[00:00.000 --> 00:02.700] I've worked with Travis in the last few weeks. [00:03.400 --> 00:05.700] One of the things that I created for this conference... [00:05.700 --> 00:06.360] Shut up. [00:06.540 --> 00:07.180] All right, shut up! [00:07.860 --> 00:08.520] Talk's starting. [00:10.160 --> 00:19.620] One of the things I created for this conference was an eight-stage puzzle hunt, very loosely based on some of the clues that have been in past MIT mystery hunts. [00:20.240 --> 00:29.920] The first two clues are embedded in the firmware of the badge, but I've seen very little uptake in the third and further rounds, because I guess people just don't know it's there. [00:30.980 --> 00:35.000] The issue is that it's only in the B firmware of the badge, that's correct? [00:35.320 --> 00:35.460] Yes. [00:35.640 --> 00:50.180] If you look at your badge, and if you look at the serial number NHB12, and you'll either have a B or you won't, if you have a B, dump the firmware over JTAG, and you'll see the beginning of the work that I put in. [00:50.540 --> 00:51.920] So, I think that's about it. [00:52.660 --> 00:54.780] If anyone has any questions, they're free to ask me at the end. [00:54.920 --> 00:55.120] Cool. [00:55.300 --> 00:55.820] Where's Nick? [00:58.760 --> 00:59.780] Go get up here, neighbor. [01:02.420 --> 01:02.900] Nope. [01:04.420 --> 01:04.760] All right. [01:07.800 --> 01:08.420] Go ahead. [01:08.720 --> 01:09.080] Oh, okay. [01:09.320 --> 01:09.760] Sorry about that. [01:10.540 --> 01:11.480] Good evening, everybody. [01:12.880 --> 01:14.100] Can you do a FinFittin demo? [01:14.700 --> 01:15.280] Yeah, sure. [01:15.340 --> 01:15.640] FinFittin? [01:15.900 --> 01:16.220] All right. [01:16.340 --> 01:24.200] This is my very good and neighborly friend, Travis Goodspeed, who is responsible for this awesome badge happening. [01:24.380 --> 01:26.420] So, just for that, give him a round of applause. [01:32.060 --> 01:35.900] If there's anything wrong with it, I can guarantee you it's not Travis's fault. [01:36.620 --> 01:37.200] It's Nick's fault. [01:37.380 --> 01:37.980] It's my fault. [01:38.320 --> 01:39.140] Everything is my fault. [01:39.360 --> 01:45.120] And because of that, we're going to demonstrate something that we've been spreading at hacker cons all over the world. [01:46.280 --> 01:47.440] It's a new protocol. [01:47.860 --> 02:02.020] Well, not that new, but it's if you ever have an irreconcilable difference, something that you know you're never going to work out with somebody who you should remain on neighborly terms with, you issue a f*ck you packet like this. [02:02.020 --> 02:03.420] F*ck you neighbor. [02:05.280 --> 02:09.240] To which there is a reply packet, a f*ck you to neighbor packet. [02:10.620 --> 02:15.940] So, suppose that Nick comes up to me and he says, Travis, my badge keeps turning off. [02:16.160 --> 02:17.120] What do I do? [02:17.620 --> 02:20.720] I tell him the battery, but there's still a little grudge left. [02:20.920 --> 02:22.060] So, here's how we solve it. [02:22.780 --> 02:23.680] F*ck you neighbor. [02:23.920 --> 02:24.680] F*ck you to neighbor. [02:25.060 --> 02:27.560] And you shake hands and the handshake is important. [02:27.560 --> 02:29.960] That's what ends the un-neighborliness. [02:30.360 --> 02:32.640] It's all now over and everything can be neighborly. [02:34.020 --> 02:36.660] Neighborliness abounds and we need a round of applause for that. [02:40.230 --> 02:41.130] You ready to go? [02:42.010 --> 02:42.110] Yeah. [02:42.530 --> 02:47.350] So, without any further ado, Travis Goodspeed building and breaking The Next HOPE badge. [02:47.670 --> 02:49.090] Huge round of applause this time. [02:49.310 --> 02:49.490] Woo! [02:56.790 --> 02:57.310] Okay. [02:57.570 --> 03:06.390] So, I could either give you a lecture about how the badge works here, which I assume you're all familiar with after the panel yesterday, and from walking around. [03:06.630 --> 03:09.170] So, they run the OpenBeacon protocol. [03:09.630 --> 03:11.670] There's the website and you can view the maps. [03:11.830 --> 03:12.610] The maps are now working. [03:13.850 --> 03:16.630] I could either do a second hour-long lecture on that. [03:17.390 --> 03:22.930] Pissing off everyone else who worked in it because I'd be hogging the stage and all that stuff. [03:23.150 --> 03:25.350] Or, I could show you how to do something new with the badge. [03:26.230 --> 03:29.490] So, in this talk, I'm barely going to mention OpenBeacon. [03:29.830 --> 03:32.050] I'm barely going to mention the attendee metadata project. [03:32.050 --> 03:37.670] Those are both very big, very complicated projects that do incredible things, but they are not the topic of this lecture. [03:39.670 --> 03:43.170] Instead, I'm going to tell you how to break into electronics like the HOPE badge. [03:43.590 --> 03:45.690] And one of these projects nearly got me sued. [03:46.150 --> 03:48.970] So, neighborliness abounded in that and that I did not. [03:50.690 --> 03:56.470] The idea is that, in this lecture, I'm going to be telling you about 8 and 16-bit embedded systems and how to reverse engineer them. [03:56.470 --> 04:01.170] The computer inside your HOPE badge is about as powerful as the Sega Genesis. [04:02.150 --> 04:03.570] It might run a little bit faster. [04:03.910 --> 04:05.050] It might run a little bit slower. [04:05.290 --> 04:06.450] Bad at multiplication. [04:06.890 --> 04:07.790] Better at power efficiency. [04:08.110 --> 04:09.190] But it is a computer. [04:09.310 --> 04:10.850] You can write a new program for it. [04:10.890 --> 04:13.430] You can flash that program into the badge. [04:13.430 --> 04:15.710] You can reverse engineer the code that's already there. [04:18.070 --> 04:21.110] And you can also start playing around with the radios. [04:21.910 --> 04:27.810] You can start broadcasting new messages, receiving messages, or you can start receiving messages that you're not supposed to. [04:27.990 --> 04:29.630] Which, as we all know, is a lot of fun. [04:33.410 --> 04:34.270] So, let's see. [04:35.170 --> 04:39.930] The target hardware that we'll be talking about is the sort of stuff used in Zigbee, Ant, 802.50.4. [04:41.390 --> 04:44.690] This technology is also known as wireless sensor networks or the smart grid. [04:45.290 --> 04:46.830] It's used in sports and medical equipment. [04:47.090 --> 04:52.410] The idea is that, very often, you want to broadcast a radio signal, but you don't want to waste a lot of power on it. [04:52.550 --> 04:54.810] And at the same time, you don't need to send a lot of data. [04:54.930 --> 04:56.890] You're not trying to stream video here. [04:56.890 --> 05:01.670] All you want to do is send a little chirp that says, here I am, as your badges do. [05:04.110 --> 05:06.010] So, a quick show of hands. [05:06.610 --> 05:09.450] How many of you are very familiar with soldering? [05:10.730 --> 05:11.210] Awesome. [05:11.670 --> 05:14.210] How many of you know about the Intel 8051? [05:15.990 --> 05:16.470] Okay. [05:16.910 --> 05:22.230] How many of you are familiar with RISC assembly