Decoding the obfuscated bash script on a Uniqlo t-shirt
tris.sherliker.net
tris.sherliker.net
Imagine having to return a t-shirt because that malfunction!
— I don't understand why are you returning this, was the size wrong or you didn't like it?
— No, there is a syntax error at line 37 that makes it impossible to run, and I'm concerned people on the street may think I promote unsafe bash scripting.
.. was trying to think of a way to somehow incorporate "k-rad" but couldn't figure anything out haha ( https://www.urbandictionary.com/define.php?term=k-rad )
I reverse engineered it to a unobfuscated version a few years ago:
https://gist.github.com/olooney/a89db3932b089925b71b68d7e9f2...
He's done a ton of other great ASCII visualizations as well:
edit: it’s impressive as all hell but like
https://archive.org/details/1983-01-compute-magazine/page/96...
OCR? oh my sweet summer child, you cannot know the days we spent typing in raw code from a magazine, and the joy when it finally ran.
echo "Fgnaq+sbe+Qrzbpenpl!" | tr 'A-Za-z+' 'N-ZA-Mn-za-m '
On a Samsung S24U I held down the "circle to search" homescreen button which brings up the AI tools interface (I don't know what it's officially called), held down on the text and copied the whole thing in one shot.
It took like 2 seconds.
There's something else a lot stranger going on, though. It is a proper monospace font, but the typesetting on the shirt is not. There's some kerning going on (I noticed it especially in the 'Iy' pair), and also it appears that narrower characters such as 'i' take less horizontal space. If I had to guess, I would say that it was set with a tool such as "optical kerning" in InDesign.
We use monospace fonts for a reason, they stack in a grid nicely. But within the confines of that grid there is room to shift a character left or right a bit which may lead to a nicer to read monospace. (it is equally likely to lead to a hideous mess, every time a letter would shift left it would leave a larger space right)
https://github.com/githubnext/monaspace/blob/main/docs/Textu...
It's the main reason I use monaspace as a font.
And: doesn't this result in text that "jumps around" as you type?
It's a fun subtle adaptation to keep close to the typewriter-like experience of the app.
I think though it could likely be easily OCR'd if you give the image to any decent agentic harness with a good vision model, e.g. newest Claude/GPT ones, and tell them to split the image per lines, and then just OCR each line individually.
I wonder if the script itself was written by an LLM before obfuscation? There seem to be a lot of comments in it, but in this case it's still ok :)
The congratulations text is both in English and Japanese. Contains a single heart emoji.
There was an intention to have a cyan to orange gradient, but the range starts in an ANSI block, ends halfway through the 256 color block and 256 terminal colors are not arranged like a gradient at all.
There's no sleep at the end of the loop where I feel like an LLM would add that defensively.
In my mind an AI would do something the most popular way even when that's not appropriate.
A human might do things in an unpopular way even when that's not appropriate.
Can't remember his name now, there's been so many distractions...
He even sent the now-deceased man a birthday card with some words that strongly suggest he knew what was going on..
(.../s)
It's not that difficult, our industrial OCR model read it correctly on its first attempt with default parameters. The characters are easily separable, there is no structured background (think expiration dates on yogurt aluminum lids) that confuses the reader, there is no almost-text-like texture anywhere that would clutter the result. The font is also nice and standard.
That, plus engineering and support: a robust implementation, deployment on almost any system, fast and good long-term support so your factory doesn't stop for too long if something goes wrong etc.
(Obviously those applications don't need the engineering and support, and probably would not be a good fit for your company.)
I wonder what it's doing under the hood to get such good performance?
Looked it up, you put mouse over text, then just select and copy it - very cool!
https://support.apple.com/en-gb/guide/safari/ibrw20183ad7/ma...
On meetings I will often take a screenshot of the URL someone is presenting. I’m then able to just open the image and click the URL in the image.
Preview has pretty good background removal.
Notes will transcribe audio from audio files.
