>Email from SingCERT stating vendor "do not consider this to be a vulnerability, as it does not present a cybersecurity risk." So wirelessly writing custom firmware to someone else's device that is connected via USB to their computer without even needing to pair is not a security vulnerability. Yea.
"You can just make it type words, what's the risk in that?" Makes you wonder what other peripheral companies out there are also operating with seemingly no security team. There must be other vulnerabilities like this just waiting to be discovered. My brother was awoken one morning at 2am because some neighborhood kids connected to his bluetooth speaker and blasted fart sounds on loop at max volume, and that's literal…
Pwnd Blaster: Hacking your PC using your speaker without ever touching it
11–20 of 133 posts
Re: Pwnd Blaster: Hacking your PC using your speaker without ever touching it
#12Re: Pwnd Blaster: Hacking your PC using your speaker without ever touching it
#13>Email from SingCERT stating vendor "do not consider this to be a vulnerability, as it does not present a cybersecurity risk." So wirelessly writing custom firmware to someone else's device that is connected via USB to their computer without even needing to pair is not a security vulnerability. Yea.
Re: Pwnd Blaster: Hacking your PC using your speaker without ever touching it
#14Re: Pwnd Blaster: Hacking your PC using your speaker without ever touching it
#15Re: Pwnd Blaster: Hacking your PC using your speaker without ever touching it
#16Re: Pwnd Blaster: Hacking your PC using your speaker without ever touching it
#17Re: Pwnd Blaster: Hacking your PC using your speaker without ever touching it
#18>Email from SingCERT stating vendor "do not consider this to be a vulnerability, as it does not present a cybersecurity risk." So wirelessly writing custom firmware to someone else's device that is connected via USB to their computer without even needing to pair is not a security vulnerability. Yea.
Re: Pwnd Blaster: Hacking your PC using your speaker without ever touching it
#19Having a guaranteed audio channel makes this so much cooler for exploits -- you can exfiltrate over audio!! I love it. I wonder how many of these were sold. I also imagine based on Creative's response (this is fine) that many other devices in the class have similar security models in place. Def scary.