Sign in

Ian @ Dangerous Prototypes

@buspirate.bsky.social
1.4K followers 45 following 656 posts

Ian@dangerousprototypes. Slacker hacker, Instructable author, Hack a Day writer, Purveyor of hardware at Dangerous Prototypes and DirtyPCBs. Organizer of Hacker Camp Shenzhen. I made pink capacitors once too. We're also on: @buspirate@mastodon.social

PostsRepliesMedia
Ian @ Dangerous Prototypes @buspirate.bsky.social · 11/12/2025
This should be the final production version of the DDR4 adapter board. Did a last minute revision to add reverse polarity protection to the 9 volt programming voltage connection. Prototypes are in production now, after a final test we'll make a small batch.
050
Ian @ Dangerous Prototypes @buspirate.bsky.social · 09/12/2025
Automate your Bus Pirate with Rust programs using a crate that neatly abstracts the BPIO2 flatbuffer interface: github.com/DangerousPro...
020
Ian @ Dangerous Prototypes @buspirate.bsky.social · 05/12/2025
A Python library for Bus Pirate automation. This simple wrapper for the BPIO2 FlatBuffers interface makes scripting easy. Includes examples for I2C, SPI, and 1-Wire protocols - and a SPI flash read/write demo. Much cleaner than raw FlatBuffers. tinyurl.com/ykxdpv7v
tinyurl.com
BPIO2 FlatBuffers Interface
Bus Pirate FlatBuffers interface (BPIO2) documentation
050
Ian @ Dangerous Prototypes @buspirate.bsky.social · 04/12/2025
Control your Bus Pirate from PC software with the simple FlatBuffers interface. Flatc(c) provides premade tooling for a bunch of languages including C/++/#, Python, Rust, Go, Java, etc. Include the tooling in your app/script and skip the low level protocol stuff.
170
Ian @ Dangerous Prototypes @buspirate.bsky.social · 03/12/2025
As of this morning the DDR5 adapter plank is on back order for about 2 weeks. You might be able to score one at a distributor (PiHut UK) earlier. The DDR4 plank I'm working on now should be in production just in time for a messy Spring Festival delay :)
A PCB with two long sockets that can hold DDR5 SODIMM and UDIMM RAM modules.
030
Ian @ Dangerous Prototypes @buspirate.bsky.social · 02/12/2025
DDR4 UDIMM (desktop style)RAM stick arrived for a final test of the adapter plank. The new Bus Pirate 'ddr4' command correctly identifies the module by reading the SPD data. I'm going to make a few tweaks to the adapter, and this should be the final production revision.
110
Ian @ Dangerous Prototypes @buspirate.bsky.social · 28/11/2025
Big moment: will magic smoke escape? DDR4 wants 9 volts on address pin 0 before it allows changes to write protection. We're using a bench supply, to be replaced by a 9 V battery later. The High Voltage is applied when needed by an optocoupler and Bus Pirate pin.
110
Ian @ Dangerous Prototypes @buspirate.bsky.social · 26/11/2025
Made a prototype adapter for reading/writing previous gen DDR4 RAM sticks. Dumping the contents via I2C is easy. We can tell that this is a DDR4 SODIMM made in 2018 by Kingston with Micron DRAM chips. S/N ACR24D4S7S8MB-4. There's some manuf. specific data too which may be extended profile info.
190
Reposted by Ian @ Dangerous Prototypes
Robert Lipe @robertlipe.bsky.social · 31/10/2025
Ian, to your GPS resource, please consider adding the cross-platform, free, and open-source GPSBabel. CLI and GUI. Twenty four years & counting. It can reduce, interpolate, toss out junk, etc. Coming soon (merged to Git): Kalman filter www.gpsbabel.org Specfically www.gpsbabel.org/htmldoc-deve...
gpsbabel.org
GPSBabel: convert, upload, download data from GPS and Map programs
131
Ian @ Dangerous Prototypes @buspirate.bsky.social · 31/10/2025
Anyone going to 39C3 in Hamburg this December? It's my first, and I hope we get a chance to meet up if you'll be there too!
021
Ian @ Dangerous Prototypes @buspirate.bsky.social · 30/10/2025
New I2C quick connect adapter plank! One board to rule them all - supports Qwiic, Stemma (3P/4P/QT), Grove, Gravity, and Breakout Garden connectors. Quick prototyping with the Bus Pirate and your favorite solder-free ecosystem.
