Obviously, in most cases, proper "hacking", as in breaking in to someone's system without permission, is illegal.
However, it is quite fun to be able to do some "hacking" in the sense of working out how something works, and breaking in to it and doing things it was not designed to do. It is also fun to document how it works, even when it is using a protocol from the last millennium. In fact, in some ways, that is what makes it extra fun as it is nostalgic too...
So, today, I am playing with the Honeywell Galaxy alarm system. You see them everywhere - a very popular system. We use them, and slightly hate them to be honest. Even with full installer access they are impossible to make do some thing sensibly, even though they are actually very flexible. They have some really annoying quirks - like you can disarm the alarm using a key fob (good), but that does not also open the door, you have to use the key fob again to open the door. You can also set the alarm using the key fob (holding it to reader), but that also unlocks the door whilst doing it which may not catch (depending on type of lock). Little things like that just make it that extra bit annoying.
However, the actual bits that go with a Galaxy system are not bad - there is the keypad (as per picture) with display, the Max readers which work a door entry system, and RIOs which provide a range on input / output for sensors like reed switches and PIRs. They all sit on an alarm bus which is typically untwisted screened wire carrying 0V/12V power and A/B of an RS485 bus. Different panels have different number of busses and allow different number of devices.
My hacking today is understanding the protocol on that bus, and it has taken me most of the day. The main delay was many hours trying to work out how to make the RS485 USB lead switch to transmit and drive the bus. My mistake was assuming that I needed a a separate control like using RTS/CTS or some such (as some devices do). What I did not realise is the UART itself had a TXDEN output which does the driving and in fact I had a faulty cable - arrrrg. Change to different cable and you literally just write bytes to the port (from linux) and it enables the transmission side and sends them on the bus cleanly. Obviously that was the first thing I tried, but, faulty cable. It could not be simpler.
The nostalgia really has started to kick in though - I remember busses like this from, well, the 90s maybe, perhaps even earlier. We are talking standard serial protocol, 8n2 at 9600. The messages have no length indicator, just using timing to find end of message. There is a simple 1's compliment sum on the message for checking. No sequence numbers or acknowledgement or retransmission - it seems to use a state based logic, so sending the same message repeatedly until something needs to change. A really noddy and really old fashioned protocol. I suspect the "legacy" is strong with this one.
There are a few lovely quirks, like the keypad codes "0" to "9" as 0x40 to 0x49, but codes key "A" and 0x4B and key "B" as 0x4A, LOL.
Anyway, I have not only been able to work out the protocol but also send messages, even ones I should not be able to - like sneaking a status from a Max reader saying that someone has pressed the door exit button during the 10ms turn around time before the reader actually responds! Hence making a door open. Also sneaking in some messages to the keypad/display for fun, or changing the LEDs on the max reader. Basically, if you get access to a bus on one of these systems you can do all sorts.
OK, so why?
Well, I am thinking of making some open source linux code to work with the Honeywell / galaxy kit. Allow an open source alarm panel to be made, even. I suspect the protocol documentation and low level tools are what we would release, and maybe we make a high level panel and sell that as a solution, or maybe we make that open source, or like asterisk - a community designed alarm panel. Linux based would allow use of small industrial computer boards that could fit in a box with a PSU, battery and RIO. USB to RS485 allows plenty of busses with no problems. If you wanted to do something on the cheap you could even use a Raspberry Pi, but they tend to be less reliable than you would want for an alarm panel.
Of course this could allow a panel with modern config, using a web based interface.
It could allow integration with IT systems, like allowing SNMP of status feeding in to Nagios.
It could allow alarm state reporting by SMS, and email, even tweet DMs.
I suspect that getting insurers to be happy is a trick. We decided long ago that, at the office, contents insurance was more expensive that making the place secure. This applied even though we did have a burglary with several expensive machines stolen. So we do not have an insurance company breathing down our neck if we want a more custom alarm system. At home, the insurance company said the premium is no different, so they did not care if this was a custom alarm system or not. I suspect, even without insurance endorsed alarm system, there are plenty of opportunities for a system like this, and if it does get at all good and popular they may well endorse such a system. After all, the components are all proper off-the-shelf parts, standard RIO and PIRs and so on.
Of course, there are many other non alarm systems, such as purely door entry systems or time recording systems, which could use these same components.
What can I say? watch this space and we'll see what we can do.
First step is probably publishing the protocol.
It is fun.
2017-07-04
2017-07-03
Moral high ground?
I like to do things right, and I do like to do the "right thing", and so it will be no surprise that after the last post I had concluded before we started that I needed to let the supplier know. Interestingly, many of my friends said I was mad to, and I should just exploit them as much as I could.
