Slashdot Mirror


Kodak Wireless Picture Frames Open To Public

Jaxoreth writes "The Kodak Easyshare Wireless Digital Picture Frame displays images via a per-frame RSS feed hosted by FrameChannel. Each frame's URL is identical except for a parameter matching its particular MAC address, enabling public browsing of users' feeds. And worse, if you reach the feed of a not-yet-activated frame, it gives you the code to activate it, allowing you to preload it with whatever content you choose."

185 comments

  1. zero day vulnerability? by Froeschle · · Score: 1

    Would this constitute a zero day vulnerability?

    1. Re:zero day vulnerability? by fuzzyfuzzyfungus · · Score: 4, Funny

      It bloody well would, unless the gaping black hole of goatse man in a million homes across the country qualifies as "defense in depth"...

    2. Re:zero day vulnerability? by burni2 · · Score: 5, Insightful

      No don't mess yourself up in the first place.

      It's called a cloudfeature being so it's not a bug it's a KODAK ;)

      Share your memories and your nude girlfriends with your friends, enemies, law enforcement agencies and employers - and clouds[1].

      [1]http://www.myspace.com/developerchallenge

    3. Re:zero day vulnerability? by Spad · · Score: 1

      With the level of captcha-beating OCR software out there these days you could probably automate a scan of the entire MAC address space for Kodak, activate any available frames and upload whatever you wanted into all of them, which would be "interesting".

    4. Re:zero day vulnerability? by fuzzyfuzzyfungus · · Score: 4, Insightful

      If one were a truly awful person, one could probably maximize the damage by going with less horrifying images...

      Classic shock site stuff turns the stomach; but, for that reason, is a pretty implausible thing to have show up outside of a hack.

      A steady stream of sexual but more or less pedestrian pictures, on the other hand, is a much more plausible thing for somebody who has a little something to hide from his/her family/significant other/doting grandparents to accidentally upload to the wrong location.

      For pure nausea you can't really beat the classics; but for pure evil, the more plausible, the better...

    5. Re:zero day vulnerability? by durrr · · Score: 5, Insightful

      For maximum damage; child pornography.
      I'm sure you are all more than capable of imagining the fallout without any further explanation; it's hard to find anything being more of the .jpeg equivalent of nuclear weapons.

    6. Re:zero day vulnerability? by xaxa · · Score: 1

      By the way, don't look at the photostreams. There's a link to one in the article, and (as of the time of this comment) it's just an activation screen, but a few MAC addresses lower and the pictures are all shock stuff.

    7. Re:zero day vulnerability? by OolimPhon · · Score: 3, Funny

      Oh, come on. Don't look at the photostreams with remaining eye.

    8. Re:zero day vulnerability? by FatdogHaiku · · Score: 1

      Would this constitute a zero day vulnerability?

      ummm, do you have something less than that? The account can be pooched before the user ever opens the box containing the device... to me that's less than zero. I just tried the RSS feed in the story, altered the hex address and yes, I could have set up a device that has yet to be unboxed... Wow, someone's ass is going on the block because you just know that a ton of goatsee, porn, and disturbing images are going to go into these accounts.

      --
      You have the right to remain sentient. If you give up the right to remain sentient, you will be elected to public office
    9. Re:zero day vulnerability? by Qzukk · · Score: 2, Funny

      If I took some pictures from each person and shuffled them around to other people, would I be crossing the photostreams?

      --
      If I have been able to see further than others, it is because I bought a pair of binoculars.
    10. Re:zero day vulnerability? by Idiomatick · · Score: 2, Interesting

      I think the best would be to take someone's photos that they have uploaded already... And photoshop them. Nothing OBVIOUS... subtle... make them a bit fatter... little more greasy and maybe slightly unsymmetrical. Over the course a few months you could crush a sufficiently vain person.

    11. Re:zero day vulnerability? by Anonymous Coward · · Score: 0

      Would this constitute a zero day vulnerability?

      Since everyone wants to claim a zero day vulnerability, I've watch the definition weaken to the point it's useless. As far as I'm concerned lets just call everything zero day and make it entirely meaningless.

    12. Re:zero day vulnerability? by ResidntGeek · · Score: 1

      That's not what zero-day means.

      --
      ResidntGeek
  2. Mac address anatomy by Arker · · Score: 4, Insightful

    Havent thought about this for awhile, but IIRC the first three octets are supposed to indicate the manufacturer of the device, so if we can assume the NIC in these frames is always from the same manufacturer, the address space to search becomes much smaller. Still, it's going to be pretty huge, with probably the largest number of possible URLs invalid, and most of the valid ones full of normal junk no one but family/friends really want to see anyhow. The probability of one or two really nice racy pictures in there will no doubt motivate someone to search the space eventually though.

