How The NSA Can Read Your Emails

Since [Snowden]’s release of thousands of classified documents in 2013, one question has tugged at the minds of security researchers: how, exactly, did the NSA apparently intercept VPN traffic, and decrypt SSH and HTTP, allowing the NSA to read millions of personal, private emails from persons around the globe? Every guess is invariably speculation, but a paper presented at the ACM Conference on Computer and Communications Security might shed some light on how the NSA appears to have broken some of the most widespread encryption used on the Internet (PDF).

The relevant encryption discussed in the paper is Diffie–Hellman key exchange (D-H), the encryption used for HTTPS, SSH, and VPN. D-H relies on a shared very large prime number. By performing many, many computations, an attacker could pre-compute a ‘crack’ on an individual prime number, then apply a relatively small computation to decrypt any individual message that uses that prime number. If all applications used a different prime number, this wouldn’t be a problem. This is the difference between cryptography theory and practice; 92% of the top 1 Million Alexa HTTPS domains use the same two prime numbers for D-H. An attacker could pre-compute a crack on those two prime numbers and consequently be able to read nearly all Internet traffic through those servers.

This sort of attack was discussed last spring by the usual security researchers, and in that time the researchers behind the paper have been hard at work. The earlier discussion focused on 512-bit D-H primes and the LogJam exploit. Since then, the researchers have focused on the possibility of cracking longer 768- and 1024-bit D-H primes. They conclude that someone with the resources of cracking a single 1024-bit prime would allow an attacker to decrypt 66% of IPsec VPNs and 26% of SSH servers.

There is a bright side to this revelation: the ability to pre-compute the ‘crack’ on these longer primes is a capability that can only be attained by nation states as it’s on a scale that has been compared to cracking Enigma during WWII. The hardware alone to accomplish this would cost millions of dollars, and although this computation could be done faster with dedicated ASICs or other specialized hardware, this too would require an enormous outlay of cash. The downside to this observation is, of course, the capability to decrypt the most prevalent encryption protocols may be in the hands of our governments. This includes the NSA, China, and anyone else with hundreds of millions of dollars to throw at a black project.

Hijacking Quadcopters With A MAVLink Exploit

Not many people would like a quadcopter with an HD camera hovering above their property, and until now there’s no technical resource to tell drone pilots to buzz off. That would require actually talking to a person. Horrors. Why be reasonable when you can use a Raspberry Pi to hijack a drone? It’s the only reasonable thing to do, really.

The folks at shellIntel have been messing around with quads for a while, and have recently stumbled upon a vulnerability in the Pixhawk flight controller and every other quadcopter that uses the MAVLink protocol. This includes the Parrot AR.drone, ArduPilot, PX4FMU, pxIMU, SmartAP, MatrixPilot, Armazila 10dM3UOP88, Hexo+, TauLabs and AutoQuad. Right now, the only requirement to make a drone fall out of the sky is a simple radio module and a computer. A Raspberry Pi was used in shellIntel’s demo.

The exploit is a consequence of the MAVLink sending the channel or NetID used to send commands from the transmitter to the quadcopter in each radio frame. This NetID number is used so multiple transmitters don’t interfere with each other; if two transmitters use the same NetID, there will be a conflict and two very confused pilots. Unfortunately, this also means anyone with a MAVLink radio using the same NetID can disarm a quadcopter remotely, and anyone with a MAVLink radio can tell a quad to turn off, or even emulate the DJI Phantom’s ‘Return to China’ function.

The only required hardware for this exploit is a $100 radio and three lines of code. It is certainly possible to build a Raspberry Pi-based box that would shut down any Pixhawk-equipped quadcopter within radio range, although the folks at shellIntel didn’t go that far just yet. Now it’s just a proof of concept to demonstrate that there’s always a technical solution to your privacy concerns. Video below.

Continue reading “Hijacking Quadcopters With A MAVLink Exploit”

Graphene Grown On Semiconductors Big Step Toward Manufacturability

No modern technology has been met with more hype than graphene. These single-layer sheets of carbon promise everything from incredibly efficient power grids to more advanced electronics to literal elevators to space. Until now, though, researchers have yet to produce graphene sheets or ribbons in a reliable way. Researchers at the University of Wisconsin at Madison and the US Department of Energy Argonne National Laboratory have done just that, growing graphene nanoribbons on the surface of a germanium crystal.

By using a germanium crystal as a substrate, the researchers have found a directionality to the way these graphene nanoribbons form. This has been a problem for researchers experimenting with graphene microelectronics in the past; labs experimenting with making transistors out of carbon nanotubes found growth is highly unpredictable. The controlled growth of graphene nanoribbons opens the door to more precise fabrication, something that is necessary for microelectronics fabrication.

Synthesis of nanoribbons this small have not been possible before. Because germanium itself is a semiconductor – and was used for the first transistor – this discovery may pave the way for the creation of graphene-based circuits grown using the same semiconductor fabrication processes used today.

Skarp Laser Razor Kickstarter Suspended, Jumps To Indiegogo

An irritation-free razor that gives a close shave has been a dream for thousands of years. [Gillette] came close, and with multiple blades came even closer, but all razors today are still just sharpened steel dragged across the skin. This is the 21st century, and of course there’s a concept for a laser razor pandering for your moola. We recently covered the Skarp laser razor and its Kickstarter campaign, and today the campaign has been shut down.

The email sent out to all contributors to the Skarp campaign follows:

Hello,

This is a message from Kickstarter’s Integrity team. We’re writing to notify you that the Skarp Laser Razor project has been suspended, and your pledge has been canceled.

