Sunday, September 20, 2026

Hackaday Links: September 20, 2026

September 20, 2026 0
Hackaday Links: September 20, 2026
Hackaday Links Column Banner

Some sad news to start this week off — after 52 years in business, Sherline has announced they are winding down their manufacturing operations. By the end of October they estimate they’ll have produced their last tool, and although they will no longer be making new products, they plan on supporting their existing customers for as long as possible. Although from the sound of the press release, that may mean simply keeping the website up and selling through their inventory of spare parts.

The company offered a range of American-made miniature lathes and mills, and while their manual machines may have been better known in our community, they did eventually branch out into CNC. The press release doesn’t go into a lot of details the chain of events that lead up to this decision, but they do mention the challenges of modern manufacturing and the lingering after effects of the COVID pandemic.

At first blush it might seem strange that the company would falter just as desktop CNCs appear to finally be gaining momentum, but of course that doesn’t change their ability to compete with overseas manufacturing in terms of price.

Of course, keeping competitive is only a concern when you actually have competitors in the first place. That’s the situation that NASA and Boeing may find themselves in should SpaceX decide to retire the Crew Dragon after 2030. While the International Space Station will (probably) be out of the equation by that point, the US space agency will still need the capability to fly humans to…somewhere, and that means there will be lucrative government contracts up for grabs.

The chances of any other American company developing and launching a human-rated spacecraft between now and the end of the decade is pretty much zero, which means Boeing will have to pick up the slack with their Starliner capsule. Or at least, try to, as Starliner hasn’t exactly had the best track record so far. Although by the 2030s SpaceX plans to have transitioned most if not all of their operations to Starship, one does wonder if a big enough check from Uncle Sam could change their minds.

While the market for putting humans into orbit might be shrinking, there’s no shortage of new ways to move stuff around here on terra firma. IEEE Spectrum has the details on a rather unique electric vehicle from startup Revoy that’s designed to sit between a traditional diesel semitruck and its cargo trailer. This essentially turns the combined rig into a hybrid, with the EV module capable of pushing the load for up to 400 kilometers (250 miles). Though it might seem rather low-tech, this approach offers a major advantage in that fleets won’t need to replace their existing vehicles to take advantage of the efficiency gains promised by electrification — with the company claiming that it can cut a truck’s total fuel consumption by up to 85%.

If the day has been going a little too smoothly for your liking and you need something to be frustrated about, here’s something to agonize over. Reality Check shows you images and tasks you with determining if they’re AI-generated or not. As the timer ticks down you’ll be furiously searching the background for malformed bits of text or extra fingers, but even that trick won’t necessarily save you in this era of increasingly capable image models.

Finally, while AI is getting very good at fooling grandmothers on Facebook, we can take some comfort in the knowledge that it’s finding the business world far more difficult to dominate. Drew Magary recently wrote up the experience of visiting a store “managed” by an AI model for SFGATE, and it sounds like things are going just as poorly as you’d imagine.

Given agency to pick the items it wanted to sell in the store the computer stocked the shelves with bric-a-brac that has no obvious overarching theme, and although there’s a human staffer behind the counter, purchases apparently need to be negotiated with the AI via voice chat. The store is burning through its initial investment money with no profit in sight, made all the worse by the fact that one of the line items on the budget is the token cost to run the AI that’s mismanaging the whole thing in the first place.

It’s an entertaining read, and a refreshing splash of cold water on the general AI hype that seems so prevalent these days. But its impact as a condemnation of machine learning in business is undermined a bit when the bottom of every page on SFGATE reminds readers that they are producing content with the assistance of generative AI. C’est la vie.


See something interesting that you think would be a good fit for our weekly Links column? Drop us a line, we’d love to hear about it.


Reviving TEMPEST Attacks with an Injected Signal

September 20, 2026 0
Reviving TEMPEST Attacks with an Injected Signal
A laptop is shown set up on a desk next to a spectrum analyser, an SDR, and two antennas. The antennas are aimed toward assorted electronics, including headphones and a phone handset.

TEMPEST attacks are often the most effective way to break air-gapped security: rather than directly accessing a computer, the attacker records the system’s unintended radio emissions and uses them to reconstruct its internal operations. This kind of attack was much more effective in the days of noisy, high-voltage CRT displays, and has gradually become less effective as electronics migrate to quieter, less powerful components. A group of researchers, however, has found that even modern electronics can become effective TEMPEST transmitters when irradiated with an RF signal.

The RF a device emits depends on the unintentional antennas in its internal structure. These are difficult to eliminate, and it’s usually not worth the effort; they’re usually small enough that they only effectively radiate at much higher frequencies than the electronics carry. The researchers’ technique, called InjectEave, radiated these electronics with a radio frequency tuned to their internal antennas, injecting that frequency into the circuit. Nonlinear electronic components, such as amplifiers, then mix the injected frequency with the internal signal, creating RF sidebands. This mixed signal then radiates out of the device and can be picked up and demodulated to recover the device’s internal signal.

