stacksmashing @stacksmashing.bsky.social · 28/09/2026> You're right, and I own this: I ran erase/program sequences I had not validated against a scope, on your hardware, and it bricked the chip. That was the wrong call 🥲 1132
stacksmashing @stacksmashing.bsky.social · 19/08/2026AST2500😅 AST2600 seems to work very differently (running OpenBMC?) 110
stacksmashing @stacksmashing.bsky.social · 18/08/2026Found a Supermicro BMC vulnerability yesterday and now getting Supermicro ads all day 🤡 1131
stacksmashing @stacksmashing.bsky.social · 16/08/2026I don't know what to do with this information, so just sharing it here: Apparently Stern Pinball game-code updates are encrypted LUKS containers 😀 2263
stacksmashing @stacksmashing.bsky.social · 15/08/2026At DEF CON I had the idea to look at a particular subsystem of iOS & macOS. When I came back I started reversing - and found exactly the type of bug I was looking for 😀 0240
stacksmashing @stacksmashing.bsky.social · 14/08/2026We only clone the bad things - Some product person, probably 090
stacksmashing @stacksmashing.bsky.social · 14/08/2026Google releases their own AirTag. Also Google: Let's make sure it ALSO does not attach to a key. 2141
stacksmashing @stacksmashing.bsky.social · 05/08/2026Does someone happen to have one of the vulnerable COLDCARDS and would sell it to me at DEFCON?🙏 162
stacksmashing @stacksmashing.bsky.social · 31/07/2026If there's one hardware wallet I always told people not to trust it's COLDCARD. Not surprised in the slightest by the recent events. (They messed up their RNG in multiple ways, leading to - so far - user losses above $38 million USD.) 1101
stacksmashing @stacksmashing.bsky.social · 31/07/2026Hacking random companies is totally okay if I claim my GPU did it?! 0252
stacksmashing @stacksmashing.bsky.social · 28/07/2026(It works on some browsers but not in others) 030
stacksmashing @stacksmashing.bsky.social · 28/07/2026Did KiCAD get compromised? Or some over-eager AI-scraping prevention?! 230
stacksmashing @stacksmashing.bsky.social · 22/07/2026If the sandbox escape was so advanced then publish the details. 0162
stacksmashing @stacksmashing.bsky.social · 11/06/2026My DEF CON talk "Hacking jetskis - from Sea-Don't to Sea-Doo" got accepted 🥳 We'll be having some good fun - such as bypassing the immobilizer using a custom Flipper Zero app, building a custom diagnostic adapter, and some big plot-twists 🛥️ 0270
stacksmashing @stacksmashing.bsky.social · 16/05/2026Opposite of solder-pr0n: Messed up the stencil solder application and was hoping for surface tension to fix it for me 🥲 The expired paste probably didn't help either 2150
stacksmashing @stacksmashing.bsky.social · 08/05/2026This guy doesn’t even use AI for bug hunting 🙄 1170
stacksmashing @stacksmashing.bsky.social · 06/05/2026Non-technical teams are now shipping production vulns 2254
stacksmashing @stacksmashing.bsky.social · 04/04/2026Told someone their "vulnerability report" is bs (result of an automatic scanner that has a false positive...) This was the response 😑 2150
stacksmashing @stacksmashing.bsky.social · 30/03/2026Sometimes it’s nice to go back to basics: Built firmware that’s just 246 bytes, uses no RAM at all, and runs parasitically from a 1-wire bus at just 0.2 mA. Yet it emulates a full jetski key! You can see voltage rising until the chip starts running based on the BOD threshold. 3291
stacksmashing @stacksmashing.bsky.social · 25/03/2026If you ever lose the keys to your older Sea-Doo Jetski you might find these bytes useful when talking to the ECU😇 95 BC 2F 02 04 A4 75 BE 1221
stacksmashing @stacksmashing.bsky.social · 25/03/2026Option A: Upgrade iPhone to iOS26 and have to use liquid glass Option B: Get pwned by DarkSword malware I don't know which one is worse 5180
Reposted by stacksmashingBanda Bassotti @orpach.neocities.org · 17/03/2026Put that thing on a pole and call it the BLE swiffer. 011
stacksmashing @stacksmashing.bsky.social · 17/03/2026Sometimes, you simply need Bluetooth HIGH Energy📡 2450
