Der Chaos Computer Club ist die größte europäische Hackervereinigung, und seit über 25 Jahren Vermittler im Spannungsfeld technischer und sozialer Entwicklungen.
…
continue reading
Der Chaos Computer Club ist die größte europäische Hackervereinigung, und seit über 25 Jahren Vermittler im Spannungsfeld technischer und sozialer Entwicklungen.
…
continue reading
Der Chaos Computer Club ist die größte europäische Hackervereinigung, und seit über 25 Jahren Vermittler im Spannungsfeld technischer und sozialer Entwicklungen.
…
continue reading
Der Chaos Computer Club ist die größte europäische Hackervereinigung, und seit über 25 Jahren Vermittler im Spannungsfeld technischer und sozialer Entwicklungen.
…
continue reading
This feed contains all events from 33c3-sendezentrum as opus
…
continue reading
This feed contains all events from jev22 as mp4
…
continue reading
This feed contains all events from CCCAC as mp4
…
continue reading
This feed contains all events from 36c3 as mp4
…
continue reading
This feed contains all events from 38c3-meta as webm
…
continue reading
This feed contains all events from camp2023 as mp4
…
continue reading
Closing session of All Systems Go! 2025Licensed to the public under https://creativecommons.org/licenses/by/4.0/de/about this event: https://cfp.all-systems-go.io/all-systems-go-2025/talk/DR8ELH/
…
continue reading
Closing session of All Systems Go! 2025Licensed to the public under https://creativecommons.org/licenses/by/4.0/de/about this event: https://cfp.all-systems-go.io/all-systems-go-2025/talk/DR8ELH/
…
continue reading
Closing session of All Systems Go! 2025Licensed to the public under https://creativecommons.org/licenses/by/4.0/de/about this event: https://cfp.all-systems-go.io/all-systems-go-2025/talk/DR8ELH/
…
continue reading

1
One Boot Config to Rule Them All: Bringing UAPI Boot Specification to Legacy BIOS (asg2025)
24:59
24:59
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
24:59The UAPI Boot Loader Specification defines conventions that let multiple operating systems and bootloaders share boot config files. So far, only systemd-boot implements it - and it’s UEFI-only by design.As a result, hybrid UEFI/BIOS images require maintaining (and keeping in sync) two sets of bootloader configs: one for systemd-boot, and one for a …
…
continue reading

1
OS as a Service at Meta Platforms (asg2025)
25:30
25:30
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
25:30I overview how OS management is done at Meta. We run millions of Linux servers and we have to make sure that OS gets updated on all of them in a given period of time. To do that we developed several products: MetalOS (Image based version of CentOS), Antlir (image builder) and Rolling OS Update (a service that keeps a set of DNF repos in sync with u…
…
continue reading

1
One Boot Config to Rule Them All: Bringing UAPI Boot Specification to Legacy BIOS (asg2025)
24:59
24:59
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
24:59The UAPI Boot Loader Specification defines conventions that let multiple operating systems and bootloaders share boot config files. So far, only systemd-boot implements it - and it’s UEFI-only by design.As a result, hybrid UEFI/BIOS images require maintaining (and keeping in sync) two sets of bootloader configs: one for systemd-boot, and one for a …
…
continue reading

1
OS as a Service at Meta Platforms (asg2025)
25:30
25:30
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
25:30I overview how OS management is done at Meta. We run millions of Linux servers and we have to make sure that OS gets updated on all of them in a given period of time. To do that we developed several products: MetalOS (Image based version of CentOS), Antlir (image builder) and Rolling OS Update (a service that keeps a set of DNF repos in sync with u…
…
continue reading

1
OS as a Service at Meta Platforms (asg2025)
25:30
25:30
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
25:30I overview how OS management is done at Meta. We run millions of Linux servers and we have to make sure that OS gets updated on all of them in a given period of time. To do that we developed several products: MetalOS (Image based version of CentOS), Antlir (image builder) and Rolling OS Update (a service that keeps a set of DNF repos in sync with u…
…
continue reading

1
One Boot Config to Rule Them All: Bringing UAPI Boot Specification to Legacy BIOS (asg2025)
24:59
24:59
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
24:59The UAPI Boot Loader Specification defines conventions that let multiple operating systems and bootloaders share boot config files. So far, only systemd-boot implements it - and it’s UEFI-only by design.As a result, hybrid UEFI/BIOS images require maintaining (and keeping in sync) two sets of bootloader configs: one for systemd-boot, and one for a …
…
continue reading

