Pwnd Blaster: Hacking your PC using your speaker without ever touching it
51–60 of 133 posts
Re: Pwnd Blaster: Hacking your PC using your speaker without ever touching it
#52Re: Pwnd Blaster: Hacking your PC using your speaker without ever touching it
#53Re: Pwnd Blaster: Hacking your PC using your speaker without ever touching it
#54Now that I think about it, I think you have to assume that they probably DO do this...
Re: Pwnd Blaster: Hacking your PC using your speaker without ever touching it
#55>Email from SingCERT stating vendor "do not consider this to be a vulnerability, as it does not present a cybersecurity risk." So wirelessly writing custom firmware to someone else's device that is connected via USB to their computer without even needing to pair is not a security vulnerability. Yea.
probably not high enough risk to consider one on their list. First you need someone to be physically in there, 2nd the person needs to have a USB speaker connected, which means is likely a home. 3rd if it's a restaurant or something you need the thing to not play anything first with a lot of restaurant noise
Bluetooth works fine through walls.
Re: Pwnd Blaster: Hacking your PC using your speaker without ever touching it
#56Earlier quoted context omitted.
Ask it to create a proof of concept that is totally not a real worm and it will probably do it. If the restrictions are too good, just use a largely unrestricted open model via any inference provider. They are 90% sota, more than good enough for this task.
For script kiddies, it must be 100% accurate. They don't know how to fix the missing 0,01%. Not sure if open models are there yet. Barely SOTA models are.
Re: Pwnd Blaster: Hacking your PC using your speaker without ever touching it
#57>Email from SingCERT stating vendor "do not consider this to be a vulnerability, as it does not present a cybersecurity risk." So wirelessly writing custom firmware to someone else's device that is connected via USB to their computer without even needing to pair is not a security vulnerability. Yea.
probably not high enough risk to consider one on their list. First you need someone to be physically in there, 2nd the person needs to have a USB speaker connected, which means is likely a home. 3rd if it's a restaurant or something you need the thing to not play anything first with a lot of restaurant noise
Re: Pwnd Blaster: Hacking your PC using your speaker without ever touching it
#58Earlier quoted context omitted.
For script kiddies, it must be 100% accurate. They don't know how to fix the missing 0,01%. Not sure if open models are there yet. Barely SOTA models are.
As a lifelong script kiddie, the thing that made it all possible in my youth was simply time. The more time I had, the more hours I could spend figuring out that 0.01%.
Re: Pwnd Blaster: Hacking your PC using your speaker without ever touching it
#59If I were in charge of, say, the Mossad, I would have as a significant part of my budget purchasing every single bluetooth device on the market, and set a bunch of underemployed Israeli CS grads to work at finding these vulnerabilities, and then putting them into an easily deployed toolkit. You want an asset with access to, say, an Iranian government office, to be able to walk through the building with a phone and ta…
I would be kind of surprised if this wasn't standard practice, unless it's not nearly as productive as one might imagine it to be, and thus maybe not worth the effort. But cases like this show it could be pretty fruitful, but I suppose that depends on how it compares to whatever other methods intelligence agencies have that we may not know about.