<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>LoveMHz</title>
    <description></description>
    <link>https://lovemhz.com/</link>
    <atom:link href="https://lovemhz.com/feed.xml" rel="self" type="application/rss+xml" />
    <pubDate>Sun, 13 Jul 2025 03:28:16 +0000</pubDate>
    <lastBuildDate>Sun, 13 Jul 2025 03:28:16 +0000</lastBuildDate>
    <generator>Jekyll v3.10.0</generator>
    
      <item>
        <title>Blog: Theft in the Xbox Scene - Part 2</title>
        <description>&lt;h1 id=&quot;introduction&quot;&gt;Introduction&lt;/h1&gt;

&lt;p&gt;This is a continuation of Theft in the Xbox Scene - Part 1, where I began documenting some of the challenges and setbacks
we’ve faced as a result of ongoing IP theft and misinformation.&lt;/p&gt;

&lt;!--more--&gt;

&lt;h2 id=&quot;unresolve-issues&quot;&gt;Unresolve Issues&lt;/h2&gt;
&lt;p&gt;There’s been a lot of confusion about the core issue raised in the original post. To be clear, it’s the &lt;strong&gt;theft of our
software&lt;/strong&gt;. That was the first and most important part of the article to be written. Everything else was added to provide
background and context; but unfortunately, that also introduced a lot of noise into the conversation.&lt;/p&gt;

&lt;p&gt;Despite the attention the post received, very little has been done to address these concerns. The key issues remain
unresolved.&lt;/p&gt;

&lt;h3 id=&quot;unresolved&quot;&gt;Unresolved&lt;/h3&gt;
&lt;ul&gt;
  &lt;li&gt;Theft of XboxHD+ logic&lt;/li&gt;
  &lt;li&gt;Theft of HDD unlocking (key recovery) logic&lt;/li&gt;
  &lt;li&gt;Theft of CPU upgrade support logic&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;I also believe the In-Game Reset (IGR) logic copied from rmenhal’s GPL-licensed work deserves more attention within the
community. However, since this isn’t my code and we don’t use it, we’re not pursuing it ourselves.&lt;/p&gt;

&lt;h3 id=&quot;partially-addressed&quot;&gt;Partially Addressed&lt;/h3&gt;
&lt;p&gt;PrometheOS has taken responsibility for incorporating XboxHD+ code. However, the issue remains unresolved, as the license
terms are still not being followed. A formal request will be submitted to address this.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/img/blog/xbox-scene-theft-2/1.jpg&quot; alt=&quot;GitHub&quot; /&gt;&lt;/p&gt;

&lt;p&gt;Since PrometheOS is built and distributed using Cerbios, we also believe the underlying Cerbios-related issues need to be
addressed as part of that resolution.&lt;/p&gt;

&lt;h3 id=&quot;dmca&quot;&gt;DMCA&lt;/h3&gt;
&lt;p&gt;Over the past year, we have made multiple attempts to address the unauthorized distribution of XboxHD+ files on xbins.
This has included outreach from others in the retro community, but so far, those efforts have not led to a resolution.&lt;/p&gt;

&lt;p&gt;A DMCA notice was submitted to GitHub for Pandora, a tool built specifically to download files from xbins. Most of these
files are not legally available through any other means. To clarify, our concern lies only with the distribution of our
works without permission. If members of the Cerbios and PrometheOS teams have contacts at xbins, we hope they will step
in to help resolve the issue.&lt;/p&gt;

&lt;p&gt;We have also submitted DMCA notices to online stores selling products that include or enable unauthorized use of our protected
works. This includes hardware specifically designed to circumvent the XboxHD+, such as boards marketed with phrases like
“just find the firmware,” as well as, in one case, an OpenXenium product explicitly sold with Cerbios and PrometheOS preloaded.&lt;/p&gt;

&lt;p&gt;In the case of Cerbios and PrometheOS listings, we have stepped back from issuing further notices for now. We hope the
teams behind those projects will take responsibility and work to resolve the issue themselves instead of leaving the
burden entirely on third-party sellers.&lt;/p&gt;

&lt;h1 id=&quot;theft-of-hdd-unlocking-key-recovery-logic&quot;&gt;Theft of HDD Unlocking (Key Recovery) Logic&lt;/h1&gt;

&lt;p&gt;There has been a lot of confusion surrounding what was stolen and why it matters. To clarify: drive unlocking and drive
unlocking via key recovery are two very different processes.&lt;/p&gt;

&lt;p&gt;Drive unlocking through vendor commands is often a fallback method for manufacturers. It allows access to drives
that are locked but without recovering the original key. In contrast, drive unlocking via key recovery uses a diagnostic
interface to run custom payloads that extracts the drive’s unique key directly from its controller.&lt;/p&gt;

&lt;p&gt;The Seagate U5 is a perfect example of why key recovery is not straightforward. There is no predefined command to ask
the drive for its key. Unlocking it requires a custom payload, executed through an undocumented diagnostic interface, to
force the controller to execute code fromo a specific location in memory that places the hardware in just the right state
for the key to remain accessible and not cleared from memory.&lt;/p&gt;

&lt;p&gt;I reached out to EqUiNoX for clarification on how their implementation works but have not received a clear response.&lt;/p&gt;

&lt;p&gt;The initial list of resources they shared includes:&lt;/p&gt;
&lt;ul&gt;
  &lt;li&gt;Documents covering TTY-based unlocking with and without key recovery&lt;/li&gt;
  &lt;li&gt;References to drives with completely different architectures&lt;/li&gt;
  &lt;li&gt;One closed-source program, which I have not been able to confirme to support key recovery on original Xbox drives.&lt;/li&gt;
&lt;/ul&gt;

&lt;h2 id=&quot;the-elephant-in-the-room&quot;&gt;The Elephant in the Room&lt;/h2&gt;
&lt;p&gt;A common challenge with publishing technical write-ups is having to respond to made-up accusations. I want to address
one of them directly because it containts a direct quote from EqUiNoX of Team Resurgent.&lt;/p&gt;

&lt;p&gt;On July 8th I was tagged in a post on Bluesky claiming that one of the many samples we provided was a direct copy of
Microsoft code.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/img/blog/xbox-scene-theft-2/2.jpg&quot; alt=&quot;BlueSky&quot; /&gt;&lt;/p&gt;

&lt;p&gt;Not only is this incorrect, but the cropped screenshot being circulated is misleading. It omits surrounding context that
differentiates our implementation from Microsoft’s. This kind of selective framing only fuels misinformation.&lt;/p&gt;

&lt;p&gt;I addressed this on the OGXbox forums.&lt;/p&gt;

&lt;p&gt;Below is the full section in question without the crop. I’ve added labels to make it clear which code is Project Stellar,
PrometheOS, and the same retail Xbox kernel. This is not “leaked source code” or anything like that. It’s the exact same
kernel as the one in the BlueSky post. It’s the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;Retail 3944&lt;/code&gt; kernel with the SHA1SUM of
&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;67054fc88bda94e33e86f1b19be60efec0724fb6&lt;/code&gt; for the full 1MB backup.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/img/blog/xbox-scene-theft-2/3.jpg&quot; alt=&quot;Ghidra&quot; /&gt;&lt;/p&gt;

&lt;p&gt;This is from the &lt;strong&gt;same retail kernel&lt;/strong&gt; as the cropped screenshot and was decompiled using Ghidra with default settings.
Kernel exports were renamed using &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;RenameKernelImports.py&lt;/code&gt;, generated from the XboxDev wiki infromation on the kernel
exports, and type information was applied from &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;nxdk&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;The original code in question is a polling routine used to ensure the drive resets. It does not match Project Stellar. We
included it in our list of samples because it exists outside of the kernel and the pattern lifted from Project Stellar
into PrometheOS is still clear. The timings also still matter. If the surrounding logic changes, the delays could change
too or be optimized away if that was the goal.&lt;/p&gt;

&lt;p&gt;To be absolutely clear, I am are not claiming ownership over basic I/O instructions like &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;out&lt;/code&gt; or standard functions like
&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;KeStallExecutionProcessor()&lt;/code&gt;. That would be like claiming ownership over &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;if()&lt;/code&gt; statements.&lt;/p&gt;

&lt;p&gt;Our implementation is based on the ATA/ATAPI specification, as shown below from the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;Information Technology - AT Attachment
with Packet Interface - 6 (ATA/ATAPI-6)&lt;/code&gt; datasheet.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/img/blog/xbox-scene-theft-2/4.jpg&quot; alt=&quot;Datasheet&quot; /&gt;&lt;/p&gt;

&lt;p&gt;The timing values used in our implementation apply a multiplier to account for bus delays and timer resolution differences.
These timers are based on the onboard crystal, and ownership of the bus from the CPU through the northbrige and to the
southbridge must be queued. While the timings are not exact, our values were tested extensively to ensure stability.&lt;/p&gt;

&lt;p&gt;But you might ask, “The PrometheOS code uses a variable to store &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;mIdePort&lt;/code&gt;. Isn’t that obviously different from either
implementation?”&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/img/blog/xbox-scene-theft-2/5.jpg&quot; alt=&quot;Ghidra&quot; /&gt;&lt;/p&gt;

&lt;p&gt;And to that I would say this shows a basic misunderstanding of how the Xbox works. If this had actually been reverse
engineered from the Xbox kernel, that variable would not exist. The Xbox has only a single IDE controller, and it is
always mapped to a fixed I/O address. Anyone doing even basic reverse engineering would know this. In fact, just looking
at the motherboard would make it clear that it only has one IDE controller because it only has one IDE port.&lt;/p&gt;

&lt;p&gt;If your concern is “optimizations,” then that’s a free one. Because as it stands, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;mIdePort&lt;/code&gt;, does nothing but make
it one line of code different from Stellar.&lt;/p&gt;

&lt;h2 id=&quot;team-resurgents-response&quot;&gt;Team Resurgent’s Response&lt;/h2&gt;

&lt;p&gt;&lt;img src=&quot;/assets/img/blog/xbox-scene-theft-2/6.jpg&quot; alt=&quot;GitHub&quot; /&gt;&lt;/p&gt;

&lt;p&gt;After publishing the first article, I opened a GitHub issue on the PrometheOS repository to seek clarification on the
HDD unlocking logic. The goal was to ask direct, technical questions about the origins of the code and the development
process behind it.&lt;/p&gt;

&lt;p&gt;The responses from EqUiNoX were appreciated, and I want to be clear that I gave every opportunity for clarification. I
asked specific questions, followed up where needed, and allowed their words to speak for themselves.&lt;/p&gt;

&lt;p&gt;However, several of the responses raised new questions, revealed inconsistencies, or introduced claims that will need to
be addressed in more detail. For now, I want to provide a summary of what was said and what is still unclear. I will
expand on these concerns later in the article.&lt;/p&gt;

&lt;h2 id=&quot;response-1&quot;&gt;Response #1&lt;/h2&gt;

&lt;p&gt;&lt;img src=&quot;/assets/img/blog/xbox-scene-theft-2/7.jpg&quot; alt=&quot;GitHub&quot; /&gt;&lt;/p&gt;

&lt;p&gt;I find the statement &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;hddVscUnlocker::resetIdeBus &amp;lt;- derived from the retail kernel decompilation reset bus delays&lt;/code&gt;
questionable. PrometheOS requires Cerbios to execute from a modchip, and both projects have worked together publicly in
the past. This is important context, because Cerbios is compiled from leaked Xbox source code.&lt;/p&gt;

&lt;p&gt;In the implementation of &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;resetIdeBus&lt;/code&gt;, the oddity of using &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;mIdePort&lt;/code&gt; has already been addressed above. As for the
claims regarding how the remaining timing values were derived, there would need to be actual testing to validate that assertion.&lt;/p&gt;

&lt;p&gt;The most significant red flag is the statement about &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;Sleep()&lt;/code&gt; that it causes
&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;issues with background threads accessing hard drive&lt;/code&gt;, and that this is why &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;KeStallExecutionProcessor()&lt;/code&gt; was chosen.
This is simply not how the Xbox works. The Xbox uses &lt;a href=&quot;https://en.wikipedia.org/wiki/Preemption_(computing)&quot;&gt;preemptive multitasking&lt;/a&gt;,
meaning it constantly and rapidly switches between threads.&lt;/p&gt;

&lt;p&gt;To prevent other threads from accessing the drive, the correct behavior is to raise the interrupt request level (IRQL)
to &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;DISPATCH_LEVEL&lt;/code&gt; or higher to block thread switching via &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;KeRaiseIrqlToDpcLevel&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/img/blog/xbox-scene-theft-2/8.jpg&quot; alt=&quot;Microsoft API&quot; /&gt;&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/img/blog/xbox-scene-theft-2/9.jpg&quot; alt=&quot;Microsoft API&quot; /&gt;&lt;/p&gt;

&lt;p&gt;But PrometheOS doesn’t do this. Instead, it copies Stellar’s exact logic: raising the IRQL to the interrupt level of the
IDE controller by calling &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;HalGetInterruptVector&lt;/code&gt; and &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;KfRaiseIrql&lt;/code&gt;. And this isn’t the only way to achieve this.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/img/blog/xbox-scene-theft-2/10.jpg&quot; alt=&quot;Ghidra&quot; /&gt;&lt;/p&gt;
&lt;p style=&quot;text-align:center&quot;&gt;The only difference here being that IRQL is raised by the caller via callee. ie PrometheOS
moved the KeRaiseIrqlToDpcLevel call from outside the drive functions to right inside them.&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;&lt;/p&gt;

&lt;p&gt;This is not for blocking other threads. It’s for blocking kernel responses to IDE controller interrupts.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/img/blog/xbox-scene-theft-2/11.jpg&quot; alt=&quot;Quote&quot; /&gt;&lt;/p&gt;

&lt;p&gt;This undermines the explanation that it was done for optimization. I don’t belive this is a misunderstanding on my part.
It reads more like an excuse layered over copied logic.&lt;/p&gt;

&lt;hr /&gt;

&lt;p&gt;To drive this home… Something I noticed while putting this article together, and honestly found a bit funny, is this
&lt;a href=&quot;https://github.com/Team-Resurgent/PrometheOS-Firmware/blob/main/PrometheOSXbe/PrometheOSXbe/hddVscUnlocker.cpp#L522&quot;&gt;line&lt;/a&gt;
in the PrometheOS 1.3.0 source release:&lt;/p&gt;

&lt;p&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;HalGetInterruptVector(0xe, &amp;amp;irql); // 0xe = PNPISABus&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;The value &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;0xe&lt;/code&gt; is the same value as the interrupt for the IDE controller, but the comment is completely incorrect.
&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;PNPISABus&lt;/code&gt; is a constant from the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;INTERFACE_TYPE&lt;/code&gt; enum used to describe how devices identify themselves to the system,
such as PCI or ISA. It is not related to interrupt levels in this context.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/img/blog/xbox-scene-theft-2/12.jpg&quot; alt=&quot;Microsoft API&quot; /&gt;&lt;/p&gt;

&lt;p&gt;This is without a doubt a case of someone not understanding what the code is doing. The comment was likely added to make
sense of a value they copied without knowing what it actually represented. It brings everything full circle.&lt;/p&gt;

&lt;h2 id=&quot;response-2&quot;&gt;Response #2&lt;/h2&gt;

&lt;p&gt;&lt;img src=&quot;/assets/img/blog/xbox-scene-theft-2/13.jpg&quot; alt=&quot;Quote&quot; /&gt;&lt;/p&gt;

&lt;h3 id=&quot;lack-of-source-code&quot;&gt;Lack of Source Code&lt;/h3&gt;
&lt;p&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;Unfortunately no, when working on a new PrometheOS version I tend to work locally and when ready to push, push as one commit...&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;This development approach is incompatible with open-source license requirements, especially for any project that uses
GPL-licensed code. The GPL requires that the complete source code be made available for &lt;strong&gt;all&lt;/strong&gt; distributed versions.
That includes any intermediary versions that were released as binaries, such as v1.2.0 of PrometheOS. Failing to
retain or provide this source code is a direct violation of the license.&lt;/p&gt;

&lt;p&gt;This is not a small or technical oversight. It is a license breach that affects the legality of distributing the software
itself. If you distribute a binary, you are also required to provide the full corresponding source to that binary. There
is no exception for working locally or pushing code in one large commit. By not maintaining source control in a transparent
and trackable way, the project undermines the trust that open-source licensing is built on.&lt;/p&gt;

&lt;p&gt;What makes the situation worse is that PrometheOS includes code taken from XboxHD+, which is also released under the GPL.
When that code is reused, modified, or redistributed, the GPL still applies. The license terms are not optional or negotiable.&lt;/p&gt;

&lt;p&gt;PrometheOS is distributing binaries that contain our GPL-licensed code, yet it fails to:&lt;/p&gt;
&lt;ul&gt;
  &lt;li&gt;Provide the complete source code for the versions being distributed&lt;/li&gt;
  &lt;li&gt;Properly attribute the original work&lt;/li&gt;
  &lt;li&gt;Grant the same rights to others to inspect, modify, and redistribute under the same terms&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;This is not theoretical. These are the exact obligations outlined in GPLv2, sections 1 and 3.&lt;/p&gt;

