39th Chaos Communication Congress Videos
359 points
10 hours ago
| 9 comments
| media.ccc.de
| HN
neiman
10 hours ago
[-]
Where were people's favourite lectures?

I attended 7 talks.

My favourite talk by far was hacking the GPG. Brilliant, really: https://media.ccc.de/v/39c3-to-sign-or-not-to-sign-practical...

The "In-house electronics manufacturing from scratch" was a very inspiring talk: https://media.ccc.de/v/39c3-in-house-electronics-manufacturi...

The rest were less good for me personally. Either over-dramatic and shallow (with a sexy-sounding topic) or too procedural in topics I'm not an expert in.

reply
weinzierl
8 hours ago
[-]
Somehow it did not get much attention, but Signal president Meredith Whittaker (together with Udbhav Tiwari) spoke about the risks and threats from AI-enabled systems.

AI Agent, AI Spy

https://media.ccc.de/v/39c3-ai-agent-ai-spy

I also found the talk about Asahi interesting, both from a technical standpoint but also as a nice update what the current status is.

Asahi Linux - Porting Linux to Apple Silicon

https://media.ccc.de/v/39c3-asahi-linux-porting-linux-to-app...

Finally, not recorded, but workshops like

Foundation workshop: Hands-on, how does the Internet work?

by Ingo Blechschmidt, is congress at its best. Getting a diverse set of people with various backgrounds and knowledge levels to ARP spoof in a little over an hour is art.

https://events.ccc.de/congress/2025/hub/event/detail/foundat...

reply
Phelinofist
44 minutes ago
[-]
The Asahi talk was good, but the video switched waaaayyyyy too often between slide only -> slide + speaker -> stage -> only speaker. Made me kinda uncomfortable.
reply
aberoham
2 hours ago
[-]
Meredith's talk was extremely scripted, not very original and then she ducked out of taking any audience questions. Udbhav awkwardly stood there but seemed like he could have had much more to say. It was hard to watch.

Mona Wang's talk early on Day 2 wasn't recorded but was the polar opposite -- Original, off-the-cuff, engaging, and just fun to witness.

https://fahrplan.events.ccc.de/congress/2025/fahrplan/event/... https://m0na.net/papers/wirewatch.pdf

reply
pamcake
9 hours ago
[-]
I also enjoyed the GPG talk. Other highlights:

Not an Impasse: Child Safety, Privacy, and Healing Together: https://media.ccc.de/v/39c3-not-an-impasse-child-safety-priv...

APT Down and the mystery of the burning data centers: https://media.ccc.de/v/39c3-apt-down-and-the-mystery-of-the-...

Bluetooth Headphone Jacking: A Key to Your Phone: https://media.ccc.de/v/39c3-bluetooth-headphone-jacking-a-ke...

reply
robingchan
9 hours ago
[-]
order by personal rank:

Sandstorm JP-8000 sawtooth DSP reversing https://www.youtube.com/watch?v=XM_q5T7wTpQ

Washing machines hacking https://www.youtube.com/watch?v=Q1S-PVo3GlA

AMD (ps5 sorta) security: https://www.youtube.com/watch?v=cVJZYT8kYsI

cool demo for the BT headphones talk: https://www.youtube.com/watch?v=TK5Tz4Bt94Y

precise time syncing with PTP: https://www.youtube.com/watch?v=dOt-zRIG5co

x86 > arm with intermediate: https://www.youtube.com/watch?v=3yDXyW1WERg

reply
Beretta_Vexee
7 hours ago
[-]
"Liberation of the Freebox", A slightly crazy Frenchman embarks on a quest to find exploit and write a complex exploit chain, using PrDoom and the Linux HFS+ driver to gain root privileges on his set-top box. All this in order to unlock the recording of somewhat rubbish TV channels such as TF1 and M6.

And he waited almost ten years and the retirement of the hardware to reveal it because he didn't want it to be patched.

