8 ms·
I wasnt aware of this wifi blob. This feeds a tiny paranoia I have at the back of my head when dealing with esp32/espressif. I have dozens of esp32s around and
by finnjohnsen2 3y ago
I wasnt aware of this wifi blob. This feeds a tiny paranoia I have at the back of my head when dealing with esp32/espressif. I have dozens of esp32s around and I love them, but Espressif is 100% Chinese.
Im uncomfortable with what I read that every company of significant size in China automatically requires CCP party members to be involved in the company at a high level.
So Im very happy to hear people such as these guys are looking deep at this.
Ofcourse since Espressif controls the hardware, so they can do anything eventually. My itch will always be there and Im going to switch once I find something made in preferably the EU when I find something comparable to esp32. Maybe Nordic Semiconductors will make some nice risk-v chips and dev-boards soon.
- ajsnigrutin 3y agoWifi is easy... there's no way to send anything undetected, since you control the routers, etc. GSM->5G modems are a lot harder to debug... maybe now in recent years with cheaper SDRs, but a lot harder then wifi. And not sure why you'd be afraid of CCP, we saw the wikileaks, USA does a lot of similiarly bad stuff too and even got caught doing it... and if you live in a "western" country, USA has much easier access to you than China.
- jacquesm 3y agoYou are assuming you have full insight into what the board is capable of.
- ajsnigrutin 3y agoWhat part don't I have insight into? At least the parts that could be exploited by china in some way that would affect me, and couldn't be detected?
- jacquesm 3y agoGoogle 'the thing' and tell me that you could have predicted what it was and how it worked. Hardware is finicky in that way: you look at one thing it can be quite another.
- jszymborski 3y ago> And not sure why you'd be afraid of CCP, we saw the wikileaks, USA does a lot of similiarly bad stuff... I find little solace in this whataboutism.
- mardifoufs 3y agoIt's not whatboutism when there's literally no proof that they are doing mass dragnet spying on western residents. And when we do have tons of proof of western governments doing exactly just that Again, it's a trendy buzzword to use but it literally isn't a catch all shield to argue that it's fine when we do it. When there's no proof of something happening, maybe we should focus on the thing that we know is happening instead of chasing literal ghosts
- jszymborski 3y ago1) The activities of the US gov't have precisely nothing to do with the probability that a device from China has some backdoor or surveillance function. When someone raises this concern, the response "the USA has a history of surveiling its citizens" is not a rebuttal, it's irrelevant. Thus a whataboutism. 2) Your burden of proof might be different from mine, but one needs to be pretty naive to think that the CCP doesn't surveil western citizens. I doubt their intelligence apparatus is that bad at their job. In fact, I have plenty of reason to believe it's pretty great at it. [0] https://www.csis.org/analysis/how-chinese-communist-party-uses-cyber-espionage-undermine-american-economy https://www.csis.org/analysis/how-chinese-communist-party-us... [1] https://foreignpolicy.com/2023/04/27/china-ccp-spying-us-police-stations-influence-operations/ https://foreignpolicy.com/2023/04/27/china-ccp-spying-us-pol...
- rowanG077 3y ago1) of course it does. This is an information cold war. If participant 1 is doing something then participant 2 is forced to do at least the same thing so as to ensure they don't fall behind. It's very naive to not expect the actions of one state to not affect the actions of the other.
- simondotau 3y agoThere’s no point having a vague Chinese back door in Espressif devices which security researchers could discover with relative ease. The remarkable prevalence of these chips in commodity consumer goods means that they’ve likely already been analysed by countless world governments and strategic enterprises. If the IoT ecosystem has any weak spots, it is the Tuya software stack. It would be much easier, much more useful layer to put a back door into that.
- asylteltine 3y agoI restrict my esps to local network only absolutely no internet access for them. No trust for Chinese products from Chinese companies
- tredre3 3y ago> No trust for Chinese products from Chinese companies That's fair but Espressif is wayyyyyyy more open than ANY Western chip maker. The entire framework and toolchains are open-source for one thing. You get listings and sometimes pseudo-code for the internal ROMs (though no code). You get full access to datasheets, technical reference, and sdk documentation. Everything in their SDK is documented. You even get help on github. All of that accessible to anyone anywhere at any time. Contrast that to the last time I worked with Nordic in a professional manner, I had to sign NDAs to get the full documentation and toolchain. Their toolchain contained binary blobs that when inquired about you get told "don't worry about it ;)" which is shockingly frustrating when a crash occurs in them and you're left trying to work around it. And if you're not a professional you're basically SOL and left with half-baked community toolchains, when they exist for a particular chip.
- crote 3y agoIf I'm not mistaken a very significant part of that is due to hobbyist interest in the chips, not in the least by Sprite_tm (also a HN user, now employed by Espressif). The ESP8266 essentially started out as a wifi modem, responding to AT commands transmitted over serial, but going from there to a full standalone device relied on a lot of work by enthusiasts[0] and a leaked proprietary SDK[1]. [0]: https://hackaday.com/2014/09/06/the-current-state-of-esp8266-development/ https://hackaday.com/2014/09/06/the-current-state-of-esp8266... [1]: https://tweakers.net/reviews/7992/community-interview-sprite_tm-van-elektronicamodder-tot-engineer-in-shanghai.html https://tweakers.net/reviews/7992/community-interview-sprite...
- dromtrund 3y ago> Contrast that to the last time I worked with Nordic in a professional manner, I had to sign NDAs to get the full documentation and toolchain That has to be at least 5 years ago, but even back then, 99% of their software was out in the open. Now, their SDK is open source, their official toolchain is based on the Linux Foundation's Zephyr toolchain and their docs are open and buildable. Their support is done on an open forum and complete data sheets are available both as PDFs and (with the exception of the nRF51) as web pages. They aren't allowed to publish their LTE stack because of operator licensing, their Bluetooth link layer is still distributed as a library and some upcoming SoCs aren't publicly available yet, but aside from this, they're as open as they can possibly be.
- 2Gkashmiri 3y agoLol. The Chinese fud is pretty hard. Do you know about this https://www.swisscommunity.org/en/news-media/swiss-review/article/the-cia-used-a-swiss-company-to-spy-on-over-100-countries https://www.swisscommunity.org/en/news-media/swiss-review/ar... https://www.reuters.com/technology/cybersecurity/governments-spying-apple-google-users-through-push-notifications-us-senator-2023-12-06/ https://www.reuters.com/technology/cybersecurity/governments... So... you are basing your fears on just that, hunches and yet presumably your own government is spying on others and maybe you but that doesnt bother you because USA /five eyes are the "good guys"
- halJordan 3y agoThats a false dichotomy, a false equivalence- it's just a lot of false stuff
- 2Gkashmiri 3y agowhat is false?
- mardifoufs 3y agoHow are the two not equivalent? If anything, for anyone living in the west it's probably less of an issue to have China spy on them than a western government. Sure, at a state security level it's not but for regular individuals I sure would rather have China spy on me since they can't do anything to me directly.
- deleted 3y ago[deleted]
- lannisterstark 3y agoYou have at least some civil rights in those countries, you don't in China. Be careful of a layover.
- mardifoufs 3y ago
- RF_Savage 3y agoIt is because of FCC certification requirements. Usually, if the end user can modify the lowlevel radio firmware on the device, the device looses it's FCC certification and cannot be sold in USA. It also seems that Espressif has bought their wifi IP, so their contracts and licensing terms with the IP vendor likely prevent any sharing. But FCC is the reason for closed binary blob firmware for all wifi radios out there these days.
- dariosalvi78 3y agoI don't understand how the license affects certification TBH. As this post clearly shows users can implement their own stack if they really want to, it's not that the license is going to prevent them. Why can't one have an open source stack with specific builds that are approved, tested and certified?
- RF_Savage 3y agoThey could, but somebody would have to write that FOSS wifistack. You could not run selfcompiled versions of the stack on any hardware that has been FCC certified, because if you could, the certs would be gone once again. Wifi is shared spectrum and devices using are licenced to make sure they conform to the local regulations. One size does not fit all. For example 2.4GHz wifi channel 13 is legal in EU, but in USA it falls on a govt owned band. This is why companies like Mikrotik or Ubiquiti have specific hardware versions for USA. So that they verifiably cannot be set on illegal channels by the enduser.
- wkat4242 3y agoIs that really why? I know many devices where I can just set whatever country I want :) This is handy sometimes because in the EU it's the opposite, the 5 and 6 GHz bands are much smaller.
- dariosalvi78 3y agoSo it's perfectly feasible to have an open source Wifi, or Bluetooth or any other RF, stack, but only certain compiled versions are actually certified. I understand that the openness in this case would be limited: you lose the freedom to modify and run the software as you wish (unless you want to risk to break the law), but you can still help bugfix, improve the software and verify that there no backdoors / spying features. The reason sometimes given by vendors that "FCC demands the code to be proprietary" is an excuse.
- DeathArrow 3y agoI would rather have CCP listen than other parties. I am not a Chinese citizen, so I don't care.
- DeathArrow 3y agoI use a Chinese phone with a Chinese ROM. I installed Google service as apps, with limited permissions. I'd rather have Uncle Xi listening than Uncle Sam.
