home.social

#tarlogicsecurity — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #tarlogicsecurity, aggregated by home.social.

fetched live
  1. It's easy to get scared when headlines combine terms like "backdoor", "Bluetooth", and "a billion devices".

    Should you be worried? No.

    The "attack" for ESP32 chips in some Internet of Things devices is some undocumented commands that are likely to be for testing by the manufacturer, Espressif, the in the factory. It cannot spread from one device to another like a virus/worm, and it takes a lot more than being within Bluetooth range -- it requires physical access to I/O pins on the chip itself or access to a USB port (if one is present). That's just the standard way to flash the firmware. It should go without saying that if a malicious person has physical access to the inside of your device then you may have more security concerns.

    It's been fascinating to watch the propagation of fear and misinformation in a niche where I have dabbled enough to develop a bit of technical proficiency.

    My interpretation of events is that Tarlogic Security is spreading panic to gain attention or notoriety.

    Undocumented "backdoor" found in Bluetooth chip used by a billion devices:
    bleepingcomputer.com/news/secu

    NIST (National Institute of Standards and Technology) has a CVE:
    nvd.nist.gov/vuln/detail/CVE-2

    Edit to update:

    Espressif’s Response to Claimed Backdoor and Undocumented Commands in ESP32 Bluetooth Stack
    espressif.com/en/news/Response

    #ESP32 #Espressif #TarlogicSecurity #IoT #InternetOfThings

  2. It's easy to get scared when headlines combine terms like "backdoor", "Bluetooth", and "a billion devices".

    Should you be worried? No.

    The "attack" for ESP32 chips in some Internet of Things devices is some undocumented commands that are likely to be for testing by the manufacturer, Espressif, the in the factory. It cannot spread from one device to another like a virus/worm, and it takes a lot more than being within Bluetooth range -- it requires physical access to I/O pins on the chip itself or access to a USB port (if one is present). That's just the standard way to flash the firmware. It should go without saying that if a malicious person has physical access to the inside of your device then you may have more security concerns.

    It's been fascinating to watch the propagation of fear and misinformation in a niche where I have dabbled enough to develop a bit of technical proficiency.

    My interpretation of events is that Tarlogic Security is spreading panic to gain attention or notoriety.

    Undocumented "backdoor" found in Bluetooth chip used by a billion devices:
    bleepingcomputer.com/news/secu

    NIST (National Institute of Standards and Technology) has a CVE:
    nvd.nist.gov/vuln/detail/CVE-2

    Edit to update:

    Espressif’s Response to Claimed Backdoor and Undocumented Commands in ESP32 Bluetooth Stack
    espressif.com/en/news/Response

    #ESP32 #Espressif #TarlogicSecurity #IoT #InternetOfThings