Not just specs

Issues & Camp Impact

Safety warnings, delivery problems, app-store gaps, team-process history, and first-hand reports are tracked as sourced records.

Reset
1262 matching issue record(s)

repository recovery gap · official source but unrecovered archive · needs deeper archive recovery

HITB stated that the badge hardware, software, and firmware were fully open sourced, but this pass did not recover a stable repository or downloadable source archive URL.

The dossier records the public hardware-spec and challenge surface while avoiding unsupported firmware, schematic, or implementation claims beyond the official page.

Source note: HITBSecConf2018 Amsterdam CommSec Village page.

repository recovery gap · official source but unrecovered archive · needs deeper archive recovery

HITB stated that the badge hardware, software, and firmware would be fully open sourced, but this pass did not recover a stable repository or downloadable source archive URL.

The dossier records the public hardware notes and challenge surface while avoiding unsupported firmware, schematic, exact-chip, or implementation claims beyond the official page.

Source note: JD-HITBSecConf2018 Beijing CommSec Village page.

repository scope caveat · primary repository plus official event sources · public hardware and firmware repository recovered

The Electronic Cats repository now proves badge components, firmware, commands, KiCad files, and the challenge flow, but this pass still does not verify final shipped-unit variations, attendee-specific provisioning, or rights-cleared documentary photos.

The dossier can use component-level and firmware claims from the repository while still keeping image and distribution details conservative.

Source note: ElectronicCats badge-dragonJar-2025 repository, DragonJARCON 2025 event page, and DragonJAR badge raffle page.

repository-license boundary · repository metadata · documented

The BangleApps repository is MIT licensed, while related runtime/workshop/model repositories have mixed or unspecified repository-license metadata in the recovered source trail.

Software-resource links are preserved, but this record does not convert repository assets into local image or complete hardware-license claims.

Source note: GitHub metadata for espruino/BangleApps, espruino/Espruino, gfwilliams/workshop-nodeconfeu2019, and nearform/nodeconfeu-gesture-models.

repository-license caveat · repository metadata · documented for source evidence only

GitHub did not report a license for aranya-project/demo-board-v2 during this pass, even though the repository exposes README text, PCB source, and board images.

The repository is cited as public technical evidence, but its images and design files are not republished locally or treated as broadly reusable catalogue assets.

Source note: aranya-project/demo-board-v2 repository metadata and badge.gallery image policy.

repository-license caveat · public repository metadata plus README review · documented

The public firmware repository remains license-metadata-limited in this pass, while the Build-A-Badge repository README embeds MIT License text used only for the selected upstream badge render and customization-app evidence.

The catalogue records public firmware and customization surfaces conservatively while allowing the specifically reviewed Build-A-Badge render to carry explicit MIT provenance.

Source note: freewili/freewili-firmware and freewili/build_a_badge repository review.

repository-license caveat · GitHub metadata and repository tree · documented for source only

The public GitHub repository exposes source, PDFs, hardware files, firmware image, and site imagery, but this pass did not recover a top-level license or image-specific reuse grant.

The catalogue cites the repository as evidence but does not republish repository media or treat design files, PDFs, or images as reusable publication assets.

Source note: compukidmike/Saintcon2018 repository tree and badge.gallery image policy.

repository-license caveat · GitHub metadata recheck · documented

The public `poplicola/Thotcon0xA_Pub` repository exposes workshop, firmware, and example-code material, but no repository license was detected in the current GitHub metadata pass.

The catalogue treats the repository as evidence and a user-facing technical reference, not as a blanket permission source for republishing media, firmware, or hardware assets.

Source note: GitHub repository metadata and Thotcon0xA_Pub README.

repository-license caveat · GitHub API and README recheck · documented

The public `poplicola/thotcon-examples` repository exposes Eagle board files and demo firmware, but GitHub reports no detected repository license and the README only frames the examples as provided as-is.

The catalogue cites the repository as evidence and a user-facing reference without treating its images, firmware, or hardware files as freely reusable beyond what the source itself permits.