language, as opposed to x86, or anything non-x86? [05:22.750 --> 05:23.650] All right, cool. [05:24.370 --> 05:27.750] And how many of you understand the finer analog points of radio? [05:29.390 --> 05:30.350] Cool, because I don't. [05:32.410 --> 05:34.850] If you measure the antenna, I'm sure you've figured this out already. [05:36.590 --> 05:39.390] So, this is the next hope badge, and I'm sure you've all got them. [05:41.590 --> 05:46.490] If you don't, security will escort you outside and be jerks and all of that fun stuff that they're paid to do. [05:48.310 --> 05:50.610] On this, let me grab a laser pointer. [05:51.470 --> 05:52.070] All right. [05:52.610 --> 05:55.630] So, how many of you have taken a look at the design? [05:55.790 --> 05:59.490] Grabbed the schematics off of SourceForge and started to play around with your badge? [06:00.170 --> 06:00.550] Okay. [06:00.950 --> 06:06.370] For those of you who haven't, this chip here is the MSP430 microcontroller. [06:06.690 --> 06:10.710] Texas Instruments was kind enough to donate $25,000 worth of these to the conference. [06:10.710 --> 06:11.870] Let's give them a round. [06:19.030 --> 06:23.310] Their corporate web filter has also banned the conference website as a hacker website. [06:27.570 --> 06:28.370] So, it goes. [06:29.030 --> 06:32.310] Over here, there's Nordic RF radio chip. [06:32.830 --> 06:38.030] This is used in a variety of devices, one of which I'll go into a bit of detail about later. [06:39.310 --> 06:46.810] This radio speaks on any frequency from 2.400 gigahertz to 2.528 gigahertz. [06:47.630 --> 06:54.390] You just have a 7-bit field that describes the number of megahertz above 2.4 gigahertz that the channel is on. [06:56.330 --> 07:02.310] On the back, you can hack your badge with a badge hacking kit being sold by Mitch Altman and also by Lady Ada. [07:03.070 --> 07:06.270] This chip here is an FTDI USB to serial converter. [07:06.270 --> 07:09.930] It's the same thing that you have within an FTDI cable used for Arduinos. [07:10.590 --> 07:13.090] And then, over on the edge, there is a USB plug. [07:14.690 --> 07:25.250] If your lights start flickering when you try to install this, it's because the power plug on the USB plug, that's the line furthest to the left, is missoldered. [07:27.090 --> 07:29.730] If it doesn't work at all, you've probably messed up some of these pins. [07:29.930 --> 07:38.350] It's not a soldering project for beginners, but if you do it, it's quite rewarding, and you get to do all sorts of fun stuff and fun neighborly stuff. [07:39.710 --> 07:46.330] This here is the CAD file design that was used for manufacturing the badge. [07:46.550 --> 07:48.490] All of this is in the SourceForge project. [07:48.930 --> 07:50.690] You can check it out by SVN. [07:50.850 --> 07:52.330] The project name is NHBadge. [07:53.210 --> 07:57.110] And later on, I assume this will be rolled into a distribution or something. [07:57.110 --> 07:58.250] But for now, grab SVN. [07:58.870 --> 08:01.110] That way, when I fix things, you can get the update immediately. [08:02.570 --> 08:05.510] Down here at the bottom, there is a general purpose I.O. [08:05.550 --> 08:05.790] port. [08:07.710 --> 08:12.150] I don't mean to impose, but if someone could grab me a beer or a kumata, I would very much appreciate that. [08:16.310 --> 08:17.770] Yeah, this general purpose I.O. [08:17.790 --> 08:19.150] port is used as a touch sensor. [08:19.150 --> 08:30.190] If you hold the crystal on your board with one hand, thumb and forefinger, and then you also, with your other thumb and forefinger, touch along this row, you'll see the lights respond. [08:30.530 --> 08:32.330] You can get red, green, and blue. [08:32.810 --> 08:34.770] Green and blue cannot be lit at the same time. [08:34.950 --> 08:35.950] Green will take precedence. [08:36.190 --> 08:37.630] It's an electronic thing. [08:38.330 --> 08:40.630] Up here at the top is the JTAG port. [08:40.850 --> 08:44.130] This is what was used for commissioning the badges on the assembly line. [08:45.790 --> 08:55.130] This is also used for copying software out of the badge, if perhaps there were some secrets here, such as the one that David was alluding to, that might or might not only be in the 12B model. [08:57.370 --> 08:59.330] Here we have an ICE port. [08:59.610 --> 09:10.070] This was broken out not because of any expectation that you would need it, but because it displays a neat little property, which is that you can wiretap the connection between the microcontroller and the radio. [09:10.330 --> 09:12.710] And I'll be talking about the details of that in a minute. [09:13.350 --> 09:25.310] But watching this connection, you can see exactly which channel the badge is running on, or exactly which packets it's sending out or receiving, exactly which MAC addresses it's listening on, which is, for this chip, a rather big deal. [09:25.490 --> 09:30.530] The only thing preventing you from sniffing all traffic is that the chip has no promiscuous mode. [09:30.910 --> 09:35.530] There is no way with this radio to sniff traffic aimed at every MAC address. [09:35.710 --> 09:37.510] You need to know at least the first three bytes. [09:39.150 --> 09:41.790] Up here is a BSL connector. [09:41.790 --> 09:44.290] This is used for connecting a bootloader. [09:45.670 --> 09:47.910] An FTDI cable for talking to the bootloader. [09:48.610 --> 09:52.210] It's sort of the poor man's way of doing the badge hacking kit on the back. [09:52.690 --> 09:56.810] I have not tested this, but I know that at least Mike Kershaw and perhaps others have it working. [09:59.030 --> 10:02.670] So this CAD file is enough to have boards manufactured. [10:03.010 --> 10:04.310] They were sent off to China. [10:04.790 --> 10:06.990] We got... they were panelized. [10:07.510 --> 10:11.470] And then there were these files that would come back to me. [10:11.750 --> 10:14.350] This is a machine translation and a very poor one. [10:14.910 --> 10:22.270] Mike Zhao was our manufacturing contact in China, who was chosen by Mitch Altman, who was very neighborly. [10:23.250 --> 10:31.790] Mike took care of taking the Chinese that Google could not understand and translating it, and also making sure that this whole thing actually came out of the assembly line on time. [10:32.110 --> 10:35.530] A lot of that involved harassing me, for which I am terribly grateful. [10:36.330 --> 10:38.350] Otherwise, this would not have shipped on time. [10:40.470 --> 10:42.190] So this lecture will be in three parts. [10:42.610 --> 10:45.350] The first part will just simply show you how to sniff an SPI bus. [10:45.590 --> 10:50.870] The second part will describe how I reverse engineered another device, which is compatible with the hope badge. [10:51.050 --> 10:55.210] And then the third part will describe how to sniff and inject traffic from that device. [10:57.210 --> 11:00.330] And then if there's time at the end, I'll show you some neat little tricks that you can do. [11:01.970 --> 11:06.890] A big part of this lecture will be the GoodFET, which is an open-source