I'm coming to COLORADO! Catch me in DENVER on Jan 22 at The Tattered Cover<, and in COLORADO SPRINGS from Jan 23–25 where I'm the Guest of Honor at COSine. Then I'll be in OTTAWA on Jan 28 at Perfect Books and in TORONTO with Tim Wu on Jan 30.
If Andrew "bunnie" Huang didn't actually exist, I'd swear he was a character out of a(n extraordinarily technologically well-informed) cyberpunk novel. Every time I interact with this legendary hardware hacker, he blows my mind with some incredible project or insight that permanently alters how I think about technology.
I first met bunnie when he came to EFF for help with the threats he'd received from Microsoft. At the time, bunnie was an electrical engineering grad student at MIT, and he'd taken the bootloader locks on the new Xbox platform as a personal affront and challenge. He applied his prodigious skill and talent to these digital handcuffs, and in short order, he had broken the Xbox and installed Linux on it. MIT's general counsel immediately washed its hands of any responsibility to defend this young grad student from bullying by a corporate monopolist, hanging him out to dry. So he turned to us – and we got his back. You can read all about it in Hacking the Xbox, his canonical work about hardware hacking and technological freedom (it's free!):
In the many years since, I've been lucky enough to count bunnie as a friend, colleague and comrade, albeit one I only physically run into every year or so, usually at some tech event or on the playa at Burning Man, where he still camps with the MIT crew at The Institute.
I just got to see bunnie in person again, over Christmas week at the Chaos Communications Congress in Hamburg. He gave a late-night presentation with his collaborator Sean "xobs" Cross, entitled "Xous: A Pure-Rust Rethink of the Embedded Operating System":
https://www.youtube.com/watch?v=BbWWGkyIBGM
Don't let the technical-sounding title intimidate you! This was a banger of a talk, and as with every bunnie Huang production, it left a pleasant and persistent aftertaste.
The background for this talk is bunnie's obsession with building a trustworthy computer. For decades, bunnie has been chasing the dream of a computer whose every component – operating system, drivers, firmware, and hardware designs – are open to inspection. Bunnie's reasoning here is that anything that can't be inspected (and, by extension, modified) by its users is a spot where bad guys can hide bad stuff, and where lurking bugs can fester until they are exploited by bad guys. Remember the spectacular (and still mysterious) claims that Apple's servers had all been compromised with minuscule hardware bugs? The single best explanation of that you will find comes from bunnie:
https://www.youtube.com/watch?v=RqQhWitJ1As
Bunnie was doing all this before there was an "open source hardware" movement, and he remains at its vanguard. His "Precursor" project is a reference hardware platform where every component is open to inspection and modification, from the chassis to the random number generator:
One area of especial concern and interest for bunnie is the promise and peril of the "system-on-a-chip" (SoC). This is exactly what it sounds like: a cheap chip that incorporates everything you need to do full-fledged computing, including interfaces and drivers for networks, screens, peripherals, etc. SoCs are ubiquitous. You find them in things like individual car engine components and inkjet printer cartridges, and each one is a whole-ass computer, capable of running some really ugly malware.
As bunnie explained back in 2020, there are two problems with SoCs: first, they are packaged such that the silicon traces inside of them can't be readily inspected, and second, they are so expensive to fabricate that someone like bunnie can't possibly come up with the millions needed to make an open, trustworthy, inspectable alternative:
That's where bunnie's CCC talk comes in. The chips that SoCs are etched upon have lots of space (relatively speaking – we're talking about nanometer-scale circuits, after all). Even after an SoC designer packs in a ton of extra traces to handle oddball applications, the chip is still mostly "dark matter" – blank silicon.
The first half of bunnie and xobs's talk concerns itself with "Xous," a secure operating system for an SoC, written in Rust. But the second half of the talk tackles the problem of procuring an SoC that you can trust to run Xous on. That's where this dark matter comes in.
Bunnie's day-job is consulting on extremely gnarly, high-stakes, high-value hardware design and manufacturing, so naturally, he's got lots of clients and contacts in the SoC manufacturing world. He approached one of these companies with a proposal: let me tape out a whole separate chip that fits in the dark matter for one of your upcoming chips. Adding these traces adds virtually no cost to the production, and adding bunnie's chips to the production run actually saves the manufacturer money, because the prices drop when the quantities increase.
The idea is to put two chips on the chip, and badge most of them with the OEM's branding, while a small rump of the chips will have bunnie's branding (he calls it the Baochip). On bunnie's chips, the traces to the OEM chip will be physically cut, meaning that the Baochips will just be Baochips – the original chip will be inaccessible and unusable.
