7 ms·
My audio interface has SSH enabled by default
- yonatan8070 6mo agoHaving the firmware image just be a boring old tarball + hash sounds super nice. I wish more devices were this open, and I hope Rode won't see this and decide to lock the firmware upgrades down.
- EvanAnderson 6mo agoIn the off chance anybody from Rode sees this: This makes me want to purchase your gear. Don't change it. It's funny this comes up now. Tomorrow I'm dragging my Zoom R20 recorder on-site to use as an overly-featured USB audio interface for a single-mic live stream. If I'd know this about Rode a week ago I'd have purchased one of these and could have left my R20 hooked-up in the home studio!
- QuantumNomad_ 6mo agoI’m guilty of using my Zoom R16 in a similar fashion; as USB audio interface most of the time for a couple of inputs. The only thing that is a little sad about it is that for example the faders do nothing when the R16 is in USB audio interface mode. It does however like to randomly turn on reverb and one other effect after power cycling. Which I sometimes forget and then wonder for half a second why the audio is sounding weird :P So there is some extra functionality that is available even in USB audio interface mode, although in this case not desirable for me to have enabled within it. If I want to add reverb or other effects when using the R16 as USB audio interface, I prefer to do so in the DAW. I would have liked to be able to use the faders though.
- EvanAnderson 6mo agoInteresting. I'm running my R20 in USB interface / stereo mix mode and the faders do work. I didn't think about trying to apply any effects. I'll play with that, for fun, but I'd definitely add them in the DAW as well. (I really only use my R20 for multitrack recording and do all my effects in the DAW. I like it, and it can do a ton standalone, but my workflow really just needed a multitrack recorder and I could have probably spent a lot less. It just looked like fun...)
- deleted 6mo ago[deleted]
- jasomill 6mo agoFunny you mention that, because my first thought when reading that he submitted a report to the vendor was that they'd "fix" the problem by requiring firmware uploads to be signed (in which case it's "secure" because only their service techs have access to the private key, IOW, security by sternly worded written policy).
- tombert 6mo agoI had to upgrade the firmware in my HP printer a couple years ago. It’s a printer that I think was released in ~2009 (I am not able to check right now), and in order to upgrade the RAM to 256MB I needed to do a firmware update. I dreaded this, but then I found out that all you do to update the firmware was FTP a tarball to the printer over the network. I dropped it in with FileZilla, it spent a few minutes whirring, and my firmware was updated. Then I got mad that firmware updates are ever more complicated than that. Let me FTP or SCP or SFTP a blob there, do a checksum or something for security reasons, and then do nothing else.
- thwarted 6mo agoI think my favorite is wifi access points that support tftp to load a firmware image (with some kind of hardware switch to enable this state). These can be made effective unbrickable and it's really nice for experimenting.
- ssl-3 6mo ago> Let me FTP or SCP or SFTP a blob there, do a checksum or something for security reasons Whose security are we talking about here? Mine, or the manufacturer's?
- jkrejcha 6mo agoI'm not sure if it was what OP meant, but it's arguably a good availability technique (as long as you can generate the checksum, that is). Like, if I want to run custom firmware and flash it, having a checksum which verifies that the firmware isn't corrupted may help prevent bricking.
- ssl-3 6mo agoRight, I'm not sure either. Hence the question. :) Checksums are great for helping to validate data integrity. And data integrity can be related to security. But over the last 25 years or so, I've grown to become pretty averse to phrasing that parse like "for security purposes".
- 6mo ago
- Gigachad 6mo agoI think it should be locked down to require some kind of physical button input to enable the commands, putting it in some kind of "DFU" mode. Otherwise anything with USB access could brick your device by flashing a bad firmware.
- gamerslexus 6mo agoI don't want my audio interface to run SSH (and have some random authorized key added), personally.
- yonatan8070 6mo agoI agree that it shouldn't have SSH enabled, but I do like that the firmware isn't encrypted or signed, so it's not hard to mod it, at no cost to thr manufacturer
- gamerslexus 5mo agoFact.
- Geezus_42 6mo agoJust don't expose it on a public network?
- 9p 6mo agowhy was disclosure the objective? wouldn't you want to keep this interface open?
- hhh 6mo agonot really an objective, I hope RODE continues to keep it open
- vablings 6mo agohttps://github.com/ThomasStolt/Copy-Recordings-Off-Rodecaster-Pro-2 https://github.com/ThomasStolt/Copy-Recordings-Off-Rodecaste... It used to be completely open lol
- EvanAnderson 6mo agoThat's sad.
- serious_angel 6mo ago[flagged]
- hhh 6mo agobecause its fun to tear stuff apart and poke at it, and I am writing to share with people and for fun, not as a business.
- serious_angel 6mo ago[flagged]
- JadeNB 6mo agoYou expressed your opinion once. I think that there's no need to shit on the post again.
- serious_angel 6mo ago[flagged]
- realo 6mo agoI understand the hacker rationale to have fun owning the device, and i would like it to stay that way. But... please do not forget that the CRA will put a heavy blanket on that fire.
