• TalkBass has been independent since 1998. Add your voice.
    Create a free account to reply to discussions, view embedded media, and browse with fewer display ads.
    Join freeLog in
    Want zero display ads or expanded classifieds tools? Compare plans.

Could a pedal be hacked via malicious firmware?

FWIW: What about modifying a digital pedal in a more subtle way so its gain/volume/bass boost is unexpectedly maximized mid-song, and your rig doesn't cope with that hot signal and blows the speaker?

(Of course any compressor/delimiter in the chain would prevent that.)

Not probable, I agree...
 
  • Like
Reactions: Doctor Roberts
Let me follow-up on my earlier suggestion that someone could hack a Bluetooth pedal and mess with it. Is this likely? No. But hackers do all sorts of stuff just because they can, whether for proof of concept or just for giggles. I'm a Type 1 Diabetic and there have been stories of hackers hacking insulin pumps for proof of concept. That's something to attack just one person. How would this be used? Well, maybe they would have a specific target in mind for terrorist-type activities, or maybe they're just a psychopath who messes with one person for no reason. But these sorts of small scale attacks do happen, even if it wouldn't seem like a worthwhile target to a normal person.

However, using the pedal to deliver some sort of virus or whatever would be terribly inefficient, if it would work at all, as others with a little more expertise than me have explained.
 
I would be much more concerned about the closed-source software used to update those things. No insight into how well the software is built and low confidence that the vendor has good security-aware programmers. Throw in auto-updating and you have a nice attack vector (without involvement from the vendor).
 
  • Like
Reactions: Doctor Roberts
As for the question for the "why" it is difficult to think of something, but I'm sure there could be gain for someone if there's even the smallest amount of money involved.
If that was the case, then every Internet-connected device would be compromised.


For example, something related to a ransomware, where they intervene the firmware before it is downloaded and then charge the company for the fix.
That doesn't make any sense.

First, the hacker needs to compromise the web server that's hosting the firmware. The companies do not host that from their own private network, by the way.

Next, the hacker alerts the company that "we put malware into your firmware." At which point, the company isn't going to pay the hacker. They're going to pull that compromised firmware, and yell at their web host for getting compromised.

In other words, it isn't going to work.


Maybe some new pedals will require to be "more connected" in the future.
Probably, but effects pedals will always be a crappy attack vector. Just about any other IOT device is a more lucrative target than pedals.
 
  • Like
Reactions: mcnach
It's not impossible, given the correct pedal that has bluetooth or a few that have WiFi, but you would need a reason and a payoff along with a lot of technical know how. I guess I'm in the tinfoil hat crowd because I won't own any pedals by a certain company located in a certain country.
 
FWIW: What about modifying a digital pedal in a more subtle way so its gain/volume/bass boost is unexpectedly maximized mid-song, and your rig doesn't cope with that hot signal and blows the speaker?

(Of course any compressor/delimiter in the chain would prevent that.)

Not probable, I agree...
I would think that the part of a pedal that can be edited by someone should be in front of some form of Digital-to-Analog converter that makes bits into audio... This, by itself should have it's own output limiter that may prevent a pedal to reaching way over line levels, also, the digital part could get as loud as the amount of bits it can handle so I see this very unlikely to happen...
 
It is possible but pedals are an unlikely target.

There is a history of "hacking" (probably not the best verb) in the world of effects pedals but it has usually been done to augment the pedal or to change it's firmware entirely in cases where a line shared hardware and architecture. The old DigiTech series with the Whammy, Space Station, & Reverb could have their firmware swapped or stacked if chips were added. So you could buy a cheap Whammy and install the Space Station firmware on to it.
 
  • Like
Reactions: mr_musica
If pedals were ever connected straight to the internet, possibly? It doesn't seem the microprocessors in pedals would even be able to physically handle the malicious code, as there are no operating systems that I know of in pedals for the bad code to target. They would also have to be connected to a computer or home network to be able to give hackers access. There is nothing in pedals that would make hacking them worthwhile, IMO.