Category Archives: Security

FareBot Update for Android 2.3.3

FareBot is an open-source application written by Eric Butler for Android phones to read the NXP Semiconductor MIFARE DESFire and display balance and trip history information.

Each card has a unique 7 Byte serial number (UID) locked in NV memory. It uses 3DES hardware on the RF-channel with replay protection, and has a 4 Byte message authentication code (MAC) for data authenticity. However, it relies on the application to provide the authentication.

FareBot parses the unencrypted data on the Seattle ORCA and dumps others (e.g. San Francisco’s Clipper). According to the ORCA Card privacy statement…

In order to keep the processing time to several milliseconds when an ORCA Card is tapped, the information on the card is generally not encrypted. However, date of birth or passenger type expiration date, if present, is encrypted.

Would you wait a second if you knew it would mean your transit data was protected?

An update was just released for Android 2.3.3.

…no longer needs internal APIs!

Video: Westboro Church Raises Funds for Anonymous

Anonymous reports that they saw a 3,000% increase in ad revenue after the Westboro Church started their victimization rants.

Anonymous also points out that religious extremist group websites are targeted by other hacktivists (e.g. th3j35t3r) and not always attributable to them.

A live Anonymous attack on Westboro Church is then given as an illustration. How can you tell the difference? Their spokesman repeatedly points out their “mature” and coordinated methods. A dry wit, calm demeanor and persistent sense of humor (lulz), appears to be their signature.

German Police Raid PS3 Hacker House

Authorities performed an early morning raid on a home in Germany and confiscated computer equipment suspected in hacking the Sony PS3.

Originally Posted by graf_chokolo
February 23, 2011 at 11:52 am
Guys, SONY was today at my home with police and got all my stuff and accounts. So be careful from now on.

The suspect soon after released all his work to the public and into torrents.

Originally Posted by graf_chokolo
February 23, 2011 at 12:26 pm
Guys, i don’t joke, it’s serious.
And to prove it, i kept my word and uploaded all my HV reversing stuff.
Upload it everywhere so SONY couldn’t remove it easily. Grab it guys, it contains lots of knowledge about HV and HV procs.

Here is my HV bible: Sendspace.com upload.com 2shared.com < - Coolstuff.rar [164mb]

He then posted the legal documents he was served with and his plans to continue unilaterally work to get Linux on the PS3.

So, SONY you failed again, you took my equipment but my mind is still free and you canot control it. You failed again. They are just tools, i can get new ones and will continue my HV reversing and bringing back PS3 Linux which you took from us. If you want me to stop then you should just kill me because i cannot live without programming, HV and Linux kernel hacking You know who am i and where i live, so come and get me !!!

Sony has been fighting this war for many years. A brief history of important battles was recently posted on Make.

I couldn’t find one location that documented Sony’s all-out war on makers, hackers, and innovators, so I started my own (and it isn’t pretty). The talented artists, designers, and engineers who work at Sony deserve better, and their customers deserve better. Don’t worry, I’m not just going to spank Sony. I’m going to give Sony some ideas to right this ship and also let them know it’s time to reconsider suing George “geohot” Hotz, the Playstation 3 hacker Sony is dragging to court for unlocking his PS3 to run his own software on it.

I find it interesting that the alternative approach that Make advocates is to emulate none other than a company founded by the son of a powerful lawyer who openly despised hobbyists and hackers — Microsoft

Sony should take a page from Microsoft’s playbook and develop a PlayStation SDK for innovators with Hotz. Microsoft saw all the amazing projects and hacks with the Xbox Kinect, and they embraced it.

Bill Gates’ Open Letter to Hobbyists in January 1976 perhaps has more significance now than ever. He not only was proven completely wrong in his assertions about quality in code, but his company has completely and utterly reversed itself; it has embraced hobbyists as innovators and partners to help increase the appeal and expand the market for their products.

Note the tone of this message on Twitter from a Microsoft product manager.

MSoft Tweets for Hobbyist Help

It is yet to be seen whether these fights significantly influence consumer. Microsoft certainly has not fared well in the market when compared with companies that have found a way to turn themselves into media content license warehouses. For what it’s worth, after watching the above events unfold I decided to donate my PS3 to those less fortunate and order Microsoft’s Xbox as a replacement.

Volvo V60 Diesel Hybrid by 2012

Volvo has updated their announcement: expect a 125 mpg hybrid wagon with a 745 mile range and all wheel drive (diesel front, electric rear) to be available as soon as 2012 in Europe. It will debut at the Geneva car show.

The V60 PHEV has three main modes of operation: hybrid, all-electric, and power. The modes are selected by pressing the respective selection button on the car’s center console. A fourth mode, which can be entered at any time and is only used when the car’s traction control system needs it, enables an all wheel drive (AWD) system to give the V60 PHEV sure-footed manners in poor road conditions.

The diesel and electric engines together give 285 horsepower and 472 pound feet of torque; 0-60 under 7 seconds. Ford should have been the one to announce this amazing vehicle, back when they made the stunning Jaguar diesel, but oh well. It could have been a Cadillac, but oh well. It even could have been a group of talented high-school students…but instead here is the new V60:

Volvo V60 Diesel Hybrid

The diesel hybrid has many important advantages over electric or gasoline hybrid vehicles, as I have written before.

First, diesel fuel can be produced by anyone practically anywhere so there is no dependency on a grid, processor, exploration or infrastructure.

Second, it runs on fuel already widely available so there is no range limitation. The opposite, actually, as fuel stations today serve vehicles that can travel less than 400 miles on a tank. With nearly double the range this car can skip a lot of time wasted on recharge and refueling stops. Imagine filling up once a month instead of one a week (gaining at least 0.5 hours a week).

Third, even small diesel engines have the power to handle the weight of a family on vacation. Volvo says it is designed to pull up to 2 tons with a hitch, carry five passengers as well as 11 cubic feet of luggage, all while staying within the designed gross vehicle weight.

This is the exact car I have been trying to find for nearly a decade. Thank you Volvo! My only question is how soon can I buy one.

…will U.S. buyers want a plug-in Diesel hybrid? Diesels have gained more acceptance of late, but we feel Diesels still have a long way to go before the V60 PHEV is received by the U.S. general public with open arms.

Are they f#$%^@@#^ng kidding me?!

I could buy ten of these at sticker price today and sell them in the US for a profit two years from now, guaranteed. When I bought my diesel wagon in 2004 it was less expensive than the gasoline engine. I found four years later I still could have sold it for far more than I paid; it actually appreciated in value while the gasoline model resale price dropped. Craigslist ads have been filled with “TDI wanted”. Mechanics told me year after year they had a line of people asking them where they could buy a new diesel and they offered me cash. On top of all my anecdotal evidence, when Audi and VW diesels were finally reintroduced they (as predicted) crushed the gasoline sales numbers and boosted Audi’s bottom line. The data and trend is obvious. Americans love the new diesel cars.

Yet, some still ask if America is ready for diesel? Please.

The US is more ready than Europe for this technology. Just think about it. The US has wide open roads and long distances, trailers and heavy passengers, tough and rapidly changing driving conditions…a diesel hybrid all wheel drive wagon is the ideal car for America. Imagine commercial fleets that replace their pickups and vans with the efficient and roomy yet powerful design of hybrid diesel wagons and recoup the cost in under three years.

Yes, yes, yes, more than ready. I can think of more than a dozen Americans willing and able to buy one today.

I took a few liberties with their advertising campaign, but I think this might work. It’s goodbye bio-hippies who want to do the right thing; hello cyberpunks who desire innovation in highly-efficient power.

“There’s more to life, that’s why”

Naughty V60