This Week In Security: Ubiquiti, Nissan, Zyxel, And Dovecot

You may have been one of the many of us who received an email from Ubiquiti this week, recommending a password change. The email stated that there was an unauthorized access of Ubiquiti systems, and while there wasn’t evidence of user data being accessed, there was also not enough evidence to say emphatically that user data was not accessed. Ubiquiti has mentioned that the database that may have been accessed contains a user’s name, email address, hashed password, and optionally the mailing address and phone number.

Depending on how the Ubiquiti authentication system is designed, that hashed password may be enough to log in to someone’s account. In any case, updating your password would invalidate the potentially compromised hash. This event underscores a complaint voiced by Ubiquiti users: Ubiquiti has been making it difficult to administrate hardware without a cloud-enabled account. Continue reading “This Week In Security: Ubiquiti, Nissan, Zyxel, And Dovecot”

Basics Of Remote Cellular Access: Connecting Via VPN

You’ve got a machine hooked up to the Internet via a shiny new cellular modem, which you plan to administer remotely. You do a quick check on the external IP, and try and log in from another PC. Try as you might, SSH simply won’t connect. What gives?

The reality of the modern internet is that most clients no longer get their own unique IPv4 address. There simply aren’t enough to go around anymore. Instead, most telecommunications operators use Carrier Grade Network Address Translation which allows a single external address to be shared by many customers. This can get in the way of direct connection attempts from the outside world. Even if that’s not the case, most cellular operators tend to block inbound connections by default. However, there is a way around this quandary – using a VPN. Continue reading “Basics Of Remote Cellular Access: Connecting Via VPN”

Teardown: Tap Trapper

The modern consumer is not overly concerned with their phone conversations being monitored. For one thing, Google and Amazon have done a tremendous job of conditioning them to believe that electronic gadgets listening to their every word isn’t just acceptable, but a near necessity in the 21st century. After all, if there was a better way to turn on the kitchen light than having a recording of your voice uploaded to Amazon so they can run it through their speech analysis software, somebody would have surely thought of it by now.

But perhaps more importantly, there’s a general understanding that the nature of telephony has changed to the point that few outside of three letter agencies can realistically intercept a phone call. Sure we’ve seen the occasional spoofed GSM network pop up at hacker cons, and there’s a troubling number of StingRays floating around out there, but it’s still a far cry from how things were back when folks still used phones that plugged into the wall. In those days, the neighborhood creep needed little more than a pair of wire strippers to listen in on your every word.

Which is precisely why products like the TA-1356 Tap Trapper were made. It was advertised as being able to scan your home’s phone line to alert you when somebody else might be listening in, whether it was a tape recorder spliced in on the pole or somebody in another room lifting the handset. You just had to clip it onto the phone distribution panel and feed it a fresh battery once and awhile.

If the red light came on, you’d know something had changed since the Tap Trapper was installed and calibrated. But how did this futuristic defender of communications privacy work? Let’s open it up and take a look.

Continue reading “Teardown: Tap Trapper”

Making A Kid-Friendly Computer As A Present: Or How To Be The Cool Aunt At Christmas

This article was meant to be finished up before Christmas, so it’ll be a little late whenever you’re reading it to go and prepare this for the holiday. Regardless, if, like me, should you ever be on the lookout for something to give a toddler nephew or relative, it could be worth it to look into your neglected old parts shelves. In my case, what caught my eye was a 9-year-old AMD laptop catching dust that could be better repurposed in the tiny hands of a kid eager to play video games.

The main issues here are finding a decent selection of appropriate games and streamling the whole experience so that it’s easy to use for a not-yet-hacker, all the while keeping the system secure and child-friendly. And doing it all on a budget.

This is a tall order, and requirements will be as individual as children are, of course, but I hope that my experience and considerations will help guide you if you’re in a similar boat.

Continue reading “Making A Kid-Friendly Computer As A Present: Or How To Be The Cool Aunt At Christmas”

Spacing Out: Launch Successes And Failures, Next Stop Mars, Rocket Catching, & Space Stations

As large sections of the globe have seen themselves plunged into further resurgences of the pandemic over the past few weeks there has been no let-up in the world of space exploration even for the Christmas holidays, so here we are with another Spacing Out column in which we take a look at what’s going up, what’s flying overhead, and what’s coming down.

Not today, Paul. r2hox from Madrid, Spain, CC BY-SA 2.0.
Not today, Paul. r2hox from Madrid, Spain, CC BY-SA 2.0.

December was eventful, with China returning lunar samples and Japan doing the same with asteroid dust. And it was reported that we  might just possibly have detected radio waves from ET. The truth may be out there and we sincerely want to believe, but this widely reported signal from Proxima Centauri probably isn’t the confirmation of alien life we’ve all been waiting for.

There has been no shortage of launches over the last month from the usual agencies and companies, with a first launch from China of their Long March 8 heavy lift rocket from the Wenchang launch site in Hainan Province. Its payload of five satellites made it safely to orbit, and we expect the rocket will be a workhorse of their future exploration programme. Meanwhile SpaceX conducted a high-altitude test of their Starship SN8 vehicle, which proceeded according to plan until the craft was approaching the landing pad, at which point the failure of one of its engines to fire caused a spectacular crash. This does not equate to an unsuccessful test flight as it performed faultlessly in the rest of its manoeuvres, but it certainly made for some impressive video.

