting home on my mother's couch anxiously playing games on my PS/1 and drinking gallons of Dr. Pepper, waiting to hear from the lawyers what the prosecutor is going to charge me with. They were trying to figure out if the hand scanner qualified as a computer system because it has a microprocessor. In that case they could give me more time because with the assault and battery charges I already had, they can substantially increase the punishment if there are aggravating factors. Like assaulting someone to commit a crime. Turns out the DA thought they could and I wound up with 1 year in county jail and 5 years parole. Jail sucked. The ankle monitor sucked too. I was barred from going to any establishment that operates a barcode scanner in its premises. I was lucky, the judge contemplated not letting me come within 50 yards of any barcode. I pointed out that some of the court papers I have, have barcodes. He gave me ten days extra for contempt and told me to go right ahead and be a smart-alec. In the end they also took my computer and everything else that was vaguely connected with the crime I was preparing, because I never got it back. Just kidding. This is the end of the story, you've been entertained, now go away. The only true in it is about me having had a bunch of these configuration cards through my work but I never saw the point in unconfiguring somebody's scanner so they can't check customers.
@corycrowmusic
@corycrowmusic Жыл бұрын
hope you are a better hacker than story teller
@anttimaki8188
@anttimaki8188 4 жыл бұрын
Hi from finland. We have a extensive use of these bottle recycling machines. These days, in certain shops they call manager to check if the ticket is valid if over certain sum. I wonder why. Also for 30 years i knew a parking lot that printed 2 parking tickets for the same money if you 1st pushed the ticket button, then payd, and pressed it again. no idea if that place is still around though ;P
@russell2952
@russell2952 4 жыл бұрын
Posted in 2011. Nothing has changed since then.
@jacobmarrandino3551
@jacobmarrandino3551 9 жыл бұрын
how do you make a upc barcode with an sql injection?
@charliebeadle2979
@charliebeadle2979 9 жыл бұрын
Do you have any idea what SQL injection is?
@moth.monster
@moth.monster 4 жыл бұрын
>2D scanners are still expensive Oh, how times have changed... I have an app on my phone, a FOSS Android app, that can decode all of these 1D and 2D barcodes and more.
@calebgindelberger3046
@calebgindelberger3046 4 жыл бұрын
Was talking about physical spinny mirror kinds of scanner afaict
@thepi4587
@thepi4587 4 жыл бұрын
@@calebgindelberger3046 This talk is from 2008, over a month before Android even launched. I completely believe that 2D scanners were still expensive.
@SandroSmith
@SandroSmith 4 жыл бұрын
Do you realy need separate app for that? Try using just Camera system app. On the iOS its that simple.
@moth.monster
@moth.monster 4 жыл бұрын
@@SandroSmith On Android you need a separate app... but it's free and open source and works great so it's not a big deal really.
@83hjf
@83hjf 4 жыл бұрын
@@SandroSmith did you not watch the damn video? your iphone by default is scanning barcodes. the guy just told you NOT SCAN RANDOM STUFF and there you go, your phone scans random stuff without you telling it.
@MilitantPacifista
@MilitantPacifista 7 жыл бұрын
"Abdul bin Scheusal" "Wheelie of Fortune" 9/11 bester mann
@Kyle_Warweave
@Kyle_Warweave Жыл бұрын
Oh man, working at NCR was fun !
@EdwinFairchild
@EdwinFairchild 7 жыл бұрын
that was very interesting
@politarafaellus5301
@politarafaellus5301 4 жыл бұрын
Pub etiquette is interesting
@sta7e
@sta7e 4 жыл бұрын
36:08 Its 2020 and Berlin still struggles with the new, bigger airport.
@WeWanTYouRSoLe
@WeWanTYouRSoLe 7 жыл бұрын
anyone tries that URL for the barcode decoding?
@alaeriia01
@alaeriia01 7 жыл бұрын
WeWanTYouRSoLe No need; I can read 1D barcodes already.
@kreuner11
@kreuner11 9 ай бұрын
first time i heard someone use the r word to refer to the pfand system
@AwwwPishhh
@AwwwPishhh 11 жыл бұрын
top marks fella
@sjmww1235
@sjmww1235 8 жыл бұрын
Is it just me, or does he sound vaguely like yoda
@mgc45
@mgc45 8 жыл бұрын
Cool!
@TheGoodChap
@TheGoodChap 10 жыл бұрын
UPS uses only MAXICODE. Sometimes our scanners won't be synced to the terminal (terminal computer is attached to a belt we wear and log into, when we scan packages the scanner on our hand sends data to the terminal via bluetooth, the scanner is wifi I think which sends the data to the server). If it's not synced you go to a configuration menu that displays a barcode on the screen we scan to get the two working. It's pretty interesting how it all works, I've always been curious how it all works.
@darerun1051
@darerun1051 4 жыл бұрын
This talk was given in 2008.
@IronCypher
@IronCypher 4 жыл бұрын
The Riviera was a great place 😁
@topsykretz9126
@topsykretz9126 6 жыл бұрын
Lmao the fake IKEA add at 31:00 with the human table sneaking in that booty into the presentation WP sir
@calaphos
@calaphos 7 жыл бұрын
36:10 Of course our capital doesnt have a large airport. There hasnt changed a lot in the las 6 years
@zombiedude347
@zombiedude347 7 жыл бұрын
Why in the world are they not encrypting these? Basically use a "random" number generator to generate the encryption/decryption keys that periodically change. Then just set it up to have an expiration date printed with the bar codes.
@CrypticConsole
@CrypticConsole 4 жыл бұрын
Inconvenience. Imagine Tesco replacing like 1m barcodes
@CryptocurrencyInsider
@CryptocurrencyInsider 11 жыл бұрын
Does this still work?
@TheAechBomb
@TheAechBomb 4 жыл бұрын
yes -future person
@markkalsbeek5883
@markkalsbeek5883 7 жыл бұрын
So if you're wondering what that datamatrix code points to in the bottom right, but decoding doesn't work beceause of the low resulution, it leads to: www.phenoelit.org/ (I actually had to download the slides from the defcon website to find this XD)
@dannie92
@dannie92 11 жыл бұрын
nice talk
@hene193
@hene193 6 жыл бұрын
All of this replacing the barcodes and making fake receipts is illegal. At least in my country people pretty regularly get charged with fraud when they get caught. And it's huge legal process. Go to court and so on. Not worth the few euros.
@Nulono
@Nulono 5 жыл бұрын
36:44 The velvety tea?
@Backup1982
@Backup1982 11 жыл бұрын
Holy shit, a german guy with sence of humor! Awesome talk.
@HighestRank
@HighestRank 4 жыл бұрын
J. M. *Swiss
@over00lordunknown12
@over00lordunknown12 7 жыл бұрын
YO! Why is his are so pixelated?
@seanocd
@seanocd 4 жыл бұрын
1080p cameras weren't exactly common place 11 years ago, and this vid probably took two days to upload at the time.
@bigun89
@bigun89 10 жыл бұрын
31:00 - Just googled Veronica Moser.... WT-serious-F
@mewwew411
@mewwew411 9 жыл бұрын
Dude that's nasty as fuck.
@mewwew411
@mewwew411 9 жыл бұрын
Just when you think you've seen it all there's that.
@alaeriia01
@alaeriia01 7 жыл бұрын
Anonymous User Thank you for the heads-up.
@MrWatNub
@MrWatNub 5 жыл бұрын
Whew. I googled it before getting to that point in the video. Shit. Literally
@blazer6248
@blazer6248 5 жыл бұрын
There's nothing about anyone named Veronica Moser at the 31 minute mark. So what exactly are you talking about? The inky thing at 31 minutes is something about Ikea with a naked woman on her hands and knees. Nothing about her being named Veronica Moser not anything about shit. So?
@Dave062YT
@Dave062YT 8 жыл бұрын
Damn .....I thought it said Baracudas
@trouty7947
@trouty7947 4 жыл бұрын
Take a drink everytime he says "um"
@TheAechBomb
@TheAechBomb 4 жыл бұрын
instant alcohol poisoning
@besteyelashextension6386
@besteyelashextension6386 7 жыл бұрын
"the driver for technology is $ and/or porn" so true!!!
@osearthesp
@osearthesp 7 жыл бұрын
aka power
@seanocd
@seanocd 4 жыл бұрын
...partly true. The average person may be hugely motivated by sex and money. Probably no different to the average engineer. But the greatest of innovators usually seem to have different motivations. Brilliant ideas that were not patented, because the innovation was important, not the profit. Geniuses who choose human 'betterment' over greed. Some examples: Salk (polio vac), Berners-Lee (www), Bohlin (3 point harness), Bhatt (USB), Kalashnikov (wildcard - AK-47)... Do not make the mistake of crediting the desire of power for the force of invention. It's demonstrably untrue.
@Fasteroid
@Fasteroid 3 жыл бұрын
security? what security?
@JonesNoahT
@JonesNoahT 7 жыл бұрын
Does he not know what GNU is?
@UserNumber3141592653
@UserNumber3141592653 7 жыл бұрын
The first 2 minutes and 17 seconds of this video contain 20 "umm"s. Extrapolating from that the whole video contains ~389 instances of the speaker saying "umm". Assuming that saying "umm" takes ~1 second that means this video is ~14.6% "umm".
@victorliu1240
@victorliu1240 4 жыл бұрын
UserNumber3141592653 This is underrated
@RussellTeapot
@RussellTeapot 4 жыл бұрын
I think we should do the same measuring the number of oscillations he makes, and calculate the frequency
@primarypenguin
@primarypenguin 7 жыл бұрын
how would you just slip the forged barcode under your 6 pack to get scanned without the cashier noticing? Wouldn't the cashier notice that something was scanned? Theyre not going to just hand you money with no questions asked, when it seems like you should be paying them for the beer. Am I missing something here, obviously theyre going to look at the register and be like "oh it says that I owe you money for recycling but i didn't see any recycling barcode paper, where is it?"
@HenryLoenwind
@HenryLoenwind 7 жыл бұрын
The idea is to replace the original product barcode with a fake deposit barcode and not be so greedy that the total of all you buy is weirdly low. Just imagine you buy a week's worth of groceries and mix in a barcode that makes that 5 bucks cheaper---not to buy a single six pack and have the cash register tell the cashier to hand you 800...
@primarypenguin
@primarypenguin 7 жыл бұрын
this makes sense to me, thanks for the clarification
@Minecraft10892
@Minecraft10892 7 жыл бұрын
this is already been answered, but I think he means the person at the cashier is normally supposed to pick up the bar code to test the paper to see if its real, but if you put it under something heavy, the person would lazy out and just scan it instead of checking.
@PereMersenne
@PereMersenne 7 жыл бұрын
Jan 31, 2017 1 Euro equals 1.08 US Dollar
@abstractapproach634
@abstractapproach634 11 ай бұрын
Holy shit, thus will change the game for darknet vendors
@brashcrab
@brashcrab 10 ай бұрын
Timer is FAT 813 9:03
@awlomthesheepermen
@awlomthesheepermen 4 жыл бұрын
Okay you can hack with it but can you run doom on it
@biehdc
@biehdc 7 жыл бұрын
"Abdul bin Scheusal" xDDD translated~: "Abdul is disgusting"
@blazer6248
@blazer6248 5 жыл бұрын
Sounds like he wasn't getting the response he was expecting. Every time he stopped and told them how he did something to screw over 'the man', he would pause expecting them to laugh and clap. Yet no one made a sound. Every time. I'm guessing he's not part of the cool kids.
@SandroSmith
@SandroSmith 4 жыл бұрын
No, its just his awfull jokes.
@CrypticConsole
@CrypticConsole 4 жыл бұрын
He is cool
@PIVfirestarkproducon
@PIVfirestarkproducon 4 жыл бұрын
The mic just doesn't pick up the crowd, the audience was responding well
@Dtr146
@Dtr146 4 жыл бұрын
man tough crowd
@TheAechBomb
@TheAechBomb 4 жыл бұрын
the audio is from his podium mic
@Dtr146
@Dtr146 4 жыл бұрын
@@TheAechBomb how many defcons have you've watched? i could hear the crowd pretty well in all of the presentations i watched.
