Browsed by
Month: March 2024

Extracting Bitlocker keys in just a few seconds

Extracting Bitlocker keys in just a few seconds

Stacksmashing demonstrates that the communication between the CPU and TPM is unencrypted and can be snooped by attaching wires to the traces between them. This is not new, but now has all the source/board design to make it easier – on old systems with a long known security flaw of exposed traces.

This isn’t really new info. It requires numerous things to be right: physical access to the device and non-integrated TPM with a design flaw. Modern CPUs don’t have this easily exploitable design given the TPM is integrated into the die now. This was somewhat common in early days. At one point just connecting a firewire cable into a Mac let you read the encryption keys out of memory from a sleeping or running Apple.

Additionally, Bitlocker using TPM without pin was cracked years ago using fairly common electronic components. Any secure Bitlocker deployment has long been understood to be using TPM and a pin.

A reminder that security is only as good as its weakest link

Links:

  • https://www.tomshardware.com/pc-components/cpus/youtuber-breaks-bitlocker-encryption-in-less-than-43-seconds-with-sub-dollar10-raspberry-pi-pico
  • https://www.zdnet.com/article/new-bitlocker-attack-puts-laptops-storing-sensitive-data-at-risk/
  • https://github.com/stacksmashing/pico-tpmsniffer
20 minute conversation with a whale

20 minute conversation with a whale

Star Trek IV: The Journey Home saw the Enterprise crew returning to the 20th century to save a pair of humpback whales. During their search, Spock jumped into their tank and communicated with Gracie – a humpback whale. What was science fiction may now have some scientific backing.

A research team (who called themselves Whale-SETI) successfully held a ‘conversation’ with a humpback whale named Twain for about 20 minutes.

Before you get too excited, all they did was play back a recorded humpback “contact” call. Twain approached and circled their boat, responding in a conversational manner to the whale’s greeting signal. Twain consistently matched the interval variations between each playback call.

I don’t know if I’d call it rocket science or really communicating by playing back a recording – but it is an interesting first start with some experimentations around timing/latency.

Articles:

Talking Strips

Talking Strips

Here’s a fun science toy: Talking Tape Strips. The plastic strip has groves cut on it so that if you run your thumbnail across is, it plays back a little recorded sound.

Definitely very low fidelity and apparently takes a good bit of work to get it right, but pretty interesting little toy.

Genius: AI generated comic books

Genius: AI generated comic books

I gotta hand it to Nathan Truesdell. He has a whole line of AI based coloring books – that likely took him all of an afternoon to create. It’s highly likely it only took him an hour or two with some prompts to make the line art. He then probably worked with an online physical book publisher – who may even be printing them up on demand for him to avoid handling stock or shipping – and now sits back and watches the money roll in with pretty much zero effort.

He didn’t even bother to fix the 7 fingers and thumb.

Critics don’t create progress or change things

Critics don’t create progress or change things

“It is not the critic who counts: not the man who points out how the strong man stumbles or where the doer of deeds could have done better. The credit belongs to the man who is actually in the arena, whose face is marred by dust and sweat and blood, who strives valiantly, who errs and comes up short again and again, because there is no effort without error or shortcoming, but who knows the great enthusiasms, the great devotions, who spends himself in a worthy cause; who, at the best, knows, in the end, the triumph of high achievement, and who, at the worst, if he fails, at least he fails while daring greatly, so that his place shall never be with those cold and timid souls who knew neither victory nor defeat.”

—Theodore Roosevelt
Speech at the Sorbonne, Paris, April 23, 1910

Ultimately, it is the person that DOES something who ultimately changes the world. Everyone else sits on social media or their couch and lives with the changes the doers have made to the world.

This doesn’t mean those people are right – we’ve seen plenty of examples of that. If you don’t like what the doers of things are out there are doing – or how society is going – you need to get out there and get into the arena.

Realistic FIRE experience

Realistic FIRE experience

The FIRE movement, which got its start in the later 90’s, has been a hot trend the last 10 years – especially with high earning tech workers. It’s given rise to aggressive savers and hustle culture. There’s many good things about the movement as it got many young people thinking about their financial lives and how they want to live – instead of just following the crowd.

It does, however, require you to ascribe to a set of pretty restrictive and demanding principles: aggressive saving and often near-poverty level living standards that examines each penny spent. This method definitely has helped many, but it has some pretty big caveats.

FIRE methods used to be based on living as cheaply as possible and saving almost your entire income so you can retire early. Many of the adherents talk of living on just a few dollars a day eating the cheapest bulk foods they can buy (beans and rice every single day) and examining every expense with a view to shave every penny off. While this worked for many early 20’s tech workers, it isn’t possible for everyone and so variants have popped up. There’s many that claim they are retired at 35, but still keep part-time jobs (barista FIRE). Others retire early on low amounts but do so by living extremely simply and cheaply (lean FIRE).

Retire at 35

Gwen Merz started down the FIRE road aggressively and lived the FIRE mantra. She wanted to retire at 35 with $635,000. She got a job at a Fortune 100 and she saved $200,000 in just 5 years – an extremely impressive feat in expensive the Washington DC only making $80k/year. She saved 70% of her income and even started her own side hustles with a podcast, owning rental property, and running an Etsy shop. All of this sounds like the FIRE dream come true.

“I really bought into the hustle culture that is part of society and I got really burnt out.” 

But what’s it all for?

As time went on, she left her main job to be her own boss in her side hustles. Unfortunately, the side hustles fizzled and the constant grind burned her out. 9 months later she returned to her regular full-time job.