What's more, bunnie didn't just fit one chip into the OEM's "dark matter" – he fit five separate, specialized SoCs into the unused space. Remember, the beauty of SoCs is that once they're taped out and sent to production, the cost of an actual chip is peanuts, meaning that these Baochips are cheap as hell.
Even better: the traces on these chips are scaled to be readily inspected using relatively low-cost equipment, meaning that many parties around the world can grab one of these chips, stick it in a machine, and compare the traces on the chip to the free, open sourcefile that was used to produce it, confirming that there are no nasty surprises lurking inside.
This was such an exciting talk, and as I sat through it, I had this nagging feeling that it reminded me of something else I'd learned about years before, though I couldn't quite place it. Finally, as bunnie and xobs were stepping off the stage, I had it – it reminded me of another bunnie talk I'd seen – this one at The Institute, the MIT Burning Man camp, more than a decade prior.
Back in 2015, bunnie designed and built a set of really cool, wearable radio-linked badges for his campmates, which would help them locate one another on the playa at night. These badges were really cool – they used a genetic algorithm to "have sex" with one another and mutate their color patterns. Bunnie even worked in a "consent" mechanism!
But the really cool part that stuck with me was the manufacturing story. Bunnie wanted to fabricate custom injection-molded plastic enclosures for these pendants, but injection molding – like chip design – is a mass production phenomenon, with sky-high setup costs and incredibly cheap per-unit costs thereafter.
So (and this might sound familiar) bunnie reached out to a die-maker that he worked with in China and said, "Hey, the next time you're contracted to mill out a die for a client, let me know if there's any extra space on the face of the die, and I'll provide you with a shapefile you can carve out of this 'dark matter.'" This doesn't add any cost to the die setup, and it means that bunnie can run just a couple dozen injection-molded, custom cases at a cost of pennies per unit.
I grabbed bunnie later that night and mentioned this old Burning Man project to him and he said, "You know, I haven't ever thought of it, but you're right, there's definitely a throughline between the two projects."
I asked him what he called this technique and he shrugged and said he didn't really have a name for it, but he thought of it as "piggybacking," which seems like a good name to me.
It seems to me that these two kinds of manufacturing can't be the only ones that can be "piggybacked" onto. That's what motivated me to write this post – to get people thinking about these high-setup/low-unit cost production types that might be piggybacked for small batch, delightful projects like bunnie's.
Well, that, and just to do one of my periodic bunnie Huang appreciation posts. If there's one person that I'd recommend people pay more attention to, it's him. He's also a terrific communicator, and an indecently great writer. My readers might be familiar with him thanks to the afterword he contributed to Little Brother:
https://craphound.com/littlebrother/download/
More recently, he wrote a fantastic intro for last year's Science Comics Computers: How Digital Computers Work, a brilliant middle-grades graphic novel that uses steampunk dinosaurs to explain digital logic and the building blocks of computation:
He also co-authored a fascinating research paper with Edward Snowden, after the two of them collaborated on a daughter-board that spots otherwise untraceable malware:
That's not bunnie's only sweet hardware hack, of course. Check out the insanely clever design for a contact-tracing dongle he prototyped for the EU in 2020:
But really, you owe it to yourself to read bunnie at book length, and his best book is 2016's The Hardware Hacker, a tour-de-force, lay-friendly exegesis on the theory and practice of hardware hacking:
If you'd like an essay-formatted version of this post to read or share, here's a link to it on pluralistic.net, my surveillance-free, ad-free, tracker-free blog:
“Science Comics Computers: How Digital Hardware Works”
I'm on a tour with my new book, the international bestseller Enshittification: catch me next in Burbank, Lisbon, Cardiff, London and Oxford! Full schedule here.
In Science Comics Computers: How Digital Hardware Works, legendary cypherpunk Perry Metzger teams up with Penelope Spector and illustrator Jerel Dye for a tour-de-force young adult comic book that uses hilarious steampunk dinosaurs to demystify the most foundational building-blocks of computers. It's astounding:
https://www.veniac.com/
"Science Comics" is a long-running series from First Second, the imprint that also published my middle-grades comic In Real Life and my picture book Poesy the Monster-Slayer (they are also publishing my forthcoming middle-grades graphic novel Unauthorized Bread and adult graphic novel Enshittification). But long before I was a First Second author, I was a giant First Second fan, totally captivated by their string of brilliant original comics and English translations of beloved comics from France, Spain and elsewhere. The "Science Comics" series really embodies everything I love about the imprint: the combination of whimsy, gorgeous art, and a respectful attitude towards young readers that meets them at their level without ever talking down to them:
https://us.macmillan.com/series/sciencecomics
But as great as the whole "Science Comics" series is, How Digital Hardware Works is even better. Our guide to the most profound principles in computer science is a T Rex named Professor Isabella Brunel, who dresses in steampunk finery that matches the Victorian, dinosaur-filled milieu in which she operates.
