[00:33.860 --> 00:35.800] Is everyone ready to start? [00:51.660 --> 00:52.980] Nice and warm. [00:53.720 --> 00:57.960] I feel like such a pimp. [00:59.600 --> 01:00.880] I smacked my hose. [01:01.460 --> 01:02.000] Hold on. [01:02.480 --> 01:02.960] Alright. [01:03.240 --> 01:04.360] Hey, can you guys hear me in the back? [01:07.730 --> 01:09.150] Is that a yes or a no? [01:10.630 --> 01:11.110] No. [01:12.590 --> 01:14.470] Can you guys hear me in the back now? [01:15.450 --> 01:15.930] No. [01:16.390 --> 01:16.870] Okay. [01:18.690 --> 01:19.170] Alright. [01:20.270 --> 01:24.310] You're here at the hardware and electronics Q&A panel. [01:24.690 --> 01:25.830] My name is Kingpin. [01:26.070 --> 01:27.110] This is Javaman. [01:28.270 --> 01:30.930] Brian Oblivion is supposed to be here. [01:31.030 --> 01:31.870] I'm sure he'll show up late. [01:35.030 --> 01:38.130] So, if you're at the wrong panel, you can't leave now because we're watching you. [01:39.450 --> 01:44.490] This is actually going to be a hard act to follow after CDC, but it's probably going to be a little more boring. [01:46.670 --> 01:53.350] But basically, what this is, is a round table discussion about hardware and electronics issues. [01:53.550 --> 01:53.790] Anything. [01:54.090 --> 01:54.830] Any questions. [01:55.010 --> 01:55.870] No questions are stupid. [01:56.130 --> 02:03.430] If you have like a flea market something, something you found in the trash, you don't know what it is, hopefully you brought it and we can discuss it and check it out. [02:05.210 --> 02:07.650] The questions don't need to be targeted to one of us. [02:07.930 --> 02:12.910] If you just want to ask a general question, go ahead and I'm sure there's someone else in the room that's going to be able to answer it. [02:13.950 --> 02:18.270] Obviously, we don't know everything and it's just a good way for everybody to get some discussions in. [02:19.150 --> 02:26.550] So, before we open this up to questions, what we're going to do is just run through who we are, where we come from, and some of the current projects we're working on. [02:27.150 --> 02:28.910] So, as I said before, I'm Kingpin. [02:29.010 --> 02:29.830] I come from Boston. [02:31.150 --> 02:36.910] Member of L0pht Heavy Industries, which is currently the AtStake research and development labs. [02:37.130 --> 02:38.990] So, I get to research things all day long. [02:41.130 --> 02:44.790] What I enjoy doing the most is reverse engineering hardware products. [02:47.150 --> 02:48.710] Mostly hardware security products. [02:48.870 --> 02:52.650] Any products really, but hardware security products currently are the best things to look at. [02:53.210 --> 02:54.510] There's a lot of problems with them. [02:54.610 --> 03:01.190] It's kind of a new field, so there's a lot of problems with the developers, and they're not really sure how to implement security in their products. [03:02.230 --> 03:07.570] I'm also into portable electronics and microprocessor system design, so basic embedded system type of stuff. [03:09.910 --> 03:18.750] Something I announced back in 1997 at Beyond HOPE, God, three years ago, was I was doing a lot of Palm Pilot development. [03:19.390 --> 03:27.530] Since then, the whole PDA field has caught on a lot, so it's really blown up, and I'm sure half the people in here at least have Palm Pilots. [03:28.110 --> 03:30.810] I announced a war dialer that I was working on back then. [03:31.130 --> 03:32.170] It didn't have a name. [03:33.270 --> 03:34.390] I just finished it. [03:34.530 --> 03:35.330] It's called TBA. [03:36.010 --> 03:37.930] It has a bunch of different meanings. [03:38.090 --> 03:39.470] You can think of one that you want. [03:40.530 --> 03:44.130] What it is, is basically a war dialer, a portable war dialer. [03:45.550 --> 03:46.670] Throw it up in a ceiling. [03:46.670 --> 03:51.530] If you want to do a war dial from somewhere you're not supposed to be, throw it in a phone can. [03:51.870 --> 03:56.990] Palm Pilots are so cheap now, you pay 25 or 50 bucks for one, put the war dialer in a phone can, walk away. [03:57.270 --> 03:58.470] If it gets stolen, who cares? [03:58.590 --> 04:01.330] If not, you come back in a week and you have your prefix scanned or whatever. [04:01.550 --> 04:02.730] So, it's kind of cool. [04:03.870 --> 04:08.170] You can either grab it from the L0pht website or come up here afterwards and I can beam it to you. [04:08.710 --> 04:11.210] There's a few other applications that I'll beam to you as well. [04:11.370 --> 04:13.870] If you have a color palm, definitely come see me. [04:14.050 --> 04:16.790] I'm not going to talk about what I have, but it's a brand new program. [04:17.110 --> 04:18.470] It only works on color palms. [04:18.970 --> 04:20.130] It's called Blue Balls. [04:20.850 --> 04:22.310] So, I'll leave it at that. [04:24.270 --> 04:26.230] So, some of my current research projects. [04:26.990 --> 04:32.910] Some of you may have seen an advisory that I recently released on the Aladdin e-token, which is a USB hardware token. [04:33.490 --> 04:37.190] I have one in my pocket, but they're kind of small. [04:37.770 --> 04:38.970] You want to display it? [04:39.170 --> 04:39.730] There we go. [04:40.430 --> 04:43.450] It's a tiny, tiny little embedded system. [04:43.890 --> 04:45.630] Connects to the USB port of a PC. [04:45.630 --> 04:48.830] And what it does, basically, it's meant for authentication. [04:48.830 --> 04:53.070] It stores private data, credentials, anything you want, really. [04:53.170 --> 04:54.230] X-509 certificates. [04:55.690 --> 04:58.970] And it's supposed to be this private thing that proves you are who you are. [04:59.250 --> 05:02.370] So, having this thing, it's two-factor authentication. [05:02.890 --> 05:09.670] Having this thing, a physical device, and knowing the pin number which protects the data, that's supposed to prove who you are. [05:09.810 --> 05:12.530] Unfortunately, it's not exactly that simple. [05:14.590 --> 05:16.750] There was a problem with the Aladdin e-token. [05:18.610 --> 05:19.010] The... [05:19.370 --> 05:23.430] Let's see, actually, before I say that, these things are simple embedded systems. [05:23.770 --> 05:29.650] The components on the board are a piece of cake to probe and kind of experiment with, which made it such an easy target. [05:29.910 --> 05:39.090] There's not really any kind of tamper evidence or tamper resistance on these things, so you can open the thing up real easily, clip onto the chips, and do all sorts of experimentation with it. [05:41.950 --> 05:45.650] So, for the e-token, all the data is protected by one pin number. [05:46.170 --> 05:47.470] It's an 8-byte value. [05:48.850 --> 05:52.530] What these guys did, though, is they left a default pin. [05:53.230 --> 05:56.330] So, a default login string, basically. [05:56.490 --> 05:59.970] They left that programmed into the external memory device of every single device. [05:59.970 --> 06:16.670] So, regardless of what the user sets the pin number to, all you have to do is open the device, read the external memory, move that one default string from its known address, which is always fixed, into the user pin area, and you can log right in with the default password, [06:16.770 --> 06:23.810] grab all the private information out of it, get everything out of it that the legitimate user had in there. [06:23.810 --> 06:25.390] So, that's a big problem. [06:25.810 --> 06:37.050] And look for another advisory coming out in about a week on a similar product, actually a competitor's product, that's also a USB hardware token, and they did the same thing. [06:37.250 --> 06:43.530] So, getting into the hardware side of security products, there's a lot of things, and there's a lot of problems that can be exploited. [06:45.330 --> 06:50.970] But we can also help the vendors by fixing their products and have products that we can actually use and feel good about using. [06:51.870 --> 06:56.530] So, kind of, all this thing was, was a Cypress CY7C63000. [06:57.730 --> 07:02.590] What that is, is just a general purpose microprocessor, which had USB support on board. [07:04.390 --> 07:14.310] There's not that many processors right now that have USB support, so it's kind of easy to target that particular processor and get any kind of information I needed on it in development kits and stuff like that. [07:14.990 --> 07:17.990] And then it used an Atmel serial EEPROM as the external memory. [07:18.150 --> 07:21.630] So, that's, as some people know, it's extremely easy to read those things. [07:21.630 --> 07:23.710] There's no protection of any sort. [07:24.450 --> 07:27.210] And these guys didn't encrypt any of their data on there. [07:27.230 --> 07:30.910] So, I could easily just change that pin and then access all the data. [07:31.010 --> 07:32.010] So, that's what I'm working on now. [07:33.430 --> 07:36.330] There's a technical white paper that I'm putting out pretty soon. [07:36.330 --> 07:40.710] It describes all of the attacks that we tried on these keys and some worked, some didn't. [07:41.190 --> 07:45.270] Both from a hardware, electrical point of view and also mechanical attacks and software attacks. [07:45.470 --> 07:47.070] So, keep your eyes open for that. [07:49.070 --> 07:50.250] And, that's it for me. [07:50.510 --> 07:51.930] So, Javaman, take it away. [07:53.190 --> 07:53.890] Yo, yo, yo. [07:55.250 --> 07:55.670] Word. [07:59.430 --> 08:06.510] According to these lies that were printed about me, I'm a Philadelphia-based hacker with a background RF engineer, which is pretty much true. [08:07.630 --> 08:12.130] My main area of expertise has traditionally been RF hardware design. [08:13.570 --> 08:14.530] And, drinking. [08:14.990 --> 08:21.250] Which, if anyone was at the bar last night, I apologize for anything I have said. [08:23.770 --> 08:26.170] I know that I was carried back to a room. [08:26.170 --> 08:27.950] But, I apologize to the people in the room, too. [08:27.970 --> 08:29.930] Yes, I apologize to the people in the room, too. [08:30.330 --> 