The Pontoon Bridge Being Floated As An NYC Transit Fix

New York City’s L train carries about 400,000 passengers a day, linking Manhattan and Brooklyn and bringing passengers along 14th Street, under the East River, and through the neighborhoods of Williamsburg, Bushwick, Ridgewood, Brownsville, and Canarsie. About 225,000 of these passengers pass through the Canarsie Tunnel, a two-tube cast iron rail tunnel built below the East River between Manhattan and Brooklyn in 1924. Like many other New York City road and subway tunnels, the Canarsie Tunnel was badly damaged when Hurricane Sandy’s storm surge inundated the tubes with million of gallons of salt water. Six years later, the impending closure of the tunnel is motivating New Yorkers to develop their own ambitious infrastructure ideas.

Continue reading “The Pontoon Bridge Being Floated As An NYC Transit Fix”

Microchip Acquires Microsemi For $8.35B

Microchip has acquired Microsemi for $8.35 Billion dollars. Rumors of this acquisition were floating around earlier this week, but now the deal is done.

This acquisition is the latest in a years-long process of consolidation in the silicon industry. Previously, Broadcom attempted a hostile takeover of Qualcomm for One… Hundred… Billion dollarsLattice would have been bought if the deal wasn’t shut down for national security concerns. Of course, Microchip bought Atmel in a deal likened to the fall of Constantinople, NXP and Freescale merged, Intel bought Altera, Linear and Analog are one, and On Semiconductor acquired Fairchild.

With the acquisition of Microsemi, Microchip will be looking to add a few interesting components and capabilities to their portfolio. In contrast to Microchip’s portfolio, you won’t find many Microsemi parts on a hacker’s workbench; they’re dealing with stuff like optical networking and avionics. Closer to home, they have a large line of FPGAs and some nice frequency synthesizers.

Of course, there are slightly cooler components in Microsemi’s portfolio. If you’ve ever wanted a rad-tolerant telemetry controller for reaction wheels and thruster assemblies, they’ve got your back. Just connect that to Microchip’s rad-hard Arduino and you have a complete satellite built from Microchip parts.

Memcached Servers Abused For DDoS Attacks

Cloudflare announced recently that they are seeing an increase in amplification attacks using memcached servers, and that this exploit has the potential to be a big problem because memcached is capable of amplifying an attack significantly. This takes DDoS attacks to a new level, but the good news is that the problem is confined to a few thousand misconfigured servers, and the solution is to put the servers behind a tighter firewall and to disable UDP. What’s interesting is how the fundamental workings of the Internet are exploited to create and direct a massive amount of traffic.

We start with a botnet. This is when a bunch of Internet-connected devices are compromised and controlled by a malicious user. This could be a set of specific brand of web camera or printer or computer with unsecured firmware. Once the device is compromised, the malicious user can control the botnet and have it execute code. This code could mine cryptocurrency, upload sensitive data, or create a lot of web traffic directed at a particular server, flooding it with requests and creating a distributed denial of service (DDoS) attack that takes down the server. Since the server can’t distinguish regular traffic from malicious traffic, it can’t filter it out and becomes unresponsive.

This DDoS attack is limited to the size of the botnet’s bandwidth, though. If all the web cameras in the botnet are pounding a server as fast as they can, the botnet has reached its max. The next trick is called an amplification attack, and it exploits UDP. UDP (as opposed to TCP) is like the early post office; you send mail and hope it gets there, and if it doesn’t then oh well. There’s no handshaking between communicating computers. When a device sends a UDP packet to a server, it includes the return address so that the server can send the response back. If the device sends a carefully crafted fake request with a different return address, then the server will send the response to that spoofed return address.

So if the web camera sends a request to Server A and the response is sent to Server B, then Server A is unintentionally attacking Server B. If the request is the same size as the response, then there’s no benefit to this attack. If the request is smaller than the response, and Server A sends Server B a bunch of unrequested data for every request from the camera, then you have a successful amplification attack. In the case of memcached, traffic can be amplified by more than 50,000 times, meaning that a small botnet can have a huge effect.

Memcached is a memory caching system whose primary use is to help large websites by caching data that would otherwise be stored in a database or API, so it really shouldn’t be publicly accessible anyway.  And the solution is to turn off public-facing memcached over UDP, but the larger solution is to think about what things you are making available to the Internet, and how they can be used maliciously.

