From the conference recordings

10 insights from MRMCD 2026’s most viewed talks

Drone teardowns, AI workflows, Euroboxes and virtual machines: ten grounded lessons from MRMCD 2026’s most viewed recordings, with links to each talk.

By Awesome Cybersecurity Conferences

Published

A smiling illustrated computer trailing a rainbow, from the official MRMCD 2026 event artwork
Image: MRMCD 2026 — official event artwork
Dates
September 11–13, 2026
Venue
Robert-Piloty-Gebäude, TU Darmstadt
Theme
GRENZEN ÜBERWINDEN
Available catalog talks
55
Languages
German / English

A box that does not fit its shelf, a traffic-light countdown that keeps changing, and a virtual machine that boots before it can stop gracefully: MRMCD 2026’s popular recordings find surprising depth in familiar systems. They also reach into heavier territory, including drone teardowns, breach response and powerful data analytics. This selection’s appeal is its breadth, with practical making alongside questions about what technical systems do and who lives with their consequences.

MRMCD 2026 ran from September 11–13 in Darmstadt under the theme GRENZEN ÜBERWINDEN, or overcoming boundaries. This recap follows the ten recordings with the highest cumulative YouTube view counts in an October 8 snapshot of the edition’s 55 available eligible catalog talks. Each insight comes from a complete caption read and links to its source recording here on the platform. Together, they offer plenty to investigate, build and question.

10 insights from the recordings

Make evidence easy for others to inspect

Enno Lenze’s drone teardown account is as much about making observations usable as it is about opening equipment. His team sorts components, photographs them, reads markings and asks people with the relevant expertise. A photograph with a scale can give another researcher a question they can actually answer.

That matters because Lenze repeatedly reaches the edge of his own knowledge. AI-assisted identification offers a starting point, while specialists do the deeper work. He also says Ukrainian experts generally already know these findings; his team’s distinctive contribution is public documentation. The lesson is a collaborative evidence trail, with uncertainty still visible.

Follow the data all the way into decisions

Manuel Atug’s critique of Palantir begins with an ontology: objects, attributes and relationships that join people, devices, locations and interactions. In his account, engineers structure the inputs and build workflows around them; an AI model is one component of that larger arrangement.

He argues that the consequential questions concern how those connections become recommendations and actions, and how difficult it can be to replace the surrounding system. An editorial takeaway from his argument is to examine the data, decision process and vendor dependence together. These are Atug’s interpretations of the systems he discusses, grounded here in his recorded critique.

Give policy an operational counterpart

The Berlin incident session makes a sharp distinction between a written rule and a working control. It describes a prohibition on storing plaintext passwords alongside allegedly exposed password lists, then asks what enforced the rule in practice. The same critique reaches logging, detection and legacy applications that constrain recovery.

The broader argument is about resilience: preventing an incident where possible, detecting it and reducing its consequences when it occurs. The session also advocates a regularly updated, timestamped public incident FAQ. Read this as the recording’s assessment of Berlin; its useful operational question is whether policies, systems and response processes can be demonstrated working together.

Check the edges of compatibility

The Eurobox talk gives interoperability a wonderfully physical test. Boxes can share familiar dimensions while differing in bottom depth, handles, wall taper, lids and the points where a shelf supports them. A nominally suitable rack can still fail to hold the combination someone actually bought.

The presenter follows those differences through manufacturing, historical research and practical examples. His investigation raises questions about what the Euronorm label guarantees, rather than treating the name as a complete specification. It is a maker and logistics lesson with a clear application: check the interfaces that touch, and measure the space the object will really occupy.

Start with the people who must use the tool

Enno Lenze recounts a journalist turning a supplied security USB stick into ordinary storage after finding that plugging it in did not do what they expected. Another example concerns a secure system that lacked the recipient’s familiar applications. The intended protection and the actual user experience had separated.

His observations come from his own work, chiefly in Ukraine, where people still have ordinary tasks and established habits amid extraordinary conditions. For designers, the editorial lesson is to investigate that context before proposing a setup. A tool needs an understandable purpose, a workable routine and a fit with the person’s actual risks.

Keep uncertainty visible in the countdown

A bicycle-oriented traffic-light receiver sounds like a simple countdown project. The recording shows why it is harder: the receiver must identify the relevant intersection, lane and signal group, then interpret the timing data supplied for that movement.

When available, those data can include earliest, latest and likely switching times. Traffic-dependent lights may extend a phase, and some intersections in the presenter’s examples supply only the current state. A tidy number can therefore hide missing information or a changing estimate. The prototype’s unfinished mapping and display work is part of the story. Its useful design lesson is to preserve the source’s limits when turning machine data into an interface.

Confirm delivery before claiming connectivity

The MeshCore session with Christian Stankowic shows why hearing a radio signal is only a starting point. Its mapping example distinguishes an acknowledged exchange from overheard traffic, a discovery response and no response at all. Each observation says something different about whether communication works at that location.

The presenters connect those measurements with repeater placement, route visibility and local participation. They also discuss stale map information and devices that are switched off. The practical insight is to test the path a message needs, including the return confirmation, while keeping the network’s limits in view. A promising range figure alone does not describe that path.

Audit the authentication journey

The password session becomes especially revealing when it leaves textbook methods and follows real login flows. The presenter recounts adding a security key to an account, then finding that later sign-ins still requested an email token. Another example involves a password shortened during registration but handled differently at login.

He also explicitly says email-token login is not inherently bad; his concerns include choice, dependencies and what the account actually asks for. The lesson from these reported experiences is to inspect the whole journey: setup, subsequent sign-in, device changes and recovery. A configured option is useful evidence only alongside the behavior it produces.

Separate firmware restrictions from silicon limits

Petri Krohn’s mining-GPU account separates two causes of limited capability. Some restrictions are imposed by firmware; others are tied to physical fuses. He describes comparing variants and an engineering-sample experiment in which changing firmware altered exposed compute and memory.

That distinction gives the research a method: establish which layer is responsible before deciding what can be recovered. Successive implementations then expose different capabilities and reset constraints. Krohn also recounts a clean-room reimplementation based on public material. The insight is careful boundary mapping, rather than a promise that every card becomes an unrestricted A100. The remaining hardware limits still matter.

Treat shutdown as part of the VM

The QEMU session starts with a small working virtual machine and gradually makes its surrounding responsibilities visible. Running it under a service manager keeps it alive after the initiating SSH session ends. But the first stop operation simply terminates QEMU, leaving the guest abruptly cut off.

The presenter then adds a guest power-down request through QEMU’s monitor and waits for completion. Console access and networking require their own decisions too. The example makes shutdown a separate requirement from process exit. Its author repeatedly warns that these are compact teaching demonstrations, with performance and security work left out. That boundary is useful: understand the lifecycle before treating a successful boot as a finished setup.

The most-viewed recordings

Ranked by YouTube views captured on .

  1. MRMCD2026 - Russische Drohnen zerlegen für Anfänger

    Enno Lenze recounts how unfamiliar recovered equipment becomes documented museum material through photographs, component markings, measurement and specialist collaboration. His account emphasizes the limits of his own expertise and the value of publishing findings. In the discussion, he distinguishes that public documentation from discoveries already known to Ukrainian specialists.

    344,401 YouTube viewsWatch recording →
  2. MRMCD2026 - Palantir Überwachungstechnologie und tödliche Kriegswaffen mit KI im CyberWarfare

    Manuel Atug presents a critical account of Palantir’s data integration, ontology and AI workflows, connecting surveillance, military use and decision making. He argues that debates about individual models miss the machinery that makes data actionable. The recording also discusses dependence on an integrated vendor system and his concerns about democratic safeguards.

    146,981 YouTube viewsWatch recording →
  3. MRMCD2026 - Warum Berlin gehackt wurde und wie desolat gehandelt wird

    This critical review of a Berlin cyber incident connects crisis communication with logging, segmentation, enforceable password rules and workable legacy systems. It argues for resilience that keeps administrative services functioning. The recording also considers how sensitive information can remain consequential for affected people long after an incident’s immediate response ends.

