frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

A Copy-Paste Bug That Broke PSpice AES-256 Encryption

https://jtsylve.blog/post/2026/03/18/PSpice-Encryption-Weakness
2•jtsylve•1h ago

Comments

jtsylve•1h ago
I posted SpiceCrypt (https://github.com/jtsylve/spice-crypt) a few days ago for decrypting LTspice models. It now supports all six PSpice encryption modes as well.

PSpice is Cadence's SPICE simulator. Vendors encrypt component models with it, which locks them to PSpice and prevents use in NGSpice, Xyce, etc. Modes 0-3 and 5 derive keys entirely from constants in the binary, so those are straightforward once you extract them.

Mode 4 is the interesting one. It's the only mode with user-supplied key material and uses AES-256 in ECB mode. The key derivation has two base keys: a 4-byte short key (originally for DES) and a 27-byte extended key (intended for AES). The code passes only the short key to the AES engine -- it looks like a copy-paste from the DES path that was never corrected. The short key gets null-terminated and zero-padded to 32 bytes, so 28 of 32 AES key bytes are known. Effective keyspace is 2^32, brute-forceable in seconds with AES-NI.

The first encrypted block after every marker is a metadata header with a known plaintext prefix, which gives you a crib for validation. Once you recover the 4-byte short key, the full user key is also recoverable from the decrypted header.

This has likely been shipping since PSpice 16.6 in 2014. Fixing it would break every encrypted model created in the last twelve years.

The blog post linked above walks through the full details. The repo also has specifications documenting all the encryption schemes: https://github.com/jtsylve/spice-crypt/tree/v2.0.1/SPECIFICA...

The 3-Point Takeover

https://sheets.works/data-viz/every-shot-mapped
1•jonbaer•24s ago•0 comments

Sycophantic AI Decreases Prosocial Intentions and Promotes Dependence

https://arxiv.org/abs/2510.01395
2•RickJWagner•1m ago•0 comments

Is This Metabolic Molecule from Pythons the Next Big Weight-Loss Drug?

https://nautil.us/is-this-metabolic-molecule-from-pythons-the-next-big-weight-loss-drug-1279047
1•Brajeshwar•2m ago•0 comments

Crypto and AI industries tested their influence in IL. It didn't go that well

https://apnews.com/article/crypto-ai-spending-illinois-election-influence-1dd012c903fe5092c4133b9...
1•1vuio0pswjnm7•2m ago•0 comments

ARDC Is Hiring: Technical Writer

https://www.ardc.net/ardc-is-hiring-technical-writer/
1•ARDC_73•3m ago•0 comments

Show HN: Reverse Image Search on the National Gallery of Art Archive

https://nga.mxp.co/
1•Beefin•3m ago•0 comments

Front end and back end are optimizing for different things

https://derrickburns720047.substack.com/p/your-frontend-and-backend-are-optimizing
1•derrickrburns•4m ago•1 comments

Launch HN: Canary (YC W26) – AI QA that understands your code

2•Visweshyc•5m ago•0 comments

Western Europe, state formation, and genetic pacification

https://pubmed.ncbi.nlm.nih.gov/25748943/
1•CGMthrowaway•5m ago•0 comments

Show HN: LLM-Visualized – Interactive 3D and 2D Visualization of GPT-2

https://www.llm-visualized.com/
1•saahithj•7m ago•0 comments

Show HN: Three new Kitten TTS models – smallest less than 25MB

https://github.com/KittenML/KittenTTS
2•rohan_joshi•10m ago•0 comments

Show HN: Patchcord, a Messenger for AI Agents

https://patchcord.dev
1•pravdin•10m ago•0 comments

AI infrastructure has a networking problem, zero-trust overlays can help

https://www.defined.net/blog/ai-networking-zero-trust/
1•bgolat•12m ago•0 comments

How Invisalign Became the World's Biggest User of 3D Printers

https://www.wired.com/story/how-invisalign-became-the-worlds-biggest-3d-printing-company/
1•bookofjoe•12m ago•1 comments

LOLBins-Reference

https://livingofftheland.dev/
1•Ilias1988•13m ago•0 comments

Introducing the Apache Airflow Registry

https://airflow.apache.org/blog/airflow-registry/
1•jonbaer•13m ago•0 comments

Reflections after 1 year at Anthropic

https://threadreaderapp.com/thread/2024567162216865922.html
1•gmays•14m ago•0 comments

Prompt Injecting Contributing.md

https://glama.ai/blog/2026-03-19-open-source-has-a-bot-problem
2•statements•14m ago•0 comments

GM 'Factor of Future' Will Run with Robots (1984)

https://www.nytimes.com/1984/10/20/business/gm-factory-of-future-will-run-with-robots.html
1•mattas•15m ago•0 comments

Ask HN: Is WhatsApp's group voice chat gesture bad UX?

1•fvv•16m ago•0 comments

Biennial Bingo

https://biennialbingo.com
2•gardenboy•17m ago•0 comments

35mm analog camera on a drone [video]

https://www.youtube.com/watch?v=UEtYXA88X9w
2•ostacke•17m ago•0 comments

Watch NASA roll out Artemis 2 moon rocket tonight ahead of April 1 launch

https://www.space.com/space-exploration/artemis/watch-nasa-roll-out-artemis-2-moon-rocket-tonight...
1•Brajeshwar•18m ago•0 comments

LHCb Collaboration discovers new proton-like particle

https://home.cern/news/news/physics/lhcb-collaboration-discovers-new-proton-particle
1•gmays•18m ago•0 comments

Show HN: Dyslexia-oriented TTS reader for Chrome

https://hoverspeak.com/
1•yaronl_elh•20m ago•0 comments

Evolving software using agents and scoring metrics

https://robc.substack.com/p/welcome-to-the-darwin-derby
1•lukewilson02•21m ago•0 comments

Population doomster Paul Ehrlich has died

https://reason.com/2026/03/16/population-doomster-and-false-prophet-of-ecological-apocalypse-paul...
2•speckx•22m ago•0 comments

Reinventing Python's AsyncIO

https://blog.baro.dev/p/reinventing-pythons-asyncio
1•tmarice•23m ago•0 comments

Oil and gas prices jump after Iran and Israel attack gasfields

https://www.theguardian.com/business/2026/mar/19/oil-prices-gas-prices-rise-iran-israel-donald-trump
17•teleforce•23m ago•3 comments

Cryptid Quarterly VIII (2025): Top List of Cryptid Horror Fiction

https://lionelraygreen.com/2026/03/04/cryptid-quarterly-viii-2025-top-10-list-of-cryptid-horror-f...
1•keepamovin•23m ago•0 comments