On the subject of SpaceX and Starship, Elon Musk has said he will sell all his personal property to fund a Martian colony. This will require a fleet of up to 1000 Starships, with three launches a day to ferry both colonists and supplies to the Red Planet. He attracted controversy though by saying that interplanetary immigration would be open to people of all means with loans available for the estimated $50,000 one-way travel cost, and Martian jobs on offer to enable the debt to be paid. Many critics replied to his Tweets likening the idea to indentured servitude. It’s worth remembering that Musk is the master of the grand publicity stunt, and while it seems a good bet that SpaceX will indeed reach Mars, it’s also not inconceivable that his timeline and plans might be somewhat optimistic.

A more tangible story from SpaceX comes in their super heavy booster rocket, which is to be reusable in the same manner as their existing Falcon 9, but not landing on its own legs in the manner of the earlier rocket. It will instead dock with its launch tower, being caught by the same support structures used to stabilise it before launch. At first glance this might seem too difficult to succeed, but no doubt people expressed the same doubts before the Falcon 9s performed their synchronised landings.

Finally away from more troubling developments in the political field, The Hill takes a look at some of those likely to have a hand in providing a commercial replacement for the ISS when it eventually reaches the end of its life. They examine the likely funding for NASA’s tenancy on the station, and looked at the cluster of Texas-based companies gearing up for space station manufacture. That’s right — space station modules from the likes of Axiom Space will become a manufactured assembly rather than one-off commissions. The decades beyond the ISS’s current 2030 projected end of life are likely to have some exciting developments in orbit.

The coming year is likely to be an exciting one, with a brace of missions heading to Mars for February as well as a new space station to catch our attention. The Chinese aren’t content to stop at the Moon, with their Tianwen-1 Mars mission due to start exploring our planetary neighbour, and the first Tianhe module of what will become their much larger space station taking to the skies in the coming year. Meanwhile the Red planet will see NASA’s Perseverance rover also reaching its surface, taking with it the Ingenuity helicopter. Finally, the United Arab Emirates’ Hope probe will go into orbit, making the second month one that should have plenty of news.

Wherever you are, keep yourself safe from Earth-bound viruses, and keep looking at the skies in 2021.

Ask Hackaday: What’s In Your Fastener Bin?

A Saturday afternoon. The work week was done, the household chores were wrapped up, and with almost a week left until Christmas, there was just enough wiggle room to deny that there was still a ton of work left to prepare for that event. It seemed like the perfect time to escape into the shop and knock out a quick project, one that has been on the back burner since at least March. I’m nothing if not skilled in the ways of procrastination.

This was to be a simple project — adding an aluminum plate to a plastic enclosure that would serve as an antenna entry point into my shack. Easy as pie — cut out an rectangle of aluminum, cut and drill a few holes, call it a day. Almost all of my projects start out that way, and almost every time I forget that pretty much every one of those builds goes off the rails at exactly the same point: when I realize that I don’t have the fasteners needed. That’s what happened with this build, which had been going swimmingly up to that point — no major screw-ups, no blood drawn. And so it was off to the hardware store I trundled, looking for the right fasteners to finish the job.

Finding hardware has long been where my productivity goes to die. Even though I live a stone’s throw from at least half a dozen stores, each with a vast selection of hardware and most open weekends and nights, the loss of momentum that results from changing from build-mode to procure-mode has historically been deadly to my projects. I’m sure I’m not the only one who has run into this issue, so the question is: what can a hacker do to prevent having to run out for just the right fasteners?

Continue reading “Ask Hackaday: What’s In Your Fastener Bin?”

Plant Communication Hack Chat

Join us on Wednesday, January 13th at noon Pacific for the Plant Communication Hack Chat with Lex Kravitz!

As far as conversation goes, plants are usually a pretty poor choice of partners. Sure, we’ve all heard that talking to you houseplants is supposed to be good for them, but expecting them to talk back in any meaningful way is likely to end in disappointment.

Or is it? For as simple and inanimate as plants appear to be, they actually have a rich set of behaviors. Plants can react to stimuli, moving toward attractants like light and nutrients and away from repellents. Some trees can secrete substances to prevent competitors crowding around them, by preventing their seedlings from ever even taking root. And we’ve known for a long time that plants can communicate with each other, through chemical signaling.

Plants are clearly capable of much more than just sitting there, but is there more to the story? Neuroscientist Lex Kravitz thinks so, which is why he has been wiring up his houseplants to sensitive amplifiers and looking for electrical signals. While the bulk of what we know about plant communications is centered on the chemical signals they send, it could be that there’s an electrical component to their behaviors too. Join us as Lex stops by the Hack Chat to talk about his plant communication experiments, and to see if it may someday be possible to listen in on what your plants are saying about you.

join-hack-chatOur Hack Chats are live community events in the Hackaday.io Hack Chat group messaging. This week we’ll be sitting down on Wednesday, January 13 at 12:00 PM Pacific time. If time zones have you tied up, we have a handy time zone converter.

Click that speech bubble to the right, and you’ll be taken directly to the Hack Chat group on Hackaday.io. You don’t have to wait until Wednesday; join whenever you want and you can see what the community is talking about.

Continue reading “Plant Communication Hack Chat”