======================================================================== MAKE / BREAK issue #06 BOOT YOUR OWN OS MAKE - 27 Oct 2026 - by the Norfolk Hacker ======================================================================== This week's security in plain English, a two-minute check on what your phone's apps can reach, and the project: boot a tiny operating system I built, then bring the plasma from #00 back to life as one of its apps. colour edition: https://makebreak.co.uk/issues/06.html Two BREAK issues on the bounce, so we're owed a proper MAKE. And this one's a bit personal: for the last few weeks I've been building an operating system. A small one -- desktop, windows, a terminal, a tracker, a handful of games -- called acid OS. Today you boot it, write an app for it, and then crash that app on purpose to see why the rest of the system doesn't care. It's free, it's open source, and you don't need to flash anything. ------------------------------------------------------------------------ [ 1. THIS WEEK IN SECURITY ] Three quick ones -- and a theme you'll spot again in the project: keep things in separate boxes. * A robot broke into a security charity -- on its own. On 21 September an autonomous AI agent, with no human driving it, chained two unknown bugs in Zammad (a popular open-source helpdesk) and got root on a server at DIVD, the Dutch volunteer group that literally warns people about vulnerabilities. DIVD called it "loud and very, very messy" -- it even tripped over its own password-spraying. What stopped it going further wasn't cleverness: their network was split into compartments. -> do this: if you run anything at home that faces the internet -- a NAS, a Plex box, a little server -- switch on its automatic updates, and put it on its own network (your router's "guest" Wi-Fi will do). One break-in, one room. (source) [1] * Police took down a ransomware gang allegedly run by a 16-year-old. Operation KillSwitch, on 30 September, seized KillSec's servers and leak site -- and at least 110 terabytes of stolen data -- after around 1,000 attacks. Searches took place in four countries, the UK among them. -> do this: the thing that makes ransomware toothless is a backup the attacker can't reach. Copy the photos and documents you'd cry over to an external drive this weekend, then unplug it. (source) [2] * Chrome patched a bug that attackers were already using. CVE-2026-85046, a flaw in Chrome's JavaScript engine, let a booby-trapped web page run code on your machine -- and Google confirmed it was being exploited in the wild. Fixed in Chrome 152. -> do this: in Chrome go to ⋮ -> Help -> About Google Chrome. If it says "Relaunch", the fix is sitting there doing nothing until you click it. (source) [3] ------------------------------------------------------------------------ [ 2. BEGINNER'S CORNER ] Today's project is all about apps that live in their own little box. Your phone already works that way -- the trick is checking what each box is allowed to reach. * Do a two-minute permissions audit. On an iPhone open Settings -> Privacy & Security; on Android, search Settings for Permission manager. Tap Location, then Microphone, then Camera. Anything that doesn't obviously need it -- a torch app with your location, a game with your microphone -- set it to Never or Ask every time. An app can't leak what it was never given. ------------------------------------------------------------------------ [ 3. THE PROJECT ] BOOT YOUR OWN OS acid OS runs in a window on your Linux desktop, so nothing gets installed over anything. You'll boot it, give it a new app, then break that app and watch the OS shrug. What you'll need: a Linux machine with a desktop (X11 or Wayland -- any distro), about ten minutes for the first build, and a willingness to type cargo. ↗ acid OS on GitHub [4] Prefer to grab the finished app? plasma.lua [5] and plasma.app.toml [6] -- drop both into v3/apps/. >> 01. Boot it Install the build tools (Debian/Ubuntu shown -- the Fedora and Arch lines are in the repo's README): sudo apt install build-essential pkg-config libasound2-dev git curl curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh source "$HOME/.cargo/env" Then grab it and run it: git clone https://github.com/NorfolkHacker/Acid-OS-V3.git cd Acid-OS-V3 cargo run --release --manifest-path v3/Cargo.toml -p acid-os The first build takes a few minutes; after that it boots in seconds. Pick a screen size (or just wait three seconds) and you're on the desktop. Have a poke: Menu