{
  "url": "https://pretalx.c3voc.de/camp2023/talk/NHHEZN/",
  "id": 57571,
  "guid": "8805e64f-3eb0-52b3-a660-33f51d3b3c1a",
  "date": "2023-08-16T20:00:00+02:00",
  "start": "20:00",
  "logo": null,
  "duration": "00:45",
  "room": "Milliways",
  "slug": "camp2023-57571-jens_spahns_credit_score_is_very_good",
  "title": "Jens Spahns credit score is \"very good\"",
  "subtitle": "",
  "track": "Milliways",
  "type": "Talk",
  "language": "de",
  "abstract": "A case study on how to use security research as a method of direct action.",
  "description": "In the context of the CCC, we usually do our vulnerability disclosures responsibly. So we ensure that a vulnerability is closed or at least disclosed to the responsible entity for a certain amount of time before discussing it publicly. The practice of responsible disclosure is more than two decades old and has become the gold standard in handling vulnerabilities as a security researcher.\r\n\r\nOn the other hand, responsible disclosure often also minimizes a vulnerability's impact in public debates and, therefore, is an excellent way to keep everybody safe. Still, it also reduces the usefulness of security research as a method of direct action.\r\n\r\nIn this talk, I would like to explain based on two examples (the ID-Wallet as well as the Bonify case) in which cases I think the impact of a vulnerability can be maximized by shitposting it on Twitter while keeping everyone - except Jens Spahn and Helge Braun - safe.",
  "recording_license": "",
  "do_not_record": false,
  "persons": [
    {
      "guid": "fd6d2d4a-6f67-56cd-9910-822b3ed8c46b",
      "id": 4506,
      "code": "QGDPL3",
      "public_name": "Lilith Wittmann",
      "avatar": null,
      "biography": "https://links.lilithwittmann.de/",
      "answers": []
    }
  ],
  "links": [],
  "attachments": [],
  "room_id": "345ca97a-7eb6-459b-bc53-bc2a8bd5c3f1",
  "origin": "pretalx.c3voc.de"
}