    If you see anything good, or even just really strange, be sure and post it here!

    --
    =-=-=-=-=-=-=-=-=-=-=-=-=-=-
    Friends don't let friends enable ecmascript.
    1. Re:Mac address anatomy by dunezone · · Score: 3, Funny

      If you see anything good, or even just really strange, be sure and post it here!

      Nice try TMZ.

    2. Re:Mac address anatomy by Anonymous Coward · · Score: 0

      Just playing with the provided URL, going back one "number" at a time quickly provided another one.

    3. Re:Mac address anatomy by Anonymous Coward · · Score: 1, Interesting

      Another one, actually preloaded with pictures. Of course the real vulnerability is the ability of others to activate and pre-load pictures. This should really be fixed soon.

    4. Re:Mac address anatomy by sakdoctor · · Score: 1

      00:DE:AD:BE:EF

      Only the finest MAC address white-listing security for MY wireless gear.

    5. Re:Mac address anatomy by vlm · · Score: 1

      The probability of one or two really nice racy pictures in there will no doubt motivate someone to search the space eventually though.

      Just remember, goatse works both ways....

      Buy a frame for $50, upload goatse to it, for gods sake put the frame face down on the desk with a post it ordering everyone to not look at it, if not outright duct taping it, and you can goatse a "frame-scanner" or whatever you want to call them...

      As a side issue, Kodak probably knows what MACs they've sold (or do they?) so they could put up a VERY special page for framescanners of MACs that have never been manufactured. Two girls one frame, or something.

      --
      "Science flies us to the moon. Religion flies us into buildings." - Victor Stenger
    6. Re:Mac address anatomy by fuzzyfuzzyfungus · · Score: 4, Insightful

      Anybody else notice the "/productId=KD9371" bit of the URL? It would appear that this "framechannel" service either is, or is designed to be able to be, the backend to multiple digital-photo-frame products, possibly including those from other manufacturers. I couldn't find any other valid product IDs, but that was only in 30 seconds of putting in random strings, not a real effort.(and they claim )

      I'd say, until given compelling evidence otherwise, that any product using FrameChannel as a backend is Fucked. Worse, there may well be nothing that FrameChannel can do about it without breaking the service for all existing devices in the field. I'm sure, in principle, that those devices are firmware upgradeable(almost definitely just an embedded OS on a chunk of flash, with a weedy little ARM or MIPS SoC); but there is no assurance at all that the device manufacturers will offer one, nor does having to apply a critical firmware upgrade really fit well with the "ready for use by Grandma" image that the photoframes would really like to cultivate.

      I would say that we are looking at a much wider problem. This isn't just some hardware company fucking up the service that they hacked together as an afterthought to support their hardware product. This is a service provider company, whose service is integrated into hardware from over a dozen manufacturers, whose core service is completely broken and absurdly insecure. All it would take is one marginally tech-competent journalist to find a couple of baby pictures and/or a frame preloaded with 2-girls 1-cup to kick these guys so hard in the stock price that their investors' children won't be able to sit down for a month....

    7. Re:Mac address anatomy by mike260 · · Score: 1

      Whoever owns that frame sure has some interesting family photos...

    8. Re:Mac address anatomy by Ernesto+Alvarez · · Score: 2, Interesting

      Try KD9372.

      Also go to the registration page and you'll see a few models. Dunno about the model codes, though.

    9. Re:Mac address anatomy by arabagast · · Score: 1

      my favourite: 00:FA:CE:FE:ED

      and for some more fun hex strings: hexspeak

      --
      Doolittle : ...What is your one purpose in life?
      Bomb no.20 : To explode of course.
    10. Re:Mac address anatomy by fuzzyfuzzyfungus · · Score: 2, Insightful

      I messed up the link. It should be their claimed list of devices.

      Also, the company behind this service is Thinking Screen Media. This sort of thing is, in fact, their core business.

      The above link has linkedin profiles for their entire management team and board of directors. Who wants to break the news?

    11. Re:Mac address anatomy by AmiMoJo · · Score: 1

      with probably the largest number of possible URLs invalid

      What are the chances they are sequentially numbered?

      --
      const int one = 65536; (Silvermoon, Texture.cs)
      SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC
    12. Re:Mac address anatomy by xaxa · · Score: 1

      Like this one? (NSFW! Even for those of us in Europe.)

      It seems the registration process doesn't require anything more than the "activation code", which is shown in the RSS feeds for unactivated frames.

    13. Re:Mac address anatomy by tom17 · · Score: 1

      It seems to have been reset. I wonder if the creator de-activated it, or if the FrameChannel guys have been deleting the newly registered 'hacked' ones due to excessive traffic or something...

      Tom...

