Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Consider blocklisting Qualcomm CSR firmware update service #20

Open
pdjstone opened this issue Mar 1, 2017 · 4 comments
Open

Consider blocklisting Qualcomm CSR firmware update service #20

pdjstone opened this issue Mar 1, 2017 · 4 comments

Comments

@pdjstone
Copy link

pdjstone commented Mar 1, 2017

The service UUID is 00001016-d102-11e1-9b23-00025b00a5a5

The only information I could find on that service is here: https://www.csrsupport.com/download/49800/CS-327746-RP-1-Training%20and%20Tutorials%20-%20CSR%20Over-the-Air-Update.pdf

The protocol seems to do challenge-response with a shared key, rather than properly signing the firmware.

@beaufortfrancois
Copy link
Member

Thank you @pdjstone!
I believe we should blacklist Qualcomm (CSR) OTA Update service.

@jyasskin WDYT?
See PR at #21

@beaufortfrancois
Copy link
Member

@pdjstone On an unrelated note, can you tell us more about pdjstone/cloudpets-web-bluetooth#1?

@scheib
Copy link

scheib commented Apr 8, 2017

I've reached out to Qualcomm staff and am anticipating a response here.

@jyasskin
Copy link
Member

Blacklisting an update service that's only secured with symmetric keys sounds good to me. Sorry for missing this. Let's give Qualcomm until the 14th (1 week from @scheib's message) to respond?

@scheib scheib changed the title Consider blacklisting Qualcomm CSR firmware update service Consider blocklisting Qualcomm CSR firmware update service Apr 11, 2017
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

4 participants