Category: Other

The Titus II Complete SDR Solution

Recently we’ve heard news of a new portable SDR called the PantronX Titus II which is currently in development. The receiver is a full SDR solution, including the computer, speakers, antenna and SDR all in a single boombox styled enclosure. The computer appears to be based on an Android tablet, and comes with a Quad-core ARM A53 @ 1.2 GHz CPU, 1 GB RAM, 8 GB Flash memory, 7″ TFT screen, touch screen, 5 watt stereo audio, li-poly battery. HDMI output, microUSB OTG connector, WiFI/Bluetooth connectivitiy as well as having an optional camera. 

The frequency range extends from 100 kHz to 2 GHz, and the built in software is capable of decoding AM/FM/SSB and DRM. Since it is essentially an SDR with an Android tablet, it should also be capable of decoding any other signal, as long as software decoders are written for it. We are unsure what SDR is used on the inside, but judging by its frequency range we speculate that it may be the same Mirics chips that are used inside the SDRplay RSP.

Rumour currently has it from word of mouth of the developers that this unit will priced “well below $100 USD”.

The promotional PDF can be found here.

titus-2-big

Introduction to Signal Analysis Class in Baltimore-DC

A four week free class on signal analysis using SDR’s like the RTL-SDR will be taking place in the “Unallocated Space” technology community center in Baltimore-DC area. It starts on Tuesday September 20, 2016 at 7pm to 10pm. The class will help participants set up their systems, and cover locating, identifying, demodulating, and decoding common RF signal types. On the final week they will host a wireless capture the flag competition, where students will use their skills to solve problems and earn points.

You will need to bring your own SDR hardware such as an RTL-SDR, as well as an omnidirectional antenna and a PC/laptop capable of running your SDR.

Creating a Long Term Averaged Waterfall on HDSDR with Chronolapse

While tools like rtl_power and rx_power now exist for creating long term averaged waterfalls for many SDR’s, another option is to use a screenshot grabber to grab screenshots of the waterfall every few seconds on an SDR program like HDSDR.

This is what the admin of the coolsdrstuff.blogspot.com blog has done. The author used the program Chronolapse which was set to take a screenshot every 60 seconds. The waterfall in HDSDR was then set to a speed so that the waterfall would complete one cycle every 60 seconds. Then after collecting images all night he used Irfanview to bulk resize all the images to be 1 pixel high. Finally he then combined all the 1 pixel high images into a nice waterfall image.

The waterfall speed in HDSDR can also be set to a very slow update speed, but the problem with this as noted by the author is that this does not average the data, meaning that data in between waterfall updates is lost. 

An overnight averaged waterfall from HDSDR.
An overnight averaged waterfall from HDSDR.

Las Vegas CyberSpectrum: Streaming Live August 4

Every month SDR evangelist Balint Seeber hosts the Cyberspectrum Meetup in San Francisco, where many SDR fans come together to listen to various presentations. This months meetup is a special event that will be held in Las Vegas during the week of the big DEFCON and Black Hat conferences which are also being held in Las Vegas.

The talks will be presented at the SYN Shop Hackerspace in Las Vegas, and will also be live streamed via YouTube as usual (probably on balints YouTube Channel). The meetup begins on Thursday, August 4, 2016 at 6:30 PM Las Vegas time.

This month the talks include:

• “SlackRadio: Turning your Slack channel into a radio station” with Nate Temple

Slack is a popular real-time messaging system designed for team use. I will demo a small application built with GNU Radio and the Slack API that turns your Slack channel into a real radio station for your office.

slack_radio

• “Pothosware” with Josh Blum

Pothosware: An open-source software stack for the SDR community including the Pothos framework for creating interconnected topologies of processing blocks, Pothos GUI for graphical designing, controlling, and visualizing topologies, and SoapySDR – a SDR abstraction layer. The talk will present and overview of the software, cover the inner workings of the framework, and demonstrations with the GUI.

pothosware

• FPGA-based ADS-B SDR Receiver with Brian Padalino

Brian will discuss the design and implementation of an ADS-B receiver in the FPGA over the BladeRF.

bladerf_adsp_fpga

BIOS

Nate Temple:

I am software engineer, SDR Enthusiast, Maker and Amateur Radio operator. I previous presented the “Etch-a-SDR” at Cybserspectrum #11.

Josh Blum:

Josh has been crafting open source tools for the SDR community for over 10 years, starting with the GNU Radio companion back in 2006. He has been heavily involved in USRP FPGA and driver development, and now operates as an independent contractor.

Brian Padalino:

Brian has 11 years of experience working on signal processing in FPGA’s and has implemented multiple modems for real time performance. He is also the co-founder of Nuand and helped create the bladeRF.

Building a Software Defined Radio from Scratch

Over on his blog Lukas Lao Beyer has uploaded a post that shows his journey with designing and building a software defined radio from scratch. Lukas’ finished SDR design is called the FreeSRP and is based on the Analog Deviced AD9364 transceiver and a Xlinx FPGA.