After requesting and reviewing additional material from the creator of the project, we’ve concluded that it is in violation of our rule requiring working prototypes of physical products that are offered as rewards. Accordingly, all funding has been stopped and backers will not be charged for their pledges. No further action is required on your part. Suspensions cannot be undone.

We take the integrity of the Kickstarter system very seriously. We only suspend projects when we find evidence that our rules are being violated.

Regards, Kickstarter Integrity Team

It only took eight hours for the Skarp team to relaunch their crowdfunding campaign on Indiegogo. As of this writing, over 900 people (ostensibly from the 20,000 backers of the original Kickstarter campaign) have pledged to the new campaign.

Although we will never know exactly why Kickstarter suspended the original Skarp campaign, the reason given by the Kickstarter Integrity Team points to the lack of a working prototype, one of the requirements for technology campaigns on Kickstarter. Interestingly, Skarp did post a few videos of their razor working. These videos were white balanced poorly enough to look like they were filmed through green cellophane, a technique some have claimed was used to hide the actual mechanism behind the prototype’s method of cutting hair. A few commenters on the Skarp Kickstarter campaign – and here on Hackaday – have guessed the Skarp prototype does not use lasers, but instead a heated length of nichrome wire. While this would burn hair off, the color of the wire would be a dull red when filmed in any normal lighting conditions. It is assumed the poor quality of the Skarp prototype videos is an attempt to hide the fact they do not have a working prototype.

The Skarp laser razor. Source
The Skarp laser razor. Source

Skarp’s move to Indiegogo has been lauded by some – mostly in the comments section of the Indiegogo campaign – and has been derided on every other forum on the Internet. Indiegogo is commonly seen as the last refuge of crowdfunding scam artist, but there are a few legitimate reasons why a campaign would choose to go to Indiegogo. Kickstarter is not available for campaign founders in all countries, and for some, debiting a card immediately, instead of after the campaign end like Kickstarter does, is a legitimate crowdfunding strategy.

But for a crowdfunding campaign to be suspended on Kickstarter and immediately move to Indiegogo? This almost never ends well. One of the most famous examples, the Anonabox, had its Kickstarter campaign suspended after it was found the creator was simply rebadging an off-the-shelf router. The Anonabox then moved over to Indiegogo where it raised over $80,000. Already the campaign for the Skarp Laser Razor has raised $135,000 USD from Indiegogo, after having its Kickstarter campaign raised over $4 Million. No, Skarp won’t be one of the most successful technology Kickstarter campaigns of all time. We can only hope it won’t be one of Indiegogo’s most successful campaigns.

Internet-Connected Box Displays Emotion, Basement Dwellers Still Unaffected

For one reason or another, Twitter has become the modern zeitgeist, chronicling the latest fashions, news, gossip, and irrelevant content that sends us spiraling towards an inevitable existential ennui. This is a Twitter mood light. It tells you what everyone else on the planet is feeling. You, of course, feel nothing. Because of the ennui.

[Connor] decided it would be a good idea to audit the world’s collective mood using experimental social analytics. He’s doing that by watching millions of tweets a day and checking them against hundreds of keywords for several emotions. These emotions are graphed in real time, placed on a server, correlated and corroborated, and downloaded by a moodLight. Inside the moodLight, the emotions are translated into colors, and displayed with the help of a few RGB LEDs.

The moodLight is currently a Kickstarter campaign, with a $30 pledge getting you an assembled board with an ATMega328, an ESP8266, a few RGB LEDs, and a laser cut enclosure. After it’s assembled, the moodLight connects automagically to the analytics server for a real-time display of the emotional state of the Twitterverse. The display is updated every second, making the backend of this build just slightly more impressive than Kickstarter itself. It’s great work from [Connor], and an interesting experiment in analyzing the state of the Internet.

Bespoke, Artisanal, Hand Made Executables

Programmers and software engineers will always use the latest development environments, the trendiest frameworks, and languages they learned only 21 days ago. What if this weren’t the case? What if developers put care into their craft and wrote programs with an old world charm? What if Windows executables were made with the same patience as artisanal firewood, or free range granola? [Steve] has done it. He’s forging a path into the wilds of truly hand crafted executables.

The simplest executable you could run on a Windows box is just a simple .COM file. This is an extremely simple file format that just contains code and data loaded into 0100h, and a jump to another point in the code. The DOS .EXE file format is slightly more complicated, but not by much. [Steve]’s goal was to build a proper Windows executable without a compiler, assembler, linker, or anything else.

Continue reading “Bespoke, Artisanal, Hand Made Executables”

Hackaday Links: October 11, 2015

[Kratz] just turned into a rock hound and has a bunch of rocks from Montana that need tumbling. This requires a rock tumbler, and why build a rock tumbler when you can just rip apart an old inkjet printer? It’s one of those builds that document themselves, with the only other necessary parts being a Pizza Hut thermos from the 80s and a bunch of grit.

Boot a Raspberry Pi from a USB stick. You can’t actually do that. On every Raspberry Pi, there needs to be a boot partition on the SD card. However, there’s no limitation on where the OS resides,  and [Jonathan] has all the steps to replicate this build spelled out.

Some guys in Norway built a 3D printer controller based on the BeagleBone. The Replicape is now in its second hardware revision, and they’re doing some interesting things this time around. The stepper drivers are the ‘quiet’ Trinamic chips, and there’s support for inductive sensors, more fans, and servo control.

Looking for one of those ‘router chipsets on a single board’? Here you go. It’s the NixCoreX1, and it’s pretty much a small WiFi router on a single board.

[Mowry] designed a synthesizer. This synth has four-voice polyphony, 12 waveforms, ADSR envelopes, a rudimentary sequencer, and fits inside an Altoids tin. The software is based on The Synth, but [Mowry] did come up with a pretty cool project here.