My audio interface has SSH enabled by default

(hhh.hn)

90 points | by hhh 2 hours ago

7 comments

  • rikafurude21 1 hour ago
    Its still crazy to me that everyone has a pocket AI-hacker ready to inspect firmware and modify their devices now. You just put the agent on it and it gives you access in minutes. You would have to be a Hotz tier hacker if you wanted to do anything close to this only last year, or at the very least extremely patient for long hours.
    • buildbot 48 minutes ago
      This 1000% - I’ve used AI to enable SSH in one Phase One digital back I own, and to reverse engineer and patch the firmware on another to make the back think it’s a different back - Credo 50 to IQ250! The internals are literally the Sam.
      • Almondsetat 16 minutes ago
        I'm sorry, are you trusting an LLM to touch a camera that costs like a new car?
    • hhh 42 minutes ago
      its really nice to not have to spend hours looking thru packet captures and stuff, i enjoy digging but as i'm getting older I have less time to spend 16 hour days looking at random firmware blobs
    • strbean 39 minutes ago
      Damn, maybe I can throw an agent at trying to unlock IMEI spoofing on my Unifi LTE modem. That one guy on twitter who does all the LTE modem unlocking never replied to my tweet :(
  • yonatan8070 1 hour ago
    Having the firmware image just be a boring old tarball + hash sounds super nice. I wish more devices were this open, and I hope Rode won't see this and decide to lock the firmware upgrades down.
    • EvanAnderson 36 minutes ago
      In the off chance anybody from Rode sees this: This makes me want to purchase your gear. Don't change it.

      It's funny this comes up now. Tomorrow I'm dragging my Zoom R20 recorder on-site to use as an overly-featured USB audio interface for a single-mic live stream. If I'd know this about Rode a week ago I'd have purchased one of these and could have left my R20 hooked-up in the home studio!

  • montecarl 37 minutes ago
    I really want to know how he solved this problem, which I also face:

    >last year i bought a Rodecaster Duo to solve some audio woes to allow myself and my girlfriend to have microphones to our respective computers when gaming together and talking on discord in the same room without any echo

    • NikolaNovak 30 minutes ago
      Doesn't a headset with directional boom microphone do the trick? I may be misinterpreting the problem statement though :-).
    • hhh 31 minutes ago
      the rodecaster can connect to two computers, and we are both generally in the same discord call. so we have both microphones routed into one input for a computer, and the other person joins with their mic muted and the audio just comes from one client. since the mixing is local there's no echo. email me if you have more questions :)
  • coldcity_again 35 minutes ago
    Nice writeup and great domain. I don't know Zola and don't know if this is a common template or a custom jobbie but it's lovely.
  • 9p 1 hour ago
    why was disclosure the objective? wouldn't you want to keep this interface open?
  • realo 1 hour ago
    I understand the hacker rationale to have fun owning the device, and i would like it to stay that way.

    But... please do not forget that the CRA will put a heavy blanket on that fire.

  • serious_angel 1 hour ago
    [flagged]
    • hhh 1 hour ago
      because its fun to tear stuff apart and poke at it, and I am writing to share with people and for fun, not as a business.
      • serious_angel 1 hour ago
        [flagged]
        • JadeNB 1 hour ago
          You expressed your opinion once. I think that there's no need to shit on the post again.
          • serious_angel 1 minute ago
            I expressed my opinion twice. Since I value my finite life time, I thought there was a need to express a significant part that I feel is important to highlight once again considering the response I received from the one I wrote it

            A response from someone who did not even invested an adequate time to realize what I wrote with their response in a literal 3 minutes from my comment or someone who invested their life time read and respond back:

              - Me:   2026-04-24T20:22:37
              - Them: 2026-04-24T20:25:55
            
            Thank you for telling me about your thoughts, dear JadeNB.