FCC Fines Hobby King Almost $3 Million For Illegal Drone Transmitters

We take wireless devices for granted these days, and it is easy to forget that the use of the airwaves is subject to government control — the FCC in the United States. HobbyKing got a sharp reminder when the FCC levied a nearly $3 million fine for the company selling uncertified drone transmitters.

It was hardly a surprise, though. The FCC has been cracking down on these noncompliant transmitters for a while now and had issued a notice of apparent liability to the company back in 2018 and the investigation goes back to 2016. The problems included radios being sold that were on unauthorized frequencies, radios with higher than legal output power, and selling radios that were not type accepted.

Continue reading “FCC Fines Hobby King Almost $3 Million For Illegal Drone Transmitters” →

Busting GPS Exercise Data Out Of Its Garmin-controlled IoT Prison

If you take to the outdoors for your exercise, rather than walking the Sisyphusian stair machine, it’s nice to grab some GPS-packed electronics to quantify your workout. [Bunnie Huang] enjoys paddling the outrigger canoe through the Singapore Strait and recently figured out how to unpack and visualize GPS data from his own Garmin watch.

By now you’ve likely heard that Garmin’s systems were down due to a ransomware attack last Thursday, July 23rd. On the one hand, it’s a minor inconvenience to not be able to see your workout visualized because of the system outage. On the other hand, the services have a lot of your personal data: dates, locations, and biometrics like heart rate. [Bunnie] looked around to see if he could unpack the data stored on his Garmin watch without pledging his privacy to computers in the sky.

Obviously this isn’t [Bunnie’s] first rodeo, but in the end you don’t need to be a 1337 haxor to pull this one off. An Open Source program called GPSBabel lets you convert proprietary data formats from a hundred or so different GPS receivers into .GPX files that are then easy to work with. From there he whipped up less than 200 lines of Python to plot the GPS data on a map and display it as a webpage. The key libraries at work here are Folium which provides the pretty browsable map data, and Matplotlib to plot the data.

These IoT devices are by all accounts amazing, listening for satellite pings to show us how far and how fast we’ve gone on web-based interfaces that are sharable, searchable, and any number of other good things ending in “able”. But the flip side is that you may not be the only person seeing the data. Two years ago Strava exposed military locations because of an opt-out policy for public data sharing of exercise trackers. Now Garmin says they don’t have any indications that data was stolen in the ransomware attack, but it’s not a stretch to think there was a potential there for such a data breach. It’s nice to see there are Open Source options for those who want access to exercise analytics and visualizations without being required to first hand over the data.

Liquid Air Energy Storage: A Power Grid Battery Using Regular Old Ambient Air

When you think of renewable energy, what comes to mind? We’d venture to guess that wind and solar are probably near the top of the list. And yes, wind and solar are great as long as the winds are favorable and the sun is shining. But what about all those short and bleak winter days? Rainy days? Night time?

Render of a Highview LAES plant. The air is cleaned, liquefied in the tower, and stored in the white tanks. The blue tanks hold waste cold which is reused in the liquefaction process. Image via Highview Power

Unfavorable conditions mean that storage is an important part of any viable solution that uses renewable energy. Either the energy itself has to be stored, or else the means to produce the energy on demand must be stored.

One possible answer has been right under our noses all along — air. Regular old ambient air can be cooled and compressed into a liquid, stored in tanks, and then reheated to its gaseous state to do work.

This technology is called Cryogenic Energy Storage (CES) or Liquid Air Energy storage (LAES). It’s a fairly new energy scheme that was first developed a decade ago by UK inventor Peter Dearman as a car engine. More recently, the technology has been re-imagined as power grid storage.

UK utility Highview Power have adopted the technology and are putting it to the test all over the world. They have just begun construction on the world’s largest liquid air battery plant, which will use off-peak energy to charge an ambient air liquifier, and then store the liquid air, re-gasifying it as needed to generate power via a turbine. The turbine will only be used to generate electricity during peak usage. By itself, the LAES process is not terribly efficient, but the system offsets this by capturing waste heat and cold from the process and reusing it. The biggest upside is that the only exhaust is plain, breathable air.

Continue reading “Liquid Air Energy Storage: A Power Grid Battery Using Regular Old Ambient Air” →

This Week In Security: Iran’s ITG18, ProcMon For Linux, And Garbage Collection Fail

Even top-tier security professionals make catastrophic mistakes, and this time it was the operators at Iran’s ITG18. We’re once again talking about the strange shadowy world of state sponsored hacking. This story comes from the IBM X-Force Incident Response Intelligence Services (IRIS). I suspect a Deadpool fan must work at IBM, but that’s beside the point.

A server suspected to be used by ITG18 was incorrectly configured, and when data and training videos were stored there, that data was publicly accessible. Among the captured data was records of compromised accounts belonging to US and Greek military personnel.

