For years, a backdoor in popular KiwiSDR product gave root to project developer
Users are rattled after learning their devices and networks were exposed.
KiwiSDR is hardware that uses a software-defined radio to monitor transmissions in a local area and stream them over the Internet. A largely hobbyist base of users does all kinds of cool things with the playing-card-sized devices. For instance, a user in Manhattan could connect one to the Internet so that people in Madrid, Spain, or Sydney, Australia, could listen to AM radio broadcasts, CB radio conversations, or even watch lightning storms in Manhattan.
On Wednesday, users learned that for years, their devices had been equipped with a backdoor that allowed the KiwiSDR creator—and possibly others—to log in to the devices with administrative system rights. The remote admin could then make configuration changes and access data not just for the KiwiSDR but in many cases to the Raspberry Pi, BeagleBone Black, or other computing devices the SDR hardware is connected to.
A big trust problem
Signs of the backdoor in the KiwiSDR date back to at least 2017. The backdoor was recently removed with no mention of the removal under unclear circumstances. But despite the removal, users remain rattled since the devices run as root on whatever computing device they’re connected to and can often access other devices on the same network.
“It’s a big trust problem,” a user with the handle xssfox told me. “I was completely unaware that there was a backdoor, and it’s hugely disappointing to see the developer adding backdoors in and actively using them without consent.” [Click here to continue reading the full article…]
Thank you for sharing this, Franco (and many other readers who’ve recently shared this article.
I’ve always been a big fan of the KiwiSDR network and the receiver so, of course, this is disappointing news. It sounds as if there’s no evidence the developer did anything nefarious through this root access backdoor, but they were also well aware it existed. That is, without question, a huge security issue.
The KiwiSDR developer comments here on the SWLing Post so my hope is that, perhaps, they can shed some light on this story in our comments section.
Many thanks to SWLing Post contributor, David, who writes:
I live in the UK and, like many of your readers and contributors, one of the aspects of the radio hobby I enjoy is ‘content DXing’. As of yesterday [September 9, 2020], all of the US-based classical music stations and even some European news outlets are no longer available through TuneIn.
This appears to be because of a court ruling which identifies TuneIn as a ‘broadcaster & communicator’ rather than – as TuneIn itself claims – an indexer of available stations.
I’m assuming Direct Streams from each station are still available but I can’t help but worry that station aggregators might also be in the firing line at some stage.
Thank you for sharing this, David.
Implications Beyond TuneIn?
At first blush, one might think this ruling only applies to TuneIn users, but it certainly sets the stage for further law suits since TuneIn isn’t the only “audio guide service” accessible in the UK.
In 2017, Sony and Warner sued US-based radio service TuneIn, claiming the company infringed its copyrights in the UK. A judgment handed down today by the High Court states that while TuneIn does not offer content itself, the provision of hyperlinks to content not officially licensed in the UK constitutes a communication to the public and is therefore infringement.
TuneIn is one of the most prominent and recognizable providers of radio content in the world.
Available for free or on a premium basis, the service offers access to well over 100,000 radio stations and millions of podcasts. It doesn’t provide this content itself but acts as an indexer (“audio guide service”, according to TuneIn) for those looking to access third-party streams.
In 2017 it emerged that Sony Music UK and Warner Music UK had sued the US-based company in the UK, claiming that since many of the TuneIn-indexed stations are unlicensed to play music in the region, linking to them amounts to infringement of the labels’ copyrights.
Today, the High Court of England Wales handed down its decision and it doesn’t look good for TuneIn. The judgment begins by stating the opposing positions of the labels and TuneIn, which are particularly familiar in these types of disputes concerning hyperlinking.
“The claimants say that a finding for the defendant will fatally undermine copyright. The defendant says that a finding for the claimants will break the internet,” Justice Birss writes.
The labels argued that TuneIn needs a license, an assertion “strongly disputed” by TuneIn. The company argued that it does not “store any music, and merely provides users of TuneIn Radio with hyperlinks to works which have already been made freely available on the internet without any geographic or other restriction.”
In other words, TuneIn presents itself as not unlike Google search but instead of indexing websites, it indexes and links to radio streams. However, Justice Birss declared the service to be “much more than that”, in part due to its curation and search features.
“I find therefore that the activity of TuneIn does amount to an act of communication of the relevant works; and also that that act of communication is to a ‘public’, in the sense of being to an indeterminate and fairly large number of persons,” he writes.[…]
While most WiFi radio station aggregators don’t have the app and web browser-based following and popularity of TuneIn, they do offer the “curation and search features” which lead Justice Birss to side with Sony and Warner.
Dear Sonos: can you see the enormity of the damage that’s been inflicted to your product? A major feature of the product has been devalued – at least for UK customers. Internet radio is 90% of what I use Sonos for; 80% of my listening is non-UK. Stopped working overnight. And you seem to be just as surprised as I am. How come you didn’t see this coming? You send me an email whenever you have something new to sell. Why didn’t you send me an email to warn me that this predictable event was going to hit me? You don’t seem to have a mitigation plan. You don’t have a how-to-workaround or this-is-what-we-are-doing-to-fix-it article in an prominent place on your web site.
Note that it’s not only TuneIn that’s now broken but also Sonos Radio. “Sonos Radio is an Internet radio service, exclusively available on Sonos. It features 60,000 radio stations from around the world”, it says on the tin. No it doesn’t anymore. They are still all there but they don’t work when you click on them.
From Sonos’s vantage point, TuneIn may be a separate entity. But that’s irrelevant from my point of view. I want the functionality that the product promises.
OK there may be some workarounds. I’m sure I’ll find them. But the fact remains that a major feature of the product no longer “just works”. It can still be “made to work”, but that takes a certain level of cyber-literacy.
I’m willing to bet UK users of other streaming media devices and smart speakers–especially devices from companies who aren’t in the business of directly streaming copyrighted music–will eventually have a smaller selection of international content.
Is there a work around?
Surely. But it could require heavy use of a VPN or similar service to trick TuneIn, Sonos, or other Internet devices into believing they’re physically located outside the UK. This may only be a temporary fix, however. Both Netflix and Amazon Video streaming services, for example, began effectively blocking most of the major VPNs a few years ago.
Have you been affected?
To be clear: I’m no expert in streaming media law, so what I’ve presented here are the basics and user reports. These are my own opinions and assumptions about where this ruling could lead.
If you live in the UK and have been directly affected by this ruling, we’d appreciate your comments.
Radio Waves: Stories Making Waves in the World of Radio
Because I keep my ear to the waves, as well as receive many tips from others who do the same, I find myself privy to radio-related stories that might interest SWLing Post readers. To that end: Welcome to the SWLing Post’sRadio Waves, a collection of links to interesting stories making waves in the world of radio. Enjoy!
Many thanks to SWLing Post contributors Tony, Dan Robinson, Michael Bird for the following tips:
WASHINGTON, D.C. — Today, U.S. Agency for Global Media (USAGM) Chief Executive Officer Michael Pack thanked officials who will serve in an interim capacity as the heads of the agency’s two federal organizations and its three public service grantee broadcasting networks.
Elez Biberaj, who has led Voice of America (VOA)’s Eurasia Division since 2006, will serve as VOA’s Acting Director.
Jeffrey Scott Shapiro, previously Senior Advisor at Office of Cuba Broadcasting (OCB), will serve as OCB’s Acting Director and Principal Deputy Director.
Parameswaran Ponnudurai, who has been Vice President of Programming at Radio Free Asia (RFA) since 2014, will serve as RFA’s Acting President.
Kelley Sullivan, who has been a Vice President at Middle East Broadcasting Networks (MBN) since 2006, will serve as MBN’s Acting President.
Daisy Sindelar, who has been with RadioFreeEurope/RadioLiberty (RFE/RL) for nearly two decades, will serve as RFE/RL’s Acting President.
