Page 10 of 12 FirstFirst 123456789101112 LastLast
Results 181 to 200 of 225

Thread: Hacking the Tait 9100 series mobiles

  1. #181
    Premium Member AntNZ's Avatar
    Join Date
    Mar 2015
    Posts
    41
    Thanks
    23
    Thanked 31 Times in 12 Posts
    Rep Power
    58
    Reputation
    1114

    Default

    Quote Originally Posted by AntNZ View Post
    Indeed... but I assume Tait will be catering to their target audience by default. At least there is a work around!

    A



  • #182
    Junior Member
    Join Date
    Jan 2010
    Posts
    38
    Thanks
    8
    Thanked 71 Times in 24 Posts
    Rep Power
    127
    Reputation
    1430

    Default

    Quote Originally Posted by Tait TM9155 View Post
    Just also of note, seeing we are on the subject of TM8200 SFE keys. The latest TM8200 firmware (version 6.2) writes the SFE key 'TPAS083 20/25kHz Unrestricted Wideband' into your radio. Meaning that if you upgrade your radio to firmware 6.2, you will not be able to program in 25 kHz channels into your radio. However, you can reverse your radio back to firmware 6.1 and it will remove this SFE key.

    The SFE key 'TPAS083 20/25kHz Unrestricted Wideband' is available free of charge from Tait dealers outside of the USA. I personally have had success getting this SFE key from a dealer in NZ, with no questions asked. Just don't be fooled into paying for it.
    Jut curious, but how available do Tait make their programming cable and software? Is it dealer only or will they sell it to "any legitimate customer" as I've read elsewhere?

  • #183
    Premium Member
    Join Date
    Apr 2014
    Posts
    93
    Thanks
    52
    Thanked 24 Times in 15 Posts
    Rep Power
    58
    Reputation
    490

    Default

    Last time I used Tait (10 Years ago?), they used to put their software on their website, free for anyone to download.. hah.

  • #184
    Junior Member
    Join Date
    Nov 2009
    Posts
    61
    Thanks
    6
    Thanked 19 Times in 12 Posts
    Rep Power
    108
    Reputation
    315

    Default

    If you want testing on the QT app, I run Fedora + KDE at home - so I can easily test it for you....

  • #185
    Premium Member AntNZ's Avatar
    Join Date
    Mar 2015
    Posts
    41
    Thanks
    23
    Thanked 31 Times in 12 Posts
    Rep Power
    58
    Reputation
    1114

    Default

    Quote Originally Posted by CRCinAU View Post
    If you want testing on the QT app, I run Fedora + KDE at home - so I can easily test it for you....
    Will upload the qt app later today... it loaded all the keys in a 8200 during testing. It has a load all button to make life simple... so put firmware in via tait rss, run app, load all keys, reload firmware vis tait rss

  • #186
    Junior Member
    Join Date
    Aug 2014
    Posts
    97
    Thanks
    90
    Thanked 32 Times in 21 Posts
    Rep Power
    59
    Reputation
    748

    Default

    programming cables are easily enough to source from dealers. but not CPS or firmware though lol

  • #187
    Premium Member AntNZ's Avatar
    Join Date
    Mar 2015
    Posts
    41
    Thanks
    23
    Thanked 31 Times in 12 Posts
    Rep Power
    58
    Reputation
    1114

    Default

    Quote Originally Posted by diablo47 View Post
    programming cables are easily enough to source from dealers. but not CPS or firmware though lol

  • #188
    Premium Member Tait TM9155's Avatar
    Join Date
    Jun 2013
    Posts
    53
    Thanks
    52
    Thanked 40 Times in 24 Posts
    Rep Power
    73
    Reputation
    810

    Default

    From my experience, Tait dealers will sell you programming hardware, but you do get the odd dealer that won't supply anything programming related. They will not sell or provide the software however.

  • #189
    Junior Member
    Join Date
    Jan 2010
    Posts
    38
    Thanks
    8
    Thanked 71 Times in 24 Posts
    Rep Power
    127
    Reputation
    1430

    Default

    Quote Originally Posted by Tait TM9155 View Post
    From my experience, Tait dealers will sell you programming hardware, but you do get the odd dealer that won't supply anything programming related. They will not sell or provide the software however.
    Understandable - the programming cable is used to access the data interface which can be done via the mic port if programmed that way so some customers will have a valid use for the cable.