If you are into hardware emulation "From silicon to Darude sand-storm" is fun.

the https://media.ccc.de/v/39c3-from-silicon-to-darude-sand-stor...

reply
xorcist
6 hours ago
[-]
Absolutely Cory Doctorow's, for the showmanship alone. Lovely background slides. The message itself might not resonate with everyone.

The talk "Look Up" about unencrypted data over DVB satellite links was also though provoking, both in presentation and in technical content. If there's that much data unencrypted over a mainstream IP link, imagine how much is still on legacy protocols in 2025.

reply
rft
3 hours ago
[-]
I still have to go through my watch list, the age old issue of not having my slides done before congress...

The 10 year of Dieselgate is interesting just from a "how bad is it really?" PoV, I saw the part about curves and other defeat devices already [1].

The Rowhammer talk is likely going to be great as well, I like Daniel's work [2].

The practical Cross-VM Spectre was interesting to show this is still a problem [3].

The opensource secure element was good for trying such a thing, but I wasn't that impressed with the content [4].

[1] https://cfp.cccv.de/39c3/talk/7MSRA7/ https://media.ccc.de/v/39c3-10-years-of-dieselgate

[2] https://cfp.cccv.de/39c3/talk/3JXAJJ/ https://media.ccc.de/v/39c3-rowhammer-in-the-wild-large-scal...

[3] https://cfp.cccv.de/39c3/talk/ATYLN9/ https://media.ccc.de/v/39c3-spectre-in-the-real-world-leakin...

[4] https://cfp.cccv.de/39c3/talk/9DYZXG/ https://media.ccc.de/v/39c3-lessons-from-building-an-open-ar...

reply
g-mork
6 hours ago
[-]
Just for sheer geekery's sake probably the ISDN talk.

For OMG eye opening factor the FreeBSD jails talk (how the hell is this thing still so buggy?) and the talk on unencrypted satellite links

For excellent follow-along value and dedication to ridiculously pointless cause the Freebox talk. "Technically I don't own this box so instead of risking damaging it I'm going to take the extremely long and entertaining route around, somehow involving Doom WAD files"

For showmanship probably the Tegra talk

reply
jacquesm
5 hours ago
[-]
> For OMG eye opening factor the FreeBSD jails talk (how the hell is this thing still so buggy?)

Because everything that complex is going to be that buggy.

With the bugs they found fix a constant number of them still remains.

reply
pantalaimon
2 hours ago
[-]
Linus said 'many eyes make all bugs shallow', but compared to Linux, there are not many eyes looking at FreeBSD.
reply
sunbum
6 hours ago
[-]
https://media.ccc.de/v/39c3-css-clicker-training-making-game... The CSS clicker talk was really entertaining as well as just technological amazing!
reply
lskkgklglw
5 hours ago
[-]
The biggest problem with ccc is that: 0. They are releasing too few tickets. 1. They are releasing the tickets too late. 3. Still not able to pay with card?

I live somewhat nearby, but can’t book or plan a visit because of this. I appreciate that they are releasing videos shortly afterwards though.

reply
neiman
4 hours ago
[-]
You can pay with a card, but there is an additional 5 Euros fee (which is fair enough).

I booked a refundable hotel already in the summer, in case I won't get the tickets. But getting the ticket this year was relatively easy (though maybe I just got lucky).

reply
nickslaughter02
6 hours ago
[-]
The Last of Us - Fighting the EU Surveillance Law Apocalypse

https://media.ccc.de/v/39c3-the-last-of-us-fighting-the-eu-s...

reply
Alconicon
8 hours ago
[-]
I think the blue team ctf ai talk was a good benchmark were we at right now https://media.ccc.de/v/39c3-breaking-bots-cheating-at-blue-t...
reply
lmeyerov
1 hour ago
[-]
Thank you, and happy to answer questions on that, it's been a crazy time!

