ChronIC RF hacking tool for TI Chronos watch

Posted on Sunday, March 17th, 2013 in hacks, MSP430, open source, RF by the machinegeek

Adam Laurie (a/k/a/ Major Malfunction) is a white hat hacker from London, UK, who has presented at a number of conferences worldwide. He’s also the Director at Aperature Labs, Ltd. His latest explorations involve the world of RF remote control systems operating in the unlicensed ISM bands. He used the FunCube dongle to monitor the transmissions from various devices operating in the 433 MHz ISM band, along with free open source GNUradio and Audacity for signal acquisition and analysis.

As a result he discovered that many types of transmissions on the 433 MHz band are capable of being spoofed by the TI ez430 Chronos Watch. In order to simplify this use of the Chronos watch, Adam developed and released a software RF hacking package known as Chronos Integrated Commander (ChronIC).

“It’s basically a cut-down RFCat-like firmware package that allows you to use the watch to transmit arbitrary signals. You can set it up either from the watch itself, or via the original Chronos dongle with a Python helper, and then the up/down buttons on the right of the watch do the transmitting.”

The full project log can be on found on Adam’s blog. The ChronIC code can be found on GitHub.

This entry was posted on Sunday, March 17th, 2013 at 3:56 am and is filed under hacks, MSP430, open source, RF. You can follow any responses to this entry through the RSS 2.0 feed. You can skip to the end and leave a response. Pinging is currently not allowed.

One Response to “ChronIC RF hacking tool for TI Chronos watch”

Leave a Reply

Notify me of followup comments via e-mail. You can also subscribe without commenting.

Recent Comments

  • Pekka Akselin: This is ridiculous!? :-) We are back at 256(!) byte EPROMs that needed multiple, a handful, of voltages to run! :-(
  • KH: Let's try a back-of-envelope calc balancing energies. From MCP1700 datasheet, there are graphs for a 200mA load step. Estimate the energy shortfall as 12uJ. Say...
  • Daniel: It's been a week and my comment is still awaiting moderation. Apparently the CIA doesn't want their involvement known?
  • KH: Agree, so okay, I guess he must have learned from somewhere. 100nF and 1000uF is so far apart, that was jarring; it's more magic incantation...
  • Max: I have a suspicion the hefty electrolytic cap might be some sort of cargo cult carry-over from other RF-based projects - for instance, I've seen...