The supplier is Tesco, and buying 3 bottles of 1l Southern Comfort from Tesco was being charged at silly prices. Normally £28.50, discount to £20.00 and actually charged at...
Initially to my surprise, 50p a bottle.
Then 12p a bottle
And today, they only had 2 left, 10p a bottle.
Seriously, this is silly.
Contractually I am happy to accept the price they have chosen and take the goods. But morally, this is a mistake, surely, should I continue. Well I have to wait for them to get more in stock, clearly. But why not keep buying?
I wanted to do the right thing so I asked them...
To my surprise they said no!
OK well I know it clearly is not a promotion so I followed up.
No reply, so some more... minor typo...
Two days later, no reply, so more...
And still no reply.
If they really do not care, should I not order more? Surely if they are happy to sell at that price, I should just keep ordering.
Update:
I did nag them again, still no reply, but looks like it is fixed now and charging £20 a bottle!
The supplier is Tesco, and buying 3 bottles of 1l Southern Comfort from Tesco was being charged at silly prices. Normally £28.50, discount to £20.00 and actually charged at...
Initially to my surprise, 50p a bottle.
Then 12p a bottle
And today, they only had 2 left, 10p a bottle.
Seriously, this is silly.
Contractually I am happy to accept the price they have chosen and take the goods. But morally, this is a mistake, surely, should I continue. Well I have to wait for them to get more in stock, clearly. But why not keep buying?
I wanted to do the right thing so I asked them...
To my surprise they said no!
OK well I know it clearly is not a promotion so I followed up.
No reply, so some more... minor typo...
Two days later, no reply, so more...
And still no reply.
If they really do not care, should I not order more? Surely if they are happy to sell at that price, I should just keep ordering.
Update:
I did nag them again, still no reply, but looks like it is fixed now and charging £20 a bottle!
Store cards
I am puzzled...
Someone I know of had their email hacked, and, of course, that means that the hacker could use email based password resets on various systems. They proceeded to do so, and thankfully left enough of a trail to work out what they did so the passwords could be sorted out. It does highlight the importance of email passwords being secure, but the puzzle is not that - it is what they did...
They reset passwords on a load of supermarket logins.
Now, I have only used tesco.com, but I imagine they are all much the same. You cannot order from them without using a card. Yes, tesco store my card but only display the last 4 digits and want the CV2 on every order - so if someone logged in to tesco as me they could not order anything on my card.
Even if they could, somehow, order, what then? I am not sure for collection but I assume they would want to see the club card and/or the bank card when you collect, so that is not going to work. And if they go for a delivery, they they create a log of where they had things delivered.
I suppose they could see my address, but why change multiple supermarket accounts - you only need one to see that.
So really, what is the point in "stealing" someone's supermarket logins?
Am I missing the bleeding obvious here or something?
Someone I know of had their email hacked, and, of course, that means that the hacker could use email based password resets on various systems. They proceeded to do so, and thankfully left enough of a trail to work out what they did so the passwords could be sorted out. It does highlight the importance of email passwords being secure, but the puzzle is not that - it is what they did...
They reset passwords on a load of supermarket logins.
Now, I have only used tesco.com, but I imagine they are all much the same. You cannot order from them without using a card. Yes, tesco store my card but only display the last 4 digits and want the CV2 on every order - so if someone logged in to tesco as me they could not order anything on my card.
Even if they could, somehow, order, what then? I am not sure for collection but I assume they would want to see the club card and/or the bank card when you collect, so that is not going to work. And if they go for a delivery, they they create a log of where they had things delivered.
I suppose they could see my address, but why change multiple supermarket accounts - you only need one to see that.
So really, what is the point in "stealing" someone's supermarket logins?
Am I missing the bleeding obvious here or something?
2017-06-30
Moral guidance
The fact I am posting this probably says something about me :-) I am interested in people's views.
I ordered some goods on-line from a large company (does the fact that it is a large "faceless" company actually make a difference?). I ordered several things at once, and one item three times. It was on the web site at £20 which is actually an "offer", normally more.
The total order was around £90 and so I was puzzled when my card only appeared to be charged around £30. The goods arrived, along with a detailed receipt. Everything was there, and this particular item was listed as 50p each.
My guess is some sort of mistake... but...
I checked the terms and conditions, and they state quite categorically that the price shown on the web site and order form (i.e. the £20 price) is for guidance only and that the actual "price" is what they charge when they send the goods (i.e. the 50p price). So under their terms the price is indeed only 50p.
In fact, they even state that they have a temporary issue showing unit prices wrongly and they state categorically that the selling prices are correct. They say this in their terms.
