#294 – Live from Serbia with Mike Harrison

Download episode · 53 MB
Also on Apple · Spotify · YouTube · RSS
Show Notes
Welcome back, Mike Harrison (@mikelectricstuf)
- Mike is in Belgrade with Chris, both attended and gave talks at Hackaday Belgrade (will be posted eventually)
- Mike gave a talk about the Eidophor
- They will also both attend Resonate.io but neither will speak.
- The fun continues in the UK!
- April 19th - Beer and electronics meetup! We'll be at the Yorkshire Gray on Theobalds Rd starting at 6:30.
- April 20th - "Nerd Nite" event
- April 21st - There is an Open Source Hardware Users Group meeting.
- Mike recommends learning (uppercase) cyrillic to help get around places like Serbia or Russia.
- Consulting projects continue to get more interesting, you can see them on whitewing.co.uk
- There is a new project that was installed in terminal 2 of Heathrow airport
- Holiday decorations in Hong Kong
- There was a fixture to program physical locations of the assembled PCBs.
- All high level comm was done using RS485.
- Selfridges on Oxford St
- Mike saved the setup time by starting a truck using a drill battery.
- Uses the APA102.
- Test jigs are critical in field jobs, especially time critical ones like busy installs.
- Trade shows for other industries
- Mike went to one for wearable tech, ended up going to underwater exploration instead.
- Saw the company that makes the underwater buoy that Mike tore down. (Sonardyne)
- Museums
- Tesla museum was underwhelming, but Mike saw the first ever radio boat.
- Chris and Mike went to the science museum together and saw the Galaksija (previous guest Voja Antonic's design)
- Devices
- Mike has been designing devices using loads of 0402 white LEDs. He also gets $0.01 4mm LEDs on aliexpress.
- Osram Duris E
- Reverse engineering
- Mike has experience reprogramming analog(ue) phones. This was done by modifying or moving the ESN of a device.
- The Sony D50 service manual that Dave tore down had a great service manual. Some of the old phones used to have those, but they were hard to get.
- The eeproms were something like 9346
- Mike had to write disassemblers and then read the output to figure out what was going on. He also ended up tracing program flow using a logic analyzer
- Vodaphone had prepaid phones, others were not well implemented and ended up giving away free calls.
- Mike ended up emulating the Dallas UID chips with a small board in order to reprogram the ESN.
- The last time Mike was on an Amp Hour episode he talked about using PICs.
- Write the bootloader first...and make sure it's rock solid!
Transcript
Mike Harrison: This is the Up Hour Podcast. Recorded April 13th, 2016. Episode 294. Live from Serbia with Mike Harrison.
Chris Gammell: Welcome to the Amp Hour. I'm Chris Gammell of Contextual Electronics. And I'm Mike Harrison from Mike's Electric Stuff, again. Again. And we are in the same room for the first time. Well, not the first time here, but the first time... In the same room. Yes. Yes. Recording the same room. Yeah. So, and we are in a hotel room in Belgrade, where we are both hanging out. We were at the Hackaday Belgrade event. And this week we're both going to Resonate, which is... What is Resonate?
Dave Jones: It's a sort of arts festival-y type thing. Yeah. It's resonate.io. There's a whole load of sorts... Yeah. So it's maybe a slightly less techie sort of hackacon type thing. Lots of people giving talks, but more arty than tech, but somewhere in the middle of tech and art, I think. And this is the first time I've been. I only found out it randomly, someone. A lot of the people I do work for go regularly. And just someone said, oh, are you going to Resonate this year? And I said, what's Resonate? And I sort of looked it up and thought, well, I vaguely thought Belgrade might be an interesting place to go. So that was an excuse. And then I thought, okay, fine. I'll go there. I'll go there. And then the Hackaday thing just happened.
Chris Gammell: So it was quite good. Yeah. No, it was great. And actually, it was planned to be kind of adjacent because we knew we'd have similar people there. So that's good. And you gave... So you were... Obviously, I was there. You were there. We both gave talks. Your talk was not only the keynote. It was fantastic. I loved it. Can you tell us a little bit about what the talk was?
Dave Jones: Yeah. So it basically was about the history of a very little known technology for video projection developed in the 1950s. It was called the EIDA4, E-I-D-O-P-H-O-R, developed by, I think it was a German or an Austrian company. And it basically is one of these ridiculous bits of technology. What I love is old tech, which is stupidly complicated to the point of being barely practical. Right, right. But once successful, it actually dominated the market for several decades in the video. Basically, CRT large screen projectors have been around for quite a while. But they're pretty limited as to how big they can go because of things like how much brightness you can get out of a CRT plate. And at some point, you need to put such a high EHT voltage, you get a lot of x-rays coming out. So this was all quite easy. So probably the best thing, if you Google it, there is some information online, but not a huge amount. But I actually dug out a few books and a few papers, and I just put together a presentation. I'm actually giving this presentation in London on April the 20th. There's an event called Nerd Night. It'll be a slightly less technical version of it. But I think, I might think, is the Hackaday thing going to be available? It will be, yeah. So those will all be, all the talks will be up on.
Chris Gammell: Go watch that instead of me explaining it all. Yeah. No, it'll be good. And actually, the really interesting thing that I think a lot of people would like is the fact that you mentioned a lot of the control room stuff at NASA was using these huge, because that's like...
Dave Jones: If you look at some of the old NASA pictures, you'll see there's the plots that show the orbital path. And I think those were just done by electromechanical projectors. But you will see big screens showing live images in NASA. And so I dug out a few various images. How I found out about it was I was just listening to a radio program on BBC London. They have this thing where people email in just really random queries. And one that was related to this guy that had this vague memory of seeing live boxing matches being shown in cinemas in the UK in the 1970s. And I thought, well, how did they do that? Right. So someone phoned in and said, yes, it was this thing called the EIDA-4. And then I did a bit of research and found out some more information about it. It was just sort of really fascinating, this sort of ridiculous machine that used sort of vacuum pumps and oil and crazy optics. Yeah.
Chris Gammell: That one page you had up with all of the equations?
Dave Jones: Yeah. Yeah. That was like... Yeah. The maths behind it. Basically, you're combining electron beam electrostatics and fluid dynamics. And there was like 40 pages of ridiculous formulas from this page, from this thing from about the 1940s. Yeah. So it's, again, one of those things that you can't imagine how they actually managed to... The development, literally from the idea to actually a product was over 20 years development. Yeah. Right. It obviously wasn't easy. But once they developed it, it was actually... Yeah. It totally owned the market. But they only ever made about 650 of them. Yeah. And they were actually surprisingly reliable. Oh, really? Oh. Yeah. Okay. These things cost, you know, the equivalent of a couple of million dollars each. And obviously, they'd be regularly serviced. But actually, considering all the tech that was in there, it was actually quite surprising. They were doing like 50,000 hours without any major faults apart from routine maintenance. Yeah. That's insane. But yeah, if you're interested in old tech, go look it up. There's enough on the internet to actually give you the info. I might... Well, I might do at some point that book I've got. I might perhaps scan that and stick that online at some point. That'd be good.
Chris Gammell: Yeah.
Dave Jones: Yeah.
Chris Gammell: So you've been here in Belgrade now, about four or five days. Yeah. What do you think about the area?
Dave Jones: Yeah. See, it's quite nice. And the nice thing about sort of the main bit of Belgrade, it's very compact. You can walk pretty much anywhere. And it's, you know, it feels reasonably safe. You know, I've never felt at any point, you know, uncomfortable really. Yeah. Even like going through like some underpices and so on. I mean, as you look around, there's a lot of graffiti. Yeah. And the impression I get is quite a lot that it seems it's like political. I mean, there seems to be very little like vandalism. Right. For example, things that I see over here where in the UK would have just been smashed. Things like glass cases of a shoe, like outside a shoe shop, they have these glass cases of all these shoes. Yeah. And in the UK, stuff like that just wouldn't survive. Right. Exactly. And there's quite a lot of sort of street art type stuff. You walk around the back street and you suddenly find this huge sort of, you know, 12 foot square, you know, really nice drawing of somebody who is presumably some sort of political figure or something else. I don't have a clue about all the politics. And I can read about half of the Cyrillic letters. So I can sometimes figure out how to pronounce something and possibly roughly figure out from context what stuff is. Right.
Chris Gammell: You had mentioned that you had went to Russia and that was really useful to have.
Dave Jones: I mean, if you're going to a company with a country like Russia or Serbia, it is really worth learning the uppercase Cyrillic letters. There's only like about, there's like a few standard letters that are different, like the N is pronounced H or the other way around. Yeah, no, the H is an N. And there's about, there's a few common ones and a lot more, far less common ones. But it's really worth learning those because as soon as you can pronounce a name, because quite often you'll find that, for example, if you look on Google Maps or whatever, you sometimes find the names are like phonetically spelled out in Roman. And if you can relate that to the road, the street sign you can see. So if you can see the thing that says, you know, something or other of each street or whatever and actually, you know, get, translate that, that is really, really useful for just navigating. I mean, don't bother with the lower case is a nightmare. That's all different. Things like signs don't come in that. But just the uppercase Roman characters are really, really useful to know. Yeah. And they're not that hard to learn. There's not really that many of them.
Chris Gammell: I used to do that for, in Korea, I would just be like trying to like pattern match basically. Yeah. With like Korean characters. Yeah. I'm sure you can get an app that you just point your camera at it now and it will do some translation. Yeah. That's nice. Yeah. That's good. So we should mention as well, we're going to be hanging out pretty much for the next two weeks. Yeah. So we're here. You're sick of the side of each other. Yeah. And then back in the, you're going back a day before me, but we're going to be doing that meetup on the 19th in London at the Theobald, on Theobald Road.
Dave Jones: Yes. The Yorkshire Grey and Theobald Road. There is more than one Yorkshire Grey in London. It's Theobald Road, which is in, it's not quite Islington. I'm trying to think what you call that area. It's near the sort of Hoban sort of area. And that's about 6.30 to whenever. Yeah. I have no idea how many people are going to show up.
Chris Gammell: Yeah. It'll be the usual.
Dave Jones: They do have a function room. I'm sure if we turn up as a huge mob, we can negotiate the use of their room. Right, right, right, right. It looks like they do quite nice food, but we'll see. Good. Yeah. See what happens. Oh, it's right. No, I was just about to repeat something I said earlier. Oh, yeah.
Chris Gammell: The 19th thing. And then you said there's actually the thing that I should have stayed around for that I didn't realize.
Dave Jones: Yeah. On the 21st, there's a thing called the Open Source Hardware Users Group, which is a regular monthly meeting where people give presentations. It's very specifically open source hardware. And it's actually hosted by the British Computer Society. Oh, cool. And the guy that runs it has actually got a budget from them. So there's actually quite a good free buffet there. Nice. Decent food. The way to nerds' hearts. Yeah. That's generally very well attended. It covers quite a range of subjects. If you look, I think their website is osag.org. Yes, that's right. Yeah, yeah, yeah. Yeah. And you do need to book because it does quite often fill up. Okay. Okay. Yeah, no, that sounds like good. And then, like, after that, we retire down to a local pub and talk to, for example, I met Saar from Baldport there last time.
Chris Gammell: Right. Right. Yeah. So that'll be good. And Saar will be at that other meetup, too. Yeah. So, yeah, I'm excited to get all these different scenes, too. It's, you know, I feel very lucky that we get to travel around and meet all these different people, but it's good to kind of...
Dave Jones: Yeah. I mean, my voice is probably sounding a bit rough because I've been, the last few years, I've just been nonstop talking to people. And, of course, as soon as you get, you know, they retire to the noisy bar and then you're raising your voice. And my voice is on. The hackaday talk, I was really worried that my voice wasn't going to make it through. So for about the two or three hours before my presentation, I just avoided talking to anybody just to give a bit of rest. Or you just shake your head. No, no, no. Yeah, no, go away. Yeah. But... I am an introvert right now.
Chris Gammell: Yeah.
Dave Jones: But obviously, there's quite a few people, you know, because it's a very small area, you do bump into people. But in fact, the day before, the hackaday, I was just... Yeah, when I go to New City, I just take a wander around. Yeah. And I was just randomly wandering around, nowhere near the venue. I think someone just came up to me and said, hi, Mike. I thought, what's going on here? Am I that famous? Right, right. You were wearing your hand power shirt. Yeah, I think it was the fact that I was wearing an hand power shirt that gave the confirmation and possibly a bit of distance, but...
