My audio interface has SSH enabled by default

263 points79 comments17 hours ago
yonatan8070

Having the firmware image just be a boring old tarball + hash sounds super nice. I wish more devices were this open, and I hope Rode won't see this and decide to lock the firmware upgrades down.

show comments
userbinator

I think "my audio interface is a 64-bit Linux computer" would've sounded far more interesting to me as a title. Perhaps a decade or two ago, the functionality of that device would've likely been implemented on a small 16-bit or 32-bit SoC running an RTOS like VxWorks.

Given how many physical controls it has, turning it into a game console seems like a logical next step.

show comments
ZihangZ

Yeah, this is pretty common once a device has any real DSP in it. There's usually some stripped-down Linux on an ARM SoC underneath, and the vendor BSP just happens to ship with sshd on.

Not necessarily malice, more like nobody on the audio side really owns the rootfs.

The big question is whether it's only listening on the USB-side network, or on the actual LAN. First one is annoying. Second one would actually bother me.

show comments
Roark66

I think many vendors think security is synonymous with "hard to clone". This us why they require signed images and so on.

rikafurude21

Its still crazy to me that everyone has a pocket AI-hacker ready to inspect firmware and modify their devices now. You just put the agent on it and it gives you access in minutes. You would have to be a Hotz tier hacker if you wanted to do anything close to this only last year, or at the very least extremely patient for long hours.

show comments
montecarl

I really want to know how he solved this problem, which I also face:

>last year i bought a Rodecaster Duo to solve some audio woes to allow myself and my girlfriend to have microphones to our respective computers when gaming together and talking on discord in the same room without any echo

show comments
coldcity_again

Nice writeup and great domain. I don't know Zola and don't know if this is a common template or a custom jobbie but it's lovely.

show comments
realo

I understand the hacker rationale to have fun owning the device, and i would like it to stay that way.

But... please do not forget that the CRA will put a heavy blanket on that fire.

show comments
9p

why was disclosure the objective? wouldn't you want to keep this interface open?

show comments
mianos

Good old local Aussie guys write this. If you had something you wanted to report I'd just give them a call. We almost speak English down here.

tosti

It runs jack audio. This thing is literally jack in the box!

uwagar

is he happy that rode has an ssh to his device? the guy is like too nice. where's the outrage?

show comments