Optimizing The Mining Of Uranium From Coal Ash And Seawater

Of all the elements that make up the Earth’s crust, uranium is reasonably abundant, coming in at 49th place, ahead of elements such as tin, tungsten and silver. Ever since humankind began to exploit uranium for its fissile properties in energy production, this abundance has also translated into widespread availability for mining. As of 2019, Kazakhstan, Canada and Australia formed the world’s main producers, accounting for about 68% of output.

Considering the enormous energy density of uranium when used as fuel in a nuclear fission reactor, the demand for uranium is relatively low, especially combined with the long (two years on average) refueling cycles of commercial reactors. The effect is that even with the very inefficient once-through fuel cycle – which only uses a fraction of the uranium fuel’s potential energy – uranium market prices have remained relatively low and stable even amidst geopolitical crises.

Despite this, the gradual rise in uranium market prices ($10/lb in 2003, $49/lb in 2022), as well as the rapid construction of new reactors is driving new exploration. Here recent innovations may make uranium fuel even more accessible to all nations, by unlocking the billions of tons of uranium found in plain seawater as well as the many tons of fly ash produced by coal plants every single day.

Continue reading “Optimizing The Mining Of Uranium From Coal Ash And Seawater”

A Brief History Of Drywall Or: How Drywall Came To Dominate The World Of Construction

Drywall is common and ubiquitous in commercial and residential buildings today. Many of us barely think about it until we have to repair a hole smashed in it.

However, drywall has not been around forever, and actually took many years to establish itself as a popular building material. Today, we’ll look at how it came about, and why it went on to dominate the world of construction.

Continue reading “A Brief History Of Drywall Or: How Drywall Came To Dominate The World Of Construction”

Superconference 2022 Hack Chat

Join us on Wednesday, August 24 August 31 at noon Pacific for the Superconference 2022 Hack Chat!

[Sorry folks — due to a scheduling snafu, we’ve got to push this off a week. — ed]

To say that a lot of water has passed under the bridge since 2019 is something of an understatement. When last we met as a group, in Pasadena in November of that year, the Covid-19 pandemic and its fallout were ahead of us. Supercon 2019 was a smashing success, a three-day meetup that brought together the best the hacker community has to offer to exchange ideas, share their projects, and meet up IRL rather than reading about everyone’s exploits and adventures online. It was a fantastic time, but how were we to know that it would be the last meatspace meetup for a painfully long time?

join-hack-chatThankfully, that’s all behind us now, and Supercon 2022 is back, live and in person! Everyone in the hacker community is going to want to be in Pasadena, but since it’s been so long since we’ve met up in person, we thought a Hack Chat focusing on Supercon would be a good idea. We’ve invited Majenta Strongheart on to field your questions, plus hopefully we’ll have a few surprise guests too. But this will mainly be your chance to sort of “pre-network” before the con. If you’re a Supercon first-timer, this is a great way to ask questions about how it all works and whether it’s worth it to attend (answer: it is — go buy tickets now!) For vets, this is your chance to share your stories of Supercons past, or perhaps to reconnect with con-buddies you’ve lost touch with. There’ll be something for everyone, both at the Hack Chat and at Supercon, so drop by the chat and find out what all the hype is about.

Our Hack Chats are live community events in the Hackaday.io Hack Chat group messaging. This week we’ll be sitting down on Wednesday, August 31 at 12:00 PM Pacific time. If time zones have you tied up, we have a handy time zone converter.

Hackaday Links Column Banner

Hackaday Links: August 21, 2022

As side-channel attacks go, it’s one of the weirder ones we’ve heard of. But the tech news was filled with stories this week about how Janet Jackson’s “Rhythm Nation” is actually a form of cyberattack. It sounds a little hinky, but apparently this is an old vulnerability, as it was first noticed back in the days when laptops commonly had 5400-RPM hard drives. The vulnerability surfaced when the video for that particular ditty was played on a laptop, which would promptly crash. Nearby laptops of the same kind would also be affected, suggesting that whatever was crashing the machine wasn’t software related. As it turns out, some frequencies in the song were causing resonant vibrations in the drive. It’s not clear if anyone at the time asked the important questions, like exactly which part of the song was responsible or what the failure mode was on the drive. We’ll just take a guess and say that it was the drive heads popping and locking.

