Live data from Hacker News

My audio interface has SSH enabled by default

hhh.hn

101–106 of 106 posts

Re: My audio interface has SSH enabled by default

#101
post #79
post #77

Earlier quoted context omitted.

Nice! This particular box also has RS-232, ssh (with almost zero auth), and telnet as a control plane, by default. Any of that only gets used to tweak/report various things with a rather basic human-readiable protocol. (It has built-in functions to make it more secure; I just don't care on my home LAN, or on my pop-up LANs in the field. A sane person with a professional role would have it locked down and on its own V…

Re: yours, that is a _long_ boot time. Boot time on mine isn't great, but I think I'm just going to have to accept that as an artefact of U-Boot, Linux, and an Ethernet switch chip that takes some time to initialise. Anyway, re: my widget: it's a personal monitor mixer [1], something one might use in the studio or live, not dissimilar to existing products in the market, except: it supports up to 64 channels of Dante…

I'm astounded to hear that you consider this your first hardware project. That is, to be clear, rather fucking amazing.

At first, I wanted to ask why all that work is done locally instead of just controlling a mixer over the network. Because, I mean, when networked audio is already happening there's almost invariably some kind of mixer involved somewhere, but think I get it: Controls for mixers are all over the place, but AVB and Dante are fixed and unitized and it's easy-enough to find those streams (and/or for someone to make them available) on a network.

That makes your method very universal in application. Even when the monitor feed is an analog split (as is still often the case), it's easy-enough to convert that to Dante or AVB with a stage box [which can be rented] so the performers still control their own ears.

Nice, dude.

And yes, I want one. (Whether I can afford one or not is a different thing entirely, but the want is resolute.)

Re: My audio interface has SSH enabled by default

#102
post #99
post #98

Earlier quoted context omitted.

I'd like to reiterate that a CE mark means nothing to us here. If my house burns down and a widget with only a CE mark is blamed as the source, my insurance company will consider that to be the equivalent of it having no marking at all. If a company wants to sell a product globally including the USA , then CE isn't enough to satisfy the safety boffins. The world is a big place, and the US isn't alone in this way: Lot…

Well... I live in Canada and I have never seen any "modern" electronics around me that does not have the CE mark. Even things ordered directly from China have a CE mark! I guess you have never really visited Canada and looked at the marks on the things you use. And it kind of removes value from your opinion about the other countries of the world. Sorry.

That's not what I'm saying. I'm not saying that a device sold anywhere in the world can't have a CE mark -- that's not it, at all. I'm also not saying that a person or company can't seek to get a CE mark for their product from wherever they are in the world (they certainly can do that).

There's a lot that I'm not saying.

What I am saying is that there are places in the world where the CE mark (and the presence or absence of it) means nothing, and that Canada is one such place.

Y'all have your own safety marks up there.

CSA is a big one -- you've had that organization up there and doing great work for over a century. cUL is another very common, accepted mark in Canada.

There are many more. Here's the list: https://scc-ccn.ca/resources/publications/recognized-canadia...

But, again: The Standards Council of Canada doesn't recognize the CE mark for devices used in Canada. That's not a thing that they do.

Re: My audio interface has SSH enabled by default

#103
post #101
post #79

Earlier quoted context omitted.

Re: yours, that is a _long_ boot time. Boot time on mine isn't great, but I think I'm just going to have to accept that as an artefact of U-Boot, Linux, and an Ethernet switch chip that takes some time to initialise. Anyway, re: my widget: it's a personal monitor mixer [1], something one might use in the studio or live, not dissimilar to existing products in the market, except: it supports up to 64 channels of Dante…

I'm astounded to hear that you consider this your first hardware project. That is, to be clear, rather fucking amazing. At first, I wanted to ask why all that work is done locally instead of just controlling a mixer over the network. Because, I mean, when networked audio is already happening there's almost invariably some kind of mixer involved somewhere, but think I get it: Controls for mixers are all over the place…

Well, also to be clear, I did find a great hardware engineer to design the board based on my somewhat outrageously over-engineered specifications. And I have been working on it for three years and haven't shipped.

It's a great question, and indeed a centralised mixer is pretty much the common approach as it allows for economies of scale. I guess there's a philosophical bent, the same reason I run my own SMTP and IMAP servers instead of Gmail: I like distributed systems. The practical bent is that, in my studio (the target market!), I only really need one or two of these, so the economy of scale doesn't apply. And interestingly with things like Lawo .edge we are seeing distributed mixers come into fashion.

And as you point out, being protocol-agnostic means that it can fit into a lot of scenarios, which might be useful (say) if it were to be a hire product.

Feel free to drop me a line if you want to chat more, I'm lukeh at padl dot com.

Re: My audio interface has SSH enabled by default

#104
post #50

Good old local Aussie guys write this. If you had something you wanted to report I'd just give them a call. We almost speak English down here.

It's a Sydney company. But parts are now manifactured in China. So who added this backdoor to listen to its customers? The CIA has similar companies doing it over popular loudspeakers. Could also be the Chinese.

Re: My audio interface has SSH enabled by default

#105

The thing I always come back to with this stuff is that "signed firmware" and "open firmware" aren't actually opposites, they just get treated that way. Ship it with verification on by default, fine, but let the owner enroll their own key (or flip a jumper, or hold a button on boot, whatever). Basically nobody does this outside of a couple of Chromebooks and some networking gear, so every conversation about firmware…

I've said this dozens of times on here, but IMHO the correct solution to this problem is: 1. Allow the user to choose between developer control and owner control, but only at first setup / after a factory reset. This prevents somebody with physical access from easily and covertly installing a backdoor. 2. Have a scary screen on boot announcing that "your device has been hacked", bypassable via a secret combination th…

I like this. The factory-reset gate stops the attack without locking owners out, and the boot warning is basically what Android does with unlocked bootloaders.

Re: My audio interface has SSH enabled by default

#106

Earlier quoted context omitted.

I don't want my audio interface to run SSH (and have some random authorized key added), personally.

I agree that it shouldn't have SSH enabled, but I do like that the firmware isn't encrypted or signed, so it's not hard to mod it, at no cost to thr manufacturer

Fact.
Post reply on HN