1
What's up with test.thing (asg2025)
25:20
25:20
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
25:20`test.thing` is a VM runner which targets guests using an API defined by systemd. It started after a conversation at devconf about turning `mkosi qemu` into a library. A quick intro.~~composefs is an approach to image-mode systems without the disk images. Files are stored in a de-duplicated content-addressed storage with integrity guaranteed throug…
…
continue reading

1
What's up with test.thing (asg2025)
25:20
25:20
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
25:20`test.thing` is a VM runner which targets guests using an API defined by systemd. It started after a conversation at devconf about turning `mkosi qemu` into a library. A quick intro.~~composefs is an approach to image-mode systems without the disk images. Files are stored in a de-duplicated content-addressed storage with integrity guaranteed throug…
…
continue reading

1
Yocto's hidden gem: OTA and seamless updates with systemd-sysupdate (asg2025)
26:33
26:33
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
26:33Updates are a critical piece of managing your fleet of devices. Nowadays, Yocto-based distributions can utilize layers for well-established update mechanisms. But, did you know that recent releases of Yocto already come with a simple update mechanism?Enter systemd-sysupdate: a mechanism capable of automatically discovering, downloading, and install…
…
continue reading

1
Yocto's hidden gem: OTA and seamless updates with systemd-sysupdate (asg2025)
26:33
26:33
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
26:33Updates are a critical piece of managing your fleet of devices. Nowadays, Yocto-based distributions can utilize layers for well-established update mechanisms. But, did you know that recent releases of Yocto already come with a simple update mechanism?Enter systemd-sysupdate: a mechanism capable of automatically discovering, downloading, and install…
…
continue reading

1
Yocto's hidden gem: OTA and seamless updates with systemd-sysupdate (asg2025)
26:33
26:33
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
26:33Updates are a critical piece of managing your fleet of devices. Nowadays, Yocto-based distributions can utilize layers for well-established update mechanisms. But, did you know that recent releases of Yocto already come with a simple update mechanism?Enter systemd-sysupdate: a mechanism capable of automatically discovering, downloading, and install…
…
continue reading

1
What's up with test.thing (asg2025)
25:20
25:20
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
25:20`test.thing` is a VM runner which targets guests using an API defined by systemd. It started after a conversation at devconf about turning `mkosi qemu` into a library. A quick intro.~~composefs is an approach to image-mode systems without the disk images. Files are stored in a de-duplicated content-addressed storage with integrity guaranteed throug…
…
continue reading

1
A terminal for operating clouds: administering S3NS with image-based NixOS (asg2025)
34:54
34:54
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
34:54S3NS is a trusted cloud operator that self-hosts Google Cloud infrastructure in France, targeting the SecNumCloud certification, the most stringent Cloud certification framework. SecNumCloud includes strict legal and operational constraints. To manage these systems securely and reproducibly, we’ve built a family of dedicated administration terminal…
…
continue reading

1
A terminal for operating clouds: administering S3NS with image-based NixOS (asg2025)
34:54
34:54
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
34:54S3NS is a trusted cloud operator that self-hosts Google Cloud infrastructure in France, targeting the SecNumCloud certification, the most stringent Cloud certification framework. SecNumCloud includes strict legal and operational constraints. To manage these systems securely and reproducibly, we’ve built a family of dedicated administration terminal…
…
continue reading

1
A terminal for operating clouds: administering S3NS with image-based NixOS (asg2025)
34:54
34:54
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
34:54S3NS is a trusted cloud operator that self-hosts Google Cloud infrastructure in France, targeting the SecNumCloud certification, the most stringent Cloud certification framework. SecNumCloud includes strict legal and operational constraints. To manage these systems securely and reproducibly, we’ve built a family of dedicated administration terminal…
…
continue reading

1
UKI, composefs and remote attestation for Bootable Containers (asg2025)
42:50
42:50
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
42:50With Bootable Containers (bootc), we can place the operating system files inside a standard OCI container. This lets users modify the content of the operating system using familiar container tools and the Containerfile pattern. They can then share those container images using container registries and sign them using cosign.Using composefs and fs-ve…
…
continue reading