08:31.930] I, uh... [08:31.930 --> 08:32.750] But, anyway. [08:33.310 --> 08:34.710] I woke up today, thankfully. [08:35.270 --> 08:38.830] And, my main area of expertise has been, traditionally, RF hardware. [08:39.830 --> 08:45.450] And, specifically, gigahertz band and SHF hardware design. [08:46.310 --> 08:47.270] Particularly, amplifiers. [08:48.070 --> 08:53.590] Along with the actual particulars of spread spectrum systems and things along those lines. [08:54.370 --> 08:57.670] I've moved more into, now, digital logic design. [08:57.850 --> 09:00.630] I'm working on a team to design a very fast, very cheap super computer. [09:01.590 --> 09:04.350] I can't give you any details on it, because it's owned by the government. [09:04.870 --> 09:09.090] And, so, when we release it, it will also be sold to the general public, as well. [09:09.930 --> 09:13.590] My main area of interest has been, like I said, traditionally RF communication systems. [09:16.650 --> 09:18.690] And, amateur radio type facets, as well. [09:19.190 --> 09:22.030] Along with digital logic design and digital hardware design. [09:23.570 --> 09:24.690] That's about... [09:24.690 --> 09:26.310] Like I said, if... [09:26.310 --> 09:28.930] We each have topics that we get asked further about. [09:29.570 --> 09:30.690] Kingpin with his USB. [09:30.930 --> 09:31.910] And, myself, if you could ask me... [09:31.910 --> 09:38.310] I've written up a couple of little things about why spread spectrum is a little bit more inherently secure than any other communication media. [09:39.210 --> 09:40.870] Along with what it means. [09:42.790 --> 09:51.010] And, some issues regarding why we don't really have very high data rate DSLs until recently. [09:51.010 --> 09:53.130] What DSL actually does. [09:53.310 --> 09:54.890] Why its implementation is going to be difficult. [09:55.090 --> 09:57.090] And, why we also don't have very high data rate radio. [09:58.090 --> 09:59.850] To everyone in a mobile situation. [10:00.030 --> 10:03.010] Or, have a very underground digital network. [10:04.030 --> 10:06.130] Which is what guerilla.net is starting to set up. [10:06.230 --> 10:07.390] And, we're working very hard to. [10:07.470 --> 10:09.130] And, what are some of the issues we're running into with that. [10:10.590 --> 10:11.230] So... [10:11.230 --> 10:12.130] I guess... [10:13.370 --> 10:15.090] Is Brian Oblivion here? [10:16.610 --> 10:17.250] Brian? [10:17.910 --> 10:18.550] Hello? [10:19.310 --> 10:19.630] Alright. [10:19.850 --> 10:21.330] I guess we'll take questions. [10:23.270 --> 10:23.910] So... [10:23.910 --> 10:24.410] Yeah. [10:25.710 --> 10:26.350] Definitely... [10:26.350 --> 10:28.450] Do we have a microphone in here for people to ask questions? [10:28.810 --> 10:29.330] Yeah. [10:30.110 --> 10:30.750] Yeah? [10:30.970 --> 10:31.110] Okay. [10:31.290 --> 10:32.030] Hobbit has one. [10:32.470 --> 10:34.010] The guy with the tie-dye. [10:36.070 --> 10:37.670] The other hippie with the tie-dye. [10:38.750 --> 10:39.110] The other guy with the tie-dye. [10:39.190 --> 10:39.550] The other guy with the tie-dye. [10:39.730 --> 10:41.190] If you have any actual... [10:41.190 --> 10:46.070] Actually, I saw somebody in an elevator this morning that had some telephone equipment that we're going to bring here. [10:47.490 --> 10:47.850] Yeah. [10:48.050 --> 10:48.490] Stand up. [10:48.630 --> 10:49.010] Bring it up. [10:49.150 --> 10:51.790] If you guys have stuff, you can either stand in line or raise your hand or whatever. [10:52.090 --> 10:53.050] It's really informal. [10:53.730 --> 10:54.090] So... [10:54.090 --> 10:54.730] I don't know. [10:54.890 --> 10:56.010] I mean, you don't have to just sit there. [10:56.250 --> 10:57.370] You can dance or something. [10:59.790 --> 11:00.590] This one works. [11:00.930 --> 11:01.390] This one? [11:01.490 --> 11:01.750] Okay. [11:02.950 --> 11:09.450] Do we have another camera that we can, like, zoom in on the stuff and put it up on the non-existent projector screen here? [11:10.670 --> 11:13.350] That way, everybody in the room can see it if it's small. [11:14.310 --> 11:14.690] No? [11:14.830 --> 11:15.810] Are we not prepared for that? [11:16.030 --> 11:16.230] Okay. [11:24.250 --> 11:26.970] So this is a silver box. [11:27.210 --> 11:30.870] We can pass this around, too, and we're done, because it's kind of weird-looking. [11:31.910 --> 11:33.510] There's an engine connector at the end. [11:33.910 --> 11:38.290] They usually use for vacuum tube sockets, but usually it's more for power signal, for power lines. [11:39.250 --> 11:39.650] So... [11:40.290 --> 11:40.970] Oh, that's water. [11:41.430 --> 11:42.750] Oh, that would suck. [11:43.170 --> 11:43.390] Yeah. [11:43.770 --> 11:43.910] All right. [11:44.770 --> 11:45.650] I don't know if you can see it. [11:45.750 --> 11:50.310] There is a socket for what would probably be power supplies, and there's actually a little notch here. [11:50.490 --> 11:51.210] It's a circular socket. [11:51.330 --> 11:51.910] There's a little notch. [11:51.990 --> 11:53.730] You can only put it in the power supplies one way. [11:54.150 --> 12:03.670] Along with a, with a DB15 connector, the same kind of connector that you have for your joystick or your MIDI, and that's for signaling. [12:03.890 --> 12:13.270] Along with a DB25 right here, which, my guess would be, that's where it probably is where it would be programmed. [12:13.390 --> 12:14.310] This is probably system interface. [12:14.510 --> 12:15.430] This is probably program interface. [12:16.050 --> 12:17.170] That's my best guess. [12:17.350 --> 12:17.510] Yeah. [12:17.770 --> 12:21.630] What it looks like from the top, this is made by TSG, who I've never heard of. [12:21.870 --> 12:23.230] It's a technical service group. [12:23.830 --> 12:24.630] Well, I don't know. [12:24.650 --> 12:24.890] Oh. [12:25.650 --> 12:27.090] It's technical service group. [12:27.090 --> 12:29.310] This thing's called the Gemini System 2. [12:29.510 --> 12:32.170] And what it looks like, there's a bunch of configuration stuff on the front. [12:33.190 --> 12:36.930] Initial rate for pay station, 5 cents, 10 cents, 20 cents, 40 cents. [12:37.270 --> 12:40.970] Polarity of coin relay, coin mechanism type, line type, future enhancements. [12:41.130 --> 12:50.050] It looks like it's a device that's actually in the payphone that either, I don't know the real name of it, but it will take the money in basically. [12:52.810 --> 12:53.770] Anybody know? [12:54.010 --> 12:59.670] One thing that's very interesting about it is that there's a copyright in 1995 on the circuit board, the circuit pack itself. [13:00.070 --> 13:02.190] But the construction techniques are actually very old. [13:03.330 --> 13:11.190] We have for about, probably about the past, at least five years and probably 10 of things that we've done service men technology. [13:11.490 --> 13:13.950] All these devices on here are all through home components. [13:14.230 --> 13:16.610] There's no service men components on the board. [13:17.770 --> 13:22.610] So, my best guess is this board is probably designed about maybe... [13:23.290 --> 13:24.030] Where's the camera? [13:26.030 --> 13:26.550] Oh. [13:27.190 --> 13:27.710] Cool. [13:29.670 --> 13:30.430] That way. [13:32.550 --> 13:33.430] There we go. [13:34.410 --> 13:35.490] Oh, look at this. [13:35.910 --> 13:37.170] Brand oblivion has shown up. [13:37.350 --> 13:37.650] Yay! [13:37.870 --> 13:38.450] You want to come up? [13:40.990 --> 13:42.230] It started on time. [13:42.510 --> 13:43.210] Alright, here we go. [13:43.210 --> 13:44.010] Five-thirty? [13:44.850 --> 13:47.090] Um, and this board... [13:47.090 --> 13:47.570] Hour and a half. [13:47.810 --> 13:50.010] It looks like it's using older design techniques. [13:50.250 --> 13:50.970] No, it said hour and a half. [13:50.990 --> 13:51.150] Yeah. [13:51.390 --> 13:51.610] Yeah. [13:51.710 --> 13:52.250] Good picture of that. [13:52.370 --> 13:53.190] I don't know if anyone can see it. [13:53.830 --> 13:58.490] Um, and there is one empty socket and one socket that has a label on it. [13:58.610 --> 14:01.370] Usually whenever someone puts a label on it, then, uh... [14:01.370 --> 14:01.870] What are you looking at? [14:02.070 --> 14:05.710] It's probably an EEPROM because there might be a little window underneath. [14:07.370 --> 14:07.730] Um... [14:07.730 --> 14:08.330] Oh, yeah, yeah, yeah. [14:08.450 --> 14:09.370] I'm going to pass it over with Ryan. [14:09.490 --> 14:10.210] We'll see what he has to say. [14:10.670 --> 14:10.950] Oh. [14:19.470 --> 14:21.090] It looks like a tube. [14:21.370 --> 14:22.010] It's actually... [14:22.010 --> 14:22.690] It could be... [14:22.690 --> 14:23.630] It could be custom power. [14:24.570 --> 14:25.290] Uh, sure. [14:26.390 --> 14:31.830] I don't know. [14:34.590 --> 14:37.870] Alright, let's get the next piece of equipment as well up here. [14:45.310 --> 14:45.870] 16HC11. [14:46.390 --> 14:47.670] I recognize these come out of. [14:47.990 --> 14:48.270] Yeah. [14:48.970 --> 14:50.190] And this is probably itself. [14:51.710 --> 14:52.230] Uh... [14:52.230 --> 14:53.750] Well, no, no R protection. [14:54.470 --> 14:57.510] This is, uh, isolation transforms for the... [14:57.510 --> 14:58.050] Yeah, it is. [14:59.730 --> 15:00.250] Standard... [15:00.250 --> 15:02.550] Well, no, probably for in and out telephone lines. [15:03.530 --> 15:03.950] 1991. [15:05.350 --> 15:06.230] It could be part of a switch. [15:07.290 --> 15:07.810] Telotrens? [15:08.910 --> 15:10.190] Well, yeah, that's the reason why. [15:10.310 --> 15:11.170] It's just the hardware. [15:11.610 --> 15:12.130] Okay. [15:14.870 --> 15:15.750] Okay, what... [15:17.530 --> 15:17.970] Um... [15:17.970 --> 15:19.010] Yeah, so we'll pass this around. [15:19.210 --> 15:19.470] If... [15:19.470 --> 15:20.570] I guess if people... [15:20.570 --> 15:22.770] Showing hardware is a little harder than I thought. [15:23.390 --> 15:24.370] Um, if people... [15:24.370 --> 15:26.270] Do people have any real questions? [15:26.570 --> 15:28.150] Someone