Maybe of relevance to non-security people here:

1. Most of it is about AI investigating event data in general, not just SOC/IR: cyber, intel, fraud, SRE, and we're even messing with customer 360 & social media data

2. For anyone into vibes coding or building agents, I encourage jumping to the "self-writing AI" section where we're finding we are moving internally from vibes coding -> vibes engineering -> and finally now to eval-driven AI coding loops

And, for anyone in security, doing careful evals here has indeed strongly colored my view on the market :)

reply
SoylentBob
9 hours ago
[-]
The one on the bluetooth headphone vulnerabilities was quite fun: https://media.ccc.de/v/39c3-bluetooth-headphone-jacking-a-ke...
reply
weinzierl
6 hours ago
[-]
Demystifying Fuzzer Behaviour

https://m.youtube.com/watch?v=h3UcecN5fvQ

reply
jacquesm
5 hours ago
[-]
That in-house electronics one is gold.
reply
rs_rs_rs_rs_rs
9 hours ago
[-]
reply
Fnoord
7 hours ago
[-]
I haven't seen all of them (which I wanted to see) yet, I had a lot of fun with various talks. Thus far, my favourite one was hands down [1], and I can explain why. I am not at all good with hardware, nor hardware designing i.e. I'm not the target audience for this talk.

However, the talk was beautiful. It went quick, was informative, good slides, very respectful Q&A (comms and quality-wise), and it had a message of DIY _and_ inspiring hope. It is easy to criticize X or say we need to do better with Y. These guys are doing it, and their journey and findings is completely open source (even though there was substantial financial risk involved). The hacker spirit 101.

[1] https://media.ccc.de/v/39c3-in-house-electronics-manufacturi...

reply
fbias
7 hours ago
[-]
I can’t not see Catbert in the video player iconography. Someone tell me they did this intentionally.
reply
st_goliath
7 hours ago
[-]
The icon is supposed to represent one of those waving cat figurines: https://en.wikipedia.org/wiki/Maneki-neko

It has some long tradition placing those visibly on the podium. As the story goes, the idea is that you can immediately see if the video stream freezes up (because the cat in the video suddenly stops waving). You wouldn't immediately catch that in between talks (when you have some time to fix the issue) if the camera was just pointed at an empty stage with no movement. I think at 30C3 or so, I saw one that was placed so that it would repeatedly knock on the microphone as well.

Anyway, the waving cat has become a bit of a meme by itself and mascot of the VOC, hence also the (animated) icon in video player.

reply
fbias
6 hours ago
[-]
Thank you both!
reply
ximm
7 hours ago
[-]
It is a Maneki-neko (beckoning cat / Winkekatze). The video team started putting them on podiums so they could see when a stream was frozen. So it became kind of a mascot.
reply
kherud
9 hours ago
[-]
One interesting detail: In previous years, Joscha Bach gave a talk on AI, consciousness, and related topics (see e.g. [0]). A similar talk was planned for this year as well, but after emails between him and Epstein were made public (see his comment on this in [1]), his talk was canceled. Instead, there appears to have been an event that critically addressed the situation [2]. Unfortunately it was not recorded. Did anyone attend? A discussion between Joscha and his critics would have been really interesting.

[0] https://media.ccc.de/v/38c3-self-models-of-loving-grace

[1] https://joscha.substack.com/p/on-the-jeffrey-epstein-affair

[2] https://events.ccc.de/congress/2025/hub/en/event/detail/tech...

reply
anotheryou
8 hours ago
[-]
Well that discussion talk is not an open discourse about the situation...

He quoted what he believed was scientific evidence in a private conversation that became public, has comments on fashism being efficient are clearly anti-facist and believed to observe a gender stereotype. No matter if the facts were true, it should be possible to discuss such things (especially those you think are facts) in private without getting canceled. Even if they would play in to the hand of racism or sexism if made as public statements.

I found his appology a bit weak, but I also don't see his offense, despite the messages in public being offensive and possibly harmful.

reply
viccis
6 hours ago
[-]
I think people have little patience lately for tolerating private discussion they find objectionable with Epstein.
reply
lukan
4 hours ago
[-]
I think people have little patience (or rather fear) to engage with different points of view in general these days.
reply
viccis
3 hours ago
[-]
I think people have found out the hard way that the paradox of tolerance is real.
reply
BoredPositron
3 hours ago
[-]
No tolerance for the intolerant.
reply
lukan
3 hours ago
[-]
Can you show me, where exactly Joshua Bach stands for intolerance?
reply
BoredPositron
2 hours ago
[-]
You've read the email exchange with epstein?

