home > posts
  • November 21, 2024
    HD Moore
    @hdm

    #infosec  #hackers  #atx 

    Hello Austin hackers! Tonight is the November AHA meetup (shifted back a week to avoid holiday overlap). Same place and time as usual (Mister Tramps, talks start at 7:00pm). Haven't been to an AHA before? Check out the meeting info (and bring a ~5-10m lightning talk): https://takeonme.org/ #infosec #hackers #atx

    ↪ reply
  • November 16, 2024
    HD Moore
    @hdm

    Good morning RowdyCon! I'm excited to share some serious NumberWang[1] with the San Antonio hacker crowd. RowdyCon is open to ALL students in a degree programs based in San Antonio (online or in-person). Registration is available at https://www.rowdycon.org/

    1. https://www.youtube.com/watch?v=0obMRztklqU

    ↪ reply
  • November 14, 2024
    HD Moore
    @hdm

    #golang  #atx 

    Austin Go(phers): it's that time again! Tonight is the November ATX Golang Meetup. Charles Southerland and I will both be speaking. Swing by for pizza, beer, and general nerdiness around Go. Tonight's meetup is at 7:00pm at the Capital Factory on floor 16 (in the "ACL" room):

    https://www.meetup.com/atxgolang/events/301842149/

    #golang #atx

    ↪ reply
  • November 12, 2024
    HD Moore
    @hdm

    Secure your IoT devices by (accidentally) encasing them in concrete. Fortunately this is a POE doorbell and doesn't require battery changes. It does prevent someone from easily getting to the reset button under the bottom lip; does this count as embedded security?

    ↪ reply
  • November 12, 2024
    HD Moore
    @hdm

    If the NSA[1], GrapheneOS[2], and Apple[3] all believe that rebooting your mobile phone regularly is something that protects your data, you might consider doing it more often. Shortcuts on iOS make this super easy to setup.

    1. https://www.documentcloud.org/documents/21018353-nsa-mobile-device-best-practices&xcust=2-1-2330195-1-0-0

    2. https://grapheneos.social/@GrapheneOS/112204443465440601

    3. https://www.404media.co/apple-quietly-introduced-iphone-reboot-code-which-is-locking-out-cops/

    ↪ reply
  • November 5, 2024
    HD Moore
    @hdm

    Orson Peters' recent post "Breaking CityHash64, MurmurHash2/3, wyhash, and more..." is a fantastic dive into hash collisions in common algorithms: https://orlp.net/blog/breaking-hash-functions/

    PS. Want to confuse various network security scanners? MurmurHash3 collide your /favicon.ico file with something arcane. See previous work by Jorian Woltjer at https://jorianwoltjer.com/blog/p/coding/shodan-favicon-preimage

    ↪ reply
  • October 31, 2024
    HD Moore
    @hdm

    I learned at least four neat things in this post on "Looking into the Nintendo Alarmo": https://garyodernichts.blogspot.com/2024/10/looking-into-nintendo-alarmo.html

    1. mmWave sensors are actually shipping in consumer products (not just nerdy things*)

    2. "OCTOSPI" region maps to external RAM and includes most of the firmware

    3. You can hijack the CRYP interface with enough keystream to decrypt more stuff

    4. The CRYP interface places partial keys in 4 x registers and you can brute force the 4×2^32 to recover the original key

    * I spent far too long on a Go serial library for Seeed Studio mmWave sensors but gave up after the cross-room heartbeat/respiration detection required too long to lock the signal (and the logic is in the fw, so no raw data to work with to improve it)

    ↪ reply
  • October 31, 2024
    HD Moore
    @hdm

    Pretty cool to see GPUs with RISC-V co-processors, erm, main CPUs (the size/cost disparity always gets me -- the entire PC feels like an add-on card to GPUs these days): https://www.tomshardware.com/pc-components/cpus/risc-v-cpu-demoed-with-rx-7900-xtx-gpu-in-debian-linux-amd-flagship-gpu-paired-with-milk-v-megrez-board-and-sifive-p550-cores

    ↪ reply
  • October 29, 2024
    HD Moore
    @hdm

    It's not 20 minutes, but Orbital's "The Box - Full Version" YT has been my pomodoro timer for over a decade (two if you count the original CDs); queuing it up is my sure-fire way to focus for 30 minutes: https://www.youtube.com/watch?v=cONv26K0vL8

    ↪ reply
  • October 27, 2024
    HD Moore
    @hdm

    Matthew Bryant's (@mandatory) @defcon 32 talk is amazing: Secret Life of Rogue Device: Lost IT Assets on the Public Marketplace: https://www.youtube.com/watch?v=QgeEHdAmJDg

    Way more entertaining than anything currently on Netflix.

    (thank you @jduck for the link!)

    ↪ reply
  • << View newer posts View older posts >>

Copyright 1998-2025 HD Moore