• TalkBass has been independent since 1998. Add your voice.
    Create a free account to reply to discussions, view embedded media, and browse with fewer display ads.
    Join freeLog in
    Want zero display ads or expanded classifieds tools? Compare plans.

Could a pedal be hacked via malicious firmware?

I'm not an expert in computer/software stuff, but I was wondering if it is theoretically possible that a pedal could stop working if you download a malicious firmware (let's say a corrupted TonePrint or Line6 file, or any other).

Could something like this happen?
giphy.gif
 
I'm not an expert in computer/software stuff, but I was wondering if it is theoretically possible that a pedal could stop working if you download a malicious firmware (let's say a corrupted TonePrint or Line6 file, or any other).

Could something like this happen?
It could, but without an obvious payoff for the malicious actor, it’s not likely. If anything, a file that bricks a modern digital pedal is much more likely to be the result of garden variety human incompetence.

Or to put it another way, don’t attribute to malice, what can be adequately explained by stupidity.
 
If a connected device was hacked it could expose someone to your network. Is that what you're asking? A Las Vegas casino was hacked through a fish tank thermometer. The nationwide data breach at home depot was accomplished through hacking the HVAC controls.
I would not expect a pedal maker to invest more than they'd earn in cyber security.
Link Removed
 
I'm not an expert in computer/software stuff, but I was wondering if it is theoretically possible that a pedal could stop working if you download a malicious firmware (let's say a corrupted TonePrint or Line6 file, or any other).

Could something like this happen?
Ermmmm.... Yeah, the chances of this happening are near zero.

As asked above: Why?!? Pedals are almost never connected to the Internet, so they can't use a compromised pedal to do much of anything. Writing firmware that bricks a device is utterly pointless.

Not to mention the attack vectors would suck. The only place it could spread is by compromising the vendor, who will likely figure out the issue before most users are impacted.

If your pedal stops working after a firmware update, it's not because of malware. It's because either something went wrong, or you did something wrong, during the firmware update.
 
If a connected device was hacked it could expose someone to your network. Is that what you're asking? A Las Vegas casino was hacked through a fish tank thermometer. The nationwide data breach at home depot was accomplished through hacking the HVAC controls.
I would not expect a pedal maker to invest more than they'd earn in cyber security.
Link Removed

Exactly. The pedal wouldn't be the target, the computer you connect it to would be.
 
Exactly. The pedal wouldn't be the target, the computer you connect it to would be.
But the computer you connect it to is almost certainly where the compromise would come from so may as well just compromise that directly.
And if you mean hacking the pedal via bluetooth I think you would get a much better payoff as a hacker attacking phones via bluetooth at a gig than the bassists pedalboard. But YMMV...
 
  • Like
Reactions: Doctor Roberts
Thank you all. Very interesting insights.

As for the question for the "why" it is difficult to think of something, but I'm sure there could be gain for someone if there's even the smallest amount of money involved. For example, something related to a ransomware, where they intervene the firmware before it is downloaded and then charge the company for the fix. A long way and very niche attack, but who knows. It was sort of a speculative question after all.

KF raises an interesting point. Maybe some new pedals will require to be "more connected" in the future.
 
For example, something related to a ransomware, where they intervene the firmware before it is downloaded and then charge the company for the fix. A long way and very niche attack, but who knows. It was sort of a speculative question after all.
But why put all that effort into attacking something as niche as a guitar pedal? You'd attack something with a much bigger market like an appliance or a printer or virtually anything other than musical instrument stuff.

It's like the old joke(with quite a lot of truth).
Even the virus writers don't support the mac.
 
I'm not an expert in computer/software stuff, but I was wondering if it is theoretically possible that a pedal could stop working if you download a malicious firmware (let's say a corrupted TonePrint or Line6 file, or any other).

Could something like this happen?

Theoretically? Yes.

Technically? Yes.

A bad firmware could cause a pedal to simply not boot. (In that case, though, you'd probably just reinstall the firmware. The Line 6 Helix works this way, as does the Singular Sound Aeros Looper.)

Practically - there are only a few things that would probably be worth doing with devices like this, and it wouldn't be worth doing if it bricked the device. I don't think the attack surface is high, but if I wanted to do something malicious with a pedal it would probably be to generate some type of malicious traffic over WIFI. Another option would be to use it as a mass storage device to inject a malicious payloud over USB to a computer or something like that. The final thing I can think of would be to use a device to do some type of crypto mining (and even if you did end up trying to do something like that on a quad cortex, you'd still have to get the data out somehow, so it'd be kind of moot anyway).

The thing is - aside from the first thing, the WIFI traffic - there are better ways to do all of those things. The WIFI traffic thing is only viable because more is better, and so the cost-benefit is still pretty low for something like a pedal or even a modern multifx.

So yes - technically and theoretically, it's possible. But in practical terms, not really. There are just better ways to achieve that goal, at least in my opinion.
 
Yes, but people who write these types of intrusive programs tend to do so with a large audience in mind. An effect pedal would be a waste of time. People are just gonna say "my pedal got a virus" and either return it or toss it out.
There would have to be a lot more people using a lot more digital pedals with firmware that all shared the same framework in order for it to be worth a hacker's effort.
 
Something like this would only currently be developed for an attack on a specific high profile target. That’s the only way that would make it worth it. And even then it wouldn’t be anywhere near the top of the list of attack vectors.


What’s the best antivirus for pedals?
 
  • Like
Reactions: Lee Moses