JTAG debugger. [11:06.890 --> 11:08.090] It's a project of mine. [11:08.430 --> 11:17.210] This is sort of an open-source clone of both the proprietary Texas Instruments JTAG debugger, which I was very unhappy with in its Linux support at the time. [11:17.750 --> 11:21.270] And also the Hackaday Bus Pirate that Ian Lesnit made. [11:22.710 --> 11:24.650] This and the Bus Pirate don't share our code base. [11:24.830 --> 11:25.630] Maybe at some time they will. [11:25.850 --> 11:28.190] But for now, it's best to have both devices. [11:29.350 --> 11:31.450] And it implements a lot of different protocols. [11:31.710 --> 11:34.750] So you can debug 8051 microcontrollers, the MSP430. [11:34.750 --> 11:36.130] We're about to commit ARM support. [11:36.430 --> 11:38.930] You can read and write SPI and ITC EPROMs. [11:39.790 --> 11:45.090] You can talk through radios if you have a NordicRF chip or any of the ChipCon devices. [11:47.570 --> 11:52.610] And I'll send you a board for free if you send a polite email and perhaps five bucks by PayPal. [11:54.410 --> 11:55.570] The PayPal's optional. [11:55.750 --> 11:58.110] The people that do pay more than account for the people who don't. [11:58.770 --> 12:00.490] This is what a GoodFET looks like. [12:00.730 --> 12:03.190] You've got the FTDI chip on the left. [12:03.570 --> 12:04.750] The MSP430 in the middle. [12:05.010 --> 12:05.850] And the IO ports on the right. [12:06.150 --> 12:11.510] If this looks similar to the HOPE badge as far as the chip choices go, it's because they're almost identical. [12:11.770 --> 12:17.630] If you add the FTDI chip to your badge and also a USB plug, you can run the GoodFET firmware. [12:17.990 --> 12:24.930] Which instead of beaconing out as the default badge firmware does, just gives your computer access through Python to the radio. [12:26.590 --> 12:29.110] Having access to this radio, you can sniff and inject. [12:29.590 --> 12:30.210] You can jam. [12:30.930 --> 12:34.210] It's one command to hold a carrier wave on any given frequency with the HOPE badge. [12:37.630 --> 12:43.150] But first you need to figure out, before you can sniff something, which MAC address it's using, which frequency it's using. [12:43.170 --> 12:45.330] Otherwise, you're jumping around in a sea of noise. [12:45.710 --> 12:55.070] And as you're doing it with checksumming disabled, which is necessary when you don't yet know where the checksumming fields are, you wind up with a lot of packets that look kind of right but aren't. [12:55.870 --> 13:02.550] I had a thing at Defcon in the Lost Mystery Challenge where I had a radio that was just spewing garbage whenever it wasn't near a transmitter. [13:02.870 --> 13:06.110] And I had this piping into Xterm. [13:07.070 --> 13:14.690] Xterm, when it receives garbage, does not crash, but it grabs strings from random areas of memory, a lot of which happened to be English or function names. [13:14.690 --> 13:19.290] So I kept thinking that I was getting legitimate traffic when I was actually getting further away from the transmitter. [13:19.810 --> 13:21.790] You need to watch out for confusing parts like this. [13:22.650 --> 13:28.810] In taking apart any radio, you've got to identify the antenna, the radio chip itself, the microcontroller. [13:29.390 --> 13:30.690] Sometimes these two are combined. [13:30.890 --> 13:32.430] They will be in the subject that comes later. [13:32.770 --> 13:38.330] In order to sniff the radio traffic, you have to identify where the zero port between them is. [13:38.950 --> 13:41.510] This is what's on the ICE connector on your badge. [13:43.390 --> 13:48.390] In this case, you just need to identify the radio chip, and then you look at the pin labels. [13:48.790 --> 13:53.750] In this case, we want the serial clock line, serial out, and serial input, and also ground. [13:53.990 --> 13:57.430] And they happen to all be in this nice little ring around the edge. [13:59.230 --> 14:07.390] So you identify these signals, and then having found them on the board, you can figure out exactly where to tap on the board as a whole. [14:08.030 --> 14:10.050] I like to use hypodermic syringes for these. [14:11.990 --> 14:14.290] A kind thanks to Eric Michaud for getting me my beer. [14:14.930 --> 14:15.890] I appreciate it. [14:23.040 --> 14:24.920] I'm sure this beer will cost me a quart later. [14:28.200 --> 14:34.380] So you pick your tapping point, which would be here, and then you shove syringes into the board. [14:34.380 --> 14:45.460] Or you can get very high-gauge wire wrap wire, which can be fed through the vias that are only intended to move the copper from one side of the board to the other. [14:45.780 --> 14:50.380] You can slip a wire in there, tap it on with a bit of solder, and get a clean connection. [14:51.300 --> 14:54.060] On an oscilloscope, this is what the clock line looks like. [14:54.260 --> 14:56.040] Here, you have two bytes being transferred. [14:56.320 --> 14:57.640] There's a little pause in between them. [14:57.800 --> 14:58.940] The clock is idling low. [14:59.120 --> 15:06.040] And then the contents jumps high and low of the clock line to indicate when the data line should be sampled or written. [15:06.680 --> 15:13.480] This is what one of the data lines looks like by lining the two up and then reading on every rising edge or every falling edge, depending upon which speaker. [15:13.660 --> 15:15.240] You can then figure out what the byte is. [15:17.360 --> 15:18.240] No, it's not. [15:18.420 --> 15:18.620] It's not. [15:19.000 --> 15:20.780] The question was, is it Manchester encoded? [15:21.220 --> 15:30.020] And no, it's just at the instant of the clock edge, the value of the data line gets latched into flip-flop and held there. [15:31.240 --> 15:37.020] So this is so low noise that there's no need for Manchester encoding or other error correction measures. [15:38.740 --> 15:42.400] You can tap with syringe if you'd rather not use wires. [15:42.400 --> 15:44.940] This is generally helpful if you're just trying to dump an EEPROM. [15:45.140 --> 15:47.320] This is a JTAG debugger from Texas Instruments. [15:47.620 --> 15:53.020] And the USB device firmware resides in this chip, being executed on this chip. [15:53.020 --> 16:05.040] It's rather common that new chips will boot from an external EEPROM chip because the EEPROM silicon is more difficult to make. [16:05.280 --> 16:12.180] And when you're also trying to make a radio or USB device or something that involves complicated analog lines, it's best to keep them separate. [16:13.360 --> 16:13.480] Oh. [16:14.420 --> 16:14.960] End of Clumata. [16:15.660 --> 16:16.740] I like this audience. [16:19.280 --> 16:23.560] Having tapped this, there is a great series of tools from Total Phase. [16:23.980 --> 16:26.540] This is one of very few proprietary tools that I use. [16:28.640 --> 16:33.080] But they make a better product for this than any of the open-source stuff thus far. [16:34.720 --> 16:36.380] Here you can see the different transactions. [16:37.900 --> 16:39.300] Mosey is master out, slave in. [16:39.680 --> 16:41.720] You