The seamless cloud sync between devices is much appreciated too.
From the prototype shown here [0], and the way they talk about their process, I sincerely doubt it. Especially as they mention trying to make it hard for AI to handle the output.
The AI not handling the output relates to the final base64 output on the T-shirt (which other comments in this thread mention manually keying in or TFA discusses in the context of OCR). So, that is just not relevant to the question.
What made me start to wonder, personally, was that the output seems identical if you use "♥PEACE♥FOR♥ALL" instead of the version with internal repeats. IF there is any point to that "manual expansion of the cycles", IMO that deserves a comment much more so than "# Calculate length of text; text_length=".
Also, that `echo -n ...` followed by `echo ""` instead of just plain `echo` in the first place seems like the kind of copy-pasta code LLMs generate. Then again, regular devs also write pretty bad copy-pasta code.
There is also this the weirdly "broken down" calculation with 3 `bc` invocations not 1 as if it was translated from a language with more arithmetic/special function power than bash.
There is also the color scale stuff done in the loop instead of outside (except the one color=$(..)) which seems very unnatural and also very like machine translation.
Also, at least for me, on my bash-5.3.15(1), `char="${text:t % text_length:1}"` does not work to slice out the multi-byte UTF8 heart symbols, but it sure does look like the kind of thing an LLM would do translating from a python3 script (such as something like https://news.ycombinator.com/item?id=48830669) into bash.
Another thing is, as others here have observed, there is nothing "gradual" about the xterm-256 color cube. So, "gradient" is a misnomer and exactly the kind of weird things LLMs do when they cobble text together.
Finally, all the tput stuff the script does instead of just "print x spaces" really smells like a human description of the side scroll in the video game graphic he shows inspired him somehow LLM-corrupted/complexified into the vertical scroll terminals do.
None of this is conclusive, but the video mentions 2023..2025 as when he did it and given that he was a designer and his concerns more visual than code-oriented, I'd have to say I disagree with your sincere doubt and I do strongly suspect the decoded script was very likely LLM-circa2024-generated, possibly with light post-edits by hand.
All the smells you pointed out, just look like a Python dev approaching bash without fully understanding it.
also, referring to Linux as "the language of the internet" when bash isn't particularly suited for internet tasks also smell like "excited windows Python dev"...
Anyway, he seems like a very nice fellow and I wish him and almost all T-shirt designers well. That bash script just gave me a lot of pause. (And even that seems possibly downstream of him being nice and doing it himself to spare his team from what he called a "FrankenProject".)
{ Also, it was my own Py version which I mostly did in case anyone wanted to actually run the thing after such interest was expressed on this thread. :-) }
I already said regular devs and LLMs can both gen copy-pasta. That said, being "mostly" a Python dev, asking some LLM to translate to bash for him seems even more likely to me. Only he or those close to him knows for sure. You & I cannot settle it here conclusively (as also said).
I also noted from the video that the ♥s (hearts) worked on whatever version of bash he tested with though it failed for me (which is why I wrote that Python). And his terminal title bar is switching between `tput` and `bc` and such meaning that what he was demoing was not some Python script. ¯\_(ツ)_/¯
EDIT: Ah..another resolution of the hearts is to not run in an LC_ALL=C environment. Oops! `LC_ALL=en_US.UTF-8 bash ..` fixed it. Oh well, I think the Python script is nicer in almost every way. E.g., you could |head -n60 and send it to a line printer/dot matrix reminiscent of the 1980s computers he shows in the video, although your printer driver would have to strip the color escapes with a `sed` or maybe https://github.com/c-blake/bu/blob/main/noc.nim. ;-)
I seem to recall seeing an Akamai-branded base64'd shell script on a white shirt pre-2021(?), so unless they've changed the code since then, I doubt it...
My code usually clocs at 50/50 (or thereabouts)[0]. Has, since my very first real engineering project (in 1987)[1]. I discuss in detail, here[2].