- cwillu 6mo agoTLA syndrome strikes again, I have no idea what CRA refers to here.
- throwaway89201 6mo agoCyber Resilience Act [1], which is well-intentioned, and doesn't outright forbid user access to firmware, but most vendors will take the easy road and outright block user-modifiable software (if they didn't already), so that their completely closed source, obfuscated and vulnerable version is the only version allowed on their devices. [1] https://en.wikipedia.org/wiki/Cyber_Resilience_Act https://en.wikipedia.org/wiki/Cyber_Resilience_Act
- kQq9oHeAz6wLLS 6mo agoAh, EU-only. That explains why I've never heard of it, among other things.
- realo 6mo agoWell... if you look behind anything that plugs into a wall socket you will see that it has ( among many other things) a CE mark. Even things in the USofA have a CE mark. If your new product cannot have its CE mark for whatever reason, you will not have the approbations to sell in the USA either. What the CRA will do, is if you do not have a "CRA" compliant product, you will not have the CE mark. Which means you will not (with very high probability) have the other marks needed to sell outside Europe. Maybe then you can just sell to your close family members who like you, but good luck if you get caught and it can be proven that your shitty device caused a fire ...
- rikafurude21 6mo agoIts still crazy to me that everyone has a pocket AI-hacker ready to inspect firmware and modify their devices now. You just put the agent on it and it gives you access in minutes. You would have to be a Hotz tier hacker if you wanted to do anything close to this only last year, or at the very least extremely patient for long hours.
- buildbot 6mo agoThis 1000% - I’ve used AI to enable SSH in one Phase One digital back I own, and to reverse engineer and patch the firmware on another to make the back think it’s a different back - Credo 50 to IQ250! The internals are literally the Sam.
- Almondsetat 6mo agoI'm sorry, are you trusting an LLM to touch a camera that costs like a new car?
- buildbot 6mo agoOnly a little bit of touching for the really expensive one. The Credo 50 was less than 1K though. Also Phase One Support/Repair is absolutely phenomenal and unless you toast the sensor; repairs are “fairly” economical.
- magenta4 6mo ago[dead]
- hhh 6mo agoits really nice to not have to spend hours looking thru packet captures and stuff, i enjoy digging but as i'm getting older I have less time to spend 16 hour days looking at random firmware blobs
- strbean 6mo agoDamn, maybe I can throw an agent at trying to unlock IMEI spoofing on my Unifi LTE modem. That one guy on twitter who does all the LTE modem unlocking never replied to my tweet :(
- montecarl 6mo agoI really want to know how he solved this problem, which I also face: >last year i bought a Rodecaster Duo to solve some audio woes to allow myself and my girlfriend to have microphones to our respective computers when gaming together and talking on discord in the same room without any echo
- hhh 6mo agothe rodecaster can connect to two computers, and we are both generally in the same discord call. so we have both microphones routed into one input for a computer, and the other person joins with their mic muted and the audio just comes from one client. since the mixing is local there's no echo. email me if you have more questions :)
- donatj 6mo agoWhy connect it to both computers?
- ssl-3 6mo agoIt saves on rewiring stuff. Maybe there's only one person talking today. Maybe they're using PC A, or perhaps they're using PC B instead. Or maybe there's two people in the room, each on different channels altogether. In this case the other person is just uncorrelated background noise instead of a persistent echo. Or, in-context: There's two people in the same room, both talking on the same Discord channel. Anyway, audio routing is useful. Being able to route audio with two different PCs is a pretty neat feature of the rodecaster.
- kQq9oHeAz6wLLS 6mo agoNot in the same league or form factor, but I have an old Jabra 65 headset, and the noise canceling is amazing. I can be playing my cello while unmuted on a call, and nobody can hear it. I know headsets aren't everyone's cup of tea, but a mic close to the source (your mouth) with good noise canceling is a solid solution.
- montecarl 6mo ago
- coldcity_again 6mo agoNice writeup and great domain. I don't know Zola and don't know if this is a common template or a custom jobbie but it's lovely.
- bewuethr 6mo agoLooks like the https://www.getzola.org/themes/radion/ https://www.getzola.org/themes/radion/ theme
- userbinator 6mo agoI think "my audio interface is a 64-bit Linux computer" would've sounded far more interesting to me as a title. Perhaps a decade or two ago, the functionality of that device would've likely been implemented on a small 16-bit or 32-bit SoC running an RTOS like VxWorks. Given how many physical controls it has, turning it into a game console seems like a logical next step.
- ssl-3 6mo agoMy audio interface is a Linux computer with FPGAs inside (that actually get field-programmed), with two gigabit Ethernet jacks that each talk to different parts of the machine. But I don't think anyone here would care about that. It's not such an unusual arrangement. I guess it's kind of impressive to use it on my desk at home, but in pro audio world it's actually kind of mundane. Maybe I'll write about it more after I get the gumption to gain a root shell on it (or brick it, whichever comes first). I think you guys might find that part more interesting. :)
- lukeh 6mo agoI’m building an audio device. It runs Linux for the control plane (it’s just a CM4 running Yocto, maybe I’ll leave SSH running on production units, maybe not, haven’t decided yet). No audio passes through the CM4, there’s a dedicated FPGA and MCU for that. It’s been a fun project, first time hardware for me, feel free to ask my anything!
