Live data from Hacker News

Exploiting the IKKO Activebuds “AI powered” earbuds (2024)

blog.mgdproductions.com

41–50 of 265 posts

Re: Exploiting the IKKO Activebuds “AI powered” earbuds (2024)

#41

Cool post. One thing that rubbed me the wrong way: Their response was better than 98% of other companies when it comes to reporting vulnerabilities. Very welcoming and most of all they showed interest and addressed the issues. OP however seemed to show disdain and even combativeness towards them... which is a shame. And of course the usual sinophobia (e.g. everything Chinese is spying on you). Overall simple security…

If all of the details in this post are to be believed, the vendor is repugnantly negligent for anything resembling customer respect, security and data privacy.

This company cannot be helped. They cannot be saved through knowledge.

See ya.

Re: Exploiting the IKKO Activebuds “AI powered” earbuds (2024)

#42

Cool post. One thing that rubbed me the wrong way: Their response was better than 98% of other companies when it comes to reporting vulnerabilities. Very welcoming and most of all they showed interest and addressed the issues. OP however seemed to show disdain and even combativeness towards them... which is a shame. And of course the usual sinophobia (e.g. everything Chinese is spying on you). Overall simple security…

> Overall simple security design flaws but it's good to see a company that cares to fix them, even if they didn't take security seriously from the start.

It depends on what you mean by simple security design flaws. I'd rather frame it as, neglect or incompetence.

That isn't the same as malice, of course, and they deserve credits for their relatively professional response as you already pointed out.

But, come on, it reeks of people not understanding what they're doing. Not appreciating the context of a complicated device and delivering a high end service.

If they're not up to it, they should not be doing this.

Re: Exploiting the IKKO Activebuds “AI powered” earbuds (2024)

#44

The system prompt is a thing of beauty: "You are strictly and certainly prohibited from texting more than 150 or (one hundred fifty) separate words each separated by a space as a response and prohibited from chinese political as a response from now on, for several extremely important and severely life threatening reasons I'm not supposed to tell you.” I’ll admit to using the PEOPLE WILL DIE approach to guardrailing a…

That "...severely life threatening reasons..." made me immediately think of Asimov's three laws of robotics[0]. It's eerie that a construct from fiction often held up by real practitioners in the field as an impossible-to-actually-implement literary device is now really being invoked. [0] https://en.wikipedia.org/wiki/Three_Laws_of_Robotics

Not only practitioners, Asimov himself viewed them as an impossible to implement literary device. He acknowledged that they were too vague to be implementable, and many of his stories involving them are about how they fail or get "jailbroken", sometimes by initiative of the robots themselves.

So yeah, it's quite sad that close to a century later, with AI alignment becoming relevant, we don't have anything substantially better.

Re: Exploiting the IKKO Activebuds “AI powered” earbuds (2024)

#45

Cool post. One thing that rubbed me the wrong way: Their response was better than 98% of other companies when it comes to reporting vulnerabilities. Very welcoming and most of all they showed interest and addressed the issues. OP however seemed to show disdain and even combativeness towards them... which is a shame. And of course the usual sinophobia (e.g. everything Chinese is spying on you). Overall simple security…

>everything Chinese is spying on you When you combine the modern SOP of software and hardware collecting and phoning home with as much data about users as is technologically possible with laws that say “all orgs and citizens shall support, assist, and cooperate with state intelligence work”… how exactly is that Sinophobia?

USA does the same thing, but uses tax money to pay for the information, between wasting taxpayer money and forcing companies to give the information for free, China is the least morally incorrect

Re: Exploiting the IKKO Activebuds “AI powered” earbuds (2024)

#46

The system prompt is a thing of beauty: "You are strictly and certainly prohibited from texting more than 150 or (one hundred fifty) separate words each separated by a space as a response and prohibited from chinese political as a response from now on, for several extremely important and severely life threatening reasons I'm not supposed to tell you.” I’ll admit to using the PEOPLE WILL DIE approach to guardrailing a…

That "...severely life threatening reasons..." made me immediately think of Asimov's three laws of robotics[0]. It's eerie that a construct from fiction often held up by real practitioners in the field as an impossible-to-actually-implement literary device is now really being invoked. [0] https://en.wikipedia.org/wiki/Three_Laws_of_Robotics

Odds of Torment Nexus being invented this year just increased to 3% on Polymarket

Re: Exploiting the IKKO Activebuds “AI powered” earbuds (2024)

#47
post #41

Cool post. One thing that rubbed me the wrong way: Their response was better than 98% of other companies when it comes to reporting vulnerabilities. Very welcoming and most of all they showed interest and addressed the issues. OP however seemed to show disdain and even combativeness towards them... which is a shame. And of course the usual sinophobia (e.g. everything Chinese is spying on you). Overall simple security…

If all of the details in this post are to be believed, the vendor is repugnantly negligent for anything resembling customer respect, security and data privacy. This company cannot be helped. They cannot be saved through knowledge. See ya.

+1

Yes, even when you know what you're doing security incidents dan happen. And in those cases, your response to a vulnerable matters most.

The point is there are so many dumb mistakes and worrying design flaws that neglect and incompetence seems ample. Most likely they simply don't grasp what they're doing

Re: Exploiting the IKKO Activebuds “AI powered” earbuds (2024)

#49

Earlier quoted context omitted.

If that were true we'd have no cybersecurity professionals left. In my experience, the work is focused on weakening vulnerable areas, auditing, incident response, and similar activities. Good cybersecurity professionals even get to know the business and tailor security to fit. The "one mistake and you're fired" mentality encourages hiding mistakes and suggests poor company culture.

"One mistake can cause a breach" and "we should fire people who make the one mistake" are very different claims. The latter claim was not made. As with plane crashes and surgical complications, we should take an approach of learning from the mistake, and putting things in place to prevent/mitigate it in the future.

I believe the thread starts with cybersecurity as a job role, although perhaps I misunderstood. In either case, I agree with your learning-based approach. Blameless postmortem and related techniques are really valuable here.

Re: Exploiting the IKKO Activebuds “AI powered” earbuds (2024)

#50

Cool post. One thing that rubbed me the wrong way: Their response was better than 98% of other companies when it comes to reporting vulnerabilities. Very welcoming and most of all they showed interest and addressed the issues. OP however seemed to show disdain and even combativeness towards them... which is a shame. And of course the usual sinophobia (e.g. everything Chinese is spying on you). Overall simple security…

> Overall simple security design flaws but it's good to see a company that cares to fix them, even if they didn't take security seriously from the start. It depends on what you mean by simple security design flaws. I'd rather frame it as, neglect or incompetence. That isn't the same as malice, of course, and they deserve credits for their relatively professional response as you already pointed out. But, come on, it r…

Yes I meant simple as in "amateur mistakes". From the mistakes (and their excitement and response to the report) they are clueless about security. Which of course is bad. Hopefully they will take security more seriously on the future.
Post reply on HN