Live data from Hacker News

My audio interface has SSH enabled by default

hhh.hn

71–80 of 106 posts

Re: My audio interface has SSH enabled by default

#71

I think "my audio interface is a 64-bit Linux computer" would've sounded far more interesting to me as a title. Perhaps a decade or two ago, the functionality of that device would've likely been implemented on a small 16-bit or 32-bit SoC running an RTOS like VxWorks. Given how many physical controls it has, turning it into a game console seems like a logical next step.

And your video dongle might be a Unix computer: https://www.macrumors.com/2025/02/04/doom-apple-lightning-hd...

Re: My audio interface has SSH enabled by default

#72
post #44

Earlier quoted context omitted.

Ah, EU-only. That explains why I've never heard of it, among other things.

Well... if you look behind anything that plugs into a wall socket you will see that it has ( among many other things) a CE mark. Even things in the USofA have a CE mark. If your new product cannot have its CE mark for whatever reason, you will not have the approbations to sell in the USA either. What the CRA will do, is if you do not have a "CRA" compliant product, you will not have the CE mark. Which means you will…

>If your new product cannot have its CE mark for whatever reason, you will not have the approbations to sell in the USA either.

I worked for a US manufacturer that only sold directly in the US, and we never bothered getting CE certification on anything, just FCC. Lots of Europeans imported our products, but we left EU compliance up to them.

The size of the EU market didn't justify the costs of regulatory compliance.

Re: My audio interface has SSH enabled by default

#73
post #67
post #62

is he happy that rode has an ssh to his device? the guy is like too nice. where's the outrage?

I would like for SSH to be turned off, but I also like that I can just do that myself. Normally when I look at these devices firmware they’re horrific beasts with insane issues everywhere. This just requires a config change to fix the single thing I don’t like about it. There’s plenty of outrage in the world :)

Hacker News doesn't know what to do with anyone that doesn't think the world is ending and that humanity is inherently evil and must be punished.

It's still better than Reddit, though.

Re: My audio interface has SSH enabled by default

#74
post #68
post #60

Yeah, this is pretty common once a device has any real DSP in it. There's usually some stripped-down Linux on an ARM SoC underneath, and the vendor BSP just happens to ship with sshd on. Not necessarily malice, more like nobody on the audio side really owns the rootfs. The big question is whether it's only listening on the USB-side network, or on the actual LAN. First one is annoying. Second one would actually bother…

It is listening on the LAN. It connects over wifi only when you use certain features, so i didn’t test if that interface is listening as well.

Yeah, LAN is the line for me. USB-side sshd is a weird dev leftover; LAN means it’s now in the home threat model.

Re: My audio interface has SSH enabled by default

#75
post #56

I think "my audio interface is a 64-bit Linux computer" would've sounded far more interesting to me as a title. Perhaps a decade or two ago, the functionality of that device would've likely been implemented on a small 16-bit or 32-bit SoC running an RTOS like VxWorks. Given how many physical controls it has, turning it into a game console seems like a logical next step.

My audio interface is a Linux computer with FPGAs inside (that actually get field-programmed), with two gigabit Ethernet jacks that each talk to different parts of the machine. But I don't think anyone here would care about that. It's not such an unusual arrangement. I guess it's kind of impressive to use it on my desk at home, but in pro audio world it's actually kind of mundane. Maybe I'll write about it more after…

I have some of those at work: they're test platforms for the audio ICs, for things like SoundWire interfaces.

Re: My audio interface has SSH enabled by default

#76
post #44

Earlier quoted context omitted.

Well... if you look behind anything that plugs into a wall socket you will see that it has ( among many other things) a CE mark. Even things in the USofA have a CE mark. If your new product cannot have its CE mark for whatever reason, you will not have the approbations to sell in the USA either. What the CRA will do, is if you do not have a "CRA" compliant product, you will not have the CE mark. Which means you will…

>If your new product cannot have its CE mark for whatever reason, you will not have the approbations to sell in the USA either. I worked for a US manufacturer that only sold directly in the US, and we never bothered getting CE certification on anything, just FCC. Lots of Europeans imported our products, but we left EU compliance up to them. The size of the EU market didn't justify the costs of regulatory compliance.

> Lots of Europeans imported our products, but we left EU compliance up to them.

Yeah, compliance is almost voluntary unless you're absolutely huge.

Re: My audio interface has SSH enabled by default

#77
post #65
post #56

Earlier quoted context omitted.

My audio interface is a Linux computer with FPGAs inside (that actually get field-programmed), with two gigabit Ethernet jacks that each talk to different parts of the machine. But I don't think anyone here would care about that. It's not such an unusual arrangement. I guess it's kind of impressive to use it on my desk at home, but in pro audio world it's actually kind of mundane. Maybe I'll write about it more after…

I’m building an audio device. It runs Linux for the control plane (it’s just a CM4 running Yocto, maybe I’ll leave SSH running on production units, maybe not, haven’t decided yet). No audio passes through the CM4, there’s a dedicated FPGA and MCU for that. It’s been a fun project, first time hardware for me, feel free to ask my anything!

Nice!

This particular box also has RS-232, ssh (with almost zero auth), and telnet as a control plane, by default. Any of that only gets used to tweak/report various things with a rather basic human-readiable protocol. (It has built-in functions to make it more secure; I just don't care on my home LAN, or on my pop-up LANs in the field. A sane person with a professional role would have it locked down and on its own VLAN/VPN, but for me and prototyping: Telnet is actually pretty good.)

