NAME:WRECK is a collection of vulnerabilities in DNS implementations, discovered by Forescout and JSOF Research. This body of research can be seen as a continuation of Ripple20 and AMNESIA:33, as it builds on a class of vulnerability discovered in other network stacks, problems with DNS message compression.
Their PDF Whitepaper contains a brief primer on the DNS message format, which is useful for understanding the class of problem. In such a message, a DNS name is encoded with a length-value scheme, with each full name ending in a null byte. So in a DNS Request, Hackaday.com would get represented as [0x08]Hackaday[0x03]com[0x00]. The dots get replaced by these length values, and it makes for an easily parsable format.
Very early on, it was decided that continually repeating the same host names in a DNS message was wasteful of space, so a compression scheme was devised. DNS compression takes advantage of the maximum host/domain length of 63 characters. This max size means that the binary representation of that length value will never contain “1”s in the first two digits. Since it can never be used, length values starting with a binary “11” are used to point to a previously occurring domain name. The 14 bits that follow this two bit flag are known as a compression pointer, and represent a byte offset from the beginning of the message. The DNS message parser pulls the intended value from that location, and then continues parsing.
The problems found were generally based around improper validation. For example, the NetX stack doesn’t check whether the compression pointer points at itself. This scenario leads to a tight infinite loop, a classic DoS attack. Other systems don’t properly validate the location being referenced, leading to data copy past the allocated buffer, leading to remote code execution (RCE). FreeBSD has this issue, but because it’s tied to DHCP packets, the vulnerability can only be exploited by a device on the local network. While looking for message compression issues, they also found a handful of vulnerabilities in DNS response parsing that aren’t directly related to compression. The most notable here being an RCE in Seimens’ Nucleus Net stack. Continue reading “This Week In Security: NAME:WRECK, Signal Hacks Back, Updates, And More”→
When the PineCube was announced by the Pine64 project in 2020, it created a fair bit of interest. Most of this was due to the appeal of a single-board computer (SBC) in a network-based (IP) camera form factor with integrated camera module, for a mere $29.99. Add an enclosure to it, and you would have a neat little package combining a 5 MP camera module with 100 Mbit Ethernet and WiFi. As a bonus, the system could be powered either via an optional battery pack as well as passive PoE, in addition to MicroUSB.
A few weeks ago I bought two of these boards, as part of a client project, and set out to use it for a custom IP camera implementation. With existing Linux-on-SBC and MIPI (CSI) camera experience on my end ranging from the Raspberry Pi to the Odroid, Orange Pi and Banana Pi boards, I felt fairly confident that I could make it work with minimal fuss.
Unfortunately, my experiences were anything but positive. After spending many hours with the PineCube, I’m not able to recommend it for those seeking an IP camera. There are many reasons for this, which I’ll try to explain in this article.
The other day, I saw this gigantic mutant strawberry on reddit that looked like it had either been growing in a radiation zone, hitting the gym regularly, or sprinkled with magic dust. I immediately felt more than mildly interested in this phenomenon, which is called fasciation.
As it turns out, fasciation is fairly rare occurrence that nonetheless occurs in a wide variety of vascular plants. These mutant strawberries may be a bit unnerving to look at, but they are totally safe to eat. The only problem is that you’re more likely to come across a fasciated dandelion or daisy out in the wild than a strawberry or pineapple at the grocery store because the so-called ugly produce tends to be weeded out.
Fasciation is essentially unregulated tissue growth that occurs when the apical meristem, better known as the growing tip of the plant strays from shooting upward in cylindrical fashion and instead splays out flat, resulting in ribbon-like plant stems, elongated or multiple flower heads, and semi-circular strawberries.
Although fasciation tends to present as a flattened main stem, the phenomenon can occur nearly anywhere in the plant — the root, stem, leaves, flower heads, or fruit. It can be localized to just one area, or it affect the entire plant.
Fasciation gets compared to cancer because it has a number of causes and ways of expression, but it’s not quite as harmful or scary. Some races of plants exhibit extreme expression of fasciation. While it’s not fatal, it’s also not ideal, because the condition can result in broken tissues, distorted organization, and a decrease in fertility.
Fasciation: How does it work?