CEO Pack sent, in part, the following message to staff:
“The experience of these talented men and women, their knowledge of the networks, and their commitment to the standards of journalism will allow us to launch into the next exciting chapter of our agency. Dr. Biberaj, Mr. Shapiro, Mr. Ponnudurai, Ms. Sullivan, and Ms. Sindelar will serve critical roles in allowing our networks to become higher performing and to more effectively serve our audiences. For their willingness to step up and help lead this effort, I am deeply appreciative. I am excited to serve alongside them as well as with all of you.”
Virginia Air & Space Center (VASC) Executive Director and CEO Robert Griesmer has advised that the Center’s amateur radio station exhibit will be discontinued, effective July 1, when the Center, in Hampton, Virginia, reopens. VASC is the official visitor center for NASA’s Langley, Virginia, facility. The KE4ZXW display station was shut down on March 13. It was to be out of the VASC by June 30. A main feature of the exhibit was the ability to communicate with amateur radio satellites and with the International Space Station.
Randy Grigg, WB4KZI, of the VASC Amateur Radio Group said the station’s equipment would be relocated. “Thanks to all who have supported KE4ZXW during the last 25 years, especially the volunteer operators who manned the station during that time,” Grigg said. “To the many visitors we have met and school groups that have stopped by and talked with us about ham radio, communications, satellites, and STEM Program related subjects, thank you!”
On June 30, it was announced that the Virginia Tech Amateur Radio Association (K4KDJ) in Blacksburg will be the new host for the KE4ZXW Amateur Radio Demonstration. — Thanks to Randy Grigg, WB4KZI, and Ed Gibbs, KW4GF[…]
On the negative side, WWV and its sister time station WWVH in Hawaii nearly missed this centennial. That’s because NIST’s original 2019 budget called for shutting down the pair, along with WWVB, the longwave code station co-located next to WWV, as a cost-saving move.
Fortunately, these cuts never happened, and WWV, WWVH and WWVB seem likely to keep broadcasting the most accurate time from NIST’s atomic clocks, at least for the immediate future. (No further cuts have been threatened.)[…]
On June 27, a new KiwiSDR web software defined radio became operational in Iceland
A translation of the IRA post reads:
The new receiver is located in Bláfjöll at an altitude of 690 meters. It has for the first time used, a horizontal dipole for 80 and 40 meters.
The KiwiSDR receiver operates from 10 kHz up to 30 MHz. You can listen to AM, FM, SSB and CW transmissions and select a bandwidth suitable for each formulation. Up to eight users can be logged into the recipient at the same time.
Ari Þórólfur Jóhannesson TF1A was responsible for the installation of the device today, which is owned by Georg Kulp, TF3GZ.
The IRA Board thanks Ara and Georg for their valuable contributions. This is an important addition for radio amateurs who are experimenting in these frequency bands, as well as listeners and anyone interested in the spread of radio waves.
Many thanks to SWLing Post contributors David and Monti who share a link to Radio Garden, a new web-based interface for exploring online radio stations across the globe.
[…]Radio Garden, which launched today, is a similar concept—a way to know humanity through its sounds, through its music. It’s an interactive map that lets you tune into any one of thousands of radio stations all over the world in real time. Exploring the site is both immersive and a bit disorienting—it offers the sense of lurking near Earth as an outsider. In an instant, you can click to any dot on the map and hear what’s playing on the radio there, from Miami to Lahore to Berlin to Sulaymaniyah and beyond.
The project, created for the Netherlands Institute for Sound and Vision by the interactive design firms Studio Puckey and Moniker, was built using an open-source WebGL globe that draws from thousands of radio stations—terrestrial and online-only streams—overlaid with Bing satellite imagery.
