I saw Pleb Underground @Pleb Underground mention the findings of a shallow security review of the Coinkite #blockclock firmware, feeding the firmware binary to my clanker reveals that there might be some more severe vulnerabilities because of the old MicroPython version used even in the latest firmware.
I don't have an actual device myself to test but it seems likely that, because the data feeds are cleartext (no TLS connection to the data service!) a man in the middle attack is possible and therefore let someone own the box through the freezed Python WebREPL in the firmware.


Gist
MicroPython Vulnerabilities Blockclock
MicroPython Vulnerabilities Blockclock. GitHub Gist: instantly share code, notes, and snippets.
I think it is good for open-source in bitcoin and nostr that NVK has been removed from the
Check out nvk.wtf
j/k.. for now, it's easy to use the BTClock API to show this

Thanks for the photo 