&lt;p&gt;If this were simply a misunderstanding, it could have been addressed by releasing the required source for v1.2.0. Instead,
the jump from v1.2.0 to v1.3.0 includes binary changes that appear deliberately obfuscated, making it harder to identify
what was changed and why. The only changelog entry provided was “Improved: VSC HDD Unlocking Times,” yet the code changes
go far beyond timing adjustments and raise serious questions about intent.&lt;/p&gt;

&lt;h3 id=&quot;sleep-and-kestallexecutionprocessor&quot;&gt;Sleep() and KeStallExecutionProcessor()&lt;/h3&gt;
&lt;p&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;I had trouble with Sleep() because it doesn&apos;t halt background threads from accessing the drive whilst unlocking is
taking place. KeStallExecutionProcessor() will halt any background threads, along with raising the IRQL.&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;This is not true and is covered above. &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;KeStallExecutionProcessor()&lt;/code&gt; has no impact on running threads and does not read,
write, or modifiy the IRQ level in any way.&lt;/p&gt;

&lt;h3 id=&quot;research-notes&quot;&gt;Research Notes&lt;/h3&gt;
&lt;p&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;I do remember decompiling a dos utility called zu.exe however which helped greatly.&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;Earlier in this article, I covered the topic of HDD Unlocking (Key Recovery) and the confusion surrounding the type of
proof being requested. That context is important here, because the list of “prior research” provided in defense of the
PrometheOS implementation largely references TTY-based unlocking methods or closed-source software that either does not
support key recovery or does not apply to the drives in question.&lt;/p&gt;

&lt;p&gt;One new reference introduced in this discussion was &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;zu.exe&lt;/code&gt;. I had not encountered this tool before, so I asked for
clarification on exactly which drives it can unlock and whether the screenshot provided was showing key recovery in action.&lt;/p&gt;

&lt;p&gt;These details matter because the architecture of these drives varies significantly, and claiming to have “extrapolated”
key recovery from closed software, without documentation or code, raises serious questions.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/img/blog/xbox-scene-theft-2/14.jpg&quot; alt=&quot;Capture&quot; /&gt;&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/img/blog/xbox-scene-theft-2/15.jpg&quot; alt=&quot;Capture&quot; /&gt;&lt;/p&gt;

&lt;p&gt;Still, I tested the theory in good faith. I used an Intel P4 system and a motherboard built with the exact same chipset
used in the Xbox, but was unable to reproduce the result.&lt;/p&gt;

&lt;h2 id=&quot;response-3&quot;&gt;Response #3…&lt;/h2&gt;

&lt;p&gt;&lt;img src=&quot;/assets/img/blog/xbox-scene-theft-2/16.jpg&quot; alt=&quot;Capture&quot; /&gt;&lt;/p&gt;

&lt;p&gt;This was one of the last meaningful replies in the GitHub conversation, and it left several questions unanswered.&lt;/p&gt;

&lt;h1 id=&quot;obfuscations-in-the-v130-source-release&quot;&gt;Obfuscations in the v1.3.0 Source Release&lt;/h1&gt;

&lt;p&gt;PrometheOS is currently hiding behind the 1.2.0 source release, but after comparing the 1.2.0 binary to the 1.3.0 release
over the past few days, I’ve identified even more undeniable examples of copied code. In this case, the changes appear to
have been made specifically to conceal the theft.&lt;/p&gt;

&lt;p&gt;The release notes for version 1.3.0 only mention one related change:&lt;/p&gt;

&lt;p&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;Improved: VSC HDD Unlocking Times&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;With that in mind, we will focus on examples where the code was modified in ways that are unrelated to unlocking
performance or any reasonable optimization. These changes do not improve execution speed or stability. They appear to
serve only one purpose: to make the stolen code harder to recognize.&lt;/p&gt;

&lt;h2 id=&quot;meaningless-changes-obfuscations&quot;&gt;Meaningless Changes (Obfuscations)&lt;/h2&gt;

&lt;p&gt;&lt;img src=&quot;/assets/img/blog/xbox-scene-theft-2/17.jpg&quot; alt=&quot;Capture&quot; /&gt;&lt;/p&gt;

&lt;p&gt;We pressed hard for clarity on how the Seagate U5 was figured out, because as far as we know, there is no public
documentation or tool that covers key recovery for it.&lt;/p&gt;

&lt;p&gt;In comparing the 1.2.0 and 1.3.0 versions of PrometheOS, two changes stood out:&lt;/p&gt;

&lt;p&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;sgVscDiagExecCmd(..., &quot;GFFF3&quot;)&lt;/code&gt; was changed to &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;sgVscDiagExecCmd(..., &quot;GFFFFFFF3&quot;)&lt;/code&gt;
&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;sgVscDiagExecCmd(..., &quot;/1&quot;)&lt;/code&gt; was changed to &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;sgVscDiagExecCmd(..., &quot;/2&quot;)&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;These changes have no meaningful impact. In fact, the first one arguably makes things worse.&lt;/p&gt;

&lt;p&gt;The value &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;GFFF3&lt;/code&gt; instructs the hard drive controller to begin code execution at 0xFFF3. Extending it to &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;GFFFFFFF3&lt;/code&gt;
results in the same truncated address due to the controller’s address space, but it adds unnecessary characters that make
the command slower to transmit and process.&lt;/p&gt;

&lt;p&gt;The change from &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;/1&lt;/code&gt; to &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;/2&lt;/code&gt; just switches diagnostic input modes, but neither option has an effect on the controller’s
behavior in this flow.&lt;/p&gt;

&lt;p&gt;These are not optimizations. They are changes that serve no functional purpose and appear to exist only to obscure the
original source of the code.&lt;/p&gt;

&lt;h1 id=&quot;conclusion&quot;&gt;Conclusion&lt;/h1&gt;
&lt;p&gt;At this point, I’ve said everything I need to. The concerns have been laid out clearly, and the patterns speak for
themselves. Unless something meaningfully changes or new information comes to light, this will be my final word on the
matter.&lt;/p&gt;
</description>
        <pubDate>Sat, 12 Jul 2025 13:32:45 +0000</pubDate>
        <link>https://lovemhz.com/blog/xbox-scene-theft-part-2/</link>
        <guid isPermaLink="true">https://lovemhz.com/blog/xbox-scene-theft-part-2/</guid>
        
        
        <category>Blog</category>
        
      </item>
    
      <item>
        <title>: Theft in the Xbox Scene - Part 1 Corrections</title>
        <description>&lt;!--more--&gt;

&lt;h2 id=&quot;apologies&quot;&gt;Apologies&lt;/h2&gt;
&lt;p&gt;It’s not easy to admit when you’re wrong, but I want to start there.&lt;/p&gt;

&lt;p&gt;My frustration comes from the people who are actively stealing and cloning our hardware and software, and from those
spreading misinformation to protect or promote that theft. It’s the groups that hide behind anonymity to mask their acts
while at the same time constantly shouting, “it wasn’t me.”&lt;/p&gt;

&lt;p&gt;That said, the best apologies are short and sincere. While we may still disagree on some things, I want to apologize to
Harcroft, Skye, and Eaton for involving you in this situation. My issues are not with you or your projects. I had
incorrectly associated you with efforts I do have a problem with, based on the information I had at the time. Since then,
I’ve received clarification and want to set the record straight.&lt;/p&gt;

&lt;p&gt;It was unprofessional, and I will do better moving forward. I have updated the original blog post.&lt;/p&gt;
</description>
        <pubDate>Wed, 09 Jul 2025 11:32:45 +0000</pubDate>
        <link>https://lovemhz.com/blog/xbox-scene-theft-part-1-corrections/</link>
        <guid isPermaLink="true">https://lovemhz.com/blog/xbox-scene-theft-part-1-corrections/</guid>
        
        
      </item>
    
      <item>
        <title>Blog: Theft in the Xbox Scene - Part 1</title>
        <description>&lt;h1 id=&quot;introduction&quot;&gt;Introduction&lt;/h1&gt;

&lt;p&gt;This is not an article I want to be writing. It is not something I ever imagined I would have to write. But to explain
why I am writing it now, I need to provide some history.&lt;/p&gt;

&lt;!--more--&gt;

&lt;h3 id=&quot;corrections-and-updates&quot;&gt;Corrections and Updates&lt;/h3&gt;
&lt;p&gt;&lt;a href=&quot;/blog/xbox-scene-theft-part-1-corrections/&quot;&gt;Corrections and updates&lt;/a&gt; for this post can be found here.&lt;/p&gt;

&lt;h2 id=&quot;backstory&quot;&gt;Backstory&lt;/h2&gt;

&lt;p&gt;My journey with the original Xbox began about six years ago, inspired by the HDMI mods I had seen for systems like the
Dreamcast and N64. Growing up, I didn’t have much. A Game Boy Color, an N64, and eventually an Xbox were the only
consoles I ever owned as a kid. But it was the Xbox that stuck with me the most.&lt;/p&gt;

&lt;p&gt;Years later, I wanted to relive that experience. I wanted to sit down and enjoy some of my favorite games again, like
Fatal Frame 2 and Conker’s Bad Fur Day, but on modern hardware with a cleaner signal. That curiosity led me to explore
what it would take to bring HDMI to the original Xbox.&lt;/p&gt;

&lt;p&gt;I’ve always had a deep interest in reverse engineering. As a kid, cheat devices and emulators fascinated me. They became
a kind of escape from a life that, at times, felt like it had very few constants. Around the age of ten, I discovered the
memory editor on the N64 GameShark. That discovery lit a fire. I wanted to understand more, so I learned programming and
started writing my own tools. Eventually, that replaced the pen-and-paper notes I had scribbled down as a child.&lt;/p&gt;

&lt;p&gt;When I lost my father figure not long after, programming filled that void. It gave me purpose, focus, and a sense of
control at a time when everything else felt unstable.&lt;/p&gt;

&lt;p&gt;Developing the XboxHDMI brought all of that back. The joy of discovery. The thrill of building something new. And along
the way, I met people who became real friends. &amp;lt;3&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/img/blog/xbox-scene-theft/introduction/1.jpg&quot; alt=&quot;MGC&quot; /&gt;&lt;/p&gt;
&lt;p style=&quot;text-align:center&quot;&gt;Midwest Gaming Classic 2025&lt;/p&gt;

&lt;p&gt;When I finally launched XboxHDMI, I had no idea what to expect. I figured it might be a fun side project. Something I
would work on during weekends and maybe sell a few kits here and there. Once I recovered the initial costs, I planned to
open source it.&lt;/p&gt;

&lt;p&gt;But the launch went far beyond anything I could have imagined. Orders came in fast. Maybe it was the $60 price tag,
maybe it was the timing, or maybe the Xbox still meant something to a lot of other people too.&lt;/p&gt;

&lt;p&gt;Then COVID hit. Supply chains dried up. Shipping delays frustrated everyone. It was a hard time for many of us. But we
pushed through. We kept going.&lt;/p&gt;

&lt;p&gt;But I quit my job anyway to do this full time. It wasn’t an easy choice. I gave up a steady paycheck, time off, health
insurance, and stability. I had saved enough from my day job to take the risk, and I believed in what I was building. I
even had enough to fabricate the boards myself and handle everything from design to fulfillment on my own.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/img/blog/xbox-scene-theft/introduction/2.jpg&quot; alt=&quot;Twitter Post&quot; /&gt;&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/img/blog/xbox-scene-theft/introduction/3.jpg&quot; alt=&quot;Twitter Post&quot; /&gt;&lt;/p&gt;
&lt;p style=&quot;text-align:center&quot;&gt;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;I wish I could say it’s been easy, or even always fulfilling, but it hasn’t. Anyone who works with me knows how much I
put into this. I work non-stop, and I mean that in the most programmer sense possible. I’ve taken just a few days off a
year. I answer support messages on holidays. I chip away at documentation and development deep into the night.&lt;/p&gt;

&lt;p&gt;I wouldn’t trade it. Even when I look back on one of the worst medical experiences I’ve had, I try not to think about
how differently things might have gone if I had kept my job with insurance.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/img/blog/xbox-scene-theft/introduction/4.jpg&quot; alt=&quot;Dental&quot; /&gt;&lt;/p&gt;
&lt;p style=&quot;text-align:center&quot;&gt;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;I do wish I had more time with family and friends. But they understand. They know what this work means to me. This isn’t
just about hardware. It’s about preservation. It’s about making something that lasts.&lt;/p&gt;

&lt;p&gt;Project Stellar launched at the end of 2022. It was another passion project I couldn’t let go of. All the research from
XboxHD+ felt like it had more to give. I wanted to keep fixing, keep improving, and keep exploring. I knew from the
beginning it wouldn’t be highly profitable. It’s a more expensive product and the audience is smaller. But I had faith
that the Xbox and retro gaming community would support it.&lt;/p&gt;

&lt;p&gt;And I have to say, recreating an operating system from scratch, legally and cleanly, has not been easy. But it has been
rewarding. Spending weeks to fix a single edge case in a game that has been broken for a decade is the kind of work I
live for. I couldn’t imagine doing anything else.&lt;/p&gt;

&lt;p&gt;All of that makes what I am writing now so much harder.&lt;/p&gt;

&lt;p&gt;Because while we were focused on building something meaningful, others were quietly copying, stealing, and taking credit
for work that was not theirs.
&lt;br /&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;This article exists because this cannot continue.&lt;/strong&gt;&lt;/p&gt;

&lt;h2 id=&quot;why-now&quot;&gt;Why Now?&lt;/h2&gt;
&lt;p&gt;When I first got involved in the Xbox community, I was pretty outspoken about theft and the general disregard for
intellectual property. There are plenty of old screenshots floating around of some of my hot takes, and while I could
have worded things better, I still stand by the core message. I believe we can all do better.&lt;/p&gt;

&lt;p&gt;I’ve tried speaking out before. But every time I did, it led to personal attacks against me and against my company.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/img/blog/xbox-scene-theft/why-now/1.jpg&quot; alt=&quot;Reddit&quot; /&gt;&lt;/p&gt;
&lt;p style=&quot;text-align:center&quot;&gt;Accusations like this are not just misleading. They are part of a larger pattern used to
discredit and silence anyone who pushes back against theft. This is one of the reasons I stayed quiet for so long.&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;&lt;/p&gt;

&lt;p&gt;I’ve stayed quiet for years to avoid the drama and protect the work we were doing.&lt;/p&gt;

&lt;p&gt;I’m writing this now because that silence has only made things worse. It is time for things to change.&lt;/p&gt;

&lt;p&gt;The Xbox community is better than this. This is the same community that built projects like the open-source NKPatcher,
long before I came along. It proved that legally extending the retail Xbox kernel was not just possible, but practical.
Projects like nxdk have gone even further by showing that legal, independent toolchain development can work and thrive.&lt;/p&gt;

&lt;p&gt;I’m also writing this now because I’m tired. I’m tired of constantly worrying that everything I’m working on is going to
be stolen the moment it is released. This is not how things should work. It’s not fair to my mental health. It’s not fair
that updates to Stellar are delayed so we can implement obfuscation and anti-circumvention measures, just to slow down the
people trying to take our work.&lt;/p&gt;

&lt;p&gt;I’m writing this for the thousands of people who have put their trust in our work. We are just weeks away from reaching
10,000 orders shipped, not including retail partners. All of those people are being stolen from too, whether they realize
it or not.&lt;/p&gt;

&lt;p&gt;And I’m writing this for future developers. Even those who may one day replace what I’ve built. If the community accepts
theft as normal, then there is no real path forward for anyone who wants to build something original. It becomes impossible
to compete with shortcuts, and that drives real progress out of the scene.&lt;/p&gt;

