Closing Out DEF CON 23

We had a wild time at DEF CON last week. Here’s a look back on everything that happened.

defcon-23-hackday-breakfast-thumbFor us, the festivities closed out with a Hackaday Breakfast Meetup on Sunday morning. Usually we’d find a bar and have people congregate in the evening but there are so many parties at this conference (official and unofficial) that we didn’t want people to have to choose between them. Instead, we made people shake off the hangover and get out of bed in time for the 10:30am event.

We had a great group show up and many of them brought hardware with them. [TrueControl] spilled all the beans about the hardware and software design of this year’s Whiskey Pirate badge. This was by far my favorite unofficial badge of the conference… I made a post covering all the badges I could find over the weekend.

We had about thirty people roll through and many of them stayed for two hours. A big thanks to Supplyframe, Hackaday’s parent company, for picking up the breakfast check and for making trips like this possible for the Hackaday crew.

Hat Hacking

For DEF CON 22 I built a hat that scrolls messages and also serves as a simple WiFi-based crypto game. Log onto the access point and try to load any webpage and you’ll be greeted with the scoreboard shown above. Crack any of the hashes and you can log into the hat, put your name on the scoreboard, and make the hat say anything you want.

Last year only one person hacked the hat, this year there were 7 names on the scoreboard for a total of 22 cracked hashes. Nice work!

  • erich_jjyaco_cpp    16 Accounts
  • UniversityOfAriz     1 Account
  • @badgerops             1 Account
  • conorpp_VT             1 Account
  • C0D3X Pwnd you    1 Account
  • D0ubleN                   1 Account
  • erichahn525_VTe     1 Account

Three of these hackers talked to me, the other four were covert about their hat hacking. The top scorer used a shell script to automate logging-in with the cracked passwords and putting his name on the scoreboard.

I’d really like to change it up next year. Perhaps three hats worn by three people who involves some type of 3-part key to add different challenges to this. If you have any ideas I’d love to hear them below, or as comments on the project page.

[Eric Evenchick] on socketCAN

eric-evenchick-socketCAN-defcon-23-croppedOne of the “village” talks that I really enjoyed was from [Eric Evenchick]. He’s been a writer here for a few years, but his serious engineering life is gobbling up more and more of his time — good for him!

You probably remember the CANtact tool he built to bring car hacking into Open Source. Since then he’s been all over the place giving talks about it. This includes Blackhat Asia earlier in the year (here are the slides), and a talk at BlackHat a few days before DEF CON.

This village talk wasn’t the same as those, instead he focused on showing what socketCAN is capable of and how you might use it in your own hacking. This is an open source software suite that is in the Linux repos. It provides a range of tools that let you listen in on CAN packets, record them, and send them out to your own car. It was great to hear [Eric] rattle off examples of when each would be useful.

Our Posts from DEF CON 23

If you missed any of them, here’s our coverage from the conference. We had a blast and are looking forward to seeing everyone there next year!

I2C Bus Splitting With A More Professional Touch

Last week, I covered some of the bitter details of an interesting hack that lets us split up the I²C clock line into multiple outputs with a demultiplexer, effectively giving us “Chip Selects” for devices with the same address.

This week, I figured it’d be best to layout a slightly more practical method for solving the same problem of talking to I²C devices that each have the same address.

I actually had a great collection of comments mention the same family of chips I’m using to tackle this issue, and I’m glad that we’re jumping off the same lead as we explore the design space.

Recalling the Work of Our Predecessors

Before figuring out a clever way of hacking together our own solution, it’s best to see if someone before us has already gone through all of the trouble to solve that problem. In this case–we’re in luck–so much that the exact bus-splitting behavior we want is embedded into a discrete IC, known as the PCA9547.

chip_reverence

It’s worth remembering that our predecessors have labored tirelessly to create such a commodity piece of silicon.

