Know Your Food: Our Daily Bread

It’s time to return to our no-punches-pulled look at food manufacture, and this time we’re looking at the humble loaf of bread. As before, we’re approaching the subject with a look at breadmaking both in the traditional sense that marketing people would like you to imagine, and in the modern sense of the loaf you’ll find on your supermarket shelf.

A Food Of Great Cultural Significance

An ancient Egyptian relief, showing stylised figures at work on a variety of baking tasks.
An ancient Egyptian bakery, depicted in the reign of Ramesses III. Scanned by Peter Isotalo, CC BY-SA 4.0.

Perhaps there are few foods with as much cultural significance as bread. If your distant ancestors took the path of growing grain as their major subsistence carbohydrate, the chances are there will be some form of bread woven into your identity. Where this is being written for example were I to head for the cathedral of a Sunday morning I would recite the Lord’s Prayer as part of the service, Give us this day our daily bread. Whether your culture leavens its bread or not, or whatever grain it uses, the chances are that there will be something similar about the humble foodstuff within it.

Continue reading “Know Your Food: Our Daily Bread”

Cell Broadcast: The Modern Emergency Alert System

Once upon a time, telephones were primarily point-to-point communications systems. There were options for three-way and conference calls out there, but by and large the plain old telephone system was about connecting one handset to another for a direct conversation. For this reason, the telephone was seldom used for mass emergency communications, because it was simply not fit for broadcasting a message to a wide number of people.

However, technology has since changed. Our modern phones are all connected to a big digital over-the-air network, and large swathes of them can be addressed all at once if so needed. This has led to the development of emergency warning systems that use the cellular network, with Cell Broadcast being the most notable iteration.

Continue reading “Cell Broadcast: The Modern Emergency Alert System”

BornHack Radio 102.8 FM, Playing Radio At A Hacker Camp

Over the years I have been to many hacker camps and done a lot of very cool things, but BornHack 2026 brought me something entirely new: Radio. By which I don’t mean radio in terms of amateur radio, LoRa, or whatever, but Radio. Broadcast radio, because the camp had a special event FM radio station for the first time. And because in a previous life I spent an inordinate amount of time in my university’s student radio station and have the Radio Voice to prove it, I was totally there for it.

A view of a tent shelter in bright sunlight with studio equipment visible on a table in it. There's a sign: "BornHack FM".
The BornHack Radio nerve centre.

For a hacker camp, one of the special things about BornHack Radio was unexpected, that it was entirely analogue. No online streams, the only broadcast was over the air, 5 watts ERP from a vertical antenna stuck on a mast at the highest point of the Hylkedam scout camp site. I don’t know whether any of the residents of the isle of Funen listened, or what they made of it, but it certainly reached as far as the two closest towns.

The other unexpected feature of the station was that it had no music licensing. Personally I viewed this as an asset, because it forced the programming to be hacker-focused rather than suit the musical tastes of whichever people are enthusiastic enough to be DJs. I sincerely hope they don’t get a music licence at future events, speech-only gives it a special quality.

The studio for an analogue station like this one can be surprisingly simple, in that it’s a mixing desk to bring all the different microphones and other inputs together and set the levels, and not a lot else. the whole thing was in a Coleman shelter on the main drag through the camp, so as studios go it could have been quieter. Programming varied from talk shows through interview shows, a live feed from the speaker tent — is this the first ever Hacker Jeopardy broadcast? — and a beautifully done robotic numbers station which I suspect may also have been part of one of the on-camp games.

I brought two shows to the airwaves, both recorded, the first of which was a BornHack take on the Hackaday Podcast format, and the second a half-hour roving interview show. I believe I may be the first person ever to live-commentate a pixelflood screen in the style of Formula One coverage.

The thing that struck me most in my first foray into radio journalism was how straightforward it was. Wander the camp with microphone (complete with fluffy windshield and 3D-printed Hackaday cube), drop the results into Audacity, and a remarkably straightforward editing process compared to video. Last time I did this it involved 1/4″ tape and a razor blade.

So that was BornHack Radio, a new experience at a hacker camp both for those of us who ventured forth on the airwaves, and I hope also for the listeners. A format in which the live shows disappeared into the aether rather than having an online afterlife gave the whole thing a freedom rarely found in 2026. I really hope this isn’t the last time I break out the fluffy microphone at a hacker camp.

Thanks to [⁨Morel Sourvalley⁩] for the images.

Road Trains Roam The Backroads Of Australia

Trains and the railways they run on are a great way to move lots of stuff, or lots of people, a long way. Steel wheels on steel rail can shift great loads at good speeds and railways remain a backbone of logistics for this very reason. The only problem is that they require a great deal of initial investment to build and plenty of maintenance to keep them functional over time.

These concerns can make a railway a difficult proposition when it comes to getting large amounts of goods in and out of remote areas. It’s a problem that Australia faces, with settlements far off the beaten track that are nevertheless in need of high-throughput freight connections. And if you can’t go rail, you go road… in a big way.