Continue reading “Hackaday Links: August 21, 2022”

Dream Projects Face Reality

Do you ever get a project stuck in your mind? An idea so good you just keep thinking about it? Going over iterations and options and pros and cons in the back of your mind, or maybe on paper, but having not yet subjected it to the hard work of pulling it into reality? I’ve had one of those lurking around for the last couple weeks, and it’s time for me to get building.

And I’ve got to get started soon, because it’s rare that any project makes the leap from thought to reality unscathed, and when I hold on to the in-thought project too long, I become far too fond of some of the details and nuances that just might not make the cut, or might get in the way of getting a first pass finished. When I really like a (theoretical) solution to a (theoretical) problem, I’ll try to make it work a lot longer than I should, and I can tell I’m getting attached to this one now.

The only cure to this illness is to get prototyping. When the rubber hits the road, and the bolts are tightened, either the solution is a good one or it’s not, and no amount of dreaming is going to change that. Building is a great antidote to the siren song of a dream project. Although it feels now like I don’t want the fantasy to have to adapt to reality, as it inevitably will, I know that getting something working feels a lot better. And it frees me up to start dreaming on the next project… To the workshop!

This Week In Security: Secure Boot Bypass, Attack On Titan M, KASLR Weakness

It’s debatable just how useful Secure Boot is for end users, but now there’s yet another issue with Secure Boot, or more specifically, a trio of signed bootloaders. Researchers at Eclypsium have identified problems in the Eurosoft, CryptoPro, and New Horizon bootloaders. In the first two cases, a way-too-flexible UEFI shell allows raw memory access. A startup script doesn’t have to be signed, and can easily manipulate the boot process at will. The last issue is in the New Horizon Datasys product, which disables any signature checking for the rest of the boot process — while still reporting that secure boot is enabled. It’s unclear if this requires a config option, or is just totally broken by default.

The real issue is that if malware or an attacker can get write access to the EFI partition, one of these signed bootloaders can be added to the boot chain, along with some nasty payload, and the OS that eventually gets booted still sees Secure Boot enabled. It’s the perfect vehicle for really stealthy infections, similar to CosmicStrand, the malicious firmware we covered a few weeks ago.
Continue reading “This Week In Security: Secure Boot Bypass, Attack On Titan M, KASLR Weakness”

Bufferbloat, The Internet, And How To Fix It

There’s a dreaded disease that’s plagued Internet Service Providers for years. OK, there’s probably several diseases, but today we’re talking about bufferbloat. What it is, how to test for it, and finally what you can do about it. Oh, and a huge shout-out to all the folks working on this problem. Many programmers and engineers, like Vint Cerf, Dave Taht, Jim Gettys, and many more have cracked this nut for our collective benefit.

When your computer sends a TCP/IP packet to another host on the Internet, that packet routes through your computer, through the network card, through a switch, through your router, through an ISP modem, through a couple ISP routers, and then finally through some very large routers on its way to the datacenter. Or maybe through that convoluted chain of devices in reverse, to arrive at another desktop. It’s amazing that the whole thing works at all, really. Each of those hops represents another place for things to go wrong. And if something really goes wrong, you know it right away. Pages suddenly won’t load. Your VoIP calls get cut off, or have drop-outs. It’s pretty easy to spot a broken connection, even if finding and fixing it isn’t so trivial.

That’s an obvious problem. What if you have a non-obvious problem? Sites load, but just a little slower than it seems like they used to. You know how to use a command line, so you try a ping test. Huh, 15.0 ms off to Google.com. Let it run for a hundred packets, and essentially no packet loss. But something’s just not right. When someone else is streaming a movie, or a machine is pushing a backup up to a remote server, it all falls apart. That’s bufferbloat, and it’s actually really easy to do a simple test to detect it. Run a speed test, and run a ping test while your connection is being saturated. If your latency under load goes through the roof, you likely have bufferbloat. There are even a few of the big speed test sites that now offer bufferbloat tests. But first, some history. Continue reading “Bufferbloat, The Internet, And How To Fix It”