Hackaday Podcast Episode 384: OCR MOD Records, Magical PCBs, And The Gravity Of Space Stations

What did Hackaday editors Elliot Williams and Al Williams read in Hackaday last week? Probably everything, but you can tune in and hear about their favorites on this week’s podcast. They heard from lots of listeners this week, and also saw DIY projects running from a 3D-printed Stirling engine, to clogs, to LEDs.

There are some over-the-top hacks like a refit for a decades-old watch to do tap-to-pay and a — for lack of a better word — a record player that optically reads MOD files. Want to emulate an iPod? Talk to Eliza? Print a hand-operated rail car? Hackaday is the place to read about it all.

The can’t miss articles included a talk from Hackaday Europe about making magical PCBs and a not-so-brief history of space stations starting in the 1800s.

Check out the links if you want to follow along, and as always, tell us what you think about this episode in the comments!

Direct download in MP3 suitable for hand-decoding.

Continue reading “Hackaday Podcast Episode 384: OCR MOD Records, Magical PCBs, And The Gravity Of Space Stations”

This Week In Security: Android Malware, VOIP Hijack, Signal Contact Discovery, And TeamPCP Arrests

On GitHub, [AyaanB] details buying a cheap Android TV streaming device, looking for, and finding, baked-in malware.

Multiple warnings have been issued by the FBI and CISA regarding malware on media box Android devices. Many devices have been caught participating in botnets providing residential proxies, ad-click fraud, and DDOS services. [AyaanB] sets out to discover if a $30 set-top streaming box is pre-infected with malware, and extracting it – without ever letting the device talk to the Internet or access other devices on the local network.

Picking a device named in the advisories, [AyaanB] discovered that it was, indeed, preloaded with multiple app stores and applications that wouldn’t typically make sense on a set-top TV box. After identifying the serial port test pads and obtaining a low-voltage serial adapter, they were able to gain access to the bootloader and from there dump the contents of the MMC over TFTP.

With the entire filesystem accessible out-of-body, proving it was infected with malware at the factory becomes simple: the malware is signed as a system application, baked onto the system partition of the MMC, granted SELinux exceptions to mark it as a system binary with shell privileges, and has multiple launch scripts to make sure it is executed even if partially removed. With the malware identified, [AyaanB] continues to dig through to uncover the capabilities.

By installing hooks into the low-level Android process spawning system, the malware installs hooks into every application as it is launched: even if an application isn’t trojaned already, by the time it finishes executing, it’s definitely been subverted. The functions patched and the methods used match the Vo1d botnet, which is used for account takeovers, residential proxies, free “VPN” services, and other unfriendly behavior.

Further digging into the system showed hooks for ad-click fraud, where hidden browser windows are allowed to run unthrottled and display overlays are configured to obscure ads below where the user may click. Other included tools bid in real-time ad auctions, claiming to directly publish ads to the user which may or may not be visible. To cap it all off, a root level backdoor allows botnet operators to access the systems directly and install additional tools.

Be sure to check out [AyaanB]’s writeup for more details on exfiltration methods and other malware found on the devices. Continue reading “This Week In Security: Android Malware, VOIP Hijack, Signal Contact Discovery, And TeamPCP Arrests”

FLOSS Weekly Episode 879: Easy Like Butter

This week Jonathan chats with Nathan Freitas of the Guardian Project! What is going on at the forefront of Open Source and privacy advocacy? Where are we on a true Tor browser on iOS? And what’s the ideal solution to the Android Lockdown issue? Watch to find out!

Continue reading “FLOSS Weekly Episode 879: Easy Like Butter”

AI Book Scanning: Just What Is A Rare Book?

One of the stories of the last few weeks has been that AI companies have been scanning books in very large numbers in order to train their models with content guaranteed to have been written before 2002, and thus AI free. It’s caused some outrage, because of the size of the operation, and because the scanning process is destructive. In particular the phrase being bandied around is that these are rare books, and it’s this phraseology I find problematic. I think it’s time to unpack why that is the case.

