3 ms·
Great. Time to replace half my home automation devices! This is not entirely unexpected, regardless of whether it was intentional or not, but it still hurts. Al
by iamjackg 2y ago
Great. Time to replace half my home automation devices! This is not entirely unexpected, regardless of whether it was intentional or not, but it still hurts. Although I guess it means it might be easier to take control of existing devices without having to open them up and connect to the GPIOs.
I wonder if this is patchable at all?
- sigmoid10 2y agoThis is not a remote exploit. It's not even a backdoor. It's just a bunch of undocumented interface commands that allow access to things like memory. To exploit any of this you need an attacker have physical access or get to run privileged software on the device. In both cases you'd already be totally screwed anyway. This is a clickbait nothingburger and that's the reason why it was presented at a random local conference. An actual backdoor that infects billions of wireless devices would have easily earned you a top presenter spot at a highly prestigious conference.
- iamjackg 2y agoYou're right! It looks like I misunderstood the report and the "hidden opcodes" are only accessible to the ESP32 itself, not to connected devices? The article is somewhat confusingly worded.