    14. Re:Mac address anatomy by MartinSchou · · Score: 1

      All it would take is one marginally tech-competent journalist to find a couple of baby pictures and/or a frame preloaded with 2-girls 1-cup

      Remember that even possessing child pornography is a federal offence or something like that in the US. Even (probably especially) if you then delete the pictures without notifying the authorities.

      Wouldn't it be interesting if someone were to send one of these picture frames to all the federal politicians in the US. And then made sure their particular frame would pull up such pictures? Instant slammer time for all politicians. Imagine how much fun the news networks would have with that.

      </evil grin>

    15. Re:Mac address anatomy by Anonymous Coward · · Score: 0

      It seems to have been reset.

      Sorry, that was me :-S (using the /reset=1 that's described below).

      (I didn't think it was working, so I tried it on the goatse one, but I think it was working and the page was just cached...)

    16. Re:Mac address anatomy by Nerdposeur · · Score: 3, Interesting

      I just sent them an email with a link to this story and urged them to act quickly. This is funny and all, but will someone please think of the grandmas?

    17. Re:Mac address anatomy by darthnoodles · · Score: 2, Informative

      All unregistered frames now go to an error image. It states that they can't provide a registration number at this time. Looks like they caught on.

    18. Re:Mac address anatomy by NotBornYesterday · · Score: 1

      Instant slammer time for all politicians.

      If they were regular people, maybe. Even then, decent investigative work should show that they were framed, so to speak (har har har). I know you're just joking, but can you imagine the uproar this would cause? Hilarious, to be sure, until the congresscritters use it as an excuse to legislate another rights-curbing abomination to control the internet in the name of protecting the children.

      --
      I prefer rogues to imbeciles because they sometimes take a rest.
    19. Re:Mac address anatomy by Tensor · · Score: 1

      racy like this ? NSFW obviously

      http://rss.framechannel.com//productId=KD9371/frameId=00:23:4D:B8:07:6e

    20. Re:Mac address anatomy by geekoid · · Score: 1

      try TK321

      --
      The Kruger Dunning explains most post on /. http://en.wikipedia.org/wiki/Dunning%E2%80%93Kruger_effect
    21. Re:Mac address anatomy by yacc143 · · Score: 1

      Well, ideally you should do that out of a country, that has a more strict definition of child pornography. Then mail the frames with a believable cover letter, ...

      And then post the URLs to the news media and the FBI, ideally anonymously :)

    22. Re:Mac address anatomy by Anonymous Coward · · Score: 0

      Hey, it's not like they're not tackling the vulnerability. They're removing all the MACs posted on Slashdot. What more could you want?

    23. Re:Mac address anatomy by Anonymous Coward · · Score: 0

      http://rss.framechannel.com//productId=KD9371/frameId=00:23:4D:B8:07:13
      has also been hacked, very politely I might add, except for the manatee p0rn

    24. Re:Mac address anatomy by An+ominous+Cow+art · · Score: 1

      I tried TK421, but it wasn't at its post.

    25. Re:Mac address anatomy by MichaelSmith · · Score: 1

      Its not in the correct position.

    26. Re:Mac address anatomy by pwfffff · · Score: 1

      Some programmer's day just got a lot shittier as well... :(

    27. Re:Mac address anatomy by fuzzyfuzzyfungus · · Score: 2, Informative

      All addresses are now returning an identical "fmdefaultfeed", so it looks like they got a dirty hack in place. Probably a fair few bullets sweated, though.

      I just hope that the inevitable grudge firings fall on the guy who said "C'mon, unique keys will add manufacturing complexity, we'll just use MACs" rather than whatever poor bastard just did the implementation.

    28. Re:Mac address anatomy by Anonymous Coward · · Score: 0

      not true, I was able to get a feed by typing in random mac addresses manually. They've just added user-agent checking, so you have to spoof your user agent, like so:
      curl -A "AVOS/1.1 libhttp/1.1" -o ~/Desktop/test.rss http://rss.framechannel.com//productId=KD9371/frameId=00:23:4D:B8:07:6D

  3. Competition: by RMH101 · · Score: 1

    Best "you've been p0wned" slideshow set. Post URL when done.

    1. Re:Competition: by think_nix · · Score: 1

      all your pix are belong to us

    2. Re:Competition: by Anonymous Coward · · Score: 0

      Prediction: It's going to include Goatse.

    3. Re:Competition: by Anonymous Coward · · Score: 0

      I'm pretty sure this URL was activated by someone who read TFA or this /. story. Note the 'hackers123' username and the update timestamp. Pretty innocuous pictures so far, though.

    4. Re:Competition: by Anonymous Coward · · Score: 0

      I would guess that this one has been gotten at.
      Apologies to Mr. Goatse2600 if I'm wrong.

