Illustrated Kristina with an IBM Model M keyboard floating between her hands.

Keebin’ With Kristina: The One With The Curved Typewriter

Aerodox Flies on Wireless Wings

Aerodox, a wireless, split keyboard.[Simon Merrett] didn’t know anything about keyboards when he started this project, but he didn’t let that stop him. [Simon] did what any of us would do — figure out what you like, learn enough to be dangerous, and then start fiddling around, taking all that inspiration and making a mashup of influences that suits your needs.

The Aerodox design became a cross between the ErgoDox‘s key layout and the logic and communication of the Redox Wireless, itself a reduced-size version of the ErgoDox. Interestingly, [Simon] chose the ErgoDox’s dimensions and spacing, and not those of the Redox. Like a lot of people out there, I found the ErgoDox to be too big for my hands, mostly in that the thumb cluster is too far away from the mainland. It’s nice to see that it suits some people, though.

[Simon] worked up a custom hot-swap footprint that makes the board reversible, much like the ErgoDox. Each half has an NRF51822 for a brain, and there’s a third one that acts as a receiver. This external NRF board is connected over UART to an Arduino Pro Micro, which acts as the USB HID and runs QMK. It’s an interesting journey for sure, so go dig into the logs.

Continue reading “Keebin’ With Kristina: The One With The Curved Typewriter”

Showdown Time For Non-Standard Chargers In Europe

It seems that few features of a consumer electronic product will generate as much rancour as a mobile phone charger socket. For those of us with Android phones, the world has slowly been moving over the last few years from micro-USB to USB-C, while iPhone users regard their Lightning connector as the ultimate in connectivity. Get a set of different phone owners together and this can become a full-on feud, as micro-USB owners complain that nobody has a handy charging cable any more, USB-C owners become smug bores, and Apple owners do what they’ve always done and pretend that Steve Jobs invented USB. Throwing a flaming torch into this incendiary mix is the European Union, which is proposing to mandate the use of USB-C on all phones sold in its 27 member nations with the aim of reducing considerably the quantity of e-waste generated.

Minor annoyances over having to carry an extra micro-USB cable for an oddball device aside, we can’t find any reason not to applaud this move, because USB-C is a connector born of several decades of USB evolution and brings with it not only the reversible plug but also the enhanced power delivery standards that enable fast charging no matter whose USB-PD charger you are using. Mandating USB-C will put an end to needlessly overpriced proprietary cables, and bring eventual unity to a fractured world. Continue reading “Showdown Time For Non-Standard Chargers In Europe”

Fukushima Daiichi at night

A Tritium Story: How Afraid Should You Be Of Hydrogen’s Big Brother?

Despite being present in everything that contains water, tritium is not an isotope that many people were that familiar with outside of select (geeky) channels, such as DEF CON with a tritium-containing badge, the always excellent NurdRage’s assembly of a tritium-based atomic battery, or the creation of a tritium-phosphor-based glow-in-the-dark tesseract cube.

Tritium is a hydrogen isotope that shares a lot of characteristics with its two siblings: 1H (protium) and 2H (deuterium), with the main distinction being that tritium (3H) is not a stable isotope, with a half-life of ~12.32 years that sees it decay into 3He. Most naturally occurring tritium on Earth originates from interactions between fast neutrons (>4.0 MeV) from cosmic radiation and atmospheric nitrogen.

Recently tritium has become a politically hot topic on account of the announced release of treated water at the Japanese Fukushima Daiichi nuclear plant. This has raised for many the question of just how much tritium is ‘too much’ and what we’re likely to notice from this treated — but still tritium-containing water — being released into the ocean.

Continue reading “A Tritium Story: How Afraid Should You Be Of Hydrogen’s Big Brother?”

Keith Thorne, Engineer At LIGO, To Deliver Remoticon Keynote

It is my pleasure to announce that Keith Thorne has graciously agreed to deliver a keynote take at Hackaday Remoticon 2. Get your ticket now!

Keith is an astrophysicist and has worked on the Laser Interferometer Gravitational-Wave Observatory (LIGO) since 2008, literally looking for ripples in space-time that you know as gravitational waves. The effects of the phenomena are so subtle that detecting an event requires planet-scale sensors in the form of 4 km long interferometers placed in different parts of the United States whose readings can be compared against one another. A laser beam inside these interferometers bounces back and forth 300 times for a total travel distance of 1,200 km in which any interaction with gravitational waves will ever-so-slightly alter how the photons from the beam register.

The challenges of building, operating, and interpreting such a device are manifold. These interferometers are the highest precision devices ever devised, able to detect motion 1/10,000 of the diameter of a proton! To get there, the mirrors need to be cooled to 77 nano-Kelvins. Getting the most out of it is what Keith and the rest of the team specialize in. This has included things like hacking the Linux kernel to achieve a sufficient level of real-time digital control, and using “squeezed light” to improve detection sensitivity in frequencies where quantum mechanics is getting in the way. While the detectors were first run in 2015 & 2016, successfully observing three events, the work to better understand this phenomenon is ongoing and may include a third site in India, and a space-based detector in the future.