mentioned they had a Palm Pilot question? [15:28.950 --> 15:29.530] That guy? [15:33.400 --> 15:33.880] Okay. [15:33.880 --> 15:34.780] Uh, okay. [15:34.920 --> 15:35.500] We're starting at a question. [15:35.760 --> 15:36.760] Did you have a question? [15:37.100 --> 15:37.880] Yeah, hold on one second. [15:38.100 --> 15:38.420] Okay. [15:39.220 --> 15:40.200] Don't break the notes. [15:40.960 --> 15:44.780] Uh, you mentioned, uh, you developed for, uh, PDA. [15:45.020 --> 15:46.360] So, do you develop anything for Newton? [15:47.140 --> 15:47.420] Ha. [15:49.180 --> 15:49.660] N... [15:49.660 --> 15:49.960] No. [15:51.540 --> 15:52.020] Um... [15:52.820 --> 15:53.300] Next? [15:53.400 --> 15:53.700] Sorry. [15:54.000 --> 15:54.440] Yeah, next. [15:54.700 --> 15:55.800] No, um... [15:57.060 --> 15:57.840] Not at all. [16:00.260 --> 16:00.740] Yeah. [16:00.740 --> 16:02.180] Yeah, I have a question for Javaman. [16:02.760 --> 16:08.880] Um, how sensitive are the current, uh, cell phone technologies to white band art? [16:09.760 --> 16:10.680] White band art? [16:11.080 --> 16:11.680] All right. [16:11.820 --> 16:12.000] Why... [16:12.000 --> 16:13.300] I was actually waiting for this question. [16:13.560 --> 16:14.760] Um, dead serious. [16:16.780 --> 16:17.240] Um... [16:17.240 --> 16:18.220] So, let's talk about... [16:18.220 --> 16:19.660] We'll talk about CDMA specifically. [16:20.140 --> 16:21.860] Uh, CDMA is a spread spectrum... [16:21.860 --> 16:22.240] Excuse me? [16:22.380 --> 16:23.200] Read a question. [16:23.600 --> 16:24.320] Oh, the... [16:24.320 --> 16:24.680] Okay, read. [16:24.780 --> 16:29.060] The question was, how, uh, sensitive is current cellular technology to jamming? [16:29.060 --> 16:30.180] Specific wide band jamming? [16:30.380 --> 16:30.780] Yeah. [16:31.080 --> 16:31.480] Okay. [16:32.020 --> 16:36.500] The question was, how, um, how vulnerable are our systems to jamming? [16:37.200 --> 16:38.920] Uh, so let's take CDMA for example. [16:39.040 --> 16:47.180] CDMA is a nice test case, uh, or a nice specific case, because it's, uh, really our only true spread spectrum, uh, cellular protocol out there right now. [16:47.800 --> 16:51.140] Uh, what spread spectrum means is, you have your incoming... [16:51.140 --> 16:54.220] Well, let's say we have, uh, two level, for a very simplified version. [16:54.220 --> 16:58.580] A, uh, minus five volt signal and plus five volt signal. [16:58.800 --> 17:00.290] So, it's negative one... [17:00.780 --> 17:01.720] Uh, you hit zero and one. [17:01.900 --> 17:02.200] Okay? [17:02.780 --> 17:11.100] And you send that into a mixer along with a pseudorandom code, uh, which has a frequency rate much higher than your incoming data rate. [17:11.460 --> 17:17.840] What happens is, if you look at the power spectral density, it's so much easier if I had an overhead or a whiteboard or some shit like that. [17:18.340 --> 17:32.020] If you look at the power spectral density of your regular signal before spreading, you'll see a single spike come up and some humps over the side, uh, due to the, uh, the variable frequency nature and the square wave nature of the actual data rate. [17:32.220 --> 17:41.400] When you look at spread spectrum, your power spectral density is dumped much further out, uh, at a specific ratio to the property of that modulation format. [17:42.880 --> 17:43.680] Direct sequence... [17:43.680 --> 17:45.960] Specifically direct sequence spread spectrum, which is CDMA. [17:46.740 --> 18:01.580] Um, and what happens as a result is that if you want to... if you look at the signal on a scope, if the, uh, actual, uh, the, the frequency rate of the spreading sequence is much greater than of the actual data sequence, you will just see noise in the scope. [18:01.740 --> 18:06.380] And mathematically, importantly, mathematically, your signal is actually is very similar to noise. [18:06.500 --> 18:23.620] If you take an autocorrelation of your signal space, uh, with itself, or autocorrelation means with itself, you take a correlation of it, uh, what it actually looks like is it's It's very, very, very narrow actual correlation area, which is a sign that it's very much closer to noise than a normal signal. [18:23.820 --> 18:29.720] A normal signal's all correlation with itself is just one spike at tau equals zero. [18:30.380 --> 18:39.320] What this means, though, is that unless you have the exact PN sequence on the other end, you will never be able to recover your original signal. [18:39.760 --> 18:58.000] The PN sequences are designed to be completely orthogonal with each other, so that if you try to generate another sequence, it's not exactly the same number of convolutions, not exactly the same convolutions at each, what they call, chip, at the same as each data bit, [18:58.160 --> 18:59.880] you're never going to be able to recover your original signal. [19:00.640 --> 19:14.900] Now, what's interesting, if you try jamming a standard spread spectrum system with a single tone, a narrow frequency tone, like let's say you want to jam someone on walkie-talkie, you key up on their exact frequency using the same modulation format with a little bit more power. [19:15.680 --> 19:21.760] Because of the way spread spectrum works, that jamming signal is spread itself, while the rest of the signal is de-spread. [19:21.920 --> 19:32.680] So if you actually look at the power spectral density after the mixer, which de-spreads your signal, you will see your original signal and your interferer is very broadband. [19:33.540 --> 19:38.700] So the actual single spike, or narrow band jamming is very difficult. [19:39.160 --> 19:43.560] Wide band jamming is almost impractical because of the power considerations. [19:43.940 --> 19:50.340] You have to generate, you know, if you integrate over that entire area, that's the amount of, you know, power you have to be able to dump into an antenna. [19:50.820 --> 19:53.240] Or narrow power, you have to be able to generate from power transistors. [19:53.360 --> 19:57.140] And when we're getting up to two gigahertz, you can use, like, klystrons or power transistors. [19:57.300 --> 20:00.120] But the power considerations are... excuse me? [20:00.380 --> 20:01.400] Spark apps. [20:01.520 --> 20:02.680] Yeah, spark apps. [20:03.300 --> 20:07.420] But the only problem is that, again, you're not going to be able to get the power you need to do it. [20:09.120 --> 20:17.980] An interesting point that was brought up kind of recently, someone had this thing, it made SuckDOT, about the idea of jamming a satellite. [20:18.420 --> 20:23.760] And the way it worked was by jamming a large, a single frequency power spike. [20:24.000 --> 20:26.080] And what it did was descend to the front end of the receiver. [20:26.220 --> 20:30.820] I want to explain what that means and why this is actually important, and why people are doing this now. [20:33.120 --> 20:38.360] Basically, our front end amplifiers, our receivers, have very narrow dynamic range, a lot of times. [20:38.380 --> 20:42.420] If it's a low noise amplifier, we're narrow in response, in respect to the jammer. [20:42.680 --> 20:56.300] And when you generate a very large, single frequency, very narrow bandwidth signal, very high power, it forces the front end amplifier in what's called 1 dB compression, or force it into compression. [20:56.300 --> 20:59.060] And what happens is that the gain of that amplifier is reduced. [20:59.300 --> 21:04.240] So your original signal you're trying to receive actually gets dumped, it gets pushed further and further into the noise floor. [21:04.440 --> 21:15.560] So it actually is possible by generating enough power, you can exploit the properties of receiver technology, and therefore effectively jam a spread spectrum signal. [21:15.740 --> 21:27.180] But probably the best way to do something like this would be a very narrow beam width antenna point somewhere close to the receiver, within a local area receiver, to completely deafen the receiver. [21:27.920 --> 21:29.320] Does that answer your question? [21:30.020 --> 21:30.480] Yeah. [21:31.500 --> 21:31.760] All right. [21:33.400 --> 21:34.160] All right. [21:34.180 --> 21:34.500] Hold on. [21:35.160 --> 21:35.600] Next? [21:36.720 --> 21:37.200] Next. [21:39.120 --> 21:39.920] Hold on. [21:39.920 --> 21:40.600] All right. [21:40.600 --> 21:41.300] Hey, we got the mic. [21:41.460 --> 21:41.700] Mike? [21:42.900 --> 21:44.900] Since I got the mic, I'm going to ask my question. [21:44.980 --> 21:45.160] All right. [21:45.980 --> 21:46.360] Kingpin. [21:47.020 --> 21:47.420] What... [21:47.420 --> 21:49.320] You still doing much work with POCSAG? [21:49.400 --> 21:51.280] And what's your favorite way of doing POCSAG and killing it now? [21:52.000 --> 21:52.700] Oh, man. [21:53.020 --> 21:54.740] I was hoping you wouldn't ask that question. [21:55.720 --> 22:06.220] No, I haven't done anything with POCSAG since we ran out of the L0pht POCSAG kits back in, what, 98, 97 or something. [22:07.500 --> 22:09.120] I kind of gave up on POCSAG. [22:09.260 --> 22:12.380] I thought Flex was going to kind of come in and take it away. [22:14.040 --> 22:14.480] Probably... [22:15.040 --> 22:22.020] I don't really have a favorite method now, but if I were to do it again, I'd probably use maybe like a PIC processor. [22:23.540 --> 22:35.620] Have a portable POCSAG decoder and just write some software with the PIC, maybe external circuitry if I need it, to have an actual portable POCSAG decoder maybe hook it up to a pager. [22:35.880 --> 22:44.440] So take the discriminator output from the pager or the actual unfiltered signal from the pager into this whatever circuit. [22:45.480 --> 22:47.800] But I probably wouldn't do it with a laptop or anything. [22:47.900 --> 22:48.740] Maybe with a Palm Pilot. [22:48.960 --> 22:52.200] Have circuitry and just have a serial input into the Palm Pilot or something like that. [22:54.200 --> 22:55.420] Oh, go ahead. [22:56.180 --> 22:57.000] Do you want... [22:57.000 --> 22:57.460] I can... [22:58.520 --> 22:59.200] This