&lt;h2 id=&quot;what-needs-to-change&quot;&gt;What Needs To Change?&lt;/h2&gt;
&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;Stop misleading users into thinking Modxo, PrometheOS, and CERBIOS are open source. Modxo was once open source but now
uses a restrictive license (non FOSS). &lt;a href=&quot;/assets/img/blog/xbox-scene-theft/changes/24.jpg&quot;&gt;1&lt;/a&gt; &lt;a href=&quot;/assets/img/blog/xbox-scene-theft/changes/25.jpg&quot;&gt;2&lt;/a&gt;
PrometheOS is not an operating system; it is an Xbox application built using a stolen SDK and a stolen BIOS. CERBIOS is
closed source and built on leaked kernel code along with stolen work from others.
&lt;a href=&quot;/assets/img/blog/xbox-scene-theft/changes/1.jpg&quot;&gt;1&lt;/a&gt;
&lt;a href=&quot;/assets/img/blog/xbox-scene-theft/changes/15.jpg&quot;&gt;2&lt;/a&gt;
&lt;a href=&quot;/assets/img/blog/xbox-scene-theft/changes/16.jpg&quot;&gt;3&lt;/a&gt;
&lt;a href=&quot;/assets/img/blog/xbox-scene-theft/changes/17.jpg&quot;&gt;4&lt;/a&gt;
&lt;a href=&quot;/assets/img/blog/xbox-scene-theft/changes/18.jpg&quot;&gt;5&lt;/a&gt;&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;Stop encouraging theft of the XboxHD+ and Legacy kit by telling customers to “just find the firmware.”
&lt;a href=&quot;/assets/img/blog/xbox-scene-theft/changes/23.jpg&quot;&gt;1&lt;/a&gt;&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;Stop selling known counterfeits and hardware clones.
&lt;a href=&quot;/assets/img/blog/xbox-scene-theft/changes/9.jpg&quot;&gt;1&lt;/a&gt;
&lt;a href=&quot;/assets/img/blog/xbox-scene-theft/changes/8.jpg&quot;&gt;2&lt;/a&gt;
&lt;a href=&quot;/assets/img/blog/xbox-scene-theft/changes/10.jpg&quot;&gt;3&lt;/a&gt;&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;Developers should stop claiming they are not stealing while at the same time publishing guides that explain how to do
exactly that.
&lt;a href=&quot;/assets/img/blog/xbox-scene-theft/changes/12.jpg&quot;&gt;1&lt;/a&gt;
&lt;a href=&quot;/assets/img/blog/xbox-scene-theft/changes/13.jpg&quot;&gt;2&lt;/a&gt;&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;Stop using alternate accounts to fish for implementation details or gain access to private work.
&lt;a href=&quot;/assets/img/blog/xbox-scene-theft/changes/19.jpg&quot;&gt;1&lt;/a&gt;&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;Stop making up claims that Stellar is anti-community, including false accusations like “Stellar intentionally broke
support for XCAT.” The truth is that XCAT’s own DRM prevents it from working. Nothing was done on our end to block it.
&lt;a href=&quot;/assets/img/blog/xbox-scene-theft/changes/20.jpg&quot;&gt;1&lt;/a&gt;&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;Stop making claims that we have abandoned the XboxHD+ Legacy kit. This is the first time since the original XboxHDMI
launch that the legacy, no-modchip option, has been truly out of stock. We are actively working on it. Recent trade-related
issues, including tariffs, have caused unexpected delays.
&lt;a href=&quot;/assets/img/blog/xbox-scene-theft/changes/21.jpg&quot;&gt;1&lt;/a&gt;
&lt;a href=&quot;/assets/img/blog/xbox-scene-theft/changes/22.jpg&quot;&gt;2&lt;/a&gt;&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;This is only a small part of the harassment, theft, and misinformation we have dealt with.&lt;/p&gt;

&lt;h2 id=&quot;who&quot;&gt;Who?&lt;/h2&gt;

&lt;h3 id=&quot;cerbios--team-resurgent&quot;&gt;Cerbios / Team Resurgent&lt;/h3&gt;
&lt;p&gt;I’m calling out Cerbios / Team Resurgent. This includes all of its members: EqUiNoX, HoRnEyDvL, Hazeno, and Dempsey_86.&lt;/p&gt;

&lt;p&gt;These individuals have repeatedly shown a disregard for intellectual property, copyright, and the work of others. Their
actions are not isolated incidents. They are part of a long-running pattern of theft.&lt;/p&gt;

&lt;h3 id=&quot;moderators-of-roriginalxbox&quot;&gt;Moderators of r/originalxbox&lt;/h3&gt;
&lt;p&gt;I’m calling out the moderators of the Original Xbox subreddit: Derf_Jagged, TXCrunchBite, OGXboxGamer, GoTeamScotch,
AlbinoSheepDawg, KeepForgettingLogin, awesomesprime, Random_Shadowscale, DivideByZer0, and ulubulu.&lt;/p&gt;

&lt;p&gt;These moderators continue to allow harassment, misinformation campaigns, and the promotion of stolen work. Some have even
gone as far as promoting it directly.
&lt;a href=&quot;/assets/img/blog/xbox-scene-theft/who/2.jpg&quot;&gt;1&lt;/a&gt;
&lt;a href=&quot;/assets/img/blog/xbox-scene-theft/who/3.jpg&quot;&gt;2&lt;/a&gt;&lt;/p&gt;

&lt;h3 id=&quot;xbox-scene-discord&quot;&gt;Xbox Scene Discord&lt;/h3&gt;
&lt;p&gt;I’m calling out the Xbox Scene Discord for hosting and supporting ongoing theft of our work.&lt;/p&gt;

&lt;h3 id=&quot;others&quot;&gt;Others&lt;/h3&gt;
&lt;p&gt;I’m calling out darkonecustoms.com and ogxstore.com (Andr0) for selling products that rely on stolen work from the
XboxHD+ project.
&lt;a href=&quot;/assets/img/blog/xbox-scene-theft/who/4.jpg&quot;&gt;1&lt;/a&gt;
&lt;a href=&quot;/assets/img/blog/xbox-scene-theft/who/5.jpg&quot;&gt;2&lt;/a&gt;
&lt;a href=&quot;/assets/img/blog/xbox-scene-theft/who/6.jpg&quot;&gt;3&lt;/a&gt;&lt;/p&gt;

&lt;h1 id=&quot;xboxhd&quot;&gt;XboxHD+&lt;/h1&gt;

&lt;h2 id=&quot;summary&quot;&gt;Summary&lt;/h2&gt;

&lt;p&gt;To understand how the theft of XboxHD+ occurred, we need to take a step back and explain how this project began. Some of
this has been shared before, but given the ongoing efforts to copy and clone our work, I want to be cautious while still
providing enough detail to show how we got here.&lt;/p&gt;

&lt;p&gt;The XboxHD+ project originally started as XboxHDMI in late 2019 or early 2020. During early development, we discovered
that we could either build an expensive FPGA-based solution or implement extensive software patches. We chose software,
in part because an FPGA would not fully resolve every video-related issue on the Xbox. That decision led to one of the
largest software projects I have ever worked on, though I did not realize it at the time.&lt;/p&gt;

&lt;p&gt;The initial idea was simple: patch the last retail Xbox BIOS, which supported all hardware revisions, with just enough
logic to pass AV initialization and GPU configuration data to a microcontroller on the XboxHDMI. This approach worked
well at first. It allowed us to inject handwritten assembly into the existing kernel with minimal disruption, which was
important because there were only a few hundred free bytes available to work with. Anything more complex would have been
nearly impossible in that environment.&lt;/p&gt;

&lt;p&gt;We briefly explored porting the patches to other BIOSes, including iND BIOS, but this quickly turned into a nightmare.
After significant effort, I discovered that the iND BIOS had been compiled from leaked source code and was heavily hacked
together. At this time CERBIOS did not exist.&lt;/p&gt;

&lt;p&gt;As a result, over a year’s worth of research and patching logic no longer applied. We abandoned any further
attempts to port the patches and focused on building something more sustainable.&lt;/p&gt;

&lt;p&gt;In April 2021, we rebranded XboxHDMI as XboxHD+ and launched firmware version 2.0.0. The new name was meant to reflect
that it provided “HD plus more.”&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/img/blog/xbox-scene-theft/xboxhd/1.jpg&quot; alt=&quot;XboxHD+ Announcement&quot; /&gt;&lt;/p&gt;
&lt;p style=&quot;text-align:center&quot;&gt;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;At this point, we moved away from manually patching the kernel on every update and introduced a system I developed
called &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;kpatch&lt;/code&gt;. This was a minimal loader that ran at boot and executed what we called the XboxHD+ runtime. We made
&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;kpatch&lt;/code&gt; open source to make it easier to integrate, and it became the foundation for future development.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/img/blog/xbox-scene-theft/xboxhd/2.jpg&quot; alt=&quot;GitHub&quot; /&gt;&lt;/p&gt;
&lt;p style=&quot;text-align:center&quot;&gt;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The runtime would detect which Xbox revision it was running on and load the appropriate module. Each module was written
in C and compiled specifically for that hardware revision. This let us replace hardware-specific kernel functions with
reimplemented versions optimized for each system. It also gave us more space to work with, since we could target unused
or replaceable code in a structured way.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/img/blog/xbox-scene-theft/xboxhd/6.jpg&quot; alt=&quot;Twitter Post&quot; /&gt;&lt;/p&gt;
&lt;p style=&quot;text-align:center&quot;&gt;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;This architecture made it possible to fix longstanding issues and improve video output beyond what the original Xbox ever
supported. We added upscaling, better widescreen handling, and even per-game fixes. Because the runtime could be updated
separately from the BIOS, users could upgrade features just by replacing a file. The kpatch build system and the XboxHD+
runtime became the foundation for what would eventually evolve into Project Stellar.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/img/blog/xbox-scene-theft/xboxhd/3.jpg&quot; alt=&quot;kpatch&quot; /&gt;&lt;/p&gt;
&lt;p style=&quot;text-align:center&quot;&gt;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;This design was intentional. It allowed for modular development, future porting to other BIOSes, and easy updates for
users. But that is not the path CERBIOS chose.&lt;/p&gt;

&lt;p&gt;Instead of using or building a system like &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;kpatch&lt;/code&gt;, CERBIOS appears to have copied the XboxHD+ runtime logic directly
into its kernel. This was not an integration. It was a transplant.&lt;/p&gt;

&lt;p&gt;As we will highlight throughout this article, the design decisions made by the CERBIOS team do not reflect original
development. The methodologies appear to be copied directly from the XboxHD+ runtime, which is copyrighted and not public.&lt;/p&gt;

&lt;p&gt;The first red flag is their handling of the function &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;AvSetDisplayMode&lt;/code&gt;. This is a relatively straightforward kernel export
responsible for setting up the GPU and video encoder based on the selected video mode. On the original Xbox, most of this
work is done using lookup tables, with minor conditional logic based on the encoder type. Under XboxHD+, these lookups are
redirected to the microcontroller.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/img/blog/xbox-scene-theft/xboxhd/4.jpg&quot; alt=&quot;Ghidra&quot; /&gt;&lt;/p&gt;
&lt;p style=&quot;text-align:center&quot;&gt;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;CERBIOS takes a very unusual approach. They re-implemented &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;AvSetDisplayMode&lt;/code&gt; three separate times, once for each encoder.
This makes no practical sense. It triples the code size, increases complexity, and does not follow the design of the
original kernel. More importantly, it closely mirrors the XboxHD+ runtime structure, where we split modules by hardware
revision to reduce memory usage. That design made sense in a boot-loaded runtime. It makes no sense inside a BIOS kernel
unless it was copied directly.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/img/blog/xbox-scene-theft/xboxhd/5.jpg&quot; alt=&quot;Ghidra&quot; /&gt;&lt;/p&gt;
&lt;p style=&quot;text-align:center&quot;&gt;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;Anyone reverse engineering the Xbox video subsystem would have seen that a single function with conditional logic is
the right approach. Duplicating the logic three times is not only inefficient but also suggests that it was taken from a
system designed to be loaded dynamically at runtime, not built directly into a BIOS. That kind of structure only makes
sense when you have the flexibility and memory overhead that a separate runtime allows. This matters because the Xbox
kernel has strict size limits. Without additional memory, like what Project Stellar provides, pushing memory usage higher
introduces uncertainty. It increases the risk that existing software will behave unpredictably or fail entirely.&lt;/p&gt;

&lt;p&gt;That is not all.&lt;/p&gt;

&lt;p&gt;Other parts of the project have also been copied. Code that was released under the GPL for the XboxHD+ application has
shown up in PrometheOS as well. This includes struct definitions that only exist in our released source code and cannot
be reconstructed by reverse engineering. These structures have been copied almost verbatim, with only minor changes such
as capitalization. This is not reverse engineering. This is copy and paste. And it is a clear violation of the license
and theft of our work.&lt;/p&gt;

&lt;h2 id=&quot;the-important-questions&quot;&gt;The Important Questions&lt;/h2&gt;
&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;If CERBIOS truly developed their work independently, why does their code mirror the structure of the XboxHD+ runtime,
which was never publicly released?&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;Why would anyone re-implement AvSetDisplayMode three separate times, when conditional logic in a single function is
the clear and correct solution?&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;How did struct definitions from our GPL-released userland application end up in PrometheOS, when those definitions
cannot be recovered through reverse engineering?&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;Why are memory usage patterns and hardware handling strategies identical to ours, even down to function placement?&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;Why would a BIOS be written in a way that pushes it closer to unknown memory limits, unless the design was copied from a
system intended to run as a boot-loaded runtime?&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;h2 id=&quot;theft-in-plain-sight&quot;&gt;Theft in Plain Sight&lt;/h2&gt;
&lt;p&gt;The comparisons in this section focus exclusively on code and behavior that were never part of the original public
domain release of the XboxHDMI patch. The early patch I released was minimal, designed only to initialize video output
and hand off control. It does not include subroutines for the virtual SMBus tables, configuration, or initialization.&lt;/p&gt;

&lt;p&gt;What follows are similarities that exist only in the private, copyrighted runtime and cannot be explained as
reimplementations of public work. These are not isolated coincidences. When viewed all together, I believe they show a
clear pattern of copying.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/img/blog/xbox-scene-theft/xboxhd/7.jpg&quot; alt=&quot;Ghidra&quot; /&gt;&lt;/p&gt;
&lt;p style=&quot;text-align:center&quot;&gt;The same logic of applying the exact same delay after storing the video mode.&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;&lt;/p&gt;

&lt;p&gt;As part of the XboxHD+ runtime, I introduced a small helper routine for setting the current virtual page. Functionally,
it’s extremely simple as it’s just a single register write with a hardcoded offset. It duplicates logic that already exists
elsewhere in the runtime, and looking back, even I’ll admit it should have just called the standard register write function.&lt;/p&gt;

&lt;p&gt;There was no technical reason to split it out. It was a quick decision made during development, and it remained because
it worked.&lt;/p&gt;

&lt;p&gt;The screenshots below show that CERBIOS includes the exact same kind of helper routine, with the same structure and purpose.
This is not a common design pattern. Anyone writing this from scratch would have just used the existing write register
subroutine. The fact that this unnecessary and oddly specific function appears in both runtimes is not a coincidence. I
believe it is another clear example of copied code.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/img/blog/xbox-scene-theft/xboxhd/8.jpg&quot; alt=&quot;Ghidra&quot; /&gt;&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/img/blog/xbox-scene-theft/xboxhd/9.jpg&quot; alt=&quot;Ghidra&quot; /&gt;&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/img/blog/xbox-scene-theft/xboxhd/10.jpg&quot; alt=&quot;Ghidra&quot; /&gt;&lt;/p&gt;
&lt;p style=&quot;text-align:center&quot;&gt;Identical virtual page setter routine found in both XboxHD+ and CERBIOS. The logic
duplicates existing write functionality that I believe would not have been independently re-created without copying.&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;&lt;/p&gt;

&lt;p&gt;Another example appears during the XboxHD+ initialization sequence. In early XboxHDMI firmware, we encountered a bug
where, in I2C software mode, the microcontroller could overflow before it entered hardware mode. To resolve this, we
added a very specific delay and call pattern in the initialization logic of the XboxHD+ runtime. This fix ensured
reliable behavior under edge conditions caused by queued SMBus transactions in the Xbox kernel.&lt;/p&gt;

&lt;p&gt;This delay is subtle and internal. It would not be visible externally, because SMBus operations are abstracted and queued
within the Xbox kernel. There is no way to observe or infer this behavior by watching from the outside.&lt;/p&gt;

&lt;p&gt;Yet, somehow, CERBIOS includes the exact same logic. The same call structure. The same delay in the same place. The only
difference is that CERBIOS omits this delay in unrelated areas, which further highlights how deliberate its inclusion is
here.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/img/blog/xbox-scene-theft/xboxhd/11.jpg&quot; alt=&quot;Ghidra&quot; /&gt;&lt;/p&gt;
&lt;p style=&quot;text-align:center&quot;&gt;CERBIOS initialization includes a delay and call structure identical to XboxHD+, originally
added to fix a microcontroller overflow issue in I2C software mode. This behavior is not externally observable and would
not appear without access to the XboxHD+ implementation.&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;&lt;/p&gt;

&lt;p&gt;The next example is not just a design copy. It’s a direct copy of source code.&lt;/p&gt;

&lt;p&gt;The screenshot below shows the PrometheOS source code defining a settings struct that matches our own, almost line for
line. This struct was published as part of the open source XboxHD+ application under the GPLv2. But in PrometheOS, it has
been taken without attribution, and more importantly, used in a way that is not compatible with our license. This is not
just a license violation. It is source-level theft.&lt;/p&gt;

&lt;p&gt;What makes this even more telling is that they copied struct members that are not implemented in their own code and could
not be reverse engineered. These fields serve no purpose under the XboxHD+ runtime or in PrometheOS but appear exactly as
they do in our code, with the same names and the same unused placeholders. That cannot happen by coincidence.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/img/blog/xbox-scene-theft/xboxhd/12.jpg&quot; alt=&quot;Ghidra&quot; /&gt;&lt;/p&gt;
&lt;p style=&quot;text-align:center&quot;&gt;PrometheOS struct copied directly from GPLv2 XboxHD+ source code, including unused and
unimplemented fields that cannot be reverse engineered. No attribution. No license compliance. This is source-level theft.&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;&lt;/p&gt;

&lt;h2 id=&quot;where-does-the-theft-end&quot;&gt;Where Does the Theft End?&lt;/h2&gt;
&lt;p&gt;Since the release of XboxHDMI, there has been a consistent effort within parts of the Xbox scene to clone, copy, and
steal whatever they can. This is not new. It has been happening in the open for years.&lt;/p&gt;

&lt;p&gt;At least four separate projects have attempted to recreate or reverse engineer XboxHDMI or XboxHD+, not through original
development but by following, dissecting, and imitating our work as closely as possible. With CERBIOS and PrometheOS, the
line between inspiration and theft is not blurry. It no longer exists.&lt;/p&gt;

