• TalkBass has been independent since 1998. Add your voice.
    Create a free account to reply to discussions, view embedded media, and browse with fewer display ads.
    Join freeLog in
    Want zero display ads or expanded classifieds tools? Compare plans.

Could a pedal be hacked via malicious firmware?

If pedals were ever connected straight to the internet, possibly?
Possibly, but it's still not all that likely. Something like a thermostat or a printer, which is on 24/7, is a better target.


It doesn't seem the microprocessors in pedals would even be able to physically handle the malicious code...
Malicious code doesn't need to take up much room. That's why relatively simple IOT devices can get hacked and used in botnet attacks.

The bigger issue is that the pedal won't be on all the time, so it won't be all that useful in a botnet.
 
  • Like
Reactions: Cave Puppy
Let me follow-up on my earlier suggestion that someone could hack a Bluetooth pedal and mess with it. Is this likely? No. But hackers do all sorts of stuff just because they can, whether for proof of concept or just for giggles. I'm a Type 1 Diabetic and there have been stories of hackers hacking insulin pumps for proof of concept. That's something to attack just one person. How would this be used? Well, maybe they would have a specific target in mind for terrorist-type activities, or maybe they're just a psychopath who messes with one person for no reason. But these sorts of small scale attacks do happen, even if it wouldn't seem like a worthwhile target to a normal person.

However, using the pedal to deliver some sort of virus or whatever would be terribly inefficient, if it would work at all, as others with a little more expertise than me have explained.

Very interesting, sometimes it is about exploring possibilities more than making an instant profit
 
Last edited:
I believe some pedals can be edited through Bluetooth, so theoretically it's possible. It would take a special kind of vindictive, malicious nerd to pull it off tho, I imagine.

But why put all that effort into attacking something as niche as a guitar pedal? You'd attack something with a much bigger market like an appliance or a printer or virtually anything other than musical instrument stuff.

It's like the old joke(with quite a lot of truth).
Even the virus writers don't support the mac.

I was thinking about some use cases and thought the following: a troll goes to a Taylor Swift concert (or any popstar concert), "hacks" the bluetooth pedal and changes the setting to a Lo-Fi patch that makes the guitarist sound like those old videos of "Paco de Lucia shreds". It would make for good laughs and likes.
 
  • Like
Reactions: LowActionHero
Do you have a Russian pedal?

I do, it is as Russian as Gerard Depadieu, though

IMG_20220714_131735~2.jpg
 
Last edited:
Anything can be hacked. If there isn't a reasonable cost to benefit ratio involved then no one qualified to hack the thing, will.

In this case there's no attack vector that would make sense. You'd need to download bad firmware to a pedal, that somehow also could compromise the device you pair with it.

That bad firmware would need viable exploits it could leverage to compromise said device. If they aren't using some unknown 0 day style exploits, that's a non-starter.

Most parties that uncover exploits of that nature either sell them or use them on hacks that are much more profitable than this would be.

So the chances of this happening are nonexistent.
 
If a connected device was hacked it could expose someone to your network. Is that what you're asking? A Las Vegas casino was hacked through a fish tank thermometer. The nationwide data breach at home depot was accomplished through hacking the HVAC controls.
I would not expect a pedal maker to invest more than they'd earn in cyber security.
Link Removed
Who thought it was such a great idea to control the fish tank thermometer from the same cell phone they access their bank???
 
  • Like
Reactions: Killing Floor
Anything can be hacked. If there isn't a reasonable cost to benefit ratio involved then no one qualified to hack the thing, will.

In this case there's no attack vector that would make sense. You'd need to download bad firmware to a pedal, that somehow also could compromise the device you pair with it.

That bad firmware would need viable exploits it could leverage to compromise said device. If they aren't using some unknown 0 day style exploits, that's a non-starter.

Most parties that uncover exploits of that nature either sell them or use them on hacks that are much more profitable than this would be.

So the chances of this happening are nonexistent.
As I said earlier, I don't think this is true. Sometimes people do things just to do things. So, having a negative cost-benefit analysis doesn't make the chances nonexistent, just very low.
 
  • Like
Reactions: Doctor Roberts
I'm not an expert in computer/software stuff, but I was wondering if it is theoretically possible that a pedal could stop working if you download a malicious firmware (let's say a corrupted TonePrint or Line6 file, or any other).

