How I discovered a hidden microphone on a Chinese NanoKVM

67 points by UkiahSmith


abeyer

This fails to mention a kind of important fact: this device is just a couple of extension boards added on to one of their preexisting dev boards, and the mic is part of that original board and it was always documented as such, not a secret. The dev board schematics are available at https://cn.dl.sipeed.com/shareURL/LICHEE/LicheeRV_Nano/02_Schematic. There's clearly some risk here, and it's good for people to know this, but this feels like just an oversight in disclosure about some preexisting hardware, not a malicious attempt to hide it.

Also, just in general, sipeed has always made lots of cool little toys... but they are typically toys. Their products seldom go beyond the demo/devkit level of polish and support, so I wouldn't be jumping to plug something like this into a production system unless I was using it as a base to customize/rebuild vs just use as-is.

Edit: And thinking about it now, a mic might actually be kind of useful here. Typically a proper server LOM will report even hardware/preboot faults remotely, but that's not possible if you're just getting usb & hdmi connections. If you're using this for remote server management, you could actually use the mic to listen for beeps/tones sometimes used by bios to report those kinds of failures.

Gaelan

You can start with your iPhone - last year Apple has agreed to pay $95 million to settle a lawsuit alleging that its voice assistant Siri recorded private conversations. They shared the data with third parties and used them for targeted ads. “Unintentionally”, of course! Yes, that Apple, that cares about your privacy so much.

(Emphasis mine.)

To be clear, Apple settled without admitting any wrongdoing beyond the "Hey Siri" feature unintentionally activating (something I'm sure any iPhone user has experienced). The plaintiffs' only reason to believe targeted advertising was involved is correlation with some ads they saw later. Apple are no saints, but I would not be claiming this as fact.