see the data is written here. [16:41.980 --> 16:44.060] And then data comes on the other side. [16:44.060 --> 16:49.400] These bytes are in pairs because in SPI, a single byte is transferred for every byte that's received. [16:50.920 --> 16:52.780] These have to come at the same time. [16:53.140 --> 17:03.000] But because that's very rarely useful in a protocol, very often one side of the data will either be ignored or will be irrelevant or all ones. [17:05.100 --> 17:12.200] Having tapped this, you can see delightfully useful things in that quite often the radio implements more than just radio stuff. [17:13.040 --> 17:15.200] AES acceleration is one of the best of these. [17:15.380 --> 17:25.420] So if you wiretap a, let's say, ChipCon2420 on an early Zigbee prototype, there are two spots in RAM that actually have the AES keys written to them. [17:25.420 --> 17:28.700] And you can just watch the key get written over the line. [17:29.320 --> 17:35.440] You can also knock the original host off of the bus and read that RAM out of these chips. [17:35.580 --> 17:38.300] So you can say, oh, shucks, I forgot what my AES key is. [17:38.380 --> 17:39.220] Could you please remind me? [17:39.700 --> 17:42.940] And then you get a copy from which you can decrypt any packet you like. [17:42.940 --> 17:57.580] It's also very useful for channel hopping devices because you can tap one device, watch its orders to change channels, and then follow the channel hopping knowing on which channel to sniff even though you're not yet aware of exactly what the channel hopping algorithm is. [18:00.120 --> 18:01.800] So that's enough of an abstract theory. [18:01.900 --> 18:03.140] Let's take an actual product apart. [18:03.440 --> 18:05.400] This is a turning point clicker. [18:05.580 --> 18:07.160] Do we have any university students in the audience? [18:07.840 --> 18:11.420] Particularly those in freshman astronomy or chemistry. [18:12.740 --> 18:20.400] These devices, for those of you who don't have to suffer such stuff, are used for attendance taking and in-class quizzes and in-class polling. [18:20.640 --> 18:22.500] It's also used in some large corporate meetings. [18:23.020 --> 18:36.880] The idea is that you press one of the buttons, they're labeled 1, 2, 3, 4, or A, B, C, D, and it will broadcast your serial number, that's these three bytes here, followed by the byte of the button being pressed as ASCII. [18:37.160 --> 18:44.980] So if you hit the 1 button, it'll do 31 hex, which is ASCII for 1, 2 is 32 hex, all the way to the question mark, which is 3F hex. [18:46.920 --> 18:50.420] So you can pop this open just by peeling the keypad off. [18:50.560 --> 18:51.780] It's not actually screwed in. [18:53.000 --> 18:56.100] You'll find either Philips or Nintendo screws here. [18:57.740 --> 19:00.940] Just buy a Nintendo Wii screwdriver and you can pull this right out. [19:02.120 --> 19:06.020] Once you're down to the board, you have a radio, which is also a microcontroller. [19:06.020 --> 19:07.640] This is an 8051 clone. [19:07.780 --> 19:13.020] It's a very early Intel chip that everyone has copied because the patents have expired and that sort of stuff. [19:15.280 --> 19:17.100] Down here, you have a SPY ROM. [19:17.300 --> 19:22.360] And the SPY ROM is actually used for booting the 8051 chip. [19:22.520 --> 19:26.900] Because the 8051 chip includes a radio, it was very difficult for them to also include EEPROM. [19:26.900 --> 19:31.300] And therefore, this is necessary to have permanent storage. [19:31.600 --> 19:35.200] So there's a little bit of permanent memory that boots from this external memory. [19:35.740 --> 19:40.140] There are also these handy debug pins, which are accessible from outside of the case. [19:40.620 --> 19:51.020] So to dump the firmware, you just have to read up on these chips, discover the protocol of 24C32, and then reading its datasheet, you write a little good fit driver for dumping it. [19:51.400 --> 19:56.000] The radio itself is an 8051 containing a Nordic RF 2401 radio. [19:56.540 --> 20:00.820] The hope badges use a 24L01, if that's any foreshadowing. [20:02.600 --> 20:10.920] They speak at 1 megabit per second, 2.4 to 2.5 gigahertz, 1 megahertz channel spacing, almost exactly the same as the hope badges, except the hope badges run at 2 megabits per second. [20:13.700 --> 20:19.180] To dump the firmware, all you have to do is run this cable out to the side to one of my handy-dandy good fit boards. [20:19.420 --> 20:22.200] And if you add USB to your badge, you can run it on that as well. [20:24.960 --> 20:31.380] Having dumped it, you send a little command, 03, the low byte of the address, the high byte of the address, and any dummy byte. [20:32.500 --> 20:37.120] The chip will reply with three bytes of Fs, and then the fourth byte will be the byte at that address. [20:37.120 --> 20:41.860] So this is the exact Python code that I wrote to dump the firmware. [20:42.440 --> 20:46.560] All it does is send the four bytes and read the fourth byte of the reply. [20:47.120 --> 20:48.500] These are the opcodes that are used. [20:48.740 --> 20:51.420] These are the only commands that the memory chip supports. [20:52.660 --> 20:55.180] Having dumped it, this is the firmware. [20:55.900 --> 21:05.460] It begins with some length fields out here, and then it has the MAC address in this region, and the seventh byte is actually the default channel on which it broadcasts. [21:05.460 --> 21:06.220] Sorry, the eighth byte. [21:08.680 --> 21:11.900] The 8051 code begins immediately after that. [21:14.300 --> 21:18.680] To dump the firmware, you do goodfet.spy25c, dump clicker.hex. [21:18.780 --> 21:20.220] This is the exact command that you run today. [21:20.980 --> 21:24.460] You copy all of the first few bytes into a binary file. [21:24.660 --> 21:30.360] You then load that into IDA Pro, and you open it at index zero. [21:31.380 --> 21:33.500] These are all of the functions properly named. [21:36.300 --> 21:41.100] The names themselves can't be recovered from symbol files as they would be within a PC application. [21:41.320 --> 21:44.580] So instead, you have to look for port names, which are documented. [21:47.580 --> 21:55.420] They're included in the data sheet, and you can very quickly import them into IDA Pro, because there's a maximum of about 100 of them, far fewer of which are actually used. [21:55.420 --> 21:59.060] The spy data exchange function, which is open-source. [21:59.280 --> 22:03.620] It's part of Nordic RF reference design that was copied by Turning Point in their clicker. [22:04.340 --> 22:06.100] This is legitimate copying, by the way. [22:06.240 --> 22:08.040] It's like a public domain thing for them to copy. [22:09.760 --> 22:13.760] All it does is move the input into the data register. [22:13.760 --> 22:28.900] So by searching for this exact line of assembly code, followed by a while loop that waits until the reply comes in, and then something that moves the result into an output variable, you can identify the spy transaction function. [22:29.020 --> 22:32.640] This is what's used to read