&lt;p&gt;Even now, it is difficult to find a major project in this space that is not either directly benefiting from CERBIOS’s
stolen work or openly working to copy and replicate what we have built. What started as quiet imitation has become a
public ecosystem centered around copying. And somehow, this behavior continues to be rewarded and normalized.&lt;/p&gt;

&lt;p&gt;There are clone devices already on the market. Sellers advertise them and tell buyers they “just need to find the firmware”.
These are not throwaway comments. Members of Team Resurgent have previously written guides on how to bypass our copyright
protections in the past, and those same techniques are now being used to install stolen firmware onto unauthorized hardware.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/img/blog/xbox-scene-theft/xboxhd/13.jpg&quot; alt=&quot;Github&quot; /&gt;&lt;/p&gt;
&lt;p style=&quot;text-align:center&quot;&gt;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;This is not about gatekeeping. It is about respecting the time, effort, and work that go into creating something new.
The theft is not some distant danger; it is already happening behind closed doors. Stolen work is being rebranded,
repackaged, and quietly sold back to the very community it was taken from.&lt;/p&gt;

&lt;h1 id=&quot;hdd-unlocking&quot;&gt;HDD Unlocking&lt;/h1&gt;

&lt;h2 id=&quot;summary-1&quot;&gt;Summary&lt;/h2&gt;

&lt;p&gt;On &lt;a href=&quot;https://x.com/MakeMHz/status/1740841806810763660&quot;&gt;December 29, 2023&lt;/a&gt;, we released firmware version 1.4.0 for Project
Stellar. This update introduced, for the first time, fully integrated support for unlocking original Xbox hard drives
directly from a running system. This feature had been in development for over a year.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/img/blog/xbox-scene-theft/hdd-unlock/1.jpg&quot; alt=&quot;Twitter Post&quot; /&gt;&lt;/p&gt;

&lt;p&gt;Our work was based on in-depth reverse engineering of original Xbox hard drive firmware. To our knowledge, outside of
private commercial data recovery tools targeting specific models, there were no known public methods for unlocking these
drives. No documentation existed that demonstrated how to apply these techniques in the context of the Xbox, and no prior
tool supported all drive variants over IDE from a running system.&lt;/p&gt;

&lt;p&gt;Even more significant, this was an entirely new side channel attack that allowed drive unlocking to be performed directly
over the IDE bus.&lt;/p&gt;

&lt;p&gt;Later that same day, Harcroft, a member of the Xbox Data Preservation Discord and other related projects,
publicly replied to our announcement, stating:&lt;/p&gt;

&lt;p&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;We&apos;ve been doing this for the better part of a year with free software tools and $2 USB/TTL boards.&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href=&quot;https://x.com/OGX_Harcroft/status/1740847328314200410&quot;&gt;Twitter Post&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/img/blog/xbox-scene-theft/hdd-unlock/2.jpg&quot; alt=&quot;Twitter Post&quot; /&gt;&lt;/p&gt;

&lt;p&gt;The implication was clear: that this was old news, that what we had built was nothing new, and that the feature had
already been available in the scene for some time.&lt;/p&gt;

&lt;h2 id=&quot;the-important-questions-1&quot;&gt;The Important Questions&lt;/h2&gt;
&lt;ul&gt;
  &lt;li&gt;If this had already been done before, why does no one now seem to understand how Stellar works?&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;img src=&quot;/assets/img/blog/xbox-scene-theft/hdd-unlock/8.jpg&quot; alt=&quot;Chat&quot; /&gt;&lt;/p&gt;

&lt;p style=&quot;text-align:center&quot;&gt;Public Chat on Jan. 8th 2024 - Xbox Data Preservation Discord&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;If you’re not reverse engineering Project Stellar, how would you know that the unlocking logic was moved to a separate XBE?&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;img src=&quot;/assets/img/blog/xbox-scene-theft/hdd-unlock/4.jpg&quot; alt=&quot;Chat&quot; /&gt;&lt;/p&gt;
&lt;p style=&quot;text-align:center&quot;&gt;Public Chat on Jan. 8th 2024 - Xbox Data Preservation Discord&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;
    &lt;p&gt;If this is your own original implementation, why does the code match our patterns and not yours? Ours was originally
written for the Stellar kernel, which lacks a full runtime library and was only moved to an XBE at the last minute. Your
version uses direct kernel calls instead of the common RTL functions found throughout the rest of your codebase, which
are provided by the stolen XDK environment.&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;How is it that the temporary sleep and delay values that we implemented, down to the microsecond, also appear in your code?&lt;/p&gt;
  &lt;/li&gt;
  &lt;li&gt;
    &lt;p&gt;Why was the source code for the first release of PrometheOS with this feature never released? Seems odd for an
“open source” project.&lt;/p&gt;
  &lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;img src=&quot;/assets/img/blog/xbox-scene-theft/hdd-unlock/6.jpg&quot; alt=&quot;Twitter Post&quot; /&gt;&lt;/p&gt;
&lt;p style=&quot;text-align:center&quot;&gt;GitHub&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;Who is this mysterious “Phantom” member that joined the team? They haven’t been seen since… Scapegoat?&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;img src=&quot;/assets/img/blog/xbox-scene-theft/hdd-unlock/12.jpg&quot; alt=&quot;Chat&quot; /&gt;&lt;/p&gt;
&lt;p style=&quot;text-align:center&quot;&gt;Public Chat on March 1st 2024 - Xbox Data Preservation Discord&lt;/p&gt;
&lt;p&gt;&lt;br /&gt;&lt;/p&gt;

&lt;h2 id=&quot;theft-in-plain-sight-1&quot;&gt;Theft in Plain Sight&lt;/h2&gt;
&lt;p&gt;In this section, we’ll present direct comparisons between disassembled code from Project Stellar and PrometheOS, showing
unmistakable similarities that go far beyond coincidence. Screenshots and annotated listings will follow to allow anyone
to verify the claims for themselves.&lt;/p&gt;

&lt;p&gt;On February 25, 2024, nearly two months after Stellar’s 1.4.0 firmware release, Team Resurgent published PrometheOS
v1.2.0. [&lt;a href=&quot;/assets/img/blog/xbox-scene-theft/hdd-unlock/9.jpg&quot;&gt;1&lt;/a&gt;] This version introduced a new feature: support for
unlocking original Xbox hard drives.&lt;/p&gt;

&lt;p&gt;We’ll start with the smoking gun.&lt;/p&gt;

&lt;p&gt;The HDD unlock logic in Stellar was originally written as part of the kernel itself but was moved to an embedded
application (XBE) just before release. Because of this, the core logic remained unchanged. Inside that logic, we rely on
lower-level system functions due to the limitations of the Stellar kernel, which does not include a full runtime library.
Simple functions like &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;Sleep&lt;/code&gt; or &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;SleepEx&lt;/code&gt; are not available, nor are many standard helper functions. As a result, we used
&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;KeStallExecutionProcessor&lt;/code&gt; as a crude but effective way to introduce delays between command sequences.&lt;/p&gt;

&lt;p&gt;This approach is completely inconsistent with how PrometheOS typically handles delays. PrometheOS is built using a
stolen version of the official Xbox Development Kit (XDK) and has full access to &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;Sleep&lt;/code&gt;, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;SleepEx&lt;/code&gt;, and other XAPI-based
runtime functions. Their codebase contains over 150 references to Sleep-related calls, and only three references to
&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;KeStallExecutionProcessor&lt;/code&gt;. All three appear in a legacy method named SendATACommand() that was originally released by
&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;Team Assembly&lt;/code&gt; in 2003.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/img/blog/xbox-scene-theft/hdd-unlock/10.jpg&quot; alt=&quot;GitHub&quot; /&gt;&lt;/p&gt;

&lt;p&gt;Anyone who has written debug or delay-heavy logic using printf or timing functions knows how unpredictable and arbitrary
these values can be. The same applies here. But now consider this: &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;KeStallExecutionProcessor&lt;/code&gt; introduces delays in
microseconds, not milliseconds or seconds. These are one-millionth-of-a-second intervals.&lt;/p&gt;

&lt;p&gt;So what are the chances that two completely independent implementations, written by different people in different
environments, would not only use the same low-level delay function, but also choose the exact same timing values down to
the microsecond?&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/img/blog/xbox-scene-theft/hdd-unlock/code_0.jpg&quot; alt=&quot;Code&quot; /&gt;&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/img/blog/xbox-scene-theft/hdd-unlock/code_1.jpg&quot; alt=&quot;Code&quot; /&gt;&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/img/blog/xbox-scene-theft/hdd-unlock/code_2.jpg&quot; alt=&quot;Code&quot; /&gt;&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/img/blog/xbox-scene-theft/hdd-unlock/code_3.jpg&quot; alt=&quot;Code&quot; /&gt;&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/img/blog/xbox-scene-theft/hdd-unlock/code_4.jpg&quot; alt=&quot;Code&quot; /&gt;&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/img/blog/xbox-scene-theft/hdd-unlock/code_5.jpg&quot; alt=&quot;Code&quot; /&gt;&lt;/p&gt;

&lt;p&gt;This comparison of disassembled code represents the bulk of the new HDD unlock logic. It shows a repeated pattern of
identical pause logic, matching code structure, and even small but telling details like the use of the same temporary
buffer sizes. For example, both implementations allocate a 2048-byte buffer to handle roughly 500 bytes of data. There is
no technical justification for that size. It only makes sense if the implementation was copied.&lt;/p&gt;

&lt;p&gt;The few differences that do exist appear to be superficial refactoring. In Stellar, we access hardware registers directly
through inline instructions. In PrometheOS, these same accesses are routed through member functions. This is another
inconsistency that calls the originality of their code into question. Why would you go to the trouble of introducing
microsecond-precision delays using KeStallExecutionProcessor, only to throw away that timing accuracy by introducing
indirect hardware access? It does not add up unless you consider the possibility that the original logic was copied,
then lightly restructured to appear different.&lt;/p&gt;

&lt;p&gt;I don’t believe &lt;a href=&quot;https://maxcandocia.com/blog/2020/Dec/19/dream-power/&quot;&gt;Dream&lt;/a&gt; is a developer for PrometheOS when they’re
not playing Minecraft. And I don’t believe this code was written independently.&lt;/p&gt;

&lt;h1 id=&quot;theft-of-cpu-upgrade-support&quot;&gt;Theft of CPU Upgrade Support&lt;/h1&gt;

&lt;h2 id=&quot;summary-2&quot;&gt;Summary&lt;/h2&gt;
&lt;p&gt;One of the latest signs of copying appears in CERBIOS’s recent attempt to add support for upgraded CPUs. This is a
technically complex area and we are not disclosing any implementation details at this time.&lt;/p&gt;

&lt;p&gt;What we can show is a block of handwritten assembly in CERBIOS that matches code found in Stellar with near exact
precision. This is not compiled C code or something taken from documentation. This is hand-written assembly, written
instruction by instruction, with specific intent. It reflects deliberate choices made during development, not something
a compiler would generate on its own.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/img/blog/xbox-scene-theft/cpu-support/1.jpg&quot; alt=&quot;Twitter Post&quot; /&gt;&lt;/p&gt;
&lt;p style=&quot;text-align:center&quot;&gt;Side-by-side comparison of handwritten assembly in Stellar and CERBIOS. The instruction sequence is nearly identical. This is not coincidence. This is not reverse engineered. This appears to be copied.&lt;/p&gt;

&lt;p&gt;Yet somehow, CERBIOS includes what appears to be the same sequence of instructions, in the same order, performing the
same task. These are not high-level abstractions. These are low-level, manual decisions.&lt;/p&gt;

&lt;p&gt;It appears that CERBIOS has not yet completed the remaining logic needed to make this functional. But that is not what
matters here. This appears to be yet another case of theft. The code has no reason to exist in this exact form unless it
was copied. The chances of two developers independently writing the same hand-crafted assembly, down to the instruction
and layout, are virtually zero.
&lt;br /&gt;&lt;/p&gt;

&lt;h1 id=&quot;theft-of-the-xbox-kernel-source-code&quot;&gt;Theft of the Xbox Kernel Source Code&lt;/h1&gt;

&lt;h2 id=&quot;summary-3&quot;&gt;Summary&lt;/h2&gt;
&lt;p&gt;It is no secret that an older, pre-production version of the Xbox kernel source code was leaked years ago. What is also
widely known, though rarely acknowledged publicly, is that CERBIOS is that stolen code.&lt;/p&gt;

&lt;p&gt;This is not speculation. It is easily verifiable.&lt;/p&gt;

&lt;p&gt;The screenshot below shows how quickly the match can be confirmed. By using symbol signatures from debug and retail
kernels prior to version 5000, we were able to identify 1,478 out of 1,638 functions in CERBIOS with no additional effort.
Only 160 functions remained unmatched. With a small amount of tuning or adjustments, it would likely be possible to
identify nearly 100 percent of the original symbol map.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/img/blog/xbox-scene-theft/xbox-kernel/1.jpg&quot; alt=&quot;Xbox Kernel&quot; /&gt;&lt;/p&gt;
&lt;p style=&quot;text-align:center&quot;&gt;Out of 1,638 known functions, 1,478 match the Xbox kernel without modification. CERBIOS is
not clean-room. This is direct use of stolen Microsoft IP.&lt;/p&gt;

&lt;p&gt;This is not a clean-room implementation. This is not reverse engineering. This is just recompiling stolen code.&lt;/p&gt;

&lt;p&gt;It is a slap in the face to every developer who has chosen to do the work the right way. Many of us have spent years
reverse engineering legal, retail kernels and building our understanding from scratch. That work is slow, difficult, and
often thankless. But it is necessary for anyone who respects the boundaries of intellectual property and wants to build
something sustainable.&lt;/p&gt;

&lt;p&gt;CERBIOS throws that effort away. It relies on a stolen base, masks it with superficial changes, and presents it as
original development. It is not.
&lt;br /&gt;&lt;/p&gt;

&lt;h1 id=&quot;theft-of-the-xbox-development-sdk&quot;&gt;Theft of the Xbox Development SDK&lt;/h1&gt;

&lt;h2 id=&quot;summary-4&quot;&gt;Summary&lt;/h2&gt;
&lt;p&gt;Yet another open secret in the scene is the widespread illegal use of the official Xbox Development SDK. This is not a
rare case. It is routine. And it is required to build PrometheOS.&lt;/p&gt;

&lt;p&gt;Team Resurgent relies on the stolen SDK as part of their build process. This is not speculation. Their source code
contains headers, symbols, and dependencies that come directly from Microsoft’s proprietary SDK. Without it, the
project would not compile.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/img/blog/xbox-scene-theft/xbox-xdk/1.jpg&quot; alt=&quot;FATXplorer&quot; /&gt;&lt;/p&gt;
&lt;p style=&quot;text-align:center&quot;&gt;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;What makes this worse is that there are legal, open-source alternatives available. Toolchains like nxdk have been built
from the ground up by developers who respect licensing and legality. Despite this, the team behind PrometheOS continues
to take what is not theirs and justify it with silence.&lt;/p&gt;

&lt;p&gt;Because the SDK is stolen and unlicensed, no project that depends on it can be considered open source. It does not matter
how much code is published. If your toolchain requires pirated software to function, your project is not open. It is not
legal. It is not yours.&lt;/p&gt;

&lt;p&gt;The use of the stolen SDK is not just a technical shortcut. It is another example of how core parts of these projects are
built on theft. The foundation is illegitimate, and the work that follows carries that forward.
&lt;br /&gt;&lt;/p&gt;

&lt;h1 id=&quot;theft-of-in-game-reset-logic&quot;&gt;Theft of In-Game Reset Logic&lt;/h1&gt;

&lt;h2 id=&quot;summary-5&quot;&gt;Summary&lt;/h2&gt;
&lt;p&gt;In 2004, rmenhal released an open-source implementation of “In-Game Reset” (IGR) under the GPLv2 license. It is a clever and
unique approach that works by injecting logic into the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;KeRaiseIrqlToDpcLevel&lt;/code&gt; function. The key idea is to detect if the
function was triggered during the XAPI USB controller input interrupt by inspecting the call stack. Since Xbox applications
embed their own copies of the USB driver, this method allows the kernel to detect controller input with as little of a
memory footprint as possible.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/img/blog/xbox-scene-theft/igr/2.jpg&quot; alt=&quot;FATXplorer&quot; /&gt;&lt;/p&gt;
&lt;p style=&quot;text-align:center&quot;&gt;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;It is a smart solution to a difficult problem, but it comes with a tradeoff: performance. Because this check runs inside
&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;KeRaiseIrqlToDpcLevel&lt;/code&gt;, it is triggered on every interrupt raised to DPC level. That adds overhead, especially in systems
that already handle a high number of interrupts.&lt;/p&gt;

&lt;p&gt;Project Stellar avoids this entirely. Our implementation of in-game reset does not rely on IRQ-level detection and does
not hook into &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;KeRaiseIrqlToDpcLevel&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;CERBIOS, on the other hand, simply copies the original GPL-licensed implementation.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/img/blog/xbox-scene-theft/igr/1.jpg&quot; alt=&quot;FATXplorer&quot; /&gt;&lt;/p&gt;
&lt;p style=&quot;text-align:center&quot;&gt;&amp;nbsp;&lt;/p&gt;

&lt;p&gt;The screenshot above shows the beginning of &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;KeRaiseIrqlToDpcLevel&lt;/code&gt; in CERBIOS. The in-game reset logic is clearly visible
and matches exactly to rmenhal’s GPLv2 implementation. It is theft.&lt;/p&gt;