Chris Gammell: And I've been reminding people, too, if people don't remember, Mike is the one who came up with the amp hour. Yeah. So we are in his great debt. But licensing fees will come at some point. Yeah. Yeah. Yeah.
Dave Jones: I think this is it on the table here. Yeah, right. Some euros. There we go. Yeah.
Chris Gammell: The royalty for this episode. Right, right. It's all you'll ever get, David. That's good. Any other talks or things you saw at the Belgrade conference? Yeah.
Dave Jones: And it's all sort of quite interesting. There's a variety of different things. Some of them were interesting. One or two, maybe not so. But yeah, something for everyone, really. And I was quite surprised. Obviously, beforehand, I didn't have a clue how many people were going to show up. And I really was quite surprised that you managed to get that many people in.
Chris Gammell: Oh, yeah.
Dave Jones: Yeah, that's good. The impression I got was it was quite a lot of relatively locals. I don't know what the – I'm sure you've got the stats.
Chris Gammell: I think it was actually like half. Yeah.
Dave Jones: Only like half were from Belgrade or something. Yeah. So it was probably there's that many people in Belgrade that are interested in that sort of thing. Yeah, a lot of them were so for people. And there's posters all over town as well. But I mean, if you want to know what's happening in Belgrade, just walk around and look around the streets. There's posters everywhere. Absolutely everywhere. Right. And they seem to update them quite – you don't often see out-of-date posters. They seem to refresh them quite regularly. So that's a way just to find out what's going on. And it seems like it works, actually. You know, like I've – Well, yeah. If that's the established way to do it, then clearly people know that. I was reading like the tourist guides before and apparently I went to English language papers. I've never actually seen any of them. But just the posters, I'll walk past, you know, see something interesting, take a photo of it. Yeah. Like, you know, I've been trying to look – trying to find some decent live music to see. So I'll see a post. I'll take a photo. Find them on YouTube. Yeah. And then try and figure out from the Cyrillic where it actually is. Of course.
Chris Gammell: So you were showing me some pictures of some of the installations you've been working on. I'm not sure which ones you're allowed to talk about. But some of those were just really –
Dave Jones: Yeah. Some of them are – say a lot of them are on my website, whitewing.co.uk. The Heathrow Airport one, I'm going to do a super detailed technical video. That's probably going to be one of the next videos I do. But that may well still be a few weeks off before I get time to do it. I need to make sure I've got, like, samples of all the boards and actually set up some demos. But that's going to be a super, super deep – probably of the similar scale to the iPod Nano videos, which were quite popular. Yeah. And the other big one we've done recently was in Hong Kong at a big shopping center for their Christmas decorations. And again, at some point, I'll probably do a video on that. And the interesting thing about it, that was entirely made out of PCB. Right. I thought people would be interested in that one for sure. Yeah. But basically, we've got, like, a strip which is sort of – so I'm waving my hands here, which doesn't really work on – Right, right. I'll measure the hand. Yeah, about 200-millimeter long strip with three RGBW LEDs on each side and a little six-pin pick. And we basically designed this system of, like, six-sided stars with mounting holes and a jig. So this whole thing is modular. So you set up this jig. You drop all the stars in. Drop all the – they've got, like, posts that locate everything. You drop the strips on. So these form the – if you actually look at the video on my website, you'll see that generally – they're like snowflakes, basically. Right, right.
Chris Gammell: This standard shape.
Dave Jones: Yeah. So, yeah, it's all snowflake. So it's all a hexagonal-based thing. You drop all the stars on the jig. You drop all the strips on. You then push plastic rivets in to secure it. And then the jig actually has pogo pins at each strip location. So the jig then programs the IDs onto all the strips. So the strip knows where it is within the star. Yeah. And the nice thing about that system is the jig is modular. So you can just – if you want to make a different shape, you just unscrew all the parts of the jigs, fix it together in a different shape. And then you've then got the jig for another shape. Did you use it in more than one shape? No, no. That was purely for that installation. But because, obviously, we've manufactured all that stuff and it's for Christmas, they are talking about reusing those in a slightly different shape. Oh, cool. Although I don't really want to be the guy that has to pop out all those plastic rivets. They're really easy to get in, but they're a bit of a pain in the butt to take out again. Yeah, to pull them out or something. No, no. You push them out, but you've got to basically – if you look at them on the line, there's like a piece that goes in and then a pin that goes in the middle. So you push it. Yeah, the rivet goes in and then as you keep pushing, the pin expands the bottom end of the rivet. Gotcha. Which means – but to get them out, it means you have to push the pin out from the underside and it's quite a small pin first before you can then extract. I mean, my fingernails are totally trash when I was – Right. Right, right. But I think we need to make the right tool to do that. But even so – but yeah, that was quite a nice installation. So almost all – the whole thing was made out of PCB, even some of the vertical bits.
Chris Gammell: So how would you – so you were mentioning the programming stuff too. So you would – so you put all these in together. It was just like a serial line to each –
Dave Jones: Yeah, basically it's just a common parent, you know, positive, negative, and a single-ended data line in parallel across everything. The nice thing about that is that, you know, you can change this. You don't have to worry about the routing at all. Of course. Everything is connected in parallel. Well, so all you need to do is make sure each thing has a different address in the right physical position. And this is probably something else I'll do a video on at some point about programming the physical position of things. There's a few really interesting techniques I've developed for doing that sort of thing. But say in this case, literally everything's connected in parallel. The jig has a pogo pin at every strip position and the strip has a pad on it. And the jig can basically send a command over the whole bus that says, if you can see that pin being pulled low, you are address number three.
Chris Gammell: So the pogo pin would only come up when it's programming?
Dave Jones: No, no. The pogo pins are always there and they're driven by the programming jig. And the jig can just drive that – either drive that pin low or high. Oh, okay. So the – Yeah, so the jig drives one pin low, sends a command that says, if you can see this pin low, you are address number three. And then it repeats that for each device. Okay. So it's like you're basically multiplexing the – it's almost like you're doing like
Chris Gammell: a chip enable with the pogo pin.
Dave Jones: Sort of. Yeah, yeah. It's just like a chip at gym there. But it's a chip enable. There's a command. There's a bit field in the command that says, filter – yeah, either do this command or only do it if you see this pin being pulled low so you can do local stun. And I've used that on loads of different installations in various different shapes of all. That's nice. Because I've seen that before.
Chris Gammell: The way I've seen it before is if you do like – you can do physical addressing with like resistors setting like dips and resistors and stuff like that. And then like lowest address winds for – that's like a CAN bus.
Dave Jones: Yeah. But yeah, that's all very fine. Yeah, so there's lots of ways if you've got a whole bunch of things on the bus to assign individual addresses. Yeah. But the tricky bit is where that thing needs to know its physical position as opposed to just being on the bus. So that's where you need some sort of local – and I've done similar things whereby instead of a jig, for example, let's say you've got a big string of LEDs or LEDs as some people would prefer me to say. I'm okay with that. I'm not going to get into that. So you have a whole string of LEDs all on a common bus. And you've got like a little handheld probe. So you send a command that says your address three and if you physically go and touch that particular one or you could do it with a touchpad, for example. Let's say you could do a touchpad. So you touch that one and it says, okay, I recognize that. And there's then a refinement of that you can do whereby the way I normally say I've got a little handheld probe that does the touching. But the probe can also sense that it is being touched onto the node. It is in charge of sending the command. So when it sees that it's being touched and then knows that one's been programmed, then it automatically increments to the next address. So all you have to do is set your initial address on this handheld unit and then literally go and touch each one in turn and it programs everything. Right. But then you're the program. You have to make sure you touch them in the right order. Yeah, exactly. But that's a one-off thing and it's got a little display on it and it gives you a little beep. So it's all fairly automated. That's cool.
Chris Gammell: So then how do you... So then each snowflake has like maybe what, 10, 12 points?
Dave Jones: Well, each snowflake is 60 boards. Oh, 60. So that runs TTL data at, I think it was 100k boards, something like that. And that then goes into a splitter box. There's a splitter which takes a, I think a 2 megaboard RS485 and then splits that into 12 separate ports at 125k board. Oh, so you've got a custom board. Yeah, these things run like a 5-meter drop cable. So down that 5-meter cable, you've got 100k board at TTL levels, 24-volt supply. And then the splitter, basically you've got a splitter and a big power supply. And there's some big like metal stars in the ceiling you can see. And that's what's hiding where the power supplies and splitters are. So you've got this big power supply. I think each star takes about 2 amps or so. You've got this like 25-amp, 24-volt power supply going into a splitter. That splitter then provides fused power to each one. Because you've got that big power supply and you get a short at the bottom. You don't really want the cable to catch fire. Right. Shopping tenders take a pin for that sort of thing.
Chris Gammell: Merry Christmas. Ah!
Dave Jones: You've got a polyfuse on each port and obviously protection against your data line getting shorted to... 24 volts. And then just there's a big 32 in there that takes an incoming packet and then just splits that out into multiple flyer packets in parallel.
Chris Gammell: Yeah. That's great. And so you have 60 per snowflake. Yeah. How then did you just kind of just set addresses manually? You just said...
Dave Jones: Well, that's what the jig does. The jig says within each snowflake, it addresses each strip within the snowflake 1 to 60. Okay. So the next snowflake is 4.1 and 4.2. Yeah. And the snowflake is by which port it's plugged into in the splitter. I got you. And then the splitter's got a dip switch. So there's about, I think there's about three or four splitters on each 485 bus. The splitter's got a dip switch to say which splitter it is on that 485 bus. Nice. And then there's multiple 485 buses just to get a central balance of bandwidth. And they all come into a four-port 485 USB interface. And they're actually running off iMacs. But in these sort of things, my responsibility tends to end at the USB port. Uh-huh. Yeah, yeah, yeah. And then it's just a mapping for them. Yeah, exactly. Yeah, yeah. Interesting.
Chris Gammell: Well, that's great. It was a beautiful installation too.
Dave Jones: Yeah, and unfortunately I've not yet got any video of all the animations running. That's just stuff that I took on the last night of the install. But I'll have to try and hassle them to get something online because the animations look really nice. Because, of course, the snowflake, you've got lots of scope for doing sort of sweeps over it and local rotations and color stuff. So what do you do then? Do they spec an API to you or do you push an API? I give them the API. So here's the packet format. Here's the send. It's generally very simple. It's almost always one way. Just keep things simple. Right. The return path is, is it on fire? No, no. You don't need that. But as soon as you have return path, you don't have to deal with error handling. It's like, you know, if you're like, you know, the thing I love about RS 485 is just rock solid reliable. You just don't get errors. It just does not happen unless you do something stupid like. Yeah, it doesn't. One of the problems with it is because it's a differential thing. If one of the lines isn't connected, it will sometimes work. Oh, great. Depending on how that other line is floating. And that's where you get problems. If it's connected, so any 485 installation, you know, you always do an end-to-end continue. You normally have a termination at the end. So you always go to one end and check that you can see that termination. Yeah. And as long as that's okay and you're, you know, you've got enough margin. Like, say, you don't try pushing, like, 10 megabits over a kilometer of Cat5. Right.
Chris Gammell: That's when I had problems. Yeah.
Dave Jones: But, I mean, you know, you can do, you can easily do, like, a couple of megabits over a couple hundred meters of Cat5 very, very reliably. In fact, the first limitation you hit on Cat5 is actually the series resistance of the cable because you've got that 120-ohm terminator at the far end. And then as that resistance builds up, that's actually pretty much the first limit you hit. Yeah. Rather than actually actual bandwidth limitation. It's quite interesting if you, I think quite a while ago, I tweeted this picture, scope picture. You see, like, clean data going in, scope probe across the Cat5, which looks horrible, and then clean data coming out the other end. It's using the differential signal. Yeah, digs it out of the dirt, basically, right? And the other thing I quite like using, there's a company called NVE that makes a really nice passive input isolator. It's a bit like an opto-cupper in that the input doesn't require any power, but it's magnetic, so that your input is basically a coil on the chip. It's all integrated on the chip. But the nice thing is that input is completely floating, so it doesn't need a ground connection. Oh, nice. So there's no possibility of ground news. But it also means that you can get four buses down one piece of Cat5, which is quite convenient. Interesting, yeah. Oh, because, yeah, there's all the different lines. Because you don't need a ground. Right. Whereas if you're proper 485, you do really need a ground. I did a video about that a while ago. Okay. The only problem with it is the loading is quite high, so you can't really have more than about four or five of them on the same bus before you start getting into some marginal data issues. That was the other issue I had. I tried putting, like, 60-plus things on the bus.
