

I’m sorry to say it but now I’m even more confused.


I’m sorry to say it but now I’m even more confused.


“You’re the vulnerability”


I don’t understand how this can still happen with a well known brand in 2026. Personally the microphone is the least concerning aspect of this finding, since a Bluetooth connection would still be required. With more dedicated research, the BadUSB aspect is far more concerning in my book. Plug the speaker into a computer, even once and only to charge, and the computer is pwned? Preventing any future patching? I don’t know how I could ever trust one of these devices going forward.


I suppose that depends on your definition of a cybersecurity risk. Unfortunately it likely won’t matter to them unless it starts affecting their bottom line.


I don’t understand the purpose of your comment. That word exclusively appears twice in the twelfth paragraph, and makes complete sense in context. I think the write up is incredibly detailed but also easy to understand.


Awesome write up.
Allowing arbitrary firmware updates without any signature validation, over Bluetooth, even unpaired and in sleep mode, and without any authentication is absolutely wild and should be criminal negligence.
It took Creative nearly two months to respond to SingCERT. Unfortunately, their response was that “they do not consider this to be a vulnerability, as it does not present a cybersecurity risk”
What a foolish response. The guy wasn’t asking for money and gave them everything they would need to make a patched firmware.


Agreed.
I don’t mind paying a reasonable price for access to SSO, especially if the service is fully provided by third-party infrastructure. For something that is fully self hosted on the other hand, a recurring cost for what should be a basic (or at most a one time reasonable fee) feature feels egregious.


Yes I already do so, but this dashboard requires an enterprise license to also use OIDC.


This looks really cool, but I wish that OIDC wasn’t tied to an enterprise license that doesn’t show a price (just a contact us form and email address) and requires annual renewal.
I’d be willing to pay a reasonable one time fee to unlock OIDC support, and I understand why they charge a recurring fee for the other enterprise license features, but as it currently stands this doesn’t really make sense for a home lab.
Breakfast pizza is amazing. Replace the tomato sauce with sausage gravy, sprinkle on the scrambled eggs, diced ham, and any other toppings of your choice, add the shredded cheese, and bake at 400F for 10-15 minutes (depending on your oven).