Avatar
Dr. Hax
d30ea98ea65e953f91ab93f6b30ea51eb33c506f87d49f600a139aef00aa9511
Cypherpunk. Infosec veteran of about 15 years (vulnerability research, exploit development and cryptography). Cypherpunks write code. :-) Signet maintainer. Self-custody your passwords... in hardware! https://hax0rbana.org/signet Want to see wider adoption so Bitcoin can be used as digital cash and not just an investment vehicle. XMR: 44RDkTFmTeSetwAprJXnfpRBNEJWKvA5dBH5ZVXA4DofgoZ9AgjyZdSa2fo7pMD3Qe3pdKga8X22y3Lyn1xYde5kPQPzVUu

I'm enjoying focusing on a single project for a day. Well, half-day, but point being: a longer block than usual.

Normally I'm continuously bouncing back and forth between projects and nyms. It feels like I have a lot more focus today, which might be why I'm only working on #Signet today and not switching around

I think this #OpenSource #Hardware Association membership drive is giving me a distraction too. So I'm bouncing back and forth, but it's between the stream and #Signet. Interesting to take a step back and think about these things.

I've been working on a new case design and I am fascinated that the exact same model, printed at different quality levels (layer heights) fit better with the LOWER quality setting.

I've adjusted the model, and I hope that the low quality one will still fit perfectly and the high quality one will fit better.

Will post pics later.

Here is some amazing documentation for assembling mechanical hardware: https://github.com/Open-Lab-Starter-Kit/Online-Documentation

It's open source and it makes your documentation much better. The model is accessible in a web browser, including paning around, zooming, and showing an exploded view. It also make the task of keeping your documentation up to date easier: just drop your new model in and you're done.

They just keep going! Now they're talking about #OpenSource medical devices. This is a great way to inspire people to join. Even people like with almost no income (namely: me) are considering joining.

Do you like #OpenSource #Hardware? The Open Source Hardware Association is doing a membership drive right now. People are showing off their open source hardware projects right now. The current speaker is talking about building open source hardware for people with disabilities! https://www.youtube.com/watch?v=L6jIMzSJioc

If you can afford to join, I'd encourage you to do so! You can pay anytwhere from $25/year to $1000/year

Three USB keyboard/mouse to PS/2 hats complete. 4 transistors and 8 resistors on the hat + bring your own raspberry pi pico.

Cable is taped together because I had to make it into a crossover cable.

#OpenSource #FOSS #hardware #security #privacy #DIY

ICYMI, that Linux RCE in all GNU/Linux systems was all hype.

From wdormann:

"- Does NOT affect all GNU/Linux systems.

- Is not CVSS 9.9. I put it at a 6.3

It also requires:

1) The victim system has no active firewall to block incoming connections.

2) A user on the victim system must print something to a printer that mysteriously appears on the system that has never been there before.

If these two things happen, then command execution can happen as the "lp" user.

We get it.  You found a vulnerability.

Lying about it to try to stir up interest in it is not appreciated by anybody who takes themselves seriously in this industry."

https://infosec.exchange/@wdormann/113205636224106943

I think he wrote iptables itself as well, not just the man page!

Who knew that heating up water needed a micro computer? 🤣

TorBrowser, DuckDuckGo browser or Mull are all good choices.

Can't do it.

It only works with stock Android and I lug around a second phone specifically for this.

They're using hardware security features that just so not function with aftermarket images. I can't remember the details, but working around it would require breaking the hardware security feature. They're trying to guarantee credit card companies that the cards are always being protected by their security approved code and it's not being undermined by someone having a weaker O/S. Of course, this also prevents people from using it when they have a stronger O/S.

Ironically, Google Pay works just fine on devices that are long past end of life and haven't gotten any security patches in years. Let's hope they don't change that so I can keep using this cheap old phone for credit card taps while my actually secure one can hold my personal data.

What does that "...chippen + pinnen" sign translate to in English?

Like, I can guess that last part is about paying with credit cards (chip + PIN), but what does that first part say?

It's hard to succinctly capture how sodding cool #Meshtastic is.

- There are pictures of #hardware, but they don't really do it justice.

- There are maps, which are better, but still fall short

- Once in a blue moon there will be a diagram, which is getting closer to communicating the awesomeness level

I feel like the low cost, resilliance, and utility are just really tough to get into a single post, graphic, or even a short (e.g. 30 second) video.

Hopefully I'll come up with something novel by the time my new nodes arrive.

If you've never seen the movie "Network" (1976), it's worth a watch. Here's a scene and quote from it (note: the video is a bit of a spoiler since you can see which characters are speaking with each other):

https://www.americanrhetoric.com/MovieSpeeches/moviespeechnetwork4.html

You are an old man who thinks in terms of nations and peoples. There are no nations. There are no peoples. There are no Russians. There are no Arabs. There are no third worlds. There is no West. There is only one holistic system of systems, one vast and immane, interwoven, interacting, multivariate, multinational dominion of dollars. Petro-dollars, electro-dollars, multi-dollars, reichmarks, rins, rubles, pounds, and shekels.

It is the international system of currency which determines the totality of life on this planet. That is the natural order of things today. That is the atomic and subatomic and galactic structure of things today! And YOU have meddled with the primal forces of nature, and YOU WILL ATONE!

Am I getting through to you, Mr. Beale?

You get up on your little twenty-one inch screen and howl about America and democracy. There is no America. There is no democracy. There is only IBM and ITT and AT&T and DuPont, Dow, Union Carbide, and Exxon. Those are the nations of the world today.

What do you think the Russians talk about in their councils of state -- Karl Marx? They get out their linear programming charts, statistical decision theories, minimax solutions, and compute the price-cost probabilities of their transactions and investments, just like we do.

We no longer live in a world of nations and ideologies, Mr. Beale. The world is a college of corporations, inexorably determined by the immutable bylaws of business. The world is a business, Mr. Beale. It has been since man crawled out of the slime. And our children will live, Mr. Beale, to see that perfect world in which there's no war or famine, oppression or brutality -- one vast and ecumenical holding company, for whom all men will work to serve a common profit, in which all men will hold a share of stock, all necessities provided, all anxieties tranquilized, all boredom amused.