I saw Pleb Underground @Pleb Underground mention the findings of a shallow security review of the Coinkite #blockclock firmware, feeding the firmware binary to my clanker reveals that there might be some more severe vulnerabilities because of the old MicroPython version used even in the latest firmware. I don't have an actual device myself to test but it seems likely that, because the data feeds are cleartext (no TLS connection to the data service!) a man in the middle attack is possible and therefore let someone own the box through the freezed Python WebREPL in the firmware.