The training videos also contained a few interesting tidbits. If a targeted account used two factor authentication, the attacker was to make a note and give up on gaining access to that account. If a Google account was breached, the practice was to start with Google Takeout, the service from Google that allows downloading all the data Google has collected related to that account. Yoiks. Continue reading “This Week In Security: Iran’s ITG18, ProcMon For Linux, And Garbage Collection Fail” →

CBS Announces Functional Tricorder Replica For 2021

It’s taken 54 years, but soon, you’ll finally be able to buy a fully-functional version of the tricorder from Star Trek. Announced on the official website for the legendary sci-fi franchise, the replica will be built by The Wand Company, who’ve previously produced a number of high-quality official Star Trek props as well as replicas for Doctor Who and the Fallout game series.

Admittedly, we’re not sure what a “fully-functional tricorder” actually is, mainly because the various on-screen functions of the device were largely driven by whatever bind Kirk and Spock managed to find themselves in that week. But the announcement mentions the ability to scan radio frequencies, pull in dynamic data from environmental sensors, and record audio. The teaser video after the break doesn’t give us any more concrete information than the announcement, but it does seem to confirm that we’ll be viewing said data on the device’s iconic flip-up display.

Now as the regular Hackaday reader knows, fans have been building extremely impressive “functional” tricorders for some time now. Unlike the sleek 24th century versions seen in Star Trek: The Next Generation, the original tricorder prop was rather clunky and offers plenty of internal volume for modern goodies. Cramming a Raspberry Pi, LCD, and a bunch of sensors into an inert replica is a relatively approachable project. So it will be interesting to see how the official version stacks up to what’s already been done by intrepid hackers and makers.

The official tricorder won’t be available until summer of 2021, but you can sign up to be notified when it’s your turn to beam one up. While the $250 USD sticker price might keep the more casual Trekkers at bay, it’s actually a bit cheaper than we would have assumed given the amount of time and money we’ve seen fans put into their own builds.

Continue reading “CBS Announces Functional Tricorder Replica For 2021” →

Pine Made Phones, Laptops, And Now… Soldering Irons?

The TS100 smart soldering iron may have some new competition. Pine — the people best known for Linux-based phones and laptops — though the world needed another smart soldering iron so they announced the Pinecil — Sort of a knock off of the TS100. It looks like a TS100 and uses the same tips. But it does have some important differences.

It used to be a soldering iron was a pretty simple affair. Plug in one end; don’t touch the other end. But, eventually, things got more complicated and you wanted some way to make it hotter or cooler. Then you wanted the exact temperature with a PID controller. However, until recently, you didn’t care how much processing power your soldering iron had. The TS100 changed that. The smart and portable iron was a game-changer and people not only used it for soldering, but also wrote software to make it do other things. One difference is that the device has a RISC-V CPU. Reportedly, it also has better ergonomics and a USB C connector that allows for UART, I2C, SPI, and USB connections. It also has a very friendly price tag of $24.99.

Continue reading “Pine Made Phones, Laptops, And Now… Soldering Irons?” →

BadPower Vulnerability In Fast Chargers Might Make Phones Halt And Catch Fire

A few days ago, Chinese researchers from technology giant Tencent released a paper outlining a firmware vulnerability in several types of fast charger power bricks (translated). The attack is known as BadPower, and it works by altering the default parameters in the firmware of fast chargers to deliver more power to devices than they can handle, which can cause them to overheat, melt, or catch fire.

The ancient and basic USB charging spec provides 0.5 A at 5 V, which is equal to 2.5 W. In theory, that’s all you’ll ever get from those types of chargers. But the newer generation of chargers are different. When you plug your phone into a fast charger, it negotiates a voltage and charging speed with your phone before passing it any power.

Fast chargers can push power at 20 V or more to speed up the charging process, depending on the charger and connected device. If the phone doesn’t do fast charging, it will default to the 5 V standard. Researchers claim the BadPower attack is capable of harming devices whether or not they include a fast charging feature. When a capable device is connected, the charger will still negotiate for 5V, but instead give 20V and wreak havoc.

In the demo after the break, one of the team uses a malicious device disguised as a phone to push the BadPower firmware change to a fast charger that’s hooked up to a voltmeter. Before the attack, the charger gives 5V. After the attack, it gives 5V for a few seconds before jumping up near 20V. Then they connect the now-dirty charger to two identical illuminated magnifying glasses. In one the chip lets the smoke monster out rather violently, and the chips of the other emit sparks.

The researchers tested 35 of the 200+ fast charging bricks currently on the market and found that 18 of them were vulnerable to BadPower, including 11 that can be exploited through the charging port itself. They believe the issue is fixable with a firmware update.

What is not available is enough information to verify this research, or a list of brands/models that are vulnerable. Researchers say the findings were submitted to the China National Vulnerability Database (CNVD) on March 27th, so the absence of this information may be a product of manufacturers needing more time to patch the vulnerability.

What do you think? We say halfway decent chargers shouldn’t be open to firmware attacks from the devices they are charging. And any halfway decent phone should have built-in electrical protection, right?

Continue reading “BadPower Vulnerability In Fast Chargers Might Make Phones Halt And Catch Fire” →