Testing the World's Thinnest Boombox with a modular setup containing the basic components.

Supercon 2022: Joe Grand And The Thinnest Boombox

Boomboxes are one of those status symbols that define the 1980s and part of the 1990s, being both a miracle of integration and the best way to share your love of music with as many people as possible. Naturally, this led Joe Grand to figure that it would make it a perfect subject for a modern take on such an iconic device. The primary inspiration for this came from a piezo speaker developed by TDK called the ‘PiezoListen’. These are piezo devices that can be less than a millimeter thick, while still claiming to reproduce a broad range of audio frequencies.

Just having these speakers is only part of the solution, of course, which led Joe down the rabbithole of not only figuring out the components that should go into the system, but also how to get it all on a single PCB and see how far one can push different solder mask colors with an appropriately boombox-like design. At its core is a Raspberry Pi Zero 2 W that runs Mopidy, to provide music server functionality. Also added are some RGB lighting and touch controls.

Continue reading “Supercon 2022: Joe Grand And The Thinnest Boombox”

Software For Satellites Hack Chat

Join us on Wednesday, July 12 at noon Pacific for the Software for Space Hack Chat with Jacob Killelea!

In space, everything is harder. Hardware has to be built to withstand not only the harshest possible regimes of temperature and radiation but the rigors of launch. Power is at a premium, things that are supposed to stay cool get too hot, and things you want to keep warm freeze solid. It seems like everything you “send upstairs” has to be over-engineered compared with the stuff that stays down the gravity well.

join-hack-chatBut what about software? Yep, that needs special engineering too — after all, one little mistake, one uncaught exception, and millions or even billions of exquisitely crafted space hardware could become as useful as a brick. Jacob Killelea is an aerospace engineer who has done the rounds of a number of space concerns, and he’s worked on a number of space software projects, including a pulsed laser system with the potential for lunar orbital communications. He knows what it takes to write software that keeps space hardware ticking, and we’re excited to have him log into the Chat to talk about it.

Our Hack Chats are live community events in the Hackaday.io Hack Chat group messaging. This week we’ll be sitting down on Wednesday, July 12 at 12:00 PM Pacific time. If time zones have you tied up, we have a handy time zone converter.

[Banner image: NASA’s GPM satellite.]

Hackaday Links Column Banner

Hackaday Links: July 9, 2023

Good news this week from Mars, where Ingenuity finally managed to check in with its controllers after a long silence. The plucky helicopter went silent just after nailing the landing on its 52nd flight back on April 26, and hasn’t been heard from since. Mission planners speculated that Ingenuity, which needs to link to the Perseverance rover to transmit its data, landed in a place where terrain features were blocking line-of-sight between the two. So they weren’t overly concerned about the blackout, but still, one likes to keep in touch with such an irreplaceable asset. The silence was broken last week when Perseverance finally made it to higher ground, allowing the helicopter to link up and dump the data from the last flight. The goal going forward is to keep Ingenuity moving ahead of the rover, acting as a scout for interesting places to explore, which makes it possible that we’ll see more comms blackouts. Ingenuity may be more than ten-fold over the number of flights that were planned, but that doesn’t mean it’s ready for retirement quite yet.

Continue reading “Hackaday Links: July 9, 2023”

99% Partspiration

Thomas Edison once said that genius was 1% inspiration and 99% perspiration. That doesn’t leave much room for partspiration.

I’m working on a top-secret project, and had to place a parts order on AliExpress with a minimum order quantity of five in order to get decent shipping times. No big deal, financially, and it’s always great to have spares as backup for the ones you fry.

But as I started lighting up the little round smartwatch displays to put them through their paces, I started thinking of all sorts of ways that I could use something like this. I had no idea how easy to drive they were, or frankly, how good they looked in person. When you get a round display in your hands, you find that you need dial indicators everywhere.

And then my son came by and said “Oh neat. I want one!” and started thinking up all sorts of gizmos that I could put them in. Two of them would make awesome eyes, and he’s been on a chameleon kick – the animal, you know. So we’re looking for chameleon eye animations online.

And all of a sudden, I have more projects lined up than I have remaining screens. I’m calling this phenomenon “partspiration”. You know, when you figure out how to use something and then you see uses for it everywhere? Time to place another Ali order.

Gearing Up for the Hackaday Prize

And don’t forget, we just started the next round of the Hackaday Prize: Gearing Up. In this challenge round we want to see your best DIY tools, jigs, and workflow accelerators. Custom reflow plates, home-built power supplies, or even software tools – as long as it helps you get the job done, it has a place here. You’ve got until Aug. 8 to get your entry finished, but head on over to Hackaday.io and get started now.