So I have to assume the 50p charge is correct, it says so in the terms that they wrote. It is an excellent deal for the goods in question. So much so, I have ordered 3 more for tomorrow to see what happens.
Am I wrong to accept the 50p price they are charging, even though they state categorically that they are correct in their terms?
Should I tell them?
Should I not try and buy more at the low price?
Should I tell my friends the details so they can benefit?
Yes, I am sure a lot of people would not ponder the right or wrong of this situation for a moment.
Update...
It is clearly a system issue, or a genuine (bloody good) offer, as today I was charged 12p each.
I have asked them on twitter if I should tell them if charged a much lower price than the web site, and they said I do not need to.
I'm not going to take the piss. I'll see what I get charged next time I want to order some.
I ordered some goods on-line from a large company (does the fact that it is a large "faceless" company actually make a difference?). I ordered several things at once, and one item three times. It was on the web site at £20 which is actually an "offer", normally more.
The total order was around £90 and so I was puzzled when my card only appeared to be charged around £30. The goods arrived, along with a detailed receipt. Everything was there, and this particular item was listed as 50p each.
My guess is some sort of mistake... but...
I checked the terms and conditions, and they state quite categorically that the price shown on the web site and order form (i.e. the £20 price) is for guidance only and that the actual "price" is what they charge when they send the goods (i.e. the 50p price). So under their terms the price is indeed only 50p.
In fact, they even state that they have a temporary issue showing unit prices wrongly and they state categorically that the selling prices are correct. They say this in their terms.
So I have to assume the 50p charge is correct, it says so in the terms that they wrote. It is an excellent deal for the goods in question. So much so, I have ordered 3 more for tomorrow to see what happens.
Am I wrong to accept the 50p price they are charging, even though they state categorically that they are correct in their terms?
Should I tell them?
Should I not try and buy more at the low price?
Should I tell my friends the details so they can benefit?
Yes, I am sure a lot of people would not ponder the right or wrong of this situation for a moment.
Update...
It is clearly a system issue, or a genuine (bloody good) offer, as today I was charged 12p each.
I have asked them on twitter if I should tell them if charged a much lower price than the web site, and they said I do not need to.
I'm not going to take the piss. I'll see what I get charged next time I want to order some.
2017-06-26
What is the scam here?
We have a (non) customer the keeps trying to buy a mobile number to receive texts.
Our automated credit control systems trap him every time! He makes new postal addresses, email addresses, bank details, telephone numbers, etc, but the systems are working well. The latest one flagged the account in 15 different ways!
Every time, he orders a mobile number and has some system send him a text from "AUTHMSG" to him which looks like Your Valued Opinions verification code is: XXXXXX.
He does not get the text due to the account being flagged as suspicious.
Obviously he wants a UK mobile number to get some code to do something, but I am at a loss as to what the scam is here.
I tried googling but still did not find what the scam is...
It is annoying the accounts staff, reversing out the account and invoices. 29 attempts so far!
P.S.....
Treading on thin ice? I am MD of a communications company - I (and the company) have to respect the Data Protection Act, and obviously as a company we take things very seriously, not just in terms of law but in terms of morals and ethics. In this case we have someone I cannot really identify as a person - but I have managed to identify (correlate) multiple fraudulent attempts as probably the same person that is trying to act illegally - so is there personal data? I posted the slightly redacted content of a message, is that personal data? Even so, there are exceptions in the legislation for prevention and detection of crime, so is that valid? It is a good point and maybe a fine line, on which I hope I am the right side.
At the end of the day, if the individual in question feels aggrieved, I am more than happy for them to identify themselves and raise the issue with me or the company. There are several outstanding invoices as well as possible criminal charges for fraud and breaches of the Communications Act that await if you feel I have breached your privacy - please go ahead!
Our automated credit control systems trap him every time! He makes new postal addresses, email addresses, bank details, telephone numbers, etc, but the systems are working well. The latest one flagged the account in 15 different ways!
Every time, he orders a mobile number and has some system send him a text from "AUTHMSG" to him which looks like Your Valued Opinions verification code is: XXXXXX.
He does not get the text due to the account being flagged as suspicious.
Obviously he wants a UK mobile number to get some code to do something, but I am at a loss as to what the scam is here.
I tried googling but still did not find what the scam is...
It is annoying the accounts staff, reversing out the account and invoices. 29 attempts so far!
P.S.....