How billions dieng to famine would be a good thing or culling the elderly and infirm?

Don't even know why I bother answering.

reply
lukan
2 hours ago
[-]
I read just parts of it. Can you link or explain what you mean here? I do not understand the connection to intolerance.
reply
BoredPositron
2 hours ago
[-]
It's linked right above in this chain. I am not going to discuss why killing people is intolerant. That's just silly even for hn standards.
reply
lukan
2 hours ago
[-]
You edited your post after I commented and there was nothing about killing there before. (Just something about haters)

Indeed not HN standards. And if Joshua said killing people is good, I am interested in a full quote.

reply
anotheryou
1 hour ago
[-]
also interested in the source. read a compilation of mails and this was not in there.
reply
BoredPositron
1 hour ago
[-]
If you are going to defend someone you have no or very distant association with like you stated in another reply. Maybe just maybe read what everyone else is talking about, in this chain it would be his email exchange with epstein. Thanks for making ME read that pseudo intellectual shit again so YOU don't have to.

"too many people, so many mass executions of the elderly and infirm make sense is the fundamental fact that everyone dies at some time .make it imporrisbole to ask so why not earilier. if the brain discards unused neurons, why shold socieity keep their equivalent."

https://www.jmail.world/thread/HOUSE_OVERSIGHT_026413?view=i...

EDIT: There was no comment before I edited mine. @dang can probably timestamp it if you want to make a fuss about.

reply
lukan
1 hour ago
[-]
"EDIT: There was no comment before I edited mine. @dang can probably timestamp it if you want to make a fuss about."

Dang would just flag us both if we make a fuss here.

And what you apparently mean is, that when you started to edit your comment, my answer wasn't there. But it was already, after you edited.

Anyway, I am fine with calling this part a missunderstanding.

reply
lukan
1 hour ago
[-]
Maybe present the full quote?

"too many people, so many mass executions of the elderly and infirm make sense is the fundamental fact that everyone dies at some time .make it imporrisbole to ask so why not earilier. if the brain discards unused neurons, why shold socieity keep their equivalent

The radical idea of treating individuals in a society as cells and the society itself as a well-organized organism is fascism, or course. Probably the most efficient and rationally stringent way of governance, if someone could pull it off in a sustainable way; and if it is aggressive and expansive, its efficiency makes it a virus that everybody will want to stomp out. Fascism makes romantic doo-gooders like me very uncomfortable"

He dares to explore radical taboo ideas and concludes that it would be fascism, which he is not comfortable with.

So .. I see nothing where he is intolerant of anything. But you seem not tolerant for people daring to explore certain thoughts in general? Even if they reach the conclusion this is not the way to go. (And maybe even an attempt at dissuading the other person of those concepts)

reply
BoredPositron
37 minutes ago
[-]
That's why I didn't want to quote anything because it's just deteriorating into a debate club about hypotheticals.

To extend your "full" quote: "The radical idea of treating individuals in a society as cells and the society itself as a well-Organized organism is fascism, or course. Probably the most efficient and rationally stringent way of governance, if someone could pull it off in a sustainable way… I rather like the treatment Fascism gets in the Amazon Series ‘The Man in the High Castle’, which explores what would have happened if the Germans and Japanese had won the war: A society that tries to function as a brutal and ruthlessly efficient machine, eliminating all social and evolutionary slack. It is very dark, but not a flat caricature of pointless evil for its own sake."

Let's stay away from killing people how about the misogyny?:

"You cannot learn what does not attract your attention. Women tend to find abstract systems, conflicts and mechanisms intrinsically boring."

reply
anotheryou
1 hour ago
[-]
oh, did not read that one...
reply
pantalaimon
2 hours ago
[-]
He did have an anual talk beginning with 30C3

https://media.ccc.de/search?p=Joscha

reply
looperhacks
5 hours ago
[-]
Assembly events like [2] are not recorded because they are largely self-organized and barely moderated (if at all).
reply
lukan
3 hours ago
[-]
This one was moderated, though.