is to anybody. [22:59.480 --> 23:01.800] Did anybody do anything with the Virgin Connect? [23:03.080 --> 23:03.560] What? [23:03.760 --> 23:05.060] The Virgin Connect appliance? [23:07.610 --> 23:07.650] What? [23:08.230 --> 23:08.350] No. [23:08.470 --> 23:08.890] Spell it. [23:09.390 --> 23:10.150] Virgin Connect. [23:10.370 --> 23:10.850] No. [23:11.370 --> 23:12.370] Has anybody heard of that here? [23:13.570 --> 23:14.050] Yeah? [23:14.190 --> 23:15.430] Do you want to explain what it is? [23:15.550 --> 23:15.670] Oh. [23:16.290 --> 23:18.250] Does anybody know and wants to explain what it is? [23:18.750 --> 23:18.990] Right. [23:19.710 --> 23:20.450] Virgin Connect. [23:21.710 --> 23:22.190] Oh. [23:22.850 --> 23:23.930] It's a net client. [23:24.130 --> 23:24.230] Yeah. [23:24.430 --> 23:26.190] It's one of those net clients things. [23:26.310 --> 23:26.450] Yeah. [23:26.450 --> 23:27.970] I heard Virgin's in there somewhere. [23:31.120 --> 23:32.140] So it's a... [23:32.140 --> 23:32.740] It's kind of like... [23:32.740 --> 23:33.060] Okay. [23:33.300 --> 23:35.280] So it's a net appliance like the eye-opener. [23:35.460 --> 23:35.680] Yeah. [23:36.280 --> 23:36.760] Where... [23:41.140 --> 23:41.620] Okay. [23:41.820 --> 23:44.380] It uses a Cyrix chipset with a... [23:44.380 --> 23:44.700] What did you say? [23:44.780 --> 23:44.980] IDE? [23:46.720 --> 23:50.540] IDE, pinouts, year to pinouts, and PCMCIA. [23:51.180 --> 23:51.420] Okay. [23:51.420 --> 23:55.940] So we're trying to figure out if we can make it like the eye-opener, make it into a real computer. [23:57.300 --> 23:58.660] I'm sure it's possible. [23:58.800 --> 23:59.020] Go ahead. [23:59.380 --> 24:06.460] I was gonna say, the cost of actual manufacturing of a complete proprietary system is so extremely high that no one does it. [24:06.860 --> 24:08.860] So it's all based off-the-shelf technologies. [24:09.400 --> 24:13.440] Additionally, the cost of doing anything that would obfuscate something would add so much... [24:13.440 --> 24:16.840] would add more time to the actual production costs and the actual design costs. [24:17.040 --> 24:18.200] No one ever does this. [24:18.600 --> 24:20.020] You know, or very rarely do it. [24:20.120 --> 24:23.020] Now, I mean, they do it with the eye-opener where they just put some epoxy on it. [24:23.160 --> 24:23.560] You know what I mean? [24:23.680 --> 24:25.700] And that was their idea of obfuscation. [24:26.360 --> 24:27.780] Or, you know, flipping the pins over. [24:27.880 --> 24:30.060] But the pins in the IDE controller probably being flipped over. [24:30.240 --> 24:33.720] It was probably something that was convenient for them when they were actually manufacturing the board. [24:34.020 --> 24:35.560] So I think it would be pretty easy for you to do. [24:36.460 --> 24:37.060] Yeah, definitely. [24:37.160 --> 24:41.560] Another point with the manufacturing costs is the manufacturers of these boards need to be able to test them. [24:42.280 --> 24:48.120] And I'm sure they're not going to want to develop their whole test fixtures just, you know, for this one cheap proprietary product. [24:48.580 --> 24:49.860] So it's probably just... [24:49.860 --> 24:55.380] From my understanding, the eye-opener was just a standard motherboard and stuff obfuscated with epoxy, covered in epoxy or whatever. [24:56.520 --> 24:58.200] So I'm pretty sure that would be the same. [24:58.340 --> 25:01.160] If you know where to buy them, I'm sure other people would want to know. [25:02.980 --> 25:04.140] From the Virgin website. [25:05.640 --> 25:06.780] From the Virgin website. [25:07.020 --> 25:07.240] Yeah. [25:08.440 --> 25:09.400] You can guess that one. [25:09.400 --> 25:11.920] You'll probably come up with some other fun sites at the same time. [25:12.840 --> 25:13.820] There's a question over here. [25:17.690 --> 25:23.610] I was just wondering if you've messed around with and compared the Visor hardware to the actual Palm hardware. [25:23.790 --> 25:29.110] Because I've noticed that the Visor running with the same OS runs a hell of a lot faster than the Palm does and everything. [25:29.250 --> 25:30.290] So I'm just wondering what you've done with that. [25:30.910 --> 25:31.730] That's a good question. [25:31.730 --> 25:43.510] The Visor is a new PDA that's made by Handspring, which is actually a company formed by Jeff Hawkins, who's the founder of Palm Computing or the Pilot back in the day. [25:44.730 --> 25:45.610] There's one here. [25:45.750 --> 25:47.970] It looks strikingly similar to the Palm Pilot. [25:48.130 --> 25:51.330] It's actually bigger and a little more bulky. [25:52.970 --> 25:58.490] What the Handspring is, is basically, it's a standard Palm Pilot, but it's made by this other company. [25:58.770 --> 26:03.950] It runs a ROM version of Palm OS 3.3. [26:04.350 --> 26:07.930] Most of the Palm Pilots now have Flash ROMs, so you can upgrade the software. [26:09.130 --> 26:12.130] These Visors are stuck at OS 3.3 currently. [26:13.070 --> 26:17.710] Their hardware, their board design is different, but it operates just the same. [26:18.050 --> 26:26.970] I think the Visors have... so the Palm Pilots and the Palm... up to the Palm 3 run on the Dragon Ball 68 328. [26:27.050 --> 26:28.130] It's a Motorola processor. [26:28.350 --> 26:29.670] It's a 68000 compatible. [26:30.770 --> 26:40.150] I think from the 3 to the... or from above the 3 to maybe like the 7, they use the Dragon Ball EZ processor, which is just an enhancement of that. [26:40.330 --> 26:45.490] It kind of takes away some of the unused functionality of the 68 328, and it's a little cheaper. [26:47.050 --> 26:50.410] It's also a little bit faster, and I think that's what the Visor uses. [26:50.730 --> 26:55.670] Now, there's also a 68 328 VZ, which just came out, and I'm not sure if it's in any devices yet. [26:56.670 --> 26:59.930] Possibly the Palm 3C, which is the color version. [27:01.770 --> 27:12.770] The VZ has a PLL for getting up to 33 MHz as a system clock, which is basically twice as fast as the Palm Pilots were 16.7 MHz. [27:12.930 --> 27:15.370] The Palm 3C is comparable in speed to the Visor. [27:15.410 --> 27:15.670] Okay. [27:16.590 --> 27:20.630] So the Palm 3C is comparable in speed to the Visor, I've just been told. [27:20.630 --> 27:29.690] But basically everything that runs on the PalmOS platform from version 3.3 is going to run on any, any PalmOS platform. [27:29.970 --> 27:37.870] The good thing about the Handspring device, if you go to Handspring.com, they have an expansion port in the back, which is totally hackable. [27:38.390 --> 27:46.910] What it is, is a bunch of direct connects to some of the IO ports and some of the port circuitry and pins on the Dragon Ball. [27:47.730 --> 27:48.690] Which makes it nice. [27:48.810 --> 27:51.590] The original PalmPilots only had a serial port. [27:51.990 --> 27:56.390] And there's only so much you could do with the serial port without having external circuitry. [27:56.450 --> 27:58.050] Here comes some CDC stickers, I think. [27:58.550 --> 27:59.510] Thanks, Death Veggie. [28:00.410 --> 28:02.750] Feel free to come up here and answer some questions with us. [28:04.370 --> 28:10.490] So this springboard module, they call it, is this expansion port on the Handspring, on the Visors. [28:10.710 --> 28:12.830] And it's, it's amazing. [28:13.170 --> 28:15.450] There's a bunch of white papers up on Handspring's site. [28:15.590 --> 28:19.390] You can make custom circuit boards to basically do whatever you want. [28:19.470 --> 28:21.630] I think they have an MP3 player currently out. [28:21.790 --> 28:25.750] They have a camera, basic consumer applications. [28:25.750 --> 28:27.730] But you could basically do whatever you want with it. [28:28.110 --> 28:31.270] They also have some that just have Flash on board. [28:31.410 --> 28:34.290] So you can write software and kind of distribute it like a cartridge. [28:35.370 --> 28:37.070] So I'm not sure really why you'd want to do that. [28:37.230 --> 28:38.470] Because it's going to cost a lot of money. [28:39.350 --> 28:44.010] But definitely take a look at the Handspring device if you wanted to do any kind of hardware modifications. [28:45.190 --> 28:49.990] And also, actually on that note, the Palm3X, I believe, made by... [28:49.990 --> 28:50.970] Pay attention to the man over here. [28:51.030 --> 28:51.870] Yeah, save one for me. [28:53.630 --> 28:57.710] The Palm3X also has an expansion port, but it's not really defined as well as the... [28:57.710 --> 28:58.750] Springboard module. [29:05.590 --> 29:06.190] Alright, wait. [29:06.470 --> 29:07.490] Wait, you can't just throw them out. [29:07.650 --> 29:08.810] You guys have got to do something cool. [29:09.530 --> 29:09.890] Alright? [29:10.450 --> 29:11.330] Why don't you... [29:11.330 --> 29:16.170] How about for really good questions or if you dance or like pop your eyeballs out or something? [29:17.970 --> 29:21.090] Where's the guy that was rapping at the movie last night? [29:21.290 --> 29:22.730] I want to see him and he'll get a shirt. [29:25.290 --> 29:25.890] What's that? [29:26.350 --> 29:27.930] Do you have a Newton story to share? [29:28.350 --> 29:30.250] I won't sing! [29:31.150 --> 29:31.750] You'll what? [29:32.010 --> 29:32.870] I won't sing! [29:32.930 --> 29:33.750] You won't sing? [29:34.210 --> 29:35.910] If you do sing, can we give you one? [29:38.970 --> 29:40.430] I bet I'll get a shirt. [29:41.330 --> 29:42.270] Alright, why don't I sing? [29:42.450 --> 29:43.130] Whatever you want. [29:43.830 --> 29:44.390] Hey, where's the mic? [29:44.390 --> 29:45.370] Since it's not here. [29:45.430 --> 29:46.390] Maybe he got back. [29:48.250 --> 29:48.750] Oh. [29:49.270 --> 29:51.930] Hey, I had a question I asked about how... [29:53.090 --> 29:56.890] Do you guys mess around with the microchip PIC controllers? [29:57.230 --> 29:58.790] I mean, microchip as in the... [29:58.790 --> 29:59.550] Oh. [29:59.650 --> 30:00.150] Yes. [30:00.410 --> 30:00.670] Oh yeah. [30:00.910 --> 