    5. Re:Competition: by mike260 · · Score: 1

      Looks like the guy who broke the story has been visited by the frame-fairy.

    6. Re:Competition: by Anonymous Coward · · Score: 0

      I am just browsing, but a simple flip of the original author's mac, swapping a 1 for a 6 and we get this page someone from 4chan must have hit and another swaps of MAC and we get this page with the amusing registration password of "PEEPU". hahah. PEE POO.

    7. Re:Competition: by RMH101 · · Score: 1

      that is *pure* 4chan. Nice find!

  4. so now we know the main plot point by circletimessquare · · Score: 3, Funny

    for "the ring ii"

    --
    intellectual property law is philosophically incoherent. it is your moral duty to ignore it or sabotage it
  5. Luckily... by fuzzyfuzzyfungus · · Score: 3, Interesting

    MAC addresses are in no way predictable based on the company producing the product in question, so we should be perfectly safe.

    Sarcasm aside, how could they possibly have thought that this was a good idea? Nobody expects Joe Consumer to remember something as hostile as a MAC address, so there isn't a "user convenience" argument to be made, and anything with enough processor power and mass storage to run these sorts of web functions could have gotten away with cramming in an onboard GUID or some certs or something. WTF?

    1. Re:Luckily... by drinkypoo · · Score: 1

      It's pretty obvious, they printed the MAC on the device, and were looking for a unique code to use for the password that wasn't the serial number.

      I'm hoping I can hack my HP photo frame, it's got USB2, CF, and SD! It plays fullscreen video very nicely (I transcoded a DVD to it with ogmrip) and I would guess it's got some cojones.

      --
      "You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
    2. Re:Luckily... by Stenchwarrior · · Score: 1

      Nobody expects Joe Consumer to remember something as hostile as a MAC address, so there isn't a "user convenience" argument to be made

      Then maybe they will implement MNS (Mac Name Service)?

      --
      Loading...
    3. Re:Luckily... by Anonymous Coward · · Score: 0

      its more obvious than that.
      they dont expect a user to remember or know the mac. the user just turns the thing on and says "framechannel". it does a GET of the as-yet-undefined feed. The feed it gets back has an image that says "log into framechannel.com and enter this confirmation code: XXXXXX". the user does that, and thus attaches their new device to the account.

  6. cue ... by Anonymous Coward · · Score: 2, Insightful

    /. effect across the entire product line. Be polite and don''t load them with tubgirl.

  7. How many people will get their brand new frame... by Chrisq · · Score: 4, Insightful

    How many people will get their brand new frame home, plug it in and find that it displays a "preloaded" goatse

  8. Well... by benjymous · · Score: 2, Interesting

    It seems you get an RSS feed with an activation code no matter what you enter for the frameid (it doesn't even seem to have to be a valid MAC address) so it seems they're not filtering on the server for addresses that actually belong to frames

    --
    Help me! I'm turning into a grapefruit!
    1. Re:Well... by Ernesto+Alvarez · · Score: 4, Interesting

      Even more interesting, using an id of "'" (an apstrophe) gets you some sort of default channel with some rather nice pictures. They even change them after some time.

      http://rss.framechannel.com//productId=KD9371/frameId='

      I wonder what's happening behind curtains.

    2. Re:Well... by benjymous · · Score: 1

      Considering that the activation code has 5 alphabetic characters, I'd guess the process works something like:

      Frame requests a page based on its MAC
      Server has no record, so it generates a new feed, creates a (random?) activation code, and logs this in its database
      User sees the message, enters the activation code online, which is retrieved from the db.

      5 digits doesn't give many options. What happens if they all get used up when people start scanning and generating fake IDs? Will the database just fall over, and be unable to activate new frames at all?

      --
      Help me! I'm turning into a grapefruit!
    3. Re:Well... by Ernesto+Alvarez · · Score: 1

      I meant what was going on with the apostrophe business.
      What sort of logic would get the default feed.

      (I was honestly expecting a database error....)

    4. Re:Well... by ConstantiusChlorus · · Score: 2, Funny

      I wonder what's happening behind curtains.

      Screaming. Finger pointing, witch-hunts and frantic resume polishing. The usual.

    5. Re:Well... by mike260 · · Score: 1

      5 digits doesn't give many options.

      It's 5 alphanumeric chars, so that's around 60m combinations. A limit of 60m activations in-flight at any one time seems reasonable to me.

    6. Re:Well... by benjymous · · Score: 1

      Ahh, you right - the few I tried all seemed to be alphabetic only, which would've rather limited the pool

      --
      Help me! I'm turning into a grapefruit!
    7. Re:Well... by Anonymous Coward · · Score: 0

      Heh..
      Worse still, you can directly retrieve content from http://fs.framechannel.com/
      Looks like the filesystem is described in the XML returned ..