1
UKI, composefs and remote attestation for Bootable Containers (asg2025)
42:50
42:50
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
42:50With Bootable Containers (bootc), we can place the operating system files inside a standard OCI container. This lets users modify the content of the operating system using familiar container tools and the Containerfile pattern. They can then share those container images using container registries and sign them using cosign.Using composefs and fs-ve…
…
continue reading

1
UKI, composefs and remote attestation for Bootable Containers (asg2025)
42:50
42:50
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
42:50With Bootable Containers (bootc), we can place the operating system files inside a standard OCI container. This lets users modify the content of the operating system using familiar container tools and the Containerfile pattern. They can then share those container images using container registries and sign them using cosign.Using composefs and fs-ve…
…
continue reading

1
Leveraging bootable OCI images in Fedora CoreOS and RHEL CoreOS (asg2025)
25:51
25:51
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
25:51In last year's ASG!, bootc and bootable containers were introduced. In this talk, we'll go over what changed since last year, and how Fedora CoreOS and RHEL CoreOS are leveraging bootable containers to reduce maintenance and increase sharing.Licensed to the public under https://creativecommons.org/licenses/by/4.0/de/about this event: https://cfp.al…
…
continue reading

1
Introducing ue-rs, minimal and secure rewrite of update engine in Flatcar (asg2025)
24:20
24:20
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
24:20Introduce ue-rs, a fresh project that aims to be a drop-in reimplementation of update engine, written in Rust.The goal of ue-rs is to have a minimal, secure and robust implementation of update engine, required by A/B update mechanism of Flatcar Container Linux. Just like the existing update engine, it downloads OS update payloads from a Nebraska se…
…
continue reading

1
Leveraging bootable OCI images in Fedora CoreOS and RHEL CoreOS (asg2025)
25:51
25:51
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
25:51In last year's ASG!, bootc and bootable containers were introduced. In this talk, we'll go over what changed since last year, and how Fedora CoreOS and RHEL CoreOS are leveraging bootable containers to reduce maintenance and increase sharing.Licensed to the public under https://creativecommons.org/licenses/by/4.0/de/about this event: https://cfp.al…
…
continue reading

1
Introducing ue-rs, minimal and secure rewrite of update engine in Flatcar (asg2025)
24:20
24:20
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
24:20Introduce ue-rs, a fresh project that aims to be a drop-in reimplementation of update engine, written in Rust.The goal of ue-rs is to have a minimal, secure and robust implementation of update engine, required by A/B update mechanism of Flatcar Container Linux. Just like the existing update engine, it downloads OS update payloads from a Nebraska se…
…
continue reading

1
Leveraging bootable OCI images in Fedora CoreOS and RHEL CoreOS (asg2025)
25:51
25:51
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
25:51In last year's ASG!, bootc and bootable containers were introduced. In this talk, we'll go over what changed since last year, and how Fedora CoreOS and RHEL CoreOS are leveraging bootable containers to reduce maintenance and increase sharing.Licensed to the public under https://creativecommons.org/licenses/by/4.0/de/about this event: https://cfp.al…
…
continue reading

1
Introducing ue-rs, minimal and secure rewrite of update engine in Flatcar (asg2025)
24:20
24:20
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
24:20Introduce ue-rs, a fresh project that aims to be a drop-in reimplementation of update engine, written in Rust.The goal of ue-rs is to have a minimal, secure and robust implementation of update engine, required by A/B update mechanism of Flatcar Container Linux. Just like the existing update engine, it downloads OS update payloads from a Nebraska se…
…
continue reading

1
container-snap: Atomic Updates from OCI Images using Podman’s Btrfs Driver (asg2025)
22:46
22:46
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
22:46Traditional package updates using tools like RPM or Zypper can introduce risks, such as incomplete updates or accidentally breaking the running system. To overcome these challenges, we developed **container-snap**, a prototype plugin designed to deliver atomic OS updates—updates that are fully applied or rolled back without compromising the system'…
…
continue reading

1
container-snap: Atomic Updates from OCI Images using Podman’s Btrfs Driver (asg2025)
22:46
22:46
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
22:46Traditional package updates using tools like RPM or Zypper can introduce risks, such as incomplete updates or accidentally breaking the running system. To overcome these challenges, we developed **container-snap**, a prototype plugin designed to deliver atomic OS updates—updates that are fully applied or rolled back without compromising the system'…
…
continue reading

