My business card runs Linux and Ultrix (2022)
dmitry.gr
dmitry.gr
Second thought: If I received this card, I would think twice about attaching a homemade USB device to anything. Who knows what it might do? [1]
Third thought: I should let people I know that this is becoming possible.
Fourth thought: Wait a minute, any USB device is potentially risky, not just homemade ones. Carry on!
.. 1. https://usbkill.com/
I have a Raspberry Pi devoted to the purpose of plugging unknown USB devices into in order to do a security check on them.
If it kills the R-Pi, no big deal. If it doesn't, then you have the power of Linux to interrogate the device with and spot suspicious behavior.
Primarily what I'm looking for is if the capabilities of the device match what I expect them to be (does this flash drive -- or even just a random USB cable -- also represent itself as a user input device?), and to spy on the USB packets for things like keystroke replay, bitstreams that don't match what would be expected (virii installations, unusual behavior if the storage device thinks that it is being booted from, etc.)
It is not comprehensive. Just a sanity check.
Ideally, you’d find the malicious payload. It’s probably not hidden so well that it can’t be found by a security researcher.
My reasoning for using the R-Pi is that it's disposable, so if the USB device turns out to be an electrical USB-killer, it doesn't kill any hardware that really matters to me.
Against a very sophisticated attacker? Maybe not, but it doesn't matter for my purposes. My concern is the most likely kinds of attacks, which are not terribly sophisticated. It's really more of a sanity check than a comprehensive security audit.
No security can ever be 100% effective. Like all security measures, this is just one layer intended to cover attacks I am most likely to be exposed to.
In other words, if I'm protecting against governments and other well-funded entities or skilled and determined hackers, I wouldn't be using this alone. I'd be using it in conjunction with other security processes, such as not attaching unknown USB devices to my systems at all, or at least not to ones that matter or aren't permanently isolated from my other machines.
We settled on a CRU Wiebetech write blocker and a minimal sandboxed distro (that could reboot to a clean slate in a couple of seconds) with little more than a kernel for which we could activate and deactivate USB modules.
Conclusions:
USB is terrifying! :)
Buying USB things in the internet is even more scary!!
[0] https://www.solent.ac.uk/degree-shows/students/helen-plews-2The file signature listings shown on page 80 are most likely spurious (false matches). The first give away is why there would be over 2000 microcode artifacts, the next is that all of the inspected fields are bogus, including the size field (some in the GBs). In theory you could purposefully obfuscate that, but then why would you carry any tell of microcode at all. Much more likely this is just patterned data that happens to match that file magic. Anybody with experience with binwalk knows how common this is.
Same goes for the mcrypt(?) headers. Blowfish 448 CBC 8-bit happens to be all 0s. Another very common false positive (matches \x00m\x02). Also look at the offsets carefully. Seems more like a match confusion.
As for encrypted appearing data at all, not too surprising if someone is selling used drives and naively wiped them. But it isn’t clear that encrypted vs compressed data was identified.
There’s also a fundamental misunderstanding of what a write blocker is/does repeated. "Results indicated the presence of firmware ... in the machine code of the unallocated spaces of the storage device.". Machine code of the unallocated spaces makes no sense.
In general: microcode attacks are sophisticated attacks. Anybody carrying these out is unlikely to leave such an obvious smoking gun. Not saying impossible, but it would give any serious researcher pause to scrutinize their work.
Also not saying you won’t get shitty crap from random sellers and should buy random junk, but I’d take this paper with a large grain of salt.
Rather a shame that page with the abstract has excessively large & linespaced body text which makes it hard to actually read on mobile... that the chat feature assumes you must be a student not anyone else... and the Contact Us is buried many levels deep in the nav... hence me giving up and telling you about the above here.
If the point of the exercise is a proof of concept as an expirement then awesome.
If it's supposed to be something you can hand out to stakeholders as a business card then it's probably not that useful.
The first time I saw a PCB business card, I thought it was pretty cool. Then I saw a PCBA business card (with components!) and was amazed. But now I just see them as unnecessary e-waste for vanity. Business cards get read, scanned, and tossed. At least the impact of a piece of paper and ink is small compared to fiberglass resin, copper foil, ENIG, and solder mask. This example isn't even that great as a business card: the typography and contrast make the contact information poorly legible compared to the component silkscreen. Amazing PCB art (https://grandideastudio.com/portfolio/projects/the-worlds-th... is the best I've seen) makes creative use of the different contrast, translucency, and textures between exposed and masked copper, masked and unmasked bare FR4, and silkscreen layers. It's a very constrained graphic design problem that takes a good eye.