But one reason that I like LLMs, is that they help me to write even more documentation. I have found that I can instruct an LLM to revise my documentation, and make it even more effective.
[0] https://github.com/ChrisMarshallNY (My GH profile. Pretty much everything there, is like that -has, since long before LLMs were a broken rubber on the drug store shelf).
[1] https://littlegreenviper.com/wp-content/uploads/2022/07/TF30... (Downloads a PDF)
https://github.com/RiftValleySoftware/RVS_Spinner/blob/d44ee...
An LLM would have commented `// Create temporary UI view.`
Completely redundant comments like this are a classic hallmark of LLMs:
# Set frequency scaling factor
freq=0.2
Dunno why I have been downvoted for stating the obvious.Also from my brief look at one file it looks like you have 50% comments because you have a gazillion comment separator lines.
I worked for a Japanese company that accreted comments.
Yeah, lots of whitespace.
Especially in a case like this, I would definitely write a lot of comments to aid in understanding, thus increasing trust so people would try it out and tinker with it.
The comments can be more cute/awe inspiring for people who aren't as familiar with bash but like solving puzzles as well.
IDK what the author was using but I feel like he could have shared how his OCR attempt went, but I am thinking he tried some naive OCR tools.
All in, you should have a non-corrupted string in 10-15 min.
It’s not the final word, since automation has other benefits: documenting the procedure’s steps, reducing human errors, increasing consistency, etc.
[0] https://github.com/GL-Kageyama/UNIQLO_Akamai_T-shirt_Code
Basically it just clusters same characters and asks the human to find the problems, which is easy when you're looking at a series of pictures like ssssss5sss.
The UI is kinda least-effort. Should ask a modern AI agent to make it look nice and intuitive, sometime maybe.
sleep 0.1
in the loop so that as this prints in a terminal it is actually readable; any modern terminal will scroll so fast you can't see the message in flight.Slowing it to a 10hz refresh makes it look great.
perl -e '
"$a="etbjxntqrdke";
$a=~s/(.)/chr(ord($1)+1)/eg;
print "$a\n;"'
It's cursing. Don't run it if it might offend you.Upon seeing this, I decided to golf and came up with a shorter version:
perl -e "print chr 1+ ord for split //,'etbjxntqrdke'" raku -e 'say "etbjxntqrdke".comb.map({chr .ord + 1}).join'raku -e 'say "etbjxntqrdke".comb.map(*.succ).join'
That's better than half the tech howtos out there.
I typed it out myself, and I liked the comment in Japanese text, which sort of added another layer of obfuscation (even though pasting it in an online decoder was trivial, it still was something more to decode, a level deeper). Also, I can now spot non-ASCII blobs in base64-encoded text, which is a skill I hadn't ever considered was possible before.
In case the author is reading: The decorative feather images are between 2MB to almost 5MB in size. Compression might be in order to save users time and bandwidth, and make the site look less broken while the images are partially loaded :)
It’s a movie plot.
https://www.uniqlo.com/us/en/products/E480814-000/00?srsltid... (US)
base64: stdin: (null): error decoding base64 input stream
#!/bin/bash
# Congratulations! You found thu eastur ugg!#B��O��
# おめでとう��M�ぇM�す!隣C��わM�サ�#ライ����見でM�������!O��
# Define thu tuxt to anima|e
text="♥PEACE♥FOR♥ALOB��PEACE♵FOR♵ALL♵PEACE♥FOR♥ALL♥PEACE♥FOR♥ALL♥PEACE♵FOR♵ALL♥"
# Get termb�al dmmensions
cols=$(tput cols)
linus=$(tput lines)I was expecting some cool js deobfuscation tricks, so to put nicely I’ll just say that my disappointment is immeasurable and my day is ruined.