In getting to know Keith he mentioned that he is excited to speak to a conference packed with people who want to hear the gory technical details of this fantastic piece of hardware. I’m sure we’re all giddy to learn what he has to say. But if you’re someone who wants to work on a project like this, he tipped us off that there’s an active EE job posting for LIGO right now. Maybe you’ll end up doing the keynote at a future Hackaday conference.

Call for Proposals is Still Open!

We’re still on the hunt for great talks about hardware creation. True creativity is fed by a steady stream of inspiration. Be that inspiration by giving a talk about the kinds of things you’ve been working on!

Things Are Looking Brighter! But Not The Stars

Growing up in Montana I remember looking out at night and seeing the Milky Way, reminding me of my insignificance in the universe. Now that I live in a city, such introspection is no longer easy, and like 1/2 of humanity that also lives in urban areas, I must rely on satellites to provide the imagery. Yet satellites are part of the problem. Light pollution has been getting worse for decades, and with the recent steady stream of satellite launches and billionaire joyrides we have a relatively new addition to the sources of interference. So how bad is it, and how much worse will it get?

Looking up at the night sky, you can usually tell the difference between various man-made objects. Planes go fairly slowly across the sky, and you can sometimes see them blinking green and red. Meteors are fast and difficult to see. Geostationary satellites don’t appear to move at all because they are orbiting at the same rate as earth’s rotation, while other orbit types will zip by.

SpaceX has committed to reducing satellite brightness, and some observations have confirmed that new models are a full magnitude darker, right at the threshold of naked-eye observation. Unfortunately, it’s only a step in the right direction, and not enough to satisfy astronomers, who aren’t looking up at the night sky with their naked eyes, naturally.

The satellites aren’t giving off the light themselves. They are merely reflecting the light from the sun back to the earth, exactly the same way the moon is. Thus something that is directly in the shadow of the Earth will not reflect any light, but near the horizon the reflection from the satellites can be significant. It’s not practical to only focus our observatories in the narrow area that is the Earth’s shadow during the night, so we must look closer to the horizon and capture the reflections of the satellites. Continue reading “Things Are Looking Brighter! But Not The Stars”

Hackers And China

The open source world and Chinese manufacturing have a long relationship. Some fifteen years ago, the big topic was how companies could open-source their hardware designs and not get driven bankrupt by competition from overseas. Companies like Sparkfun, Adafruit, Arduino, Maple Labs, Pololu, and many more demonstrated that this wasn’t impossible after all.

Maybe ten years ago, Chinese firms started picking up interesting hacker projects and producing them. This gave us hits like the AVR transistor tester and the NanoVNA. In the last few years, we’ve seen open-source hardware and software projects that have deliberately targeted Chinese manufacturers, and won. We do the design and coding, they do the manufacturing, sales, and distribution.

But this is something else: the Bangle.js watch takes an essentially mediocre Chinese smartwatch and reflashes the firmware, and sells them as open-source smartwatches to the general public. These pre-hacked watches are being sold on Kickstarter, and although the works stands on the shoulders of previous hacker’s reverse engineering work on the non-open watch hardware, it’s being sold by the prime mover behind the Espruino JavaScript-on-embedded language, which it runs on.

We have a cheap commodity smartwatch, being sold with frankly mediocre firmware, taken over by hackers, re-flashed, re-branded, and sold by the hackers on Kickstarter. As a result of it being (forcibly) opened, there’s a decently sized app store of contributed open-source applications that’ll run on the platform, making it significantly more useful and hacker friendly than it was before.

Will this boost sales? Will China notice the hackers’ work? Will this, and similar projects, end up in yet another new hacker/China relationship? We’re watching.

This Week In Security: Apache Nightmare, REvil Arrests? And The Ultimate RickRoll

The Apache HTTP Server version 2.4.49 has a blistering vulnerability, and it’s already being leveraged in attacks. CVE-2021-41773 is a simple path traversal flaw, where the %2e encoding is used to bypass filtering. Thankfully the bug was introduced in 2.4.49, the latest release, and a hotfix has already been released, 2.4.50.

curl --data "echo;id" 'http://127.0.0.1:80/cgi-bin/.%2e/.%2e/.%2e/.%2e/bin/sh'

If that returns anything other than a 403 error, your server may be vulnerable. It’s worth pointing out that Apache is shipped with a configuration block that mitigates this vulnerability.

# Deny access to the entirety of your server's filesystem. You must
# explicitly permit access to web content directories in other
# blocks below.
#
<Directory />
AllowOverride none
Require all denied
</Directory>

The Day The Internet Stood Still

You might have noticed a bit of a kerfluffel on the Internet on Monday. Facebook dropped out for nearly six hours. While the break was nice for some, it was a major problem for others. What exactly happened? The most apparent cause was that the Facebook.com domain was returning nxdomain to DNS lookups. This led to some fun tweets, with screen caps showing Facebook.com for sale.
Continue reading “This Week In Security: Apache Nightmare, REvil Arrests? And The Ultimate RickRoll”