30:01.410] Those... [30:02.750 --> 30:04.250] Do you want to talk about this? [30:06.190 --> 30:10.870] Microchip is a company that makes a bunch of different integrated circuits. [30:12.170 --> 30:14.910] Their PIC processor is a general purpose processor. [30:15.250 --> 30:16.190] They're really cheap. [30:16.350 --> 30:17.730] They're available everywhere. [30:19.630 --> 30:20.090] Yeah. [30:20.290 --> 30:21.470] We haven't forgotten about the shirts. [30:21.730 --> 30:23.130] You just have to pay attention now. [30:23.850 --> 30:24.790] It's like school. [30:26.670 --> 30:27.390] Yeah, right. [30:28.450 --> 30:30.290] If you stay quiet, then you get a shirt. [30:31.670 --> 30:34.690] Yeah, so the PIC processors are really cheap. [30:34.830 --> 30:36.670] You can get them from Digikey. [30:37.490 --> 30:38.330] Digikey.com. [30:39.050 --> 30:40.490] Basically, any electronics store. [30:40.630 --> 30:42.550] I've done a lot of development with them. [30:42.650 --> 30:43.830] Mostly for like art projects. [30:44.230 --> 30:45.310] So I have things that... [30:45.310 --> 30:51.530] I'll use a multicolor LED and like change the color of the LED every minute and just do some stupid art stuff with it. [30:51.970 --> 30:53.130] They're really easy to program. [30:53.270 --> 30:57.150] They have development kits that are like maybe 20 bucks, 29 bucks. [30:57.310 --> 31:00.090] So it's something that students can use and it's affordable enough. [31:01.370 --> 31:03.550] Well, the reason why I was asking is... [31:03.550 --> 31:10.170] I do a development on the 16C84 or F84 one that has a flash memory. [31:10.330 --> 31:10.390] Yep. [31:10.930 --> 31:13.750] The reason why I picked that one is because it's not as a flash memory. [31:13.930 --> 31:19.670] I mean, it only takes like a couple dollars worth of parts to build a serial interface and then the software and stuff for free. [31:20.190 --> 31:27.330] Do you know if Microchip or like Atmel, I think it's another company that makes processors, assuming I'm pronouncing the name correctly. [31:28.750 --> 31:33.530] Do you know if they're going to start turning all into flash memory and get away from that OTP thing? [31:34.230 --> 31:34.670] No. [31:34.990 --> 31:37.910] I don't think they're ever going to go away totally from OTP. [31:39.630 --> 31:43.010] Yeah, it depends on the application if you actually want flash. [31:43.290 --> 31:48.390] And it's also developing integrated circuits with flash technology is still more expensive than OTP. [31:49.710 --> 31:54.670] And if you're not going to want to reprogram your system, you'd have an OTP part. [31:54.670 --> 32:00.490] What people usually do is they do development with a flash part so they can keep on reprogramming their firmware as they're doing development. [32:00.730 --> 32:11.050] And then when they go into production, they just get a ROM version, have Microchip program it at their manufacturing plant, send them to the vendor who's manufacturing with that already programmed. [32:11.050 --> 32:20.410] Okay, well, what I was going to mention about is Microchip, they also make, you know, the UV version of pretty much every one of their OTP processors. [32:20.690 --> 32:20.830] Right. [32:20.930 --> 32:31.810] But what sucks about using the UV process is there's like, for me, it's like a 10 to 20 minute turnaround time, whereas the flash thing with my $2 programmer, I can turn around as short as 3 seconds. [32:32.130 --> 32:37.570] Yeah, yeah, they do have the UV parts which you erase with UV light, as the name would imply. [32:38.550 --> 32:40.490] It does take like 10 or 20 minutes. [32:41.070 --> 32:43.190] I don't know how much those are going to go away. [32:46.770 --> 32:52.230] I'm sure people are still going to use it, but flash is definitely more convenient for development and also if you want to do firmware upgrades on your product. [32:55.520 --> 32:56.160] Anything else? [32:56.440 --> 32:58.880] I mean, do you have a specific question about that? [32:59.020 --> 33:01.820] I mean, using flash, yeah, I mean, it really depends on your product. [33:02.060 --> 33:11.060] I think it's also important to mention that there's companies don't do things without a reason usually, especially an electronics company, so it could be more expensive. [33:12.200 --> 33:17.860] Well, I mean, when it comes to like, when production means real money, they do things for reasons. [33:18.160 --> 33:22.400] And it could be that they might have like higher failures in production of a flash memory. [33:22.520 --> 33:23.960] It might be harder for them to actually manufacture. [33:24.420 --> 33:27.080] And also for a lot of applications, they never reprogram things. [33:27.080 --> 33:31.940] You know, like chips in analog grade systems, for example. [33:32.840 --> 33:36.460] It's very rare that they'll ever reprogram the chip in production. [33:36.900 --> 33:38.460] They might just shake the entire board. [33:39.440 --> 33:39.780] Okay. [33:39.980 --> 33:47.120] Well, I was just thinking, you know, like, okay, the OTP is cheaper, but, you know, it's an option of, you know, permanent one-chip to cook it all. [33:47.220 --> 33:55.800] But, you know, for me, when I'm doing development, it's a nice build to, you know, reprogram it, you know, get the bugs and stuff out of it, but they'd be able to do it fast. [33:56.060 --> 33:59.640] But that's why you would use flash RAM if you had to reprogram it. [33:59.680 --> 34:07.020] If you went to a situation where you were making a million of them, then you would just use one-time programming because you would never reprogram it if you had a million units. [34:07.600 --> 34:07.760] Uh-huh. [34:08.060 --> 34:09.720] Use the Atmel 8535. [34:10.100 --> 34:12.740] The Atmel 8535 is what? [34:13.280 --> 34:13.560] It's [34:23.560 --> 34:24.000] something . [34:24.000 --> 34:24.660] Okay. [34:25.420 --> 34:27.020] 512K of RAM? [34:27.520 --> 34:29.340] It's either 512K or 512K. [34:29.980 --> 34:30.300] Okay. [34:34.100 --> 34:37.300] 8K of flash and 512 bytes of RAM. [34:37.740 --> 34:38.180] Okay. [34:38.760 --> 34:41.740] And that's a general, that's another general purpose type of processor? [34:42.040 --> 34:43.620] Yeah, we use them at what we said. [34:43.840 --> 34:44.100] Cool. [34:44.440 --> 34:44.980] And that's Atmel. [34:45.100 --> 34:45.780] Atmel.com. [34:48.420 --> 34:49.040] What'd you say? [34:50.060 --> 34:52.940] What's the programming interface he wants to know? [34:59.380 --> 35:00.160] Programming interface? [35:00.160 --> 35:00.820] Yeah. [35:01.020 --> 35:04.520] I mean, do you know what the pin apps and stuff? [35:05.820 --> 35:07.080] Oh, the pin apps and stuff? [35:07.260 --> 35:07.420] Yeah. [35:07.620 --> 35:10.380] I don't have the actual schematic on me, but... [35:10.820 --> 35:16.280] A lot of the chips that have flash are definitely serial protocols. [35:16.680 --> 35:18.180] Some of them are standards, like... [35:18.180 --> 35:19.200] No, they are serial. [35:20.020 --> 35:22.040] Yeah, it's going to be serial for the most part. [35:23.400 --> 35:30.980] And whatever it is, there's data sheets that would provide that information on the timing, so you could either build a development system yourself or just use one. [35:31.060 --> 35:32.080] But it's going to be standard serial. [35:32.080 --> 35:36.180] There's a combination of, like, two or three pins that enables you to program it. [35:36.320 --> 35:39.840] And once you set those up, then you can just pretty much send serial data in. [35:40.140 --> 35:44.760] There's an actual protocol for it, but it's in the Atmel data sheet on Atmel.com. [35:45.220 --> 35:47.200] Can you pass the mic over this guy in the blue shirt? [35:50.790 --> 35:52.070] I'd also like to mention... [35:52.070 --> 35:55.790] I've been working on some stuff like Doppler or RDF, if anyone has any questions about that. [35:55.790 --> 35:57.930] Well, my question is for Brian Oblivion. [35:58.050 --> 36:02.530] Can you just maybe stand up and tell us what you've been working on lately, what you've been playing around with? [36:02.850 --> 36:03.710] I think we're all curious. [36:04.010 --> 36:04.230] Yeah. [36:05.410 --> 36:06.150] Let's hear it. [36:06.430 --> 36:07.150] I want a shirt. [36:07.270 --> 36:08.070] Can I add front of the speakers? [36:08.590 --> 36:09.130] Yes, you do. [36:10.950 --> 36:16.850] Well, I mainly come from a cryptographic accelerator, a cryptographic co-processor arena. [36:17.790 --> 36:25.070] I worked on the key management device, I'll say, at a government contractor. [36:25.070 --> 36:31.070] And I'm trying to take that information that I've learned there, and try to put it into the public-sourced arena. [36:33.050 --> 36:40.210] We're kind of doing a little side work with Peter Gutman in Australia, and in Auckland. [36:40.750 --> 36:52.530] And he's going to be releasing a paper on open-source cryptographic processors that you just stick on your machine whenever you do operations, and when you're done with it, just pop it off, throw it in your pocket, walk away. [36:52.530 --> 36:55.410] But the idea is to keep the keys off the system. [36:56.010 --> 37:06.690] Right now, every OS is completely open, and there's all kinds of papers on it, on key searching and finding keys off of hard drive images and stuff. [37:06.690 --> 37:16.330] So we want to move the stuff off of the hard drives into some type of IC or into some type of token you can walk away with, like the high button. [37:17.250 --> 37:21.450] Or even some type of prom-based key, like a data key or something. [37:22.410 --> 37:24.970] Aside from that, I'm still working on GuerillaNet. [37:27.150 --> 37:32.010] It's just, you know, it's like herding cats, trying to get people to get up and buy the equipment that's necessary. [37:35.090 --> 37:42.710] Yeah, and it's difficult because nobody wants to play around with 1,200 or 2,400 bot data links. [37:42.830 --> 37:46.050] They want to do 10 meg and higher, or at least 1.2 meg and higher. [37:46.270 --> 37:48.110] And you really need behind