Review: InfiRay P2 Pro Thermal Camera

It probably won’t surprise you to learn that Hackaday is constantly hounded by companies that want us to review their latest and greatest gadget. After all, getting us to post about their product is cheaper, easier, and arguably more effective than trying to come up with their own ad campaign. But if you’ve been with us for awhile, you’ll also know that in-house reviews aren’t something we actually do very often.

The reason is simple: we’re only interested in devices or products that offer something useful or unique to this community. As such, the vast majority of these offers get ignored. I’ll give you an example. For whatever reason, multiple companies have been trying desperately to send me electric bikes with five-figure price tags this year. But since there’s no obvious way to turn that into useful content for the readers of Hackaday, I’m still stuck pedaling myself around like it’s the 1900s. I kid of course…I haven’t dared to get on a bike in a decade.

So I don’t mind telling you that, when InfiRay contacted me about reviewing their P2 Pro thermal camera, the email very nearly went into the trash. We’ve seen these kind of phone-based thermal cameras before, and it seemed to be more of the same. But after taking a close look at the specs, accessories, and claims laid out in the marketing material, I thought this one might be worth checking out first-hand.

Continue reading “Review: InfiRay P2 Pro Thermal Camera”

Bankruptcy Sale Scatters Virgin Orbit To The Winds

When Virgin Orbit filed for bankruptcy in April, it was clear the commercial launch provider was in serious trouble. Despite successfully putting four payloads into low Earth orbit, the spin-off of Richard Branson’s Virgin Galactic space tourism company had struggled to achieve a high enough launch cadence to become profitable, and had recently suffered a highly-publicized failure when their first launch from the UK from the newly-completed Spaceport Cornwall ended in a complete loss of the vehicle.

There was some hope that a buyer would swoop in and save them at the last minute, but now that the bankruptcy auction has spread out the company’s assets among several other players in the commercial launch industry, Virgin Orbital is officially no more. With future launches now off the table, the company’s remaining employees are set to be let go as operations wind down over the coming weeks.

Continue reading “Bankruptcy Sale Scatters Virgin Orbit To The Winds”

Experimenting With 20 Meters Of Outlet Adapters

You may have seen some of the EEVblog dumpster dive videos, where [Dave Jones] occasionally finds perfectly good equipment that’s been tossed out. But this time, rather than a large screen monitor, desktop computer, or a photocopier, he features a stash of 283 electrical outlet double adapters that he found last year. He decided to perform a test in the parking lot, connecting all 283 adapters in series.

Using a pair of power meters and a 2 kW electric heater as a test load, [Dave] and his son [Sagan] measure the loss through this wild setup. It works out to about about 300 W, or roughly 1 W per adapter. He did a follow-up experiment using a FLIR thermal camera, and confirmed that the power loss is reasonably uniform, and that no single rogue adapter consuming all the lost power. After a back of the envelope calculation, we estimate this chain of adapters is about 20 meters long, making this whole thing entirely pointless but interesting nonetheless. Stick around until the end of the video for a teardown — they’re not as cheaply made as you might think.

[Dave]’s crazy experiment aside, we do wonder why someone had so many adapters to throw away in the first place. What would you have done with 283 adapters — left them in the dumpster or rescued them?

Continue reading “Experimenting With 20 Meters Of Outlet Adapters”

Your Own Santa? Thermal Camera Roundup

With Christmas and other end-of-year celebrations, there are gifts. The problem is that your loved ones don’t really know what to get you. Who can blame them? Do you want an Arduino, a Raspberry Pi, or a Blue Pill? Is that 3D printer on sale better than the one you have? Do you even want a second printer? They don’t know. In the best case, they’ll give you gift cards. But sometimes you just have to buy yourself something nice. [Wired] has a suggestion: a phone-based thermal camera. Which one? They have four suggestions ranging from about $150 to $200.

Different people have different reasons for wanting a thermal camera. You can see hot spots in electronics, for example. Or pick out hot water pipes behind walls. The resolution is limited. The highest in the [Wired] review is only 206×136. For the digital camera buffs, that’s 0.028 megapixels! Some cameras have even less resolution. For example, one of the cameras has an 80×60 resolution but uses an optical camera to give the illusion of a higher resolution.

Continue reading “Your Own Santa? Thermal Camera Roundup”

A working, partially disassembled thermal camera

Cheap Display Fix Brings Thermal Camera Back To Life

When it comes to repairability of electronic devices, much depends on how helpful the original manufacturer is. Some make repairs very easy by publishing detailed service manuals and selling spare parts. Others keep everything under wraps to protect their intellectual property, turning even a supposedly simple fix into a reverse engineering ordeal. When [BuyItFixIt] got his hands on a FLIR multimeter-thermal camera combination instrument with a broken display, he quickly found that FLIR was firmly in the “all our designs are top secret” camp and wouldn’t even tell him what kind of display they had used.

