Gaming With Roombas


Yesterday we looked at the Pac-Man Roomba casemod. In the video, creator [Ron Tajima] expressed interest in seeing Roombas participate in real life games. So we did some digging around and found some used in an interesting augmented reality game. From Brown University, these modified Roomba Create units play various games, like tag, with an underlying goal of developing smarter robots.

The setup consists of a Java powered client/server arrangement. The game server coordinates the Small Universal Robot Vehicles (SmURVs) and builds a database of events for future use. Players can also control the robots through a Java telepresence client.

The units themselves are made up of the iRobot Create with a Mini-ITX computer strapped to the top. They run Linux and communicate over WiFi with the server and players. They also have an IR emitter used in the games to “shoot” other units.

Gameplay has the server acting as the referee and humans only acting as instructors. The humans come into play when the robots are unable to respond based on their existing database of decision making policies. Through the client, players are able to see exactly what the robot sees with the addition of 3D overlays. Future plans for the game include removing the camera view and replacing with nothing but these overlays. One of the final goals of the project was to create a 24/7/365 gaming experience similar to what is found in MMOs and Xbox Live applications today.

ARP Poisoning Is Still A Problem


You’ve no doubt heard that the site hosting Metasploit, the exploit framework, was hacked earlier this week, but what you may not have heard is that it was done using a layer 2 attack. Though Metasploit.com was not actually cracked, a server on the same VLAN was compromised and used to ARP poison the gateway. ARP poisoning is a method of sniffing data by sending a false ARP message to an Ethernet router to associate the hacker’s MAC address with a valid IP address from a genuine network node. From there the hackers were able to mount their MITM attack and show the image above instead of Metasploit’s website. This problem could have been avoided if the ISP was using fixed ARP entries, which is what [HD Moore] had to do to get the site back online. [Richard Bejtlich] points out that even though most people have been focusing on application security lately, fundamental attacks like this still happen. If you’re doing a good job protecting yourself, you can still be at the mercy of the security of 3rd parties when operating in shared hosting environments.

Hydrophone


Chances are you’ve never wondered what your goldfish is trying to say, but if you have (or if you just want a project), check out this DIY hydrophone.

You will need a computer microphone, vegetable oil, plastic wrap, scissors, solder, and a small unused plastic bottle. Solder the mic capsule to an appropriate length of cable and test. The entire assembly can then be submerged in vegetable oil inside a plastic bottle. Yes, vegetable oil. Seal the bottle and you’re done.

DIY Slingbox


[David] took some interesting steps to put together his own Slingbox-ish setup. He used a Mac mini running Quicktime Broadcaster to capture the stream from a Firewire video camera which his cable/satellite receiver is plugged into. You’ll have to use an OS X machine, but that’s not too difficult these days. Broadcaster is about the simplest way to capture from Firewire and stream. We’re using it in our own office to multicast the signal from a Canadian satellite box.

Roomba Pac-Man


[Ron Tajima] fashioned a Pac-Man casemod for his Roomba using 448 LEDs and a SH2 MPU control unit. It features the correct arcade sounds and even the death animation. The bot has Bluetooth access thanks to his previous Wiimote hack. He hopes to use this platform to create a real world version of the game.

[youtube=http://www.youtube.com/watch?v=2wsP_nmk_iw&hl=en]

For more Roomba hacking, check out the Hacking Roomba book and our previous Roomba related posts.

[via Geekdad]

Using Multiple Browsers For Security


[Rich] over at Securosis takes us through some of his browser paranoia exercises. He uses different browser profiles for different types of web activities. Based on potential risk, various tasks are separated to protect from CSRF attacks and more. Everyday browsing with low risk passwords is done in one. RSS reading with no passwords is done in another. He runs his personal blog in a browser dedicated just to that.

For high risk research, he uses virtual machines to further minimize any potential nasty code getting through. Very high risk sites are browsed through a non-persistent read-only Linux virtual machine. While these techniques can be less effective if the entire OS is comprised, they can still provide a few layers of additional security.

Fellow browser paranoia sufferers may want to consider Firefox plug-ins like NoScript and memory protection from Diehard.

Playing The Building With David Byrne


Do you remember the solenoid concert that used a sequencer to control several solenoids striking different surfaces? Musician David Byrne has taken the concept and executed it on a much larger scale with his “Playing the Building” installation in an old municipal ferry terminal in New York. Devices that bang the girders, rattle the rafters, and blow through the pipes of the building are attached to the only object inside, a weathered pipeorgan. Every key is wired to different device in the building, each producing a unique sound. Attendees are invited to fiddle with keys of the organ to produce sounds from the building’s various materials, thus playing the building like an instrument. Here’s a video from the installation.

[via Today and Tomorrow]