Live data from Hacker News

Unveiling secrets of the ESP32: creating an open-source MAC layer

zeus.ugent.be

121–130 of 157 posts

Re: Unveiling secrets of the ESP32: creating an open-source MAC layer

#121

Earlier quoted context omitted.

1) of course it does. This is an information cold war. If participant 1 is doing something then participant 2 is forced to do at least the same thing so as to ensure they don't fall behind. It's very naive to not expect the actions of one state to not affect the actions of the other.

you either intentionally or unintentionally phrased it in a way that blames unnamed participant 1. And given the context of this conversation, it seems that you blame US for CCP's inevitable spying. Seems weird given the kind of government CCP is(hint, the name). In my opinion US is only at fault for spying on it's own citizens(im not citizen nor resident of the us), and in doing so it undermined its counter intelege…

I'm not blaming either party. I don't even know who first started it. I'm just pointing out the fallacy in the argument. That's why I explicitly used generic names instead of CCP and US Gov.

Re: Unveiling secrets of the ESP32: creating an open-source MAC layer

#122
post #54

Earlier quoted context omitted.

I restrict my esps to local network only absolutely no internet access for them. No trust for Chinese products from Chinese companies

The vast majority of people who use ESP-32 smart devices, however, probably just give it the password to their WiFi.

Sure, but if one in a million people bothers to check what it is actually sending through their router, then any malicious activity would get detected and disclosed to the public - and since that hasn't happened, we can assume that it isn't happening on a large scale.

Re: Unveiling secrets of the ESP32: creating an open-source MAC layer

#123

Earlier quoted context omitted.

How are the two not equivalent? If anything, for anyone living in the west it's probably less of an issue to have China spy on them than a western government. Sure, at a state security level it's not but for regular individuals I sure would rather have China spy on me since they can't do anything to me directly.

You have at least some civil rights in those countries, you don't in China. Be careful of a layover.

> You have at least some civil rights in those countries

I'm sure the lads that spent decades in Guantanamo with no charges brought against them after being kidnapped based on their watch model will be very glad to hear they have civil rights.

Re: Unveiling secrets of the ESP32: creating an open-source MAC layer

#124
> 50000 peripheral memory accesses are needed [to initialize the hardware]

Wow, that's a lot. If OP could upload somewhere the list of accesses together with a stack trace for each, I think we could crowd source a rewrite of each function - I'd be willing to bet the vast majority of those are repetitive patterns - ie. 'run this transmission test 1000 times while increasing the power levels each time until the received power = some set value'.

Re: Unveiling secrets of the ESP32: creating an open-source MAC layer

#125
> 50000 peripheral memory accesses are needed

Have you tried just replaying those 50,000 accesses and seeing if things work? Obviously some things might not be correctly calibrated, but merely knowing that a simple replay works tells you that there are no complex hardware/software handshakes (ie. Take random token from here and write it to there). It also tells you that the process is probably fairly timing independent.

Re: Unveiling secrets of the ESP32: creating an open-source MAC layer

#126

Earlier quoted context omitted.

Wifi is easy... there's no way to send anything undetected, since you control the routers, etc. GSM->5G modems are a lot harder to debug... maybe now in recent years with cheaper SDRs, but a lot harder then wifi. And not sure why you'd be afraid of CCP, we saw the wikileaks, USA does a lot of similiarly bad stuff too and even got caught doing it... and if you live in a "western" country, USA has much easier access to…

You are assuming you have full insight into what the board is capable of.

What part don't I have insight into? At least the parts that could be exploited by china in some way that would affect me, and couldn't be detected?

Re: Unveiling secrets of the ESP32: creating an open-source MAC layer

#127

The section on trying to attenuate outside wifi signals interested me. There is a bunch of hand wavy information on building faraday cages online, some people suggesting to utilize a microwave oven, since they operate at the same frequency. There are even wifi faraday cages for sale on amazon. However I can't really find much actual benchmark data online about how well these various approaches actually attenuate sign…

A microwave oven is an excellent (30-40dB) attenuator specifically around 2.4GHz. The legal requirements essentially mandate 30dB + manufacturing safety margin. Your mileage will vary for other frequencies, as they're not actually faraday cages, so it's usually easier to simply use aluminum foil or a copper mesh/PVC box depending on your needs.

Thing is, 30-40dB is not sufficient to properly block wireless connections, they can still work with 40dB attenuation.

Re: Unveiling secrets of the ESP32: creating an open-source MAC layer

#128

What kind of programmer does one need to work with ESP32? I bought jlink for stm32 thinking that's the ultimate programmer for all my needs, however it does not claim compatibility with esp32.

The commonly used cheap devboards have everything included on the board, you just plug in USB and that's all you need.

There are also 'premium' devkits with smaller and nicer packaging e.g. I like m5 devkits that are inch-by-inch-by-halfinch blocks at $7.5 for https://docs.m5stack.com/en/core/AtomS3%20Lite or with an integrated screen for $15.5 https://shop.m5stack.com/products/atoms3-dev-kit-w-0-85-inch... is useful for visual feedback.

Re: Unveiling secrets of the ESP32: creating an open-source MAC layer

#129

Earlier quoted context omitted.

It's not whatboutism when there's literally no proof that they are doing mass dragnet spying on western residents. And when we do have tons of proof of western governments doing exactly just that Again, it's a trendy buzzword to use but it literally isn't a catch all shield to argue that it's fine when we do it. When there's no proof of something happening, maybe we should focus on the thing that we know is happening…

1) The activities of the US gov't have precisely nothing to do with the probability that a device from China has some backdoor or surveillance function. When someone raises this concern, the response "the USA has a history of surveiling its citizens" is not a rebuttal, it's irrelevant. Thus a whataboutism. 2) Your burden of proof might be different from mine, but one needs to be pretty naive to think that the CCP doe…

So, usa was "proven" (well.. data was leaked and believed by many to be true) to be spying on many people, both local to US and foreign... and for china, all you have is "you're naive, if you don't think they doo it too".

So, you don't mind being spied on by someone who was already caught spying on their own citizens, (assuming that you're from USA), has access to you, your finances, can lock you up, can suicide you in jail, etc., but you're afraid of china who has access to none of those powers?

Re: Unveiling secrets of the ESP32: creating an open-source MAC layer

#130

Earlier quoted context omitted.

Wifi is easy... there's no way to send anything undetected, since you control the routers, etc. GSM->5G modems are a lot harder to debug... maybe now in recent years with cheaper SDRs, but a lot harder then wifi. And not sure why you'd be afraid of CCP, we saw the wikileaks, USA does a lot of similiarly bad stuff too and even got caught doing it... and if you live in a "western" country, USA has much easier access to…

> And not sure why you'd be afraid of CCP, we saw the wikileaks, USA does a lot of similiarly bad stuff... I find little solace in this whataboutism.

Op above me was bothered with the company being chinese, and I was pointing out the hypocracy because the chinese didn't get caught at a level nearly as bad as US did with wikileaks and that for most people in the west, it's better that the chinese find out that you did something bad than if your own intelligence agencies find out.
Post reply on HN