Dave Jones: With conventional receivers, as long as you use the low-load ones, you can do that. But as soon as you get into that quantity, you do start needing to be a bit careful about how you do it. Yeah, yeah. And, like, not having stubs and that sort of thing.
Chris Gammell: Right, yeah. Yeah, good matching.
Dave Jones: Yeah. But for, like, shorter cables and low data rates, you can almost do wet string and it works. It's just super hard. Every time that people said, oh, why don't you use Ethernet, RS485 is just so much. Direct, there's no stack. Exactly. It's super simple. You can whack a scope on it in your serial debug and debug it. It just, you know, does the job beautifully. And I almost always use it single-directional. So it's sort of technically RS422 rather than 485, but the hardware is the same. Right. But it means you can also do, you know, if you want to, you can do remote sensing. Even if it's just simply to detect the presence of the thing at the other end as a quick reality check, is everything working? Right, yeah.
Chris Gammell: And so you will put multiple devices on one bus?
Dave Jones: Yeah, yeah.
Chris Gammell: And usually max out, like, 16 or something per bus for, like, the last...
Dave Jones: It depends. So if I'm using these, I said they're IL-610s from memory. Uh-huh. So you can only generally... It starts getting sketchy once you hit about five or six because of the loading. Okay. But with quarter load, my other go-to transceiver is an ST485. And, yeah, you can get... I can't remember what the spec is, but you can get 60-odd. And if you're not pushing the board right, you can probably get more than that. Yeah, yeah, yeah. I think the issue there is probably going to be, like, little local reflections rather than bus capacitance. Right. But, yeah, if the 60 nodes are going to be running multiple buses because, you know, I tend to use the FTDI. They've got a company called EasySync that basically package their USB serial stuff into, like, industrial-type boxes. Like this metal box with four D connectors with four RS485s, which are on a USB high-speed. So, I mean, you can easily blow, like, four megaborts out of all ports simultaneously. Right. So you can get a decent amount of data.
Chris Gammell: Right, and if you think about that kind of, like, what you would need to get that equivalent in Ethernet, you would need, like, almost like a gigabit drop.
Dave Jones: Well, no, you could probably do it on 100 mega Ethernet.
Chris Gammell: But just, like, on the collisions and stuff, I'm saying.
Dave Jones: Well, if it's one way you don't have the collisions, obviously, you know, you don't share your output Ethernet with anything else. Yeah. And ideally, you wouldn't use TCP IP. You just use raw Ethernet packets. I mean, that's what I might look into at some point. Because, you know, a lot of micro-controls have Ethernet hardware. So if you can just use that as an effective fast serial port and just ignore, you know, don't even think about TCP IP. And literally, you could almost use it as a fast point-to-point interface and not even need a lot of the hubs, for example. You can just use it as a transistor and receiver and daisy chain, and you could probably do that without even needing a hub or a switch or anything. So that's the other problem with Ethernet. Of course, you need all these switches and all this. It gets messy really quickly. Right, right, right, right, right.
Chris Gammell: Well, that is interesting. You were mentioning, too, about the connectors on there.
Dave Jones: Oh, yes. One of the things, part of this snowflake design, obviously, we're snapping these PCBs together with plastic riviers. Now, of course, you can't just have a PCB, you know, flat face contact because you need a bit of springiness to make sure that it gives you a reliable contact. So we were looking for, like, a spring probe type contact. And now you can actually buy some quite nice surface mount leaf contacts. But then when I was looking, this is one of these cases where a paper catalog is great because you see stuff on the same page. Oh, yeah, connectors, for sure. Mobile phone SIM connectors. So these are basically sort of like a block with six contacts, which was, I don't know, 40p or something. Yeah. Surface mountable. And the block width was such that we could use another spacer made out of PCB. So it's the same shape as the star with a big rectangular cutout for the connector. So when you sandwich your star and the space and the strip PCB, the contacts have got just the right amount of deformation. And I think we actually cleared out pretty much the entire worldwide stock of those. This was one of those fairly short timescale projects. And, okay, we could probably have found it in Shenzhen. But it was so critical that we had this exact highway side of the grid. It has to be this Molex part number. And, yeah, we cleared out DigiKey. We cleared out Arrow and a few other people. And it was really about 28. I think it was about 30,000 of them we bought.
Chris Gammell: Can you imagine the nightmare scenario of, like, someone else doing that at the exact same time? Yeah. That's the sort of thing that keeps me up at night. Yeah, right, right. Oh, God, someone else has it too. Or, like, even worse if it would be, like, some broker, like, catching a trend and being like, I know someone's going to need these things. I get to charge Mike more. Well, again, it's a bit hard to catch that. That's great. So what about other projects? I mean, other things you're working on.
Dave Jones: Yeah, there's a few other things going on that I can't particularly talk about yet. But they will probably be the subject of videos as and when. Cool, cool.
Chris Gammell: I feel like you need to hire a videographer just to follow your...
Dave Jones: Yeah, I mean, the videoing of stuff, the problem is it's probably quite hard to do in practice. A lot of stuff is just sitting there at a keyboard or, you know, sitting at a piece of hardware swearing. So it's a little bit difficult. Yeah, the occasional things are sort of recreating. Probably one of the other recent ones we did was a Christmas installation on the front of Selfridges in Oxford Street. That was a big, like, 10-metre diameter circle which were made out of, like, flat blinds. I did actually cover this in my video where I... One of the key things that basically saved that installation was that I started a truck using a Makita drill battery. That's right. But go and look at that video. That's all explained there. But that was quite amusing, especially with all the riggers and the mechanical guys who didn't know much about it. Right, right. I think I'm a legend in some circle. He's the guy that started the truck. But because we had a very, very limited time window, you know, if we couldn't have got that truck started, that would have been an absolutely catastrophic problem to deal with. And, of course, we were holding up the traffic and we closed one lane of Oxford Street as well. So it was, yeah, that was a somewhat fraughty experience.
Chris Gammell: I mean, I think a lot of this stuff, though, too, it seems like, you know, this is just stuff that you're learning over time, too, and you've got all these skills because you have these...
Dave Jones: Yeah, and a lot of it is, yeah, a lot of it is just something, just the logistics of doing installations. Just stupid things like, for example, making sure that you make up little jigs and stuff. So any part of the installation, you can test it. You plug something in and test it. You don't want to be dicking around with meters or power supplies, literally. Plug it in, it lights up next one. Yes, no, green, red. So, yeah, for example, on the Hong Kong one, yeah, we had all this frame made. We had all these drop cables. So the first thing to do is, before we put any stars on, literally go around and plug in each of these cables to a tester just to make sure that the splitter's working, the cable, yeah, and all the cables are working because we had to plug all the cables in. Yeah, because it's like a 3D installation, we had to put the top stars on, winch the whole frame up, put the next stars up, wrench it up. So if there was a problem with one of those top stars, it would have actually been really difficult to get at. You'd have to probably take some of the other ones off, up a cherry picker, and actually get into the one that you needed to get to. So, you know, test as you go, but taking literally an afternoon to make all the test jigs. For example, on the Selfridges job, we used a lot of, it was the APA 102 type lead strip. So I made a little box that you just plug in, it'll light up all the LEDs, but not very bright, so you didn't need a stupidly big battery. And again, battery pounds, it's all literally taken out of your pocket, plug it in, immediately test it. So that, yeah, I can't overemphasize how important it is to do stuff like that. And also just making sure you've got all the tools you need. And sometimes I'm actually making up specific tools to do a job, because if you're doing a job like several times over, you know, you can, even if it saves like a few seconds of time, if you're doing that same thing 500 times, that's, you know, a lot of time saved.
Chris Gammell: Yeah. And so you've been learning some of this stuff from, I mean, obviously your installations, but also from like reverse engineering, which is something that you want to talk about.
Dave Jones: Yeah, I'll just do another quick, there's just a couple of other things before we get into the more heavy stuff, which is probably going to go on for a while. Something, I actually mentioned this briefly at one of the previous Ampowers, is going to trade shows for completely other industries. Oh, yeah. A few months ago, there was a wearable tech exhibition in London. And the only reason I went is it was really close by, and I thought, well, there might be something vaguely interesting. And it was basically, you know, boring as batshit. It was all internet themes, wearable health devices, VR stuff, which is not interesting at all. But across the, it was one of these big exhibition halls where they have lots of different shows at the same time. So I walked across and I thought, well, the huge, literally half of the whole building was the International Oceanics Exhibition. And fortunately, you could actually just walk up and register there. And that was just awesome. It was ROVs, underwater sonar. I mean, I wanted to tear down everything in that building. If you saw the current model of something, I've taught a while ago, I tore down a, I can't believe they call it, it's basically an underwater buoy that uses for locating ROVs. You basically, the ROV pinged it and then it pings back. It's like underwater GPS. And Sonodyne was the company that made it. I actually saw the current model of that there. But there was just, one thing I was amazed at was the number of companies making ROVs. Literally, there must have been over 30 different companies, each making multiple different versions. And literally, there was everything from the size of maybe 200 millimeters sphere up to the size of a car and everything in between. Really? And some that had all these cool grabby attachments and all sorts of stuff. What's driving that? Is that because of the oil industry? Yeah, I think it probably is mostly oil exploration and just various other things. But I think it's like that industry's equivalent of electronica. It was like every two years. So there were people from all sorts of countries everywhere. So it's probably the one industry in exhibition. And the nice thing, that exhibition center, it's actually in what used to be the London Docklands. So they've actually got docks next to it so they actually had some ships. And if you walk out of the exhibition center and they had some ships laid up and they had all the gear in the ships. And they'd thrown a few things, a cable over the side so you could actually use the RV to find the cable and pick it up. That's fun as hell. Yeah. I just love things like, yeah, just finding out about industry. It's like, you know, I like doing teardowns or stuff that people didn't even know existed. Right. I just love going around that sort of just to see the technology. And things like, you know, one whole stand, all it was was connectors for underwater applications. Oh, it's like the super high pressure, you know, designed to work thousands of feet below. And, you know, those are cheap, huh? Yeah. I'm sure if you have to ask how much, you really can't afford it. Yeah, right, exactly. Just a lot of it. And also just in close, just the real, you know, problems you hadn't ever even thought about how to solve, you know, solutions for that sort of stuff. Yeah. It was really, really exciting. You know, it's always worth it if you go and go to an exhibition. Just look at the venue website and see if there's any other shows on. Yeah. Because, yeah, you quite often find there's other stuff that's sort of quite interesting.
Chris Gammell: Well, it's another thing we were talking about earlier in the week, too, about just kind of like seeing parts or seeing connectors and stuff like that and kind of just mentally filing them away. Yeah. Because you never know. Like you might be working on a project in two, three years. And then you think about, oh, I need this to be waterproof. Yeah. Oh, I remember that show.
Dave Jones: Yeah. We'll see. Yeah. Connectors in particular, yeah, I'm always coming across weird connector requirements. So just knowing in the back of my mind, yes, something does exist that I've definitely seen it.
Chris Gammell: I don't have to make a custom connector. Yeah.
Dave Jones: I don't want to do that. Or just don't have to use something that isn't quite as good a solution. Yeah. I don't think Google Image Search is brilliant for finding connectors. That's how I do it, too. Yeah. If you can figure at least something that's like, you know, right-angled, two-millimeter pitch edge connect, or, you know, if you can get enough words to describe it and just go through Google Image Search, you can quite quickly find something. Yeah. Right. Sometimes it's even just finding a vendor being like, they might do something. Or finding something similar. Find out what they call it and then doing a search on that term. Oh, yeah. That's another good one. You don't know the term kind of problem, right? Yeah.