- ssl-3 6mo agoNice! This particular box also has RS-232, ssh (with almost zero auth), and telnet as a control plane, by default. Any of that only gets used to tweak/report various things with a rather basic human-readiable protocol. (It has built-in functions to make it more secure; I just don't care on my home LAN, or on my pop-up LANs in the field. A sane person with a professional role would have it locked down and on its own VLAN/VPN, but for me and prototyping: Telnet is actually pretty good.) I designed none of it. I just bought it, and make good use of it. New, it was a mid-4-digit box; used, they're not so bad. (And I use it every day and like it quite a lot, hence the reluctance to go harder on the potential root shell hack.) My box, as it sits, just does general-purpose GUI-connected DSP stuff with near-realtime tweaking. I'm in the process of getting it to grok OSC, and thus Reaper or whatever, so it has a better control surface for live work. It has a USB interface that my Linux box treats as a sound card, which works well. My main reason for wanting to get root is to examine (solve?) its ~5-minute boot times. 5 minutes in a live sound environment is the difference between having a large, active, and involved crowd, and having everyone get bored and find something else to do. Anyway, the FPGAs here just exist to behave as DSPs and...well, digitally process [audio] signals. It works well; I really just wish it booted faster. And that may be its downfall. :P --- But enough about that. What's your device do? What are your plans and dreams with it? (Do I want one?) I've built a very small amount of hardware. At least at the level of custom PCBs and some code, it's been richly rewarding even when I screw it up, and it makes me feel like I'm on top of the world when I get it right. Can you tell me about your widget?
- mianos 6mo agoGood old local Aussie guys write this. If you had something you wanted to report I'd just give them a call. We almost speak English down here.
- rurban 5mo agoIt's a Sydney company. But parts are now manifactured in China. So who added this backdoor to listen to its customers? The CIA has similar companies doing it over popular loudspeakers. Could also be the Chinese.
- tosti 6mo agoIt runs jack audio. This thing is literally jack in the box!
- ZihangZ 6mo agoYeah, this is pretty common once a device has any real DSP in it. There's usually some stripped-down Linux on an ARM SoC underneath, and the vendor BSP just happens to ship with sshd on. Not necessarily malice, more like nobody on the audio side really owns the rootfs. The big question is whether it's only listening on the USB-side network, or on the actual LAN. First one is annoying. Second one would actually bother me.
- hhh 6mo agoIt is listening on the LAN. It connects over wifi only when you use certain features, so i didn’t test if that interface is listening as well.
- ZihangZ 6mo agoYeah, LAN is the line for me. USB-side sshd is a weird dev leftover; LAN means it’s now in the home threat model.
- surajrmal 6mo agoLinux defaults are unfortunately not great for production of devices of this nature. By comparison, android ships with 3 default image types, eng, userdebug, and user. By creating this system of preconfigured defaults, it makes it easy to avoid this sort of mistake.
- uwagar 6mo agois he happy that rode has an ssh to his device? the guy is like too nice. where's the outrage?
- hhh 6mo agoI would like for SSH to be turned off, but I also like that I can just do that myself. Normally when I look at these devices firmware they’re horrific beasts with insane issues everywhere. This just requires a config change to fix the single thing I don’t like about it. There’s plenty of outrage in the world :)
- dlcarrier 6mo agoHacker News doesn't know what to do with anyone that doesn't think the world is ending and that humanity is inherently evil and must be punished. It's still better than Reddit, though.
- Roark66 6mo agoI think many vendors think security is synonymous with "hard to clone". This us why they require signed images and so on.
- sentinel-safety 6mo ago[dead]
- hoopla_ching 6mo agoThe thing I always come back to with this stuff is that "signed firmware" and "open firmware" aren't actually opposites, they just get treated that way. Ship it with verification on by default, fine, but let the owner enroll their own key (or flip a jumper, or hold a button on boot, whatever). Basically nobody does this outside of a couple of Chromebooks and some networking gear, so every conversation about firmware security ends up being a fight between "lock it down" and "leave it wide open" instead of "let the person who paid for the hardware decide." Rode shipping a tarball + hash is great. Just hoping that if they ever do tighten it up, they tighten it in a way that still lets me put whatever I want on a thing I own.
- miki123211 6mo agoI've said this dozens of times on here, but IMHO the correct solution to this problem is: 1. Allow the user to choose between developer control and owner control, but only at first setup / after a factory reset. This prevents somebody with physical access from easily and covertly installing a backdoor. 2. Have a scary screen on boot announcing that "your device has been hacked", bypassable via a secret combination that isn't displayed on the screen. This isn't a problem for anybody who roots the device themselves, but instantly gives the game away if a third-party messes with it.
- hoopla_ching 5mo agoI like this. The factory-reset gate stops the attack without locking owners out, and the boot warning is basically what Android does with unlocked bootloaders.
- nike-17 6mo ago[flagged]