The result is the best kind of internet rabbit hole: Engrossing, perspective shifting, provocative, and delightful. […]
Many thanks to SWLing Post reader, Bob Chandler (VE3SRE), who leaves the following reply to our WiFi Radio Primer:
I have been streaming online radio using a PC for a number of years using a really simple programme for the GNU/Linux operating system called “RadioTray“. RadioTray is a tiny programme written in Python that uses the Gstreamer “back end”.
This programme is so small, that you can turn that old 1990’s vintage Pentium II laptop that’ gathering dust in a broom closet into an internet radio. Just choose a very “lightweight” distribution of GNU/Linux.
For instance, on an old “original” Asus EeePC netbook, with a 900 MHz. Celeron processor, 512 MB RAM and a little 4 GB solid state hard drive, I installed the “Debian” distribution but used the lightweight “JWM” window manager for the GUI. JWM isn’t pretty, but it works great!
You can get “RadioTray” using the package management system of just about any GNU/Linux distribution. I know for sure it’s in the “repos” for Ubuntu, Debian, Arch and Fedora along with all of the derivatives. Unfortunately, it’s not available for Windows and MacOS. But, the GNU/Linux OS is “free as in freedom and free as in free beer” as they say!
All of your radio station “bookmarks” are stored in a simple “bookmarks.xml” file that makes it a breeze to copy your bookmarks from computer to computer. Over the years I’ve accumulated a thousand or more (I’ve lost count) internetradio stations in RadioTray.
RadioTray is capable of handling just about any streaming format.
My online “dx challenge” is finding the “real” stream URL of the station that’s often buried inside of browser based “Flash” players. But, since these days most radio stations outsource their audio streaming to one of about half a dozen streaming audio providers, once you’ve figured out the provider’s URL pattern for one station, you’ve figured them all out.
I’m able to figure out the “real” stream URL about 90% of the time. Some are easy, while some require a bit of detective work.
That also means that I don’t depend on streaming aggregators, since stream URL’s are changing all the time and sometimes it takes the aggregator a while to do an update. I can just update a station that I’m interested in myself.
I am a heavy user of internet radios and have a few scatted around the home, the one most frequently used is the Grace in the kitchen. What stations do people listen to?
I listen to lots of different things while cooking, what I do is tune to a station local to whatever I am preparing. So that means a lot of Asian stations; Indonesia, Vietnam, India, Japan, China, Laos etc! A few months ago spending time in Southern California put me in the mood for Mexican food, so there has been a lot of Mexican radio playing in the kitchen lately. On the special occasions when cooking Grits for breakfast I usually listen to 103.3 AshevilleFM.
[Note to Mark: I’d like to think I have something to do with the fact you’re one of the only guys cooking grits in Australia! -Thomas]
The Logitech in the bedroom is usually tuned into European stations late a night as I drift off, and as I wake up and dress I’m usually listening to Japanese community radio stations.
In the main living area mostly USA alternative and indi rock, NPR or college radio is on.
I am a very serious flight-simmer and love exploring around the world this virtual way. I’m very serious about this so preflight and route planning takes up to an hour, so in the hours before a flight I quite typically listen to a station in the city my Cessna-404 twin turbo happens to be at that particular time.
I’m kind of interested – what are you guys listening to on internet radios?
PS. Oh and the Como Solo looks great – Im ordering one!
Your query is timely, Mark, as someone recently asked me the same question.
The Sangean WFR-28 WiFi Radio
I primarily use Internet radio to listen to music and local news outlets.
In terms of music, I love almost everything, but especially Jazz, Classic Rock, Big Band, Brazilian music, French, Mambo, Zydeco, Electronica, and, frankly, anything a little eclectic and musically interesting.
Some of my favorite music stations are: The UK 1940s Radio Station, RFI Musique, FIP, Radio Bossa Nova, KBON, Espace Musique (various outlets), CBC Ambient Lounge, Kanal Jazz, Radio Swiss Jazz, WNMB, RadioNostalgia, Celtic Music Radio 1530, WNCW, Radio 6 and Fréquence 2 to name a few.
