Backdoor found in ESP32 chips that allow arbitrary memory access and more remotely via Bluetooth

https://www.bleepingcomputer.com/news/security/undocumented-backdoor-found-in-bluetooth-chip-used-by-a-billion-devices/

Reply to this note

Please Login to reply.

Discussion

yikes

Bye bye blockstream Jade

While things like Bluetooth or USB are typically safe, still better to avoid them. That's why I use my Jade in stateless mode, no BT version of the firmware, and via QR.

Stateless Jade is the wtg if you can't build a SeedSigner

True. I forgot about stateless

Safest way for sure

Do you have to flash with special firmware to disable BT completely?

Blockstream Jade now not safe?

In total, they found 29 undocumented commands, collectively characterized as a "backdoor," that could be used for memory manipulation (read/write RAM and Flash), MAC address spoofing (device impersonation), and LMP/LLCP packet injection.

Espressif has not publicly documented these commands, so either they weren't meant to be accessible, or they were left in by mistake.

Lol

Wild times we livin in

"The researchers warned that ESP32 is one of the world's most widely used chips for Wi-Fi + Bluetooth connectivity in IoT (Internet of Things) devices, so the risk of any backdoor in them is significant."

nostr:nevent1qqsyrgqa44ehrz0xxk6xd4vnpxc6knvqksfyjw3p2pjytkeg2edk65cpr4mhxue69uhkummnw3ezucnfw33k76twv4ezuum0vd5kzmp0qgs99d9qw67th0wr5xh05de4s9k0wjvnkxudkgptq8yg83vtulad30grqsqqqqqph4zkjd

Who else uses that chip?

Everyone.

Backdoor found in ESP32 chips that allow arbitrary memory access and more remotely via Bluetooth

https://www.bleepingcomputer.com/news/security/undocumented-backdoor-found-in-bluetooth-chip-used-by-a-billion-devices/

This has "intelligence" agency written all over it, and given the 2014 WikiLeaks revelations, guaranteed to be supply chain attacked into most consumer products.

It can be safely assumed that most peoprietary chips have backdoors used by terrorist "intelligence" agencies such as the NSA and CIA, this one just happened to be discovered.

nostr:nevent1qqsyrgqa44ehrz0xxk6xd4vnpxc6knvqksfyjw3p2pjytkeg2edk65cprdmhxue69uhhg6r9vehhyetnwshxummnw3erztnrdakj7q3q2262qa4uhw7u8gdwlgmntqtv7aye8vdcmvszkqwgs0zchel6mz7sxpqqqqqqzuwqy6g