&lt;p&gt;This is only a portion of it. There is significantly more IGR-related logic elsewhere in the codebase that is also copied
but not shown here.&lt;/p&gt;

&lt;h1 id=&quot;other-concerns&quot;&gt;Other Concerns&lt;/h1&gt;
&lt;p&gt;There are several additional areas of concern that reflect ongoing issues with code theft, GPL violations, and uncredited
reuse. These examples, while not covered in depth above, continue to follow the same pattern of taking work that does not
belong to them and presenting it as original.&lt;/p&gt;

&lt;h2 id=&quot;cerbios-virtual-dvd-iso-support&quot;&gt;CERBIOS Virtual DVD (ISO) Support&lt;/h2&gt;
&lt;p&gt;CERBIOS’s Virtual DVD support behaves identically to rmenhal’s GPL-licensed implementation. Based on decompiled analysis,
it appears they have merged rmenhal’s virtual drive and image-handling logic. This is not a coincidence. The same gameplay
bugs and edge cases present in rmenhal’s code also appear in CERBIOS.
&lt;br /&gt;&lt;br /&gt;&lt;/p&gt;

&lt;h1 id=&quot;conclusion&quot;&gt;Conclusion&lt;/h1&gt;
&lt;p&gt;This isn’t the article I wanted to write. But after years of dealing with theft, misinformation, and targeted harassment,
it became clear that staying quiet was only helping the people taking advantage of the work we’ve built.&lt;/p&gt;

&lt;p&gt;What you’ve read here is just part of a much larger story. For every example shown, there are many more. Every product we
release, every line of code, and every idea ends up with someone ready to take it, remove the credit, and pass it off as
their own.&lt;/p&gt;

&lt;p&gt;But this isn’t just about me. It is about the thousands of people who have supported our work, who expect better from this
community, and who believe in doing things right. It is about building a space where legal, creative, and original work can
grow without being buried under theft and deception.&lt;/p&gt;

&lt;p&gt;If nothing else, I hope this post makes it clear that this behavior is not going unnoticed. It is not acceptable. And it
will be called out.&lt;/p&gt;

&lt;p&gt;I will keep going. I will keep improving Project Stellar, supporting XboxHD+, and doing the hard work the right way.
If you believe in that too, thank you for being here.&lt;/p&gt;

&lt;p&gt;This is only part one.&lt;/p&gt;
</description>
        <pubDate>Fri, 20 Jun 2025 11:32:45 +0000</pubDate>
        <link>https://lovemhz.com/blog/xbox-scene-theft/</link>
        <guid isPermaLink="true">https://lovemhz.com/blog/xbox-scene-theft/</guid>
        
        
        <category>Blog</category>
        
      </item>
    
      <item>
        <title>Blog: DIY Wifi Enabled Fish Tank</title>
        <description>&lt;p&gt;I recently purchased a
&lt;a href=&quot;http://www.amazon.com/gp/product/B001B4IKXS/ref=as_li_tl?ie=UTF8&amp;amp;camp=1789&amp;amp;creative=9325&amp;amp;creativeASIN=B001B4IKXS&amp;amp;linkCode=as2&amp;amp;tag=lo0e1-20&amp;amp;linkId=JJZXX7ZZAQ2P7VXI&quot;&gt;Aquarius AQ11204 BettaView Brite Corner Tank&lt;/a&gt;
and a cheerfully blue betta fish. The tank is a simple corner shaped tank that
fits perfectly on my desk and adds a bit of life to the mountain of technology
that every other inch of my office occupies. This particular tank also
incorporates a multi-mode RGB LED that can cycle through different modes by
pressing the button at the top. Overall, even without modifications, it’s a
great tank!&lt;/p&gt;

&lt;p&gt;But.. the lighting is a bit lacking. The light can only be toggled to stay on
for a few hours after a complicated sequence of long and short button presses.
The lighting modes are quite boring with only a few solid colors and an awkward
attempt at PWM control of the LEDs for the fading. Now this got me thinking how
I could improve this. I’ve had a bag full of ESP8266 boards for a while now,
almost 6 months, that I haven’t done anything with.&lt;/p&gt;

&lt;p&gt;For those who do not know anything about the ESP8266; it’s specs are as follows:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;Cost is less than $2 shipped!&lt;/li&gt;
  &lt;li&gt;Wi-Fi chip with full TCP/IP stack&lt;/li&gt;
  &lt;li&gt;80 MHz Microcontroller&lt;/li&gt;
  &lt;li&gt;64 KiB of instruction RAM&lt;/li&gt;
  &lt;li&gt;96 KiB RAM&lt;/li&gt;
  &lt;li&gt;External 512 KiB flash.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;In short, a powerful enough WiFi enabled microcontroller to control both the IO
devices and host a basic HTTP server on the cheap!&lt;/p&gt;

&lt;p&gt;So let’s get started! The goal for this project were as followed.&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;Weekend project. Shouldn’t take more than two days from start to finish.&lt;/li&gt;
  &lt;li&gt;Monitor and record water temperature every 30 seconds.&lt;/li&gt;
  &lt;li&gt;Text message alert if the water temperature reaches a concerning level.&lt;/li&gt;
  &lt;li&gt;Mobile friendly web interface for changing the color and effect mode.
(Constant color, fading, etc)&lt;/li&gt;
&lt;/ul&gt;

&lt;!--more--&gt;

&lt;h1 id=&quot;parts-list&quot;&gt;Parts List&lt;/h1&gt;

&lt;p&gt;The links provided below are through the Amazon Affiliate program. If you want
to do this project, and don’t mind waiting for the parts, then I highly recommend
buying most of them off of eBay. Buying from eBay should lower the project cost
(minus the tank) to around $12 bucks!&lt;/p&gt;

&lt;table&gt;
  &lt;thead&gt;
    &lt;tr&gt;
      &lt;th&gt; &lt;/th&gt;
      &lt;th&gt;Name&lt;/th&gt;
      &lt;th&gt;Qty&lt;/th&gt;
      &lt;th style=&quot;text-align: right&quot;&gt;Price&lt;/th&gt;
    &lt;/tr&gt;
  &lt;/thead&gt;
  &lt;tbody&gt;
    &lt;tr&gt;
      &lt;td&gt;&lt;a href=&quot;http://www.amazon.com/gp/product/B01B034F7O/ref=as_li_tl?ie=UTF8&amp;amp;camp=1789&amp;amp;creative=9325&amp;amp;creativeASIN=B01B034F7O&amp;amp;linkCode=as2&amp;amp;tag=lo0e1-20&amp;amp;linkId=PONNU5TCCWNMQ5RC&quot;&gt;&lt;img src=&quot;/assets/img/blog/diy-wifi-enabled-fish-tank/parts_voltage_reg.jpg&quot; alt=&quot;&quot; /&gt;&lt;/a&gt;&lt;/td&gt;
      &lt;td&gt;&lt;a href=&quot;http://www.amazon.com/gp/product/B01B034F7O/ref=as_li_tl?ie=UTF8&amp;amp;camp=1789&amp;amp;creative=9325&amp;amp;creativeASIN=B01B034F7O&amp;amp;linkCode=as2&amp;amp;tag=lo0e1-20&amp;amp;linkId=PONNU5TCCWNMQ5RC&quot;&gt;3.3V 950mA LD33V Voltage Regulator&lt;/a&gt;&lt;/td&gt;
      &lt;td&gt;x1&lt;/td&gt;
      &lt;td style=&quot;text-align: right&quot;&gt;$1.50&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;&lt;a href=&quot;http://www.amazon.com/gp/product/B017GPEFN4/ref=as_li_tl?ie=UTF8&amp;amp;camp=1789&amp;amp;creative=9325&amp;amp;creativeASIN=B017GPEFN4&amp;amp;linkCode=as2&amp;amp;tag=lo0e1-20&amp;amp;linkId=OFNQC3T7J2KT2ZDX&quot;&gt;&lt;img src=&quot;/assets/img/blog/diy-wifi-enabled-fish-tank/parts_esp.jpg&quot; alt=&quot;&quot; /&gt;&lt;/a&gt;&lt;/td&gt;
      &lt;td&gt;&lt;a href=&quot;http://www.amazon.com/gp/product/B017GPEFN4/ref=as_li_tl?ie=UTF8&amp;amp;camp=1789&amp;amp;creative=9325&amp;amp;creativeASIN=B017GPEFN4&amp;amp;linkCode=as2&amp;amp;tag=lo0e1-20&amp;amp;linkId=OFNQC3T7J2KT2ZDX&quot;&gt;ESP8266 WIFI Module&lt;/a&gt;&lt;/td&gt;
      &lt;td&gt;x1&lt;/td&gt;
      &lt;td style=&quot;text-align: right&quot;&gt;$5.99&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;&lt;a href=&quot;http://www.amazon.com/gp/product/B00IYE4X70/ref=as_li_tl?ie=UTF8&amp;amp;camp=1789&amp;amp;creative=9325&amp;amp;creativeASIN=B00IYE4X70&amp;amp;linkCode=as2&amp;amp;tag=lo0e1-20&amp;amp;linkId=RBP6K7HZU5CDWCLU&quot;&gt;&lt;img src=&quot;/assets/img/blog/diy-wifi-enabled-fish-tank/parts_temp.jpg&quot; alt=&quot;&quot; /&gt;&lt;/a&gt;&lt;/td&gt;
      &lt;td&gt;&lt;a href=&quot;http://www.amazon.com/gp/product/B00IYE4X70/ref=as_li_tl?ie=UTF8&amp;amp;camp=1789&amp;amp;creative=9325&amp;amp;creativeASIN=B00IYE4X70&amp;amp;linkCode=as2&amp;amp;tag=lo0e1-20&amp;amp;linkId=RBP6K7HZU5CDWCLU&quot;&gt;Waterproof Temperature Sensor DS18B20&lt;/a&gt;&lt;/td&gt;
      &lt;td&gt;x1&lt;/td&gt;
      &lt;td style=&quot;text-align: right&quot;&gt;$5.99&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;&lt;a href=&quot;http://www.amazon.com/gp/product/B005X251AE/ref=as_li_tl?ie=UTF8&amp;amp;camp=1789&amp;amp;creative=9325&amp;amp;creativeASIN=B005X251AE&amp;amp;linkCode=as2&amp;amp;tag=lo0e1-20&amp;amp;linkId=CZQ4HCWBAWZXTJMJ&quot;&gt;&lt;img src=&quot;/assets/img/blog/diy-wifi-enabled-fish-tank/parts_cap_10uf.jpg&quot; alt=&quot;&quot; /&gt;&lt;/a&gt;&lt;/td&gt;
      &lt;td&gt;&lt;a href=&quot;http://www.amazon.com/gp/product/B005X251AE/ref=as_li_tl?ie=UTF8&amp;amp;camp=1789&amp;amp;creative=9325&amp;amp;creativeASIN=B005X251AE&amp;amp;linkCode=as2&amp;amp;tag=lo0e1-20&amp;amp;linkId=CZQ4HCWBAWZXTJMJ&quot;&gt;10uF Polarized Capacitor&lt;/a&gt;&lt;/td&gt;
      &lt;td&gt;x1&lt;/td&gt;
      &lt;td style=&quot;text-align: right&quot;&gt;&amp;lt; $0.08&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;&lt;a href=&quot;http://www.amazon.com/gp/product/B00HPQOFR6/ref=as_li_tl?ie=UTF8&amp;amp;camp=1789&amp;amp;creative=9325&amp;amp;creativeASIN=B00HPQOFR6&amp;amp;linkCode=as2&amp;amp;tag=lo0e1-20&amp;amp;linkId=ALDUBBPWV54XLTAD&quot;&gt;&lt;img src=&quot;/assets/img/blog/diy-wifi-enabled-fish-tank/parts_cap_100nf.jpg&quot; alt=&quot;&quot; /&gt;&lt;/a&gt;&lt;/td&gt;
      &lt;td&gt;&lt;a href=&quot;http://www.amazon.com/gp/product/B00HPQOFR6/ref=as_li_tl?ie=UTF8&amp;amp;camp=1789&amp;amp;creative=9325&amp;amp;creativeASIN=B00HPQOFR6&amp;amp;linkCode=as2&amp;amp;tag=lo0e1-20&amp;amp;linkId=ALDUBBPWV54XLTAD&quot;&gt;0.1uF (100nF) Capacitor&lt;/a&gt;&lt;/td&gt;
      &lt;td&gt;x1&lt;/td&gt;
      &lt;td style=&quot;text-align: right&quot;&gt;&amp;lt; $0.08&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;&lt;a href=&quot;http://www.amazon.com/gp/product/B00GUNXE6I/ref=as_li_tl?ie=UTF8&amp;amp;camp=1789&amp;amp;creative=9325&amp;amp;creativeASIN=B00GUNXE6I&amp;amp;linkCode=as2&amp;amp;tag=lo0e1-20&amp;amp;linkId=75GQFFMKNN5YLRMN&quot;&gt;&lt;img src=&quot;/assets/img/blog/diy-wifi-enabled-fish-tank/parts_power.jpg&quot; alt=&quot;&quot; /&gt;&lt;/a&gt;&lt;/td&gt;
      &lt;td&gt;&lt;a href=&quot;http://www.amazon.com/gp/product/B00GUNXE6I/ref=as_li_tl?ie=UTF8&amp;amp;camp=1789&amp;amp;creative=9325&amp;amp;creativeASIN=B00GUNXE6I&amp;amp;linkCode=as2&amp;amp;tag=lo0e1-20&amp;amp;linkId=75GQFFMKNN5YLRMN&quot;&gt;5V DC Wall Power Adapter&lt;/a&gt;&lt;/td&gt;
      &lt;td&gt;x1&lt;/td&gt;
      &lt;td style=&quot;text-align: right&quot;&gt;$7.98&lt;/td&gt;
    &lt;/tr&gt;
  &lt;/tbody&gt;
&lt;/table&gt;

&lt;hr /&gt;

&lt;h1 id=&quot;brief-overview&quot;&gt;Brief Overview&lt;/h1&gt;
&lt;p&gt;&lt;img src=&quot;/assets/img/blog/diy-wifi-enabled-fish-tank/brief_overview_header.jpg&quot; alt=&quot;Brief Overview&quot; /&gt;
On top of the tank is a removable, oblong puck shaped module that encloses the
RGB LEDs, the big blue button for controlling the LEDs, a 5V power barrel input
port and a battery slot for 3 AAA batteries.&lt;/p&gt;

&lt;hr /&gt;

&lt;p&gt;&lt;img src=&quot;/assets/img/blog/diy-wifi-enabled-fish-tank/led_module.png&quot; alt=&quot;LED Module&quot; /&gt;&lt;/p&gt;

&lt;h2 id=&quot;led-module&quot;&gt;LED Module&lt;/h2&gt;

&lt;p&gt;Inside of the LED Module, for the lack of a better name, consists of a few bare
components. From left to right we find the PCB, battery contacts and the 5v
power connector at the rear.&lt;/p&gt;

&lt;hr /&gt;

&lt;p&gt;&lt;img src=&quot;/assets/img/blog/diy-wifi-enabled-fish-tank/led_pcb.png&quot; alt=&quot;LED PCB&quot; /&gt;&lt;/p&gt;

&lt;h2 id=&quot;led-pcb&quot;&gt;LED PCB&lt;/h2&gt;
&lt;p&gt;The LED PCB pictured above is a simple layout consisting of MCU (removed in the
picture), an NPN transistor array with pull down resistors for each channel of
the RGB LEDs, self-power off logic(transistor + capacitor) and power button. The
MCU was not investigated due to it being unmarked and most likely being a masked
ROM. In the picture I’ve highlighted the pinout from the MCU footprint for each
of the RGB LED transistor leds and the button.&lt;/p&gt;

&lt;hr /&gt;

&lt;p&gt;&lt;img src=&quot;/assets/img/blog/diy-wifi-enabled-fish-tank/deconstruction.png&quot; alt=&quot;Deconstruction&quot; /&gt;&lt;/p&gt;

&lt;h2 id=&quot;deconstruction&quot;&gt;Deconstruction&lt;/h2&gt;
&lt;p&gt;Deconstruction was quite easy. Started by removing all of the components and
breaking the plastic pieces of the battery separator. In the future, I hope to
find the right Dremel bit for cleaning up such tasks. Not a lot of time was spent
freeing up space as there’s plenty on the inside for what I wanted to do.&lt;/p&gt;

&lt;hr /&gt;