Bye Bye, Maplin

Well, that was quick. Four days ago we mentioned that the British electronics retail chain Maplin was being offered for sale, and today it has been announced that no buyer has been found and the company is going into administration.

We dealt with all the nostalgia for what was roughly a British equivalent to Radio Shack in our previous post. Perhaps now it’s time to look beyond the jumpers-for-goalposts reminiscences about spaceships on the catalogues for a moment, and consider what this means for us in 2018.

It’s fairly obvious that a retail model for selling either electronic tat or components is no longer viable in an age of online ordering and availability of almost anything at knock-down prices for anyone prepared to wait for a packet from China. This applies on both sides of the Atlantic, but for British retailers, the killer combination of very high rents and local business taxes makes it particularly difficult. Maplin were extremely convenient when you needed a part immediately, but the universal reaction from Hackaday readers was that they were overpriced. It’s the same story that has cleared away numerous chains in other sectors, and the toxic view that retail property is still the goldmine it might have been in decades past is largely responsible.

Despite all that, there must still be some demand for electronic components at a retail level even if the economics no longer support a showroom model. Perhaps a trade counter operation might have better luck, it will be interesting to see whether suppliers such as RS Components or CPC expand their networks to try to capture that business. Whatever happens, we’ll keep you posted.

Microsoft Quantum Simulator Goes To Linux And Mac

Everyone seems to be gearing up for the race to be the king of quantum computers. The latest salvo is Microsoft’s, they have announced that their quantum simulator will now run on macOS and Linux, with associated libraries and examples that are now fully open source. They have produced a video about the new release, which you can see below.

Microsoft also claims that their simulator is much faster than before, especially on large simulations. Of course, really large simulations suffer from memory problems, not speed problems. You can run their simulator locally or on their Azure cloud.

Continue reading “Microsoft Quantum Simulator Goes To Linux And Mac”

Repairs You Can Print Contest: Meet The Winners

Six weeks ago, we asked you to show us your best 3D printed repairs for a chance to win $100 in Tindie credit and other prizes. You answered the call with fixes for everything from the stuff everyone has, like zippers and remotes, to the more obscure stuff, like amazing microscopes scavenged from dumpsters.

It was hard to whittle down the entries we received into the top 20 because you came up with so many awesome fixes. A few of them had us thinking hard about the definition of repair, but are brilliant in their own way.

So without further ado, we are pleased to announce the winners of our Repairs You Can Print contest. We also want to give honorable mention to those projects that wowed us with ingenuity.

Continue reading “Repairs You Can Print Contest: Meet The Winners”

Maplin For Sale

If you are an American Electronics Enthusiast of a Certain Age, you will have misty-eyed reminiscences of the days when every shopping mall had a Radio Shack store. If you are a Brit, the name that will bring similar reminiscences to those Radio Shack ones from your American friends is Maplin. They may be less important to our community than they once would have been so this is a story from the financial pages; it has been announced that the Maplin chain is for sale.

Maplin started life as a small mail-order company supplying electronic parts, grew to become a large mail order company selling electronic parts, and them proceeded to a nationwide chain of stores occupying a similar niche to the one Radio Shack fitted into prior to their demise. They still sell electronic components, multimeters, and tools, but the bulk of their floor space is devoted to the more techy and hobbyist end of mass-market consumer electronics. As the competition from online retailers has intensified  it is reported that the sale may be an attempt to avoid the company going into administration.

It’s fair to say that in our community they have something of a reputation of late for being not the cheapest source of parts, somewhere you go because you need something in a hurry rather than for a bargain. A friend of Hackaday remarked flippantly that the asking price for the company would be eleventy zillion pounds, which may provide some clues as to why custom hasn’t been so brisk. But for a period in the late 1970s through to the 1980s they were the only place for many of us to find  parts, and their iconic catalogues with spaceships on their covers could be bought from the nationwide WH Smith newsagent chain alongside home computers such as the ZX Spectrum. It’s sad to say this, but if they did find themselves on the rocks we’d be sorry to see the name disappear, but we probably wouldn’t miss them in 2018.

One of the things Maplin were known for back in the day were their range of kits. We’ve shown you at least one in the past, this I/O port for a Sinclair ZX81.

Footnote: Does anyone still have any of the early Maplin catalogues with the spaceships on the cover? Ours perished decades ago, but we’d love to borrow one for a Retrotechtacular piece.

Maplin store images: Betty Longbottom [CC BY-SA 2.0], and Futurilla [CC BY-SA 2.0].