Live data from Hacker News

ESP32 Undocumented Bluetooth Commands: Clearing the Air

developer.espressif.com

91–92 of 92 posts

Re: ESP32 Undocumented Bluetooth Commands: Clearing the Air

#91
post #78

Earlier quoted context omitted.

What is CE?

https://europa.eu/youreurope/business/product-requirements/l... Like FCC with extras but for the European region.

I find it odd that the CE marking doesn't come with anything that also uniquely identifies the source company, product or SKU the way that an FCC ID does, it means it's impossible to determine if a CE mark is real or not.

Re: ESP32 Undocumented Bluetooth Commands: Clearing the Air

#92
post #29

Earlier quoted context omitted.

It was both, tbh. These commands would be usable in some attacks against a “trusted” esp32 implementation. It’s something they probably should allow developers to disable but it’s also being WILDLY overstated by clout seekers. You can, from some angles, call this a security flaw or issue. Anyone calling it a backdoor - a term with a specific meaning intentional secret access - is being irresponsible imho

We are talking about a programable device used as a programable device by hobbyists and device manufacturers to make things that you need to program to do something. It’s no different to trying to claim a PC has a security problem because you can load software onto it to do bad things.

Fwiw I’m referring to “trusted” as a specific use case using specific features. Most users won’t use those features. For those that do, this is a big game over. Although some do this, the platform was never well suited to it anyways.

I think we both agree, this “vulnerability” is overstated.

Post reply on HN