Live data from Hacker News

Critical Exploit in MediaTek Wi-Fi Chipsets: Zero-Click Vulnerability

blog.coffinsec.com

21–30 of 109 posts

Re: Critical Exploit in MediaTek Wi-Fi Chipsets: Zero-Click Vulnerability

#23
I would like to remind people of the 2016 Adups backdoor:

> According to Kryptowire, Adups engineers would have been able to collect data such as SMS messages, call logs, contact lists, geo-location data, IMSI and IMEI identifiers, and would have been able to forcibly install other apps or execute root commands on all devices.

https://www.bleepingcomputer.com/news/security/android-adups...

Re: Critical Exploit in MediaTek Wi-Fi Chipsets: Zero-Click Vulnerability

#24

Not too surprising given what I've seen of their vendor sdk driver source code, compared to mt76. (Messy would be kind assessment) Unfortunately, there are also some running aftermarket firmware builds with the vendor driver, due to it having an edge in throughput over mt76. Mediatek and their WiSoC division luckily have a few engineers that are enthusiastic about engaging with the FOSS community, while also maintain…

Why is it so much of this hardware/firmware feels so much like deploying a PoC to production? Why can't they hire someone that actually knows what they are doing?

Hardware companies are bad at making software, and the corollary, software companies are bad at making hardware.

Re: Critical Exploit in MediaTek Wi-Fi Chipsets: Zero-Click Vulnerability

#25

Earlier quoted context omitted.

Why is it so much of this hardware/firmware feels so much like deploying a PoC to production? Why can't they hire someone that actually knows what they are doing?

Hardware companies are bad at making software, and the corollary, software companies are bad at making hardware.

In the middle you have Apple that is getting better at making certain kinds of hardware, worse at some hardware and definitely worse in software.

Re: Critical Exploit in MediaTek Wi-Fi Chipsets: Zero-Click Vulnerability

#26

I've been buying laptops with AMD CPU's but they always come with these trash MediaTek RZ616 Wi-Fi cards, why is that? I've been replacing them with Intel Wi-Fi cards, now I have a pile of RZ616 cards ready to become future microplastics :-(

You know why. Price.

Re: Critical Exploit in MediaTek Wi-Fi Chipsets: Zero-Click Vulnerability

#27

Earlier quoted context omitted.

Why is it so much of this hardware/firmware feels so much like deploying a PoC to production? Why can't they hire someone that actually knows what they are doing?

Hardware companies are bad at making software, and the corollary, software companies are bad at making hardware.

I feel like there's an opportunity for a joke here somewhere along the lines of hardware companies being really terrible at writing software, while software companies being just a normal amount of terrible at writing software.

Re: Critical Exploit in MediaTek Wi-Fi Chipsets: Zero-Click Vulnerability

#28

Earlier quoted context omitted.

Hardware companies are bad at making software, and the corollary, software companies are bad at making hardware.

I feel like there's an opportunity for a joke here somewhere along the lines of hardware companies being really terrible at writing software, while software companies being just a normal amount of terrible at writing software.

A few attempts with chstgpt managed it: "Hardware companies writing software is like watching a train wreck in slow motion. Software companies? They just crash at regular speed."

Re: Critical Exploit in MediaTek Wi-Fi Chipsets: Zero-Click Vulnerability

#29
post #22

Can the OP's link be changed to the original source, not the advertisement it currently links to? The exploit is documented https://blog.coffinsec.com/0day/2024/08/30/exploiting-CVE-20...

I don't think that link is necessarily better just because it's the original source. The linked article gives a concise overview, while the blog post spends the first paragraph talking about moving and starting a new job.

Re: Critical Exploit in MediaTek Wi-Fi Chipsets: Zero-Click Vulnerability

#30

Not too surprising given what I've seen of their vendor sdk driver source code, compared to mt76. (Messy would be kind assessment) Unfortunately, there are also some running aftermarket firmware builds with the vendor driver, due to it having an edge in throughput over mt76. Mediatek and their WiSoC division luckily have a few engineers that are enthusiastic about engaging with the FOSS community, while also maintain…

Why is it so much of this hardware/firmware feels so much like deploying a PoC to production? Why can't they hire someone that actually knows what they are doing?

The consumer space is brutally competitive - you're working on tight margins and designs become obsolete very quickly. MediaTek's business is built on selling chips with the latest features at the lowest possible price. Everything has to be done at a breakneck pace that is dictated by the silicon. You start writing firmware as soon as the hardware design is finalised; it needs to be ready as soon as the chips are ready to ship. These conditions are not at all suited to good software engineering.

In an ideal world, consumers would be happy to pay a premium for a device that's a generation behind in terms of features but has really good firmware. In the real world, only Apple have the kind of brand and market power to even attempt that.

Post reply on HN