1
Dirlock: a new tool to manage encrypted filesystems (asg2025)
26:27
26:27
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
26:27In the Linux world there are several tools and technologies to encrypt data on a hard drive, most falling into one of two categories: block device encryption (like LUKS) or stacked filesystem encryption (like EncFs or gocryptfs). This presentation will introduce Dirlock, a new tool that belongs to a third category: native filesystem encryption, usi…
…
continue reading

1
Dirlock: a new tool to manage encrypted filesystems (asg2025)
26:27
26:27
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
26:27In the Linux world there are several tools and technologies to encrypt data on a hard drive, most falling into one of two categories: block device encryption (like LUKS) or stacked filesystem encryption (like EncFs or gocryptfs). This presentation will introduce Dirlock, a new tool that belongs to a third category: native filesystem encryption, usi…
…
continue reading

1
container-snap: Atomic Updates from OCI Images using Podman’s Btrfs Driver (asg2025)
22:46
22:46
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
22:46Traditional package updates using tools like RPM or Zypper can introduce risks, such as incomplete updates or accidentally breaking the running system. To overcome these challenges, we developed **container-snap**, a prototype plugin designed to deliver atomic OS updates—updates that are fully applied or rolled back without compromising the system'…
…
continue reading

1
Dirlock: a new tool to manage encrypted filesystems (asg2025)
26:27
26:27
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
26:27In the Linux world there are several tools and technologies to encrypt data on a hard drive, most falling into one of two categories: block device encryption (like LUKS) or stacked filesystem encryption (like EncFs or gocryptfs). This presentation will introduce Dirlock, a new tool that belongs to a third category: native filesystem encryption, usi…
…
continue reading

1
Forget zbus, zlink is the future of IPC in Rust (asg2025)
38:14
38:14
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
38:14Last year, Lennart Poettering of the systemd fame, [gave a presentation](https://media.ccc.de/v/all-systems-go-2024-276-varlink-now-) at this very same conference, where he introduced Varlink, a modern yet simple IPC mechanism. He presented a case for Varlink, rather than [D-Bus](https://en.wikipedia.org/wiki/D-Bus) to be the future of Inter-proces…
…
continue reading

1
Forget zbus, zlink is the future of IPC in Rust (asg2025)
38:14
38:14
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
38:14Last year, Lennart Poettering of the systemd fame, [gave a presentation](https://media.ccc.de/v/all-systems-go-2024-276-varlink-now-) at this very same conference, where he introduced Varlink, a modern yet simple IPC mechanism. He presented a case for Varlink, rather than [D-Bus](https://en.wikipedia.org/wiki/D-Bus) to be the future of Inter-proces…
…
continue reading

1
pidfd: What have we been up to? (asg2025)
39:28
39:28
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
39:28File descriptors for processes on Linux have been available for quite some time now. Userspace has adapted them widely.Over the last two years or so we've extended the abilities of pidfds significantly. This talk will go over all the new features and deep dive into their implementation and usage.Licensed to the public under https://creativecommons.…
…
continue reading

1
pidfd: What have we been up to? (asg2025)
39:28
39:28
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
39:28File descriptors for processes on Linux have been available for quite some time now. Userspace has adapted them widely.Over the last two years or so we've extended the abilities of pidfds significantly. This talk will go over all the new features and deep dive into their implementation and usage.Licensed to the public under https://creativecommons.…
…
continue reading

1
Forget zbus, zlink is the future of IPC in Rust (asg2025)
38:14
38:14
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
38:14Last year, Lennart Poettering of the systemd fame, [gave a presentation](https://media.ccc.de/v/all-systems-go-2024-276-varlink-now-) at this very same conference, where he introduced Varlink, a modern yet simple IPC mechanism. He presented a case for Varlink, rather than [D-Bus](https://en.wikipedia.org/wiki/D-Bus) to be the future of Inter-proces…
…
continue reading

1
pidfd: What have we been up to? (asg2025)
39:28
39:28
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
39:28File descriptors for processes on Linux have been available for quite some time now. Userspace has adapted them widely.Over the last two years or so we've extended the abilities of pidfds significantly. This talk will go over all the new features and deep dive into their implementation and usage.Licensed to the public under https://creativecommons.…
…
continue reading