Chris Gammell: I mean, it's called a mezzanine connector or it's called a whatever. Right. And then amazing, too, when you get that word and you're like, you type it and you're like, oh, I found the right aisle. You know, that's like you have the right aisle in the shop kind of thing. Yeah. It's great. Yeah, exactly. It's great. That's cool. Yeah. So any other shows that, I mean, is it like, I mean, does it help that, I mean, obviously you're in London. Do you think that these exist in a lot of places?
Dave Jones: Yeah. I mean, the big trade that say there's one big exhibition center in London, but there's another one, big one in Birmingham, which is like central, centralizing England. There's a lot of shows go on there. So those are really the two major ones. But the super niche ones, like electro optics or whatever, they tend to be in much smaller things.
Chris Gammell: So you'll keep like an eye on the convention schedule or something?
Dave Jones: Okay. When I can remember. I mean, I'd say XL is convenient because I can get there in like 20 minutes and I know a sneaky place I can park for free as well. Oh, yes.
Chris Gammell: Which you won't reveal here, folks. That's his secret.
Chris Gammell: Top secret.
Dave Jones: It's like knowing the location of the lost. I'd like to say a lot of the trade type things, it's worth finding out. A lot of them they'll do. You can register up to a week. The ones which are part trade, part consumer, like for example, wearable tech ones, you could register free as a trade visitor up to a week before, but then they were charging after that. So if there is something that's worth pre-registering, obviously, you can make up company details if you haven't got a company. Just think that might injure. Just invent company details. No one checks this stuff.
Chris Gammell: Also, one other hack is you can pretend your media. I've done that one many times before. Yeah. That's the other. Yeah. Just say you have a blog or something.
Dave Jones: But yeah, just pretend like someone like a consultancy. They don't know whether you're just some random dude or some guy that actually works for a huge company advising them to spend millions on whatever. Yeah, right.
Chris Gammell: I was walking around Pasadena one weekend when I was there over the weekend, and there was a Japanese food show, and I found out they were giving away free beer and sake and stuff. And so I was a purveyor of fine spirits from Ohio. And it worked fine. They didn't care. That's good. What else is on your list here? Mike made a list, so he's actually prepared here. I don't know how he thought we were going to actually run out of things to talk about, but you have things on your list, so let's get to the list. Yeah, I'm one of the things on the list.
Dave Jones: Have you got anything on your list?
Chris Gammell: No, I'm just keeping track. Well, actually, I have things like from, well, I have the things that maybe we should get back to before we get too far away from it. You were at the Tesla Museum. Yes. So we can talk about that. You and I went to the Science Museum, which is okay. And then also I wanted to talk about it.
Dave Jones: I think I actually like the Science Museum better than the Tesla one because they had like the old analog, huge analog computers and one of the Voyer's computers.
Chris Gammell: Yeah, that's right. So people remember, Voyer Antonezh was on the show when I was here last year and he did the Galaxya one of the, like the 1980s computer from Yugoslavia and we got to see it. It was smaller than I thought it would be, you know, but it was a kit and it was cool to see.
Dave Jones: But it's quite great. It's really into the center of town. It's like two, you know, two dollars to get in. If you're only in it, Belgrade is definitely worth the trip. Oh, yeah. It's the Belgrade Museum of Science and Technology, if you look that up. Yeah, yeah. The Tesla Museum, it's quite small. It's probably more interesting from the historical than the actual look at stuff. They do some sort of demos and so on, which I was struggling to not point out the technical analysis. I'm sure the guy has been like given the talk to Derny where he wasn't a technical guy and they zap people with Tesla coils. Yeah, right. So it's quite sort of...
Chris Gammell: Yeah, and we did have someone mention on the Colin show the boat and the... Yeah. There's like a... The radio control...
Dave Jones: Yeah, one of the Tesla's things, he basically did this radio control boat as a demonstration of wireless power and they had a replica of that, but that wasn't actually working. Oh, it wasn't? Okay. Basically see how it was working. Get a rough idea of how it works. Right.
Chris Gammell: Yeah, it's amazing just like the span of time, how much further ahead he was. Yeah, yeah. Yeah, that's cool. And so the other thing though was that the device you had brought, I don't know if you can talk about the little shake device.
Dave Jones: Yeah, that's something you really need to see. Again, I'll probably do a video of that at some point. Generally, if you meet me in person, I've usually got some sort of lead-based toy in my pocket that I'll bring out and show you. There's some people that just start rolling their eyes. Oh, God, Mike.
Chris Gammell: Well, the thing that I was interested in, you were really into the 0402 white LEDs and I really had never tried those before, but it seems like they're cheap and available.
Dave Jones: Yeah, well, LEDs are cheap. I mean, actually I was looking recently because of the explosion in LED lighting recently, the lighting size LEDs, the ones that are maybe like four or five millimeters square, the white ones, are just insanely cheap. If you buy a reel of those, they're under one cent each. Really? And they're stupidly bright. They are really, really amazing. Is it four millimeter LEDs? Probably a bit more than that, actually. There's a few standard formats, like 0603, but like 35, 20-something. Oh, yeah, yeah. If you look on AliExpress, you'll just see thousands and thousands of these. And there's also some interesting, like some quite nice long, thin ones, sort of about like 12 mil long by 4 mil wide. Oh, that's interesting. And a few other. And there are also some which have got like three or four dying series to run on 12 volts. But there's all sorts of interesting. But I'm just amazed at how cheap they are. So that's another one where you'll search it on Google Images? Well, AliExpress usually. AliExpress. It's all there. I mean, I wouldn't tend to use that for things I permanently install. I tend to go use Osram or Evergo. Because there's so much competition, even the big name brands are fairly cheap. So my go-to white LED is the Osram Dura-C3, which I've not counted out, but I think I must be pretty close on having designed a million of those in for various installations.
Chris Gammell: Yeah. Do you get like a shopper's card? I think it's a good point.
Dave Jones: You did it. In volume, they're like under 3p each in real quantities. Oh, wow. That's good, yeah. Again, because they're shipped in such huge quantities. One of the distributors we deal with, obviously, when they come at the factory, they come with various different binning codes for the color temperature and intensity. Oh, okay. And they quite often carry like many hundred thousand in stock. And they'll quite often, if I say, okay, I need toward like 100K, they will send me a list of all the bin codes they've got in stock and let me pick which ones I want so I can get a good grouping so that we have maybe two or three different sub bins of the color temperature.
Chris Gammell: Yeah, because I guess that would matter if you kind of looked at it from far away, if you saw the print.
Dave Jones: It's one of those things, it probably doesn't matter a huge amount. It depends a lot on the installation. But if you can do it, why wouldn't you do that? Right, of course, of course. That makes sense. Because what some of the big, at least one manufacturer did, I think they even had a patent on this. They make so much stuff, they've got this process where they get all the leads in and they just mix them all up so that in any given fixture, they've got a random distribution of these binning codes. Obviously, you have to be buying huge quantities to be able to do that. So we don't have that luxury. So it's a case of, yeah, we just talk nicely to our distributor and at least let's pick and choose to get the best match we can. That's cool. The other thing which sometimes happens, in fact, there was one thing I did a while ago, which was a moderately large white matrix. It started off as being, I think, was it 48 by 48, something like that. And we actually reduced it very slightly so that we could get the whole matrix. I think two boards would go to one reel because one reel is always going to be the same bin code. So we didn't have to mix reels on the bin. We actually adjusted the number of leads on the panel so that I think the original came, literally it was one reel plus 50 or something. So we just trimmed the size down a little bit just so that we didn't have any issues of splitting reels over boards.
Chris Gammell: Right, right. No, that's a good idea. It must be crazy too. I mean, you wouldn't think about it for an installation, but you're kind of doing production quantities at that point, I mean, like hundreds of thousands.
Dave Jones: Yeah, but it's fairly rare that we occasionally do that sort of volume, but it's quite often like 10s, 20 thousands or so. Yeah. But that can be literally 10 or 20 boards in some cases. No, that's true. But in terms of buying, it's not a huge quantity.
Chris Gammell: Yeah. And you also mentioned that you're mostly doing UK, but sometimes if you're doing a project overseas, you might manufacture overseas.
Dave Jones: Yeah, I mean, typically, again, most of these projects are not particularly constrained by the actual manufacturing cost of the hardware. A lot of the cost is the installation and all that sort of stuff. So my default way of doing it would be to get PCBs either locally or from China and get them assembled in the UK. But the Hong Kong project, you know, it was in Hong Kong and there was, say, 28,000 of these strips. So it would have been insane to ship. Yeah, I think we worked out it would have been like three and a half thousand quid just in shipping. Oh, jeez. So we actually went through a – I found a UK distributor that has a Hong Kong office. So we did it through them. And that worked out pretty well. They sort of did all the sourcing. And we got all the – like the star PCBs. There was no assembly. There were just PCBs. We got all those through PCB cart and got those delivered locally. Oh, nice. That's great. Again, that was handy because they had their office. We could get everything delivered to their office, which was quite convenient. That worked out pretty nicely. I didn't look at the final cost. The actual assembly cost, there wasn't a huge difference in the actual assembly cost compared to UK assembly. Oh, really? But it was all about the shipping and logistics for that one and the part sourcing to a lesser extent.
Chris Gammell: Yeah, and I guess it's nice to have someone local too. If you did have an issue, you could always pop down and see them or – It's local or – right? Yeah, yeah. Not going to be like right next door.
Dave Jones: Yeah, but it's a lot more next door than from the UK.
Chris Gammell: Yeah, right. Cool. So what else we got on this list here? We got –
Dave Jones: Yeah, I can't read your handwriting. Yeah, yeah, yeah. I can't compare you. Yeah. One thing I'll sort of – me, I'm sure it would have been inevitable. I'd been in the ampere again. One thing was basically how I got into reverse engineering. Yes. Okay. Which was – this would have been – I was trying to think the other day when it had been. It was probably the early 90s in the days when the first analog cellular phones came out in the UK. And the UK was one of the first places they came out. Oh, yeah. And I had a friend that worked at a repair shop doing repairs on these. And these were when like an analog – initially it was the car phones, like the big shoebox-sized bricks in the back of the car.
Chris Gammell: The ones where you've slammed it over your shoulder if you didn't make a bubble.
Dave Jones: And then later the ones where they took that same hardware and stick a big over-the-shoulder battery pack.
Chris Gammell: Yeah.
Dave Jones: Which is effectively a walkie-talkie with like more keying and stuff, right? Well, yeah. It was a cell phone. Yeah. It was the cellular – it was – I'm not sure. I vaguely remember reading the story, but I think it was the UK that actually pioneered the actual cellular method of doing things. So the phones are intelligent. They switch cells and so on. Yeah. But basically, I mean, there's some – security-wise, these things were just – it was just lucky that weren't many people trying to hack these. Because basically, the only thing that authenticates your phone to the network is your phone number, which is almost the same as the number you dial. The prefix is different, but there's a one-to-one mapping of those. And the electronic serial number, or ESN, which is the 32-bit number of which that split into a country code, a manufacturer code, a range code, and a unit code. So the entire security of this system was based on the fact that, in theory, you can't change these serial numbers.
Chris Gammell: Because who solders and who has other chips?