In principle, almost any semiconductor device will perform mixing to some extent; in testing, the researchers had success with an amplifier, analog-to-digital converter, power converter, and switching MOSFETs, but detected no significant emissions without an injected signal. For a portable setup, the researchers used a USRP B210 SDR for transmission and a spectrum analyzer to demodulate the received signal.

This was able to recover audio from wired headphones, wireless headphones, and a wireless landline, and detect the state of a smart lamp and a smart fan. All of this worked over short distances, even through walls, and with a power amplifier, the range increased to 30 meters. Even with multiple devices present, they could focus on one by tuning the injection frequency to resonate with its internal antennas. Perhaps most impressive (or concerning) was a demonstration with the VoIP phone: the researchers were able to listen in on the person speaking, clone that person’s voice, synthesize new speech in that voice, and remotely inject it onto the phone call, altering the call in real time.

If the history of these attacks is any guide, it won’t be too long before we see an open-source implementation of this technique; we’ve already seen a few approaches to traditional TEMPEST. This kind of unintended nonlinear mixing can also be used to find bugs or electronics.


Ski Lift Removes Mice from Chicken Coop

September 20, 2026 0

Getting rid of rodents like squirrels, mice, or groundhogs is a lot like digging a hole on the beach. No matter how much you remove, it’ll always fill back in. So, while [Super Valid Designs] could keep trapping and “removing” the mice in his chicken coop, more will always work their way back in. His theory is that removing them live from the chicken coop and placing them some distance away will be more effective, and with this semi-automated ski lift that traps them and carts them off, it might end up being less work too.

The build comes to us in roughly two parts. The first is the gondolas, which not only cart the mice down the hill to freedom but also double as the mousetrap themselves. They are placed in the chicken coop, and a trap door on the ceiling with bait causes the mice to fall inside. 3D printed with acrylic windows, they are a luxurious way for a mouse to travel. At the bottom, another trap door opens onto a pile of brush, releasing the mice. The second part is the lift, built hastily out of wood and other parts lying around. After much hiking up and down the hill, [Super Valid Designs] eventually got it working properly and reliably toting the mice and automatically releasing them at the bottom of the hill.

It’s a bit too early to tell if this method is more effective than more traditional methods of dealing with mice. But it was at least a fun way to deal with the problem while he also works on more effective methods of preventing the mice from getting into his buildings in the first place. There are some simpler catch-and-release mousetraps out there as well if a ski lift is out of the question for whatever reason.


World War I Coded Message Appears Cracked, Finally

September 20, 2026 0
World War I Coded Message Appears Cracked, Finally

When you think of wartime cryptography, you probably think of World War II and Enigma, although there were other famous codes used during that war. But in fact, there have been codes used through wars and in peacetime for much longer. Even the Romans used codes. Of course, World War I, or The Great War, as it would have been known, had its share of codes and, as you might expect, most of these have been broken long ago. Most of them. But apparently an AI model, GPT-6 Astra, recently cracked one that was previously undeciphered.

If you aren’t up on century-old cryptography, the ADFGVX cipher appeared in 1918. It began as ADFGX, but after a few months grew an extra letter — and a larger grid. The letters were chosen because their Morse-code patterns were relatively easy to distinguish: A, D, F, G, V, and X.

The original ADFGX version used a 5×5 grid containing the alphabet, usually merging I and J. The later ADFGVX version expanded this to 6×6, making room for all the letters and the digits as well.

Encoding required a 5×5 (or 6×6) grid with the alphabet within. The table’s rows and columns were labeled… you guessed it… ADFGX pr ADFGVX. Each plaintext letter gets replaced by the corresponding row and column such as AF or XG. Finally, the letter pairs would be written under a transposition key.

Concatenating those pairs gives AGXGDDDXXF. Written in five columns under CANDY, the first row is AGXGD and the second is DDXXF.

Next, you sort the letters in the transposition key, taking the columns along with the letters. That would make the transposition key ACDNY, and the first row would now be GAGXD. Then the message is sent by columns. Too much to wrap your head around? Visit dCode and plug in some plain text, squares, and keywords for yourself.

The French broke the code in 1918, but without computers it was tough work. Codebreaker [Georges Painvin] reportedly worked on the cipher until it made him ill, but he did solve it. However, some of the intercepted messages remained a mystery. One in particular was sent on November 27, 1918. Apparently, the message used the codeword TRUPPENVERSCHIEBUNG, a German key believed to have gone into service in December. If this decoding is correct, then this message used it even earlier.

The message was, of course, in German and appears to be a report about a British ship’s movements near Sevastopol. In fact, HMS Canterbury’s position on the dates mentioned matches the message.

Honestly, we were more impressed that people like [Georges Painvin] in 1918 were able to decode these intercepted messages. But it is still an interesting glimpse into the capabilities of Astra.