Retrotechtacular: The Nuclear Cruise Ship Of The Future Earns Glowing Reviews

The average modern cruise ship takes about 250 tons or 80,000 gallons of fuel daily. But can you imagine a cruise ship capable of circling the globe fourteen times before it needed to top off? That was the claim for the NS Savannah, a nuclear-powered cruise ship born out of President Eisenhower’s “Atoms for Peace” initiative.

The ship was a joint project of several government agencies, including the US Maritime Administration. With a maiden cruise in 1962, the vessel cost a little more than $18 million to build, but the 74-megawatt nuclear reactor added nearly $30 million to the price tag. The ship could carry 60 passengers, 124 crew, and over 14,000 tons of cargo around 300,000 nautical miles using one set of 32 fuel elements. What was it like onboard? The video below gives a glimpse of nuclear cruising in the 1960s.

Continue reading “Retrotechtacular: The Nuclear Cruise Ship Of The Future Earns Glowing Reviews”

Hackaday Podcast 226: Ice, Snow, And Cooling Paint In July

This week, Editor-in-Chief Elliot Williams and Al Williams shoot the breeze about all things Hackaday. We start off with some fond remembrances of Don Lancaster, a legendary hardware hacker who passed away last month. There’s also news about the Hackaday Prize (the tool competition) and a rant about fast computers and slow software, a topic that drew many comments this week.

In the What’s That Sound event, Al proves he’s more of a Star Trek fan than a videogamer. But there were plenty of correct answers, but only one winner: [Wybrandus]. There’s always next week, so keep playing!

Elliot may be dreaming of cooler weather since he talks about ice sculptures, snow measurements, and a paint that can make things cooler. We don’t know what Al is dreaming about, but he is worried about his fuses, and the ins and out of open source licensing.

Along the way, you’ll hear about personal vehicles, sky cameras, and zapping weeds with extreme solar power. As usual, there is an eclectic mix of other posts. What has the Hackaday crew been up to? Field trips! Hear about Dan Maloney’s visit to the SNOTEL network to measure snowfall and a report from Al and Bil Herd’s trip to the Vintage Computer Festival Southwest.

What to read along? The links below will get you started. Don’t forget to tell us what you think in the comments!

Or, download a copy for posterity to file away in your archive.

Continue reading “Hackaday Podcast 226: Ice, Snow, And Cooling Paint In July”

This Week In Security: Bogus CVEs, Bogus PoCs, And Maybe A Bogus Breach

It appears we have something of a problem. It’s not really a new problem, and shouldn’t be too surprising, but it did pop up again this week: bogus CVEs. Starting out in the security field? What’s the best way to jump-start a career? Getting a CVE find to your name certainly can’t hurt. And as a result, you get very junior security researchers looking for and reporting novel security vulnerabilities of sometimes dubious quality. Sometimes that process looks a lot like slinging reports against the wall to see what sticks. Things brings us to an odd bug report in the OBS Studio project.

A researcher put together a script to look for possible password exposure on Github projects, and it caught a configuration value named “password” in a .ini file, being distributed in the project source. Obvious credential leak in Git source, right? Except for the little detail that it was in the “locale” folder, and the files were named ca-es.ini, ja-jp.ini, and similar. You may be in on the joke by now, but if not, those are translation strings. It wasn’t leaked credentials, it was various translations of the word “password”. This sort of thing happens quite often, and from the viewpoint of a researcher looking at results from an automated tool, it can be challenging to spend enough time with each result to fully understand the code in question. It looks like this case includes a language barrier, making it even harder to clear up the confusion.

Things took a turn for the worse when a CVE was requested. The CVE Numbering Authority (CNA) that processed the request was MITRE, which issued CVE-2023-34585. It was a completely bogus CVE, and thankfully a more complete explanation from OBS was enough to convince the researcher of his error. That, however, brings us back to CVE-2023-36262, which was published this week. It’s yet another CVE, for the same non-issue, and even pointing at the same GitHub issue where the alleged bug is debunked. There’s multiple fails here, but the biggest disappointment is MITRE, for handing out CVEs twice for the same issue. Shout-out to [Netspooky] on Twitter for spotting this one. Continue reading “This Week In Security: Bogus CVEs, Bogus PoCs, And Maybe A Bogus Breach”