1
Privilege delegation for rootless containers, what choices do we have? (asg2025)
21:43
21:43
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
21:43Going for minimal containers with restricted system calls and unprivileged users is the usual Kubernetes approach these days, and it works great for most web apps. However, the development of more complex infrastructure extensions frequently hinders application functionality.While looking for a solution to deploy virtiofsd in an unprivileged contai…
…
continue reading

1
CentOS Proposed Updates: Bridging the Gap between development and production (asg2025)
25:32
25:32
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
25:32CentOS Stream is especially suited for production deployments. In these environments it's often common to develop improvements to distribution packages and want to contribute them upstream. Unfortunately, until very recently that required one to then maintain their own build and deployment pipeline for the packages, at least until the changes made …
…
continue reading

1
CentOS Proposed Updates: Bridging the Gap between development and production (asg2025)
25:32
25:32
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
25:32CentOS Stream is especially suited for production deployments. In these environments it's often common to develop improvements to distribution packages and want to contribute them upstream. Unfortunately, until very recently that required one to then maintain their own build and deployment pipeline for the packages, at least until the changes made …
…
continue reading

1
CentOS Proposed Updates: Bridging the Gap between development and production (asg2025)
25:32
25:32
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
25:32CentOS Stream is especially suited for production deployments. In these environments it's often common to develop improvements to distribution packages and want to contribute them upstream. Unfortunately, until very recently that required one to then maintain their own build and deployment pipeline for the packages, at least until the changes made …
…
continue reading

1
Privilege delegation for rootless containers, what choices do we have? (asg2025)
21:43
21:43
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
21:43Going for minimal containers with restricted system calls and unprivileged users is the usual Kubernetes approach these days, and it works great for most web apps. However, the development of more complex infrastructure extensions frequently hinders application functionality.While looking for a solution to deploy virtiofsd in an unprivileged contai…
…
continue reading

1
Privilege delegation for rootless containers, what choices do we have? (asg2025)
21:43
21:43
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
21:43Going for minimal containers with restricted system calls and unprivileged users is the usual Kubernetes approach these days, and it works great for most web apps. However, the development of more complex infrastructure extensions frequently hinders application functionality.While looking for a solution to deploy virtiofsd in an unprivileged contai…
…
continue reading

1
Modernizing GNOME (asg2025)
31:54
31:54
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
31:54GNOME has collected some very old code over the years. During the recent GNOME 49 release, we've made some drastic cleanups. Most visibly, we've dropped support for X11 and gained many dependencies on systemd. Let's explore some of the what and why for these changes!Licensed to the public under https://creativecommons.org/licenses/by/4.0/de/about t…
…
continue reading

1
New Linux Kernel Coredump Infrastructure (asg2025)
41:04
41:04
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
41:04Coredumping on Linux has long been a nightmare. Currently two modes are supported:(1) Dumping directly into a file somewhere on the filesystem.(2) Dumping into a pipe connected to a usermode helper process spawned as a child of the system_unbound_wq or kthreadd.For simplicity I'm mostly ignoring (1). There's probably still some users of (1) out the…
…
continue reading

1
New Linux Kernel Coredump Infrastructure (asg2025)
41:04
41:04
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
41:04Coredumping on Linux has long been a nightmare. Currently two modes are supported:(1) Dumping directly into a file somewhere on the filesystem.(2) Dumping into a pipe connected to a usermode helper process spawned as a child of the system_unbound_wq or kthreadd.For simplicity I'm mostly ignoring (1). There's probably still some users of (1) out the…
…
continue reading

1
New Linux Kernel Coredump Infrastructure (asg2025)
41:04
41:04
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
41:04Coredumping on Linux has long been a nightmare. Currently two modes are supported:(1) Dumping directly into a file somewhere on the filesystem.(2) Dumping into a pipe connected to a usermode helper process spawned as a child of the system_unbound_wq or kthreadd.For simplicity I'm mostly ignoring (1). There's probably still some users of (1) out the…
…
continue reading

1
Modernizing GNOME (asg2025)
31:54
31:54
Lejátszás később
Lejátszás később
Listák
Tetszik
Kedvelt
31:54GNOME has collected some very old code over the years. During the recent GNOME 49 release, we've made some drastic cleanups. Most visibly, we've dropped support for X11 and gained many dependencies on systemd. Let's explore some of the what and why for these changes!Licensed to the public under https://creativecommons.org/licenses/by/4.0/de/about t…
…
continue reading