    126,586 YouTube viewsWatch recording →
  4. MRMCD2026 - Alles über die Eurobox

    An unusually detailed tour of modular plastic boxes moves from pallet history and manufacturing to lids, rims, handles and shelves that do not always fit together. The presenter questions what the familiar Eurobox label actually guarantees. Practical examples show how nominal dimensions can conceal differences that matter when boxes meet other equipment.

    118,667 YouTube viewsWatch recording →
  5. MRMCD2026 - Kriegsgebiete in Theorie und Praxis

    Enno Lenze describes the gap between imagined crisis scenarios and everyday work in Ukraine. His examples range from changing infrastructure and routines to security tools their recipients do not understand. The recurring point is context: identify the person, task and actual risk before proposing equipment or technical solutions.

    83,699 YouTube viewsWatch recording →
  6. MRMCD2026 - Wie lange ist noch grün? Ampelphasen per WLAN empfangen

    A bicycle-mounted receiver turns traffic-light broadcasts into a display of signal states and possible switching times. The build exposes the work behind a simple countdown: lane matching, awkward time formats, optional data and changing phases. It also distinguishes machine-readable movement states from the simpler signal a person sees.

    68,082 YouTube viewsWatch recording →
  7. MRMCD2026 - MeshCore - Grenzenloser Spaß auf 868 MHz

    This MeshCore introduction, with Christian Stankowic, covers text messaging, repeaters, companions, coverage mapping and software experiments. The presenters distinguish confirmed communication from hearing nearby traffic, and show why local deployment affects a usable route. They also discuss placement, community participation, device availability and the network’s practical limits.

    50,489 YouTube viewsWatch recording →
  8. MRMCD2026 - Passwort-Policies, Anmeldung per Mail-Token und weitere Verbrechen

    The presenter’s tour of passwords, tokens, security keys and passkeys ends with awkward real-world login journeys. He compares configured options with the factors actually requested, highlights registration/login inconsistencies and considers device loss and legacy systems. His examples make authentication a workflow to observe and test, rather than a setting to tick.

    35,691 YouTube viewsWatch recording →
  9. MRMCD2026 - FACEB13D exploit: Liberating the A100 beast inside Nvidia’s CMP 170HX e-waste

    Petri Krohn recounts efforts to recover capabilities from a restricted mining GPU, distinguishing firmware restrictions from physical fuses. Comparisons, an engineering-sample experiment and successive implementations drive the story. The session also discusses public research, a clean-room reimplementation and the limits that remain when hardware and software restrictions coexist.

    23,621 YouTube viewsWatch recording →
  10. MRMCD2026 - Über die Grenzen von Proxmox hinaus: Selber VMs mit QEMU basteln

    A minimal QEMU demonstration makes virtual hardware, serial output, networking and service management visible. The presenter works through persistent execution, graceful shutdown and interactive console access, exposing responsibilities behind management interfaces. He repeatedly frames the setup as a teaching example, with security and performance work deliberately left out.

    21,573 YouTube viewsWatch recording →

More from the recordings

Editorial synthesis: ask for observable behavior

Across the Berlin, traffic-light, MeshCore and QEMU recordings, a useful comparison emerges: a policy, a displayed value, a heard signal and a running process each leave important questions open. The examples make those questions concrete through enforceable controls, timing limits, acknowledgments and guest shutdown. For these four cases, the next step is an observation tied to the intended outcome. This is a synthesis of the selected recordings, rather than a claim about every session at MRMCD.

Editorial synthesis: match the abstraction to real use

The Eurobox, crisis-context, authentication and QEMU talks also put a limit on convenient abstractions. A familiar box format leaves physical fitting work; a supplied security tool still needs a user who understands it; a login label leaves a journey to test; a management layer hides lifecycle decisions. The comparison suggests making the remaining responsibilities explicit for the person doing the work. The useful level of simplicity depends on that person and task, as these particular examples illustrate.