Continue reading “Road Trains Roam The Backroads Of Australia”

The 16K Display That Ate Las Vegas

You may have a 4K television. Perhaps you have even bought an 8K screen, despite the shortage of things worth watching in 8K. A 16K display is, today, a rarity. But even when those eventually become commonplace, yours probably will not cover 14,900 square meters, rise 73 meters into the air, or wrap over your head and behind your peripheral vision.

That is approximately what happens inside Sphere in Las Vegas. The venue’s interior display is quoted as having a resolution of 16K by 16K and an area of 160,000 square feet, or about 3.7 acres. Unlike most enormous movie screens, it is not illuminated by a projector. The entire surface is a direct-view LED display: an immense, curved video wall assembled from tens of thousands of smaller pieces.

After seeing The Wizard of Oz at Sphere, however, the most interesting part was not simply the screen’s size. It was how thoroughly the screen could disguise itself.

Where Did The Theater Go?

Radio City or the Sphere? (It is the Sphere; photo courtesy [DP])
Before the presentation began, the auditorium appeared to have a conventional architectural ceiling. Great orange ribs curved over the seating, while ventilation grilles, suspended loudspeakers, lighting fixtures, curtains, and video monitors completed the illusion. It looked like the Radio City Music Hall’s proscenium. Then the show started — and the apparent theater completely disappeared. The speakers, the TVs, even the stage.

The obvious first conclusion was that the LED surface must be optically transparent, allowing the audience to see the real roof behind it until the pixels illuminated. That explanation was attractive because Sphere’s audio system really is installed behind the display, and the surface must allow sound through it.

It was also, apparently, wrong. The only explanation that makes sense is that the ceiling, ribs, grilles, speakers, and monitors were already being displayed by the screen. It was like a holodeck impersonating a physical theater interior. When the Oz material began, the system simply replaced one complete visual environment with another.

That’s what happens when a display fills nearly all of your useful visual field. A normal screen announces itself with a bezel, a wall, or at least a clearly visible edge. Sphere’s display extends upward and around the audience, removing many of those references. Give the image credible perspective, texture, shadows, and familiar architectural details, and the brain accepts the pixels as a room.

The same effect makes the Oz landscapes seem less like scenes displayed in front of the audience and more like places into which the auditorium has been inserted. Of course, there are more special effects. For The Wizard of Oz, there is wind and smoke, along with paper leaves, flower petals, and foam-rubber apples that fall from the sky. All of this makes it even more immersive.

Continue reading “The 16K Display That Ate Las Vegas”

This Week In Security: What’s In A Name, The AI Bugpocalypse Hits Everyone, OpenWRT Flaws, And Duress Passwords

The great thing about standards is there’s so many to pick from, right?. (Insert obligatory XKCD #927 here.) Several companies have developed naming schemes to refer to groups of attacks, and now Google has too.

Sometimes, malware, ransomware, or exploit groups name themselves: “Shinyhunters”, “LapSus$”, “Cl0p”, “Lockbit”, and so on. For the groups that don’t advertise their presence, identification and naming can be more difficult. Mostly state-run affairs that didn’t want to draw attention to themselves, these Advanced Persistent Threats (APT) groups were originally simply given numbers. APT28 refers to the Russian GRU Intelligence Directorate suspected of hacking the Democratic Party email servers, APT38 is a North Korean governmental agency involved in financial and crypto currency theft.

Multiple companies and agencies have developed naming schemes to make referring to threat groups easier, typically including a regional identifier as well. CrowdStrike naming uses name groups like “Bear” group for suspected Russian actors, “Panda” for China, “Spider” for unattributed crime groups, while Microsoft uses “Blizzard”, “Typhoon”, and “Tempest”.

Google, deciding there weren’t enough classifications already, now introduces “RELIC”, “CASTLE”, and “COMET”. Of course, each naming organization has dozens of other classification groups as well, but now the next time you hear about an attack being attributed to “Scattered Spider” you know it’s the CrowdStrike name for a crime group.

Critical OpenWRT DHCP Flaw Fixed

The Hacker News reports on a major release of OpenWRT which includes fixes to the odhcpd server, the embedded DHCPv4 and DHCPv6 server written by OpenWRT.

The bug is a straight-forward stack style attack where a buffer is allocated, but not length-checked against the data required to reply to a malformed request. OpenWRT runs on a wide range of devices, but one of the most popular legacy platforms still in use, the MIPS processor architecture, lacks most modern security protections against stack-based attacks, making this attack sting more than it might on other architectures.

The latest OpenWRT releases also fix issues in the uhttpd embedded web server, multiple issues in the LUCI web configuration interface that allowed attackers to inject cross-site scripting content and Linux kernel security fixes. If you run a direct OpenWRT build on your equipment, update! These bugs will have an extremely long tail however, with tens of thousands, or likely more, OpenWRT-based devices that will never see updates.

The company behind several of the findings, Hacker House, say they used multiple AI tools and both open and frontier models to discover the bugs, then manual review and testing to confirm before reporting.

Cisco to Stop Assigning (some) CVEs

Cisco has announced it is moving to a twice-monthly patch cycle. Additionally, Cisco will no longer assign CVEs to each bug in the release.

Cisco says this is in reaction to the rapid increase in bugs found by AI tools, and that “Assessing security risk CVE-by-CVE and applying point mitigations is no longer fit for purpose.” Cisco will still assign a CVE to a bug that “requires compensating controls” or is known to be exploited.

It seems like it will be business as usual for the most severe bugs, but it will be interesting to see what happens when exploits are found for bugs which did not get a CVE in a prior release.

Microsoft Suggests Three-Day Patch Race

Microsoft is now recommending a 3 day patch window for new patches. This is, to say the least, an “aggressive” schedule for applying new patches, given the recent track record of issues introduced by patches.

A update that crashes is inconvenient on a home computer — even more so if it’s your parent’s computer — but could be catastrophic when it brings down an entire corporate fleet. Most large organizations have their own internal patch schedules and internal testing requirements before patches are deployed, delaying the patch process further.

Systems like the CISA KEV database, a list of vulnerabilities known to be actively exploited, are in place to help identify the most important issues. With repeated record-breaking numbers of vulnerabilities pushed in Patch Tuesday and the decreasing support of the KEV and related vulnerability indexing systems, the load on IT departments and administrators is becoming impossible.

The AI “bugpocalypse” is finding record numbers of vulnerabilities, while also closing the timeline between bug to exploit to hours in some cases. The time between bug and exploit then drives the patch cycle, which means less testing. With less testing, the patches are less stable, leading to less trust in rapidly installing them.

Oracle Patches Almost 1500 CVEs

Moving directly from the impacts of the flood of Microsoft security issues, the July 2026 patch set from Oracle included fixes for 1499 security issues and 1434 CVEs over 334 Oracle products.

Oracle is also pressuring administrators to move to a monthly patch cycle, but acknowledges “transitioning to a monthly security patching cadence may require updates to existing operational processes”. Not to worry – there is a Oracle consulting service you can hire to help you patch your Oracle problems.

Linux Patches 323 CVEs in Two Days

After announcing over 400 CVEs in the Linux kernel last week, Linux mainters have announced an additional 323 in the last three days alone. The vulnerabilities cover Bluetooth, Ethernet, USB gadget mode, WiFi drivers, virtualization systems, SMB file sharing, and of course more.

One benefit to the architecture of the Linux kernel is that typically all the fixes will arrive in a single kernel update, but when almost every week brings critical updates and a new kernel, patch fatigue is a real thing. Either users stop applying every update, or the uptime and testing requirements of a company prohibits constantly updating and changing servers.

Duress Passwords Aren’t Necessarily a Good Thing

The security-hardened Android variant Graphene, is in the news this week for the use of duress passwords.

A duress password is a mechanism where a second PIN or password can be used to initiate a device wipe. The hope is that in a situation where you are compelled to unlock a device, providing a password which then wipes the device is a preferable option.

The legality of a duress password depends on the environment it is used in. The United States Customs and Border Patrol claims that by wiping a device during an inspection at the US border, Samuel Tunick destroyed evidence and property in violation of federal laws. The issue is compounded because the stop happened at a border, where many US laws against search, seizure, and the availability of a lawyer are suspended, even for US citizens.

The inclusion of duress passwords, and their cousin hidden encrypted volumes, can sound like a good idea, but can place users in serious danger when in situations with less strict rules of law. Having the ability to wipe data sounds great in isolation, but protestors, human rights workers, and other targeted groups have faced direct and physical threats under some regimes. Facing retaliation for wiping a device, or facing physical violence before providing an unlock code out of fear that it might wipe a device, can be a real risk for some.

FreeBSD Fixes a WireGuard Bug

FreeBSD has issued a security update pertaining to the WireGuard VPN implementation.

WireGuard is a modern VPN with excellent performance even on low-end systems, and which has implementations on basically every platform. The FreeBSD implementation, however, didn’t fully validate VPN packets, accepting packets without checking one of the cryptographic validation measures.

Attackers are able to inject data to a FreeBSD WireGuard implementation if they are able to guess some attributes of the connection, and able to fully modify the data in the VPN if they are able to intercept the packets.

The bug impacts any FreeBSD user of WireGuard. FreeBSD has released updated kernels.

FLOSS Weekly Episode 877: RCE As A Service

This week Jonathan chats with Francois Proulx about SmokedMeat! That’s the third in a trio of Open Source security tools from Boost Security, and this one is the red team tool to demonstrate vulnerabilities. Why are Continuous Integration vulnerabilities such a persistent problem, and what’s on the horizon that may help? Watch to find out!

Continue reading “FLOSS Weekly Episode 877: RCE As A Service”