Readit News logoReadit News
moonsword commented on The Weird BLE-Lock – Hacking Cloud Locks   nv1t.github.io/blog/the-w... · Posted by u/moonsword
stordoff · a year ago
FWIW, there seems to have another attempt (about a year later) to bring these issues to the company's attention, also without success:

> 1st September 2023 - Initial contact - Multiple points of contact within eLinkSmart e-mailed with a high-level description of the issues and proof-of-concept code.

> 19th September 2023 - Follow-up after no response from vendor.

> 11th October 2023 - Follow-up after no response from vendor. Intention to publicise findings communicated.

> 8th December 2023 - Public presentation of findings at BSides London.

> 6th February 2024 - Blog post publication.

https://labs.withsecure.com/publications/elinksmart---unlock...

moonsword · a year ago
Wild, that the SQLi was still there...
moonsword commented on Reverse engineering and dismantling Kekz headphones   nv1t.github.io/blog/kekz-... · Posted by u/mtlynch
yftsui · a year ago
The beginning of the article says the device "work without any internet connection and all of the content already on the headphones itself", then the device needs a Windows application downloads content from the Internet.

I am a bit frustrated as isn't this just an MP3 player playing from SD card but put inside a headphone? Doesn't sound like an invention at all.

moonsword · a year ago
basically yes. it is a prefilled mp3 player with content, which get's activated with nfc chips. You can add custom content for 3 nfc chips with this windows application (or update the pre fillment).

all of this little children audio devices are glorified mp3 players, with encryption inside.

The point is, that most of them don't allow to really "own" the content, like vinyl/tape/cd. they are encrypted, and you only get the encryption key, which is only playable on the device...you buy a license key and not the content.

u/moonsword

KarmaCake day187February 3, 2024View Original