160
Ian @ Dangerous Prototypes @buspirate.bsky.social · 29/10/2025
New tutorial: Learn NMEA GPS modules with the Bus Pirate! Connect any GPS module via UART, decode NMEA sentences in real-time, and extract coordinates/satellite data. Includes a full teardown of common NMEA sentences. docs.buspirate.com/docs/devices...
130
Ian @ Dangerous Prototypes @buspirate.bsky.social · 28/10/2025
Time to upgrade a 10-year-old GPS! New modules track all 4 GNSS systems (GPS/BeiDuo/GLONASS/Galileo) for faster locks & better accuracy. Ublox NEO-M9N ($10) is common and solid, but the ZhongKeWei ATGM336H-F8N76 ($6.50) is cheaper with more frequencies/satellites. Any other recs?
160
Ian @ Dangerous Prototypes @buspirate.bsky.social · 27/10/2025
The latest Bus Pirate firmware has a usbpd command to probe and trigger USB C power delivery. Select a fixed voltage profile, or specify a voltage if PPS is supported. We used a generic AP33772S breakout board for development, but a Bus Pirate USB PD plank prototype is in the works.
0110
Ian @ Dangerous Prototypes @buspirate.bsky.social · 24/10/2025
USB-C PD enables fast charging with fixed & programmable voltage outputs. Using Bus Pirate + AP33772S, I found charger labels don't always match actual PD profiles. This laptop charger lists 5/9/15/20V, but also supports 3.3-21V programmable output—unlabeled. More below..
171
Ian @ Dangerous Prototypes @buspirate.bsky.social · 23/10/2025
DDR5 RAM Serial Presence Detect chips tell a computer about the RAM specs. It has 1024 bytes of EEPROM storage, temperature monitoring, and pass-through access to a Power Management IC (PMIC). I wrote a very hands on low-level demo on how to access the chip using a Bus Pirate
180
Reposted by Ian @ Dangerous Prototypes
OldMattyB @oldmattyb.bsky.social · 22/10/2025
I love the expandability of the Bus Pirate. Fully open source with a great community, it's easy to add new functionality to interface to different hardware and busses.
041
Ian @ Dangerous Prototypes @buspirate.bsky.social · 22/10/2025
It took 3 revisions to get right, but the DDR5 RAM SPD adapter is now available. Use with the Bus Pirate to read and write DDR5 SPD EEPROMs. HSA pin is grounded so blocks can be unlocked (offline mode). UDIMM (desktop) and SODIMM (laptop) supported.
1102
Ian @ Dangerous Prototypes @buspirate.bsky.social · 15/07/2025
Super happy with the new Bus Pirate HEX viewer! Valid ASCII and non-zero values are highlighted. Quiet mode (-q) hides addresses for easy paste into HEX editors. Dump range can be specified, and paging is enabled by default. Used in all data dump commands: DDR5 tool, SLE4442...
171
Ian @ Dangerous Prototypes @buspirate.bsky.social · 10/07/2025
Grabbed some SHT3x and SHT4x temperature and humidity sensors for a Bus Pirate demo. SHT3x is a significant upgrade to the ancient SHT2x with a wider temperature and humidity range, and higher accuracy at the extremes. SHT4x slightly improves on the SHT3x specs, but is mostly...
170
Ian @ Dangerous Prototypes @buspirate.bsky.social · 08/07/2025
The typical 8 pin memory chip has ground (GND, VSS) on pin 4 and power (VCC) pin 8. It doesn't appear to be a formal standard, but more a tradition. Modern EEPROMs (24x, 25x), flash (25Qx), SRAM (23x) and FRAM all have a similar power n ground pinout. However there are a couple oddities out there...
120
Reposted by Ian @ Dangerous Prototypes
Bruce ("grymoire") Barnett @grymoire.bsky.social · 04/07/2025
My #jumperless + #BusPirate all pimped out and ready to party! @buspirate.bsky.social @architeuthisflux.bsky.social
052
Ian @ Dangerous Prototypes @buspirate.bsky.social · 04/07/2025
Has anyone used a Microchip UNI/O single wire EEPROM? Protocol looks like Manchester encoded I2C. Debuted >10 years ago (when 1-Wire was already a zombie) with talk of a bunch of devices. Today there's just a couple EEPROMs, and a few hits on GitHub. Single wire must kill it...
