Live data from Hacker News

Pwnd Blaster: Hacking your PC using your speaker without ever touching it

blog.nns.ee

61–70 of 133 posts

Re: Pwnd Blaster: Hacking your PC using your speaker without ever touching it

#64
post #4

>Email from SingCERT stating vendor "do not consider this to be a vulnerability, as it does not present a cybersecurity risk." So wirelessly writing custom firmware to someone else's device that is connected via USB to their computer without even needing to pair is not a security vulnerability. Yea.

In reality, even if they did recognize the severity of this problem, they likely view the cost to remediate it as prohibitive, as it would involve reworking their whole weird janky system. So better to pretend they don’t have to deal with security.

Re: Pwnd Blaster: Hacking your PC using your speaker without ever touching it

#69
post #4

>Email from SingCERT stating vendor "do not consider this to be a vulnerability, as it does not present a cybersecurity risk." So wirelessly writing custom firmware to someone else's device that is connected via USB to their computer without even needing to pair is not a security vulnerability. Yea.

The same can be said about any computer that runs macOS or Windows. Being able to run your own software doesn't have to be a vulnerability per se.

The reflashing interface being available over Bluetooth is weird but you will need physical access to pair with the speaker AFAIK

Edit: I was wrong, this is a BTLE endpoint that works without pairing. In that case, this is a ridiculous vulnerability. I hope they'll patch it in a way that doesn't take away the ability to run your own software.

Post reply on HN