it's 2023, so how about a security vuln in a guitar processor? (I know, I know, it's not a "guitar processor", they call it "modeller". anyway)

ping @GossiTheDog
https://neuraldsp.com/news/statement-regarding-a-quad-cortex-security-vulnerability

Statement regarding a Quad Cortex security vulnerability

@stomilin @GossiTheDog very bait and switch, i expected an actual hardware attack lol

@Rairii @GossiTheDog

yep! after (not so) carefully reading the article for the second time I think most likely their "technical" mailbox was compromised because it had an easy-to-brute-force/weak password (or they don't use encryption) and now they are rolling out the firmware update just to change the mailbox's password. (at first I thought some "researcher" discovered the password in the firmware, but, well, I guess I was wrong)

@stomilin @Rairii @GossiTheDog hm, but why would they have to roll out an update to the device to change that password?

agree it’s a good announcement but I can’t come up with any explanation for requiring the firmware update beyond “wait they did WHAT”

(also, using mail for this and not an API endpoint is clever and terrible all at once)

@mendel @Rairii @GossiTheDog
their gmail mailbox was pwned by some computer-savvy Quad Cortex enjoyer, I've just found a more or less informative youtube video abt it, here are couple of screenshots (hope we wont get DMCAed)

(link to the video https://youtu.be/7NOSJc9_C2g)

Things Got Worse For Quad Cortex

YouTube
@stomilin @Rairii @GossiTheDog ahahaha I figured there was a password in there. brutal