Live data from Hacker News

Pwnd Blaster: Hacking your PC using your speaker without ever touching it

blog.nns.ee

101–110 of 133 posts

Re: Pwnd Blaster: Hacking your PC using your speaker without ever touching it

#101
post #4

>Email from SingCERT stating vendor "do not consider this to be a vulnerability, as it does not present a cybersecurity risk." So wirelessly writing custom firmware to someone else's device that is connected via USB to their computer without even needing to pair is not a security vulnerability. Yea.

That answer will change very quickly, if someone marches to a Creative show room, sales event or CES and "patches" all of their devices.

That's assuming the attacker informs Creative of the attack. A malicious actor could go to the showroom, update the firmware on all devices, and simply let them continue on as normal, waiting for a future opportunity to strike.

Let's hope Creative patches things before something like this happens.

Re: Pwnd Blaster: Hacking your PC using your speaker without ever touching it

#102

If I were in charge of, say, the Mossad, I would have as a significant part of my budget purchasing every single bluetooth device on the market, and set a bunch of underemployed Israeli CS grads to work at finding these vulnerabilities, and then putting them into an easily deployed toolkit. You want an asset with access to, say, an Iranian government office, to be able to walk through the building with a phone and ta…

Pretty sure that's what NSO Group (https://en.wikipedia.org/wiki/NSO_Group) is. Israeli intelligence could also just insert vulnerabilities in cheap garbage (or even more expensive garbage like this) for NSO or NSO-like Israeli orgs to take advantage of. We know they sell pagers.

Re: Pwnd Blaster: Hacking your PC using your speaker without ever touching it

#103
post #97
post #23

Earlier quoted context omitted.

Do you know that if you turn off saving YouTube history, you can have no front page at all?

where do you turn that off?

In the mobile app, it’s under Settings -> Manage history

Not that hard to guess, right? ;)

Re: Pwnd Blaster: Hacking your PC using your speaker without ever touching it

#104

If I were in charge of, say, the Mossad, I would have as a significant part of my budget purchasing every single bluetooth device on the market, and set a bunch of underemployed Israeli CS grads to work at finding these vulnerabilities, and then putting them into an easily deployed toolkit. You want an asset with access to, say, an Iranian government office, to be able to walk through the building with a phone and ta…

There is no way that not every intelligence agency in the world is doing this.

Re: Pwnd Blaster: Hacking your PC using your speaker without ever touching it

#105

It is quite common to find device manufacturers, even those of many years standing, who _appear to_ begin with the device and add the software as an afterthought. Paying little attention to security or even the software lifecycle (patches, updates, the changing landscape/ecosystem). I have even known it happen that the device brand subs out the software to a random small developer, who then closes up shop/dies/gets o…

It's frightening how often this happens. And these days with the boatloads of cheap computer and phone peripherals being bought every minute there's just no realistic way for an authority to monitor and regulate all of it.

I bet it's not an insignificant amount of devices out there that had their firmwares written by a "random small developer" who is in fact some kind of supply chain hacker.

Re: Pwnd Blaster: Hacking your PC using your speaker without ever touching it

#106
post #72
post #48

Earlier quoted context omitted.

> "You can just make it type words, what's the risk in that?" I don't know if it's a useful answer to people saying this kind of stuff, but here are some examples of other attacks arbitrary USB pwn allows. A USB device can appear as a network adapter and most OS will happily route all your traffic there, so your speaker can know which porn you're looking at! It can also appear as a DisplayLink dongle, so it can see w…

The ability to "type words" is worse than all of that. Just type Win+R, "cmd", Enter and you've got arbitrary code execution on the connected PC. I think that was GP's point. Any competent security team would be aware of such risks.

Couple decades ago a product team of our product, the team consisting of PMs, senior engineers, etc., dismissed a security issue as a not serious because notepad.exe - which the PoC used to show arbitrary command execution - supposedly can't do much damage.

Re: Pwnd Blaster: Hacking your PC using your speaker without ever touching it

#107

Having a guaranteed audio channel makes this so much cooler for exploits -- you can exfiltrate over audio!! I love it. I wonder how many of these were sold. I also imagine based on Creative's response (this is fine) that many other devices in the class have similar security models in place. Def scary.

I somehow hadn't even considered Bluetooth as an option when I read the headline, I immediately thought about INFILTRATING via audio, which also sounds insanely cool, but I couldn't possibly wrap my head around how an audio circuit would have to be set up and connected back to the cpu to pull that off. Exfiltrating via audio also brings to mind one of those devices I really wanted to build ~20 years ago that can list…

[dead]

Re: Pwnd Blaster: Hacking your PC using your speaker without ever touching it

#108

Earlier quoted context omitted.

Shopping in the US, these have entirely replaced zigbee and other sensible mesh-based options at hardware stores like Home Depot and Lowes. The only exception I can find is Phillips Hue, and those seem to be slowly getting phased out with (sigh) a new "hubless" (requires wifi) series. I run my home automation network entirely offline, so anything that needs the internet doesn't get added to my cart. I just do not tru…

> Regular bulbs are still much more common on store shelves, because why fix what isn't broken? TV manufacturers might want to differ.

If we could started teaching Morse Code in standard curriculum then in about 18 years or so we could finally subsidize smart lightbulbs with blinking ads for products and then we could stop selling pesky "dumb" bulbs.

Re: Pwnd Blaster: Hacking your PC using your speaker without ever touching it

#109
It's funny to see all the commenters who didn't read the article closely enough or at all. This is basically the bluetooth device equivalent of "left S3 bucket open to public".

That said, really cool work. I honestly thought it would be harder to turn a usb connected device into an exploit vector.

That it's as easy as emulating a keyboard that pops a local terminal and runs a malicious command is actually pretty funny. Though it will be a non-admin terminal so the damage should be somewhat limited. And on Windows, users often just click through any UAC prompt so I bet you'd get full access on many windows boxes.

Re: Pwnd Blaster: Hacking your PC using your speaker without ever touching it

#110
post #28
post #8

Earlier quoted context omitted.

Oh yeah, for some reason the companies with the highest risk products seem to be the ones that care less about security. Don't even get me started with "smart" bulbs and cameras that each individually connect to your local network and the Internet. You have 5 lightbulbs? That's 5 different devices you need to track, keep updated and trust the in the vendor firmware's security.

> "smart" bulbs Thankfully I don't think I've seen these for sale. What sensors would they have that could be exploited by an attacker?

You can find a lot of literature out there for tracking people based on WiFi signal strength. The very thing they use to connect ends up being a sensor that gives away some pretty critical info.
Post reply on HN