Pwn2Roll: Who Needs a 595€ Remote When You Have wheelchair.py?

media.ccc.de

Leaking not released product names via Certificate Transparency logs is apparently still a thing.

Someone did not their "Obacht" they do in other places.

#Pwn2Roll

Apparently folks are now vibe-coding wheelchair control reverse engineering and scripts for accessing config etc.

Including false assumptions, hallucinated constants, inconsistencies across the code base. All the patterns sloppy AI code has.

I just don't understand why. The speed and amount of littering the public internet with barely-working-to-not-working code and docs is scary.

Technical debt as a service.

#Pwn2Roll

Mood: listening carefully to the computer's fans spinning duration and pattern to determine if build of firmware succeeds.

#Pwn2Roll

Funny Bluetooth quirks: holding the ESP32 in your hand's palm increases response time from previously maximum of ~200ms up to nearly two seconds.

But only on the wheelchair drive of both that's farther away from the ESP.

#Pwn2Roll #HackThePlanet

Staring at hexadecimals, Bluetooth LE edition.

#Pwn2Roll

The jadx is doing jadx things again.

#Pwn2Roll

I just posted the script with all the content I intended to talk about in my #39c3 talk last weekend on Github:

https://github.com/roll2own/m5squared-resources/blob/main/39c3-talk/39c3-talk-spoken-text.md

It's a lot of text, but might be a good read and has more context to the history of the source code, the concepts, social/ethic questionability of DRM in mobility aids, etc.

#39c3 #Pwn2Roll

m5squared-resources/39c3-talk/39c3-talk-spoken-text.md at main · roll2own/m5squared-resources

All non-code resources wrt. the Alber e-motion M25 wheelchair drive. Media, documentation, etc. live here. - roll2own/m5squared-resources

GitHub

Since people in the Heise comments are complaining about my English accent and chewing gum: nobody forces anyone to watch the talk. If you want the technical details, look them up in the Github repo.

The incident with the slides right before the talk made me extremely nervous - even more as I'd be before/during giving a talk. I know it's far from perfect. And maybe such dudes should try doing smth. similar, for free and in their free time.

https://www.heise.de/news/39C3-Rollstuhl-Security-Wenn-ein-QR-Code-alle-Schutzmechanismen-aushebelt-11126816.html

#39c3 #Pwn2Roll

It's January 1st and I've seen enough jadx output for the whole year.

#Pwn2Roll #39c3