&lt;h1 id=&quot;schematic&quot;&gt;Schematic&lt;/h1&gt;
&lt;p&gt;&lt;a href=&quot;https://github.com/LoveMHz/WifiFishTank/blob/master/schematic/WifiFish.pdf&quot;&gt;&lt;img src=&quot;/assets/img/blog/diy-wifi-enabled-fish-tank/schematic.png&quot; alt=&quot;Schematic&quot; /&gt;&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;The schematic for this project is actually quite simple and is built of a couple
sections. Were saving a lot time by directly controlling the transistors on the
LED PCB. The LEDs, wired in parallel, would normally pull too much current for
the ESP pins to handle, but in this case we should be fine since we’re only
controlling the transistors directly.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Power Input&lt;/strong&gt; -
The power input is the barrel jack located on the device and provides 5v to the
LED PCB and to the LD1117V33 voltage regulator.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Power Input -&amp;gt; 3.3v&lt;/strong&gt; - This is the 5v to 3.3v regulator along with the
associated stability capacitors.
&lt;a href=&quot;https://www.sparkfun.com/datasheets/Components/LD1117V33.pdf&quot;&gt;Datasheet&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;RGB PCB IC&lt;/strong&gt; - 
This section represents 4 of the MCU/IC pins found on the PCB as described
previously in the PCB LED section.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;ESP8266&lt;/strong&gt; - 
In this project I’m using the ESP8266 ESP-03. &lt;em&gt;CH_PD&lt;/em&gt; must be tied high, 3.3v,
for the ESP8266 to turn on and &lt;em&gt;GPIO15&lt;/em&gt; must be tied to ground. (More
information about the different board variations of the ESP8266 can be found
&lt;a href=&quot;http://www.esp8266.com/wiki/doku.php?id=esp8266-module-family&quot;&gt;here&lt;/a&gt;.) &lt;em&gt;GPIO0&lt;/em&gt;,
also know as &lt;em&gt;PROG&lt;/em&gt;, must be tied to ground on power to enter programming mode.&lt;/p&gt;

&lt;p&gt;An optional decoupling cap of 0.1uf on the &lt;em&gt;VCC&lt;/em&gt;/&lt;em&gt;GND&lt;/em&gt; pins may be added,
but was omitted.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;ESP8266 - Debug Header&lt;/strong&gt; -
In this project I used a simple 1x4 pin header to breakout a connection for the
&lt;em&gt;TxD&lt;/em&gt;, &lt;em&gt;RxD&lt;/em&gt;, &lt;em&gt;5v&lt;/em&gt;, and &lt;em&gt;GND&lt;/em&gt;. This allowed me to program and debug with a 3.3v
USB serial cable that also provided 5v for the LED PCB.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;ESP8266 - Temp Probe&lt;/strong&gt; -
The temperature probe is a DS18B20 and was chosen as it comes in a waterproof
enclosure. The DS18B20 communicates over 1-Wire and a 4.7k pull down resistor is
used on the &lt;em&gt;VDD/DQ&lt;/em&gt; pins.&lt;/p&gt;

&lt;hr /&gt;

&lt;h1 id=&quot;hardware&quot;&gt;Hardware&lt;/h1&gt;
&lt;p&gt;&lt;img src=&quot;/assets/img/blog/diy-wifi-enabled-fish-tank/hardware.png&quot; alt=&quot;Schematic&quot; /&gt;&lt;/p&gt;

&lt;p&gt;The hardware is pretty straight forward. Following the schematic along with a
bit of hot glue. The connections were made on top of a piece of prototyping
board. As this is a one off prototype and won’t be moving around I was not
worried about using hot glue or the appearance of the internal circuitry.
&lt;em&gt;Yummm hot glue.&lt;/em&gt;&lt;/p&gt;

&lt;hr /&gt;

&lt;h1 id=&quot;software&quot;&gt;Software&lt;/h1&gt;
&lt;p&gt;&lt;img src=&quot;/assets/img/blog/diy-wifi-enabled-fish-tank/software_screenshot.png&quot; alt=&quot;Schematic&quot; /&gt;&lt;/p&gt;

&lt;p&gt;The software is easily the most interesting part of this project for myself. The
project as a whole really demonstrates that the industry for IoT devices is
currently possible with the low cost of the hardware required. However, in a lot
of ways we lack the software needed to connect everything together. For this
project, the web interface is made of simple HTML, CSS and Javascript. For a
quick UI I went with  Bootstrap. This provides a clean and responsive interface
both for desktop and mobile.&lt;/p&gt;

&lt;p&gt;Initially, I wanted to code this simple project using Angular or React, but was
worried about packing everything up on the ESP8266’s somewhat limited 512 KiB of
storage. So in the end, I went with a more traditional solution of using jQuery
for the basic UI switching and GET based communication.&lt;/p&gt;

&lt;p&gt;The C/C++ side of things was pretty straight forward as it’s using the ESP8266
library for hosting and routing the HTTP server. The build process consists of
using the PlatformIO platform along with a Python script to build and compress
the HTML resources into C headers. The LED functions were initially coded by
myself, but later I came across “Arduino-RGBEffects”, which I found to be better
structured and already had a clean cube/fade effect implemented.&lt;/p&gt;

&lt;p&gt;Another great feature of ubidots is the event system. This allows me to set up
events for any condition based on the sensor I have installed which, in this
case, was the water temperature sensor. Currently, I have a text message alert
setup for, if the water temperature reaches an unsafe level of less than 65 °F
or greater than 80 °F, I will be alerted via text message.&lt;/p&gt;

&lt;hr /&gt;

&lt;h1 id=&quot;the-world-of-iot&quot;&gt;The World of IoT&lt;/h1&gt;
&lt;p&gt;&lt;img src=&quot;/assets/img/blog/diy-wifi-enabled-fish-tank/ubidots_dashboard.png&quot; alt=&quot;Ubidots Dashboard&quot; /&gt;&lt;/p&gt;

&lt;p&gt;While there’s an increasingly large number of IoT implementation and tracking
services being released everyday, I chose to go with the ubidots due to it’s
easy to use REST API and free tier of 0.5 million sensor updates (dots) per
month, with 1 month of historical storage. This allows me to track the water
temperature at a conservative rate of every 30 seconds and view the resulting
data for the month online from anywhere in the world.&lt;/p&gt;

&lt;p&gt;Using this service solved one of my original concerns for this project on how to
implement tracking, both efficiently and quickly. Luckily, by using ubidots, I
went from a working prototype to having it fully implemented within an hour.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/img/blog/diy-wifi-enabled-fish-tank/ubidots_events.png&quot; alt=&quot;Ubidots Events&quot; /&gt;&lt;/p&gt;

&lt;hr /&gt;

&lt;h1 id=&quot;conclusion&quot;&gt;Conclusion&lt;/h1&gt;

&lt;p&gt;Now that I’m the NSA of fish metadata tracking, I can sit back and think over
the project. This was a really fun project and I’m happy to say that I was able
to accomplish the original goals I had set out to complete.&lt;/p&gt;

&lt;p&gt;The ESP8266 has been a wonderful chip to work with and the community support,
taking full advantage of it, has made it a breeze to use. This will most
definitely not be the last project I take on using the ESP8266.&lt;/p&gt;

&lt;p&gt;In the future, I hope to more closely evaluate using Node JS instead of C/C++
for the main code. Alongside implementing a proper REST API, I hope to also
incorporate the MQTT protocol for a more complete IoT device.&lt;/p&gt;
</description>
        <pubDate>Sat, 19 Mar 2016 11:32:45 +0000</pubDate>
        <link>https://lovemhz.com/blog/diy-wifi-enabled-fish-tank/</link>
        <guid isPermaLink="true">https://lovemhz.com/blog/diy-wifi-enabled-fish-tank/</guid>
        
        <category>Java</category>
        
        <category>Go</category>
        
        <category>Python</category>
        
        
        <category>Blog</category>
        
      </item>
    
      <item>
        <title>Blog: KF-Mario_64 - Map Release</title>
        <description>&lt;p&gt;&lt;a href=&quot;http://steamcommunity.com/sharedfiles/filedetails/?id=645410401&quot;&gt;Project Page&lt;/a&gt;
&lt;a href=&quot;http://steamcommunity.com/sharedfiles/filedetails/?id=645410401&quot;&gt;Steam Workshop&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;It’s not everyday that I get to sit down and work on something that excites me
as much as this project. Over the years I’ve taken great joy in working on video
game related projects. When &lt;a href=&quot;http://store.steampowered.com/app/232090/&quot;&gt;Killing Floor 2&lt;/a&gt;
entered Early Access on Steam last year I knew I wanted to finally make a mod
for this game.&lt;/p&gt;

&lt;!--more--&gt;

&lt;h1 id=&quot;screenshots&quot;&gt;Screenshots&lt;/h1&gt;

&lt;p&gt;&lt;img src=&quot;/assets/img/blog/kf-mario/20160314182448_1.jpg&quot; alt=&quot;Screenshot 1&quot; /&gt;&lt;/p&gt;

&lt;table&gt;
  &lt;tbody&gt;
    &lt;tr&gt;
      &lt;td&gt; &lt;/td&gt;
      &lt;td&gt; &lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;&lt;img src=&quot;/assets/img/blog/kf-mario/20160314182143_1.jpg&quot; alt=&quot;Screenshot 1&quot; /&gt;&lt;/td&gt;
      &lt;td&gt;&lt;img src=&quot;/assets/img/blog/kf-mario/20160314182406_1.jpg&quot; alt=&quot;Screenshot 2&quot; /&gt;&lt;/td&gt;
    &lt;/tr&gt;
    &lt;tr&gt;
      &lt;td&gt;&lt;img src=&quot;/assets/img/blog/kf-mario/20160314181435_1.jpg&quot; alt=&quot;Screenshot 3&quot; /&gt;&lt;/td&gt;
      &lt;td&gt;&lt;img src=&quot;/assets/img/blog/kf-mario/20160314181641_1.jpg&quot; alt=&quot;Screenshot 4&quot; /&gt;&lt;/td&gt;
    &lt;/tr&gt;
  &lt;/tbody&gt;
&lt;/table&gt;

&lt;hr /&gt;

&lt;h1 id=&quot;3d-modeling&quot;&gt;3D Modeling&lt;/h1&gt;

&lt;p&gt;&lt;img src=&quot;/assets/img/blog/kf-mario/kf_mario_blender.png&quot; alt=&quot;Blender Screenshot&quot; /&gt;&lt;/p&gt;

&lt;p&gt;The 3D modeling aspect of this project was fairly straight forward. The map is
based off of the amazing
&lt;a href=&quot;https://sketchfab.com/models/a21cffbe8b8c4ae9b1614f26f2da8fed&quot;&gt;Peach Castle&lt;/a&gt;
by &lt;a href=&quot;https://sketchfab.com/mstuff&quot;&gt;mStuff&lt;/a&gt;. Most the work myself was optimizing 
textures, fixing geometry, and simplifying the ground model to work better in
the Unreal Engine without having to create collision meshes.&lt;/p&gt;

&lt;p&gt;The inside of the castle was ripped from Super Mario 64 using modified debug
code I had written for &lt;a href=&quot;http://lovemhz.com/projects/love364/&quot;&gt;Love364&lt;/a&gt;. Most of
the work there was fixing vertices and some oddities from development
optimizations in the game. The UV Map was completely redone by hand.&lt;/p&gt;

&lt;p&gt;The map consists of 116,681 Verts, 89,222 Faces, and 178,422 Tris.&lt;/p&gt;

&lt;hr /&gt;

&lt;h1 id=&quot;unreal-engine-35&quot;&gt;Unreal Engine 3.5&lt;/h1&gt;

&lt;p&gt;&lt;img src=&quot;/assets/img/blog/kf-mario/kf_mario_unreal.jpg&quot; alt=&quot;Unreal Editor&quot; /&gt;&lt;/p&gt;

&lt;p&gt;It’s been awhile since I’ve worked with the Unreal Engine, and the first time
I’ve used anything newer than Unreal Engine 2, but it’s interface and options
over the years are for the most part the same.&lt;/p&gt;

&lt;p&gt;Most of this project consisted of working inside of the Unreal Editor. Tweaking,
and even more tweaking, pathing was one of the more challenging aspects. The key
to any good Killing Floor map is setting up an unseemingly predictable paths
with AI spawners behind every corner. Additional work was performed on adding
blocking elements to prevent exploitable map spots.&lt;/p&gt;

&lt;p&gt;Skybox, global lighting, normal mapping, etc was applied. Currently, Killing
Floor 2 doesn’t support custom Materials and instead requires creators to use a
limited set of premade Materials via Material Constants. Due to this, a lot of
time was not spent trying to improve the lighting beyond simple world settings
due to limitations. (All the textures have prebaked shadows and the lack of
additional lighting tricks isn’t visual missed)&lt;/p&gt;

&lt;hr /&gt;

&lt;h1 id=&quot;steam-workshop&quot;&gt;Steam Workshop&lt;/h1&gt;

&lt;p&gt;&lt;img src=&quot;/assets/img/blog/kf-mario/kf_mario_steamworkshop.jpg&quot; alt=&quot;kf_mario_steamworkshop&quot; /&gt;&lt;/p&gt;

&lt;p&gt;Not much to say about the Steam Workshop, but I did want to talk about it none
the less. Starting this project was I unsure of the submission process involved
and put it off until the map was completed. I was very surprised to find out
that through a simple upload tool provided with the SDK I was able to click a
few buttons and it uploaded to Steam. Since then I’ve added screenshots and
descriptions. Already in the last few weeks I’ve had amazing feedback. It
appears Steam has created a great platform for game content.&lt;/p&gt;

&lt;hr /&gt;

&lt;h1 id=&quot;conclusion&quot;&gt;Conclusion&lt;/h1&gt;

&lt;p&gt;At the end of this I must say I’m really happy with how everything turned out.
It was a short project, 3-4 days, but seeing other people enjoy something you
created is none the less as enjoyable. It was also a great refresher in 3D
modeling and the Unreal Engine. Hopefully, in the near future, I will return and
either improve this map or create something new entirely. Though I may wait
until Tripwire adds proper support for Unreal Materials.&lt;/p&gt;
</description>
        <pubDate>Mon, 14 Mar 2016 11:21:21 +0000</pubDate>
        <link>https://lovemhz.com/blog/kf-mario_64-map-release/</link>
        <guid isPermaLink="true">https://lovemhz.com/blog/kf-mario_64-map-release/</guid>
        
        
        <category>Blog</category>
        
      </item>
    
      <item>
        <title>Blog: Reverse Engineering a Bluetooth Enabled Battery Charger</title>
        <description>&lt;h3 id=&quot;overview&quot;&gt;Overview&lt;/h3&gt;

&lt;p&gt;Through the never ending stream of &lt;em&gt;connected&lt;/em&gt; devices on the market we
have yet another. Today, I look at and tear into the workings of Efest’s latest
product, the 
&lt;em&gt;&lt;a href=&quot;http://www.efestpower.com/index.php?ac=article&amp;amp;at=read&amp;amp;did=409&quot;&gt;Efest LUC BLU6 OLED Intelligent Charger&lt;/a&gt;.&lt;/em&gt;&lt;/p&gt;

&lt;p&gt;The goal of this project is to identify, reverse engineer, and evaluate the
safety of this device. Through this process I’ll also be writing a simple
interface library in Go as a working exercise in my pursuit to become more
efficient in this new programming language.&lt;/p&gt;

&lt;!--more--&gt;

&lt;hr /&gt;

&lt;h3 id=&quot;what-you-will-need&quot;&gt;What You Will Need&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;Basic Java knowledge&lt;/li&gt;
  &lt;li&gt;Bluetooth LE compatible computer&lt;/li&gt;
  &lt;li&gt;Android Development Environment&lt;/li&gt;
&lt;/ul&gt;

&lt;hr /&gt;

&lt;h3 id=&quot;analysis&quot;&gt;Analysis&lt;/h3&gt;

&lt;p&gt;Analysis starts off with looking at companion app. We will be downloading the
Android version of the app due the fact that it’s generally easier to
disassemble.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/img/blog/reverse-engineering-a-bluetooth-enabled-battery-charger/google-play.png&quot; alt=&quot;Google Play&quot; /&gt;&lt;/p&gt;

&lt;p&gt;After looking at the device on a mobile device, or via running it inside of
Android x86 and Virtualbox with Bluetooth passthrough, we can see that it’s very
simple app that displays information about each charging slot. (Current voltage,
charging current, status, and charging progress chart). Also it has the option
to change each charging slots’ charging current.&lt;/p&gt;

&lt;p&gt;Now let’s peek inside the app. All Android applications are packaged into an APK
file. APK files are simply ZIP archives and can be easily extracted. The easiest
way I’ve found to download the application’s APK is to first find the app on the
Google Play website, retrive the app id, and use a third party website to
download the APK. For example, this app can be found at
https://play.google.com/store/apps/details?id=cn.efest&amp;amp;hl=en. Note the id
parameter in the url. Now that we have the app id we can use a site such as
&lt;a href=&quot;https://apkpure.com/&quot;&gt;apkpure.com&lt;/a&gt; to download the APK. Once downloaded,
extract the APK as a zip.&lt;/p&gt;

&lt;p&gt;&lt;img src=&quot;/assets/img/blog/reverse-engineering-a-bluetooth-enabled-battery-charger/files.png&quot; alt=&quot;Files&quot; /&gt;&lt;/p&gt;

&lt;p&gt;Once extracted the files should look like the screenshot above. Now the first
thing I do is check to see if it’s bundled with any native libs, normally
located in a /libs folder if any exist. Luckily in this case there isn’t any.
So at this point we can carry on and disassemble the Java code. The easiest and
quickest method I’ve found for doing this is a site called 
&lt;a href=&quot;http://decompileandroid.com&quot;&gt;http://www.decompileandroid.com/&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Great! Now we have the app and the decompiled Java code so let’s start looking
around.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;MainActivity.java&lt;/em&gt;&lt;/p&gt;