  • #190
    Junior Member
    Join Date
    Jan 2018
    Posts
    12
    Thanks
    0
    Thanked 6 Times in 4 Posts
    Rep Power
    0
    Reputation
    130

    Default

    Quote Originally Posted by mnix View Post
    Understandable - the programming cable is used to access the data interface which can be done via the mic port if programmed that way so some customers will have a valid use for the cable.
    They seem to prefer people use the data cable at the back, rather than the mic port. I'm not sure on the hardware but the software isn't meant to be given out to anyone but dealers, it's part of the agreement with Logic when you get a Support account with them to gain access to the portal. Motorola are the same (at least with the TRBO stuff, the other stuffs pretty old, they probably don't care too much anymore)

    Wideband shouldn't be used on PRS anymore as naturally it will bleed into the adjacent channels (when they went from 40 to 80), SCADA is the only thing I can think of (in NZ) that is allowed wideband. Maybe marine too? As previously mentioned by AntNZ in his URL there are still licenses capable of running wideband channels, however all licenses issued since about 2011 are narrowband (but wideband radios are allowed to use.) Noone has made a wideband only radio in 10 years or more, really there's no excuse to still be running one.
    Last edited by Z-master; 13-01-18 at 01:26 PM.

  • #191
    Premium Member AntNZ's Avatar
    Join Date
    Mar 2015
    Posts
    41
    Thanks
    23
    Thanked 31 Times in 12 Posts
    Rep Power
    58
    Reputation
    1114

    Default

    Version 1


    What I have discovered is that it will enable keys - but not disable them. So I assume the disable code is different to the enable code, so need to dig through mnix's posts again.
    A

  • The Following User Says Thank You to AntNZ For This Useful Post:

    technoweenie (13-01-18)

  • #192
    Premium Member AntNZ's Avatar
    Join Date
    Mar 2015
    Posts
    41
    Thanks
    23
    Thanked 31 Times in 12 Posts
    Rep Power
    58
    Reputation
    1114

    Default

    Quote Originally Posted by AntNZ View Post
    Version 1


    What I have discovered is that it will enable keys - but not disable them. So I assume the disable code is different to the enable code, so need to dig through mnix's posts again.
    A
    When you compile it locally remove/comment out the DefaultTEA key entry in the taitGenerateSFE function otherwise it will not read for your body.

  • #193
    Premium Member
    Join Date
    May 2012
    Posts
    58
    Thanks
    23
    Thanked 13 Times in 8 Posts
    Rep Power
    76
    Reputation
    260

    Default

    Thanks AntNZ for compiling this GUI program for the Tait Tm8200 SFE keys. Excuse my ignorance, I'm a little retarded with QT, code and the likes. I know a bit about RF system engineering and captured on to a bit of perl adaption when CRCinAU first released this information but struggle with code and the likes. In a nutshell, and for the slower of us including myself, what's the best way to use what you have provided? I have QT installed but have never put it to use. A simple readme notepad file or likes of myself would help lots. Many thanks and keep up the awesome work!

  • The Following User Says Thank You to p1350m For This Useful Post:

    diablo47 (13-01-18)

  • #194
    Junior Member
    Join Date
    Nov 2009
    Posts
    61
    Thanks
    6
    Thanked 19 Times in 12 Posts
    Rep Power
    108
    Reputation
    315

    Default

    Good news is that it builds ok on Fedora 27... I commented out the DefaultTEA in mainwindow.cpp and rebuilt it - now I'm trying to remember how the hell to program these things - and more importantly - where the lead I made up lives these days lol

    EDIT: Damn, I found my lead, hooked up to a TM9154 (I think?) VHF unit - and it worked first go. Nice.
    Last edited by CRCinAU; 13-01-18 at 06:00 PM.

