cybergibbons Posted November 25, 2015 Author Posted November 25, 2015 So 2013 firmware was in your report? Firmware that was on a device installed 2013 - 2.5x. The latest on their site was 3.53 or 3.10 for UDL. This is the version number that flashes up as the board is booting. I'd be interested to hear about other versions of the firmware though. I have two DigiAirs now, so I am presently giving them a once over. So as of April 2015 your findings are valid? Unless CSL secretly deployed a later firmware version using programmers that no installers have, yes. If one of you still have a valid login to the CSL installer area, you could check what the latest firmware version is. Maybe ask them what the latest version is for the Gradeshift as well... Quote I have a blog, some of which is about alarm security and reverse engineering:http://cybergibbons.com/
james.wilson Posted November 25, 2015 Posted November 25, 2015 Be interesting if that's just 100 affected units? Can't agree that its a round 600 units affected. That is imo bullsh1t Is that grade 3 units, or gradeshift grade 4 Most end users won't know, care or give one as their insurer will come back on the maintainer. I wonder what the insurers think on this. As usual the insurers will ask for Dualcom plus Quote securitywarehouse Security Supplies from Security Warehouse Trade Members please contact us for your TSI vetted trade discount.
cybergibbons Posted November 25, 2015 Author Posted November 25, 2015 Be interesting if that's just 100 affected units? Can't agree that its a round 600 units affected. That is imo bullsh1t Is that grade 3 units, or gradeshift grade 4 Most end users won't know, care or give one as their insurer will come back on the maintainer. I wonder what the insurers think on this. As usual the insurers will ask for Dualcom plus I can't see any difference between the different units - certainly the ones I have, the grade is just an option set in NVRAM. What is "Dualcom plus" - seen that in insurance docs, but doesn't seem to line up with a product. Quote I have a blog, some of which is about alarm security and reverse engineering:http://cybergibbons.com/
sixwheeledbeast Posted November 25, 2015 Posted November 25, 2015 I'd be interested to hear about other versions of the firmware though.3.77 Is that grade 3 units, or gradeshift grade 4It still not clear, but they seem to be all the same hardware. You can buy spare units and program them to be whatever grade you need. Most end users won't know, care or give one as their insurer will come back on the maintainer.Completely agree. Quote
james.wilson Posted November 26, 2015 Posted November 26, 2015 Surprised as such maintainers will be liable that it isn't a busier topic. My take is that I needed to remove them. Seems a lot of firms don't care that they are fitting very insecure devices. Quote securitywarehouse Security Supplies from Security Warehouse Trade Members please contact us for your TSI vetted trade discount.
james.wilson Posted November 26, 2015 Posted November 26, 2015 Im also surprised there hasn't been a response from csl on this. I was personally contacted after my videos of Dualcom vs, Redcare, vs webway. Quote securitywarehouse Security Supplies from Security Warehouse Trade Members please contact us for your TSI vetted trade discount.
Nova-Security Posted November 26, 2015 Posted November 26, 2015 Surprised as such maintainers will be liable that it isn't a busier topic. My take is that I needed to remove them. Seems a lot of firms don't care that they are fitting very insecure devices. Nope ARC is liable as we subcontract the monitoring out. Quote www.nova-security.co.uk www.nsiapproved.co.uk No PMs please unless i know you or you are using this board with your proper name.
al-yeti Posted November 26, 2015 Posted November 26, 2015 Nope ARC is liable as we subcontract the monitoring out. How? Quote
cybergibbons Posted November 26, 2015 Author Posted November 26, 2015 3.77 Is that the number as reported when you turn the board on? Do you know when it was purchased? Quote I have a blog, some of which is about alarm security and reverse engineering:http://cybergibbons.com/
cybergibbons Posted November 26, 2015 Author Posted November 26, 2015 I don't know why CSL haven't responded more robustly to it. Fundamentally, what I have published doesn't say the system is ruined. Surprised they haven't defended themselves better. Quote I have a blog, some of which is about alarm security and reverse engineering:http://cybergibbons.com/
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.