and write memory. [22:32.840 --> 22:34.500] And sure enough, this is the assembly code here. [22:37.140 --> 22:48.000] Internally, an SPI port, even though there isn't an external one for talking to the radio, is used to communicate between the microcontroller inside of the chip and the radio inside of the chip. [22:48.140 --> 22:50.440] The two are right next to each other, but sharing a thin bus. [22:50.780 --> 22:58.060] So you can look using these registers and actually identify exactly where the radio code is. [22:59.120 --> 23:00.600] These are what the two functions look like. [23:00.600 --> 23:06.740] You're either setting the third bit of the radio register or clearing the first bit of port 0. [23:07.240 --> 23:09.440] And then you're reading and writing your bytes. [23:09.680 --> 23:12.940] And then you flip that bit back to end the transaction. [23:14.740 --> 23:16.700] This is the function that sets up the radio. [23:18.240 --> 23:22.420] If you look deeper in it, you see all of these move instructions followed by local calls. [23:22.560 --> 23:25.020] This is how functions are sent. [23:25.200 --> 23:28.660] So it's sending 8, 8, 0, 0, 0, bunches of 0s. [23:28.660 --> 23:31.580] And then the contents of memory at 1b, 1c, 1d. [23:32.020 --> 23:33.400] Then these magic constants. [23:33.560 --> 23:38.500] Then twice the value of 1a that's written incorrectly. [23:39.580 --> 23:46.300] You can then look up the format of this configuration string within the datasheet. [23:46.440 --> 23:53.140] You can figure out where the width is, where the address is, the address width, the check summing, the configuration, and the channel number. [23:54.440 --> 23:56.860] And you can start running through the code and identifying it. [23:57.840 --> 23:59.780] Because it's just a lot of reads and writes. [24:00.000 --> 24:06.460] So this tells us that the channel number, which is the frequency in megahertz above 2.4 gigahertz, is stored at 1a. [24:06.720 --> 24:08.560] You've got a MAC address in these bytes. [24:08.940 --> 24:11.260] You've got four bytes of data being sent. [24:11.420 --> 24:13.120] And then one byte of check sum. [24:14.700 --> 24:19.180] Reading a transaction, you'll soon figure out that these three bytes are the destination MAC address. [24:19.180 --> 24:21.620] And these three are the source MAC address. [24:22.320 --> 24:24.100] These are registered names, by the way. [24:24.240 --> 24:30.980] This chip has a lot of internal RAM, which is sort of like a register and sort of like RAM. [24:31.900 --> 24:35.160] In any case, each one of these is a unique identifier for a place in memory. [24:35.280 --> 24:36.800] It's not a literal constant. [24:37.860 --> 24:40.920] But you can search for these things to find the instructions that load them. [24:40.920 --> 24:47.300] And this tells us that every single packet is addressed to 12 hex, 34 hex, 56 hex. [24:48.240 --> 24:51.760] This number, the channel, and the data rate are all that you need to receive packets. [24:54.380 --> 24:58.940] These are packets being sniffed on a next hope badge. [25:00.020 --> 25:02.800] This final column is the number 5 being pressed. [25:03.160 --> 25:05.040] Here you have the serial number. [25:05.200 --> 25:09.240] If you do this in a classroom, you can actually get a histogram of quiz answers as they're being placed. [25:13.020 --> 25:14.720] And this is the hardware that I used. [25:14.900 --> 25:19.340] You can wire up your own badge, run two commands, and be sniffing the same traffic. [25:23.470 --> 25:28.450] So jumping ahead, I used similar but more powerful hardware. [25:28.630 --> 25:29.110] Oh, yes. [25:34.060 --> 25:37.800] What happens if the clicker sends two answers in rapid-fire succession? [25:38.080 --> 25:41.020] Such as if one were the legitimate answer and the other were a forgery. [25:41.540 --> 25:43.180] There are only two ways to do this. [25:43.340 --> 25:46.360] You can either accept the first value or the most recent value. [25:47.080 --> 25:52.320] Either way, you can sniff the MAC addresses from early in the class period and use it to beat them to the punch. [25:53.820 --> 25:57.780] Of course, the software should scream holy murder when it sees this, but it probably won't. [26:01.380 --> 26:05.320] Especially as the button might be hit multiple times to cause a legitimate rebroadcast. [26:07.340 --> 26:09.680] The radio chain is just copied from a reference design. [26:10.060 --> 26:17.580] So I don't really understand any of the analog parts of the radio except that if you place these components in these places, magic stuff happens. [26:17.840 --> 26:23.380] And it runs either the open beacon firmware, which is what all of you with blinking LEDs are running. [26:23.380 --> 26:26.920] Being tracked and all of the intended metadata stuff. [26:27.480 --> 26:31.780] Or it runs the GoodFET firmware, which allows you to sniff it. [26:31.980 --> 26:33.800] And this whole thing is built from a GNU toolchain. [26:34.040 --> 26:37.800] So GCC was used to build the firmware for all of these badges. [26:38.100 --> 26:39.740] They were also programmed by GoodFET. [26:39.820 --> 26:49.820] So actually on the assembly line, every single one of your badges was hooked up to a GoodFET, which flashed its firmware and also ran a radio test case, which is why only four units or so had bad radios. [26:51.580 --> 26:53.620] Out of 1,800, it's a decent yield. [26:54.620 --> 27:00.860] The GoodFET firmware exposes the radio by USB, so when you want to talk with it, you just write Python code. [27:01.280 --> 27:06.360] In the same way that to dump the EEPROM earlier in the lecture, I only had to write a little bit of Python code. [27:08.060 --> 27:11.300] Comparing the radio settings, here on the right, you've got open beacon. [27:11.500 --> 27:16.780] On the left, you've got the clicker thing. [27:16.780 --> 27:20.500] The checksumming is a little bit different, as are the MAC addresses and their lengths. [27:20.880 --> 27:22.620] But other than that, they're largely compatible. [27:23.640 --> 27:28.100] The Python client is a separate class from most of the other protocols. [27:29.860 --> 27:34.400] And it needs a little bit of C code to actually wait for an incoming packet to arrive. [27:34.660 --> 27:37.460] But other than that, it's entirely self-contained within Python. [27:37.740 --> 27:43.100] There are only two functions unique to the radio within the badge sniffing firmware. [27:44.660 --> 27:47.100] Within the radio, every single thing is a register. [27:49.440 --> 27:57.560] So, in order to, say, set the frequency, all I'm doing is taking the value that's given and I'm poking it into memory at the fifth register. [27:57.780 --> 28:00.980] Or, sorry, the sixth register, but five hex, within the radio. [28:01.160 --> 28:03.040] And then I start asking for packets. [28:05.000 --> 28:09.520] The client driver just needs to set up the radio in the right way. [28:09.520 --> 28:12.400] And after the radio has been set up, it's the same code to sniff packets. [28:12.660 --> 28:19.380] So, if you're sniffing