Dave Jones: No, no, no. That's okay because if you read – I've got all the specification documents and it says the specification, the electronic serial number, must be protected against tampering. Okay. So you can't – you clearly can't change the serial numbers. And there's some interesting stories I'll go into based around that. But basically, because obviously these things were super expensive, like a handheld mobile phone was probably £1,000. So they were very, very heavily subsidized by the networks. Well, I mean, I hear – They still are to some extent. I thought it was going to be £1,000 these days, right? Yeah. But yeah, we're talking about brick-sized things. Yeah. So basically, to cut this slightly short, mainly because of that, and also the issue of, for example, if you had a handheld phone and wanted to use it in the car, you could get a car kit, which was basically a power amplifier and various other things. But these were also super expensive. Right. So by the time the sort of sensible-sized handheld phones came out, the older car phones were actually available quite cheaply secondhand. So what would be useful to do is instead of buying this expensive car kit, you have a handheld and you get an old car phone and program it to have the same serial number. Oh, okay. Which, as long as you don't turn them on at the same time, works just fine. What happens if you did turn them on at the same time? I don't know. Don't cross the screen. Yeah, too expensive to turn. I honestly don't know what would have happened. But someone would probably have noticed. Yeah, right. And secondly, because these things were so heavily subsidized, if you bought the phone from the network, if you then wanted to change networks, you had to pay them a loan of money. Or if you wanted to export it to another country, because part of the serial number was a country code. So basically, there were two entirely legal reasons for wanting to change the serial number. Now, of course, there were some other less legal ones. But there were enough legal reasons to want to do it that if you happened to, say, for example, sell some software to do it, you could justify that on the basis that, well, this is for an entirely legitimate purpose. And I did actually write some software for one mobile cellular phone manufacturer who shall remain nameless, who could not get the stuff out of Japan to do it, and just commissioned me to, because the problem they had was service replacement. You take your phone into the phone shop, they wanted to give you a loan unit to use temporarily. Right, right, right. And it would be a real pain, for reasons I'd never quite get into it, it was a real pain to temporarily register a different one on the network. So what they did is I built them a little box. You plug the, if the phone was still working, you'd plug it in and they'd exchange. But obviously, one of the reasons you're taking it in for repair is it's not working, so maybe you can't do that. So they needed a way so that their dealers could program a serial number into their loan phones, which, again, Japan wouldn't give them, so they came to me. And, again, this is one of these industries that everyone knew everyone else, everyone knew what was going on. Yeah, it's practical. So if we get into the practicalities of, the first phone I looked at was a really old Panasonic unit, which had the serial number was stored in a bipolar prom. Okay. Which some of our younger listeners might not, but basically it's a chip where you basically blow fuses in this chip to permanently set it. It was like a 16-byte, if that, memory chip.
Chris Gammell: It was used for identification on it.
Dave Jones: Yeah, yeah. So they had this bipolar prom, which is on a PCB, which was riveted into the case and then connected to the main board with a ribbon cable. So, yeah, that was satisfying their tamper-resistant requirement. And, helpfully, the format of this prom was actually in the service manual. One of the reasons for this was that they also used a prom for what they called the NAM, which is the number assignment module, which is basically your mobile phone number. So that when you bought a phone, the shop would have a programmer for these proms. They'd plug a prom in, type your number, and you'll program that prom that you then put into a socket in the phone to get your serial number. So the service manual…
Chris Gammell: I'm just imagining a socket in a phone. Let's just take a second.
Dave Jones: Yeah, but no, by phone, bear in mind we're talking about like an 8x4x2-inch brick mounted in the back of a car. This was not how… Yeah, this is a fixed installation car phone. Yeah. So, of course, the service manual documented the NAM format because you needed that to program it. And it just, for completeness, this was in the days when everyone made really nice service manual. I remember Dave recently did a thing on the Sony D50 and they showed the service manual. That was standard in the industry before stuff went all cheap and non-repairable. So, you know, the format was in there. So, yeah, I just made up a little prom program, a dedicated prom program so people could… Actually, no, what I did was the plug from this cable plugged into the main board. So I just did a little PCB. You stick your prom on and just unplug the one from the phone and plug it straight into the PCB. Yeah, yeah. But there was, I mean, there was some hilarious bad design decisions so that, okay, this was the concept for the car phones. Fine, they did that. Yeah. Then another company did the same thing, but instead of a bipolar prom, they used an E-squared prom. Oh, yeah. So a little bit of UV light and… No, no, E-squared E-prom. So all you had to do, and in fact, the plug that went onto the main board was actually an eight-pin dill in the same pinout as the E-squared prom. So you just unplug that, plug that digital program and reprogram it. Yeah, it was completely pointless riveting this damn thing into the chassis. It was just utterly ridiculous. Yeah, right. So basically, I sort of got into the business of producing software and hardware to change serial numbers on mobile phones. Yeah. And it was, I was, there was me, there was, basically, I did a lot of the oddball phones, and there was one guy that did Motorola, because the Motorola was, Motorola was the only one that had any sort of security and real super, proper encryption on it. Gotcha. Yeah. And I don't, I know snippets. I don't know enough of the story to be able to speak authoritatively on it, but there were, you know, his software was super, super complicated. It took, like, it did this two-way encryption thing. You had to stick the phone on for literally, leave it for 10 minutes to chug away, and it did a job. So I let him play with that. Yeah. So he had that market. But I specialized in all the oddball phones, because one of the things is the manufacturers didn't care about this, because… They wanted to sell more phones, right? Yeah. Well, the two sides to this. One is, if a phone was regarded as it couldn't be, there's a lot of very dubious characters in this business, and there was a lot of interesting vocabulary that came about. So to change the number on a mobile phone was called chipping it. So to be able to, if you had a new phone comes out that couldn't be chipped, it was less popular, because people knew they couldn't, for example, you know, they couldn't put it onto a different network. Because what would happen is, when people wanted to do that, because it's only a 32-bit number, of which 16 bits would pretty much fix, people used to just make up numbers and program them into phones. So… And then register them on the network. So there was no, you know, it wasn't like the manufacturers tell the networks the list of numbers they'd issued. They would make them up. So what could happen is you would buy… A dealer would buy a new phone, only to find that its serial number had already been registered. Right. Which, again, was another reason why they needed to be able to change the serial number. It propagates down the line, yeah. And there was another thing, like, there was a very thriving trade of exporting, so that a phone would come out, particularly with Italy, and also, I think, Southern Ireland as well, because they had a different country code. For example, a phone would come out in Italy that was, say, a stylish phone, like, there was this Swatch thing that came out. There was actually a Nokia 101 in a fancy case. So someone wanted to stay out in the UK, they shipped these over from Italy and reprogrammed the serial number to a UK serial number. And there was, I mean, there were stories I heard of, like, phone cases full of cash sort of being shipped in the other direction. It was just crazy, crazy outlaw. I'm pretty sure that at least two of the people that I sort of knew ended up in prison for various things.
Chris Gammell: No, but that's interesting, too. Like, you said the stuff that you were doing definitely wasn't, I mean, there was...
Dave Jones: It was definitely being used to reprogram stolen phones. I mean, I would be totally naive, but there was enough good reason to do it that I couldn't really be accused of directly doing this purely because... I mean, the industry was ridiculously lacked. I mean, it took them many, many years to even set up... There were two networks, there were CellNet and Vodafone. And for many years, if a phone was reported as stolen on CellNet, they didn't even tell Vodafone. So you could take a stolen phone that had been reported as stolen and register it on the other network. So the networks carry a lot of blame for this, for just not caring, not doing... You know, they did eventually... By the time they got their act together, it was, you know, GSM had come along and that problem pretty much disappeared. And before there was any legislation covering any of this, that was really... It was GSM that started with. So the analog stuff died pretty much very, very quickly once GSM started. So what about the reverse engineering sets? Yeah, so basically a new phone comes out and typically what you'd have in there, you'd have an 8-bit microcontroller. And in those days, you couldn't get enough memory space on an 8-bit controller to have all the code on the chip, with one exception. So basically you had an 8-bit micro, an external ROM. You generally had an E-squared PROM that stored the serial number. Now, the serial number was pretty much a standard format. It was something like 0102, 03, 12345. And there was six bits of, I think, four bits of country code, six bits of manufacturer code, six bits of model number code, and then 16 bits of serial number. And if you read the written serial number, that was almost always stored in exactly the same format in binary in the thing. So you could read... The first thing you do, you read the E-squared PROM off the... Take the board, like 93, 4, 6s or whatever. You'd read that out and you could quite often see exactly where the number was in the memory. There were one or two cases where it was encrypted, and that's actually one story I'll go into. That's a really interesting story. But quite often you'd see it. But obviously the problem is that you don't really want to have to be messing about unsoldering these chips. People did that. If that was the only way, people would unsolder the chip-free program and solder them back in again. That was done very, very commonly. Because it was worth it. Yeah, it was worth it. It took them a bit of practice. And this is when hot air stations were quite expensive. And MetCal, actually that's where MetCal actually sold a lot of kit into that industry because you've got shielding cans and so on, and you really need an iron that can pump stuff into it. So their sales technique, they'd just lend a phone shop a MetCal for a week and they'd buy it. Oh, yeah. Of course, yeah. Because it was just like, you know, amazing. It just works, yeah. Yeah, so basically you'd have, you'd probably know where the e-squared problem. So what you do is, okay, you disassemble the ROM. And, of course, there was probably maybe a dozen different, every manufacturer used a different processor. There'd be 8051s, 6802s, pretty much every microcontroller that was on the market somebody was using. So I ended up writing a load of disassemblers. Oh, yeah. So I just disassembled the entire ROM. Now, of course, typically these would be between 32 and 64K because this ROM will be handling user interface and the network stuff, which wasn't hugely complicated. It was, you know, it was analog, so all it was doing was channel hopping, communicating with the base station. So it was quite a lot of code, but not ridiculous. Your GSM was just ridiculous. Yeah. So there were a number of techniques. One was quite often, for example, they'd have an external serial e-squared problem, which, of course, would be tied to certain iopins. So the first thing you do, you look through that code, look for any access to that iopin. Okay. And that will quite often, very quickly, you'd find the code that reads and writes the e-squared problem. You then look for calls to that code. You'd look for maybe calls to the address that you already know has got the e-squared problem. So quite often, very quickly, you'd find the code that was related to it. Now, the reason you want to do this is that you want to be able to program it without opening the phone. And almost all of these phones had some sort of factory test protocol. To actually do that in the future. So they typically have a connector on the bottom, which was often used to plug into a hands-free kit, but also for testing and quite often for programming, for example, the customer's information. In some cases, for example, NEC, all the dealers had this little programmer unit. They'd type it in, plug it in the bottom. And again, going back to this sort of jargon, underground jargon, to be able to program a phone using the connector was referred to as to being able to do it up the bum. So you'd say, oh, he can do Nokia's up the bum now. It was a very, you'd hear that expression quite frequently, which you can see how it came about. Would that be like chipping it up the bum? Is that the... The chipping was pretty much implied. If he said, you can do a Nokia up the bum, it means you can change the serial number with the connector. So my specialty became producing software to do that. So there's various routes of doing it. Yeah. So you had to firstly figure out... The primary thing was figuring out the factory test protocol, which would often be a very simple serial protocol. And what was really annoying is when I figured it out, and it was so simple that someone could sniff the bus and figure out what it is. Because the problem is that this was, again, pretty much pre-internet. But everyone in the industry knew everybody else. So if I put out a bit of software that was unprotected, within a week, every phone shop in the country would have it. And a lot of people would have made a lot of money out of that. Because it was quite time-sensitive as well. So that, you know, if you're the first person in the country to be able to do that phone, you've got a lot of business doing it. People would send phones up for you to do. So what I would have was... So what about the sniff... So if people could sniff the serial bus, why did that... I'll get into how I... So the first thing was, I had to dongle the crap out of this thing. What I did is actually... I took a commercial dongle. But actually, it had an internally squared problem that had encrypted data. And what I did is I actually put a PIC in there. So that for those phones that had some sort of encoding or encryption or... None of them used anything you could call encryption, but obfuscation. I would actually have code inside my PIC that did that final process. So they could actually disassemble my software, which of course this was DOS command line software. They could look... I could give them the source of my software and they still wouldn't know how it worked. But the second thing, for those phones which... Because most phones had a special goodness. I'll give them the dongle. That also had the... I'd make up some sort of connector. It maybe made out of PCB to go into the bottom of the phone. For those phones that had a very obvious protocol, I would find lots and lots of commands that had no function and just spray a torrent of commands that didn't do anything, but bury the actual programming commands within this torrent in such a way that it was really, really difficult to look at that torrent and figure out where a lot of the commands would happen to have pieces of the serial number in purely to disguise the fact, the real one. So you've got this massive... You might sit there for like 30 seconds spraying data out continuously and after all that data there would be like three or four bytes which were the real commands which were buried not only in a random place and that place would be randomized based on the actual serial number you were trying to program.
Chris Gammell: Oh, wow. So this is so that you could make sure that the stuff that you'd spend time on you could still actually sell that software to people.