The PCA9547 (PDF) is an octal, I²C bus multiplexer, and I daresay, it’s probably the most practical solution for this scenario. Not only does the chip provide 8 separate buses, up to seven more additional PCA9547s can be connected to enable communication with up to 64 identical devices! What’s more, the PCA9547 comes with the additional benefit of being compatible with both 3.3V and 5V logic-level devices on separate buses. Finally, as opposed to last week’s “hack,” each bus is bidirectional, which means the PCA9547 is fully compliant with the I²C spec.

Selecting one of the eight I²C buses is done via a transfer on the I²C bus itself. It’s worth mentioning that this method does introduce a small amount of latency compared to the previous clock-splitter solution from last week. Nevertheless, if you’re planning to read multiple devices sequentially from a single bus anyway, then getting as close-as-possible to a simultaneous read/write from each device isn’t likely a constraint on your system.

 

With a breakout board to expose the pads, I mocked up a quick-n-dirty Arduino Library to get the conversation started and duplicated last week’s demo.

Happily enough, with a single function to change the bus address, the PCA9547 is pretty much a drop-in solution that “just works.” It’s definitely reassuring that we can stand on the shoulders of our chip designers to get the job done quickly. (They’ve also likely done quite a bit more testing to ensure their device performs as promised.) Just like last week, feel free to check out the demo source code up on Github.

Until next time–cheers!

Tonight Is Hacker Chat With The Hackaday Writing Crew

Tonight at 6pm PDT (UTC-7) is that last Hacker Chat before the entry deadline for the 2015 Hackaday Prize. Join us to talk about all things hardware. Those who need last-minute advice, or are looking for team members for an epic weekend hackathon to bootstrap your winning entry, this is the place to find it. It’s worth entering something… we’re giving everyone with an entry a limited-edition shirt.. and a well executed idea just might get you to the next round!

Joining [Brian Benchoff], [Adam Fabio], and me for tonight’s festivities are [Richard Baguley], [Kevin Dady] (aka [Osgeld]), [Bil Herd], [Kristina Panos], and [Al Williams]. We run these things a bit like the wild-west. There is just a bit of structure, but mostly anything goes. As far as the structure, add your project to this sheet if you want it to be one of the discussion topics. Other than that, share your knowledge and opinions while being excellent to each other. See you this evening!

The 2015 Hackaday Prize is sponsored by:

Retrotechtacular: Robots, Robots Everywhere, With Kitschy Pronunciation

One of the great things about the human intellect is that we have the ability to build machines of varying complexity to do our bidding. As a major proponent of technology, the Chevrolet automobile corporation once dreamed of a future where the American housewife’s most mundane tasks are handled with the push of a button—one that sets a robot butler into action.

Chevy shows us what this future might look like in this short film, which they presented at the 1940 World’s Fair. A housewife’s faithful ‘robot’, pronounced throughout the picture as ‘robe-it’, has gone on the fritz. Naturally, she calls for a repairman. We see from the console controller that Roll-Oh the Robe-it can take care of all kinds of housewifely duties: he can answer the door and the phone, wash dishes, clean house, make beds, fetch hats, get dinner, and fix the furnace (and only the furnace). And that SCRAM! function? That’s never explained. We like to think it has to do with getting kids off the lawn, or could be used in conjunction with ‘get door’ to chase away would-be burglars. We get a glimpse of this when Roll-Oh answers the door and scares the daylights out of a young [Gary Sinise*] delivering flowers in a cop uniform.

Roll-Oh’s upper limbs have several Swiss Army knife-like implements in them. He uses a sharp one to cut the ribbon off of the flower box. Upon seeing the flowers, he gives them a gentle misting with his sprayer attachment. Dropped petals are no problem for Roll-Oh. He promptly vacuums them up from the thin industrial sound stage carpet with his big metal feet. Roll-Oh is then tasked with getting dinner. This amounts to him painstakingly opening a couple of cans and lighting candles with the torch hidden in his face.

