Having the firmware image just be a boring old tarball + hash sounds super nice. I wish more devices were this open, and I hope Rode won't see this and decide to lock the firmware upgrades down.
I don't want my audio interface to run SSH (and have some random authorized key added), personally.
My audio interface has SSH enabled by default
91–100 of 106 posts
Re: My audio interface has SSH enabled by default
#92Earlier quoted context omitted.
didn't PS3 have a hardcoded nonce for their ECDSA impl that allowed full key recovery? I would agree that I doubt LLMs let people mount side-channel attacks easily on consumer electronics though.
Yes indeed, that chain of exploits was all software and not hardware. Developed after the Hotz exploit and Sony subsequently shuttering OtherOS. It didn't directly give access to anything however. IIRC they heavily relied on other complex exploits they developed themselves, as well as relying on earlier exploits they could access by rolling back the firmware by indeed abusing the ECDSA implementation. At least, that…
Re: My audio interface has SSH enabled by default
#93Yeah, this is pretty common once a device has any real DSP in it. There's usually some stripped-down Linux on an ARM SoC underneath, and the vendor BSP just happens to ship with sshd on. Not necessarily malice, more like nobody on the audio side really owns the rootfs. The big question is whether it's only listening on the USB-side network, or on the actual LAN. First one is annoying. Second one would actually bother…
Re: My audio interface has SSH enabled by default
#94Earlier quoted context omitted.
> You would have to be a Hotz tier hacker if you wanted to do anything close to this only last year This isn't true at all. Yes, LLMs have made it dramatically easier to analyse, debug and circumvent. Both for people who didn't have the skill to do this, and for people who know how to but just cannot be bothered because it's often a grind. This specific device turned out to be barely protected against anything. No en…
> ... but as there's no complete feedback loop, it still would require a lot of human effort. Not for long. Picture this: a robot receives instructions on what to physically solder in order to complete the desired modification task. However, before it can send an image back to the vision-aware LLM guiding it, the PCB lights on fire along with the robot because said LLM confidently gave the wrong instructions. Then, t…
Re: My audio interface has SSH enabled by default
#95Rode shipping a tarball + hash is great. Just hoping that if they ever do tighten it up, they tighten it in a way that still lets me put whatever I want on a thing I own.
Re: My audio interface has SSH enabled by default
#96The thing I always come back to with this stuff is that "signed firmware" and "open firmware" aren't actually opposites, they just get treated that way. Ship it with verification on by default, fine, but let the owner enroll their own key (or flip a jumper, or hold a button on boot, whatever). Basically nobody does this outside of a couple of Chromebooks and some networking gear, so every conversation about firmware…
1. Allow the user to choose between developer control and owner control, but only at first setup / after a factory reset. This prevents somebody with physical access from easily and covertly installing a backdoor.
2. Have a scary screen on boot announcing that "your device has been hacked", bypassable via a secret combination that isn't displayed on the screen. This isn't a problem for anybody who roots the device themselves, but instantly gives the game away if a third-party messes with it.
Re: My audio interface has SSH enabled by default
#97Re: My audio interface has SSH enabled by default
#98Earlier quoted context omitted.
We don't place any value on the CE mark in the States. A lot of consumer electronics need to be FCC compliant, which involves a process of proving that the device doesn't emit too much of the wrong EMI/RFI in the wrong places. And safety-wise, we use tend to use ETL, UL, and CSA for testing. These are third-party Nationally Recognized Testing Labs, and their own marks are used on devices they approve. But they're onl…
Oh. Sorry. I work for a rather large company that sells globally. In our business unit we always considered the CE mark mandatory. I understand your point though. Of course a US company that is only ever going to sell in the US does not need to bother with international marks.
If my house burns down and a widget with only a CE mark is blamed as the source, my insurance company will consider that to be the equivalent of it having no marking at all.
If a company wants to sell a product globally including the USA, then CE isn't enough to satisfy the safety boffins.
The world is a big place, and the US isn't alone in this way: Lots of other countries also don't care about an isolated CE mark, like Canada and Mexico here in North America.
Some other large, important markets like Japan and Brazil are this way, too.
Acceptance of CE is not universal.
Re: My audio interface has SSH enabled by default
#99Earlier quoted context omitted.
Oh. Sorry. I work for a rather large company that sells globally. In our business unit we always considered the CE mark mandatory. I understand your point though. Of course a US company that is only ever going to sell in the US does not need to bother with international marks.
I'd like to reiterate that a CE mark means nothing to us here. If my house burns down and a widget with only a CE mark is blamed as the source, my insurance company will consider that to be the equivalent of it having no marking at all. If a company wants to sell a product globally including the USA , then CE isn't enough to satisfy the safety boffins. The world is a big place, and the US isn't alone in this way: Lot…
Even things ordered directly from China have a CE mark!
I guess you have never really visited Canada and looked at the marks on the things you use.
And it kind of removes value from your opinion about the other countries of the world. Sorry.
Re: My audio interface has SSH enabled by default
#100Earlier quoted context omitted.
I'd like to reiterate that a CE mark means nothing to us here. If my house burns down and a widget with only a CE mark is blamed as the source, my insurance company will consider that to be the equivalent of it having no marking at all. If a company wants to sell a product globally including the USA , then CE isn't enough to satisfy the safety boffins. The world is a big place, and the US isn't alone in this way: Lot…
Well... I live in Canada and I have never seen any "modern" electronics around me that does not have the CE mark. Even things ordered directly from China have a CE mark! I guess you have never really visited Canada and looked at the marks on the things you use. And it kind of removes value from your opinion about the other countries of the world. Sorry.
Also, I'd be surprised if all those Chinese devices have actually earned that CE mark.