One absolute unit of dandelion. Image via Wild Yorkshire
Fasciation has many causes both internal and external. Internally, it happens because of a hormonal imbalance in the growth cells, a bacterial or viral infection, or a random genetic mutation. There are also environmental causes, like chemical exposure, cold and frost exposure, or fungi, mite, and insect attacks.
The wonder of fasciation knows no geographical, climatic, ecological, or taxonomical bounds among vascular plants. It equally affects annuals, biennials, and perennials; woody and herbaceous plants; shrubs, trees, and vines. Although fasciation can occur in any vascular plant, it is quite common in the rose (includes strawberries), legume, sunflower, and cactus families, and is often found among dandelions and snapdragons.
Some vascular plants are prone to fasciation and prized for it, like the cockscomb (Celosia cristata) flower. A few fasciated flora have even become objects of reverence, like the Virgin Mary appearing on a slice of toast. There was once a fasciated pumpkin vine growing in South India. The twenty-foot-long fasciated portion drew huge crowds of people to worship it, believing the vine to be an incarnation of King Cobra or Naga Sarpa, messenger of the god Vishnu.
This spring, I’ll be looking high and low for abnormal dandelions and daisies. I’ve already started scouting the produce at the grocery store for giant strawberries and found these two in the same box. Won’t you join me? We’re probably more likely to find fasciated fruits or flowers than four-leaf clovers.
Getting great results from a laser cutter takes a bit of effort to make sure all of the settings are just right. But even then, if the air between the material and the laser source is full of smoke and debris it will interfere with the laser beam and throw off the results. The solution is to add air assist which continuously clears that area.
Earlier this year I bought an Ortur laser engraver/cutter and have been hacking on it to improve the stock capabilities. last month I talked about putting a board under the machine and making the laser move up and down easily. But I still didn’t have an air assist. Since then I found a great way to add it that will work for many laser cutter setups.
I didn’t design any of these modifications, but I did alter them to fit my particular circumstances. You can find my very simple modifications to other designs on Thingiverse. You’ll also find links to the original designs and you’ll need them for extra parts and instructions, too. It is great to be able to start with work from talented people and build on each other’s ideas.
Plenty of development is ongoing in the world of lithium batteries for use in electric vehicles. Automakers are scrapping for every little percentage gain to add a few miles of range over their competitors, with efforts to reduce charging times just as frantic as well.
Of course, the real win would be to succeed in bringing a bigger, game-changing battery to market. Solid state batteries fit the bill, potentially offering far greater performance than their traditional lithium counterparts. BMW think there’s merit in the technology, and have announced they intend to show off a solid-state battery vehicle by 2025.
There’s a document I had to sign to wrap up a community responsibility in rural Oxfordshire. At the bottom, dotted lines for signature and date. My usual illegible scrawl for a signature, and scribble in the date below it. Then there’s the moment when the lady handling the form scans it with a puzzled face for a minute, before accepting it with a smile. She’s just been ISO’d!
I’m telling you, you’ve got Pi Day wrong. Evan Shelhamer, CC BY 2.0.
Where I come from in England, it’s the norm to represent dates in ascending order: day, month, year. Thus the 4th of March 2021 becomes 04/03/2021 when written down on a form. This is entirely logical, and makes complete sense given the way a date is said aloud in English and other languages.
Meanwhile in America it’s the norm to represent dates in a different manner: month, day, year. Thus March 4th, 2021 becomes 03/04/2021 when written down on a form. This is also entirely logical, and makes complete sense given the way dates are pronounced in American English.
As someone whose job entails crossing the Atlantic in linguistic terms, I am frequently confused and caught out by this amusing quirk of being divided by a common language. Is 03/04/2021 the 3rd of April or March 4th? “Why can’t Americans use a logical date format!” I cry as in a distant transatlantic echo I hear my friends over there bemoaning our annoying European ways. It’s doubtful that this divergence has caused any satellites to crash, but it sure can be annoying.
Confusing Everyone For Over Three Decades
So I took a stand. A couple of decades ago I adopted ISO 8601 in writing dates, an international standard that’s been with us for well over three decades. It too is an entirely logical way to express time, but unlike the two mentioned earlier it’s not tied to any linguistic quirks. Instead it starts with the largest unit and expresses a date or time in descending order, and extends beyond dates into time. Thus the date on my form that caused the puzzlement was 2021-03-04. I’m guessing that here at Hackaday I’m preaching to the choir as I certainly won’t be the only one here using ISO 8601 in my daily life, but while we’re talking about alternative date formats within our community it’s an opportunity to take stock of the situation.