Not to be deterred, [BuyItFixIt] took the meter apart and tried to find out what was going wrong. The signals from the microprocessor seemed to reach the display OK, so the fault was somewhere in the screen itself. The display’s part number didn’t return any useful results online, but AliExpress did have a very similar-looking display available with a slightly different part number. This display seemed to work at first, but the instrument then got caught in a boot loop.

Unlike FLIR, the supplier of the replacement display was happy to supply datasheets, and even had one available for the original FLIR part. With this new information [BuyItFixIt] was able to deduce that the new screen didn’t output one signal that the processor expected to see, causing it to reset itself. A simple workaround was to connect the corresponding pin to a PWM signal from the backlight controller, which fooled the CPU into thinking the proper display was connected.

In this case, a $12 display and a single piece of wire were enough to bring an expensive instrument back to life, but things are not always that simple. More complex machines can take weeks to debug, even if parts are available. If not, you might even need to design your own. Continue reading “Cheap Display Fix Brings Thermal Camera Back To Life”

Restoring $5 Busted Synthesizer Made Easy, Thanks To Thermal

[D. Scott Williamson] paid $5 for a Roland JV-30 synthesizer at a garage sale. Score! There was only one catch: it didn’t work and didn’t include the power supply. Luckily, restoring it was made easier by breaking out a thermal camera.

As mentioned, the keyboard was missing a 9 VDC power supply (rated 800 mA) with a center-negative barrel connector. Slightly oddball, but nothing an enterprising hacker can’t deal with. After supplying power with a bench supply, not only did the keyboard not come to life, but the power supply clamped the current draw at 1.5 A! Something was definitely not right.

This shorted glass-bodied diode might look normal to the naked eye, but thermal imaging makes it clear something’s amiss.

Inside, there was no visible (or olfactory) sign of damage, but looking closer revealed that a little SMT capacitor by the power connector was cracked in two. Fixing that didn’t bring the keyboard to life, so it was time to break out the thermal imager. Something was soaking up all that current, and it’s a fair bet that something is getting hot in the process.

The culprit? The reverse polarity protection diode was shorted, probably as a result of damage by an inappropriate power supply or a surge of some kind. Replacing it resulted in a working keyboard! Not bad at all for $5, a diode, an SMT cap, and a little workbench time. The finishing touch was replacing a missing slider knob, which took some work in OpenSCAD and a 3D printer. Overall, not bad!

Thermal imaging used to be the stuff of staggering price tags, but it’s downright accessible these days, and makes it easy to spot things that are hot when they shouldn’t be. And if a thermal camera’s lens isn’t what you think it should be? It’s even possible for a sufficiently motivated and knowledgeable hacker to modify those.

This Week In Security: IoT In The Hot Tub, App Double Fail, And FreeBSD BadBeacon

[Eaton Zveare] purchased a Jacuzzi hot tub, and splurged for the SmartTub add-on, which connects the whirlpool to the internet so you can control temperature, lights, etc from afar. He didn’t realize he was about to discover a nightmare of security problems. Because as we all know, in IoT, the S stands for security. In this case, the registration email came from smarttub.io, so it was natural to pull up that URL in a web browser to see what was there. The page presented a login prompt, so [Eaton] punched in the credentials he had just generated. “Unauthorized” Well that’s not surprising, but what was very odd was the flash of a dashboard that appeared just before the authorization complaint. Could that have been real data that was unintentionally sent? A screen recorder answered that question, revealing that there was indeed a table loaded up with valid-looking data.

Digging around in the page’s JavaScript comes up with the login flow. The page uses the Auth0 service to handle logins, and that service sends back an access token. The page sends that access token right back to the Auth0 service to get user privileges. If the logged in user isn’t an admin, the redirect happens. However, we already know that some real data gets loaded. It appears that the limitations to data is all implemented on the client side, and the backend only requires a valid access token for data requests. What would happen if the response from Auth0 were modified? There are a few approaches to accomplish this, but he opted to use Fiddler. Rewrite the response so the front-end believes you’re an admin, and you’re in.

This approach seems to gain admin access to all of the SmartTub admin controls, though [Eaton] didn’t try actually making changes to see if he had write access, too. This was enough to demonstrate the flaw, and making changes would be flirting with that dangerous line that separates research from computer crime. The real problem started when he tried to disclose the vulnerability. SmartTub didn’t have a security contact, but an email to their support email address did elicit a reply asking for details. And after details were supplied, complete radio silence. Exasperated, he finally turned to Auth0, asking them to intervene. Their solution was to pull the plug on one of the two URL endpoints. Finally, after six months of trying to inform Jacuzzi and SmartTub of their severe security issues, both admin portals were secured.

Continue reading “This Week In Security: IoT In The Hot Tub, App Double Fail, And FreeBSD BadBeacon”