"The main part of the workshop consists of a moderated deliberative discussion with the audience."

I think it is a bit ironic, that Joshua got canceled because of a private conversation - and the debate about it is not recorded, so .. in effect people are more free to express their opinions without getting canceled.

Disapointing to me. Joshua seems to have points of views I find debatable (I don't know much about him) But canceling to not have to stand his opinions? That is very much against the hacker spirit to me and he is a smart guy who knows a lot about AI.

reply
weinzierl
9 hours ago
[-]
To add some context and to spare readers who, like me, know nothing about Joscha Bach and only little about Epstein from having to go through all the linked material:

The allegations do not appear to involve abuse or moral complicity with Epstein. Instead, they seem to focus on emails Bach exchanged with Epstein concerning IQ, race, and possibly sex. Bach denies these allegations of racism and sexism.

That is at least how I understand the material based on the provided links.

reply
jtefera
7 hours ago
[-]
For context, this is the email exchange between Joscha and Epstein: https://www.jmail.world/thread/HOUSE_OVERSIGHT_026406?view=i... (original doc: https://epstein-emails.sfo3.digitaloceanspaces.com/docs/HOUS...).
reply
Alconicon
8 hours ago
[-]
Urgh wtf...

This meta discussion synopsis "Tech-Transcendentalism as Hypermodern Myth and Neofeudal Ideology [all creatures welcome]" feels like reading a rabit hole of a mountain.

I would have loved another talk from Joscha, the critisism is weirdly ignorant.

reply
walls
8 hours ago
[-]
"All of the people I know who were friends with this sociopathic child-trafficking pedophile told me he was reformed now" is certainly something to put out there.
reply
blakesterz
10 hours ago
[-]
reply
Phelinofist
4 minutes ago
[-]
It is a very good talk and he makes some really great points, but alas the EU will never have the balls to do this (I'm a EU citizen :'-( )
reply
teroshan
9 hours ago
[-]
Transcript of the speech on his blog: https://pluralistic.net/2026/01/01/39c3/#the-new-coalition

An excerpt:

> I assume you've spotted the pattern by now: the US trade representative has forced every one of its trading partners to adopt anticircumvention law, to facilitate the extraction of their own people's data and money by American firms. But of course, that only raises a further question: Why would every other country in the world agree to let America steal its own people's money and data, and block its domestic tech sector from making interoperable products that would prevent this theft?

> Here's an anecdote that unravels this riddle: many years ago, in the years before Viktor Orban rose to power, I used to guest-lecture at a summer PhD program in political science at Budapest's Central European University. And one summer, after I'd lectured to my students about anticircumvention law, one of them approached me.

> They had been the information minister of a Central American nation during the CAFTA negotiations, and one day, they'd received a phone-call from their trade negotiator, calling from the CAFTA bargaining table. The negotiator said, "You know how you told me not to give the Americans anticircumvention under any circumstances? Well, they're saying that they won't take our coffee unless we give them anticircumvention. And I'm sorry, but we just can't lose the US coffee market. Our economy would collapse. So we're going to give them anticircumvention. I'm really sorry."

> That's it. That's why every government in the world allowed US Big Tech companies to declare open season on their people's private data and ready cash.

> The alternative was tariffs. Well, I don't know if you've heard, but we've got tariffs now!

> I mean, if someone threatens to burn your house down unless you follow their orders, and then they burn your house down anyway, you don't have to keep following their orders. So…Happy Liberation Day?

reply
divan
8 hours ago
[-]
I shared this link on my personal FB page couple of times and it was automatically removed within seconds.
reply
crtasm
7 hours ago
[-]
I imagine it will be uploaded to the youtube channel soon: https://www.youtube.com/@mediacccde
reply
sneak
8 hours ago
[-]
Then why continue to donate time and attention to censorship platforms? Having a Facebook account is completely optional.
reply
divan
6 hours ago
[-]
Network effects, obviously.
reply
aweiher
5 hours ago
[-]
I’d argue that what you're experiencing isn't the Network Effect anymore, but rather Vendor Lock-in.