Source note: GitHub API repository metadata and `thotcon-examples` README.

repository-license caveat · repository audit · needs license audit before media reuse

The 2022 badge tools repository exposes useful manuals, firmware, software tools, and a badge image candidate, but this pass did not identify a top-level GitHub-reported license that clearly covers local reuse of the repository photo or manual imagery.

The catalogue cites the repository for source facts and tooling while withholding local image publication until a specific image license or permission basis is verified.

Source note: Hack-a-Day/2022-Supercon6-Badge-Tools repository, assembler subdirectory license files, GitHub repository metadata, and badge.gallery image policy.

repository-license caveat · source-backed but incomplete · needs license audit before media reuse

The public repository exposes hardware, software, and photo resources, but this pass did not identify a top-level license file that clearly covers image reuse for the catalogue.

The catalogue records technical facts and outbound source links while withholding local images and avoiding license assumptions.

Source note: GitHub repository contents API, repository README, and badge.gallery image policy.

repository-license caveat · source-backed repository audit · documented

The local image uses one exact repository photo covered by the MIT-licensed source tree; article media and other repository rasters remain unmirrored unless separately selected and recorded with provenance.

The catalogue avoids broad image assumptions while publishing a specific audited source photo for the badge page.

Source note: 2025 Communicator Badge LICENSE.txt, repository images directory, README image reference, and badge.gallery image policy.

repository-license caveat · GitHub metadata · documented for source only

GitHub reports no detected license for `jrgdiaz/HHW_HackConRD2024`, and the badge-team writeup does not expose a reusable image license.

The catalogue cites the repository as evidence for the 2024 badge but does not copy its render, photos, pinout images, screenshots, notebook media, or fabrication archive media into the public image directory.

Source note: GitHub repository metadata, HackConRD 2024 writeup media, and badge.gallery image policy.

repository-license caveat · GitHub metadata · documented for source only

GitHub reports no detected license for `w0rkm4n/Badge_HackConRD_2026`, and the official site footer reserves rights.

The firmware repository and official pages are used as evidence, but site photos, animated renders, frames, YouTube thumbnails, and repository images are not copied as catalogue visuals.

Source note: HackConRD official pages, GitHub repository metadata, and badge.gallery image policy.

repository-license caveat · repository audit · documented

The repository README says the project is released for educational purposes and to see individual files for specific licenses; no top-level LICENSE file was recovered in this pass.

The catalogue cites the repository for evidence but does not use repository images locally or claim a single reuse license for the whole project.

Source note: ZonkSec kernelcon-2026-badge README and missing top-level LICENSE probe.

repository-license caveat · GitHub metadata · documented for source only

GitHub reported no detected license for the DC32 main badge board, main badge firmware, CTF challenge, and CHV SAO specification repositories in this pass, while the separate Speedometer SAO firmware repository reports MIT.

The catalogue cites those repositories as source evidence but does not treat repository images, board renders, firmware, CTF material, or documentation as broadly reusable publication assets without explicit license coverage.

Source note: GitHub repository metadata for car-hacking-village/DC32_CHV_Badge_Board, DC32_CHV_Badge_Firmware, DC32_CTF_CHALLENGES, CHV_SAO_Specification, and DC32_CHV_Speedometer_Firmware.

retrospective archive caveat · repository archive backed · documented

The 2022 badge files are recovered through the public 2024 branch rather than a dedicated nsec22 branch, so this record treats the tree as a retrospective hardware archive and keeps event claims anchored to NorthSec's official past-editions page.

The catalogue can seed the badge without implying that every file was published during the original 2022 event window.

Source note: nsec/nsec-badge 2024 branch `hw/2022` tree and NorthSec past-editions page.

retrospective-only source caveat · secondary retrospective source · needs primary writeup

The current public source set found for this pass describes the badge through later Security Fest badge retrospectives rather than a standalone 2022 build page.

The dossier keeps the 2022 badge discoverable while avoiding chip-level, firmware, app, production, or author claims until primary sources are recovered.