stacksmashing @stacksmashing.bsky.social · 17/03/2026The issue is the ESR. It's too low, impacting the loop stability of the regulator in this case 211
stacksmashing @stacksmashing.bsky.social · 17/03/2026If the datasheet says to use tantalum capacitors - then use tantalum capacitors! Blue = Ceramics Yellow = Tantalum 1160
stacksmashing @stacksmashing.bsky.social · 09/03/2026Not if you try ifconfig first every single time 🤷♂️ 000
stacksmashing @stacksmashing.bsky.social · 08/03/2026Simple age check for Linux: Just have the shell ask the user to check the host IP on first boot. If they type ifconfig they are old enough, if they type ip addr they deserve to be restricted from their computer 😇 6407
stacksmashing @stacksmashing.bsky.social · 06/03/2026Things I didn’t see coming: apparently I own a Game Boy signed by a Eurovision contestant?! 😆 youtu.be/8XR2RvfZ-68 4412
stacksmashing @stacksmashing.bsky.social · 05/03/2026No JLC, component placement is not correct 😂 3280
stacksmashing @stacksmashing.bsky.social · 05/03/2026Awesome!! We wrote a similar tool compatible with a bunch of programmers: flash.hextree.ioflash.hextree.ioHextree Flash Programmer 130
stacksmashing @stacksmashing.bsky.social · 28/02/2026Won today’s bet of “Do I really have no oil pressure, or is the gauge just broken?” 😅 0280
stacksmashing @stacksmashing.bsky.social · 27/02/2026If you find one where some channels don’t move: In 90% of cases it’s just the transistors that are broken. Simple to change and readily available at Digikey & co. Replaced all on mine just to be sure. 050
stacksmashing @stacksmashing.bsky.social · 27/02/2026Wow, used Yamaha 01V96 are a steal - and 17 motor faders are a lot of fun 😀 2170
stacksmashing @stacksmashing.bsky.social · 20/02/2026Memory Tagging Extension checking my pointermedia.tenor.coma shirtless man with blonde hair is sitting in a chair .ALT: a shirtless man with blonde hair is sitting in a chair . 070
stacksmashing @stacksmashing.bsky.social · 20/02/2026Yes VSCode, I obviously want to use the color-picker to edit the address offsets in Arm assembly 😂 5706
stacksmashing @stacksmashing.bsky.social · 05/02/2026Yep, just a very simple nRF52840 BLE sniffer :) 010
stacksmashing @stacksmashing.bsky.social · 05/02/2026Fancy, the board-house sent me x-rays of my PCBs! 1230
stacksmashing @stacksmashing.bsky.social · 03/02/2026We were able to find some minor correlations, but by far not enough to leak the key successfully. If you think you found something - even if it's not a full attack - send an e-mail, it's about making the implementation more secure, not about building the best attack.🛡️ 080
stacksmashing @stacksmashing.bsky.social · 03/02/2026My first post on the RaspberryPi Blog 😍 We've extended the RP2350 side-channel hacking challenge to April 30 - and even better: To make attacks for the challenge easier, we decided to disable the random chaffing and some more mitigations! www.raspberrypi.com/news/rp2350-...raspberrypi.comRP2350 Hacking Challenge 2: Less randomisation, more correlation - Raspberry PiOur second RP2350 Hacking Challenge has evolved, with prize money still up for grabs. 1201
stacksmashing @stacksmashing.bsky.social · 01/02/2026The one on the stands is just a random QFP carrier i had on my desk - the one on the bottom is my PCBite plate :) 020
stacksmashing @stacksmashing.bsky.social · 29/01/2026gist.github.com/nezza/3841f9...gist.github.comflashfixer.pyGitHub Gist: instantly share code, notes, and snippets. 021
stacksmashing @stacksmashing.bsky.social · 29/01/2026Yeah I have a script that takes multiple dumps and then creates one "true" dump with the most likely bytes from multiple dumps. It also logs out outliers which is helpful! 130
stacksmashing @stacksmashing.bsky.social · 28/01/2026The PCB is suuuper sensitive. I ripped off three pads so far... To get to chip-select I had to solder onto the tiny tiny tiny via barrel😵💫 090
stacksmashing @stacksmashing.bsky.social · 28/01/20269d3e36fc632d77f24c810cb89892dd1959dfb05b output.bin (Created from multiple dumps, something is messing with the signal) 5192