This Week In Security: GTA, Apple And Android, And Insecure Boot

When we first saw tweets about a security issue in Grand Theft Auto V, it sounded a bit like a troll. “Press ‘alt and f4’ to unlock a cheat mode”, or the hacker that claims to be able to delete your character. [Tez2]’s warning tweet that you shouldn’t play GTA Online without a firewall sounds like another of these online urban legends. But this one actually seems legit. NIST is even in on the fun, assigning CVE-2023-24059 for the exploit.

When playing an online game, other users send a “join request” to join the active session. This packets can contain malformed data which has been observed to crash the game client remotely. It’s believed, though not publicly confirmed, that it’s also a Remote Code Execution (RCE) vulnerability. It seems likely that this aspect will be added to some of the various cheat panels that are already widely used for this 10-year-old game. So now, rather than just giving your own character infinite ammo and health, you can inflict some havoc on other players, possibly up to corrupting their character files and getting them banned.

But why stop there? If we have code execution inside the game, what stops another player from launching a real attack? A video game isn’t sandboxed like a browser, and there’s nothing preventing a disk wiper attack or even a worm from compromising a bunch of players. The worst part is that it’s an old game, and even though there’s a large playerbase, it’s not guaranteed to get a fix. There’s at least one project aiming to be a firewall to prevent the issue. Continue reading “This Week In Security: GTA, Apple And Android, And Insecure Boot”

All About USB-C: Framework Laptop

Talking about high-quality USB-C implementations, there’s a product that has multiple selling points designed around USB-C, and is arguably a shining example of how to do USB-C right. It’s the Framework laptop, where the USB-C expansion cards take the center stage.

Full disclosure – this article is being typed on a Framework laptop, and I got it free from Framework. I didn’t get it for Hackaday coverage – I develop Framework-aimed hardware as hobby, specifically, boards that hack upon aspects of this laptop in fun ways. As part of their community developer support effort, they’ve provided me with a laptop that I wouldn’t otherwise be able to get for such a hobby. By now, I’m part of the Framework community, I have my own set of things I like about this laptop, and a set of things I dislike.

This is not an article about how I’m satisfied or dissatisfied with the Framework laptop – there’s plenty of those around, and it would not be fair for me to write one – I haven’t paid for it in anything except having lots of fun designing boards and hanging out with other people designing cool things, which is something I do willingly. I’m an all-things-laptops enthusiast, and the reason I’d like to talk about Framework is that there is no better example of USB-C, and everything you can do with it, in the wild. Continue reading “All About USB-C: Framework Laptop”

Supercon 2022: Sophy Wong Is Making An Impact With Artistic Wearables

Prolific designer and maker Sophy Wong is always looking toward the future, and that goes for everything from the costume pieces she makes to the idea of making itself. In her excellent and highly-visual Supercon talk, Sophy explores both, and gives the viewer a window on her evolved-and-evolving design philosophy.

You likely know Sophy as That Maker Who 3D Prints On Fabric, a label she is quick to dismiss, pointing animatedly toward the seminal work of one David Shorey, who also happened to be at Supercon 2022. As Sophy explains, the process begins by modeling disconnected bodies to be printed, then printing the first layer and pausing the print. At this point, a piece of nylon mesh is inserted, and the print is resumed. The result is that the mesh is trapped between the first and second layers, and the bodies are now connected by a common thread. Carefully remove the sandwich from the print bed and you have a highly-flexible, mesmerizing piece of material that almost acts like chain maille.

Continue reading “Supercon 2022: Sophy Wong Is Making An Impact With Artistic Wearables”

Hackaday.io Low-Power Challenge Begins Today

How low can you go? The 2023 Hackaday.io Low-Power Challenge is about doing the most with the least juice – bang for the power-budget buck, if you get our drift. And with three $150 gift certificates from Digi-Key on the line, you’ll be able to keep your projects going forever. The Challenge runs until March 21st, but with low-power, the devil is often in the details, so get started today!