the site for most of that. [37:48.170 --> 37:56.310] So it's very frustrating when you can't find prime real estate now that the cellular and every other kind of wireless thing is taken off. [37:57.250 --> 37:59.790] So that's basically what I'm working on now. [37:59.950 --> 38:01.530] So if you have any questions, take a look at that. [38:01.730 --> 38:02.610] I'm happy to answer them. [38:05.740 --> 38:07.300] Alright, where's the mic closest to? [38:07.300 --> 38:08.300] Thank you. [38:15.530 --> 38:17.150] A question for me, Ken. [38:17.690 --> 38:28.490] The palm killing software, a guy out in Canada I know, has written a, some low level code that he accidentally found this, that literally like fries the pilots. [38:29.230 --> 38:30.870] Have you had any experience with this at all? [38:32.110 --> 38:34.850] Without knowing exactly what it does, that sounds a little strange. [38:35.570 --> 38:38.270] Do you know what type of low level stuff he did? [38:38.270 --> 38:45.790] Yeah, he was trying to do something in the IR so it wouldn't need to get a response back from the other one before it was sent, so it just looked like a blind send. [38:47.950 --> 38:56.330] Now, I actually did another, I designed a medical device based around the 68328 that actually used infrared. [38:58.250 --> 39:02.150] And if the, all the infrared port is on the Dragon Ball, it's just a UART. [39:03.150 --> 39:08.730] And the infrared, it just has data output at a 316th bit rate, which is something that the infrared transceivers are going to use. [39:09.730 --> 39:16.850] By doing, if that's really what he did, I wouldn't see how that would actually damage anything other than maybe, maybe crash the OS or something which you could just reset. [39:17.270 --> 39:21.150] But I don't think it would damage the hardware because it's just going to, I mean, it's just going to draw power. [39:21.150 --> 39:28.050] He did this to two or three units, and eventually 3con flew him up and said, what the hell are you doing? [39:28.490 --> 39:35.890] Because he was trying to get around the OS, because the OS was basically saying, no, I need to wait for a response before I start sending. [39:36.970 --> 39:37.290] Yeah. [39:37.550 --> 39:38.130] What's that? [39:39.790 --> 39:43.210] Yeah, I mean, unless he clobbered the Flash ROM job, or the Flash ROM. [39:43.350 --> 39:46.210] But I don't know, if you have a webpage, do you know URL offhand? [39:46.210 --> 39:47.790] I can get you his e-mail address. [39:48.570 --> 39:48.970] Okay. [39:49.370 --> 39:55.890] You can e-mail it to me, and if anyone else is interested, send me e-mail, kingpin at l0pht.com, and I'll forward it on. [39:56.090 --> 39:57.450] But that would be interesting to know. [40:00.960 --> 40:02.420] Alright, there's more questions. [40:03.860 --> 40:14.380] I have a two-fold question regarding modems, and basically identifying how a particular protocol is implemented. [40:15.120 --> 40:23.920] If you're doing, let's say, a word dialing exchange, a lot of times they'll come up with numbers that just don't respond to any combination of key inputs. [40:24.560 --> 40:29.500] How would you go about finding what kind of computer this is when it doesn't respond? [40:30.620 --> 40:32.460] Yeah, I think we'll each say something on this. [40:33.380 --> 40:38.340] A lot of times, when I've been word dialing, there are a lot of systems that don't come up with anything. [40:39.540 --> 40:46.580] It could really be any type of device, and not every device hooked up to a modem is going to have an identification string. [40:47.320 --> 40:51.360] It might be expecting some weird control characters to turn it on. [40:51.480 --> 40:55.280] I'm not sure there's one generic way to identify any one system. [40:55.860 --> 41:04.000] And if it doesn't identify itself in some way, it's basically impossible to know unless you actually get into their site somehow and see what it's connected to. [41:04.000 --> 41:06.580] I have a craft access terminal at home. [41:06.700 --> 41:12.640] It's used by a phone company to check up on customer lines. [41:13.060 --> 41:15.760] I think it's like a 300 or 1200 modem. [41:16.020 --> 41:26.720] It seems like the specification is proprietary, because if I try and connect using a regular PC, I can't talk with a remote computer, but with the craft access terminal I can. [41:26.720 --> 41:34.420] Actually, my understanding of the craft terminals were they just had macros basically. [41:34.700 --> 41:38.580] So it was still, you connect 300 baud or 1200 baud or whatever the craft terminal was. [41:38.660 --> 41:42.600] The craft terminal is this big yellow lineman handset with the display and everything. [41:42.760 --> 41:43.960] It's like a fancy... [41:44.420 --> 41:45.260] Do we have one? [41:46.740 --> 41:49.300] Alright, someone has one, I guess, on the other side. [41:49.780 --> 41:51.480] But if they can wave it around, that would be cool. [41:52.460 --> 41:56.240] Yeah, my understanding is that they just used macros. [41:56.500 --> 42:00.600] So if anything, it's just gonna be, you know, strings of control characters or something. [42:00.800 --> 42:03.260] So maybe if you can monitor what those are. [42:03.560 --> 42:07.060] Maybe with like an RS-232 analyzer, or not RS-232. [42:09.460 --> 42:11.180] I guess something hooked up to the phone line. [42:11.320 --> 42:15.280] If you can analyze those strings, then you might be able to recreate that with a terminal program. [42:15.840 --> 42:22.100] So you're just gonna record the signal as it goes over my phone line and try back to an oscilloscope or something? [42:23.500 --> 42:24.760] If you're ambitious enough. [42:25.040 --> 42:30.100] I was gonna say, if you really want to be a hard ass about it, but seriously what I'll do is... [42:30.100 --> 42:31.960] You don't have to get yourself in a oscilloscope. [42:32.100 --> 42:33.640] You have a really good one at your sound card. [42:36.040 --> 42:39.360] Because think about it, your data rate on your phone line can... [42:39.360 --> 42:40.420] Oh, holy shit. [42:40.440 --> 42:43.680] No, this actually isn't a craft terminal, but it's something cool. [42:43.680 --> 42:44.300] Yeah. [42:46.200 --> 42:46.860] Thank you. [42:47.160 --> 42:47.540] Anyway. [42:51.870 --> 42:53.230] I'm trying a t-shirt for one of these. [42:55.410 --> 42:56.410] Two t-shirts. [42:58.230 --> 42:59.020] You gotta remember... [42:59.500 --> 43:00.430] Oh, let's hold this up first. [43:00.660 --> 43:00.950] It says... [43:01.640 --> 43:01.770] Ooh. [43:02.200 --> 43:03.000] That's pretty cool. [43:05.390 --> 43:09.960] It looks like some kind of mobile thing. [43:11.580 --> 43:13.200] It looks like it's either a terminal... [43:13.200 --> 43:21.750] A lot of UPS type companies use these things for keeping track of their location and kind of message tracking. [43:26.230 --> 43:28.970] And this probably also serves as a portable terminal. [43:29.170 --> 43:30.330] Which would be kind of cool. [43:30.430 --> 43:33.310] If you have an acoustic coupler and hook it up to a payphone or something like that. [43:35.130 --> 43:37.370] Yeah, you gotta remember your data rate coming down your... [43:37.370 --> 43:38.610] The actual... [43:38.610 --> 43:39.570] I'm sorry, not data rate. [43:39.630 --> 43:40.310] Your symbol rate. [43:40.470 --> 43:41.090] Excuse me. [43:41.230 --> 43:43.310] Your symbol rate on your modem line never really exceeds... [43:43.830 --> 43:43.870] What? [43:44.170 --> 43:44.590] Four kilo... [43:45.510 --> 43:46.310] Four kilohertz. [43:48.770 --> 43:49.350] Excuse me? [43:49.550 --> 43:51.070] It's an eight kilohertz sample rate. [43:51.510 --> 43:53.330] The symbol rate is four kilohertz. [43:54.170 --> 43:56.030] No, the sample rate is eight kilohertz. [43:56.030 --> 43:57.450] The symbol... [43:57.450 --> 43:58.030] Not sample. [43:58.190 --> 43:58.450] Symbol. [43:59.210 --> 43:59.590] Okay. [44:00.770 --> 44:01.270] Okay. [44:01.630 --> 44:01.730] Okay. [44:02.710 --> 44:03.350] Yes. [44:03.490 --> 44:05.090] Because of Nyquest you have to... [44:05.090 --> 44:08.130] You have to sample at double the symbol rate. [44:08.470 --> 44:09.030] Okay. [44:09.410 --> 44:10.630] Your symbol rate... [44:10.630 --> 44:14.770] Your bandwidth of your signal coming down line cannot exceed four kilohertz. [44:15.570 --> 44:16.130] And... [44:16.130 --> 44:16.470] Try to remember... [44:16.470 --> 44:19.410] You're half or double your data rate. [44:19.670 --> 44:20.210] Uh... [44:20.210 --> 44:20.650] It is your... [44:20.650 --> 44:21.410] Your symbol bandwidth. [44:21.890 --> 44:22.950] But your symbol... [44:22.950 --> 44:24.330] When you're talking about modems... [44:24.330 --> 44:24.550] Um... [44:25.110 --> 44:26.030] They don't do... [44:26.030 --> 44:26.530] Uh... [44:26.530 --> 44:27.070] Really... [44:27.070 --> 44:27.270] Uh... [44:27.270 --> 44:29.290] Binary modulation schemes anymore. [44:29.470 --> 44:30.270] Where, you know... [44:30.270 --> 44:31.310] One level means high. [44:31.390 --> 44:32.330] Or this tone means one. [44:32.490 --> 44:33.350] Or this tone means zero. [44:33.870 --> 44:34.050] Uh... [44:34.050 --> 44:37.530] The idea of the four level FSK decoder is that you have four different tones. [44:37.910 --> 44:39.810] What this is called is M-ary signaling. [44:40.110 --> 44:41.130] The idea that... [44:41.130 --> 44:41.490] Uh... [44:41.490 --> 44:42.130] You have... [44:42.130 --> 44:44.350] Two to the end possible... [44:45.210 --> 44:45.650] Uh... [44:45.650 --> 44:45.910] Yes. [44:45.990 --> 44:47.190] Two to the end possible symbols. [44:47.490 --> 44:48.110] And each... [44:48.110 --> 44:48.910] Uh... [44:48.910 --> 44:50.370] Symbol encodes M bits. [44:51.050 --> 44:51.450] So... [44:51.450 --> 44:52.590] For example... [44:52.590 --> 44:53.110] Uh... [44:53.110 --> 44:53.190] It's... [44:53.190 --> 44:54.450] It's a great saving on bandwidth. [44:54.690 --> 44:55.510] But you lose... [44:55.510 --> 44:55.710] Uh... [44:55.710 --> 44:56.850] You take your engineering hit. [44:57.410 --> 44:58.210] Because you're... [44:58.210 --> 44:59.630] It's a less power efficient scheme. [45:00.290 --> 45:00.610] Uh... [45:00.610 --> 45:01.650] You need more power to... [45:02.550 --> 45:02.950] Uh... [45:02.950 --> 45:03.670] I guess we're done. [45:03.730 --> 45:04.030] Thanks. [45:04.230 --> 45:04.370] Yeah. [45:07.310 --> 45:07.710] Um... [45:07.710 --> 45:08.350] Um... [45:08.350 --> 45:08.630] Um... [45:08.630 --> 45:08.690] Okay. [45:10.930 --> 45:11.330] Um... [45:11.330 --> 45:11.970] The... [45:11.970 --> 45:13.490] What happens is that... [45:13.490 --> 45:15.710] You actually need more power to transmit to... [45:15.710 --> 45:15.770] Uh... [45:15.770 --> 45:16.990] Get your bit error rate to be the same. [45:17.110 --> 45:18.010] Because when you have your... [45:18.010 --> 45:19.310] When you have multiple symbols like that. [45:19.370 --> 45:20.090] You have like... [45:20.090 --> 45:21.030] M symbols. [45:21.150 --> 45:21.990] I say 16 symbols. [45:22.410 --> 45:24.190] The amount of gap in between your symbols... [45:24.190 --> 45:24.530] Uh... [45:24.530 --> 45:25.050] Decreases. [45:25.630 --> 45:25.970] Uh... [45:25.970 --> 45:27.530] And in standard noise channels... [45:27.530 --> 45:29.650] There's a higher probability of getting bit errors. [45:30.430 --> 45:30.870] So... [45:30.870 --> 45:31.170] Uh... [45:31.170 --> 45:31.250] Uh... [45:31.250 --> 45:31.550] When you... [45:31.550 --> 45:34.050] When you get closer and closer to simple spacing... [45:34.050 --> 45:34.910] Than what they call the constellation. [45:35.770 --> 45:36.830] You really want to be ballsy. [45:36.910 --> 45:37.790] What you can do is... [45:37.790 --> 45:38.010] You... [45:38.010 --> 45:39.170] You sample off... [45:39.910 --> 45:40.270] Your... [45:40.270 --> 45:40.650] Uh... [45:40.650 --> 45:41.870] Your phone line... [45:41.870 --> 45:42.850] Into your sound card. [45:43.310 --> 45:44.930] And you can just display it on your screen. [45:45.270 --> 45:45.770] You've got to remember... [45:45.770 --> 45:47.170] Your sound card can sample up at 41... [45:47.750 --> 45:49.230] 44.1 kilohertz, I believe. [45:50.390 --> 45:50.750] Um... [45:50.750 --> 45:51.670] A lot of sound cards... [45:51.670 --> 45:52.110] I mean... [45:52.110 --> 45:54.210] Might be just some specialty cards you can sample higher. [45:54.650 --> 45:56.190] Or if you want to be a real badass. [45:56.390 --> 45:57.030] But I was thinking about Dylan. [45:57.390 --> 45:58.170] This is pretty cool. [45:58.550 --> 45:59.370] This is a... [45:59.810 --> 46:01.830] Hook up a PIC to a USB chip. [46:02.010 --> 46:03.610] And just have the PIC run sampling. [46:03.770 --> 46:05.950] And dump the values down the USB system. [46:06.130 --> 46:07.890] Because USB is a lot faster than anything else. [46:07.930 --> 46:09.850] You really have easy access to it on your system. [46:10.290 --> 46:11.450] And they have these little USB... [46:11.450 --> 46:11.950] These... [46:11.950 --> 46:13.430] Easy Connectivity USB boards. [46:13.430 --> 46:14.150] For like 60 bucks. [46:14.910 --> 46:15.510] And you have like... [46:15.510 --> 46:15.710] You know... [46:15.710 --> 46:16.110] Headers out. [46:16.210 --> 46:17.470] And you just head them out to like a PIC. [46:18.870 --> 46:19.190] And... [46:19.750 --> 46:20.250] That'd be cool. [46:20.330 --> 46:21.070] And you have a sample. [46:21.130 --> 46:22.030] And then stuff it down the line. [46:22.110 --> 46:23.170] And you get a sample of possibly... [46:23.810 --> 46:23.830] Uh... [46:23.830 --> 46:24.010] Like... [46:24.010 --> 46:24.730] I don't know. [46:24.850 --> 46:26.050] Maybe like 1 megahertz. [46:26.150 --> 46:26.810] Or something like that. [46:28.270 --> 46:30.470] You do even crazier schemes. [46:33.330 --> 46:34.610] I got a quick question. [46:35.070 --> 46:35.890] Brian over there. [46:37.490 --> 46:37.870] Yeah. [46:38.210 --> 46:40.710] I was curious to know that you're working a lot of crypto hardware currently. [46:40.790 --> 46:45.430] And doing some stuff for a soon-to-be former employer with Rainbow Technologies CryptoSwift card. [46:45.650 --> 46:45.810] Yeah. [46:46.130 --> 46:47.350] And I was basically wondering... [46:47.350 --> 46:48.430] First of all, what are your opinions on it? [46:48.450 --> 46:49.350] Have you worked with it at all? [46:50.190 --> 46:50.450] Um... [46:50.450 --> 46:51.250] The CryptoSwift... [46:51.250 --> 46:52.330] Which chip does it use? [46:52.410 --> 46:52.870] The Fastman? [46:53.150 --> 46:53.410] Yeah. [46:53.530 --> 46:53.910] I think so. [46:54.270 --> 46:56.650] Well, unfortunately, I'm bound by NDAs. [46:56.730 --> 46:57.650] So I care what I'm talking about. [46:57.690 --> 46:58.150] Ah, right. [46:58.150 --> 46:58.430] Yeah. [46:58.610 --> 46:59.430] It was almost... [46:59.430 --> 47:02.670] But I can tell you that there is no on-chip key storage. [47:02.870 --> 47:05.850] So the keys are lying on the card somewhere if you have full access to the device. [47:06.010 --> 47:07.710] There were two cards that I know of. [47:07.750 --> 47:09.330] One of them did 200 transactions per second. [47:09.510 --> 47:10.070] One of them did 600. [47:10.250 --> 47:13.930] The 200 transactions per second was built in a fault kind of tolerant method. [47:13.930 --> 47:16.330] It had a black box construction so that it was 10 foot hardware. [47:16.630 --> 47:17.870] The other one was just an open. [47:18.010 --> 47:20.870] And because of the heat differential, I assumed it could do more transactions per second. [47:21.050 --> 47:22.850] I have the 600 transactions per second. [47:22.950 --> 47:33.550] And my basic question is that the software that they provide beyond the SDK is more or less geared towards doing Apache web server transactions, SET transactions, SSL, all my notes. [47:33.810 --> 47:39.470] And basically, I was developing drivers at one point for OMBSD 2.7 because they had worked with the high event currents. [47:39.670 --> 47:43.150] And I wanted to see if I could offload just the general libraries onto the CryptoSwift card. [47:43.150 --> 47:44.070] And I couldn't... [47:44.070 --> 47:49.910] There were things that seemed to be from Rainbow that were getting in my way that I couldn't get around somehow in terms of access to the direct hardware. [47:50.190 --> 47:52.190] I was wondering if you could know anything about it or any hints or anything. [47:56.080 --> 47:57.020] That's not a good sign. [47:57.200 --> 48:05.180] Well, I mean, I really hate when crypto companies do this stuff because it bounds our hands and I cannot afford a legal lawsuit. [48:05.420 --> 48:05.920] Right, okay. [48:06.020 --> 48:15.860] I really think we need to, like, just start pounding on their doors to release this information because if the design is worth any salt whatsoever, they should be able to release public data sheets on how to use the card. [48:16.020 --> 48:20.720] I mean, if it's done right, no secrets will leak out of it just because you know how the card works. [48:20.900 --> 48:30.500] Well, that was the thing I was wondering is that it got me gone to thinking the more conspiracy theory aspects of what are the chances that these people are caching keys or storing information that they shouldn't be on the card in some area that you should never have access to. [48:30.500 --> 48:36.380] I mean, not that they can simply do anything with it without doing some very high level kind of network transaction in the whole nine yards, but... [48:36.380 --> 48:46.700] I mean, the whole thing with crypto accelerators is you back end all the cryptographic processes, so stuff isn't lying all over the stack and not being engaged to disk. [48:46.700 --> 49:04.500] So what they provide is a level of security where a remote attacker can't really directly address registers and key storage devices that you may have hanging off of that shit because when you use any type of accelerator, as you know, you just send in a request, [49:04.760 --> 49:06.840] it doesn't... the function in... [49:06.840 --> 49:06.860] Right. [49:07.560 --> 49:10.120] The process doesn't need to know what the key is. [49:10.280 --> 49:11.980] It just says, use this key in this register. [49:11.980 --> 49:15.120] It doesn't know the actual contents of it and then you get the results. [49:15.940 --> 49:17.740] So that's where they're... [49:18.340 --> 49:20.920] I guess that's the functionality they provide, but... [49:21.640 --> 49:25.660] As you know, there's no real added physical level of security. [49:26.500 --> 49:28.080] Specifically with the Rainbow stuff. [49:28.280 --> 49:28.980] Yeah, the Rainbow stuff. [49:29.220 --> 49:32.540] The other question I have is for Rainbow's USB i-key tools. [49:32.820 --> 49:33.540] Have you seen that at all? [49:34.580 --> 49:35.320] Kingpin has. [49:35.420 --> 49:36.560] I can't comment on that. [49:36.720 --> 49:37.180] Oh, right. [49:38.420 --> 49:39.340] But wait a week. [49:39.660 --> 49:40.180] I gotcha. [49:40.300 --> 49:41.300] I'll talk to you after this. [49:43.160 --> 49:45.660] If you guys were listening earlier, you'll understand that. [49:45.880 --> 49:47.680] So wait a week and check the web page. [49:48.460 --> 49:49.780] Let's pass it around a little bit more. [49:49.900 --> 49:51.360] Is there anyone who hasn't asked a question yet? [49:51.700 --> 49:52.540] Over there. [49:53.460 --> 49:56.880] I just wanted to know if you knew about any good sites for... [49:56.880 --> 49:57.560] It's not over. [49:58.340 --> 50:02.540] Any good sites for some Palm hardware that's not coming right from Palm companies? [50:03.300 --> 50:08.320] Like, I heard about some stuff like decoders for key cards and stuff like that. [50:09.980 --> 50:13.000] For Palm hardware, I don't know any offhand. [50:13.160 --> 50:19.540] But if you go to palmgear.com, it's mostly like a software site, third-party application site. [50:19.680 --> 50:24.300] But they also have like a news section there where people will announce their hardware products and stuff. [50:24.300 --> 50:26.180] So go there as the starting point. [50:26.360 --> 50:28.000] And you'll probably be able to find... [50:28.000 --> 50:33.200] There's basically guys working in their garage making hardware devices for the Palm. [50:33.420 --> 50:34.960] So go there first. [50:37.500 --> 50:38.620] Any other? [50:39.920 --> 50:40.820] Yeah, there's a few. [50:41.120 --> 50:41.240] Okay. [50:42.100 --> 50:42.320] I don't know. [50:42.460 --> 50:43.840] Does anyone know how much time we have left? [50:44.100 --> 50:46.220] We need to save time to give out the shirts, right? [50:48.040 --> 50:48.440] All right. [50:48.540 --> 50:48.720] Go ahead. [50:49.040 --> 50:49.440] Okay. [50:49.660 --> 50:50.720] Really quick, two-part question. [50:51.700 --> 51:01.440] First of all, if I have an AC signal coming in between 0.5 hertz and 35 hertz, probably between 2 and 200 microvolts. [51:02.460 --> 51:05.500] I'm getting a lot of noise with the signal, probably from induction. [51:05.880 --> 51:10.540] And I've tried filtering, like a high-pass and a low-pass filter, everything above and below that. [51:10.720 --> 51:12.880] But I'm still getting some noise in the actual bandwidth. [51:13.180 --> 51:15.460] Would you guys suggest any noise-cancelling techniques? [51:15.880 --> 51:17.080] Do you have a sinusoid? [51:17.960 --> 51:18.360] Yes. [51:18.820 --> 51:20.020] It's purely sinusoidal. [51:20.020 --> 51:20.440] Yes, it is. [51:21.200 --> 51:21.880] And what kind of noise? [51:21.880 --> 51:22.780] What does the noise look like? [51:23.540 --> 51:24.660] Like a shot noise? [51:24.860 --> 51:26.580] Or is it digital? [51:29.020 --> 51:31.780] Is this your board or is this like a divided board? [51:31.880 --> 51:32.480] This is your. [51:32.680 --> 51:34.860] How are you routing the power signals? [51:35.000 --> 51:37.940] Are they going by like any clock oscillators or anything? [51:38.900 --> 51:42.500] Right now, I'm just using a function generator to create the signals. [51:42.840 --> 51:45.760] And it's, like I said, a side way for now. [51:45.900 --> 51:47.340] I'm eventually going to mess around with EEG. [51:47.880 --> 51:50.260] Is it a multi-level board or just double-sided? [51:50.420 --> 51:51.080] Just double-sided. [51:51.880 --> 51:58.820] But I think probably because of the wires and everything else that I have running all over place, there might be some kind of weird induction thing going on. [51:59.400 --> 52:02.460] At 35 hertz, I mean, you're talking really low signal. [52:03.320 --> 52:05.040] That is really, really slow. [52:05.260 --> 52:12.740] And you're not going to have to worry too much about, I mean, you're looking at lumped element models for all your systems rather than distributed transmission line models. [52:15.180 --> 52:24.480] And what, I mean, what exactly, I mean, are you sure you're not picking up your noise from, from your actual, yeah, or, but not that, from your actual instrumentation that's reading this? [52:24.880 --> 52:26.820] I mean, I really can't think about it. [52:26.900 --> 52:29.540] Have you looked at, have you used different instrumentation and verified it? [52:29.620 --> 52:30.060] I have. [52:30.540 --> 52:36.660] All right, because when you're dealing with down at 35 hertz, 200, and, what is it, 200 millivolt peak-to-peak or something like that? [52:36.700 --> 52:37.360] 200 to 200. [52:37.740 --> 52:38.100] All right. [52:38.100 --> 52:41.780] So, you really should be able to just tack on a simple RC filter. [52:42.520 --> 52:47.980] I mean, you're not going to, I mean, at your lowest frequency, what did you say, was 5 kilohertz, 5 hertz? [52:48.360 --> 52:50.360] 0.5 hertz, and your highest frequency was? [52:50.480 --> 52:50.780] 35. [52:52.920 --> 52:56.420] You're talking about like a rather large end-to-end bandwidth. [52:56.660 --> 53:08.420] I mean, it's, so you got, you're not going to, like, if you have a signal coming in with 0.5 hertz and it has frequency components on top of it, at like, 5 hertz, 10 hertz, 20 hertz, you're not going to be able to go and, like, notch those out. [53:08.440 --> 53:10.440] Otherwise, you're going to affect your pass band. [53:11.240 --> 53:15.540] I mean, you could, you could build a, a multiple-pole RC filter. [53:15.760 --> 53:17.100] Hell, build something up with an op-amp. [53:17.660 --> 53:19.160] You could build up, build up a good, like, op-amp. [53:19.900 --> 53:21.480] High-common loader injection or something? [53:21.680 --> 53:21.760] Yeah. [53:22.080 --> 53:22.980] We'll take this offline. [53:23.420 --> 53:23.540] Okay. [53:25.160 --> 53:25.800] And, um... [53:25.800 --> 53:27.140] We got to do the last question. [53:27.260 --> 53:28.140] We'll, we can talk to you later. [53:28.300 --> 53:30.980] I mean, we're, we're not, like, going out and disappearing. [53:31.100 --> 53:35.280] Oh, my second question was just, if I could get a shirt, if I could make a really, really bizarre and annoying and scary noise. [53:36.900 --> 53:37.400] All right. [53:37.820 --> 53:38.140] Okay. [53:38.240 --> 53:38.360] You ready? [53:41.420 --> 53:41.760] Ah! [53:42.340 --> 53:42.620] Deal. [53:44.240 --> 53:44.680] All right. [53:44.740 --> 53:45.900] I'll give you a shirt if you shut up. [53:46.840 --> 53:48.140] We got one more after this. [53:48.280 --> 53:48.520] Okay. [53:49.140 --> 53:49.620] Uh-oh. [53:49.720 --> 53:50.960] We have one more shirt. [53:51.140 --> 53:54.020] And there's the guy that did the rap at the movie. [53:54.160 --> 53:54.900] He's over here. [53:55.020 --> 53:56.360] So, we're going to have some competition. [53:56.780 --> 53:59.240] Um, let's take one more really quick question. [54:00.680 --> 54:01.760] If there even aren't. [54:01.820 --> 54:02.940] Oh, there's a hand way back there. [54:03.060 --> 54:03.240] Okay. [54:03.560 --> 54:06.200] Can someone, can someone give that guy a mic who's about to stand up? [54:11.580 --> 54:15.240] I wonder if you've done any, uh, decoding or flex or reflex? [54:16.700 --> 54:17.540] No comment. [54:18.260 --> 54:18.740] Yeah. [54:19.700 --> 54:20.880] Javaman has no comment. [54:21.100 --> 54:21.840] Um, I haven't. [54:21.940 --> 54:26.220] But there's actually, um, an IC made by, I want to say Motorola. [54:26.700 --> 54:29.000] Um, that's an actual flex decoding IC. [54:29.620 --> 54:31.360] So, I don't know the number off hand. [54:31.480 --> 54:34.020] But if you could go to their Motorola site and check out their radio ICs. [54:34.220 --> 54:38.560] Um, you might be able to, to build up some kind of flex decoding circuitry pretty easily. [54:39.080 --> 54:41.260] Um, it is going to need a host processor. [54:41.260 --> 54:44.920] So, you could use a pick or, or whatever you want, um, to do that. [54:45.060 --> 54:47.160] But, I haven't personally, no. [54:47.900 --> 54:48.320] Okay. [54:48.440 --> 54:50.320] So, we have one more shirt. [54:50.640 --> 54:51.720] How many people want shirts? [54:52.600 --> 54:53.300] Oh my God. [54:53.480 --> 54:54.260] These are all pumpkin. [54:55.920 --> 54:56.320] Yeah. [54:56.480 --> 54:57.740] Do you even know what shirts these are? [54:59.240 --> 54:59.640] Okay. [54:59.680 --> 55:02.640] These are pumpkin 99 shirts and this is like the last of the batch. [55:02.840 --> 55:05.480] But, you can get a new one if you're invited to pumpkin this year. [55:05.800 --> 55:05.860] So. [55:06.040 --> 55:06.240] Okay. [55:06.380 --> 55:06.880] How about this? [55:07.140 --> 55:10.200] I want this guy to, to do his beat box. [55:10.520 --> 55:19.240] If someone else, if someone else comes up here and raps along with his beat box, then we'll send, we'll send somebody another. [55:19.720 --> 55:19.820] All right. [55:19.900 --> 55:21.220] Javaman, are you going to have more shirts? [55:21.540 --> 55:22.020] This year? [55:22.240 --> 55:22.440] Yeah. [55:24.440 --> 55:26.100] We'll, we'll send somebody a shirt. [55:26.260 --> 55:28.660] Either a L0pht shirt or something that we can find. [55:28.800 --> 55:30.200] Maybe like a CDC shirt or something. [55:30.320 --> 55:30.920] HNN shirt. [55:31.680 --> 55:34.680] Um, if someone has the balls to come up here and rap. [55:34.900 --> 55:35.300] Oh, yeah. [55:35.400 --> 55:35.900] We have two left. [55:35.940 --> 55:36.620] We have two more. [55:37.020 --> 55:37.360] Okay. [55:37.540 --> 55:37.800] Come on. [55:37.940 --> 55:39.420] Someone, I thought you wanted shirts. [55:40.960 --> 55:41.880] Mogul, are you here? [55:43.500 --> 55:43.860] Mogul? [55:45.840 --> 55:46.200] Mogul. [55:46.200 --> 55:46.340] Mogul. [55:46.440 --> 55:49.480] I know Mogul can like, uh, like freestyle pretty cool. [55:49.660 --> 55:50.800] So, uh, does anyone can freestyle? [55:53.880 --> 55:56.060] You guys must not watch shirts too bad. [55:56.240 --> 55:56.760] Oh man. [55:57.020 --> 55:57.180] Okay. [55:57.620 --> 55:58.820] Well then we'll save a shirt. [55:58.980 --> 56:00.720] So I'll do like 10 seconds of your shit. [56:00.860 --> 56:01.800] Cause that was funny as hell. [56:03.580 --> 56:04.060] Oh, both. [56:43.450 --> 56:44.310] You wanna listen? [56:44.530 --> 56:45.630] But I don't know what to say. [56:45.730 --> 56:46.450] But hell, ho. [56:47.070 --> 56:47.790] Ain't no way. [56:54.660 --> 56:55.300] You got something to say. [56:55.300 --> 56:55.360] You got something to say? [56:55.360 --> 56:56.060] Oh my god. [56:59.290 --> 57:00.510] Alright, that guy gets a shirt. [57:05.760 --> 57:06.080] Thanks. [57:06.660 --> 57:09.060] Alright, so I don't know if we're out of time or not. [57:09.560 --> 57:10.060] If, okay. [57:10.220 --> 57:10.780] Well, we're out of time. [57:10.880 --> 57:12.300] So if you guys have more questions, come up. [57:12.420 --> 57:13.140] Thanks a lot for coming. [57:13.320 --> 57:15.160] And come up here and get our software. [57:15.260 --> 57:16.200] Let me beam you some stuff. [57:16.600 --> 57:18.080] And we have one more shirt, I think. [57:18.620 --> 57:19.660] So we've got more shirts. [57:19.920 --> 57:20.880] So come up for something. [57:21.120 --> 57:21.780] Thanks a lot, you guys. [57:22.140 --> 57:22.480] Hey.