@Dtr146
@Dtr146 4 жыл бұрын
@@TheAechBomb the point I'm trying to make is, I thought he was funnier than what the crowd gave him. you can see it in has demeanor and face when his jokes bombed.
@Dtr146
@Dtr146 4 жыл бұрын
@@TheAechBomb I just found this funny. the popular comment right below mine talks about the audio quality is defcon 16 being good. and then like an audio quality of defcon 27 being trash
@Dtr146
@Dtr146 4 жыл бұрын
@@TheAechBomb and then you have several other people saying the same thing in the comments
@jonascurry9996
@jonascurry9996 8 жыл бұрын
I need groceries. time to hack
@tosgem
@tosgem 7 жыл бұрын
"ethical hacking", stealing peoples rental DVD's and other things
@edwardecl
@edwardecl 7 жыл бұрын
Sending the pentagon letter bombs... totally ethical.
@TheZigzagman
@TheZigzagman 4 жыл бұрын
@@edwardecl He's not talking about sending The Pentagon mail bombs. He's talking about shipping mail bombs with an authorization code *from* The Pentagon so nobody inspects them.
@SoeaOu
@SoeaOu 11 жыл бұрын
em
@ysmtek
@ysmtek 8 жыл бұрын
Is there a good reason for a casino to host a hackers' conference or just plain stupidity?
@magimichaeltablet
@magimichaeltablet 8 жыл бұрын
Yasja de Miranda As always the reason is money.
@chvishal
@chvishal 8 жыл бұрын
+Igor Seltsam or porn. as he says.
@ysmtek
@ysmtek 8 жыл бұрын
I think you're missing my point: Isn't it a straight RISK to have a single hacker in your casino? how about a full on conference huh?
@chvishal
@chvishal 8 жыл бұрын
thats like saying "isent it dangerous to host a convention for soldiers because they are trained to kill people"
@ysmtek
@ysmtek 8 жыл бұрын
Still missing my point.
@racebends
@racebends 4 жыл бұрын
my work makes us scan the barcode on drivers license of every customer
@ZarkosisSmash
@ZarkosisSmash 6 жыл бұрын
39:30 No laughter?
@MrMiss-cp9bw
@MrMiss-cp9bw 4 жыл бұрын
There's laughter, you're just deaf.
@NatalieSpa888
@NatalieSpa888 9 жыл бұрын
History of Barcodes, Lesson 0 = Practically every barcode has 666 encoded into it, it's the 2 thin stripes on the right, left and middle.
@RESISTAGE
@RESISTAGE 9 жыл бұрын
No it is not.
@izybit
@izybit 8 жыл бұрын
Vital Ral Actually it is and it isn't. Those lines do exist and look like the lines for number 6 but they are not the same. More here: www.av1611.org/666/barcode.html
@RESISTAGE
@RESISTAGE 8 жыл бұрын
Mark of the beast has nothing to do with technology.
@fernando47180
@fernando47180 4 жыл бұрын
"UMMM" -This guy, several times
@keithklassen5320
@keithklassen5320 4 жыл бұрын
Fuck you! Now I can't hear anything else, lol....
@fernando47180
@fernando47180 4 жыл бұрын
@@keithklassen5320 You must suffer the same burden as I did!
@dannyishii3160
@dannyishii3160 4 жыл бұрын
Now you have to make an UM supercut.
@fernando47180
@fernando47180 4 жыл бұрын
@@dannyishii3160 Nah man, it would stress me out too much hearing him say "Umm" that many times, haha. Plus, I have no video editing experience, even though a supercut doesn't sound too complex. Cool idea though
@TJGermany
@TJGermany 4 жыл бұрын
@@fernando47180 please, make one with only "umm", and one without all the "umm".
@skate2funtrack
@skate2funtrack 11 жыл бұрын
uhmmmm no
@ghost_ship_supreme
@ghost_ship_supreme 7 жыл бұрын
Why do most of these hackers enjoy ripping people off and fucking with planes and stuff? Like the automated house security guy was good thou!
@TheEinharjar
@TheEinharjar 7 жыл бұрын
A lot of them usually shrug it of with an explaination that: They personally don't want to hurt people but they want to show people what somebody else could do to hurt them. Kinda greyhat I'd say.