While Roll-Oh the large ductwork butler is only a dream, Chevy wants you to know that smaller robe-its are all around us already. They’re regulating the heat in our stoves, browning our bread without burning it, and brewing our coffee in cool double-globe glass percolators. These tiny servants are capable of performing other tasks, like shutting off machinery when humans are too close, or sensing heat and engaging fire suppression systems. There is brief mention of something called the Petomat, an automatic dog feeding system which is essentially a bowl of food hidden in a latched box. The latch opens rather violently when the alarm clock connected to it goes off.

Robe-its are also performing more serious tasks, like keeping airplanes level and headed in the right direction. Of course, they’re also abundant in Chevrolet automobiles. A small one in the carburetor administers the proper mix of “gasoline calories and fresh air vitamins” to the engine. It’s rare to get to this level of technical detail, you know. Others watch over the spark, the intake manifold, and the voltage regulation. Up in the cab, friendly robe-its will happily traverse the AM dial at the push of a pre-set.

*Probably not actually [Gary Sinise].

Continue reading “Retrotechtacular: Robots, Robots Everywhere, With Kitschy Pronunciation”

DEF CON Vs IoT: On Hackability And Security

Ahh DEF CON! One group of hackers shows off how they’ve broken into all sorts of cool devices and other hackers (ahem… “security professionals”) lament the fact that the first group were able to do so. For every joyous “we rooted the Nest thermostat, now we can have fun” there’s a doom-mongering “the security of network-connected IoT devices is totally broken!”.

And like Dr. Jekyll and Mr. Hyde, these two sides of the hacker persona can coexist within the same individual. At Hackaday, we’re totally paranoid security conscious, but we also like to tinker with stuff. We believe that openness and security are best friends forever. If you can open it, you can see if it’s well-made inside, at least in principle. How do we reconcile this with the security professional’s demand for devices that only accept signed binary firmware updates so that they can’t be tampered with?

We’ve got no answers, but we’ve got plenty of questions. Read on, and let us know what you think.

Continue reading “DEF CON Vs IoT: On Hackability And Security”

Hackaday Prize Entry: Vertical Aeroponics

For his Hackaday Prize entry, [MIPS ARMSTRONG] is working on an open-source terrarium that will be one of the fastest way to grow foodstuffs or other edible greens. He’s calling it Project EDEN, and it’s shaping up to be one of the most advanced homebrew horticultural devices ever made.

There are a few things that make this indoor greenhouse unique. The most obvious is the incredible number of LEDs used as grow lights. [MIPS] is using 900 Watts worth of Royal Blue and Deep Red LEDs. To water these plants, [MIPS] is taking a cue from NASA and building a High Pressure Aeroponics system – a device that shoots droplets of water only 50 microns in diameter directly onto the roots of the plants.

One of the more interesting aspects of EDEN is the CO2 system. The bulk of plant biomass – like humans – comes from carbon, and plants get their carbon from the atmosphere. Studies have shown that increasing the concentration of CO2 in a grow chamber can increase plant growth. There is a limit before CO2 becomes toxic to plants, so [MIPS] will have to keep a close eye on the CO2 levels with gas sensors.

With high-pressure watering, a CO2 system, and an amazing array of LEDs, this is one of the most advanced homebrew horticulture projects on the planet. It’s also a great fit for this year’s Hackaday prize theme of ‘build something that matters’, and we can’t wait to see [MIPS]’s future developments of his awesome aeroponic terrarium.

The 2015 Hackaday Prize is sponsored by:

Hacking A KVM: Teach A Keyboard Switch To Spy

When it comes to large systems, there are a lot more computers than there are people maintaining them. That’s not a big deal since you can simply use a KVM to connect one Keyboard/Video/Mouse terminal up to all of them, switching between each box simply and seamlessly. The side effect is that now the KVM has just as much access to all of those systems as the human who caresses the keyboard. [Yaniv Balmas] and [Lior Oppenheim] spent some time reverse engineering the firmware for one of these devices and demonstrated how shady firmware can pwn these systems, even when some of the systems themselves are air-gapped from the Internet. This was their first DEF CON talk and they did a great job of explaining what it took to hack these devices.

Continue reading “Hacking A KVM: Teach A Keyboard Switch To Spy”