In his post Lukas describes how he designed the PCB with Altium Designer, routing the traces carefully to ensure the shortest path was used, and to ensure impedance matching was correct. Then after producing the PCB’s with OSH park he writes how he assembled the board by carefully placing the components down by hand and using his reflow oven. This was no easy task due to the manual nature of the operation and the high possibility for undetectable solder problems to arise. Despite the difficulties he found that the SDR powered up as expected.

His next steps were to start work on the FPGA controller design, however he discovered that he had failed to properly route some clock pins on the FPGA. On his third revision of the PCB he was able to fix this. Finally he was able to program the FPGA and get his SDR to work.

Designing an SDR from scratch is no easy task, especially if you have little design experience like Lukas did. However, in the end despite some mistakes he was able to build a working SDR that interfaces with GNU Radio. 

Lukas' FreeSRP SDR.
Lukas’ FreeSRP SDR.

Cheating at Pokémon Go with a HackRF and GPS Spoofing

"Pokémon Go" is the latest in smartphone augmented reality gaming crazes. You may have already heard about the game on the news, or seen kids playing it in your neighborhood. To play, players must walk around in the real world with their GPS enabled smartphone, collecting different virtual Pokémon which appear at random spots in the real world, replenishing the virtual items need to collect Pokemon at "Pokéstops" and putting Pokémon to battle at "Gyms". Pokéstops and gyms are often city landmarks such as popular shops, fountains, statues, signs etc. For those who have no idea what "Pokémon" are: Pokémon are fictional animals from a popular children's cartoon and comic.

Since the game is GPS based, Stefan Kiese decided to see if he could cheat at the game by spoofing his GPS location using a HackRF software defined radio. The HackRF is a relatively low cost multipurpose TX and RX capable software defined radio. When playing the game, players often walk from Pokéstop to Pokéstop, collecting Pokémon along the way, and replenishing their items. By spoofing the GPS signal he is able to simulate walking around in the physical world, potentially automating the collection of Pokémon and replenishment of items at Pokéstops.

To do this he used the off the shelf "GPS-SDR-Sim" software by Takuji Ebinuma which is a GPS Spoofing tool for transmit capable SDR's like the HackRF, bladeRF and USRP radios. At first, when using the software Stefan noticed that the HackRF was simply jamming his GPS signals, and not simulating the satellites. He discovered the problem was with the HackRF's clock not being accurate enough. To solve this he used a function generator to input a stable 10 MHz square wave into the HackRF's clock input port. He also found that he needed to disable "Assisted GPS (a-gps)" on his phone which uses local cell phone towers to help improve GPS location tracking.

Next he was able to use the GPS-SDR-Sim tools to plot a simulated walking route and see his virtual character walking around on the real world map. A warning if you intend on doing this: Remember that 1) spoofing or jamming GPS is highly illegal in most countries outside of a shielded test lab setting, so you must ensure that your spoofed GPS signal does not interfere with anything, and 2) the game likely has cheating detection and will probably ban you if you don't simulate a regular walking speed.

GPS spoofing is not new. One attempt in 2013 allowed university researchers to send a 80 million dollar 213-foot yacht off course, and it is suspected that hackers from the Iranian government have used GPS spoofing to divert and land an American stealth drone back in 2011. In past posts we also showed how security researcher Lin Huang was able to spoof GPS and bypass drone no fly restrictions.

[Also seen on Hackaday.com] / [Russian Readers: There is a translation of this article by softdroid now available]

The "Pokemon Go" GPS spoofing set up.
The "Pokemon Go" GPS spoofing set up.

What’s so special about 50 Ohms?

Hackaday contributor Al Williams has posted an article on Hackaday titled “What’s special about 50 Ohms”. Components such as coax, connectors and other components in RF circuits all have an important parameter called impedance. For good signal performance we want everything to have the same impedance. If wildly different impedances are used between components the signal will experience reflection (i.e. not all of the signal gets transmitted and some gets reflected back, causing a reduction in signal).

The standard impedance used in most radio equipment is 50 Ohms, however some applications like TV prefer to use 75 Ohms. The hackaday article discusses why 50 and 75 Ohms is the standard impedance used. Basically 50 Ohms is an compromise between the impedance of best power handling (30 Ohms) and the impedance of lowest loss (77 Ohms) of air dielectric coax cable.

coax

Live Right Now: Cyberspectrum 17 Software Defined Radio Meetup

Every month SDR evangelist Balint Seeber hosts the Cyberspectrum Meetup in San Francisco, where many SDR fans come together to listen to various presentations. This months meetup is live right now (at the time of this post) and you can watch it live now on YouTube, or delayed later now over, but the recorded stream is available for viewing on YouTube. If you are in San Francisco you can attend the live meetup, but if not you can watch the live stream on YouTube.

This time the talks include:

•”The Land Mobile Radio Spectrum: What is out there, how it works, and how you can hear it” with Desmond Crisis (@dcrisis)

Wireless two-way is the technology that keeps the world working in sync. I’ll explore the various public safety, private enterprise, and personal communications services from[masked] MHz.  We’ll discuss the occupied spectrum, modulation bandwidths, trunked radio schemes and digital transmission modes currently in use on the band as well as what lies ahead. Bring your SDR kit and play along!

lmrs

• An Academic Look at Interference & Jamming

• Installfest / Hackfest / Debugfest