Brunel begins by introducing us to "Veniac," a digital computer that consists of a specially designed room in which a person performs all the steps involved in the operations of a computer. This person – a celebrated mathematician (she has a Fields Medal) velociraptor named Edna – moves slips of paper in and out of drawers, looks up their meaning in a decoder book, tacks them up on a corkboard register, painstakingly completing the operations that comprise the foundations of computing.
Here the authors are showing the reader that computing can be abstracted from computing. The foundation of computing isn't electrical engineering, microlithography, or programming: it's logic.
When I was six or seven, my father brought home a computer science teaching tool from Bell Labs called "CARDiac," the "CARDboard Illustrative Aid to Computation." This was a papercraft digital computer that worked in nearly the same way as the Veniac, with you playing the role of Edna, moving little tokens around, penciling and erasing values in registers, and painstakingly performing the operations to run values through adders and then move them to outputs:
CARDiac was profoundly formative for me. No matter how infinitesimal and rapid the components of a modern computer are, I have never lost sight of the fact that they are performing the same operations I performed with a CARDiac on my child-sized desk in my bedroom. This is exactly the mission of CARDiac, whose creators, David Hagelbarger and Saul Fingerman, were worried that the miniaturization of computers (in 1968!) was leading to a time where it would be impossible to truly grasp how they worked. If you want to build your own CARDiac, here's a PDF you can download and get started with:
But of course, you don't need to print, assemble and operate a CARDIac to get the fingertip feeling of what's going on inside a computer. Watching a sassy velociraptor perform the operations will work just as well. After Edna lays down this conceptual framework, Brunel moves on to building a mechanical digital computer, one composed of mechanical switches that can be built up into logic gates, which can, in turn, be ganged together to create every part of a universal computer that can compute every valid program.
This mechanical computer – the "Brawniac" – runs on compressed air, provided by a system of pumps that either supply positive pressure (forcing corks upwards to either permit or block airflow) or negative pressure (which sucks the corks back down, toggling the switch's state). This simple switch – you could probably build one in your kitchen out of fish-tank tubing and an aquarium pump – is then methodically developed into every type of logic gate. These gates are then combined to replicate every function of Edna in her special Veniac room, firmly anchoring the mechanical nuts-and-bolts of automatic computing with the conceptual framework.
This goes beyond demystification: the authors here are attaching a handle to this big, nebulous, ubiquitous hyperobject that permeates every part of our lives and days, allowing the reader to grasp and examine it from all angles. While there's plenty of great slapstick, fun art, and terrific characters in this book that will make you laugh aloud, the lasting effect upon turning the last page isn't just entertainment, it's empowerment.
No wonder they were able to tap the legendary hardware hacker Andrew "bunnie" Huang to contribute an outstanding introduction to this book, one that echoes the cri de coeur in in the intro that bunnie generously provided for my young adult novel Little Brother. No one writes about the magic of hacking hardware like bunnie:
Bunnie isn't the only computing legend associated with this book. Lead author Perry Metzger founded the Cryptography mailing list and is a computing pioneer in his own right.
The authors have put up a website at veniac.com that promises educator guides and a Veniac simulator. These will doubtless serve as excellent companions to the book itself, but even without them, this is an incredible accomplishment.
If you'd like an essay-formatted version of this post to read or share, here's a link to it on pluralistic.net, my surveillance-free, ad-free, tracker-free blog:
The original technological rationale for the wage system and the factory system was the shift in production technology from cheap, individually affordable craft tools to extremely expensive specialized machinery that only large institutions could afford to acquire — and hire wage laborers to operate.
Open source 3D printing, along with other forms of cheap desktop machine tools, offers to reverse this shift. Open source CNC machinery possesses the same qualities as craft tools of two or three hundred years ago: Cheap, general-purpose, flexible, and amenable to small-scale production on a demand-pull basis.
This means an outright end to the material rationale for the wage system and factory production. It’s a death warrant for giant corporations, and the basis for a revolution in economic democracy: Relocalized production primarily under worker control. So it’s natural that the old corporate dinosaurs would be desperate for deliverance from this fate. And Obama’s project is clearly intended to offer just such deliverance.
[...]
Fortunately, it won’t work. If you think the music industry has a hard time combating file-sharing, just wait till the old-line manufacturing companies try to prevent hundreds of thousands of hardware hackers in neighborhood garage factories from replicating “pirated” industrial designs on CAD files from The Pirate Bay.