It’s Not Book Burning, Folks

Before I worked for Hackaday I had a long career in and around the publishing industry, mostly on the electronic side, but from time to time crossing paths with my colleagues in the world of paper-based publishing. I understand the appeal of a good book, I’ve spend a lot of my life among bibliophiles, and let’s just say I own a few books myself. In particular I understand the symbolism of destroying books, bringing to mind as it does the actions of repressive regimes. I have stood in Bebelplatz in Berlin where the photo of Nazi student organisation members burning the library of Magnus Hirschfeld’s institute was taken in 1933, and if you know me, you’ll have an idea why that’s close to home. But for all that, what the AI companies are doing is not the same thing.

In this case they’re destroying the books for two reasons. Firstly, as I remember from a previous employer in the publishing world, it’s much easier to digitise a stack of papers than it is a bound book. Thus I’m pretty sure that’s one reason they remove the binding before digitising the pages. Then secondly, as I understand it it’s a copyright issue. If they buy a book, digitise it, and destroy the physical copy, they can legitimately claim that only one copy of it exists, and they hope, sidestep copyright claims from publishers. Continue reading “AI Book Scanning: Just What Is A Rare Book?”

Tech In Plain Sight: Vacuum Blood Collection

If you’re blessed enough that you haven’t had blood drawn in a while, you might not have thought much about the process. You might imagine that a needle goes in, a syringe is drawn back, and the venous blood is thusly collected. Indeed, it can be done that way.

However, there is an altogether niftier and more efficient method of fast blood collection for pathology testing. It’s all about using vacuum and smart design to ease the work of phlebotomists, while maintaining a sterile and safe environment.

Continue reading “Tech In Plain Sight: Vacuum Blood Collection”

Hackaday Links Column Banner

Hackaday Links: August 23, 2026

We’ll start this week off with some disappointing, though not entirely unexpected, news — the ambitious commercial mission to save NASA’s Neil Gehrels Swift Observatory is officially a bust. The space agency provided an update earlier this week explaining that the attitude control issues with the LINK spacecraft that started a few weeks after it launched will prevent it from being able to safely dock with the Swift Observatory and boost its altitude. As such, the space telescope is now expected to reenter the Earth’s atmosphere and burn up before the end of the year.

Although LINK won’t be able to live up to its name, NASA did say operator Katalyst Space has been given permission to continue with the rendezvous attempt. The two craft won’t actually make contact with each other, but teams on both sides feel there’s lessons to be learned and data to be collected by seeing the orbital dance of these two vehicles play out for as long as possible.

Speaking of hardware that couldn’t quite hit its design goals, TechCrunch is reporting that a class action lawsuit has been filed against Oura by customers that say the company made misleading claims about the sleep-tracking accuracy of their smart rings. Namely, that the rings could somehow detect which stage of sleep the wearer was in with only the pulse and temperature sensors it has onboard.

Continue reading “Hackaday Links: August 23, 2026”

You Gotta Want It

On Hackaday last week, and on the podcast, we were talking about one of the educational toys of yesteryear that launched a thousand careers, at least if the comment section is to be believed: the Radio Shack 200-in-1 electronics kit. The “toy” itself was basically a bunch of components with spring terminals, but the secret sauce was in in the instruction book, and maybe the marketing.

Tom had one of these when he was a kid, and told a great story about wanting it desperately based on the ads he had seen with kids Morse coding to each other. When he got the kit, and found out that “it was just a bunch of wires” he was fully pissed off. But he worked through the examples, learned some basic electronics, and the rest is history.

What I really love about this story is the siren’s call of a good project. Tom was pulled in, and maybe even fooled, by the advertising, but it probably changed his life. It’s funny how many of our folks can remember the first project that got them hooked as well. With me it was some simple audio effects pedals and then maybe later some simple BEAM robots, and for younger hackers maybe it was a 3D printer or Arduino project.

Digital or analog, the common ground here is that we all thought that some project was cool enough to warrant the sweat of learning enough to do it. Good instructions are helpful of course, and having the parts on hand never hurts. But it’s the promise of making something that you really want that I think underlies all good first projects. (And heck, every subsequent project as well.)

So while Tom, and a bunch of our readers, were looking back with nostalgia at the 200-in-1, I’m thinking about how many more than 200 projects I’ve seen made by our community, and even featured here on Hackaday, that are out there to provide the motivation to get someone started. Keep on hacking!