>Email from SingCERT stating vendor "do not consider this to be a vulnerability, as it does not present a cybersecurity risk." So wirelessly writing custom firmware to someone else's device that is connected via USB to their computer without even needing to pair is not a security vulnerability. Yea.
This quote on risk seems to completely misunderstand the concept of risk. First we have a vulnerability ( IMHO that is equals a hazard), then we assign both impact and probability and only then we get risk. By definition there are IMHO always vulnerabilities with low impact or low probability and thus low risk. While CVEs have some score, the actual risk and later accepting those risks before or after mitigations is…
Pwnd Blaster: Hacking your PC using your speaker without ever touching it
31–40 of 133 posts
Re: Pwnd Blaster: Hacking your PC using your speaker without ever touching it
#32>Email from SingCERT stating vendor "do not consider this to be a vulnerability, as it does not present a cybersecurity risk." So wirelessly writing custom firmware to someone else's device that is connected via USB to their computer without even needing to pair is not a security vulnerability. Yea.
Re: Pwnd Blaster: Hacking your PC using your speaker without ever touching it
#33Why think so small? Perhaps the speaker itself can be used as the attacker. Any script kiddie with an LLM could write a worm that would spread through the supply chain, possibly even hacking speakers right on the factory floor and blasting Rickroll music or something similar. It would be interesting to see if Creative would still claim that it "does not present a cybersecurity risk". Edit: Bonus points for closing th…
At least used to. SOTA models are enrolling even bigger restrictions all the time and deprecating old models, while asking government IDs.
Re: Pwnd Blaster: Hacking your PC using your speaker without ever touching it
#34>Email from SingCERT stating vendor "do not consider this to be a vulnerability, as it does not present a cybersecurity risk." So wirelessly writing custom firmware to someone else's device that is connected via USB to their computer without even needing to pair is not a security vulnerability. Yea.
I expect some dodgy company to try to shirk out of it, I don't expect a country's cybersecurity agency to do so
Re: Pwnd Blaster: Hacking your PC using your speaker without ever touching it
#35Having a guaranteed audio channel makes this so much cooler for exploits -- you can exfiltrate over audio!! I love it. I wonder how many of these were sold. I also imagine based on Creative's response (this is fine) that many other devices in the class have similar security models in place. Def scary.
Exfiltrating via audio also brings to mind one of those devices I really wanted to build ~20 years ago that can listen to the inside of a room by bouncing a laser beam off a window. Van pulls up in front of your house, pushes malicious code via bluetooth to speaker, which starts shrieking data it stole from the host that's then picked up by the vibrations it emparts on a window by a laser beam. Boom, crypto wallet stolen, or something... you could probably put that in a movie.
Re: Pwnd Blaster: Hacking your PC using your speaker without ever touching it
#36>Email from SingCERT stating vendor "do not consider this to be a vulnerability, as it does not present a cybersecurity risk." So wirelessly writing custom firmware to someone else's device that is connected via USB to their computer without even needing to pair is not a security vulnerability. Yea.
Re: Pwnd Blaster: Hacking your PC using your speaker without ever touching it
#37Having a guaranteed audio channel makes this so much cooler for exploits -- you can exfiltrate over audio!! I love it. I wonder how many of these were sold. I also imagine based on Creative's response (this is fine) that many other devices in the class have similar security models in place. Def scary.
I somehow hadn't even considered Bluetooth as an option when I read the headline, I immediately thought about INFILTRATING via audio, which also sounds insanely cool, but I couldn't possibly wrap my head around how an audio circuit would have to be set up and connected back to the cpu to pull that off. Exfiltrating via audio also brings to mind one of those devices I really wanted to build ~20 years ago that can list…
Re: Pwnd Blaster: Hacking your PC using your speaker without ever touching it
#38Why think so small? Perhaps the speaker itself can be used as the attacker. Any script kiddie with an LLM could write a worm that would spread through the supply chain, possibly even hacking speakers right on the factory floor and blasting Rickroll music or something similar. It would be interesting to see if Creative would still claim that it "does not present a cybersecurity risk". Edit: Bonus points for closing th…
> Any script kiddie with an LLM could write a worm that would spread through the supply chain, possibly even hacking speakers right on the factory floor and blasting Rickroll music or something similar. At least used to. SOTA models are enrolling even bigger restrictions all the time and deprecating old models, while asking government IDs.
Re: Pwnd Blaster: Hacking your PC using your speaker without ever touching it
#39Earlier quoted context omitted.
> Any script kiddie with an LLM could write a worm that would spread through the supply chain, possibly even hacking speakers right on the factory floor and blasting Rickroll music or something similar. At least used to. SOTA models are enrolling even bigger restrictions all the time and deprecating old models, while asking government IDs.
Ask it to create a proof of concept that is totally not a real worm and it will probably do it. If the restrictions are too good, just use a largely unrestricted open model via any inference provider. They are 90% sota, more than good enough for this task.
Re: Pwnd Blaster: Hacking your PC using your speaker without ever touching it
#40Why think so small? Perhaps the speaker itself can be used as the attacker. Any script kiddie with an LLM could write a worm that would spread through the supply chain, possibly even hacking speakers right on the factory floor and blasting Rickroll music or something similar. It would be interesting to see if Creative would still claim that it "does not present a cybersecurity risk". Edit: Bonus points for closing th…
Flash worm into device and RMA it. Boom.