- 123pie123 3y agoyou're either very naive or a pro-china supporter
- boffinAudio 3y agoYour paranoia about the Chinese is equally applicable to Americans, whose NSA has given itself carte-blanche to infiltrate any computing system it desires, for whatever reason, in total secrecy - without recourse for the public to address any wrongs. So I'm not sure that framing your paranoia in terms of "the Chinese" is productive - you might just want to update that thought with "any state actor who operates covert torture sites and violates human rights at immense scale", in which case your set of actually hostile actors becomes a little more realistic. The biggest threat to your freedom and human rights, as an American, is your own government.
- hmottestad 3y agoI think that US agencies are not as interested in stealing trade secrets or harming US companies as other countries would be.
- boffinAudio 3y agoI think that is a very, very naive point of view. There are countless examples of this happening - probably they're not on your radar because your nation was the recipient of the stolen goods .. The USA regularly uses its intelligence apparatus to undermine economy and industry in other countries. I would even say, at a far greater rate, with worse results (for the targets) than anything China or Russia are doing .. The mass violation of human rights for billions of people (literally) that occurs every millisecond of the day at Pine Gap on behalf of the American government, for example, demonstrates that this naivete is very, very dangerous.
- hmottestad 3y ago> The USA regularly uses its intelligence apparatus to undermine economy and industry in other countries. I would even say, at a far greater rate, with worse results (for the targets) than anything China or Russia are doing .. This was my point. How often does it use its power to undermine the US economy or industry in the US?
- p_l 3y ago
- brunohaid 3y ago> Maybe Nordic Semiconductors will make some nice risk-v chips and dev-boards soon. They are, not as CPU necessarily but for exactly those auxiliary functions: https://blog.nordicsemi.com/getconnected/why-nordic-is-getting-involved-in-risc-v?hs_amp=true https://blog.nordicsemi.com/getconnected/why-nordic-is-getti...
- deegone 3y agohttps://www.businesstimes.com.sg/events-awards/singapore-business-awards/singapore-business-awards-2023/singapores-007-who-took https://www.businesstimes.com.sg/events-awards/singapore-bus... Learn more about Espressif's founder. And I think the CCP party cannot impact Espressif. ------- Singapore’s bilingual education gave the engineer an adequate command of Chinese; he played translator for his Chinese and non-Chinese speaking staff in meetings during Espressif’s early days. And the time he spent in national service with the Singapore Armed Forces taught him the importance of being in the front line, of knowing the ground well. The CEO believes that entrepreneurship cannot be taught. One needs to have a head for risk-taking, creativity, a big-picture perspective, and to be prepared to fail. And passion, of course. He has a nugget of wisdom for those who have yet to find theirs: “There are two things that drive people... One is passion, the other is fear... If you lose that fear, you might find your passion.”
- 127361 3y agoSome old Realtek switch chips featured a protocol called RRCP[1] where you could write to the hardware registers using a specific type of Ethernet frame. So I guess a CCP-designed backdoor would probably detect a specially encrypted WiFi packet and allow then internal memory of the device to be written/read over the air. The key would be hardwired into the chip, part of the random logic - so there will be no visible block to identify on visual inspection of the die. Or more subtly they could insert (or just not fix) a bug which allows packet descriptors to be overwritten on reception of a certain malformed WiFi packet, e.g. too short or long, which makes it possible to overwrite regions of the device's memory and thus compromise it. A SDR might be required to transmit the malformed packet(s). By the way, I wonder if modern Realtek switch chips might still support RRCP, and an undocumented EEPROM bit or strapping resistor might re-enable it? 1. https://en.wikipedia.org/wiki/Realtek_Remote_Control_Protocol https://en.wikipedia.org/wiki/Realtek_Remote_Control_Protoco...
- BertoldVdb 3y agoMany modern Realtek chips still support RRCP. You just need to enable it. For example for RTL8370N: Register 0x18d6 configures the 16-bit key, 0x18d4 selects which ports can use it (0xFF for all, normally only the cpu port), 0x18d3=0x1 enables it. You can write these registers via the management interface or via the EEPROM. It will not respond to discovery packets, but get and set packets work fine. This chip also has a 8051 core that can access the internal bus and can tx/rx network packets. To use it you either attach external SPI flash (large program) or write the program into the internal RAM in the chip (small program). All documented stuff, no secret details.
- 127361 3y agoThanks for that, I wonder how many switches out there have it enabled inadvertently, because of a mistake by the manufacturer? By the way, Some of the Broadcom chips have an integrated 8051, with on-chip ROM firmware. There are leaked datasheets floating around somewhere as well. If someone has the time to dump the on-chip ROM, it would be interesting to see what's in there. Note, some of the pins marked NC in the datasheet are in fact the 8051 UART TX/RX lines.
- fennecbutt 3y agoTbf I think China is more interested in the money espressif makes than anything like spying. Because they'd be so easily caught out by anyone with a decent router. And if they ever happened then the whole company would be gibbed.