HN.zip

Reverse engineering the Creative Katana soundbar to control it from Linux

126 points by theanonymousone - 11 comments
password4321 [3 hidden]5 mins ago
This device is a bit too open; last week they shared a custom firmware to disable unsigned updates over Bluetooth.

https://news.ycombinator.com/item?id=48382310 Pwnd Blaster: Hacking your PC using your speaker without ever touching it

Tyr42 [3 hidden]5 mins ago
Same blog eh?
emilbratt [3 hidden]5 mins ago
Love reading these posts where a person implement their own solution to communicate with devices that have proprietary software that only support Windows. Thanks for sharing.
dizhn [3 hidden]5 mins ago
Katana is the name of a line of amps from Boss. A bit too close as a field to have the same name.
glitchc [3 hidden]5 mins ago
Agreed, a bit too on the nose. I have one, a great first amp.
pjc50 [3 hidden]5 mins ago
CIFF is clearly derived from RIFF: https://en.wikipedia.org/wiki/Resource_Interchange_File_Form...

I've done similar myself, because it's so easy to specify.

I've also done the "how to hide a secret in a .NET application in such a way that it will be somewhat time consuming to extract it", which is about the most you can hope for.

shevy-java [3 hidden]5 mins ago
These articles are really great, as they yield information others can use to build upon, learn - and subsequently also help improve the linux ecosystem as well as other open source ecosystems. After having used linux for many years, every time I use something like Windows, I feel like being put in a jail.
vitalyan1234 [3 hidden]5 mins ago
[flagged]
pjc50 [3 hidden]5 mins ago
You don't have to use a slur if a non-slur is available, anon.
jauntywundrkind [3 hidden]5 mins ago
This is such a great caring useful post. About such a pure, incredible human story: liberating technology. Making it better. Life finding a way. I love love love how much interesting stuff opened up because packet capture caught the (plaintext, yay!) firmware upgrade.

But man, to see this story show up around the world has been really such a terrormongering frenzy of Fear Uncertainty and Doubt. Oh no, the users: they are uploading their own firware! What if they do bad things?! Everyone is at risk!

This is such toxic terrible dreck. Even ArsTechnica, who I've loved for decades, was in full on "be terrfieid, be afraid, hide your children, no one is safe" mode over this: https://arstechnica.com/security/2026/06/highly-reviewed-spe...

And they're not even wrong here. Yes. It's some kind of a risk. The device looks like a keyboard, and it could be programmed to type. It could perhaps possibly script a way to open a terminal and exfiltrate some data, before your very eyes (but if you tab away you're ok! it's just a keyboard!)

There are so many forces (and definitely among them much of the press) who seems desperate to build such a sterile, closed world, that drive such a conservative clutching for certainty against any chance or possibility for good fear before them. We've seen similar pants wetting over wireless. The FCC in 2014 changing Part 15C rules for U-NII devices was exactly this sort of "someone might do something bad possibly" rule setting, that demanded that device makers lock down their devices:

> All U-NII devices must contain security features to protect against modication of software by unauthorized parties.

> Manufacturers must implement security features in any digitally modulated devices capable of operating in any of the U-NII bands, so that third parties are not able to reprogram the device to operate outside the parameters for which the device was certied. The software must prevent the user from operating the transmitter with operating frequencies, output power, modulation types or other radio frequency parameters outside those that were approved for the device. Manufacturers may use means including, but not limited to the use of a private network that allows only authenticated users to download software, electronic signatures in software or coding in hardware that is decoded by software to verify that new software can be legally loaded into a device to meet these requirements and must describe the methods in their application for equipment authorization.

Via the excellent Battlemesh conference, https://www.battlemesh.org/BattleMeshV8/Agenda?action=Attach...

This all is such an anti-human infernal hell. A world where we can not see our devices, much less be allowed to touch or manipulate the world around us. We are being robbed of our god given right to explore, understand, experiment. This is our heavenly purpose, our god given nature, our mission to understand and shape the world around us. Yet there are these confounding legalistic and media denials of the Enlightenment project, that are against understanding the world, against humankind gaining our footing. The government is outlawing Homo Habilus, is using the law to send us back not to a pre-Great Deal (US) time a hundred years ago, nor pre-Reconstruction (US again) two hundred years ago, but to pre Homo Habilis, pre man the skillful, 2 million years ago. Anti-circumvention anti-access laws are an affront to god, an affront to our deepest spiritual nature, an affront to our species.

Rasmus is doing amazing work. The circumstance of them being able to see what was happening, being able to observe the world around them, capturing & seeing what he had there, and then doing some work to modify & change things: that is glory. That is divine. This is virtue. That is why our species was created, and why it exists, our making and our ongoing purpose, and is what has made our species better at every turn. That Conde Naste or the FCC doesn't like it, and wages war against our species is infernal. Shame on them. Shame on the terrormongers, the fear-makers of this world, who spin human access to the world about us as bad, as scary, as something to be stopped and shut down: that fear is what we have to fear, that fear is a little death for our species. That fear diminishes not protects, that fear is against god.

The god or gods made us all hackers, and that has been the best thing going for our species for millions of years: to try to unwind this is spiritual/religious treason. The terrormongering needs to be shown the door.

shevy-java [3 hidden]5 mins ago
> The god or gods made us all hackers

What god?

People's inner motivation largely made them what they want to be; to some extent circumstance and happenstance, as well as the options they had available. In some cases also idols or people they may look up to or learn from. Just as Alan Kay once stated: one stands on shoulders of giants (before, e. g. people who helped built up the world, shape it, add to knowledge and so forth).

The world wide web, which Google and others currently try to kill off, also using AI slop (AI skynet slop), has been an enabling technology for the most part (if we ignore e. g. ads, but even ads, which I always block such as via ublock origin, helped shape some things or enabled others, through flow of money - sad that Google siphons off everything nowadays).

I remember some years ago having read a story of some poor guy in Pakistan, who is a hacker thanks to ... a cheap smartphone. I was impressed, because personally I hate USING smartphones; desktop computer systems is where I am much more comfortable with. That story was enlightening though. People write code even on devices that seem hugely unsuited for that task.

I don't really understand your analysis here though. For instance: "that is glory. That is divine. This is virtue" - what does any of this mean? It seems decoupled from reality. Are you by chance using TempleOS?