#!/usr/bin/env python3
from os import environ; E = environ.get
from math import sin
from time import sleep
text = "♥PEACE♥FOR♥ALL" # The text to sine-scroll animate
nText = len(text) # Number of utf8 chars
freq = 0.2 # Frequency scaling factor
color0 = 12 # xt256 Color cube segment 12..<208
color1 = 208; nColor = color1 - color0
(w, h) = (int(E("COLUMNS", 80)), int(E("LINES", 24)))
t = 0
while True:
x = (w/2) + (w/4)*sin(t*freq) # x pos via sine value
x = max(0, min(w - 1, int(x + 0.5))) # bound to tty width
color = color0 + ((nColor*t)//h)%nColor # cycle colors
ch = text[t%nText] # Get char & Use xterm-256 color escs
print("%*s\033[38;5;%sm%s\033[m\n" % (x, "", color, ch))
t += 1
sleep(0.1) # original used bc shell outs to rate-limit
As mentioned in https://news.ycombinator.com/item?id=48830634 , the heart symbols did not otherwise even work for my bash and some have commented on liking the screen saver.Surely this would use whatever font the virtual terminal profile was set to? I don’t know of any method to choose a virtual terminal font from bash and don’t see any code that addresses it?
I'd take that bet considering it's got close to thousand upvotes and on front page of HN
It should be on a separate line.
#!/bin/bash eval "$(base64 -d <<< '...Might have to do something like that for a verse on the next Carolina Code Conference shirt. Been trying to figure out a good way to pull in cybersecurity.
> May the m×s/t² be with you
Never thought I'd learn shell tricks from the back of a fast-fashion t-shirt, but here we are.
$ wget https://archive.org/download/PowerPointViewer_201801/PowerPointViewer.exe
$ cabextract PowerPointViewer.exe
$ cabextract ppviewer.cab
$ open CONSOLA*.TTF
and use Consolas on Linux, but it's not available by default.What they're suggesting is that a lot of their users are logging into an Akamai Linux box from a Windows machine, and therefore aren't "real Linux geeks".
You want to do that cleanup regardless why you exit.
happy to see that the base64 was valid and did something cool! ^_^
https://www.wired.com/2000/08/court-to-address-decss-t-shirt...
well, i guess no peace for me then
Pretty sure any AI can solve it in 20 seconds.
I bet 10$ I'd spend less time typing it from the t-shirt. And I wouldn't boil two kettles of water in the process.
But hey, AI makes you 10x more productive, I suppose
My bet is against manual OCR with various engines + finding mistakes later using an LLM.
This seems to work pretty well
The old one was: https://www.uniqlo.com/us/en/products/E459561-000/00
The guy who founded the new political party Team Mirai also wears it frequently: https://en.wikipedia.org/wiki/Takahiro_Anno
Very wow. Shame they assumed everyone has "bc"...
#!/usr/bin/awk -f
BEGIN {
# Split on spaces so multi-byte utf8 works
nText = split("♥ P E A C E ♥ F O R ♥ A L L", tmp, " ")
for (i = 0; i < nText; i++) text[i] = tmp[i + 1]
color0 = 12; color1 = 208 # xterm-256 color cube range
nColor = color1 - color0 # Could be a pretty gradient
w = ENVIRON["COLUMNS"]; if (w == "") w = 80
h = ENVIRON["LINES"]; if (h == "") h = 24
freq = 0.2
for (t = 0; 1; t++) {
x = int(w/2 + w/4*sin(t*freq) + 0.5) # x pos ~ sine
color = color0 + int((nColor*t)/h)%nColor # cycle colors
ch = text[t % nText] # cycle chars
printf("%*s\033[38;5;%dm%s\033[m\n", x, "", color, ch)
fflush()
# system("sleep 0.1") # awk has no builtin sleep
}
}
As to "bug reports", the T-shirt published script also fails with LC_ALL=C for me as mentioned else-thread.FWIW, I think ancient practice to reach for `bc` instead of `awk` or even the arithmetic built into shells often annoys. The only reason I keep `bc` installed at all is to compile Linux kernels. Someone had some patch set to Linux to eliminate this very dependency many years ago now.