Treading on thin ice? I am MD of a communications company - I (and the company) have to respect the Data Protection Act, and obviously as a company we take things very seriously, not just in terms of law but in terms of morals and ethics. In this case we have someone I cannot really identify as a person - but I have managed to identify (correlate) multiple fraudulent attempts as probably the same person that is trying to act illegally - so is there personal data? I posted the slightly redacted content of a message, is that personal data? Even so, there are exceptions in the legislation for prevention and detection of crime, so is that valid? It is a good point and maybe a fine line, on which I hope I am the right side.
At the end of the day, if the individual in question feels aggrieved, I am more than happy for them to identify themselves and raise the issue with me or the company. There are several outstanding invoices as well as possible criminal charges for fraud and breaches of the Communications Act that await if you feel I have breached your privacy - please go ahead!
2017-06-22
Badly written RFCs
There are many badly written RFCs, but I encountered one annoying one today
Update: Thanks for the comments, and I concede that the next page refers to "value" being quoted. Even so, the whole idea of using BNF syntax is to be unambiguous, and this is still therefor a rather badly written RFC!
So, for those less techie, "RFC" is "Request for comment" which is a sort of passive way of pushing proposals on other people when the Internet first started. The "standards" we now follow are all RFCs. There is a slightly more formal process that can promote an RFC to an actual standard.
The idea is that the RFC says how something works, especially when it is a protocol. People they try to make their systems work to the RFC.
Now, there is always a degree of ambiguity, and so there is a really good principle which has worked well for the Internet which is that you should be tolerant of what you receive and strict in what you send. Basically, if the standard says to do something you should aim to be as accurate and correct as possible in what you send. However, when someone sends something to you, and there is some flexibility in what you accept, you should try to be flexible and work out what it means.
This has allowed the slightly flawed and imperfect implementation of many standards.
Today's issue was an RFC over MIME email, specifically RFC 2387 which apparently has status of "proposed standard", and is 19 years old.
We were sending a MIME object in an email that is multipart/related with a "type" field, specifically type=text/html which says that the "root" of that object is of a type text/html. All well and good. Indeed, a type= attribute is mandatory in RFC2387.
The problem is that the email did not work properly when emailing yahoo addresses. But other email systems did work. We experimented and found the "fix" was to send type="text/html" instead.
Now, I am not happy about this! The RFC has this to say on the type attribute :-
This defines that type is specified (after a ;) has the text type, then the character = and then the type and the character / and then the subtype.
So, unless we are saying that the type is "text and the subtype is html", sending type="text/html" is simply wrong.
The problem is the examples in the RFC (and errata), such as :-
(the errata added the missing ; on the end of the first and third line)
Where the hell did those quote marks come from?
So, yahoo are not being tolerant in what they accept, they are actually expecting non standard data, and we were being strict in what we sent, but to make it work we are now being non standard.
There really is not much worse than an RFC where its own examples do not comply with the RFC!
I have submitted and errata to the RFC editors for this.
Update: Thanks for the comments, and I concede that the next page refers to "value" being quoted. Even so, the whole idea of using BNF syntax is to be unambiguous, and this is still therefor a rather badly written RFC!
So, for those less techie, "RFC" is "Request for comment" which is a sort of passive way of pushing proposals on other people when the Internet first started. The "standards" we now follow are all RFCs. There is a slightly more formal process that can promote an RFC to an actual standard.
The idea is that the RFC says how something works, especially when it is a protocol. People they try to make their systems work to the RFC.
Now, there is always a degree of ambiguity, and so there is a really good principle which has worked well for the Internet which is that you should be tolerant of what you receive and strict in what you send. Basically, if the standard says to do something you should aim to be as accurate and correct as possible in what you send. However, when someone sends something to you, and there is some flexibility in what you accept, you should try to be flexible and work out what it means.
This has allowed the slightly flawed and imperfect implementation of many standards.
Today's issue was an RFC over MIME email, specifically RFC 2387 which apparently has status of "proposed standard", and is 19 years old.
We were sending a MIME object in an email that is multipart/related with a "type" field, specifically type=text/html which says that the "root" of that object is of a type text/html. All well and good. Indeed, a type= attribute is mandatory in RFC2387.
The problem is that the email did not work properly when emailing yahoo addresses. But other email systems did work. We experimented and found the "fix" was to send type="text/html" instead.
Now, I am not happy about this! The RFC has this to say on the type attribute :-
This defines that type is specified (after a ;) has the text type, then the character = and then the type and the character / and then the subtype.
So, unless we are saying that the type is "text and the subtype is html", sending type="text/html" is simply wrong.
The problem is the examples in the RFC (and errata), such as :-
(the errata added the missing ; on the end of the first and third line)
Where the hell did those quote marks come from?
So, yahoo are not being tolerant in what they accept, they are actually expecting non standard data, and we were being strict in what we sent, but to make it work we are now being non standard.