After that, she noticed others around her “weren’t afraid to spend [money] on themselves for their own improvement.” She asked herself, ‘Why am I trying to save all this money? I don’t look my best, I am not taking care of myself as well as I should, what’s kind of the point?’

She bumped down her savings and got a personal stylist appointment after realizing she didn’t know what looked good on her. After seeing a huge improvement, she wondered what other changes she should make that would also “make a really big difference in how I felt around other people.”

“My bank account really benefited from the actions that I took in my 20s, but I think my social life suffered an equal amount”

She noticed the intensity of her saving also curtailed her social life. “It’s really hard to be a single woman in your 20s in dating and not wanting to spend any money…it turned off a lot of people who might have otherwise been probably a pretty good fit for me.”

Know why are you saving

Merz has since stepped back from aggressive FIRE living. She still uses some FIRE budgeting tips and spreadsheets from a decade ago but no longer turns to them as much. That’s because money is no longer the number one priority it once was.

At age 33, she has still managed to save a amazing $400,000 and plans on retiring at age 55. She immediately paid off her car loan, and saves 10% in her 401k each month, but “I don’t deprive myself unnecessarily anymore. Stepping it back really benefited me and gave me the flexibility and the ability to say yes.”

Knowing what is worth spending on is as important as saving for it

But even more important was that Merz realized why she was drawn to the aggressive FIRE mentality. Merz grew up in a single parent home that struggled with necessities – and it created financial trauma that can draw some to the FIRE movement. Her struggles being broke drove her to want to have enough money to weather any storm life can throw at you and instilled a value that money is to be saved for the future. But she realized. “if you don’t learn how to spend it before you get to that point [later], then you’re gonna have some issues.” Those issues seem to largely include understanding what is worth spending money on compared to just having it.

Now she tells a different story. Despite all the saving, “It would be worthless if I didn’t learn how to prioritize other aspects of my life like my health, safety, and happiness.”

“To somebody who’s going super hard for early retirement at age 30, I would really encourage them to examine their motivations behind their actions,” she says. “​​And, are they retiring from something or are they retiring to something? Because those are pretty different concepts.”

Article:

Jubensha

Jubensha

About 10 years ago in China, a very simple murder mystery party game (Guillaume Montiage’s Death Wears White) made it to China, and caught on like wildfire. It started a craze of murder mystery party games called Jubensha that is sweeping the nation.

In the US, escape rooms really became a thing in the late 2010’s and peaked in 2019 with just over 2300 different escape rooms shops. At the same time, Jubensha is looking to be a phenomenon that has displaced karaoke as the 3rd largest recreational activity in China after movies and sports. The estimate is there were over 30,000 jubensha shops hosting these gaming events in China by 2021.

What is jubensha? Jubensha is a form of scripted role-playing game much like a murder mystery party game in which the players role-play different character roles they are given. But it’s grown to much more than simple murder mystery parties. The stories have become extremely involved. They’ve expanded to include deep relationship, romance, horror, fantasy, magical, futuristic, and all kinds of other themes. The breadth and creativity has gotten staggering and it’s caught on like wildfire. Jubensha has also become wildly popular TV shows (Who’s the Murderer), have video game tie-ins, as well as expanded from simple parlor games to costumes and even live action weekends in themed locations.

According to Chinese players, it’s the social aspects of meeting new people and playing very different characters that is a huge draw – to the point it often overshadows its case-solving and gaming elements. One might be able to describe Jubensha as gamified social gathering of strangers. Part of this comes from the fact that jubensha games are almost always written to require 3 females and 3 males. Dating profiles now commonly say things like “No to hookups, yes to jubensha”. This should not really be a surprise in a country in which Covid lockdowns the last few years have been the most extreme. People are craving social interaction; and these games give young people the opportunity to act out roles and emotions that might not otherwise be socially acceptable.

Beyond the social aspects, the creativity of the stories is also apparently amazing. Characters and stories unraveling for you and other players in ways that you might never expect. The game guidance might tell you to role play in certain ways, only to find out that what you were role playing was an unreliable narrator and your own character isn’t who you thought you were. Motivations you were given in a relationship story (say making sacrifices for a loved one) might turn out to reveal a dynamic completely different than what you thought you were doing.

This isn’t all without some problems. There are no real rules to jubensha because half the fun is getting into stories without knowing where it will go. This means you have to trust the moral compass of the authors and hosts of the game. So what happens if they game doesn’t align with your values or puts you in a very uncomfortable situation?

As jubesha writers try to make a name for themselves, it has been noted that some jubensha horror games have had gratuitous levels of gore and violence to increase shock value. Another theme that is surprisingly prominent involves sexual assault. Chinese gamers largely shrug this off, claiming they have no problem with darker themes like murder and sexual assault – but it has surprised many western reporters. Unfortunately, this all means as the story unfolds you may find yourself having to role play around these themes. You may even becoming a character, an accomplice of a character, or even the victim of a character that is doing things or you might find extremely offensive or distasteful. So far there are largely no content warnings on many games.

To add complications, the Chinese government has also noticed this firestorm of popularity and are starting to review and clamp down on the industry to ensure stories adhere to accepted party standards. Recent TV shows are putting up disclaimers and one even has real life judges appear to reveal what the real world crimes and punishments would be.

Sadly, almost none of these game scripts are available in English – which is a real shame. I’m personally very curious what some of the stories are.

If you like to check what this looks like on Chinese TV, it appears multiple seasons of “Who’s the Murderer”, that become the start of the craze, are on Youtube.

Articles: