-
Notifications
You must be signed in to change notification settings - Fork 8
CYD Console Guide
What every screen, label, color, and button on the CYD touchscreen means and does. See the Console Reference page for quick-lookup tables (status words, colors, device classes, glossary).
The CYD ("Cheap Yellow Display") is the Vigil — the one node in the fleet with a screen. Every other board (the decoys) has no display at all; this console is the only window into what the whole fleet is doing. It's a 320×240 touchscreen. Almost everything you do here is a single tap; a couple of destructive actions require a deliberate two-tap confirm so a stray touch can't trigger them.
Two things to know up front:
-
Some features only exist in the "provisioned" build regime (
-DSIMULACRA_FLEET_PROVISION=1). In the simpler "baked" regime (the default, and what the browser web-flasher installs), every board already shares one built-in key and there's no enrollment step — the FLEET ROSTER bar and the pairing/enrollment banner described below simply don't exist on that build. Everything else on this page applies to both regimes equally. - The color palette is a deliberate dark theme, not literal traffic-light red/green. There are three semantic colors used consistently everywhere: a teal-green for "alive / healthy," an amber for "warning / dormant," and a red for "something was detected." A purple accent marks selection and icons. This guide names colors by their role (healthy / warning / danger / accent) rather than exact shades — see the Console Reference page for the on-screen LEGEND itself.
- HOME is the console's front page — a grid of icons, one per other page. Tap any icon to open that page.
- On every other page, the top strip is "< BACK" — tap it to return to HOME (or, from a couple of "drilled into" pages, back one level).
- Pages that show a list of things (nodes, followers) use left/right zones to step through the list one item at a time, rather than a scrollable list — tap the left third of the screen for previous, the right third for next.
- The screen goes idle back to HOME after 15 seconds with no input (unless a threat is actively showing), and the backlight turns off after 30 seconds of being idle and clear. Any touch, or a brand-new follower being detected, wakes it back up.
The console's landing page. Two regions, top to bottom:
-
Top bar. The Simulacra wordmark on the left. On the right, a one-word protection posture — the single honest headline for "how are you doing right now." See Protection posture on the Reference page for exactly what each word means. If any surveillance hardware (a camera or bodycam signature) is currently seen nearby, a small
!Ncount appears next to the posture word. -
Icon grid. Eight tiles, each opening one page:
Icon label Opens RADAR The aggregate radar view (all followers plotted around a center point) FOLLOWERS The list of detected trackers/followers DECOYS Fleet-wide decoy/crowd statistics CONTROL Presets and fleet commands LIBRARY The self-learning library and SD card status INFO System console + color/status legend EXPOSURE The "what does my own phone leak" self-check NODES The full list of every tracked decoy node
A literal radar-style view: concentric rings around a center point, with a sweeping line that animates continuously (this is purely visual — it doesn't affect anything). Each detected follower is plotted as a small colored square:
- Distance from center = signal strength (closer = stronger signal, i.e. probably nearer to you).
- Angle = not a real compass direction — it's derived mathematically from the follower's identifier just to spread multiple followers apart visually so they don't overlap. Don't read angle as "which way it is."
- Color = how many times this follower has been seen (see Escalation levels).
At the bottom: either "CLEAR" (no active followers) or a count of how many are currently tracked, plus a small status line showing the total live decoy count and how long this session has been running.
The list view for everything currently flagged. It's split into two sections:
- The main list — behavioral followers and known-fingerprint devices (trackers). Each row shows a colored escalation dot, a name (either a matched device type like "AirTag," or a short hex ID if it's an unrecognized device that's just behaviorally suspicious), how many times/places it's been seen (or "new" if this is its first sighting), and its signal strength on the right.
- A SURVEILLANCE section below it (only shown if any exist) — fixed infrastructure like license plate cameras or body-worn cameras. These are shown separately from followers because they're not "following" you, they're just present — infrastructure you happened to pass, not something moving with you.
Tap any row (when the list isn't empty) to drill into that item's full THREAT detail page.
Fleet-wide numbers about the decoy crowd itself, in three sections:
-
DECOY CROWD —
projecting(how many fake devices are live across the whole fleet right now),target(how many the current preset/settings are aiming for), and anrpa/nrpa/staticbreakdown — how many of the live decoys are using each of the three Bluetooth address-privacy behaviors real phones and devices actually use (see the Glossary for what these mean). -
ENVIRONMENT —
real crowd(the estimated number of actual nearby devices the system has detected, which is what the fake crowd's size is being matched against) andobserved(a running total of how many real advertisements have been seen this session). -
SYSTEM — the current
epoch(a counter that increments each time the fleet's shared key is rotated), how many Wi-Fiprobeshave been sent, whetherchurn(the identity-rotation engine) is running or paused, and sessionuptime.
The fleet's command center — this is the only page that can change what the decoys are actually doing. Everything sent from here goes out as a cryptographically signed command, so a captured decoy can't forge one, and the fleet only accepts a command signed by this specific console's key.
Layout:
- LIVE — what the fleet is actually, currently running, as reported back by the decoys themselves (not just what you last tapped). If different nodes in the fleet report different presets — for instance, a command is still propagating — this shows MIXED instead, in the warning color, so you're never shown a false "everyone agrees" state.
- PENDING — the preset you have selected right now but haven't sent yet, shown in a box in the middle. Tap the left third of the screen to cycle backward through presets, the right third to cycle forward.
-
SEND button — sends the pending preset to the whole fleet. Its label changes to tell you what
state you're in:
SEND(nothing sent yet),SENT(just sent, brief confirmation flash),ACTIVE(the pending preset is already what's live — nothing to do), orCONFIRM?(see TURBO below — this preset needs a second tap). - CLEAR THREATS button — wipes every decoy's detected-follower history fleet-wide. Requires two taps within 3 seconds: the first arms it (button turns to a warning color reading "CONFIRM CLEAR?"), the second actually sends it. Tapping anything else, or waiting past 3 seconds, disarms it with no effect.
- FLEET ROSTER bar (provisioned regime only) — a strip across the very top of this page. Tap it to open the fleet roster for enrolling/revoking decoys.
| Preset | What it actually does |
|---|---|
| PAUSE | Freezes identity rotation. Existing fake devices keep transmitting exactly as they are — it doesn't go silent — but nothing new appears and nothing currently on-air expires. |
| STEALTH | A smaller crowd than normal (roughly 40% of the fleet's designed max), unhurried turnover. Lower profile. |
| NORMAL | The firmware's default balance — this is what a freshly flashed board runs. |
| DENSE | Full-size crowd, with identities turning over 1.5× faster than normal. |
| MAX | Full-size crowd, turning over 2.5× faster than normal — the busiest "realistic" setting. |
| TURBO | A fundamentally different mode, not a bigger version of the others: every board independently maxes out its own Bluetooth and Wi-Fi radios, abandoning realism entirely in favor of raw volume — see the project's own docs for the full reasoning. Because this is the loudest, most disruptive setting, sending it requires two taps within 3 seconds (SEND shows CONFIRM? after the first), the same arm/confirm pattern as CLEAR THREATS. |
The console can also show two states that aren't really "presets" you'd select: CUSTOM (the fleet is running settings that don't match any of the six named presets — this generally shouldn't happen in normal use) and MIXED (described above, under LIVE).
Opened by tapping the FLEET ROSTER bar at the top of CONTROL. Shows every decoy currently trusted by this console, each identified by a short fingerprint (not a name — you're expected to visually match it against the matching text a newly-flashed decoy prints over its own serial console, the actual "proof of identity" step). From here:
- UP / DOWN — move the selection through the list.
- REVOKE — removes the selected decoy from the trusted list, and immediately rotates the entire fleet onto a brand-new shared key, re-enrolling every surviving decoy automatically. The revoked board is now completely cut out — it has no way back in without being physically re-paired. Like CLEAR THREATS, this needs two taps within 3 seconds (button shows "CONFIRM?" after the first tap).
- EXIT — closes the roster and returns to CONTROL.
Pairing a new decoy isn't done from inside this roster screen — it's a console-wide gesture: a long-press (about 1.5 seconds) anywhere on the screen while the roster isn't open. What it does depends on what's currently happening:
- If a decoy is currently waiting to be accepted (see below), the long-press accepts it.
- If a pairing window is already open, the long-press instead rotates the fleet key immediately (skips ahead rather than waiting out the current window).
- Otherwise, it opens a fresh 30-second pairing window, during which any un-enrolled decoy in range will answer and request to join.
While a pairing window is open, a banner appears across the top of the screen showing the countdown and the current epoch/allowed-count. When an unrecognized decoy answers, the banner instead turns into an alert asking "ACCEPT DECOY?" with that decoy's fingerprint shown in the warning color — this is the moment to check that fingerprint against the decoy's own serial output before long-pressing to accept it. Waiting it out instead of accepting denies it.
Status of the self-learning system and its SD card storage, in two sections:
-
STORAGE — whether the SD card is present and its capacity, plus
shapes— how many learned device templates are currently held (out of the library's capacity). -
SYNC — how long ago the console last received a newly-learned shape from a decoy (
offer rx), last pushed the library out to the fleet (sync tx), and last wrote the library to the SD card (last save, with the size of what was saved). All show "never" if that hasn't happened yet this session.
If there's no SD card function at all on this build, the page just says "not a librarian."
A two-page system console — tap the body of the page (anywhere below the header) to flip between the two pages; the current page always says which way to tap next at the bottom.
Page 1 — SYSTEM. Grouped sections:
- FLEET — how many nodes are meshed in, fleet-wide decoy count and target, and the estimated real ambient crowd size.
- SIGNATURES — the tracker-signature database's version and how many signatures it holds.
- STORAGE — same SD card summary as the LIBRARY page.
- LINK — how long ago any status was last received from the fleet.
- SYSTEM — this console's own uptime and firmware build tag.
Page 2 — LEGEND. A plain-language key for every color and status word used across the whole console: the four posture words, the three escalation levels, and the four node-health words — each shown in its actual on-screen color next to a short explanation. If you ever forget what a color means anywhere else in the UI, this page is the answer.
A self-check, not a fleet status page: it answers "what does my own phone announce about itself?" — independent of everything the decoy crowd is doing. Three steps:
- Tap anywhere to start. The screen says "listening..." for about 4 seconds — this is a baseline window, letting the console see what's normally in the air before your phone does anything.
- Then it asks you to toggle your phone's Wi-Fi off, then back on, and watches for about 6 seconds. Turning Wi-Fi off and on forces a fresh burst of probe requests, which is what makes your phone identifiable against the baseline noise.
- Result. If a clear burst was seen, it shows how many probes your phone sent and, critically, whether it named any specific saved networks while doing so (a real privacy leak — it means anyone listening now knows a network your phone has connected to before) or asked with no names at all ("named no networks (good)" — still detectable as present, but not leaking which networks it knows). If the burst wasn't clearly identifiable from the background noise, it says so plainly ("no clear signal") rather than guessing.
Tap again at the result screen to run it again.
One honest caveat worth knowing: this scan can't currently tell your own phone's traffic apart from the decoy fleet's own Wi-Fi probe traffic if you're standing inside your fleet's coverage while running it (which is the normal way you'd use it) — a decoy's own probe activity could in principle get picked as "the result" instead of your real phone, or make a real result harder to isolate. This is a known, documented limitation, not a bug — having the decoys behave any differently just to make this one diagnostic screen cleaner isn't worth compromising how realistic they look the rest of the time.
The full list of every decoy node the console is currently tracking (up to 8). Each row shows a node's id, health word, live decoy count, and battery (if present) — the same at-a-glance fields the old HOME fleet strip used to show, just as a list instead of cards, so every tracked node is reachable, not just the first few. Tap any row to open that node's full NODE detail page.
Reached by tapping a row on the NODES page. Shows everything the console knows about one specific decoy board: a health line at the top (see Node health), then:
- CROWD — that node's own decoy count, target, roster capacity, its own rpa/nrpa/static breakdown, and its own view of the real ambient crowd size.
-
POWER — battery reading:
USBif it has no battery connected, a percentage + voltage if it has a fuel gauge, or voltage alone if it only has a simple voltage-divider sensor. - SYSTEM — that node's own epoch, probes sent, pause state, and uptime.
- DETECTIONS — how many followers and how much surveillance infrastructure this specific node has personally detected (the aggregate FOLLOWERS page combines every node's detections into one list; this is just the one board's count).
Left/right zones step to the previous/next known node. If a node stops reporting, its card still shows here (marked SILENT) with how long ago it was last heard from, rather than disappearing.
Reached by tapping a row on the FOLLOWERS page. Full detail on one specific detected item:
-
CLASSIFICATION —
kind(known, meaning it matched a fingerprint database entry, orbehavioral, meaning it was flagged purely by reappearing near you without a known signature),class(the matched device type, e.g. AirTag/SmartTag/Tile/Flock/Axon — see Known device classes — or "-" if behavioral-only),category(tracker / camera / bodycam / unknown), andconfidence(a percentage, for known matches only). - SIGHTING — signal strength, the current escalation level, how many separate sessions and separate places it's been seen, how many distinct time-epochs it's shown up in, and the span between its first and most recent sighting.
See the Console Reference page for quick-lookup tables covering protection posture, escalation levels, node health, known device classes, and a glossary of terms used throughout this guide.