Source note: Hackster.io Security Fest 2023 and 2024 badge writeups.

reuse lineage caveat · event report and upstream repository · documented

The Berlin badge record is a European event reuse of the 2023 Hackaday Supercon Vectorscope badge rather than a newly designed Berlin-only PCB.

badge.gallery should preserve both the European field context and the upstream Vectorscope hardware/firmware lineage without implying a separate 2024 board design.

Source note: heise Hackaday Europe report, Hackaday Vectorscope article, and Hack-a-Day/Vectorscope repository.

reuse lineage caveat · source-backed · documented

The public evidence identifies the Europe badge through the Supercon 8 SAO badge lineage with Europe-specific firmware and add-on distribution, not as an independently new Berlin PCB.

The record should remain tied to Hackaday Europe 2025 while preserving the upstream 2024 Supercon hardware/software lineage.

Source note: Hackaday Europe 2025 ticket preview, Supercon 8 badge reveal, and Hack-a-Day/2024-Supercon-8-Add-On-Badge repository.

reused-hardware source caveat · public repository archive · documented

The project repurposes SMART Response XE classroom-response hardware and publishes setup and firmware files, but this pass did not recover a complete hardware modification guide, BOM, enclosure record, production log, or photographed final handout set.

Hardware claims stay limited to the SMART Response XE platform, ATmega128RFA1 radio path, USBasp/Arduino workflow, and the source files reviewed.

Source note: 5ohBEE README, RadioFunctions.h, SmartResponseXE.h, and sketch sources.

revision and repository-depth caveat · source-backed but historical · needs board-revision audit

The public repository preserves source files, firmware, photos, wiki links, and features, but this pass did not audit exact production-board revision, BOM state, manufacturing count, or whether every repository image maps to the distributed LCA2016 boards.

The dossier records verified features and source locations while avoiding unsupported production-run or image-provenance claims.

Source note: CCHS Melbourne ESPlant repository, Marc Merlin writeup, and Simon Lyall session notes.

revision and source-depth caveat · source-backed but historical · needs board-revision audit

The public trail proves the IoTuz project, board files, firmware, assembly guidance, and workshop use, but this pass has not audited exact production-run revision, BOM state, manufacturing quantity, or whether every repository image and file maps to the distributed boards.

The badge dossier cites public hardware and software archives while avoiding unsupported production-run claims.

Source note: CCHS Melbourne hardware/firmware repositories, software wiki, and linux.conf.au 2017 schedule.

safety warning · primary README · documented

The README warns that voltage glitching can cause damage, that the differential injector circuit is not electrically isolated from connected devices or buses, that direct boat connection needs additional safety precautions, and that the injector can drive up to 400 mA.

The catalogue presents the badge as a real fault-injection and maritime-bus lab while preserving the primary-source caution around unsafe use.

Source note: Differential Destroyer README safety warning.

scope boundary · source-conservative public archive · documented caveat

The public Proteus archive documents firmware and build/update workflow; it does not by itself clear badge photos or prove every attendee-distribution detail beyond the Compass report's Area41-team badge statement.

The dossier presents the badge as a real Area41 2018 artifact while keeping image rights and distribution-depth claims narrow.

Source note: Compass Security wrap-up and le-krogoth/proteus repository.

secondary-source technical caveat · contemporary secondary source · needs primary technical corroboration

The core badge behavior for 2016 comes from a contemporary Register report rather than an official badge-team technical archive.

The entry stays conservative and keeps the official event page as event context while treating the Arduino and running-order claims as secondary-source technical evidence.

Source note: The Register event report and BSides Canberra 2016 event page.

service-scaling caveat · event report · documented with caution

Hackaday reports that the intended Alexa-style voice service was expensive to scale for hundreds of devices, so the catalogue treats Alexa behavior as an experiment and source trail rather than claiming full cloud voice-assistant service for every attendee badge.

The record preserves the voice/audio ambition without overstating default deployed service behavior.

Source note: Hackaday LayerOne 2018 badge report and CharlieX ESP32_Alexa repository.