      0000193a728fd00b6cff91b8840bbf8d.jpg
      2009-10-22T04:02:13.000Z
      "3ec327314496f0d6d92467f399bfdba8"
      114017
      STANDARD

      http://fs.framechannel.com/0000193a728fd00b6cff91b8840bbf8d.jpg ( the Key value )

  9. Re:How many people will get their brand new frame. by Anonymous Coward · · Score: 1, Insightful

    With the right script and an image recognition software, everyone in a few hours.

  10. Not cool... by Anonymous Coward · · Score: 0

    Take the links down, theres innocent peoples photographs being put up on the net. :\ I stumbled across some family photos, I know I wouldn't be happy if it was my kids. Poor form by the source of this article. :(

    1. Re:Not cool... by Anonymous Coward · · Score: 2, Interesting

      Some kind soul needs to put together an image that explains how insecure the system is and its ramifications, and upload it to all photo frames.

    2. Re:Not cool... by Anonymous Coward · · Score: 0

      It's already been done

    3. Re:Not cool... by maokh · · Score: 1

      It was my own RSS link I posted, which the service provider provided me to share with whomever. You are looking at pictures of my family, my kids, my facebook, etc. How is this poor form?

  11. Actually this illustrates the problem well by Chrisq · · Score: 2, Funny

    This innocent person has posted pictures of children and some recognisable locations. All it takes is for some pedo pervert to fantasise over the pictures and track them down.

    1. Re:Actually this illustrates the problem well by Anonymous Coward · · Score: 4, Insightful

      Ofcourse, because tracking children down through compromised picture frames is so much more convenient for a person with malicious intent than just going to a local playground or primary school.

      I really dont understand this urge of blowing simple stories completely out of proportion by mentioning pedosexuals, muslims or the banking system.

    2. Re:Actually this illustrates the problem well by Chrisq · · Score: 1

      Well for a known offender it would be a safer activity... I'm not saying its likely but it could happen

    3. Re:Actually this illustrates the problem well by Anonymous Coward · · Score: 0
    4. Re:Actually this illustrates the problem well by Anonymous Coward · · Score: 1, Insightful

      And the exact same thing can't happen via webpages, blogs, social networking sites, and any of eleventy billion other places people post photos of their children?

      Christ, get a sense of perspective here.

    5. Re:Actually this illustrates the problem well by Anonymous Coward · · Score: 0

      it's been re-enabled. How did they do that.

    6. Re:Actually this illustrates the problem well by mike260 · · Score: 2, Insightful

      The frame would have switched back to the activation screen again. The owner would've scratched his head, shrugged, followed the activation instructions and re-upped his photos, innocent to the dark forces swirling beneath the surface of his friendly-looking gadgets.

    7. Re:Actually this illustrates the problem well by Anonymous Coward · · Score: 0

      Why would it be safer? I known offender probably couldn't go hanging around his local playground (too bad if he has kids, he no longer counts as a person), but it would still be easier to drive to a school some short distance away (these locations aren't secret) where people are unlikely to notice him, than search through all these pictures to find a recognizable location that's not halfway across the country.

    8. Re:Actually this illustrates the problem well by geekoid · · Score: 1

      Recognized location would mean a place the pedo visits already.

      --
      The Kruger Dunning explains most post on /. http://en.wikipedia.org/wiki/Dunning%E2%80%93Kruger_effect
    9. Re:Actually this illustrates the problem well by Anonymous Coward · · Score: 0

      I really dont understand this urge of blowing simple stories completely out of proportion by mentioning pedosexuals, muslims or the banking system.

      Spoken like one of our pedosexual, muslim, banker overlords.

    10. Re:Actually this illustrates the problem well by pwfffff · · Score: 1

      A) You've been to the Statue of Liberty, the Eiffel Tower, the Great Wall of China, and the moon.
      B) You've never heard of any of the above.
      C) You can recognize locations you don't visit.

      One of these options is aligned with reality. See if you can figure out which.

    11. Re:Actually this illustrates the problem well by Thud457 · · Score: 1

      A) You've been to the Statue of Liberty, the Eiffel Tower, the Great Wall of China, and the moon.
      B) You've never heard of any of the above.
      C) You can recognize locations you don't visit.

      One of these options is aligned with reality. See if you can figure out which.

      That'd be A) , I'm fuckin' Buzz Aldrin, beeotches!!!!

      --

      the preceding comment is my own and in no way reflects the opinion of the Joint Chiefs of Staff

    12. Re:Actually this illustrates the problem well by Blakey+Rat · · Score: 1

      I really dont understand this urge of blowing simple stories completely out of proportion by mentioning pedosexuals, muslims or the banking system.

      Me neither.