Internet: "Pssh. Not pretty enough. Next!"
Bring something thats genuinely unique or something that really encompasses the spirit of what a hacker was when I was growing up you just get garbage responses like the parent.
Note, however, that this does not work in threads about the Vision Pro goggles that people will chuck in the bottom of their closets (next to their Oculus and Google Glass) once the novelty wears off.
I think if somebody was talking to you, and saw your site, you'd get great offers regardless of the physical sample though.
> The first time I saw a PCB business card, I thought it was pretty cool. Then I saw a PCBA business card (with components!) and was amazed.
What about all those people who don't use LinkedIn?
I'm not asserting that non-LI tech people are more than a minority, but there seem to be quite a few of them.
The DECstation 3100 was nice. It was very fast at the time it came out, and had the huge CRT with the GUI desktop, mouse, etc., a few years after the Mac. It also my first time seeing a Unix workstation, which was fantastic at the time, since I'd only ever touched Unix on BBSes and on random old underpowered timesharing boxes with old dumb terminals. (It was an internship, I was in charge of the porting lab for some very expensive software, and our first DECstation 3100, hostname `screamer`, was probably our fastest at that moment, so it doubled as my first workstation.)
Ultrix was a decent Unix, and DECwindows was nicer than the stock X11 found on many other Unix workstations. Not as consumer-products polished and friendly as the Mac, but obviously a more powerful OS, and more flexible distributed window system.
Another nice thing about Ultrix was that it could talk both TCP/IP and DECnet. I used this to rig up transparent access to our VAXstation 3100 VAX/VMS units remotely from people's Sun workstations in their cubes. (And without trying to get purchase authorization for something like Multinet for the VAXstations.)
(This gateway later evolved into a small part of the Common User Environment (CUE) that I developed as an over-enthusiastic intern's evenings&weekends project, which gave familiar and powerful UI, features, and accesses, no matter which workstation or porting system you were in front of. Which was before the Unix workstation vendors got together to make CDE, but got their lunch eaten by Windows NT on the engineering desktop, and eventually by Linux on the dotcom servers. And you tied an onion on your belt, which was the fashion of the day.)
This article of course demonstrates much more intimate familiarity with the DECstation 3100 than I ever needed to have, and is very impressive.
Looking back, isn't it kind of crazy that a) such a magazine existed b) it was on the magazine rack at random bookstores in the middle of nowhere?
And when I finally got a 486/50 that could run Linux, I spent hours tweaking my desktop env to try to make it more workstation-y (OpenLook or Motif-ish), purely on aesthetic grounds not for practical purposes :-)
DECstation 3100 -> various later SPARCs -> RS/6000 -> HP 9000/7xx -> more SPARCs -> DEC Alpha
Yeah, I kept going back to Fwvm for a long time, after trying various things. The only thing that replace it long-term was Xmonad. (I tried i3wm, but went back to Xmonad, which seems a bit more opinionated in a good way for how I want to manage mostly transient windows on laptop.)
My business card runs Linux - https://news.ycombinator.com/item?id=32077823 - July 2022 (133 comments)
My business card runs Linux, yours can too - https://news.ycombinator.com/item?id=32071593 - July 2022 (3 comments)
Similar but different:
A DIY business card that runs Linux (2019) - https://news.ycombinator.com/item?id=36176198 - June 2023 (58 comments)
My Business Card Runs Linux - https://news.ycombinator.com/item?id=21871026 - Dec 2019 (397 comments)
For example mitxela did a business card that acts as a stylophone
It would nice to get a bit more of an overview of the finished article - photo of completed card, or a video or screenshots of what happens when you plug it in etc. Or perhaps somehow I missed all this!
The images of the PCB have silk screen explaining what happens when you plug it in.
(Am that dmitry)
https://aphyr.com/posts/353-rewriting-the-technical-intervie...
- development env with simulator - development board - production hardware
Great story, I liked the documentation of the step by step how to do it. It was nice that you had the details of the process including the good, the bad and the ugly. Lots of these stories are "bought CPU, Memory, a few caps; built a board, did some software; here is final product". I got a feel for the hours you spent and the dedication to seeing it through. As a former employer (retired) it would have caught my attention.
Congrats on a great project, hope it's been helpful to get you cool jobs. If you ever make it to the Philly area, let me know, I'd love to see it run.