Dave Jones: Absolutely, yeah. So people couldn't sniff that. Because it was really annoying when I... Yeah, some of them the protocol was actually quite obfuscated but some of them it was stupidly obvious like three bytes, then the serial number and that's it. Yeah, so if you just watch it for the serial number you just... Yeah, exactly. And then, you know, say there was only me and this other guy that were working at this technical level but there were other people who would have been capable of doing a serial sniff type thing. Gotcha. I think. But yeah. So I'd say there were a few interesting asides. One of them was encrypting what's in the squared prom. Now, there's one phone made by Mitsubishi where they had one of the... It was actually one of the Mitsubishi 6502 based microcontrollers where they had some internal ROM and some external ROM and they thought they were being really clever. So firstly, they obfuscated the serial number in the externally squared prom. Okay. And secondly, the code that did that was in the internal ROM. Okay. Rather than the external one. So, oh, no one can get it. That's protected. Except that all you need to do is put a bit of code in the external ROM that read out the internal ROM and spat it out of the serial port. So, yeah, I had the...
Chris Gammell: The external ROM has access to the internal ROM, you're saying?
Dave Jones: Well, the code has to jump into the external ROM at some point. So whenever it jumps in, that's when you've replaced your code. And generally, they would only put it... At the most, they'd have just a simple additive checksum to protect it. So it wasn't hard to make your own code image to go in there. And the actual obfuscation, it was just literally loads and loads of just bit shifts and shuffling. It was a ridiculous amount of code. If they'd have just done something like a symbol like LFSR shift register, it would have actually made it more secure. But they obviously just... It was quite interesting, actually. You quite often got into the mindset of some of the manufacturers by looking at the code. And someone obviously said, okay, obfuscate this. So some little low-level programmer would say, okay, we'll shift this bit left. We'll end this with X or this. We'll end this, whatever. But it was all actually pretty straightforward. You could follow the code. I mean, yeah, for the really complicated ones, I actually hooked a logic analyzer onto the problem. When you're trying to trace program flow, okay, you can do it from the disassembly listing. But if you can hook a logic analyzer on it, for example, when you find a conditional branch, instead of having to figure out from the code which branch it took, you can look at the logic analyzer and say, well, that's the one it took. And also, when it loads data, say, from an indirect address, you can see from the logic analyzer what address it's putting out on the bus so you know what that indirection was without having to track back through the codes. It was actually quite a quick way. And the other thing you could do, for example, if you're having trouble finding out where it was accessing the e-squared problem, you just set up a logic analyzer trigger on the e-squared problem chip select so that when that pin changes, you capture the code that was executing at that time. Right, and you play it back, and you could see when... And again, for example, a lot of the phones had a feature where you had, like, a few test functions on the phone, and you could display the serial number. So if you were really struggling, you'd set up, you could actually do a trace, and you'd activate that phone, and you could see it accessing, and you could trace it back. And some of the ones, there were some really interesting things. Because the format was very fixed, and you had this six-bit, six-bits, four-bits, quite often, if you just did... One of my techniques, I created a massive text file of the entire disassembly. I'd add a few very simple formatting things to my disassembly. Things like, you know, when you see a go-to or a return, put an extra line break just to break it up. Oh, yeah, yeah. Really, really simple formatting stuff. So you're scanning the... Exactly, so you could divide it into vaguely logical blocks. Yeah. So if you do something as simple as just search for, like, anding with 3F... Okay. That would, you know, you might only find four or five hits, and one of those would be the thing that takes the data and just formats it with a display. So that would immediately give you a routine that you could then trace forwards and backwards to find the bits that you really need to get to. Why 3F? Sorry. Six bits.
Chris Gammell: Ah.
Dave Jones: So you've got this first 16 bits, which is 664. Oh, I'm sorry. But it's always displayed as three pairs of two decimal digits. That was the standard. So to display that number, you would always have to take this thing and it with 3F and display it. Right. So, yeah, that way... Right. For those phones that had a way of displaying the stream number...
Chris Gammell: Yeah, so you're saying, like, bitwise operation type stuff. Yeah, yeah, exactly.
Dave Jones: So, you know, if you were lucky, there wouldn't be many of those in the code, and you could actually get to it really, really quickly.
Chris Gammell: Yeah, that's awesome. And that's... It's almost like... It's like digging through and seeing these operations is kind of just like... I mean, it is... You're deconstructing the...
Dave Jones: Yeah, yeah, yeah. Quite often, you had this massive 64... I mean, of course, this is when I still actually had a day job, and I had basically my own laser printer. This was when laser printers were quite expensive, so I had access. So I would do... Be turning, like, inch-thick printouts of disassemblies to then hand annotate. Well, this is like when you're bored at work kind of thing? Well, no. The first thing you do is disassemble it, do a printout, then start doing text searches, and then hand annotate that printout, because that was just the most easy... It would often take, like, a week to do this. Oh, really? Wow. But the point is, obviously, you don't know how long it's going to take until you've done it. Right. But so having figured out that protocol, I could then write some software to do this, sell it as a dongle software, and I would typically... It depends a lot on the phone popularity and whatever, but somewhere, anywhere between maybe 20 to maybe 40 copies of a bit of software, and then, basically, that would be distributed around enough dealers in the country that the ones that did enough phones to pay... It would maybe... I'd charge maybe £400 or £500 for this. So there'd be enough of these distributors around the country, so all their local guys would come to them. They would offer that as a service. They would make money by offering it as a service. They were taking some of the risks, because, obviously, potentially dodgy phones were passing through their hands physically. Right. But, you know, I was, like, one step removed from it, so... Right, yeah, yeah.
Chris Gammell: No, and like you said, I mean, I think you were providing a service. Any kind of service that people do could be turned into criminal enterprise in some way, right?
Dave Jones: Yeah, and, yeah, I've no idea of statistics. I mean, it would be naive for me to say that the majority probably weren't used for that purpose, but I think, you know, the networks, I think, have quite a lot to bloat to... You know, they were just so slow, but there were a few... A quick aside, there's another bit of the reverse engineering thing I go on to, but, as I was saying, the security of this was your phone number and your serial number. Yeah. So, and some of the phones had some interesting test modes that you could basically turn them into sniffers. Oh, interesting. A lot of them, you could actually type... A lot of the service modes, you literally had to type in a certain number to the keypad, and it puts into test mode. So, for example, a lot of the NEC phones, you put them into test mode, you can dial in a channel number, just listen in on one side of a conversation. There was something like... What? Basically, the channels, from memory, there was something of the order of 600 channels. And there was a separate channel for transmit and receive. It was full duplex, and they were always 40 megahertz apart. And one of the characteristic features of the analog phones is they had these massive duplexes. So, they were transmitting at maybe half a watt and receiving simultaneously 40 megahertz away at, like, minus 105 dBm. So, these duplexes were amazing. I'm amazed that they actually even work. It's very deep into where I feel it. Yeah. So, but the other thing is, because it was analog, if somebody was on a cell phone talking to a landline, there would be enough side tone that if you only were listening to one side of that, you would actually hear both sides of the conversation. Because, although, you know, you'd be listening to one side of the cell phone, but the landline, because it's only going over a single line, some of it would be echoing the other side of the conversation. So, if you're listening to someone, of course, these, yeah, mobile phones weren't that common in those days. So, chances are, if someone was using a cell phone, they were talking to a landline. So, if you take this phone, dial this code, and just randomly, just select channels, or channel up and channel down until you hit something, and you can't hear all these conversations. That's crazy. But, where it got really interesting, one company, I think it was Vodafone, were the first to introduce pay-as-you-go phones, prepaid phones. Okay. And, obviously, with analog phones, there were no SIM cards. So, the account was tied to the phone. And, I think Vodafone, they actually did it fairly sensibly. But, you know, this is an aspect I never actually got into. But, there was a lot of industry gossip. They say there's some real characters, and there was gossip. It was one of these really gossip-driven industries. The stories were just amazing. But, CellNet were totally caught off guard by this. They said, okay, hell, we need to offer a prepaid product now, really quickly. So, because they hadn't developed the network infrastructure to do this, the way they did it was they stored the credit in the phone in an eSquared prom.
Chris Gammell: So, you would basically take it into a dealer, pay 50 bucks or 50 pounds, whatever, and they would just store that credit on the phone. Yes.
Dave Jones: So, I think you can see where the problem is here. Totally.
Chris Gammell: No, actually, it only is the problem. I think it's an easy way to get free phone calls. Yeah.
Dave Jones: So, again, you know, you could go to a pub and buy a phone where either they just reprogrammed the credit or they – I'm trying to remember exactly what they did. I think someone may just change the phone firmware so it would just completely – just continuously reset. So, you had an everlasting phone until – I think the network had some sort of long-term block. It would sense it eventually and block it after quite a long time. I mean, in the early days, I mean, you know, this was set up with – they didn't know how successful it was going to be. Yeah. So, in the early days, the actual – they had so little – they hadn't invested in a huge amount of infrastructure other than what was needed to actually transmit the phone. So, the billing – the way the billing worked is that the exchange would record the billing data onto a tape and a motorbike guy would go around and collect all these tapes from the exchanges. Wow. Because that was cheaper than actually sending this information over the air because the bandwidth was all being used for calls. Right. Obviously, at some point, that stopped. Well, GSM, like you said, changed a lot of stuff. Oh, no, no. This was way before GCA. This was the early days of the analog cellular stuff. But, of course, and the other thing, obviously, about the ESN stuff is that you could program somebody else's serial number into your phones and make calls on their account. Because that's how they did the billing. They didn't do it by number. They did it by – It was purely – the ESN and the num is the only way that identified the phone. So, that was the other thing. That was known as being a basher. So, your phone has been bashed means somebody else has put your serial number into a phone. And because the serial number was basically 16 bits and, obviously, they started at zero and went upwards, it wasn't difficult to guess a serial number that was probably active and online. So, literally, you could take a phone, you know, without many tries, probably find a live account and start making calls on their phone. Wouldn't it matter, though? Like, don't you – wouldn't you be using their number? I mean, like, isn't that the problem? If you're using an outgoing call, it doesn't matter. If you're making outgoing calls, who cares? Gotcha. I see. So, you know, you'd get this phone in the pub to call your friends in, you know, Jamaica or wherever. Oh, gosh. And I think that's something where the networks were starting to then monitor this. You know, they realized that was happening and then started to monitor it. But it was just a complete naive attitude to security throughout the whole thing. Right. But –
Chris Gammell: I'm sure that story repeats itself, too, in terms of security. Oh, yeah, we'll deal with that later. Yeah, exactly.