220
Ian @ Dangerous Prototypes @buspirate.bsky.social · 02/07/2025
About twice a year I need a through hole resistor kit, but this is also fine... The Bus Pirate eeprom command is now read/write/dump/verify/testing 1-Wire EEPROMs.
030
Ian @ Dangerous Prototypes @buspirate.bsky.social · 30/06/2025
The Bus Pirate I2C EEPROM command is coming along, so I wanted to see if we can use a common code base to work with SPI EEPROMs. I narrowed the list of SPI EEPROMs down to this set with common page sizes and addressing methods. Most SPI EEPROMs have write protection blocks...
141
Ian @ Dangerous Prototypes @buspirate.bsky.social · 27/06/2025
Working on a command to dump, read, write, verify, erase and test I2C EEPROMs. Held off on doing this because there are so many EEPROM variations, but it should work with every 24XX EEPROM from Microchip (née ATMEL) and their major competitor, uh, also Microchip.
130
Ian @ Dangerous Prototypes @buspirate.bsky.social · 25/06/2025
Picked up a handful of new breakouts recently, one was a FRAM chip. Ferroelectric RAM is a fairly new type of memory with the speed of SRAM and the persistence of EEPROM. It’s still much more expensive than EEPROM, flash or SRAM, but check out these benefits:
3130
Ian @ Dangerous Prototypes @buspirate.bsky.social · 05/06/2025
DDR5 UDIMM and SODIMM modules on a prototype breakout board. Motherboards detect DDR5 via a "SPD hub" chip with an I2C/I3C interface. A 128 byte register configures the hub and temperature sensor. Standard tables in a 1024 byte EEPROM describe how to configure the RAM.
230
Ian @ Dangerous Prototypes @buspirate.bsky.social · 03/06/2025
Bus Pirate documentation update is complete! A new automated system captures and converts terminal output to screencasts and HTML to keep the docs up to date. Docusaurus is slow and v3 choked on a lot of Bus Pirate output, so we ported the whole site to super fast Hugo Docs.
260
Ian @ Dangerous Prototypes @buspirate.bsky.social · 18/03/2025
RP2350 supports a second NOR flash or PSRAM. Trying PSRAM, but QSPI only sends 0xFF. Here it should send 0x9F and read 6 bytes to get the chip ID. Sending any value results in 0xFF on the bus. Not sure if this is a hardware or software issue.
0142
Ian @ Dangerous Prototypes @buspirate.bsky.social · 14/03/2025
Tom Nardi tries out the new Bus Pirate I2C sniffer feature: hackaday.com/2025/03/12/i...
hackaday.com
I2C Sniffing Comes To The Bus Pirate 5
While the Bus Pirate 5 is an impressive piece of hardware, the software is arguably where the project really shines. Creator [Ian Lesnet] and several members of the community are constantly working…
050
Ian @ Dangerous Prototypes @buspirate.bsky.social · 13/03/2025
A minor convenience change for the mode command. You can already bypass the mode menu by specifying the mode number. Now you can also specify the mode by name (case insensitive). This should help scripts stay stable long term, even if the order of modes changes.
021
Ian @ Dangerous Prototypes @buspirate.bsky.social · 12/03/2025
Alternating between a space heater and the freezer to characterize the leakiness of some Schottky diodes.
An assembled Bus pirate 5 pcb sitting in the freezer.
183
Ian @ Dangerous Prototypes @buspirate.bsky.social · 11/03/2025
Sniff I2C data up to 500kHz with the latest Bus Pirate firmware. The pico-i2c-sniffer project uses all four state machines of an RP2040 PIO to spy on I2C bus traffic. Useful for reverse engineering, debugging, and long duration event logging.
5222
Ian @ Dangerous Prototypes @buspirate.bsky.social · 06/03/2025
Forgot the set-up photo. Here's a Bus Pirate connected to a CPLD development board scanning for the JTAG pins.
A Bus Pirate connected to a CPLD development board scanning for the JTAG pins.
060
Ian @ Dangerous Prototypes @buspirate.bsky.social · 06/03/2025
Exciting integration for the Bus Pirate! bluetag automates JTAG and SWD pin finding. Easily scan for JTAG/SWD interfaces by entering JTAG mode, enabling power, and using the bluetag command. Demo video in the next post.