  • #195
    Premium Member AntNZ's Avatar
    Join Date
    Mar 2015
    Posts
    41
    Thanks
    23
    Thanked 31 Times in 12 Posts
    Rep Power
    58
    Reputation
    1114

    Default

    Quote Originally Posted by CRCinAU View Post
    Good news is that it builds ok on Fedora 27... I commented out the DefaultTEA in mainwindow.cpp and rebuilt it - now I'm trying to remember how the hell to program these things - and more importantly - where the lead I made up lives these days lol
    I am also a Fedora27 person.... being Qt you can run it on any platform using Qt.... I have run it successfully in QtCreator on WIN32 as well, just haven't made a compiled stand alone .exe that will work there (that is more tricky).
    To others: fire up QtCreator, open the project .pro file, then away you go - either to make a binary for your system (excl win32 at the moment) or just run it from within QtCreator (which will work for Win32)

    A

  • #196
    Junior Member
    Join Date
    Nov 2009
    Posts
    61
    Thanks
    6
    Thanked 19 Times in 12 Posts
    Rep Power
    108
    Reputation
    315

    Default

    I found something strange... the software reports an SFE key for TMAS018 - which is TDMA support - but I thought the TM9155 or similar didn't support TDMA?

  • #197
    Premium Member AntNZ's Avatar
    Join Date
    Mar 2015
    Posts
    41
    Thanks
    23
    Thanked 31 Times in 12 Posts
    Rep Power
    58
    Reputation
    1114

    Default

    Quote Originally Posted by CRCinAU View Post
    I found something strange... the software reports an SFE key for TMAS018 - which is TDMA support - but I thought the TM9155 or similar didn't support TDMA?
    Unsure - I have taken the list of all features and tested against all of them for all models to see what pops / radio has keys for. My 8200's do not support Wideband so the test in Inspect returns 01FF (Feature not support)

  • #198
    Junior Member
    Join Date
    Nov 2009
    Posts
    61
    Thanks
    6
    Thanked 19 Times in 12 Posts
    Rep Power
    108
    Reputation
    315

    Default

    Interesting. So the TM9155 certainly doesn't return a not supported then - as we get an actual key out....

    EDIT: I'm reading through the code - and it seems mostly sane - which is good. I think I could see why the perl code I wrote for the checksum didn't work when translated - perl does lots of magic with map and then pack / unpack - which would be difficult to implement in other languages... What you've got works, so eh....

    Also looks like you still need the custom firmware to return the TEA1 / TEA2 values. It would be nice to see them extracted cleanly... I wonder if there is a method for doing this - or if that is purely Tait's secret-sauce to control the keys - which wouldn't surprise me...

    I'm quite impressed all up - this is some good work
    Last edited by CRCinAU; 13-01-18 at 06:26 PM.

  • #199
    Premium Member AntNZ's Avatar
    Join Date
    Mar 2015
    Posts
    41
    Thanks
    23
    Thanked 31 Times in 12 Posts
    Rep Power
    58
    Reputation
    1114

    Default

    Quote Originally Posted by CRCinAU View Post
    Also looks like you still need the custom firmware to return the TEA1 / TEA2 values. It would be nice to see them extracted cleanly... I wonder if there is a method for doing this - or if that is purely Tait's secret-sauce to control the keys - which wouldn't surprise me...
    I am not much for assembly but am slowly learning a little bit.....
    In the meantime mnix, who has been very patient with my many stoopid questions, tells me that the code pulls SEED2 from a preloaded ROM variable -> which infers it is loaded during flash programming and thus can only be pulled via firmware hack. My hope is that SEED2 two is actually derived - or before loading is based on data we can otherwise pull via standard commands and thus derive, but working on that puzzle has taken second place to getting a nice GUI up and going. My priority at the moment is getting disable to work so a user can disable keys selectively in their radio (which would be handy for the wideband issue).

  • The Following User Says Thank You to AntNZ For This Useful Post:

    CRCinAU (13-01-18)

  • #200
    Junior Member
    Join Date
    Jan 2010
    Posts
    38
    Thanks
    8
    Thanked 71 Times in 24 Posts
    Rep Power
    127
    Reputation
    1430

    Default

    Quote Originally Posted by CRCinAU View Post
    Also looks like you still need the custom firmware to return the TEA1 / TEA2 values. It would be nice to see them extracted cleanly... I wonder if there is a method for doing this - or if that is purely Tait's secret-sauce to control the keys - which wouldn't surprise me...
    They must have a way of setting it after manufacture, but if they have any sense they wouldn't have a way of getting it back out...
    Then again, they didn't do anything to prevent putting custom firmware in so who knows...

  • Page 10 of 12 FirstFirst 123456789101112 LastLast

    Bookmarks

    Posting Permissions

    • You may not post new threads
    • You may not post replies
    • You may not post attachments
    • You may not edit your posts
    •