      If you're going to blow simple stories completely out of proportion, you'd be better off mentioning pedosexuals, Muslims *and* the banking system all at the same time! Do it right, people.

    13. Re:Actually this illustrates the problem well by Anonymous Coward · · Score: 0

      This innocent person has posted pictures of children and some recognisable locations. All it takes is for some pedo pervert to fantasise over the pictures and track them down.

      How do YOU know this person is innocent? For all you know, these are trophies taken by a serial killer which he displays in his basement next to his cistern and moth cage.

  12. ScaredOf TheMan by Anonymous Coward · · Score: 0

    Pheeeeww Sure am glad I keep my online photos safe on facebook, you know, where no one can see them without my.......What the!?!!

  13. Pictures of dicks by bluefoxlucid · · Score: 2, Funny

    And of course, we live in a world where every 13 year old is going to look at this and go, "Sweet! When the next guy buys one of these things, he's going to see pictures of dicks!"

    1. Re:Pictures of dicks by Anonymous Coward · · Score: 0

      Someone's done it already (no, not me): http://rss.framechannel.com//productId=KD9371/frameId=00:23:4D:B8:07:29

  14. The sad thing is... by jomegat · · Score: 4, Insightful

    The really sad thing here is that if some white hat wrote a script to find these and upload to them an image warning the owners of the vulnerability, said white hat would almost certainly get smacked down by a DMCA suit or face civil/criminal penalties. No good deed goes unpunished.

    --

    In theory, practice and theory are the same. In practice, they're not.

  15. This is hilarious! by Dri · · Score: 1

    I'd pay a grand to see the system design behind the "frame" and what decisions were made on what grounds. The arguments like, -"Hey, there is this thing called a MAC address, it's like, globally unique and stuff!"

    Kodak, you're toast!

    --
    Girls are strange. They don't come with a man page.
    -- Michael Mattsson
    1. Re:This is hilarious! by fuzzyfuzzyfungus · · Score: 1

      If you are serious, just give these guys a ring...

      That is the upper management, board of directors, and board of advisors for the company behind this mess(yes, Virginia, this isn't just Kodak, this is a company whose core business is "connected screens"). Take a bow, guys, take a bow.

    2. Re:This is hilarious! by SanityInAnarchy · · Score: 1

      My brain rebels at trying to actually read that paragraph.

      Thinking Screen Media, Inc. (formerly Frame Media, Inc.) is the leader in content delivery to connected screens worldwide. Founded in 2007, Thinking Screen enhances the value proposition of connected screens...

      ...and I just stop. I have to, or I'll black out from the stupidity. "Enhances the value proposition"... gah!

      Even when I force myself (with some considerable effort) to read the entire thing, that's got to be one of the most empty bits of marketing fluff I've ever seen.

      --
      Don't thank God, thank a doctor!
  16. Let's get it on... by Dri · · Score: 2, Funny
    --
    Girls are strange. They don't come with a man page.
    -- Michael Mattsson
  17. Not difficult to track down actual users by Anonymous Coward · · Score: 3, Interesting

    1. Play with the MAC address to find a live frame. It took me 4 tries.
    2. Scroll down and see if one of their images is the weather forecast, complete with the city and state for the forecast.
    3. Now look at the userid. It likely contains a first initial and a last name.
    4. City, state, last name, first initial -- that may very well be enough to get a street address.
    5. Most people have pics of their family, including their kids. You've got a name, address, and photos of the fam.

    It seems to me that goatse/tubgirl -ing these things is the only responsible thing to do. Sure, a few dozen (hundred?) people will have to gouge their eyes out, but it's a small sacrifice necessary to generate consumer push back on this kind of nonsense.

    1. Re:Not difficult to track down actual users by Anonymous Coward · · Score: 0

      Because a little kid seeing a goatse picture on their photo frame in their living room is a necessary sacrifice? You disgust me.

    2. Re:Not difficult to track down actual users by Anonymous Coward · · Score: 0

      Which is worse...

      The kid seeing the Goatse pic?

      The kid getting abducted by a pedopreditor?

      While I don't think the GP poster's ends justify the means, I do believe that the problem is as stated. A skilled person can figure out how to obtain the pics as implied in the post- and from there, if they DO happen to have kids or grandkids, the predator can draw a bead on their location. While I'm not one for "think of the kids", in this case, the security of the frames is rather atrocious and Kodak needs to push an update that removes this hole or recall the whole lot.

    3. Re:Not difficult to track down actual users by Anonymous Coward · · Score: 0

      Well, most of the ones I found were either in France or California, so you'll need more than goatse or tubgirl on them things...

    4. Re:Not difficult to track down actual users by Anonymous Coward · · Score: 4, Insightful

      Ah yes, the infamous false dichotomy. :) Because simply putting a "Your Photo Frame Has Been Hacked" message just wouldn't do. Only hard-core porn is appropriate.