open beacon traffic or you're sniffing turning point clicker traffic, the vast majority of the code is the same. [28:19.480 --> 28:21.480] Only the register set up is different. [28:22.520 --> 28:30.520] And thus, if you want to add support for something new, such as one of the SparkFun kits that uses this radio, it's just a matter of tweaking a couple of registers. [28:32.460 --> 28:38.340] This is the complete function body for dumping firmware and printing it... [28:38.340 --> 28:42.160] Oh, sorry, dumping radio packets and printing them properly and all of that fun stuff. [28:42.940 --> 28:47.380] And that's all you need to sniff traffic and clickers and that sort of stuff. [28:48.460 --> 28:55.040] You can use similar techniques to hack into other devices, such as toys, the smart grid, sports, equipment, medical equipment. [28:55.600 --> 28:56.860] This is one of my favorites. [28:57.240 --> 28:58.040] Does anyone have one of these? [28:58.380 --> 28:59.280] Raise your hands. [28:59.280 --> 29:00.480] Neighbor does here. [29:00.640 --> 29:00.720] Right. [29:01.180 --> 29:02.520] This is the Girl Tech I Am Me. [29:02.720 --> 29:07.440] It is an instant messaging toy for children, manufactured by Mattel under the Girl Tech brand. [29:08.220 --> 29:10.940] I think it had another brand associated with it, which I forgot at the moment. [29:11.460 --> 29:16.220] The gist is that you've got a keyboard and an LCD and 900 megahertz radio. [29:17.540 --> 29:28.860] You can then connect to a server, which is running on your home PC by radio and start instant messaging with your friends without being exposed to Internet pedophiles or, more importantly, hogging the home computer. [29:31.820 --> 29:39.200] Mattel has an issue with toys, and most toy manufacturers do, which is that there are occasionally extra production runs. [29:39.360 --> 29:44.260] You know, the factory will stay open at night, roll up a couple of extra units, which then get sold in the black market. [29:44.380 --> 29:53.080] And when Mattel goes to Toys R Us to sell their new I Am Me, Toys R Us is, oh, sorry, we already bought a bunch of them, even if it's their first sale. [29:55.040 --> 29:59.380] So, as these things roll out of their first factory, they haven't been fully programmed. [29:59.720 --> 30:03.220] Instead, they have these test points beneath the battery compartment. [30:03.360 --> 30:05.240] You'll see these in almost every cell phone. [30:05.780 --> 30:07.880] These also exist in the turning point clicker. [30:09.180 --> 30:15.040] You can wire these up using just little jumper wires, run them into a GoodFET. [30:16.080 --> 30:16.760] Here it is. [30:17.140 --> 30:18.620] And then you can reflash it to be anything. [30:21.300 --> 30:23.540] Michael Osmond made a spectrum analyzer out of it. [30:25.700 --> 30:27.380] A round of applause for him, if you don't mind. [30:34.890 --> 30:37.770] He couldn't be here, but see every talk he gives. [30:37.950 --> 30:38.410] They're very good. [30:40.390 --> 30:41.990] You can also dump more obscure stuff. [30:42.150 --> 30:45.310] This is a smart water meter from the city of Paris. [30:47.090 --> 30:48.150] You can do ant devices. [30:48.150 --> 30:59.410] This is a Garmin watch for joggers that will actually track the GPS coordinates of the jogger, as well as heart rate from this heart monitor here. [30:59.730 --> 31:05.590] And then after the jog, all of this data can be downloaded to a computer through the USB plug. [31:07.410 --> 31:10.650] This protocol is open at the higher layers. [31:10.970 --> 31:13.430] All of the application layer stuff, all of that is open. [31:13.430 --> 31:14.690] You can get it free of any NDA. [31:14.830 --> 31:15.810] There's tons of example code. [31:15.810 --> 31:18.910] The only thing proprietary here is the link layer. [31:19.970 --> 31:21.910] The file layer is easy enough to figure out. [31:22.530 --> 31:26.550] Like most everything, it's a Nordic RF chip running at one megabit per second. [31:26.910 --> 31:29.470] The only difficulty is in the MAC address that I mentioned. [31:30.010 --> 31:36.510] No one quite knows what the first packets are addressed to, because that's been left out of the documentation. [31:37.550 --> 31:40.090] By reverse engineering these devices, we can figure that out. [31:40.090 --> 31:46.610] And then because all of the higher layers are identified, it will then be possible to make a completely open ant stack. [31:48.230 --> 31:52.090] I think I'll be doing this tomorrow during the advanced badge hacking workshop. [31:52.550 --> 31:53.470] Just for fun. [31:54.230 --> 31:59.190] Also, vulnerability is run by chip rather than by application. [31:59.630 --> 32:09.050] So in the same way that you can find a vulnerability for an operating system within the PC world, you can also identify a chipwise exploit here. [32:09.190 --> 32:14.590] For example, every Ember 200 series radio lacks a security fuse. [32:14.770 --> 32:21.730] So you can plug right into it and say, please give me a copy of all of your memory and keys, and it will happily oblige you. [32:23.510 --> 32:31.330] All of the ChipCon 8051 devices, including the Girltech IMME, protect their RAM from a debugger, but they don't protect flash. [32:32.070 --> 32:45.590] So you can connect to a chip and erase it and then copy RAM out and have a copy of all of the radio configurations, including keys and channels, encodings, all of that other stuff. [32:47.790 --> 32:50.690] You also wind up with problems with bad random number generators. [32:51.890 --> 33:02.990] In RSA, which is used for asymmetric cryptography in the IT world, it's not such a big deal if your random number generator is bad, because nonces can be repeated... [33:02.990 --> 33:05.310] Oh, sorry, they can be guessable or known to an attacker. [33:05.490 --> 33:06.830] They just cannot be repeated. [33:08.910 --> 33:22.810] In elliptic curve MQV, which is the public key cryptography system used by the smart grid, if the nonce is predictable, the private static key can be removed, which is sufficient to impersonate a device in the network. [33:23.050 --> 33:27.510] And the sole purpose of this cryptography is to keep devices from being impersonated by others. [33:30.570 --> 33:37.210] Some of the third-generation Zigbee chips have this right, but every single second-generation Zigbee chip screws up the random number generator in one way or another. [33:37.950 --> 33:39.070] I'll get back to that in a minute. [33:41.390 --> 33:50.690] As for memory exposure, because the access controls exist for protecting code and not data, they're just trying to keep you from copying a product. [33:50.890 --> 33:54.370] They don't really care if you can figure out which radio channel it uses. [33:56.190 --> 33:57.630] Reprogramming is almost always allowed. [33:58.950 --> 34:02.210] Before you're allowed to reprogram the chip, it wants to make sure that it's erased. [34:03.190 --> 34:07.530] So an unprivileged user is allowed to erase the entire device and nothing else. [34:08.410 --> 34:10.270] But what you can also do is erase