Issue dossier
The later public CDC Badge OS README states that flashing can wipe stored FIDO2/U2F credentials, TOTP seeds, password-vault entries, GPG keys, and PIN data; it calls the project a proof of concept/demonstrator and says not to use it as-is for production or security-critical deployments.
A linkable camp-impact record with badge context, severity, evidence confidence, and source notes.
Back to issues index
beta firmware, sensitive-data, and security-critical-use boundary · public firmware README · public source explicitly pre-1.0 beta
The record may describe the public software capability surface but does not endorse the firmware, vouch for its cryptography, privacy, data durability, or safety, or imply it was the software deployed at 39C3.
- Badge
- 39C3 Critical Decentralization Cluster Badge
- Category
- beta firmware, sensitive-data, and security-critical-use boundary
- Severity
- warning
- Confidence
- public firmware README
- Status
- public source explicitly pre-1.0 beta
- Timeframe
- 2026 public firmware state
- Source note
- krim404/cdc-badge-os README.
assembly retrospective
The cluster's own 39C3 page ties the CDC Badge repository to the completed December 27-30, 2025 Hamburg assembly context.
Badge: 39C3 Critical Decentralization Cluster Badge
firmware status and safety documentation
The firmware README documents ESP-IDF/PlatformIO, FIDO2/WebAuthn, GPG/SSH, TOTP, password-vault, plugin, BLE, and data-loss/early-beta caveats.
Badge: 39C3 Critical Decentralization Cluster Badge
hardware and documentation repository
RIAT's public CDC Badge source tree with KiCad hardware, printable cases, documentation, fabrication instructions, expansion descriptions, and linked firmware projects.
Badge: 39C3 Critical Decentralization Cluster Badge
hardware license
Public CERN Open Hardware Licence v2 Permissive source for the RIAT CDC Badge project, with third-party component attribution retained separately by the repository.
Badge: 39C3 Critical Decentralization Cluster Badge
official 39C3 assembly event
Primary official Congress event page explicitly calling the artifact an electronic conference badge and devboard, and naming its TROPIC01, ESP32-S3, e-paper, LiPo, keypad, and expansion surface.
Badge: 39C3 Critical Decentralization Cluster Badge
official assembly page
Official 39C3 assembly page for the Critical Decentralization Cluster, which lists the CDC Badge presentation in its recorded assembly programme.
Badge: 39C3 Critical Decentralization Cluster Badge
post-event public firmware
Public GPL-3.0 firmware project for CDC Badge v1.0/v1.1 hardware. Its January-July 2026 public history is kept separate from an asserted 39C3 deployed image.
Badge: 39C3 Critical Decentralization Cluster Badge
power and firmware caution
Source-published checklist covering BQ25895 charge-current/power settings, USB interaction, and TROPIC01 sleep requirements; it is not proof of configuration on every event unit.
Badge: 39C3 Critical Decentralization Cluster Badge
versioned open-hardware release
Public v1.1 release evidence for the CDC Badge hardware tree. It does not identify which source revision, if any, was on a particular 39C3 physical unit.
Badge: 39C3 Critical Decentralization Cluster Badge
39C3 Hub / Chaos Communication Congress · retrieved 2026-05-15
Official assembly source that places the CDC Badge presentation in 39C3's cluster programme and describes the Critical Decentralization Cluster's event role.
Badge: 39C3 Critical Decentralization Cluster Badge
39C3 Hub / Chaos Communication Congress · retrieved 2026-05-15
Primary official Congress source identifying the CDC Badge as an electronic conference badge and devboard with TROPIC01, ESP32-S3, e-paper/frontlight, LiPo battery path, keypad, and expansion ports.
Badge: 39C3 Critical Decentralization Cluster Badge
Critical Decentralization Cluster · retrieved 2026-05-15
Cluster-owned retrospective for the completed 39C3 assembly, its dates and location, and its direct CDC Badge repository link.
Badge: 39C3 Critical Decentralization Cluster Badge
RIAT Institute / GitHub · retrieved 2026-05-15
Primary CERN-OHL-P-2.0 license source for the CDC Badge hardware project; it does not automatically license every unrelated event mark or media asset.
Badge: 39C3 Critical Decentralization Cluster Badge
RIAT Institute / GitHub · retrieved 2026-05-15
Versioned public v1.1 CDC Badge release. It is source-release evidence, not a confirmed physical 39C3-unit firmware or bill-of-materials mapping.
Badge: 39C3 Critical Decentralization Cluster Badge
RIAT Institute / GitHub · retrieved 2026-05-15
Primary configuration-caution source for BQ25895 charging/power settings, USB interaction, full power-off, and TROPIC01 sleep handling.
Badge: 39C3 Critical Decentralization Cluster Badge
RIAT Institute / GitHub · retrieved 2026-05-15
Primary open-hardware source for the ESP32-S3/TROPIC01 board, e-paper/keypad/expansion design, KiCad fabrication material, linked firmware, and project-level licensing.
Badge: 39C3 Critical Decentralization Cluster Badge
krim404 / GitHub · retrieved 2026-05-15
Primary public firmware-status source for the documented secure-element application surface and explicit early-beta/data-loss/security-critical-use warnings.
Badge: 39C3 Critical Decentralization Cluster Badge
krim404 / GitHub · retrieved 2026-05-15
Public post-event GPL-3.0 firmware source for CDC Badge v1.0/v1.1 hardware. Its later source availability is not treated as a 39C3 deployment ledger.
Badge: 39C3 Critical Decentralization Cluster Badge