    5. Re:Not difficult to track down actual users by xaxa · · Score: 1

      A picture of Goatse is hardly necessary.

      Just a picture with the text "This device is insecure. Your photographs are available online at [rss address]. For more information, see [news site]" would be fine.

    6. Re:Not difficult to track down actual users by Anonymous Coward · · Score: 1, Informative

      Ordinary people don't freak out about seeing "this device is insecure". They just shrug and move on. Ordinary people do freak out about seeing goatse, though. If you wanted to hurt Kodak financially (as a disincentive to using such poor security practices), preloading with goatse would be 100x more effective than preloading with some polite message. It would also be far more likely to get press coverage.

    7. Re:Not difficult to track down actual users by radish · · Score: 1

      1. Drive down random street.
      2. Stop outside random house.
      3. Check inside mailbox - you now have name & address.
      4. Hang around a bit on a weekend, you now have an actual family in front of you!

      I'm all about protecting privacy, but the ability to get the name and address of a random person is hardly new. What's more dangerous (and I don't think is really possible here) is the ability to get the name and address of a _specific_ person. The security concern in this situation (AFAIC) is the ability for people to randomly snarf photos you thought were at least reasonably private, and the ability to insert stuff into your frame.

      --

      ---- Den ene knappen er powerknapp, den andre er Bender voice knapp "Bite My Shiny Metal Ass"

    8. Re:Not difficult to track down actual users by Anonymous Coward · · Score: 0

      A picture of Goatse is hardly necessary.

      I agree wholeheartedly. This is as job for Tubgirl or Lemonparty.

    9. Re:Not difficult to track down actual users by natehoy · · Score: 1

      With respect, your scenario is extremely impractical. I can't think of a single benefit using a hacked Kodak frame would offer to the would-be pedophile.

      Kodak frames exist across the country. The pedophile would have to hack random frames one by one and look at pictures to narrow pictures down to:
      (a) a victim they like,
      (b) that they can then verify actually lives in the house and isn't a grandparent's house or something,
      (c) whose parents have put enough information on the frame to be identified and located,
      (d) in close enough proximity to them to make it feasible.
      Then, they'd still have to collect enough information to figure out when the child might be unattended so they can attempt a kidnapping, or figure out some other means of luring the child away.

      In other words, the frame offers them almost no useful information, and takes a great deal more time and effort than a Facebook search (which yields far more data AND offers a way to contact the victim) or just getting in their car and driving randomly around school zones watching for kids walking home alone, then figuring out what general direction they are headed. Or just driving around looking for a kid walking alone.

      If the pedophile wants pictures of your kids taking a bath, OK, I can see this being a risk if you're uncomfortable with someone spanking off to pictures of your kids. I know the concept of it happening with a picture of my daughter makes my skin crawl.

      And Kodak needs to fix this or recall their frames (or sell them as an interesting social experiment in digital graffiti - I might pay a few bucks for one and publish its URL just out of sheer curiosity about what random strangers might post to it).

      But they don't need to recall it to protect children from being kidnapped.

      --
      "This post contains words, known to the State of California to cause thought. Wash brain thoroughly after reading."
    10. Re:Not difficult to track down actual users by Anonymous Coward · · Score: 0

      First one I found with actual personal photos.

      http://rss.framechannel.com//productId=KD9371/frameId=00:23:4D:B8:07:62

    11. Re:Not difficult to track down actual users by SanityInAnarchy · · Score: 1

      Actually, yeah. American consumers do pretty much need that kind of a kick in the balls before they'll take action.

      --
      Don't thank God, thank a doctor!
    12. Re:Not difficult to track down actual users by FiloEleven · · Score: 1

      "This device is insecure" is too weak. "YOU'VE BEEN HACKED" in big red letters with further details below is the way to go. Eye-catching, and likely to get a response, especially if there's a number to call--keep in mind that most people are more comfortable with phones than the internets.

      Putting goatse on there is irresponsible and unhelpful, especially in cases where the person who set up the channel is not the person displaying the frame (think grandma). Don't try to dress up your lulz as something they're not.

    13. Re:Not difficult to track down actual users by Anonymous Coward · · Score: 0

      mmmmmmm, little girls, how sweet...
      and apparently mom, dad, gramma & grandpa, and they're Gators who live in Florida
      man talk about leaving the barn door open

  18. Doesn't surprise me by Kaz+Riprock · · Score: 2, Interesting

    Given how rudimentary and just plain awful Kodak's interface was for their WiFi picture frames from 2 years ago when I bought a few for the family to share the same albums with each other across the nation, this story doesn't surprise me in the least.