Dave Jones: And it happened with GSM. Obviously, GSM, you know, had a lot of security designed in, but obviously that then got broken. Yeah. So, yeah, so there are a few other interesting things. One of the more interesting phones was – I think it was Novatel – where they stored the serial number in one of these non-volatile SRAM modules. Okay. So you couldn't take it off the board. You know, it wasn't even the module. I think it was just SRAM on the board with the battery backup. Right. So you couldn't take it off the board. So the way I did that one was all these phones had – like for your internal contacts list, you had maybe you could store maybe 40 or 50 numbers in the phone. So you'd like type in your phone and say store 06 and it would store that phone. Oh, yeah, yeah. Yeah, it didn't – it took a long time before they even had any text entry for it. Right, right. Remember when people used to remember numbers. Yeah, exactly. So basically the mechanism on that – I actually used this mechanism among the other phones, but that was less interesting. So what you did was you type your serial number in as if it was a phone number, stored it in a specific location. You then unplugged the ROM from the phone, plugged my little ROM in, which read the data out of that and programmed it into the SRAM serial number. Now, of course, my thing wasn't just a ROM because that would have got copied. It was actually a board with a gal on it, a program logic device, and then a ROM with my code in it. So that you couldn't copy it because the gal actually did some obfuscation, had some internal registers. Single writing, stuff like that, yeah. And also it had a lead on it so it would flash it to give you some error codes. So you'd get different flashing error codes to tell you that it was done. But what was quite amusing is that there was an industry publication called Mobile News, and that was mostly sort of sales thing. But every so often they would talk about security issues and whatever, and the industry would say, oh, this is a terrible thing. These are terrible people doing horrible things, despite the fact it was the industry that was causing most of this. And there was one article where the MD of the manufacturer of this phone was saying really proudly, oh, yeah, there's no way anyone could do this phone because we store it in non-volta home and you can't take the chip out or whatever. And I almost was going to send him one just for the hell of a bit by resistance to that temptation. I didn't see this article came out about a month after I'd done this thing. Don't poke the bear, Mike. Don't poke the bear. But, of course, yeah, I'm one of these people. One of the things I loved about it was just the sheer technical challenge and the satisfaction of beating it. Okay, you know, it was very profitable. And, yeah, thinking back a bit, there would have been ways to have made it even more profitable. So for example, maybe we've had a system whereby they type the number and it then dials up my server that then gives them the actual data to do the, so I'd actually be able to make money on everyone that got done. Right. But, again, you don't think of these things at the time. It was just sort of, you know, it was quite a fun thing. But what really, the really fun thing that then happened is that Nokia brought out a phone called the 101. Now, this was a hugely popular phone. It was one of the slim, it was a very slim phone. And it was enormously popular. And what they did is they stored their serial number in one of the Dallas laser-etched serial number chips. Oh, yeah, like the Unique ID ones? Yeah, like the DS, I can't remember what they called it. But it was fairly shortly after. It was probably actually quite a big sales win for Dallas. So these have got unique lasered serial numbers in the chip. And also, the other thing that they did, they used an H8 microcontroller that actually had enough on-board ROM that all the code was in the ROM. So, for example, if another manufacturer had done that, what you'd do is you'd just patch the firmware to nail a specific serial number into the firmware to just ignore it. But you couldn't do that. But what they did, they left enough space in the case, because these things had these big duplexes. There was quite a big ridge in the back of the case to accommodate this duplexer. And a little bit of empty space underneath it on top of where the main micro was. And that was enough space to put on a little PCB with a pick on it that emulated these Dallas serial number chips.
Chris Gammell: Yes, yes.
Dave Jones: That's the one you were telling me. Yes. So basically, I produced this system where I would sort of give the seller dealer a kit, which was a device that would program my board. So my board was a pick. This was before the days of 1660 C64. So no on-board, non-volatile. So it would be a pick and a little I squared C squared prom. And they would plug this into my program with a program with a serial number. They would then glue this chip to the top of the chip, the controller chip where there was space in the phone, and then do four little thin wires from the Dallas chip. So you'd snap the Dallas chip out and then solder these four wires onto convenient pins on the chip.
Chris Gammell: Yeah.
Dave Jones: So this would then emulate the Dallas chip, and it would have a new serial number. And there was also some – they supplied some programming software to program the user account information. So I then reverse-engineered that process and incorporated that into my programming system. So you could do the serial number and then use my software to program the deal number. So the nice thing about that was for every phone that got done, I sold one of these modules. Yeah, right. And basically that paid for my house. Right. Completely. Yeah. And then it wasn't long after that that the whole – the GSM started coming and the whole industry just pretty much collapsed. But, yeah, I made enough money to be very comfortable when they got out before the industry sort of disappeared. So that was a very nice little sideline. But, yeah, that taught me a lot – that's really taught me a lot about reverse engineering, about – yeah, it's quite often almost getting into the mindset of the – you could see by the code that, you know, none of this code was written by hacketypes. This was written by, you know – Corporate – Corporate – Yeah. Yeah, often in Japan where, again, you've got this very formalized culture. So you could very much look at this code and they'd said, okay, let's make this difficult. So they'd done this shifting or whatever without really – you know, there was no, like, imagination. So let's whack this into a CRC shift register or something. Right, right. So it was quite interesting. And different manufacturers, you could actually sometimes see different coding styles. You can see, well, you know, was this done with the compiler? Was it just purely by looking at the code? Mm-hmm. And so I think I must have written about 10 disassemblers. I wrote all these in basic. Yeah. It literally was a one-shot job just to do just enough to do it. There's no, you know, very, very minimal cross-referencing. I tend to just whack the whole thing in the test file and text file and do a text search on it. So what timeline was this? I mean, it was when the – it started – I could probably look and find some of my old files from back there. But like mid-90s? Yeah, I think early to mid-90s it would have been. I don't think it would have been.
Chris Gammell: Because also I'm thinking, like, if this was, yeah, 20 years.
Dave Jones: Yeah. Yeah. I think early 90s it started. And it lasted for, I don't know, maybe four or five years. Yeah. And that's where, you know, I was doing the day job and then it comes to the point where I was earning so much for this. I just, you know, quit the day job and went full-time. But along – in parallel with that, you know, I knew it wasn't going to last. So I was doing some consultancy stuff. Yeah. And that's how I sort of started off doing the pick stuff. That's great. And then when that died, then it just – the engineering consultancy stuff just took over from that.
Chris Gammell: And you're still a pick person mostly? I mean, is that a lot of –
Dave Jones: Yeah, mostly. I've talked about this before. And I've done some stuff with, like, the NXP arms. But, you know, the thing I like about the picks – this is a repeat. I actually listened to some of my previous NXP things, so I didn't repeat mine. Pretty much all of that is enough. Yeah, but last time it was just you and Dave. Yeah, yeah. But pretty much that was pretty much all covered. But it's just about things like, you know, the same dev tools, package availability and whatever. I mean, if – but also most of the stuff I do now is not particularly cost-sensitive. Right. You know, picks aren't necessarily the cheapest thing, but I don't care about that. Consider it in the scale of the – if I was doing something for production, then I'd certainly take a good hard look at the SGS, the ST stuff and Nordic and whatever else. But, you know, it doesn't really – I don't care whether that pick costs one pound, two pound, three pound in the scale of this thing. It just doesn't matter. Right. So use what you know is the –
Chris Gammell: Yeah, I mean, because you're on such a short timeline, it's worth it more just to have it get it done.
Dave Jones: Yeah, and the fact I can buy them pre-programmed from Microsoft if I'm doing like – Oh, I see. Yeah, like the iPod Nano, that's 2,800 QFNs. Even doing those on board would have taken quite a lot of time. Right, yeah. Even if all you do is put a bootloader in it, these things are on the same bus. You can just throw, you know, while you're waiting for those, you're writing the rest of the firmware, and then you just blow that down the serial bus, and as long as your bootloader works. I mean, one interesting tip, actually, for anyone doing anything embedded. When you do a new bit of software, it's quite often tempting, oh, you get your stuff working, and then you do the bootloader at the end. Do the bootloader first, and use that as the method you use during development to program your code. So you don't always need the emulator on there and stuff like that? Well, no, no, no, no. Purely it means you've tested the bootloader, because the one thing – Make sure it's rock solid. Exactly. Yeah, yeah. The one thing you want to be rock solid is the bootloader. So if you've tested that as part of your development process, it gives you very high confidence that that code is actually good.
Chris Gammell: Right. I've programmed thousands of times, because every time I had to load it up with a new iteration of code, we were also testing the bootloader. Yeah.
Dave Jones: And it also means sometimes, for example, if you're using manufacturer's tools that are a bit clunky, you can actually – if you've written the code to talk to your bootloader, you can have maybe your own bit of code that sits there. It sees the hex file timestamps changes. Oh, it's just compiled it and blows it straight in. So it can actually shorten your debug cycle. Yeah. And obviously, you design your bootloader in such a way that you don't have to, like, turn the thing on and wait for it to flash before it starts. You do a nice – so once your application's started, you have a way of jumping back into the bootloader quickly and programming it. And that can be as quick, if not quicker, than using some sort of hardware programmer. Yeah. But the key thing is, you know, the one thing that is really important, but bootloaders also, quite often, it's one of these things you recycle between projects, and then you suddenly forget you've put in a new chip that's got twice as much memory, and you've got some weird rollover error that it only programs half the code. So as you develop, it starts working, and then suddenly your code gets a little bit bigger, and it suddenly goes crazy. Right. You've just gone over that page boundary. But, yeah, that is one top tip that really – it will save your ass one of these days. Right.
Chris Gammell: I was talking to someone – I don't know if it was you. I was talking to someone, and we were just talking about, like, the difference between having a 30-second program cycle or a three-minute one. Like, it seems small, but when you think about all the iterations –
Dave Jones: When you're iterating, no, I mean, I'm really – I mean, I have to have – that's one of the things I hate about doing FPGA stuff. Yeah. I've got to wait, like, 30 seconds, because I do this the wrong way. I'm sure people will shout at me, say, oh, you should do simulation. I can't be bothered with that. Most of my FPGA stuff is simple enough and so far inside the capability of the device that I don't need to worry about timing stuff. Right. I just say, this is going to get this clock.
Chris Gammell: Right, and you said cost-wise, too. You just buy the faster part if you're really –
Dave Jones: Yeah. I know, but that's really about the development cycle. Okay, yes, in theory, you should. I mean, this gets me onto one of my sort of bugbears. Anyone that says this is good or bad practice at some point will always be wrong. Yes. There is no such thing as good or bad engineering or good or bad practice, only more or less appropriate for a given set of parameters. Right. And with almost zero exceptions to that rule. So things which might be horrifically bad in some – could be the exact right answer in another scenario. What about – And vice versa.
Chris Gammell: I'm trying to think of just ridiculous scenarios.
Dave Jones: Think of any bad engineering. I bet there is some scenario where you could actually justify doing it.
Chris Gammell: What if I programmed something over a serial bus, but I was using a straight key from like –
Dave Jones: No, I'm eliminating just dumb stupid decisions. The stupid and not stupid. But when everyone said, oh, you shouldn't do self-modifying code or you shouldn't do updating code by copying your code into RAM first because you might get a power down. Right. Right. Right. Right. Right. There are always some situations.
Chris Gammell: Thoughtful engineering and whatever comes out of that is always the right answer. Yeah.
Dave Jones: But it's also about analyzing, well, what are the requirements of this system? Right. Yes. Are these things important? Are these things not important? And don't waste time on doing things that don't actually matter. Yeah. Let's say, for example, I was saying on lighting systems, people say, oh, you've got a communication protocol, so you should have error checking, whatever. Well, so, you know, use a reliable protocol and it's one way and, A, errors aren't going to occur and, B, if they occur, they don't matter. Right. Right. But if you do have error checking, that's a whole load more code that could go wrong. You then have to deal with all the error situations. So, you know, it's about figuring out what the best solution is for any given problem and every problem is different. Yes. Yeah, I totally agree. I think – But, you know, when people start saying, oh, that's bad practice, my red light comes on and, you know. Right.
Chris Gammell: Well, and I think, too, like, you know, like, that's people that are not building things usually, right? They're like, oh, well, there's this proper way of doing it. It's like, have you built it this way? Have you seen it?
Dave Jones: Yeah, like, oh, you've got RS-232, so you've got to use a Max-232. You can't just use a resistor on an inverter and a inverter software. Yeah, yeah, yeah. And the arguments I've had about – with people about RS-232 transceive, unfortunately, that's gone away because people don't use RS-232 anymore. I've seen some – in the pick list, there's been some – not just me, other people, which is major sort of punch-ups about whether or not it's worth using Max-232s or whatever. Right, right, right, right. But those arguments, you know, people like, for example, people that say you should never connect LEDs in parallel and, you know, things like that. Right, right. You know, there's always some qualification on that argument. And a lot of the time, that sort of thing is spouted by people that either have a very narrow view, like they work in industry and selling, like, hugely expensive kits and have never designed a toy. Right. You know, in the industry, you stick decarping caps everywhere. On the toy, you start off with none and put one at a time in until the thing works and then ship it. Yeah, yeah, yeah.
Chris Gammell: Yeah. So what about other – so you said reverse engineering. I mean, was that mostly in the phone space? I mean – Pretty much.