UNIX time is probably the most instantly recognisable of all our measurement schemes, being a count of seconds elapsed since the Unix epoch of 1970-01-01T00:00:00+00:00 UTC. Coincidentally this is also an auspicious date for many readers, as it’s our birthday. If I’d written the 4th of March on that form as 1614816000 though I would have been met with complete incomprehension, so aside from the occasional moment of coming together to observe a rollover it’s not something we use outside coding.
But it does lead neatly to another question: since UNIX time is most often expressed in text as a base-10 number, why on earth does our clock time work in base 60 for seconds, base 12 or 24 for hours, and then base 12 for months? Why don’t we use a base 10 metric time system?
It makes sense for our annual calendar and the length of our day to be derived from Earth’s orbit, as we use dates as a measure of season and times as a measure of the daily progress rather than simply elapsed periods. We owe our twelve-hour days and nights to the ancient Greeks and our 60 seconds and minutes to the ancient Babylonians, while our twelve months come from the ancient Romans. It’s clear that a 365.24-day year with four seasons doesn’t divide neatly into ten months, so we’re at the mercy of our own set of celestial bodies when talking about dates. But surely we could move on from ancient Greece and Babylon when it comes to the time of day?
Liberté, Égalité, Ponctualité!
A 10-digit Revolutionary French clock. DeFacto, CC BY-SA 4.0
Probably the most famous attempt at a decimal calendar came in the aftermath of the French Revolution; the French Republican calendar perhaps wisely stuck with twelve months but made each of them of three 10-day weeks, and then split the day by 10 hours, with each further subdivision being by base 10. The months each had 30 days, with the remaining 5 days (or 6 in leap years) being public holidays.
It came to an official end when the revolutionary government that had introduced it was replaced by that of Napoleon. Unlike other French Republican measurements such as the meter, it evidently didn’t provide enough advantage for its popularity to outlive its political origins.
There’s an interesting parallel in the decimalisation of British currency in 1971. Previously, a pound was 20 shillings, each of which were 12 pence. Afterwards, a pound became 100 new pence, and that’s stuck. Despite some people’s lingering nostalgia for the old system, the utility of decimialisation was self-evident.
The moral of the French time-decimalization story was that people simply use a calendar and time system to tell the date and time. When you need to do frequent arithmetic, as is the case with currency, distance, or weights, this is made significantly easier through decimals. But when nature hands you four seasons, you’re pressed into twelve months. Perhaps when we slip the bonds of Earth, we’ll use decimal Stardates, but in the mean-time, ISO might just be the way to go.
3D scanning and 3D printing may sound like a natural match for one another, but they don’t always play together as easily and nicely as one would hope. I’ll explain what one can expect by highlighting three use cases the average hacker encounters, and how well they do (or don’t) work. With this, you’ll have a better idea of how 3D scanning can meet your part design and 3D printing needs.
How Well Some Things (Don’t) Work
Most 3D printing enthusiasts sooner or later become interested in whether 3D scanning can make their lives and projects easier. Here are a three different intersections of 3D scanning, 3D printing, and CAD along with a few words on how well each can be expected to work.
Goal
Examples and Details
Does it work?
Use scans to make copies of an object.
3D scan something, then 3D print copies.
Objects might be functional things like fixtures or appliance parts, or artistic objects like sculptures.
Mostly yes, but depends on the object
Make a CAD model from a source object.
The goal is a 1:1 model, for part engineering purposes.
Use 3D scanning instead of creating the object in CAD.
Not Really
Digitize inconvenient or troublesome shapes.
Obtain an accurate model of complex shapes that can’t easily be measured or modeled any other way.
Examples: dashboards, sculptures, large objects, objects that are attached to something else or can’t be easily moved, body parts like heads or faces, and objects with many curves.
Useful to make sure a 3D printed object will fit into or on something else.
Creating a CAD model of a part for engineering purposes is not the goal.
Yes, but it depends
In all of these cases, one wants a 3D model of an object, and that’s exactly what 3D scanning creates, so what’s the problem? The problem is that not all 3D models are alike and useful for the same things.