Skip to content

Comment on Security Vulnerability in Pioneer Rekordboxparent

Comments

I too also have a special place of hate for Rekordbox. However I'm somewhat confused by this vulnerability, isn't plug n play unauthenticated file access essentially a core feature of "PRO DJ LINK"? The security mitigation, and best practice, being to have the involved devices connected on a entirely private LAN. I've never tried connecting them to a "public" network.

The feature definitely does what it says it does, but I think that the mount is generally accessible outside the software may be where the “surprise” lies.

I definitely would not have used this feature on a public network or exposed the mount to the open internet as well.

You and crtasm both make an excellent point about where the problem lies. I suffered from a critical imagination failure by never considering the implications of running the link on anything other then a controlled and isolated network.

Access to files in your rekordbox library yes, but this sounds like it may be allowing access to any file on your computer/USB stick.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.