261
Ian @ Dangerous Prototypes @buspirate.bsky.social · 05/03/2025
Using the Bus Pirate, Matt successfully used power fault injection (glitching) to bypass UART password authentication on an Arduino Uno. This is a great way to try your first glitch hack. greybeardwhitehat.blogspot.com/2025/01/succ...
0131
Ian @ Dangerous Prototypes @buspirate.bsky.social · 26/02/2025
Factory boss hates our button caps! Our new injection molding factory popped the Bus Pirate button caps under a microscope and found some ugly defects.
140
Reposted by Ian @ Dangerous Prototypes
OldMattyB @oldmattyb.bsky.social · 26/01/2025
More glitching with the Bus Pirate timing and generating the glitch. This time targeting an Arduino board to better describe and explain the process. The @buspirate.bsky.social is so flexible for so many things!
A view of my work surface: one can see a Bus Pirate 5 with a "blank plank" attached. That plank has a FET used to output the glitch pulse. There's a small scope showing the glitch pulse. The Arduino board is connected to the plank with a short coax cable.
031
Ian @ Dangerous Prototypes @buspirate.bsky.social · 24/01/2025
The latest Bus Pirate firmware now supports AnalysIR, popular program to capture, analyze and replay infrared remote control signals. You will need an infrared demodulator and infrared diode, or use the IR Toy plank.
161
Ian @ Dangerous Prototypes @buspirate.bsky.social · 15/01/2025
Here's a sneak peek at some exciting updates to the Bus Pirate infrared mode: With irrx, you can capture infrared remote control signals as a sequence of on (MARK) and off (SPACE) times in the AIR (AnalysIR) format and save them to a file. With irtx, you can replay these recorded sequences.
2135
Ian @ Dangerous Prototypes @buspirate.bsky.social · 14/01/2025
Check out the Bus Pirate enclosure v2 being made at the injection molding factory last week! Join us for a factory tour and find the link to order your new enclosure at the end of the post.
170
Ian @ Dangerous Prototypes @buspirate.bsky.social · 09/01/2025
So we updated DirtyJTAG firmware for the Bus Pirate includes some cosmetic and usability fixes. Normally a 3.3volt power supply is activated. To Bring Your Own Voltage hold the button while plugging in the USB cable - now you can connect an external target voltage from 1.2-5volts to the VOUT pin.
150
Ian @ Dangerous Prototypes @buspirate.bsky.social · 08/01/2025
A glitch hack with Bus Pirate!
060
Ian @ Dangerous Prototypes @buspirate.bsky.social · 08/01/2025
A scratch and sniff "genuine" sticker seals every Bus Pirate anti-static bag. The custom scent evokes fresh green paint on factory floors, PVC plastics, and oily/diesel notes. After a year the supply is almost gone. Should we keep doing this? Did you know about it and/or smell it? 😆
271
Ian @ Dangerous Prototypes @buspirate.bsky.social · 07/01/2025
PixMob concert bracelets have RGB LEDs that synchronize across thousands of people in a stadium show. Not just color syncing, but detailed patterns such as the heart in the photo are possible. Cra0 tore one apart to see how it works, and dumped the EEPROM with a Bus Pirate. cra0.net/blog/posts/r...
390
Ian @ Dangerous Prototypes @buspirate.bsky.social · 27/12/2024
Oh man. They leaned in hard on the security aspects. They knew in September it was faulty. Wanted the disclosure delayed until January. No notice of a 0 day. Whose IP has been vulnerable for months? Hack my stuff please, but if you want a secure platform is any of this ok?
463
Ian @ Dangerous Prototypes @buspirate.bsky.social · 27/12/2024
RP2350 security cracked? CCC live stream starting now: streaming.media.ccc.de/38c3/zigzag
streaming.media.ccc.de
Saal ZIGZAG – 38C3: Illegal Instructions Streaming
Live streaming from the 38th Chaos Communication Congress
161
Ian @ Dangerous Prototypes @buspirate.bsky.social · 23/12/2024
For the next few days the latest Bus Pirate firmware is in holiday mode. Pin labels are a very Grinchy green.
0151
Ian @ Dangerous Prototypes @buspirate.bsky.social · 20/12/2024
There is a new chip dump helper command in the latest build. The idea is to repeat the r read command of the current mode and save the contents to a file. Simple, but an effective way to dump a ton of memory devices..➡️
110