Reply to post: Re: Pen testing fail?

Star Wars BB-8 toy in firmware update risk, say UK security bods

Stoneshop
FAIL

Re: Pen testing fail?

The firmware file as present on the toy maker's servers is freely accessible and copyable (which is not quite the same as 'public information' though), but given the possibility of a MITM attack, can you be sure that the firmware on the toy is the file you downloaded? Whether that can only result in farty noises every few seconds because it's lacking sensors with which to spy on you is not the point; it being possible is, and now the makers are aware of it.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon