Seller of the Sound Blaster Katana V2X doesn’t consider the behavior a vulnerability.

  • A_norny_mousse@piefed.zip
    link
    fedilink
    English
    arrow-up
    53
    arrow-down
    1
    ·
    19 days ago

    “Without being touched” seems unnecessary. That’s one possible definition for computers: completing tasks that do not require manual intervention. Automation.

    BTW the real culprit here isn’t the USB connection but Creative’s proprietary but totally unprotected transfer protocol that allows third parties to communicate with the device both ways, even load new firmware. No code signing there, either.

  • AnAmericanPotato@programming.dev
    link
    fedilink
    English
    arrow-up
    14
    ·
    19 days ago

    It’s just crazy how many Bluetooth devices have broken (or completely absent) authentication and pairing security.

    It’s very difficult to tell when they’re encrypted, too. Your Bluetooth keyboard and mouse could be broadcasting everything keystroke and click unencrypted to anyone within 100m or so.

    And that’s just the accessories. There have been tons of exploits of phone and computer firmware over the years as well. Security is an afterthought at best with Bluetooth.

  • Eideen@lemmy.world
    link
    fedilink
    English
    arrow-up
    6
    arrow-down
    4
    ·
    19 days ago

    Tittel is misleading as this a variant of BadUSB where a device act as keyboard device.

    And i agree and prefer that user is able to replace firmware.