@thpropst
@thpropst 4 жыл бұрын
great talk. but this guy is jumping around so hyperactively, it makes you nervous too. calm down, man!
@NatalieSpa888
@NatalieSpa888 9 жыл бұрын
MARK IT UP BRO lol INFLATION Value added capital
@marcjungk9208
@marcjungk9208 9 жыл бұрын
couldn`t he just think of some other alternatives to the word bullshit?
@MeetDannyWilson
@MeetDannyWilson 9 жыл бұрын
Don't forget, this is FX we are talking about here… I'm only 10 minutes in, but so far he has been comparatively civilized - you should try watching one of his talks in German, they are unbearable…
@fabiboiii
@fabiboiii 7 жыл бұрын
I was wondering if he's German until he said 'one-dynamische barcodes' lmao
@juliusfucik4011
@juliusfucik4011 6 жыл бұрын
It is ironic how you being a German can not recognize a German speaking English. I guess it could be because of lack of exposure to English? It would be an interesting topic of research. Usually, you can instantly spot a Spaniard and tell him apart from an Italian or a Frenchman. Very easy to recognize a Russian et cetera. Once you are a little more advanced you can tell Kiwis from Aussis and Irish from Scots.
@MrMiss-cp9bw
@MrMiss-cp9bw 4 жыл бұрын
​@@juliusfucik4011 It's ironic you're so narrow minded and think only Germans have 'that accent'. Now how about people who get so good at English they sound fucking British. Once you're a bit more educated you'll see how people can perfect a second language as if it's their mother tongue. Broaden your horizon instead of focusing on 'bad English'. Talking about lack of exposure to English, while being as dumb as a door knob 😂 _Once you are a little more advanced you can tell Kiwis from Aussis and Irish from Scots._ No fucking shit Sherlock 🤣
@iJoxy
@iJoxy 10 жыл бұрын
Ganz grober Unfug - translated to - very rough horseplay
@hartley9672
@hartley9672 7 жыл бұрын
uhmmm
@JonesAndGriesmann
@JonesAndGriesmann 6 жыл бұрын
Ummmm..... bar..... ummm... codes....ummmm... were... ummm... invented.... ummmm.....
DEFCON 19: The Art of Trolling (w speaker)
41:32
Christiaan008
Рет қаралды 526 М.
DEFCON 17: That Awesome Time I Was Sued For Two Billion Dollars
31:28
Christiaan008
Рет қаралды 1,6 МЛН
小路飞第二集:小路飞很听话#海贼王  #路飞
00:48
路飞与唐舞桐
Рет қаралды 19 МЛН
YouTube's Biggest Mistake..
00:34
Stokes Twins
Рет қаралды 62 МЛН
Defcon 19: DIY Non-Destructive-Entry
42:15
Schuyler Towne
Рет қаралды 632 М.
Defcon 21 - Forensic Fails - Shift + Delete Won't Help You Here
47:10
HackersOnBoard
Рет қаралды 635 М.
How to Read Barcodes
4:55
Half as Interesting
Рет қаралды 1,9 МЛН
I'll Let Myself In: Tactics of Physical Pen Testers
44:56
Wild West Hackin' Fest
Рет қаралды 2,8 МЛН
DEFCON 19: Hacking MMORPGs for Fun and Mostly Profit ( w speaker)
50:43
Пленка или защитное стекло: что лучше?
0:52
Слава 100пудово!
Рет қаралды 1,5 МЛН
Внутренности Rabbit R1 и AI Pin
1:00
Кик Обзор
Рет қаралды 1,8 МЛН
The PA042 SAMSUNG S24 Ultra phone cage turns your phone into a pro camera!
0:24
#Shorts Good idea for testing to show.
0:17
RAIN Gadgets
Рет қаралды 3,3 МЛН
What % of charge do you have on phone?🔋
0:11
Diana Belitskay
Рет қаралды 267 М.
Any Sound & Call Recording Option Amazing Keypad Mobile 📱
0:48
Tech Official
Рет қаралды 326 М.
СЛОМАЛСЯ ПК ЗА 2000$🤬
0:59
Корнеич
Рет қаралды 2,2 МЛН