More and more projects need to run on their own power, and more often than not, that means getting by without access to a wall plug. This contest is to encourage your designs that run on solar, small batteries, and generally energy harvested from wherever you can get it. But the power generation mechanism is taking the back seat here – we want to see what you can do with a few good electrons. Surprise us with your maximum minimalism!

Continue reading “Hackaday.io Low-Power Challenge Begins Today”

Smiling ad family with 3D printer

Ask Hackaday: Do Kids Need 3D Printers?

Mattel holds a fond place in most people’s hearts as they made many of the toys we played with as kids. You might remember the Thingmaker, which was essentially an Easy Bake Oven with some goop and molds that let you make rubbery creatures. But back in 2016, Mattel had an aborted attempt to bring 3D printing to kids under the Thingmaker label. You can see a promo video of the device below. You might not have seen one in real life, though. The product was delayed and eventually canceled. Even so, we frequently see press releases for “kids printers” and we’ve been wondering, should this be a thing? Continue reading “Ask Hackaday: Do Kids Need 3D Printers?”

Vintage Electronics Hack Chat

Join us on Wednesday, January 25 at noon Pacific for the Vintage Electronics Hack Chat with Keri Szafir!

The world of the hardware hacker is filled with smells. The forbidden but enticing waft of solder smoke, the acrid bite of the Magic Blue Smoke, the heady aroma of freshly greased gears, the unmistakable smell of hot metal — they all tell a story, sometimes good, sometimes bad.

But the smell inside a piece of vintage electronics? Now that’s a complicated story indeed. It might be the wax of the old capacitors, the resinous scent of well-baked resistors, the enameled wire in transformers, or just the smell of the hot glass of the vacuum tubes. Whatever it is, once you smell it, you’ll never forget it

join-hack-chatFor some of us, that first whiff starts a lifelong passion for vintage gear. Keri Szafir knows quite well what it’s like to be bitten by the vintage bug, so much so that she goes by “The Vacuum Tube Witch” over on her YouTube channel. Her projects include repairs and restorations of vintage amps and radios, and even new builds with old tubes. She’ll stop by the Hack Chat to talk about vintage electronics, tube hoarding collecting, and even her new interest in retro display technologies. Where there’s a tube, there’s a way!

Our Hack Chats are live community events in the Hackaday.io Hack Chat group messaging. This week we’ll be sitting down on Wednesday, January 25 at 12:00 PM Pacific time. If time zones have you tied up, we have a handy time zone converter.

Hackaday Links Column Banner

Hackaday Links: January 22, 2023

The media got their collective knickers in a twist this week with the news that Wyoming is banning the sale of electric vehicles in the state. Headlines like that certainly raise eyebrows, which is the intention, of course, but even a quick glance at the proposed legislation might have revealed that the “ban” was nothing more than a non-binding resolution, making this little more than a political stunt. The bill, which would only “encourage” the phase-out of EV sales in the state by 2035, is essentially meaningless, especially since it died in committee before ever coming close to a vote. But it does present a somewhat lengthy list of the authors’ beefs with EVs, which mainly focus on the importance of the fossil fuel industry in Wyoming. It’s all pretty boneheaded, but then again, outright bans on ICE vehicle sales by some arbitrary and unrealistically soon deadline don’t seem too smart either. Couldn’t people just decide what car works best for them?

Speaking of which, a man in neighboring Colorado might have some buyer’s regret when he learned that it would take five days to fully charge his brand-new electric Hummer at home. Granted, he bought the biggest battery pack possible — 250 kWh — and is using a standard 120-volt wall outlet and the stock Hummer charging dongle, which adds one mile (1.6 km) to the vehicle’s range every hour. The owner doesn’t actually seem all that surprised by the results, nor does he seem particularly upset by it; he appears to know enough about the realities of EVs to recognize the need for a Level 2 charger. That entails extra expense, of course, both to procure the charger and to run the 240-volt circuit needed to power it, not to mention paying for the electricity. It’s a problem that will only get worse as more chargers are added to our creaky grid; we’re not sure what the solution is, but we’re pretty sure it’ll be found closer to the engineering end of the spectrum than the political end.

Continue reading “Hackaday Links: January 22, 2023”