Dave Jones: I mean, yeah, that went on for – and I lost – it must have been well over maybe 15 to 20 phones I did that from scratch. Literally, all I had in my hand was a phone, no other information at all other than the label on the back that told you what the serial number was. And literally to reverse engineer where the number was stored, their factory test protocol, how to program the serial number over that, or to do another work – there was actually another one that comes to mind, which was interesting. There was a phone by Okie. Bear in mind, in these days, there were loads of phone manufacturers. A lot of companies were getting into it. Some were badging other people's phones. So, you know, there was a new model coming out every week and there was a new manufacturer. So there were maybe well over a dozen different manufacturers. Yeah. And then even more where someone was badging somebody else's phone. So this Okie phone had the serial number in a parallel E-squared prom. It was like a 28C64 or 28C16. And part of the address – I think they actually had a custom chip in this. So the microcontroller, a custom chip that – towards the end, almost all the phones had a custom chip to handle a lot of the cellular stuff. They had an analog chip and they sometimes had some stuff to do a lot of the digital handling stuff. And one of the things they did in this chip is that I think either all or part of the address bus went through this custom chip. And what they did is they stored the serial number in a location which, if you tried to access that from the processor, it would block it. So in theory, you couldn't write a piece of code in the software. And there was probably some obfuscated way to unlock that, which obviously there was no real way of knowing. So that probably only happened to the factory. So you write to that address. It doesn't do the right. You can't change the serial number. So you unsold a one-address pin, tie it, so you write to a different address that when that pin is tied, actually maps to the real address. That's great. And then they started putting epoxy over the chips. They quite often did that anyway. But that, you know. It got messier. I just love that. I think one of my strengths is lateral thinking. And, you know, people sort of industry type do their software the way they think it should be done. And I say, well, let's just botch the hardware and fix it. Right, right, right. That's a good one. I like that one a lot. Because I'm one of the other ones that is similar to that one that's stored in SRAM. And, again, they're all one or two phones, which I think before I'd figured out the protocol, I just did a replacement software on them. So you actually, I just, a slight patch to their code. So you stick my code in, type the serial number, and then store it in a specific location, and they'd actually do that right. And some phones, actually, they left that ROM in the phone. But that was highly unsecure because I couldn't really let that out because as soon as I did it, it would be like over the country in seconds. In fact, I was actually showing to one of my slightly dubious customers. And I sort of showed him this process and showed him the chip. And he had this. This is actually, there were some really interesting packages in those days. This was really before Flash was a thing. So you had UV EEPROMs in ceramic quad packs, in SO. There exists a ceramic windowed SO. I've still got most of these chips at home. Yeah, yeah, yeah. Like ceramic windowed SO package. That's a tiny window. And you could buy socket. Well, there wasn't a window. The whole top surface was a solid piece of quartz. Really? And there wasn't that. And these were in sockets, of course. Yeah, yeah. And I was actually showing this guy, this chip. He picked it up and was looking at it. And I thought he was thinking, I'm going to stick this in my pocket. So I said to him, quick, don't touch those spins. You'll get grease on it. And he used that as he used to get it back out of his hands before he suddenly disappeared. Wow, that's crazy. But no, it was crazy. And yeah, I learned a lot through it. And there's a lot of highly dubious characters in it. But yeah, it was very, very profitable at the time. And then say it.
Chris Gammell: So then you said you were working there. But you were working before that. And you did this. And then was that right when you got into interaction design stuff?
Dave Jones: No, for quite a lot. Basically, I sort of moved into the PIC consultancy thing. So I did a lot of industrial consultancy type stuff for quite a long time.
Chris Gammell: Really listed as one of the microchip. Yeah, I was on the developed list.
Dave Jones: Which is a great idea. I mean, for people that are getting into it, it's like, if you get on that list. Yeah, and then you find things like SJS Thompson then took that list and called everyone and said, you know, we're doing a program. And I think quite a lot of that goes on. And a lot of it is word of mouth. Again, I've discussed a lot of this in some of the previous things. Like, I do work for a company. The guy from that company goes to another company or whatever. But then, say, it was really by chance I sort of met up with someone that would clearly run out of what they could do with off-the-shelf electronics. And that's really sort of where all this will happen. And actually, one thing I meant to mention, I mean, I now, I just don't do any, I turn away any production job now. Because the problem with production stuff is you do the prototype, you give it to the customer, they go away, you go and do something else. Then three months later, they want to put it in production. You then got to remember everything. You got all the boring stuff like documentation. I'm just not interested in that stuff anymore. Right. You're at the point where you get to pick and choose whatever you want. Yeah, most of my jobs are design it, build it, next job. And, you know, okay, maybe two years later, design a slightly, yeah, have a slightly similar job that I can recycle from code and whatever. But there was an interesting comment on, I think it was Embedded FM a week or two ago, about talking about consulting. And the guy was saying it's a good thing to not be the smartest guy in the room. Okay. The reason being is they hire you to do this, whatever it is. And what you ideally want is to be able to hand that off to somebody that understands it and knows what they could do. So if they then need to do it, they can actually, they're then self-sufficient. They can do stuff themselves to it. They don't have to call you. Right. And this was really a situation I got into. Most of my consulting work was with companies that either had no in-house electronics or very little. Yeah. So they were very dependent on me. Right.
Chris Gammell: And that's when you get the calls at 2 a.m., right?
Dave Jones: Yeah, well, it's not so much that, it's the ongoing thing which, you know, the boredom threshold starts increasing. But also, I mean, there were certainly some jobs where they really should, I told them, said, look, you should not be hiring a one-man band to do this. Because this product into which you're putting a lot of investment, if I fall under a bus, you are screwed. Yeah, right. Especially the industry they were in. But, you know, I think there were sufficiently few, I don't know whether it was a management thing they weren't prepared to invest in taking people on in-house or whether they couldn't get people or anything. Again, this started off, you know, my, into that company was a guy I'd done work from before, worked in that company. He had this idea for a new product range. He pulled me in to do a proof-of-concept thing. And then I was then into the development of the product. And that product then transformed. Then they got an in-house electronics guy. But they didn't really have the in-house software still. So I was still doing software, which I don't like doing software. Right. So you should. I was increasingly starting to hate this job. Yeah. But I couldn't easily just drop it because it would really screw them up.
Chris Gammell: So these days, though, you would just tell them just straight, no, I'm not going to do that.
Dave Jones: No, no. Because the thing is, I still get emails saying, you know, oh, we want a proof-of-concept, but we'll get someone to do it. But I just know that is not going to happen. Right. Because it's going to say, oh, yeah, Mike, you know, can you do this? We couldn't find anyone to do this. And I just say, no, sorry. Yeah. Yeah, even like, you know, unless it, if it's something simple, I can just turn around in a day and say, look, you know, I'm doing this prototype and that's it. No more than, you know, if it's something I can do quickly. Or quite often, what sometimes happens is, obviously, every job I do, I end up with a few spare leftover boards. So if I can patch together one of those to do something and do it, then maybe I'll do that. But generally, I just don't, I'm not interested. Yeah. As a consequence of all the phone stuff, you know, I don't need the work. Right. Yeah. The house is paid for. I've got fairly low living costs. I don't drink. Right, right. I don't, don't, don't have any expensive vices. So, you know, I could afford to.
Chris Gammell: Your expensive vices are in your equipment and that's already pulled out. Yeah.
Dave Jones: But I, even then, I mean, I, you know, I'm not someone, you know, I like sort of toys and stuff, but I, I won't go and buy stuff unless I know I'm going to use it. So, okay, it's nice to play with toys, but having to sit there, I just don't get, you know, it feels a bit. Space is, yeah. Yeah.
Chris Gammell: Premium too, right?
Dave Jones: Yeah, yeah. The space is the other issue. So, you know, I don't actually spend a huge amount on sort of tests. Yeah. A lot of my, my scope is like 12 years old and I've, you know, I've actually got a spare one for various reasons of the same model. But there's no particular, you know, I could go out tomorrow and buy like a, an agilent sort of two gig off the shelf, you know, two gig super turbo nutter scope. But, you know, I wouldn't make use of it particularly. How have they not used that as a name yet? But, you know, I'd have to rearrange my entire equipment shelf for it. Yeah, right. Exactly.
Chris Gammell: Exactly. Yeah. No, that's, that's good. I mean, I think it's good to have that kind of focus on what you actually want to be doing too. Yeah.
Dave Jones: I mean, I've always had some sort of scale with what I charge is, you know, inversely proportional to how interesting the job is, which is one of my failings. I've always found it very hard to know what to charge and found it very hard to charge a lot of money for something that I don't find particularly difficult, which is probably a bit of a problem. Yeah. And to the extent that one of my sort of fairly longstanding customers will actually, you know, I'll say, I'll give them, I think this job's going to be about, I don't know, X thousand pounds. And he just said, look, you know, we've got a budget, double that. Yeah.
Chris Gammell: Round up. Yeah. Big round up. Yeah. Yeah. Yeah. Yeah. And that's good too. That means you're working with good people that are. Yeah, absolutely. Yeah. Keeping you in mind because you're helping them out. Yeah. Yeah. You're helping them out. That's good. Well, we are half an hour over our amp hour. Surprise, surprise. Mr. Coming Up With The Name. But yeah, that is expected and I'm sure appreciated by people that are listening. Yeah. I'm going to be bugging you for some videos because you've promised that you're making videos now.
Dave Jones: I've got quite a big list in my head. I've got, you know, it's a matter of time. I'm doing more and more batting away of jobs because I do want to spend more time doing my own stuff. Yeah. Yeah. But I've got, there's a couple of jobs that are happening when I get back to sort of production stuff and other things may well. Yeah. There might be another call trip. Yeah, there's stuff in the queue. And I'm planning on going to electronic and I'm probably going to make affairs by area. Oh, yeah, right.
Chris Gammell: So you might be out in California. We'll be talking about that if you're out there. Yeah.
Dave Jones: Yeah. I'm pretty certain. Yeah. I've really enjoyed the whole experience of being over here just talking. I mean, one of the problems is that I don't often get a chance to talk face to face to people on a similar technical level to me. And, yeah, that's one. That's pretty much always been the case. Yeah. And, for example, you know, when I talk, occasionally I'm going to companies that are technical people, but it's just so nice to be able to, yeah, talk about, you know, MOSFETs and they actually know what the hell I'm talking about. Yeah. So I've really enjoyed that aspect of the Hackaday thing. Yeah. So I think that's really made my mind that, yes, I pretty much am going to. I've always been wanting to go to San Francisco anyway and make a fair would seem to be a reasonable excuse. And, obviously, there's the various Hackaday things going on. So it's really a case of figuring out some dates that work with other stuff. I need to figure out what stuff's piled up when I go home and figure out some dates. So I'm provisionally planned. I might actually be helping out on somebody's stand. So I might better say, OK, if you want to meet me, I'm going to be on this stand at this afternoon or whatever, which might be quite handy. So if you're there, we'll definitely sit here. Yeah. That kind of stuff.
Chris Gammell: Friends of the show. Yeah.
Dave Jones: And so I'm probably going to Electronica this year.
Chris Gammell: Oh, good. Yeah. I'm not sure if I'm going to that one, but it is every two years, right?
Dave Jones: Yes.
Chris Gammell: Yeah.
Dave Jones: Yeah. That was interesting.
Chris Gammell: It was interesting culture there. Yeah. A little bit more. I know someone that lives in Munich, so it's a quick, easy enough thing.
Dave Jones: Perfect.
Chris Gammell: Awesome. Well, we will keep an eye and we'll, you know, where is Mike in the world? The Mike report. Yeah.
Dave Jones: Yeah.
Chris Gammell: All right. Great. Well, thanks for being on the show again. Appreciate it.
Dave Jones: You're welcome. I'm sure it probably won't be the last. No, definitely not. It looks like it's an annual residence. That's right. At the moment. Great. Talk to you soon. Okay. Cheers.
Dave Jones: We'll see you next time.
Archived Discussion (10)
Comments are closed. Archived from the original site.
Show archived discussion (10)Hide discussion
BelgradeEidophorHackadayInteractive InstallationsMeetupMike HarrisonResonateReverse Engineering
Keep current
Every episode, plus the occasional job post, in your inbox.

http://tehnika.talkb2b.net/en
But nowadays, all integrated, only easy way would be software, or internet of things or connected smart industry, and we all know where these bullshit bingos come from :)
Today is the GREATEST time to start something new. Apps, cheap hardware platforms, easy access to all the knowledge you would ever need. That 'iot bullshit' will become as ubiquitous as cellphones or wifi in the nineties.
Do you really think people in the nineties went 'wifi is the future, lets invest in that'? Here is a reality check https://www.youtube.com/watch?v=Tj5NNxVwNwQ
Few more interviews and we will learn you came up with first playstation mod (pic 12C508) ;o)