and then dump. [34:10.450 --> 34:23.170] If you want to get a copy of all of the memory of the Girl Tech IMME that's in RAM, that is every key, every global variable, all of the radio configuration registers, all of that stuff, you just run these two commands from your good vet. [34:23.170 --> 34:29.150] You do good vet dot chip con erase and then good vet dot chip con dump data file name from zero to the end. [34:29.530 --> 34:31.110] And you get this nice little image. [34:31.290 --> 34:34.330] You can look at it in the IO region. [34:34.510 --> 34:38.870] And sure enough, there is a complete copy of every key in use. [34:40.570 --> 34:50.030] You only get the presently tuned frequency, but you can sort of guess at what the center frequencies might be or at least catch some packets, if not all, should channel hopping be involved. [34:51.370 --> 35:00.750] You can do stack buffer overflow exploits just as you can on a PC, except that there are no stack control mechanisms except for accidental ones. [35:02.430 --> 35:11.330] Sometimes RAM isn't executable, but that's okay because your real goal is to get a copy of the software out of the chip when you're doing exploits against these. [35:11.670 --> 35:21.390] If you're talking to this badge and you're trying to do a stack overflow exploit on it, you would be doing so because you wanted a copy of the badge firmware, not because you were trying to remotely change what the LCDs do. [35:22.910 --> 35:27.970] So you can do a return to ROM attack in the same way that you can do a return to libc attack. [35:29.230 --> 35:39.850] And Rayan Francian, a researcher that I've worked with who used to be in Grenoble, but is now in Switzerland, he's implemented a complete return oriented programming attack framework for these chips. [35:39.850 --> 35:52.870] So you can actually give it a firmware image and have it search through and find all of the gadgets necessary to move RAM into flash memory to later be executed even though the chip does not allow the execution of RAM. [35:53.710 --> 35:54.890] It's quite a nice attack. [35:55.090 --> 35:56.210] You can also do bus usurping. [35:56.690 --> 36:06.570] You can connect a GoodFET to the SPI bus, you can then boot the target device, and then you can halt the microcontroller of the target device just by pulling its reset line to ground. [36:07.390 --> 36:11.470] Having done this, the microcontroller on the target stops executing. [36:11.650 --> 36:16.530] And it also lets off of the wires so that you, the attacker, now control the radio. [36:17.310 --> 36:19.550] And all of the RAM remains intact. [36:19.910 --> 36:21.870] All of the registers within the radio remain intact. [36:21.870 --> 36:23.950] So you can then just copy the configuration out. [36:25.210 --> 36:31.530] In the case of application processors, these are chips which implement a sockets library and expose it over an SPI port. [36:32.210 --> 36:35.070] The entire socket library remains open and accessible. [36:35.270 --> 36:40.650] So you can then continue sockets which had been opened by the previous device after hijacking all of its sections. [36:41.670 --> 36:51.630] In the case of Zigbee protocols and things like that which are quite complicated, this is very handy because it means that you don't have to understand all of the handshaking and all of the cartography and all of that stuff. [36:51.790 --> 36:52.870] It's already done for you. [36:53.230 --> 36:56.010] And you're just left with an open and already running interface. [36:59.250 --> 37:01.050] Do these look random to anyone here? [37:03.050 --> 37:07.430] This is a snowflake pattern which is generated by a linear feedback shift register. [37:08.690 --> 37:12.430] This is one of the worst random numbers generators I've seen. [37:12.710 --> 37:20.120] The entire state of this is determined by a 16-bit register that's fed by real random hardware data. [37:22.080 --> 37:28.240] That's then shuffled around repeatedly to produce the same sequence of 65,000 samples. [37:29.100 --> 37:38.220] So if you plot the first byte that you get along with the second byte that you get in order continuously, you wind up with a snowflake pattern. [37:38.760 --> 37:45.400] And given any byte within the x-axis, you know that only a colliding position on the y-axis can be the following byte. [37:46.300 --> 37:53.360] Because there are only 65,000 different positions, there are only 65,000 sequences of random numbers that can come from any starting point. [37:53.540 --> 37:59.000] Which means that there are only 65,000 ephemeral keys that can be used when this device is implementing elliptic curve cryptography. [37:59.600 --> 38:05.040] Which means that your lookup table for every key that might possibly be generated is 25 megabytes. [38:07.540 --> 38:09.520] Which makes searching trivial. [38:10.100 --> 38:17.440] There's also a great paper that came out years ago which says that if you know four bits of the ephemeral key, you can recover the rest. [38:17.600 --> 38:18.400] Here you know all of them. [38:18.680 --> 38:20.980] And you can also recover the private static key. [38:22.480 --> 38:28.860] As far as tools go, I used the GoodFET for everything and the next hope conference badge for all of the radio work. [38:29.040 --> 38:31.300] I used the total phase beagle for SPI sniffing. [38:32.540 --> 38:35.860] I've got a couple of boring conclusions here. [38:36.220 --> 38:40.980] But if you prefer, I'd like to show you something nifty that I hope some of you can one up. [38:43.480 --> 38:48.000] The badges have a test firmware image which you can find in the source code that actually receives packets. [38:49.760 --> 38:53.640] So I took this Rosie the robot that my mother made out of stained glass. [38:53.980 --> 38:54.900] Cheers to my mother. [39:02.680 --> 39:03.920] If I don't break this. [39:07.970 --> 39:10.750] Every time its eyes are blinking, it's receiving a packet. [39:14.130 --> 39:16.130] See, if I can cover this up. [39:17.490 --> 39:17.970] Yeah. [39:18.270 --> 39:18.330] Okay. [39:18.390 --> 39:19.030] So no traffic. [39:19.310 --> 39:19.690] Traffic. [39:20.610 --> 39:23.650] Your hands will block the radio signals, by the way, if you try. [39:23.910 --> 39:24.730] Like an iPhone. [39:25.110 --> 39:25.370] Yeah. [39:25.630 --> 39:25.790] Yeah. [39:25.930 --> 39:26.630] Just like an iPhone. [39:33.570 --> 39:34.910] Ain't nothing like it once was. [39:35.990 --> 39:36.230] Yes. [39:37.370 --> 39:39.270] So that's about it for this lecture. [39:39.710 --> 39:40.970] Are there any questions quickly? [39:41.250 --> 39:42.630] I've only got eight minutes left. [39:43.970 --> 39:46.350] Just come up to the microphone and say your piece. [39:53.880 --> 39:54.280] Hello? [39:54.900 --> 40:00.560] I had a brief question about shorting out these two to make the blue light stay on. [40:01.260 --> 40:04.780] Does that interfere with the operation of the anything? [40:05.120 --> 40:05.980] You're shorting out which two? [40:06.060 --> 40:06.580] The ones on the bottom? [40:06.800 --> 40:07.220] Up here. [40:07.940 --> 