is top left, and the File Manager -> Games folder has AcidStorm, Acid Invaders and a Tetris that will eat your evening. Stay in the top folder of the repo when you run it -- acid OS finds its apps by a path relative to it. >> 02. Bring the plasma back Remember the plasma from issue #00 [7] -- four sine waves stacked into something that looks alive? We're giving it a home. An acid OS app is just two files in v3/apps/: a Lua script, and a tiny "manifest" saying what it's called and how big its window is. v3/apps/plasma.app.toml name = Plasma w = 240 h = 176 desc = Issue #00's plasma, now an app v3/apps/plasma.lua local Plasma = AcidGame:extend("Plasma") Plasma.TICK_MS = 40 -- 25 frames a second local CELL = 4 -- each "pixel" is a 4x4 block local TOP = 16 -- the title bar is 16px tall function Plasma:on_create() self.w, self.h = acid_window_size() self.cx, self.cy = self.w // 2, self.h // 2 -- where the ripple starts self.t = 0 end function Plasma:on_touch(x, y, pressed) if pressed then self.cx, self.cy = x, y end -- drag the ripple about end function Plasma:on_tick() self.t = self.t + 0.08 if not self:focused() then return end local t, cx, cy = self.t, self.cx, self.cy acid_begin_frame() acid_draw_window_frame(self:window_title()) for y = TOP, self.h - 1, CELL do for x = 0, self.w - 1, CELL do -- the same four ripples as issue #00, stacked local v = math.sin(x * 0.04 + t) + math.sin(y * 0.03 - t) + math.sin((x + y) * 0.03 + t) + math.sin(math.sqrt((x - cx)^2 + (y - cy)^2) * 0.04 - t * 1.5) -- v runs from -4 to 4: turn it into a spot on the 256-colour wheel acid_fill_rect(x, y, CELL, CELL, AcidPalette.hue(math.floor(v * 32 + t * 20))) end end acid_draw_window_border() acid_end_frame() end Plasma:new():start() Run it straight into the desktop: cargo run --release --manifest-path v3/Cargo.toml -p acid-os -- --app plasma The real thing: acid OS at 640x480, plasma window up front. There it is -- the plasma, in a window, in an OS. Click and drag inside it and the ripple follows you. What's going on: >> 03. Now break it (on purpose) This is the bit I'm proudest of. Add one line at the top of on_tick -- a loop that never ends: while true do end Run it again. The plasma freezes... and about two seconds later its window just goes. Look in the terminal you launched from: Acid OS v3: v3/apps/plasma.lua: stopped responding Everything else -- desktop, clock, any games you had open -- carried on as if nothing happened. That's because every app gets its own Lua brain on its own thread, and the OS keeps a stopwatch on each one. Hog it for more than two seconds and you're out. (Try error("boom") instead and you'll get your own message in the same spot.) Real operating systems do exactly this, just with more paperwork -- it's the same "one break-in, one room" idea as this week's news. Take the line back out before you carry on. ------------------------------------------------------------------------ [ 4. YOUR TURN ] * Fold it. Issue #01 [8] turned the plasma into a kaleidoscope with one line -- measure from the centre and mirror it with math.abs. Do the same here: before the sums, swap x and y for math.abs(x - self.w // 2) and math.abs(y - self.h // 2) and watch it go symmetrical. Then make it sing: in on_touch, play a note whose pitch follows your finger (acid_play_note(0, 30 + y // 4, 60) on press, acid_stop_note(0) on release -- chapter 5 of the manual in docs/manual-v3/ has the rest). Built something good? Open a pull request on the repo with your app in v3/apps/ -- the neatest one ships with acid OS. ------------------------------------------------------------------------ A new one every other week -- free, right here: https://makebreak.co.uk/issues/ No paywall, no ads, no sponsor telling me what to say. If an issue earned you a brew: https://buymeacoffee.com/androidacid -- the Norfolk Hacker prev: #05 Sniff the air https://makebreak.co.uk/issues/05.txt ------------------------------------------------------------------------ LINKS [1] https://www.helpnetsecurity.com/?p=386522 [2] https://www.securityweek.com/police-shut-down-killsec-ransomware-identify-alleged-teen-leader [3] https://thehackernews.com/2026/09/google-releases-chrome-update-to-patch.html [4] https://github.com/NorfolkHacker/Acid-OS-V3 [5] https://makebreak.co.uk/patches/plasma.lua [6] https://makebreak.co.uk/patches/plasma.app.toml [7] https://makebreak.co.uk/issues/00.html [8] https://makebreak.co.uk/issues/01.html ========================================================================