There really is not much worse than an RFC where its own examples do not comply with the RFC!
I have submitted and errata to the RFC editors for this.
2017-06-21
Amazing
Basically, I have done it again - I found something that looks cool on thingiverse and decided to take it to the limit and do it myself. The thing was a simple labyrinth box. It was quite cool.
So I thought I would give it a try, and the issue is not really the actual 3D artwork and OpenSCAD stuff, it is the maze itself. How to make a maze that is challenging. Instead of a fixed thing that has a maze, I wanted a random maze so each one is different. OpenSCAD cannot quite manage that. So I used the source (Luke) and wrote C to make OpenSCAD.
The first thing is that this maze inherently wraps, i.e. mostly a maze is in a simple rectangle, but this is on a cylindrical shape so the X axis wraps. Easy enough for the maze generation logic.
My initial thought, and how I have made mazes before, is you have a path from origin and a point moves randomly where it can (i.e. to an empty cell). If it finds it cannot move at all it back tracks. This is a very simple algorithm to fill the whole space of a maze with no loops. The "no loops" part is pretty common as a basic principle. Maybe I'll deliberately throw in a loop some time.
My concern was that this made a maze that was going to be too simple. Or that did not "look nice", so I added a few variations.
For a start, when moving, I made a bias to continuing in a straight line rather than left or right. 25% of the time it continues, else it is random (including continuing). This makes for nice long runs in the maze.
I then added a bias for back-tracking even when not a dead end. This did make the maze more interesting but created a lot of one unit blind dead ends which are annoying and boring. You want your blind dead ends to be "interesting" and so long.
So I started again and made it that a set of all cells in the maze with somewhere to go, are picked from at random to continue the maze. This is not following the last point and backtracking, it is saying we have a set of points that can move, and picking one and moving.
This created a lot of short blind paths, hmmm... OK next trick was to add a random bias to use the last added point and continue from there, but not all of the time (just 75%). This made much longer blind runs which is what I wanted. I actually made it wander like this 100% initially until it hit a dead end or the top layer, then 75% leaving 25% of the time it picks any node at random to continue from making a fork.
Finally the trick was to then make the exit at the top the cell where it is the longest path from the start. This helped avoid accidentally having a straight line from start to finish or something that simple.
I am actually quite pleased with the result, which you can find at thingiverse. It is interesting how slight biases and choice of algorithm can massive change the nature and appearance of a maze.
P.S. You will note that there are a number of example STL files on that thingiverse entry. Obviously, as I have been tinkering, changing the artwork slightly, and changing the maze design logic slightly, I have wanted to update the thingiverse entry. But this is a set of about 10 designs as examples, so a tad tedious to load each one in to OpenSCAD and make an STL file. Thankfully OpenSCAD (even on a Mac) has a command line option, so with a simple script (and waiting several minutes) I can make a set of files automatically!
P.P.S. I did do a bit more tinkering, not just the artwork (changing from round to polygonal outer shape), but also to the maze. The one "knob" in the lid was not that good so I made the maze mirror on to the other side so allowing two knobs - this simply means as I generate the maze I add the same to the far side, but the maze can still going around the cylinder interacting with its other self even. I made it general to allow N paths. I also tweaked the bottom (end point) of the maze to be a right angle. I even scripted rendering several random boxes to make a video :-
Update: I had a call to make the maze more complex. One of the simple steps I did is, as you progress the maze, for each cell, you also have an indication of "length" which is how far from the start, increasing one each time. Then, for the exit at the top layer I pick the point with the greatest length.
However, this is not quite enough, and so I changed the logic to start the maze in the middle, and pick both the entry and exit as longest from that point. Unfortunately this allowed a common path from the start point and then a short path to entry and exit. But it did seem to make a more interesting maze overall.
The solution is creating the maze then working out the start point and exit point that create the "best" path. I decided simple length is not good enough, we want complexity. Scoring is therefor also based on how many branch points we pass as well as length.
I also made the middle a ring all the way around on the taller mazes to make a staging point where you had lots of possible options to escape, all but one of which are wrong.
Subscribe to:
Posts (Atom)
Wallot inspector
What is fun with a nice UV ink jet printer is on what you can print... One thing is a bank card. This is now my Monzo card, oops. Yeh, I can...
-
Broadband services are a wonderful innovation of our time, using multiple frequency bands (hence the name) to carry signals over wires (us...
-
For many years I used a small stand-alone air-conditioning unit in my study (the box room in the house) and I even had a hole in the wall fo...
-
This is an appeal for (sensible) comments. I am working on revised A&A tariffs for broadband. For those that are not sure how they wor...