It seems that as long as there has been writing, there have been ways to send secret messages. The Swiss in The Great War had their own encryption method.


Saturday, September 19, 2026

Laser Your Way into Debug Mode on the RP2350

September 19, 2026 0
Laser Your Way into Debug Mode on the RP2350

The RP2350 is actually a pretty secure chip, all things considered. It has secure boot, ARMv8’s TrustZone to split secure and non-secure execution, and you can permanently disable debug — the Pi Foundation even included glitch detection, meaning the traditional ‘zap the chip until it obeys’ technique is blocked. That’s why the [Ledger Donjon] security team went full Bond Villain and strapped everyone’s favourite fruit-flavoured microcontroller to a table with a slowly-approaching laser beam.

The bench setup to do all this is pretty impressive– and came with an impressive 250,000 USD price tag.

Okay — movie clichés aside, the laser was in fact very carefully focused on target before they turned it on. That target was the register that enables the 2350’s debug features. Said register was located by decapsulating the chip and examining the die with photon-emission electron microscopy; the actual attack was carried out on a chip that had been decapped on the back side, with IR shining through the silicon wafer. There was probably more than a little trial-and-error to figure out exactly where on the die adjacent to the register to zap with the laser to flip those bits. But flip they did, restoring the debugger’s access to the secure execution zone. Then, after resetting the chip, [Ledger]’s team read the 128-bit secret the Pi Foundation hid in memory as part of the 2350 hacking challenge.

It’s long been accepted that once the black hats — or white hats, for that matter — have their hands on your hardware, they’re going to find a way in. The effort it takes to break into a simple microcontroller here is actually kind of impressive. We’ve talked about laser fault injection before; ironically, we’ve also featured Pi Pico-powered glitching attacks — the kind that this chip’s glitch detection thwarts.


A Hotspot Becomes A Handheld

September 19, 2026 0
A Hotspot Becomes A Handheld

A Linux handheld computer is, in theory, easy and inexpensive given the availability of single-board computers, but in practice the budget invariably edges well into three figures. There’s an interesting alternative from [bkovac] that won’t break the bank as much, using a cheap 4G wireless hotspot, an iPhone USB keyboard case accessory, and, though a cheaper display could suffice, a fancy Adafruit Sharp memory display.

The hotspot is available from AliExpress for around 20 dollars/Euros/pounds, and it’s referred to by its model number, MF800. It’s powered by a Qualcomm MSM8916, also known as the Snapdragon 410, which you might have found in a budget cellphone early in the last decade. Importantly, though, it’s supported by mainstream Linux, and while it’s by no means the fastest on the block, it can be a poor man’s alternative to a Raspberry Pi. It comes with a small SPI display, but this project replaces it with a much bigger Sharp SPI memory display.

The build walks through a few case mods and a PCB mod on the modem, getting the keyboard to fit, and making a custom power board. Perhaps the software setup is the most interesting part, because this isn’t a simple case of installing a distro. Instead, there’s quite a bit of hackery to get the display working.

We really like this project because while a Linux handheld is nothing new, it’s making one using an unexpected starting point. It reminds us of the old days of running Linux on an old router.


Coreboot Hikes the Bay Trail to DRAM Initialization

September 19, 2026 0
Coreboot Hikes the Bay Trail to DRAM Initialization

This article is written on an open-source operating system, but not an open-source machine — the BIOS isn’t open-source, and even if it were supported by the coreboot project (formerly LinuxBIOS), there would still be a whole host of binary blobs required to get it to boot. On one vintage architecture, there’s one less blob, as coreboot can now initialize DRAM on Intel Bay Trail SOCs, as [Mate Kukri] presented in a talk at the recent Open Source Firmware Conference.

Bay Trail isn’t exactly cutting-edge hardware, to be sure — the SoCs are over a decade old at this point, and were only used in low-performance mobile applications like Chromebooks. On the other hand, coreboot has been on Chromebooks for at least as long. Getting DRAM set up is difficult because, well, you don’t have any memory to work with until you do. Traditionally, the way you did that was to call on one of the many proprietary ‘binary blobs’ provided with next to no documentation by the manufacturer. Reverse engineering that requires some serious bus-sluthing, which was done in software with the SerialICE debugger and the Unicorn Engine CPU emulator. The talk focused on that technique and how it might be applied more widely, rather than getting into the weeds of how to do DRAM init on one obsolete SOC. At some point the whole thing should be archived on the OFSC website so those of us not lucky enough to attend in person can hear what [Mate] — and all the other speakers — had to say.

Because coreboot is open, you can do a lot more with it than a proprietary UEFI firmware — for example, you can choose not to initialize RAM at all, and run entirely in the CPU’s cache. You can also — of course — run DOOM. If you want to be binary-blob-free, you’ll need to find hardware supported by the more hardcore Libreboot distribution of coreboot, which admits no binary blobs at all. When it comes to Libreboot, it might actually be easier to install than to find compatible hardware these days.