The Network Effect implies the platform gets better for you as more people join. If they are deleting your content, the network is no longer serving you—it’s just holding you hostage. This is enshitification as it best. (this ironie with a cory doctorow link)

At this stage, it’s just a walled garden. Staying because 'everyone is here' while being silenced is learned helplessness.

You're voluntarily staying in a walled garden that refuses to let you speak.

But: The door is wide open, you can go.

reply
blurbleblurble
8 hours ago
[-]
Wild.
reply
yunnpp
6 hours ago
[-]
Precisely the first video I started downloading and I didn't even realize it was from Cory.

It carries even more weight now that "post-American" is coming from...an American. This guy stands for his ideals, I envy such resolve.

reply
cyberpunk
4 hours ago
[-]
In the talk he mentions he’s from Canada…
reply
pa7ch
4 hours ago
[-]
He has been living in LA and working for the EFF for some time now.
reply
utopiah
3 hours ago
[-]
Upvoted since mine https://news.ycombinator.com/item?id=46452407 didn't take off.

PS: HN sucks with dupes.

reply
ChrisArchitect
8 hours ago
[-]
Some popular selections with discussion so far:

Bluetooth Headphone Jacking: A Key to Your Phone [video]

https://news.ycombinator.com/item?id=46453204

Hacking Washing Machines [video]

https://news.ycombinator.com/item?id=46428496

Escaping containment: A security analysis of FreeBSD jails [video]

https://news.ycombinator.com/item?id=46436828

All my Deutschlandtickets gone: Fraud at an industrial scale [video]

https://news.ycombinator.com/item?id=46411930

reply
peterfirefly
2 hours ago
[-]
It's a strange mix of very good tech talks and left-wing extremism.

I'm looking forward to watching "Who cares about the Baltic Jammer?" and "The art of text (rendering)" as examples of the former.

An example of the latter is "selbstverständlich antifaschistisch!"

reply
pamcake
1 hour ago
[-]
> It's a strange mix of very good tech talks and left-wing extremism.

That last polarisation and othering is odd, unnecessary, divisive and not generally representative of 39c3 talks nor the CCC.

Antifascism is a long tradition among humanists and European hackers and not related to "left-wing extremism".

Why do you find it necessary to discredit the message of that talk? What's the supposedly extremist message in there?

reply
cocodill
3 hours ago
[-]
Unfortunately, the congress is getting worse and worse every year. There are fewer and fewer interesting and technical topics. "It used to be better" moment.
reply
sllabres
2 hours ago
[-]
None of these interesting as "technical topic"? (only examples)

51 Ways to Spell the Image Giraffe

Who cares about the Baltic Jammer?

Asahi Linux - Porting Linux to Apple Silicon

The art of text (rendering)

Excuse me, what precise time is It?

DNGerousLINK

CPU Entwicklung in Factorio

How to render cloud FPGAs useless

Breaking architecture barriers: Running x86 games and apps on ARM

Cracking open what makes Apple's Low-Latency WiFi so fast

Reverse engineering the Pixel TitanM2 firmware

Not To Be Trusted - A Fiasco in Android TEEs

Celestial navigation with very little math

Textiles 101: Fast Fiber Transform

Escaping Containment: A Security Analysis of FreeBSD Jails

Don’t look up: There are sensitive internal links in the clear on GEO satellites

Opening pAMDora's box and unleashing a thousand paths on the journey to play Beatsaber custom songs

Lessons from Building an Open-Architecture Secure Element

And of course some of the Lightning Talks...

reply
cocodill
2 hours ago
[-]
well, about 20 this year?
reply
sllabres
1 hour ago
[-]
Every of the lightning talks itself had about 20 short different topics, And as I wrote these were examples, you didn't expect someone to re-enumerate them here all to refute your statement. You can easily find them yourself. Have look at this page, where others listed their favorites, there are many more. But I don't think from your reply you didn't look at the list of sessions yourself.
reply