In terms of news and talk, I listen to: CBC Radio 1 (Toronto, Montreal, St. Johns, Charlottetown), WFAE, WCQS, Alaska Public Media, Vermont Public Radio, France Inter, Radio Canada, ABC Radio Australia, ABC Northern Tasmania, Radio New Zealand National, BBC World Service, 7RPH, Federal News Radio, ABC Radio Perth and many, many more.
I especially love finding some random, local radio station and eavesdropping on their community news!
I have well over 100 stations/favorites organized in various folders on my WiFi radios.
Honestly, this 2016 election season in the States has so heavily dominated domestic news, I’ve focused almost exclusively on stations outside of the US to seek a little refuge.
Of course, I’m also a heavy shortwave listener. While using a WiFi radio lacks the “fun factor” and skill of SWLing, it certainly serves up a world of diversity and is the perfect compliment to shortwave listening.
Radio Australia serving up a blowtorch signal into North America this morning–a steady S9+20db on my Elecraft KX3.
As I type this post this morning, for example, I’ve been listening to the CBC and France Inter on my WiFi radio (the audio actually emanates from my vintage Scott Marine SLR-M via an SStran AM transmitter). I’ve been muting the WiFi radio from time to time to listen to the ABC top of the hour news and music programming on Radio Australia with my Elecraft KX3 (above).
Now…back to Mark’s question…
What do you, dear Post reader, listen to on your WiFi radio, mobile device or computer? Please comment!
But exactly why did I buy this small, self-contained digital music device–? Having just completed an in-depth review of several WiFi radios, I certainly didn’t need another. But the good-looking Solo, with its clean design and walnut casing really caught my attention…I couldn’t resist checking it out. Plus, in backing the radio via Kickstarter, I was able to purchase it for $100 less than the predicted future retail of $299 US.
The Kickstarter campaign funding Como Audio was prompt in communicating updates with backers and providing even more product options during the wait for production and delivery. Although several other snazzy finishes for the Solo were brandished before me, I stuck firmly by the walnut veneer I’d originally chosen.
Fast forward to the present. I finally received my Como Audio Solo a few weeks ago, and have had time to play with it. While I haven’t had time to explore every nuance of this radio, of course, I have had an opportunity to form some opinions.
I don’t often comment on the design of radios I review, but in this case it’s worth noting.
The Como Audio Solo, in wood, is elegant and simple. Love it:
The only element of the design I’m not typically keen on? I’m not the biggest fan of devices that sport colored backlit displays; to me they appear a bit flash and faddish, undermining a radio’s overall aesthetic.
But I must say, the Solo pulls it off. The color display in this case is somehow not too distracting–it’s soft yet crisp, and easy to read even at a distance.
In short, the Solo is a stunning piece of kit, especially with that warm walnut casing, and looks right at home in any setting–office, living area, kitchen, or at the bedside.
I’ve only one gripe with the Solo’s ergonomics: the front control knobs are a little too close to the bottom of the recessed controls area. When I try to turn a knob–for example, attempt to tune the FM band–I find my fingertips won’t fit between the knob and lower edge of the recessed panel, making the knobs a little hard to turn in one fluid motion. (Of course,this is also due to the fact that I have big fingers; my wife doesn’t seem to have this problem).
But this isn’t a dealbreaker as I’m finding I don’t often need to reach for the front controls, anyway. Why? Because the rig’s IR remote–or better yet, its smartphone app–control the radio effectively at any convenient distance from the radio. Sweet.
I’m a sucker for quality audio fidelity, and I must admit that this was one of the biggest deciding factors in purchasing the Solo: it touted extraordinary audio in a modest package, being designed around an acoustic chamber/chassis containing a 3″ woofer and 3/4″ dome tweeter fueled by a 2 X 30 watt RMS amplifier. I was very curious whether it could live up to its initial claim.
After turning on the Solo for the first time, I immediately wanted to hear audio, so I put it in Bluetooth mode and played a few songs, ranging from Jazz to Electronica.
In a nutshell: Wow.