40:08.580] Up at the top. [40:08.840 --> 40:11.000] The vertical line that goes up and down. [40:12.940 --> 40:13.980] Oh, that's bad. [40:14.360 --> 40:14.920] That's bad. [40:15.900 --> 40:17.080] I'm doing the bad thing then. [40:17.360 --> 40:17.500] Yes. [40:17.500 --> 40:22.080] So the vertical column is actually the serial port between the microcontroller and the radio. [40:22.380 --> 40:30.160] If you tie those together, the radio will enter an error mode in which all of the lights stay on to tell you that the radio is bad. [40:31.740 --> 40:32.460] That's how it goes. [40:32.580 --> 40:40.580] If you would like to keep the blue light on, you can tie one of the pins in the horizontal line at the bottom to ground. [40:40.580 --> 40:43.940] And that will keep any of the lights of your choice on. [40:45.020 --> 40:46.200] Are there any further questions? [40:47.300 --> 40:47.780] Yes. [40:48.280 --> 40:48.760] Yes. [40:48.760 --> 40:48.860] Yes. [40:50.020 --> 40:55.360] This is going to be a slightly targeted and rather a following question. [40:55.500 --> 41:02.880] But how hard is it to permanently damage the badge, say, if you had a bad soldering job or randomly started to wire things together? [41:04.260 --> 41:09.380] If you mis-sodder wires together, the chip can't actually supply enough current from the battery to cause damage. [41:09.700 --> 41:13.160] And with USB, it's possible but rather difficult to cause damage. [41:13.380 --> 41:19.280] If you take your soldering iron and you use it as a chisel, I guarantee that bad things will happen. [41:20.460 --> 41:23.580] But you shouldn't worry about permanent electrical damage. [41:23.760 --> 41:30.480] This is very well secured against static electricity and voltages in the 3 to 5 range. [41:31.540 --> 41:32.480] Any further questions? [41:37.020 --> 41:41.540] How about using two badges as wireless radios to link two laptops together? [41:41.660 --> 41:42.120] Could you do that? [41:42.420 --> 41:43.100] Yeah, certainly. [41:43.800 --> 41:49.300] There wasn't time to finish the code in advance of this conference. [41:49.300 --> 41:58.140] But I was thinking about making a chat room that ran through the badges by USB, where every message that you sent was then relayed by the participants which hadn't seen it to allow for mesh networking between them. [41:58.140 --> 42:03.760] And in this manner, you can have laptops throughout the entire badge area communicating. [42:04.080 --> 42:14.100] And because all of the packets are sniffed by the badge aggregator network, this could then be fed into a chat log for later monitoring. [42:17.280 --> 42:18.340] We're watching you. [42:18.500 --> 42:20.060] Or at least the OpenBeacon team is. [42:22.480 --> 42:27.540] How much does the CPU and other chips on this board cost? [42:27.800 --> 42:31.460] I'm interested because, I mean, I've done PIC programming, and those CPUs are very, very cheap. [42:31.580 --> 42:32.720] How do these compare to those? [42:33.840 --> 42:39.160] The microcontroller in use in this project is rather expensive, on the order of $8 to $10 per chip. [42:39.780 --> 42:43.900] Thankfully, we didn't have to pay any of that because Texas Instruments found it within their kind heart to help us. [42:45.040 --> 42:46.500] Yes, another round for that one. [42:51.370 --> 42:55.810] The radio chip, I believe, is just over $2 in bulk, maybe $2.25. [42:56.210 --> 43:00.810] And the other components are quite small and cheap. [43:01.070 --> 43:05.070] The assembly cost actually accounts for the majority of the cost of production. [43:06.890 --> 43:07.590] All right. [43:08.750 --> 43:09.790] Any further questions? [43:11.550 --> 43:12.110] Yes. [43:12.110 --> 43:14.250] Will you be available tomorrow? [43:14.890 --> 43:19.110] I know you're going to do a workshop, but you said there are people signed up? [43:19.990 --> 43:20.350] Yes. [43:20.490 --> 43:21.770] So the workshop is full. [43:21.990 --> 43:26.550] If you come to me with a cool badge hacking project by noon tomorrow, I'll push you in. [43:27.750 --> 43:30.670] Otherwise, there physically is no room for more. [43:30.870 --> 43:31.810] I apologize for that. [43:32.950 --> 43:34.470] But that's the way that it goes. [43:34.710 --> 43:38.130] If you've received an email from me telling me that you're in the group, then you are. [43:38.130 --> 43:41.570] Otherwise, I don't know. [43:41.730 --> 43:45.370] Either bring an impressive badge hacking project or find some blackmail on me. [43:47.230 --> 43:49.930] Neither should be terribly difficult, but neither is trivial either. [43:50.090 --> 43:50.450] I like beer. [43:50.750 --> 43:51.770] I like beer. [43:51.870 --> 43:52.870] If you could bring me IPA. [43:54.150 --> 43:55.130] India Pale Ale. [43:55.350 --> 43:56.250] I love America. [43:56.550 --> 43:58.390] We should get as much of that as we can. [43:59.530 --> 44:04.150] You briefly showed a French water smart grid application. [44:05.330 --> 44:08.750] I'm a little concerned about the smart grid infrastructure here in the U.S. [44:09.350 --> 44:12.950] Have you seen wide adoption in this country? [44:12.950 --> 44:15.270] If so, what general region of the U.S. [44:15.430 --> 44:18.070] is more advanced than others in implementing smart grid? [44:19.010 --> 44:21.070] So there are a lot of test networks. [44:22.470 --> 44:27.450] There was a point in time at which it looked as if the smart grid was going to be rolled out overnight. [44:27.450 --> 44:29.950] And poorly at that. [44:30.230 --> 44:33.790] But now there's significant effort being made into doing a proper rollout. [44:34.710 --> 44:42.410] So I'm a lot more optimistic about the success and security of the smart grid than I was a year ago. [44:43.910 --> 44:50.310] Do you know if anyone's gotten this radio working with Atmel or PIC based processors? [44:50.310 --> 44:51.050] Yes. [44:51.230 --> 44:55.270] So the original open beacon badge used a PIC microcontroller. [44:55.830 --> 44:59.610] And some of the competing clicker brands use an Atmel microcontroller. [44:59.890 --> 45:06.090] I also have a device from SparkFun that uses an Atmel microcontroller inside of a key fob. [45:06.450 --> 45:08.770] I'll very soon be adding support to the good vet for that. [45:08.950 --> 45:15.110] So you'll be able to sniff your key fob to your computer to add remote control items or anything else you might choose to script. [45:17.010 --> 45:22.390] And if anyone is fond of stained glass and would like to purchase Rosie the robot, please come and contact me. [45:23.210 --> 45:25.350] I think that's all the time that I have. [45:25.630 --> 45:26.810] I just want to know more about you. [45:34.620 --> 45:36.380] Oh, one quick further announcement. [45:36.840 --> 45:38.720] Cryptography has been turned off for this conference. [45:38.720 --> 45:40.660] So you can have all sorts of fun with the badge network. [45:40.920 --> 45:45.040] And when you reflash them, be sure to add a serial number and figure out how that works. [45:45.720 --> 45:46.300] Thank you. [45:53.330 --> 45:54.170] Yes, sure.