logoalt Hacker News

Klaus23today at 12:05 PM2 repliesview on HN

Why think so small? Perhaps the speaker itself can be used as the attacker.

Any script kiddie with an LLM could write a worm that would spread through the supply chain, possibly even hacking speakers right on the factory floor and blasting Rickroll music or something similar.

It would be interesting to see if Creative would still claim that it "does not present a cybersecurity risk".

Edit: Bonus points for closing the security hole and disabling the ability to flash the firmware normally, so that the manufacturer would have to jailbreak the speakers in order to repair them.


Replies

niccetoday at 12:31 PM

> Any script kiddie with an LLM could write a worm that would spread through the supply chain, possibly even hacking speakers right on the factory floor and blasting Rickroll music or something similar.

At least used to. SOTA models are enrolling even bigger restrictions all the time and deprecating old models, while asking government IDs.

show 1 reply
cluckindantoday at 12:10 PM

Flash worm into device and RMA it. Boom.

show 1 reply