I designed none of it. I just bought it, and make good use of it. New, it was a mid-4-digit box; used, they're not so bad. (And I use it every day and like it quite a lot, hence the reluctance to go harder on the potential root shell hack.)

My box, as it sits, just does general-purpose GUI-connected DSP stuff with near-realtime tweaking. I'm in the process of getting it to grok OSC, and thus Reaper or whatever, so it has a better control surface for live work.

It has a USB interface that my Linux box treats as a sound card, which works well. My main reason for wanting to get root is to examine (solve?) its ~5-minute boot times.

5 minutes in a live sound environment is the difference between having a large, active, and involved crowd, and having everyone get bored and find something else to do.

Anyway, the FPGAs here just exist to behave as DSPs and...well, digitally process [audio] signals. It works well; I really just wish it booted faster.

And that may be its downfall. :P

---

But enough about that.

What's your device do? What are your plans and dreams with it? (Do I want one?)

I've built a very small amount of hardware. At least at the level of custom PCBs and some code, it's been richly rewarding even when I screw it up, and it makes me feel like I'm on top of the world when I get it right.

Can you tell me about your widget?

Re: My audio interface has SSH enabled by default

#78
post #51
post #19

Earlier quoted context omitted.

the rodecaster can connect to two computers, and we are both generally in the same discord call. so we have both microphones routed into one input for a computer, and the other person joins with their mic muted and the audio just comes from one client. since the mixing is local there's no echo. email me if you have more questions :)

So both mics will pick up both people (at least somewhat, in the same room) - but because there is no, I assume 20-100ms latency going through the system, to discord, and back - it avoids a slight difference in timing of the two mics picking up the same sound slightly differently. Is that right? Very cool!

correct

also the audio output of each computer is routed thru the box as well, so i can mix my girlfriend’s computer into her headphones as well as my microphone, so she can hear me with noise canceling headphones, or turn off my microphone if i’m working so she can do stuff without my mic in her ears.

Or if she’s watching a movie or something I can also add her computer audio to my headphones. There’s even a separate audio output for host 1 where you can put ‘chat’ on, like discord on a dedicated interface, so that your application audio is clear and isolated. It’s hella expensive but it really is a great device

Re: My audio interface has SSH enabled by default

#79
post #77
post #65

Earlier quoted context omitted.

I’m building an audio device. It runs Linux for the control plane (it’s just a CM4 running Yocto, maybe I’ll leave SSH running on production units, maybe not, haven’t decided yet). No audio passes through the CM4, there’s a dedicated FPGA and MCU for that. It’s been a fun project, first time hardware for me, feel free to ask my anything!

Nice! This particular box also has RS-232, ssh (with almost zero auth), and telnet as a control plane, by default. Any of that only gets used to tweak/report various things with a rather basic human-readiable protocol. (It has built-in functions to make it more secure; I just don't care on my home LAN, or on my pop-up LANs in the field. A sane person with a professional role would have it locked down and on its own V…

Re: yours, that is a _long_ boot time. Boot time on mine isn't great, but I think I'm just going to have to accept that as an artefact of U-Boot, Linux, and an Ethernet switch chip that takes some time to initialise.

Anyway, re: my widget: it's a personal monitor mixer [1], something one might use in the studio or live, not dissimilar to existing products in the market, except: it supports up to 64 channels of Dante or AVB natively, it has a super nice (HiDPI) UI, and absolutely everything is remote controllable using OCA (AES70) or OSC. I even have a MCP bridge so you can let Claude manage it ;) [2]

The hardware is a custom board that hosts a CM4 SOM (for the control plane and UI), a Brooklyn 3 SOM (Dante), and an XMOS which runs the mixer firmware and AVB stack. There are also some nice AKM DACs, and a Marvell Ethernet switch chip that connects the SOMs and XMOS to two external Ethernet ports.

The CM4 runs Yocto which manages the switch in DSA mode (i.e. hardware offloaded bridge), runs the gPTP and SRP stacks for AVB, the OCA daemon, and the UI (which is just a regular OCA client). SSH is presently enabled but there's not a lot to do once you're in there. Working on secure boot at the moment with U-Boot and dm-verity.

[1] https://forums.swift.org/t/an-embedded-audio-product-built-w... (note, older prototype)

[2] https://www.linkedin.com/posts/lukehowardmusic_heres-a-long-...

Re: My audio interface has SSH enabled by default

#80

I really want to know how he solved this problem, which I also face: >last year i bought a Rodecaster Duo to solve some audio woes to allow myself and my girlfriend to have microphones to our respective computers when gaming together and talking on discord in the same room without any echo

I recently vibe coded a jack mixer in Rust. It can ingest and relay audio via LAN. I have around 40 ms latency, 50-60 ms if relaying via wifi.

It would solve the issue in a similar way. One pc runs the mixer. The mixer has an input channel for local mic.

Other PC broadcasts their mic to the mixer, which comes in as 'channel 2'.

You can even have music playing on your local PC, either the mixer or broadcaster creates a local sink.

It's all then mixed in the mixer, there's 3 outputs. You could say use the main out to send to discord.

And the monitor line would be used to output Discord audio, which can then be relayed to the other PC for realtime listening.

Post reply on HN