Live data from Hacker News

Pwnd Blaster: Hacking your PC using your speaker without ever touching it

blog.nns.ee

111–120 of 133 posts

Re: Pwnd Blaster: Hacking your PC using your speaker without ever touching it

#112
post #34
post #4

>Email from SingCERT stating vendor "do not consider this to be a vulnerability, as it does not present a cybersecurity risk." So wirelessly writing custom firmware to someone else's device that is connected via USB to their computer without even needing to pair is not a security vulnerability. Yea.

> SingCERT dropped the case I expect some dodgy company to try to shirk out of it, I don't expect a country's cybersecurity agency to do so

ESL moment Read the article properly, it is the company that tried to shirk out of it

Re: Pwnd Blaster: Hacking your PC using your speaker without ever touching it

#114
post #28

Earlier quoted context omitted.

> "smart" bulbs Thankfully I don't think I've seen these for sale. What sensors would they have that could be exploited by an attacker?

You don't need to exploit sensors. If a compromised device is connected to the internet (because the vendor app requires it to set up and control), you can use it as a part of botnet with a nice residential IP address.

... Why does it have anywhere near the level of computing power that a botnet would find useful?

Re: Pwnd Blaster: Hacking your PC using your speaker without ever touching it

#115
post #28

Earlier quoted context omitted.

> "smart" bulbs Thankfully I don't think I've seen these for sale. What sensors would they have that could be exploited by an attacker?

Shopping in the US, these have entirely replaced zigbee and other sensible mesh-based options at hardware stores like Home Depot and Lowes. The only exception I can find is Phillips Hue, and those seem to be slowly getting phased out with (sigh) a new "hubless" (requires wifi) series. I run my home automation network entirely offline, so anything that needs the internet doesn't get added to my cart. I just do not tru…

> I run my home automation network entirely offline, so anything that needs the internet doesn't get added to my cart.

Absolutely support you in that. I don't really feel the urge to automate appliances around me in the first place, though. I feel like I'd just be locking myself into the schedule I'd automated, building my life around it. What good is free time without freedom?

Re: Pwnd Blaster: Hacking your PC using your speaker without ever touching it

#116

Earlier quoted context omitted.

You don't need to exploit sensors. If a compromised device is connected to the internet (because the vendor app requires it to set up and control), you can use it as a part of botnet with a nice residential IP address.

... Why does it have anywhere near the level of computing power that a botnet would find useful?

Guess what the big bottleneck is in a DDOS? Not the computing power.

Re: Pwnd Blaster: Hacking your PC using your speaker without ever touching it

#117

Earlier quoted context omitted.

Shopping in the US, these have entirely replaced zigbee and other sensible mesh-based options at hardware stores like Home Depot and Lowes. The only exception I can find is Phillips Hue, and those seem to be slowly getting phased out with (sigh) a new "hubless" (requires wifi) series. I run my home automation network entirely offline, so anything that needs the internet doesn't get added to my cart. I just do not tru…

> Regular bulbs are still much more common on store shelves, because why fix what isn't broken? TV manufacturers might want to differ.

A light bulb doesn't require a processor to turn on and off when power is applied, so the only reason to add one is for extra functionality. A TV requires a (relatively) powerful processor just for decoding the signal.

Re: Pwnd Blaster: Hacking your PC using your speaker without ever touching it

#118

If I were in charge of, say, the Mossad, I would have as a significant part of my budget purchasing every single bluetooth device on the market, and set a bunch of underemployed Israeli CS grads to work at finding these vulnerabilities, and then putting them into an easily deployed toolkit. You want an asset with access to, say, an Iranian government office, to be able to walk through the building with a phone and ta…

This is kind of backwards. There aren't as many CS grads in Israel in the first place, because they already put their top talent through 8200. It's essentially a fully socialized Masters of computer engineering, and as a SIGINT shop they are learning this sort of thing. Once their 2-3 years of service is over (which doesn't result in student loans), the government makes a lot of seed funding available for startups an…

..and all that human capital is used to taint humanity itself, propagating inter generational trauma and conducting the second genocide of the last century, all justified by some religious texts.

Re: Pwnd Blaster: Hacking your PC using your speaker without ever touching it

#119
post #109

It's funny to see all the commenters who didn't read the article closely enough or at all. This is basically the bluetooth device equivalent of "left S3 bucket open to public". That said, really cool work. I honestly thought it would be harder to turn a usb connected device into an exploit vector. That it's as easy as emulating a keyboard that pops a local terminal and runs a malicious command is actually pretty funn…

I assume the malicious HID keyboard can press through the UAC prompt on its own, just like the user's actual one can.

Re: Pwnd Blaster: Hacking your PC using your speaker without ever touching it

#120
post #75
post #66

This is a cool infection vector for the ai virus from earlier today to use. It could be like NDS feature that it greeted a passerby but now for spreading stuff digitally.

> ai virus from earlier today curious what this means...

I think they mean this submission about a worm that runs local LLMs on infected machines for its own planning.

https://news.ycombinator.com/item?id=48379664

Post reply on HN