The audio is strikingly reminiscent of my Tivoli Audio Model One…which is to say, it’s excellent. It packs more audio punch than any of the radios I reviewed in my WiFi radio comparison.
Out of the box, the audio is fairly well-balanced, too. But you can tweak the equalizer, and I did, drawing in a little more bass and treble. My wife (also a bit of an audiophile) was impressed. And yes, the sound is all the more remarkable considering the radio’s relatively small form-factor: little box, big voice.
The Como Audio Solo is one of the few Wifi radios on the market that has a built-in analog FM and DAB receiver (save the $120 Sangean WFR-28, which has analog FM reviewed here).
Since I live in the US, I can’t comment on DAB reception. I have, however, had an opportunity to test the FM analog reception. Keep in mind, I live in a rural area and require a decent FM receiver with telescopic antenna fully extended just to listen to my favorite regional programming.
When I tune the Solo to my benchmark FM stations, it can receive them–but not as effectively as many of my other radios, including the WFR-28. Even when forced to use the Mono setting only, the stations it receives carry too much static for good listening. So obviously the Solo isn’t as sensitive as some of my other radios, at least in this setting. Indeed, few stations it receives in this area are able to lock in to the point that there’s no static in the received audio. For out-of-towners, this is a bit of a disappointment.
With this said, I imagine if you live in an urban area, the FM receiver should more than please you. I’ve no doubt it can faithfully reproduce beautiful audio from local FM outlets.
I should add that, while FM reception isn’t stellar for distant stations, the RDS information does convey even when the audio isn’t full fidelity.
Of course, the main reason I purchased the Como Audio Solo was to use and review it as a WiFi radio…nothing at all to do with that sharp walnut chassis, or audio power.
As I outlined in my WiFi Radio primer, WiFi radios rely on station aggregators–extensive curated databases of radio stations–to surf and serve up the tens of thousands of streaming stations around the globe.
Based on feedback from Como Audio shortly after the Kickstarter launch, I was under the impression that the station aggregator of choice was vTuner. This concerned me, as vTuner’s reputation as an aggregator is somewhat maligned due to a series of documented faults and weaknesses. Fortunately, this turned out not to be the case: after the initial confusion, I soon discovered Como had adopted the more robust Frontier Silicon aggregator, instead–a better choice.
Since I’m a pretty big fan of Frontier Silicon and since I’ve already been using their service with my Sangean WFR-28, once I connected my radio to my user account, the WiFi portion of the radio felt identical to that of my WFR-28. Simply brilliant, as the Frontier Silicon radio portal gives the user flexibility to create station lists and folders with ease–all of which readily convey to the radio itself.
The Solo also features six dedicated memory buttons on the front panel for quick access to favorites.
I love the Solo’s design–this certainly is a handsome product. Moreover, I love the audio, and am pleased that it delivers the fidelity promised by its Kickstarter campaign. The Solo and Duet are loaded with features, connections, Aux In and Aux Out audio and digital ports–more, in fact, than any similar device with which I’m familiar. I regret that the rig’s FM isn’t suited for country life, but the audio coupled with its stylish exterior do make up for this somewhat.
I do wish the Solo had an internal rechargeable battery option. Being able to move the receiver to different locations within a home or building could be a major plus for rural FM reception. As my friend John pointed out, however, the audio amplifier is robust enough, it might have been a challenge to implement an affordable-but-effective internal battery without compromising the audio amplifier’s needs.
In truth, I favor audio fidelity over portability for a tabletop radio.
In conclusion…do I have any backer’s remorse? Absolutely not–!
In short, the Como Audio Solo is a keeper. I’m still marvelling at this classy and dynamic radio that fills our home with rich beautiful audio. A few weeks in, the Solo has already become a permanent feature in our abode. It’s one of the few radios I have that meets my artist wife’s approval in terms of both design and audio.
Great job, Como Audio! If the Solo is any indication of radios to come, I’ll certainly be looking for your future innovations.