aMockTie

joined 1 year ago
[–] aMockTie@piefed.world 3 points 1 week ago (1 children)

Oof, as someone who has legitimately struggled with that deeply dark place and thankfully survived multiple attempts, I have a hard time understanding why that subject matter is joke worthy. That's almost certainly a personal problem though.

[–] aMockTie@piefed.world 1 points 2 months ago

"You're the vulnerability"

[–] aMockTie@piefed.world 1 points 2 months ago

I don't understand how this can still happen with a well known brand in 2026. Personally the microphone is the least concerning aspect of this finding, since a Bluetooth connection would still be required. With more dedicated research, the BadUSB aspect is far more concerning in my book. Plug the speaker into a computer, even once and only to charge, and the computer is pwned? Preventing any future patching? I don't know how I could ever trust one of these devices going forward.

[–] aMockTie@piefed.world 3 points 2 months ago (6 children)

Awesome write up.

Allowing arbitrary firmware updates without any signature validation, over Bluetooth, even unpaired and in sleep mode, and without any authentication is absolutely wild and should be criminal negligence.

It took Creative nearly two months to respond to SingCERT. Unfortunately, their response was that "they do not consider this to be a vulnerability, as it does not present a cybersecurity risk"

What a foolish response. The guy wasn't asking for money and gave them everything they would need to make a patched firmware.