&lt;div class=&quot;language-java highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;&lt;span class=&quot;kn&quot;&gt;package&lt;/span&gt; &lt;span class=&quot;nn&quot;&gt;cn.efest&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;;&lt;/span&gt;
&lt;span class=&quot;kn&quot;&gt;import&lt;/span&gt; &lt;span class=&quot;nn&quot;&gt;android.bluetooth.BluetoothAdapter&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;;&lt;/span&gt;
&lt;span class=&quot;kn&quot;&gt;import&lt;/span&gt; &lt;span class=&quot;nn&quot;&gt;android.bluetooth.BluetoothAdapter.LeScanCallback&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;;&lt;/span&gt;
&lt;span class=&quot;o&quot;&gt;...&lt;/span&gt;
&lt;span class=&quot;kd&quot;&gt;public&lt;/span&gt; &lt;span class=&quot;kd&quot;&gt;class&lt;/span&gt; &lt;span class=&quot;nc&quot;&gt;DeviceScanActivity&lt;/span&gt; &lt;span class=&quot;kd&quot;&gt;extends&lt;/span&gt; &lt;span class=&quot;nc&quot;&gt;ActionBarActivity&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;{&lt;/span&gt;
&lt;span class=&quot;o&quot;&gt;...&lt;/span&gt;
   &lt;span class=&quot;kd&quot;&gt;private&lt;/span&gt; &lt;span class=&quot;kt&quot;&gt;void&lt;/span&gt; &lt;span class=&quot;nf&quot;&gt;scanLeDevice&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;kt&quot;&gt;boolean&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;enable&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;{&lt;/span&gt;
&lt;span class=&quot;o&quot;&gt;...&lt;/span&gt;
      &lt;span class=&quot;n&quot;&gt;adapter&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;na&quot;&gt;startLeScan&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;k&quot;&gt;this&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;na&quot;&gt;mLeScanCallback&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;);&lt;/span&gt;
&lt;span class=&quot;o&quot;&gt;...&lt;/span&gt;
   &lt;span class=&quot;o&quot;&gt;}&lt;/span&gt;
&lt;span class=&quot;o&quot;&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;After looking at the &lt;em&gt;MainActivity.java&lt;/em&gt; we can see that it’s using the Android
Bluetooth API to do a Bluetooth LE, &lt;em&gt;low energy&lt;/em&gt;, scan. Knowing this will come
in handy when we start playing around with the connection. Now let’s figure out
how data is handled.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;MainActivity.java&lt;/em&gt;&lt;/p&gt;
&lt;div class=&quot;language-java highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;&lt;span class=&quot;kn&quot;&gt;import&lt;/span&gt; &lt;span class=&quot;nn&quot;&gt;com.iwit.bluetoothcommunication.util.encodeUtil&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;;&lt;/span&gt;
&lt;span class=&quot;o&quot;&gt;...&lt;/span&gt;
&lt;span class=&quot;kd&quot;&gt;public&lt;/span&gt; &lt;span class=&quot;kd&quot;&gt;class&lt;/span&gt; &lt;span class=&quot;nc&quot;&gt;MainActivity&lt;/span&gt; &lt;span class=&quot;kd&quot;&gt;extends&lt;/span&gt; &lt;span class=&quot;nc&quot;&gt;ActionBarActivity&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;{&lt;/span&gt;
&lt;span class=&quot;o&quot;&gt;...&lt;/span&gt;
    &lt;span class=&quot;kd&quot;&gt;private&lt;/span&gt; &lt;span class=&quot;nc&quot;&gt;Pattern&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;mChannelPattern&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;;&lt;/span&gt;

    &lt;span class=&quot;kd&quot;&gt;public&lt;/span&gt; &lt;span class=&quot;nf&quot;&gt;MainActivity&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;()&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;{&lt;/span&gt;
&lt;span class=&quot;o&quot;&gt;...&lt;/span&gt;
        &lt;span class=&quot;k&quot;&gt;this&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;na&quot;&gt;mChannelPattern&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;nc&quot;&gt;Pattern&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;na&quot;&gt;compile&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;s&quot;&gt;&quot;CH(\\d):(\\d),([0-9.]+)V,([0-9]+)mA,([0-9]+)per,(\\d)(\\d)&quot;&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;mi&quot;&gt;2&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;);&lt;/span&gt;
&lt;span class=&quot;o&quot;&gt;...&lt;/span&gt;
    &lt;span class=&quot;o&quot;&gt;}&lt;/span&gt;

    &lt;span class=&quot;kd&quot;&gt;private&lt;/span&gt; &lt;span class=&quot;kt&quot;&gt;void&lt;/span&gt; &lt;span class=&quot;nf&quot;&gt;handleData&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;kt&quot;&gt;byte&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;[]&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;buf&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;{&lt;/span&gt;
        &lt;span class=&quot;k&quot;&gt;this&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;na&quot;&gt;notifyString&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;+=&lt;/span&gt; &lt;span class=&quot;nc&quot;&gt;StringUtil&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;na&quot;&gt;hexStr2Str&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;encodeUtil&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;na&quot;&gt;decodeMessage&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;buf&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;).&lt;/span&gt;&lt;span class=&quot;na&quot;&gt;toUpperCase&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;());&lt;/span&gt;

        &lt;span class=&quot;cm&quot;&gt;/* RE Note: Is the device turning off? */&lt;/span&gt;
        &lt;span class=&quot;k&quot;&gt;if&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;k&quot;&gt;this&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;na&quot;&gt;notifyString&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;na&quot;&gt;contains&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;s&quot;&gt;&quot;AT+OK+SCROFF\r\n&quot;&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;))&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;{&lt;/span&gt;
            &lt;span class=&quot;k&quot;&gt;this&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;na&quot;&gt;closingOLED&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;kc&quot;&gt;false&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;;&lt;/span&gt;
            &lt;span class=&quot;n&quot;&gt;invalidateOptionsMenu&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;();&lt;/span&gt;
            &lt;span class=&quot;k&quot;&gt;this&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;na&quot;&gt;notifyString&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;nc&quot;&gt;BuildConfig&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;na&quot;&gt;FLAVOR&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;;&lt;/span&gt;

        &lt;span class=&quot;cm&quot;&gt;/* RE Note: Is this an update? */&lt;/span&gt;
        &lt;span class=&quot;o&quot;&gt;}&lt;/span&gt; &lt;span class=&quot;k&quot;&gt;else&lt;/span&gt; &lt;span class=&quot;k&quot;&gt;if&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;k&quot;&gt;this&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;na&quot;&gt;notifyString&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;na&quot;&gt;contains&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;s&quot;&gt;&quot;\r\n&quot;&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;))&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;{&lt;/span&gt;
            &lt;span class=&quot;nc&quot;&gt;String&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;[]&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;arr&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;k&quot;&gt;this&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;na&quot;&gt;notifyString&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;na&quot;&gt;split&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;s&quot;&gt;&quot;\r\n&quot;&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;);&lt;/span&gt;
            &lt;span class=&quot;k&quot;&gt;if&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;arr&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;na&quot;&gt;length&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;&amp;gt;=&lt;/span&gt; &lt;span class=&quot;no&quot;&gt;REQUEST_ENABLE_BT&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;{&lt;/span&gt;
                &lt;span class=&quot;n&quot;&gt;parseData&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;arr&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;mi&quot;&gt;0&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;]);&lt;/span&gt;
&lt;span class=&quot;o&quot;&gt;...&lt;/span&gt;
            &lt;span class=&quot;o&quot;&gt;}&lt;/span&gt;
        &lt;span class=&quot;o&quot;&gt;}&lt;/span&gt;
    &lt;span class=&quot;o&quot;&gt;}&lt;/span&gt;

    &lt;span class=&quot;kd&quot;&gt;private&lt;/span&gt; &lt;span class=&quot;kt&quot;&gt;void&lt;/span&gt; &lt;span class=&quot;nf&quot;&gt;parseData&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;nc&quot;&gt;String&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;data&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;{&lt;/span&gt;
        &lt;span class=&quot;k&quot;&gt;if&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;data&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;!=&lt;/span&gt; &lt;span class=&quot;kc&quot;&gt;null&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;{&lt;/span&gt;
            &lt;span class=&quot;nc&quot;&gt;Matcher&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;m&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;k&quot;&gt;this&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;na&quot;&gt;mChannelPattern&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;na&quot;&gt;matcher&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;data&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;);&lt;/span&gt;
            &lt;span class=&quot;nc&quot;&gt;List&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;&amp;lt;&lt;/span&gt;&lt;span class=&quot;nc&quot;&gt;SlotStatus&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;&amp;gt;&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;list&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;k&quot;&gt;new&lt;/span&gt; &lt;span class=&quot;nc&quot;&gt;ArrayList&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;mi&quot;&gt;6&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;);&lt;/span&gt;

            &lt;span class=&quot;k&quot;&gt;while&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;m&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;na&quot;&gt;find&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;())&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;{&lt;/span&gt;
                &lt;span class=&quot;nc&quot;&gt;SlotStatus&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;cs&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;k&quot;&gt;new&lt;/span&gt; &lt;span class=&quot;nc&quot;&gt;SlotStatus&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;();&lt;/span&gt;
                &lt;span class=&quot;n&quot;&gt;cs&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;na&quot;&gt;setName&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;s&quot;&gt;&quot;Slot&quot;&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;+&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;m&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;na&quot;&gt;group&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;no&quot;&gt;REQUEST_ENABLE_BT&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;));&lt;/span&gt;
                &lt;span class=&quot;n&quot;&gt;cs&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;na&quot;&gt;setOrder&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;nc&quot;&gt;Integer&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;na&quot;&gt;parseInt&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;m&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;na&quot;&gt;group&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;no&quot;&gt;REQUEST_ENABLE_BT&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;)));&lt;/span&gt;
                &lt;span class=&quot;n&quot;&gt;cs&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;na&quot;&gt;setStatus&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;nc&quot;&gt;Integer&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;na&quot;&gt;parseInt&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;m&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;na&quot;&gt;group&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;mi&quot;&gt;2&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;)));&lt;/span&gt;
                &lt;span class=&quot;n&quot;&gt;cs&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;na&quot;&gt;setDianYe&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;m&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;na&quot;&gt;group&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;mi&quot;&gt;3&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;));&lt;/span&gt;
                &lt;span class=&quot;n&quot;&gt;cs&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;na&quot;&gt;setDianLiu&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;nc&quot;&gt;Integer&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;na&quot;&gt;parseInt&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;m&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;na&quot;&gt;group&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;mi&quot;&gt;4&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;)));&lt;/span&gt;
                &lt;span class=&quot;n&quot;&gt;cs&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;na&quot;&gt;setPercent&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;nc&quot;&gt;Integer&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;na&quot;&gt;parseInt&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;m&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;na&quot;&gt;group&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;mi&quot;&gt;5&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;)));&lt;/span&gt;
                &lt;span class=&quot;n&quot;&gt;list&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;na&quot;&gt;add&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;cs&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;);&lt;/span&gt;
            &lt;span class=&quot;o&quot;&gt;}&lt;/span&gt;
&lt;span class=&quot;o&quot;&gt;...&lt;/span&gt;
        &lt;span class=&quot;o&quot;&gt;}&lt;/span&gt;
    &lt;span class=&quot;o&quot;&gt;}&lt;/span&gt;
&lt;span class=&quot;o&quot;&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;Even better! Looks like data is handled either of two ways through
&lt;em&gt;handleData()&lt;/em&gt;, it either notifies the app that the device is turning off or
that it has an update which is then passed to &lt;em&gt;parseData()&lt;/em&gt; and updates the UI.
Now it does looks like it’s calling an internal Java class function
&lt;em&gt;encodeUtil&lt;/em&gt;. During my research I was unable to find any information on this
encoding scheme, but in the end we will just port this function to Go.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;encodeUtil.java&lt;/em&gt;&lt;/p&gt;
&lt;div class=&quot;language-java highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;&lt;span class=&quot;kn&quot;&gt;package&lt;/span&gt; &lt;span class=&quot;nn&quot;&gt;com.iwit.bluetoothcommunication.util&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;;&lt;/span&gt;

&lt;span class=&quot;o&quot;&gt;...&lt;/span&gt;
&lt;span class=&quot;kd&quot;&gt;public&lt;/span&gt; &lt;span class=&quot;kd&quot;&gt;class&lt;/span&gt; &lt;span class=&quot;nc&quot;&gt;encodeUtil&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;{&lt;/span&gt;
    &lt;span class=&quot;kd&quot;&gt;public&lt;/span&gt; &lt;span class=&quot;kd&quot;&gt;static&lt;/span&gt; &lt;span class=&quot;nc&quot;&gt;String&lt;/span&gt; &lt;span class=&quot;nf&quot;&gt;decodeMessage&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;kt&quot;&gt;byte&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;[]&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;reciverBytes&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;{&lt;/span&gt;
        &lt;span class=&quot;kt&quot;&gt;int&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;i&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;;&lt;/span&gt;
        &lt;span class=&quot;nc&quot;&gt;String&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;decodeData&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;nc&quot;&gt;BuildConfig&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;na&quot;&gt;FLAVOR&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;;&lt;/span&gt;

        &lt;span class=&quot;kt&quot;&gt;int&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;tou&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;reciverBytes&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;mi&quot;&gt;0&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;];&lt;/span&gt;
        &lt;span class=&quot;n&quot;&gt;reciverBytes&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;mi&quot;&gt;1&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;]&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;kt&quot;&gt;byte&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;((&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;reciverBytes&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;mi&quot;&gt;1&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;]&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;^&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;tou&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;-&lt;/span&gt; &lt;span class=&quot;mi&quot;&gt;1&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;);&lt;/span&gt;

        &lt;span class=&quot;kt&quot;&gt;int&lt;/span&gt; &lt;span class=&quot;nc&quot;&gt;Onum&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;tou&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;^&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;reciverBytes&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;mi&quot;&gt;2&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;];&lt;/span&gt;
        &lt;span class=&quot;n&quot;&gt;reciverBytes&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;mi&quot;&gt;2&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;]&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;kt&quot;&gt;byte&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;nc&quot;&gt;Onum&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;;&lt;/span&gt;

        &lt;span class=&quot;k&quot;&gt;for&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;i&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;mi&quot;&gt;3&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;;&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;i&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;&amp;lt;&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;reciverBytes&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;na&quot;&gt;length&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;;&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;i&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;++)&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;{&lt;/span&gt;
            &lt;span class=&quot;n&quot;&gt;reciverBytes&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;i&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;]&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;kt&quot;&gt;byte&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;reciverBytes&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;i&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;]&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;^&lt;/span&gt; &lt;span class=&quot;nc&quot;&gt;Onum&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;);&lt;/span&gt;
        &lt;span class=&quot;o&quot;&gt;}&lt;/span&gt;

        &lt;span class=&quot;k&quot;&gt;for&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;i&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;mi&quot;&gt;3&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;;&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;i&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;&amp;lt;&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;reciverBytes&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;na&quot;&gt;length&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;;&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;i&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;++)&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;{&lt;/span&gt;
            &lt;span class=&quot;kt&quot;&gt;int&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;num&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;reciverBytes&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;i&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;];&lt;/span&gt;
            &lt;span class=&quot;k&quot;&gt;if&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;num&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;&amp;lt;&lt;/span&gt; &lt;span class=&quot;mi&quot;&gt;0&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;{&lt;/span&gt;
                &lt;span class=&quot;n&quot;&gt;num&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;+=&lt;/span&gt; &lt;span class=&quot;nc&quot;&gt;AccessibilityNodeInfoCompat&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;na&quot;&gt;ACTION_NEXT_AT_MOVEMENT_GRANULARITY&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;;&lt;/span&gt; &lt;span class=&quot;c1&quot;&gt;// ACTION_NEXT_AT_MOVEMENT_GRANULARITY = 256&lt;/span&gt;
                &lt;span class=&quot;n&quot;&gt;reciverBytes&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;i&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;]&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;kt&quot;&gt;byte&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;num&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;;&lt;/span&gt;
            &lt;span class=&quot;o&quot;&gt;}&lt;/span&gt;

            &lt;span class=&quot;nc&quot;&gt;String&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;mm&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;nc&quot;&gt;Integer&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;na&quot;&gt;toHexString&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;num&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;);&lt;/span&gt;
            &lt;span class=&quot;k&quot;&gt;if&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;mm&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;na&quot;&gt;length&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;()&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;==&lt;/span&gt; &lt;span class=&quot;mi&quot;&gt;1&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;{&lt;/span&gt;
                &lt;span class=&quot;n&quot;&gt;mm&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;s&quot;&gt;&quot;0&quot;&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;+&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;mm&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;;&lt;/span&gt;
            &lt;span class=&quot;o&quot;&gt;}&lt;/span&gt;
            &lt;span class=&quot;n&quot;&gt;decodeData&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;k&quot;&gt;new&lt;/span&gt; &lt;span class=&quot;nc&quot;&gt;StringBuilder&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;nc&quot;&gt;String&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;na&quot;&gt;valueOf&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;decodeData&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;)).&lt;/span&gt;&lt;span class=&quot;na&quot;&gt;append&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;mm&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;).&lt;/span&gt;&lt;span class=&quot;na&quot;&gt;toString&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;();&lt;/span&gt;
        &lt;span class=&quot;o&quot;&gt;}&lt;/span&gt;