Could something like this happen?

In some cases this might be less far-fetched than many here are suggesting. I am thinking of platforms that use the Chrome browser for firmware changes and for patch editing. In the modular synth domain, Noise Engineering does this. In the pedals domain, Red Panda does. Probably others do, too.

The idea is that typically Chrome will be connected to internet, so a series of connections between the device (pedal or module) and Chrome could enable a malicious actor. Next thing you know, your smart refrigerator is a granular reverb. Or something.

It's an edge case, but not unthinkable, I'm thinking.
 
Interesting thread.

Could a pedal be turned into a recording/tracking device?
In order to record it has to have storage. In order to track it has to have the ability to collect data about its location and time -- either through built-in location systems (GPS and/or Wifi-based data) or by collecting that data from a device it's connected to. In order for that recording or tracking data to be useful to a third party that's not the pedal's owner it has to have a means to independently send its data out to a destination of its choosing.

So hypothetically yes. Practically speaking, no. Even if the firmware in an effects pedal is computationally capable of recording and tracking you, that capability is irrelevant if the hardware does not allow it. There's no point to installing a GPS into an effects pedal, and very little point to building a pedal capable of transmitting large volumes of data through the internet either through wifi or through an intermediary device (such as pedal -> bluetooth -> phone). Some pedals (such as loopers) are able to record, by design, but if the only data output the hardware allows are MIDI streams or PCM audio or such, there's no way for the pedal to address that audio to anything farther away than the designated upstream device (your soundboard or MIDI hub or whatnot).

Anything can be hacked. If there isn't a reasonable cost to benefit ratio involved then no one qualified to hack the thing, will.
The hacks we hear about are usually the malicious ones done for money. But I suspect most people who hack computers and electronics are doing so out of personal curiosity or to satisfy a personal interest. You don't hear about those often because, for example, getting the control pad of a color printer to play DOOM isn't interesting to many people, and getting an effects pedal to make sounds the manufacturer didn't intend has only a limited specialist's interest. Sometimes a well-intentioned hack is used as the platform for malicious hacks (such as when the discovery that an open-source image compression algorithm is Turing-complete was leveraged to hack the smartphones of political figures through maliciously-crafted GIFs), but there's still a line to be drawn between the people who did one and the people who did the other.
 
Who thought it was such a great idea to control the fish tank thermometer from the same cell phone they access their bank???
It wasn't me.
Cellular is actually really secure but wifi devices have more exposure risk. The real issue is that they were residing unsecured devices on the same server as their point of sale system. That's just dumb.
 
  • Like
Reactions: MVE
Honestly I think a bigger concern would be a Bluetooth-enabled pedal (e.g., the Eventide H9) getting "hacked" by someone who then messes with the settings.

I've actually seen that done at a fairly big guitar show after I pitched the idea to someone working in the booth I was hanging in, just as a "what-if" thing. It was with one of the newer Fender amps, but we could see a couple of H9s in another booth on the same computer the guy used to hack the Fender. One of us cheated and procured the Fender login credentials at their booth, so it barely counts as hacking really.
 
I have always understood hacking to be an action that is in a couple contexts:
1. Breaking into a secure network to snoop around and get to things that don't belong to you.
2. Breaking into many computers to do damage to said computes, or to augment them to do stuff you want them to do, like sent out emails for porn or viagra or something...

In the case of #2, Mac owners for years have always said that they were virus-proof. TBT they're not. Most hackers just don't have an interest because they're not a large enough target. - At least that's what I have read and it does make sense...

Based on the idea that networked Macintosh computers are too small of a group to be attractive enough to hack, musicians with pedals is an even smaller group. - Is it possible to impose a virus payload on a pedal patch? Probably. It's more likely to have a messed up patch that produces unexpected results. Also firmware incompatibility could be a thing. I've upgraded devices with perfectly good firmware that just went sideways at the install. Any of the last few things I mentioned could feel virus-like if they happened to you. If I were to experience a problem with how a pedal performs after an update or downloaded patch install, my first thought would not be virus. I'd more likely think, ok, how did i mess this one up...
 

Latest posts