Here we goI would say the opposite about @Sean150 's knowledge and insight.
And again: Few, if any, pedals connect directly to the Internet, let alone use wifi in the first place. Even if they did, those devices won't contain any of the personal data that hackers want, and won't be good candidates for botnets as they aren't on 24/7.All malware - regardless of its final target - needs an entry point.
True, but you also need to use a firmware loader to actually control that device. You can't take over a Boss GT-1000 just by loading a patch.The new smart multi-effects units are computers....
No, dude. That's not how it works.when they have WiFi or Bluetooth, they are on networks.
For example, I have a camera that offers wifi connectivity. It doesn't connect to my network, it creates its own wifi network, and I have to use special software to connect to the camera. My phone or laptop's wifi can't be connected to the Internet when that connection is active. Bluetooth also isn't "on the network," it can only pair two devices to each other, and almost all attacks via Bluetooth require physical proximity to the device(s).
So, this is what would have to happen:
• Hacker has to somehow get access to Boss' proprietary code for a GT-1000 (a step which may require hacking Boss'/Roland's corporate network... and why not just stop there? or spending lots of time trying to reverse engineer the device), examine the code, insert the malicious code, and re-upload it to Boss' website provider
• Hope that no one notices that anything changed (even though skilled workers are paid to do just that)
• Wait for users to download and install the new firmware
• Hope that your malware doesn't brick a ton of expensive pedals, which would obviously tip off Boss/Roland
• Wait for users to turn on the devices and pair the device to a laptop or tablet, at which point the malware can... do stuff? Until the user unplugs it?
If you're going to go through all that effort, why not just compromise the GT-1000 System Software, which actually runs on a computer that has the data you want in the first place?
And how many users are you going to nail with this elaborate process before it gets noticed? How many people do you think buy $1200 multi-FX pedals anyway?
This isn't a serious method of attack. It's a Rube Goldberg device.
As someone who works with computers, I assure you: It is far, far, far easier to send out a bunch of phishing emails or use a zero-day exploit than do anything like what you're suggesting.
No one's watching it because... wait for it... it's a crappy attack vector that has no useful data on it.Why target an effects pedal? Because it's something that nobody is watching.
Heck, even Bluetooth speakers would be a significantly better attack vector than pedals, as they are far more abundant than pedals. Are you terrified of those, too?
Are you seriously suggesting that companies like Zoom, Boss or Line 6 are going to engage in highly illegal activities like that? And you think no one would figure out who was responsible? Please.Another scenario... Let's say company X wants to compete with company Y's device. Company X could very easily purchase a unit and reverse engineer the software.....
Right. So hackers are going to pass up tons of data-rich and poorly protected targets in favor of a complicated multi-phase attack to... take over devices that are almost never actually connected to anything at all, and owned by a tiny handful of people. Yep, that makes sense... if you live on Bizarro World.The fact that people think this is a useless thing to worry about is exactly why it could potentially become a high value target.
Back in the real world, what the Bad Guys are actually doing is stealing millions just by sending out phishing emails. THAT is the real threat today, and THAT is the type of attack you should worry about.
Last edited:
