If you want to coax more power out of your car’s engine, a turbocharger is a great way to go about it. Taking waste energy from the exhaust and using it to cram more air into the engine, they’re one of the best value ways to make big gains in horsepower.
However, unlike simpler mods like a bigger exhaust or a mild cam swap, a turbocharger install on a naturally aspirated, fuel-injected engine often requires a complete replacement of the engine management system, particularly on older cars. This isn’t cheap, leaving many to stick to turbocharging cars with factory tuneable ECUs, or to give up altogether. In the 1990s, aftermarket ECUs were even more expensive, leading many to avoid them altogether. Instead, enthusiasts used creative hacks to make their turbo builds a reality on the cheap, and there’s little stopping you from doing the very same today.
I learned a new acronym while reading about a set of flaws in the Dell BIOS update system. Because Dell has patched their driver, but hasn’t yet revoked the signing keys from the previous driver version, it is open to a BYOVD attack.
BYOVD, Bring Your Own Vulnerable Driver, is an interesting approach to Windows privilege escalation. 64-bit versions of Windows have a security feature that blocks unsigned kernel drivers from the kernel. The exploit is to load an older, known-vulnerable driver that still has valid signatures into the kernel, and use the old vulnerabilities to exploit the system. The caveat is that even when a driver is signed, it still takes an admin account to load a driver. So what use is the BYOVD attack, when it takes administrative access to pull off?
SentinelLabs is witholding their proof-of-concept, but we can speculate. The particular vulnerable driver module lives in the filesystem at C:\Windows\Temp, a location that is writable by any process. The likely attack is to overwrite the driver on the filesystem, then trigger a reboot to load the older vulnerable version. If you’re still running Windows on your Dell machines, then make sure to go tend to this issue. Continue reading “This Week In Security: BYOVD, Spectre Vx, More Octal Headaches, And ExifTool”→
You don’t have to look very hard to find another rousing success by SpaceX. It’s a company defined by big and bold moves, and when something goes right, they make sure you know about it. From launching a Tesla into deep space to the captivating test flights of their next-generation Starship spacecraft, the private company has turned high-stakes aerospace research and development into a public event. A cult of personality has developed around SpaceX’s outlandish CEO Elon Musk, and so long as he’s at the helm, we can expect bigger and brighter spectacles as he directs the company towards its ultimate goal of putting humans on Mars.
Of course, things don’t always go right for SpaceX. While setbacks are inevitable in aerospace, the company has had a few particularly embarrassing failures that could be directly attributed to their rapid development pace or even operational inexperience. A perfect example is the loss of the Israeli AMOS-6 satellite during a static fire of the Falcon 9’s engines on the launch pad in 2016, as industry experts questioned why the spacecraft had even been mounted to the rocket before it had passed its pre-flight checks. Since that costly mistake, the company has waited until all engine tests have been completed before attaching the customer’s payload.
SpaceX’s concept art for propulsive landing
But sometimes the failure isn’t so much a technical problem as an inability for the company to achieve their own lofty goals. Occasionally one of Musk’s grand ideas ends up being too complex, dangerous, or expensive to put into practice. For instance, despite spending several years and untold amounts of money perfecting the technology involved, propulsive landings for the Crew Dragon were nixed before the idea could ever fully be tested. NASA was reportedly uncomfortable with what they saw as an unnecessary risk compared to the more traditional ocean splashdown under parachutes; it would have been an impressive sight to be sure, but it didn’t offer a substantive benefit over the simpler approach.
A similar fate recently befell SpaceX’s twin fairing recovery ships Ms. Tree and Ms. Chief, which were quietly retired in April. These vessels were designed to catch the Falcon’s school bus sized payload fairings as they drifted down back to Earth using massive nets suspended over their decks, but in the end, the process turned out to be more difficult than expected. More importantly, it apparently wasn’t even necessary in the first place.
A few years ago we talked about the chance that the first known extrasolar visitor — Oumuamua — might be a derelict solar sail. That notion has been picking up steam in the popular press lately, and it made us think again about the chances that the supposed rock was really a solar sail discarded or maybe even a probe flying with a solar sail. At the same time, Mars is as close as it ever gets so there is a gaggle of our probes searching the red planet, some of them looking for signs of past life.
All this makes us think: if we did find life or even artifacts of intelligent life, would we realize it? Sure, we can usually figure out what’s alive here on Earth. But to paraphrase Justice Potter Stewart, “We know it when we see it.” Defining life turns out to be surprisingly tricky, recognizing alien technology would be even harder.
Let’s face it — for the average person, math and formulas are not the most attractive side of physics. The fun is in the hands-on learning, the lab work, the live action demonstrations of Mother Nature’s power and prowess. And while it’s true that the student must be willing to learn, having a good teacher helps immensely.
Professor Julius Sumner Miller was energetic and enthusiastic about physics to the point of contagiousness. In pictures, his stern face commands respect. But in action, he becomes lovable. His demonstrations are dramatic, delightful, and about as far away from boring old math as possible. Imagine if Cosmo Kramer were a physics professor, or if that doesn’t give you an idea, just picture Doc Brown from Back to the Future (1985) with a thick New England accent and slightly darker eyebrows. Professor Miller’s was a shouting, leaping, arm-waving, whole-bodied approach to physics demonstrations. He was completely fascinated by physics, and deeply desired to understand it as best he could so that he could share the magic with people of all ages.
Professor Miller reached thousands of students in the course of his nearly 40-year teaching career, and inspired millions more throughout North America and Australia via television programs like TheMickey Mouse Club and Miller’s own show entitled Why Is It So? His love for science is indeed infectious, as you can see in this segment about the shock value of capacitors.
Thirty-five years ago, radiation alarms went off at the Forsmark nuclear power plant in Sweden. After an investigation, it was determined that the radiation did not come from inside the plant, but from somewhere else. Based on the prevailing winds at that time, it was ultimately determined that the radiation came from inside Soviet territory. After some political wrangling, the Soviet government ultimately admitted that the Chernobyl nuclear plant was the source, due to an accident that had taken place there.
Following the disaster, the causes have been investigated in depth so that we now have a fairly good idea of what went wrong. Perhaps the most important lesson taught by the Chernobyl nuclear plant disaster is that it wasn’t about one nuclear reactor design, one control room crew, or one totalitarian regime, but rather the chain of events which enabled the disaster of this scale.
To illustrate this, the remaining RBMK-style reactors — including three at the Chernobyl plant — have operated without noticeable issues since 1986, with nine of these reactors still active today. During the international investigation of the Chernobyl plant disaster, the INSAG reports repeatedly referred to the lack of a ‘safety culture’.
Looking at the circumstances which led to the development and subsequent unsafe usage of the Chernobyl #4 reactor can teach us a lot about disaster prevention. It’s a story of the essential role that a safety culture plays in industries where the cost of accidents is measured in human life.
Although bash scripts are regularly maligned, they do have a certain simplicity and ease of creation that makes them hard to resist. But sometimes you really need to do some heavy lifting in another language. I’ll talk about Python, but actually, you can use many different languages with this technique, although you might need a little adaptation, depending on your language of choice.
Of course, you don’t have to do anything special to call another program from a bash script. After all, that’s what it’s mainly used for: calling other programs. However, it isn’t very handy to have your script spread out over multiple files. They can get out of sync and if you want to send it to someone or another machine, you have to remember what to get. It is nicer to have everything in one file.