        &lt;span class=&quot;k&quot;&gt;return&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;decodeData&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;;&lt;/span&gt;
    &lt;span class=&quot;o&quot;&gt;}&lt;/span&gt;
&lt;span class=&quot;o&quot;&gt;..&lt;/span&gt;
&lt;span class=&quot;o&quot;&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;We can greatly simplify this function in Go while also rewriting the function to
output the string instead of the hex equivalent as does the original function.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;efest6bay.go&lt;/em&gt;&lt;/p&gt;
&lt;div class=&quot;language-go highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;&lt;span class=&quot;k&quot;&gt;func&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;decodeMessage&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;reciverBytes&lt;/span&gt; &lt;span class=&quot;p&quot;&gt;[]&lt;/span&gt;&lt;span class=&quot;kt&quot;&gt;byte&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;kt&quot;&gt;string&lt;/span&gt; &lt;span class=&quot;p&quot;&gt;{&lt;/span&gt;
    &lt;span class=&quot;k&quot;&gt;var&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;decodeData&lt;/span&gt; &lt;span class=&quot;kt&quot;&gt;string&lt;/span&gt;

    &lt;span class=&quot;k&quot;&gt;var&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;oNum&lt;/span&gt; &lt;span class=&quot;kt&quot;&gt;byte&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;reciverBytes&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;m&quot;&gt;0&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;]&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;^&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;reciverBytes&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;m&quot;&gt;2&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;]&lt;/span&gt;
    &lt;span class=&quot;k&quot;&gt;for&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;i&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;:=&lt;/span&gt; &lt;span class=&quot;m&quot;&gt;3&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;;&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;i&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;&amp;lt;&lt;/span&gt; &lt;span class=&quot;nb&quot;&gt;len&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;reciverBytes&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;);&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;i&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;++&lt;/span&gt; &lt;span class=&quot;p&quot;&gt;{&lt;/span&gt;
        &lt;span class=&quot;n&quot;&gt;decodeData&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;+=&lt;/span&gt; &lt;span class=&quot;kt&quot;&gt;string&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;reciverBytes&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;i&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;]&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;^&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;oNum&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;)&lt;/span&gt;
    &lt;span class=&quot;p&quot;&gt;}&lt;/span&gt;

    &lt;span class=&quot;k&quot;&gt;return&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;decodeData&lt;/span&gt;
&lt;span class=&quot;p&quot;&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;Now that we have the code ported to Go we can test decoding messages with output
from gattool. Jared Wolff has written a well written article on using gatttool
located
&lt;a href=&quot;http://www.jaredwolff.com/blog/get-started-with-bluetooth-low-energy/&quot;&gt;here&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;(The charger constantly sends updates without having to request data) With the
use of gattool and our decodeMessage() function we should be able to decode
something like this.&lt;/p&gt;

&lt;div class=&quot;language-plaintext highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;CH1:3,4.20V,0mA,100per,31,CH2:3,4.20V,0mA,100per,21,CH3:3,4.20V,0mA,100per,21,CH4:3,4.20V,0mA,100per,21,CH5:3,4.20V,0mA,100per,21,CH6:3,4.20V,0mA,100per,31
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;Fantastic, now let’s look at the encode function and do the same.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;encodeUtil.java&lt;/em&gt;&lt;/p&gt;
&lt;div class=&quot;language-java highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;&lt;span class=&quot;kd&quot;&gt;public&lt;/span&gt; &lt;span class=&quot;kd&quot;&gt;static&lt;/span&gt; &lt;span class=&quot;kt&quot;&gt;byte&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;[]&lt;/span&gt; &lt;span class=&quot;nf&quot;&gt;encodeMessage&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;kt&quot;&gt;byte&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;[]&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;bytes&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;{&lt;/span&gt;
    &lt;span class=&quot;kt&quot;&gt;byte&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;[]&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;encodeByte&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;k&quot;&gt;new&lt;/span&gt; &lt;span class=&quot;kt&quot;&gt;byte&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;[(&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;bytes&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;na&quot;&gt;length&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;+&lt;/span&gt; &lt;span class=&quot;mi&quot;&gt;3&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;)];&lt;/span&gt;

    &lt;span class=&quot;n&quot;&gt;encodeByte&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;mi&quot;&gt;0&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;]&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;kt&quot;&gt;byte&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;mi&quot;&gt;84&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;;&lt;/span&gt;
    &lt;span class=&quot;n&quot;&gt;encodeByte&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;mi&quot;&gt;1&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;]&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;kt&quot;&gt;byte&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;bytes&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;na&quot;&gt;length&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;;&lt;/span&gt;
    &lt;span class=&quot;n&quot;&gt;encodeByte&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;mi&quot;&gt;1&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;]&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;kt&quot;&gt;byte&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;encodeByte&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;mi&quot;&gt;0&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;]&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;^&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;encodeByte&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;mi&quot;&gt;1&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;]&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;+&lt;/span&gt; &lt;span class=&quot;mi&quot;&gt;1&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;));&lt;/span&gt;

    &lt;span class=&quot;kt&quot;&gt;int&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;num&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;kt&quot;&gt;int&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;nc&quot;&gt;Math&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;na&quot;&gt;random&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;()&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;*&lt;/span&gt; &lt;span class=&quot;mf&quot;&gt;10.0d&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;);&lt;/span&gt;
    &lt;span class=&quot;n&quot;&gt;encodeByte&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;mi&quot;&gt;2&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;]&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;kt&quot;&gt;byte&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;encodeByte&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;mi&quot;&gt;0&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;]&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;^&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;num&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;);&lt;/span&gt;

    &lt;span class=&quot;k&quot;&gt;for&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;kt&quot;&gt;int&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;i&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;mi&quot;&gt;0&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;;&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;i&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;&amp;lt;&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;bytes&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;na&quot;&gt;length&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;;&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;i&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;++)&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;{&lt;/span&gt;
        &lt;span class=&quot;n&quot;&gt;encodeByte&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;i&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;+&lt;/span&gt; &lt;span class=&quot;mi&quot;&gt;3&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;]&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;kt&quot;&gt;byte&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;bytes&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;i&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;]&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;^&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;num&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;);&lt;/span&gt;
    &lt;span class=&quot;o&quot;&gt;}&lt;/span&gt;

    &lt;span class=&quot;k&quot;&gt;for&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;kt&quot;&gt;byte&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;b&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;:&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;encodeByte&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;{&lt;/span&gt;

    &lt;span class=&quot;o&quot;&gt;}&lt;/span&gt;

    &lt;span class=&quot;k&quot;&gt;return&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;encodeByte&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;;&lt;/span&gt;
&lt;span class=&quot;o&quot;&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;&lt;em&gt;efest6bay.go&lt;/em&gt;&lt;/p&gt;

&lt;div class=&quot;language-go highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;&lt;span class=&quot;k&quot;&gt;func&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;encodeMessage&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;bytes&lt;/span&gt; &lt;span class=&quot;p&quot;&gt;[]&lt;/span&gt;&lt;span class=&quot;kt&quot;&gt;byte&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;p&quot;&gt;[]&lt;/span&gt;&lt;span class=&quot;kt&quot;&gt;byte&lt;/span&gt; &lt;span class=&quot;p&quot;&gt;{&lt;/span&gt;
    &lt;span class=&quot;n&quot;&gt;encodeByte&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;:=&lt;/span&gt; &lt;span class=&quot;nb&quot;&gt;make&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;([]&lt;/span&gt;&lt;span class=&quot;kt&quot;&gt;byte&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;nb&quot;&gt;len&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;bytes&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;+&lt;/span&gt; &lt;span class=&quot;m&quot;&gt;3&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;)&lt;/span&gt;
    &lt;span class=&quot;n&quot;&gt;encodeByte&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;m&quot;&gt;0&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;]&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;m&quot;&gt;84&lt;/span&gt;

    &lt;span class=&quot;n&quot;&gt;encodeByte&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;m&quot;&gt;1&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;]&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;encodeByte&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;m&quot;&gt;0&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;]&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;^&lt;/span&gt; &lt;span class=&quot;kt&quot;&gt;byte&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;nb&quot;&gt;len&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;bytes&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;+&lt;/span&gt; &lt;span class=&quot;m&quot;&gt;1&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;)&lt;/span&gt;
    &lt;span class=&quot;n&quot;&gt;num&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;:=&lt;/span&gt; &lt;span class=&quot;kt&quot;&gt;byte&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;rand&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;Int&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;())&lt;/span&gt;

    &lt;span class=&quot;n&quot;&gt;encodeByte&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;m&quot;&gt;2&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;]&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;encodeByte&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;m&quot;&gt;0&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;]&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;^&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;num&lt;/span&gt;
    &lt;span class=&quot;k&quot;&gt;for&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;i&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;:=&lt;/span&gt; &lt;span class=&quot;m&quot;&gt;0&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;;&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;i&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;&amp;lt;&lt;/span&gt; &lt;span class=&quot;nb&quot;&gt;len&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;bytes&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;);&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;i&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;++&lt;/span&gt; &lt;span class=&quot;p&quot;&gt;{&lt;/span&gt;

        &lt;span class=&quot;n&quot;&gt;encodeByte&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;i&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;+&lt;/span&gt; &lt;span class=&quot;m&quot;&gt;3&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;]&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;bytes&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;[&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;i&lt;/span&gt;&lt;span class=&quot;p&quot;&gt;]&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;^&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;num&lt;/span&gt;

    &lt;span class=&quot;p&quot;&gt;}&lt;/span&gt;

    &lt;span class=&quot;k&quot;&gt;return&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;encodeByte&lt;/span&gt;
&lt;span class=&quot;p&quot;&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;And there we go! Now we can decode and encode messages to the device. Now
there’s two functions left that I haven’t coded in Go yet, the setCurrent() and
queryChart(). For these implementations feel free to check the project on my
&lt;a href=&quot;https://github.com/LoveMHz/Efest6bay&quot;&gt;GitHub&lt;/a&gt;!&lt;/p&gt;

&lt;div class=&quot;language-java highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;&lt;span class=&quot;kd&quot;&gt;private&lt;/span&gt; &lt;span class=&quot;kt&quot;&gt;void&lt;/span&gt; &lt;span class=&quot;nf&quot;&gt;setCurrent&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;kt&quot;&gt;int&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;order&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;,&lt;/span&gt; &lt;span class=&quot;kt&quot;&gt;int&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;value&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;{&lt;/span&gt;
    &lt;span class=&quot;nc&quot;&gt;SampleGattAttributes&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;na&quot;&gt;sendMessage&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;getAppContext&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;().&lt;/span&gt;&lt;span class=&quot;na&quot;&gt;getBluetoothService&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;().&lt;/span&gt;&lt;span class=&quot;na&quot;&gt;getBluetoothGatt&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;(),&lt;/span&gt; &lt;span class=&quot;nc&quot;&gt;StringUtil&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;na&quot;&gt;str2HexStr&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;s&quot;&gt;&quot;AT+CRT&quot;&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;+&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;order&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;+&lt;/span&gt; &lt;span class=&quot;nc&quot;&gt;BuildConfig&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;na&quot;&gt;FLAVOR&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;+&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;value&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;+&lt;/span&gt; &lt;span class=&quot;s&quot;&gt;&quot;\r\n&quot;&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;));&lt;/span&gt;
&lt;span class=&quot;o&quot;&gt;...&lt;/span&gt;
&lt;span class=&quot;o&quot;&gt;}&lt;/span&gt;

&lt;span class=&quot;kd&quot;&gt;private&lt;/span&gt; &lt;span class=&quot;kt&quot;&gt;void&lt;/span&gt; &lt;span class=&quot;nf&quot;&gt;queryChart&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;kt&quot;&gt;int&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;channel&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;)&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;{&lt;/span&gt;
    &lt;span class=&quot;nc&quot;&gt;SampleGattAttributes&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;na&quot;&gt;sendMessage&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;n&quot;&gt;getAppContext&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;().&lt;/span&gt;&lt;span class=&quot;na&quot;&gt;getBluetoothService&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;().&lt;/span&gt;&lt;span class=&quot;na&quot;&gt;getBluetoothGatt&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;(),&lt;/span&gt; &lt;span class=&quot;nc&quot;&gt;StringUtil&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;na&quot;&gt;str2HexStr&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;(&lt;/span&gt;&lt;span class=&quot;s&quot;&gt;&quot;AT+CH&quot;&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;+&lt;/span&gt; &lt;span class=&quot;n&quot;&gt;channel&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;+&lt;/span&gt; &lt;span class=&quot;s&quot;&gt;&quot;+chart\r\n&quot;&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;));&lt;/span&gt;
    &lt;span class=&quot;k&quot;&gt;this&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;na&quot;&gt;notifyString&lt;/span&gt; &lt;span class=&quot;o&quot;&gt;=&lt;/span&gt; &lt;span class=&quot;nc&quot;&gt;BuildConfig&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;.&lt;/span&gt;&lt;span class=&quot;na&quot;&gt;FLAVOR&lt;/span&gt;&lt;span class=&quot;o&quot;&gt;;&lt;/span&gt;
&lt;span class=&quot;o&quot;&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;
&lt;hr /&gt;

&lt;p&gt;That pretty much concludes the bases of reverse engineering this charger. Over
the new couple of weeks I will be uploading my Go interface library to
&lt;a href=&quot;https://github.com/LoveMHz/Efest6bay&quot;&gt;GitHub&lt;/a&gt;. If anything interesting comes
out of fuzzing commands to the device I’ll make a new post with all the details!&lt;/p&gt;
</description>
        <pubDate>Sat, 30 Jan 2016 02:45:18 +0000</pubDate>
        <link>https://lovemhz.com/blog/reverse-engineering-a-bluetooth-enabled-battery-charger/</link>
        <guid isPermaLink="true">https://lovemhz.com/blog/reverse-engineering-a-bluetooth-enabled-battery-charger/</guid>
        
        
        <category>Blog</category>
        
      </item>
    
      <item>
        <title>Blog: XBENext</title>
        <description>&lt;p&gt;&lt;img src=&quot;/assets/img/blog/xbenext/preview_gui.png&quot; alt=&quot;XBENext&quot; /&gt;&lt;/p&gt;
</description>
        <pubDate>Tue, 14 Jan 2014 20:13:41 +0000</pubDate>
        <link>https://lovemhz.com/blog/xbenext/</link>
        <guid isPermaLink="true">https://lovemhz.com/blog/xbenext/</guid>
        
        
        <category>Blog</category>
        
      </item>
    
      <item>
        <title>Blog: &lt;3 Kinect</title>
        <description>&lt;p&gt;&lt;img src=&quot;/assets/img/blog/kinect/image1.png&quot; alt=&quot;Kinect Capture 1&quot; /&gt;
&lt;img src=&quot;/assets/img/blog/kinect/image2.png&quot; alt=&quot;Kinect Capture 2&quot; /&gt;
&lt;img src=&quot;/assets/img/blog/kinect/image3.png&quot; alt=&quot;Kinect Capture 3&quot; /&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Unfortunately, it seems that the original images have been lost during recovery
of the site.&lt;/em&gt;&lt;/p&gt;
</description>
        <pubDate>Sun, 21 Aug 2011 03:14:54 +0000</pubDate>
        <link>https://lovemhz.com/blog/kinect/</link>
        <guid isPermaLink="true">https://lovemhz.com/blog/kinect/</guid>
        
        
        <category>Blog</category>
        
      </item>
    
      <item>
        <title>Blog: Super Mario Wars 3D Anaglyph Rendering Test</title>
        <description>&lt;div class=&quot;embed-container&quot;&gt;
  &lt;iframe src=&quot;https://www.youtube.com/embed/B2l4QWCspOw&quot; frameborder=&quot;0&quot; allowfullscreen=&quot;&quot;&gt;&lt;/iframe&gt;
&lt;/div&gt;
</description>
        <pubDate>Thu, 18 Nov 2010 13:19:27 +0000</pubDate>
        <link>https://lovemhz.com/blog/super-mario-wars-3d-anaglyph-rendering-test/</link>
        <guid isPermaLink="true">https://lovemhz.com/blog/super-mario-wars-3d-anaglyph-rendering-test/</guid>
        
        
        <category>Blog</category>
        
      </item>
    
      <item>
        <title>Blog: [Release] Super Mario Wars 1.8 Beta 2 Port</title>
        <description>&lt;p&gt;&lt;em&gt;What’s this? Another release from LoveMHz?..&lt;/em&gt; Yeah well you know I couldn’t
stay gone forever now.. So yeah, this a newer port of the fantastic game Super
Mario Wars 1.8 Beta 2. Nothing much to say about besides it’s an amazing game.&lt;/p&gt;

&lt;p&gt;New Features: &lt;a href=&quot;http://72dpiarmy.supersanctuary.net/viewtopic.php?f=1&amp;amp;t=10241&quot;&gt;http://72dpiarmy.supersanctuary.net/viewtopic.php?f=1&amp;amp;t=1024&lt;/a&gt;&lt;/p&gt;
</description>
        <pubDate>Fri, 12 Nov 2010 10:05:15 +0000</pubDate>
        <link>https://lovemhz.com/blog/release-super-mario-wars-1-8-beta-2-port/</link>
        <guid isPermaLink="true">https://lovemhz.com/blog/release-super-mario-wars-1-8-beta-2-port/</guid>
        
        
        <category>Blog</category>
        
      </item>
    
  </channel>
</rss>