    I mean, who lets the frame go on the internet and builds in a timer for when to turn the frame off and on at night...but then when it comes back on it ONLY goes to its own internal memory and NOT the last gallery you were viewing via the WiFi?? Every morning you have to reconnect it to the internet galleries...and its ability to cache the pics from the internet is so poor that it will often claim it has an "error" and...REVERT BACK TO INTERNAL MEMORY! It's next to impossible to use it to view galleries on the internet...that can ONLY be on their website...AND that they're now CHARGING you to keep "active"!

    So, no, it doesn't surprise me at all that they could screw even this basic security up.

    --
    Mordor...a magical, mythical land where women are more rare than dragons--but where every man would rather find a dragon
    1. Re:Doesn't surprise me by vlm · · Score: 2, Insightful

      Given how rudimentary and just plain awful Kodak's interface was for their WiFi picture frames from 2 years ago when I bought a few for the family to share the same albums with each other across the nation, this story doesn't surprise me in the least.

      I've noticed that problem is nearly universal across the entire pic frame marketplace. I swear the manufacturers are trying to kill the marketplace by intentionally making frame with horrific UIs.

      Why can't I buy a frame that simply displays a .RSS on the internet? Not a monthly pay service. Not some 3rd party that'll probably be out of business before the batteries die. Not some special format only. Just freaking show me the pix. And please no BS about processing power as everyone knows a 8 MHz XT in the 80s was good enough to view Pr0n so don't give me some BS that a dedicated 100 MHz process "could never possibly display a picture without preprocessing".

      Why can't I buy a frame that simply displays a URL? Heres the webcam IMG tag, now download it every 60 minutes and leave me alone? Again no stupid third party subscription BS please?

      Why can't I buy a frame that simply watches for a specific browsable SMB share and directory, and every time it appears on the network, sync to the local copy, plus sync every 15 minutes thereafter?

      All I can find to purchase is either flash card only, or if its networked its absolute junk garbage.

      Unless some manufacturer will build one that doesn't suck (and I got a pocket full of cash I'm willing to spend), I'm going to have to wall mount a plain ole LCD monitor, get one of those "video over Cat-5 balun thingys" and run a low power PC in my basement. I swear I'm gonna do it this year (is that the geekiest 2010 new years resolution ever?)

      --
      "Science flies us to the moon. Religion flies us into buildings." - Victor Stenger
    2. Re:Doesn't surprise me by Skraut · · Score: 1

      Agree 100% Wife bought me a frame for Christmas that she found in a grocery store, I read the box and made her take it back. Then my parents got her the same exact frame. Horrible resolution, no wireless features, the darn thing couldn't even play the photos randomly, just play them sequentially.

      --
      Introducing Microsoft Vacuum 1.0 The first Microsoft product that doesn't suck.
    3. Re:Doesn't surprise me by Neeth · · Score: 1
      --
      Yes, I am the one with the legendary sig.
    4. Re:Doesn't surprise me by wowbagger · · Score: 4, Insightful

      "Why can't I buy a frame that simply displays a URL?"
      "Why can't I buy a frame that simply watches for a specific browsable SMB share and directory, and every time it appears on the network, sync to the local copy, plus sync every 15 minutes thereafter?"
      "Why can't I buy a frame that simply displays a .RSS on the internet? Not a monthly pay service."

      Because then how can the manufacturer of the frame monitize you from a worthless waste of baryonic matter into a shining revenue stream? You forget your place, consumer: you are to consume product and crap cash on demand, month in, month out. Now get to work!

    5. Re:Doesn't surprise me by machine321 · · Score: 1

      Perhaps you should have purchased a Chumby, although most people would balk at a 4" picture frame for $100.

    6. Re:Doesn't surprise me by nanomanc · · Score: 1

      So make one then.

    7. Re:Doesn't surprise me by Anonymous Coward · · Score: 0

      Why can't I buy a frame that simply displays a .RSS on the internet?

      Get a Chumby. Or if that's too cute, just buy the Chumby guts and put 'em in your own frame. Screen's a bit small, but it's designed (and intended) to be hacked.

      In answer to your question - because nobody pays $100 for something that's just a digital picture frame, and if you're selling them for $20, you've gotta have a pay "service" with recurring revenue to make the business plan work. Knocks most of us techies out of the market. And Grandma won't want to deal with setting up RSS feeds, she just wants something that's easy to set up, and she won't notice the $5/month or whatever the fee is.

      As of a couple of years ago, 580,000 people still rent their landline phones from AT&T, and have paid upwards of $10,000 over their lifetimes. We're not talking smartphones here, we're talking that old rotary-dial thing from the 50s.

      Never underestimate the power of inertia.

      Back in the dialup days, I paid the phone company $8/month for an "answering machine service". When I was on dialup, it was nice to have all incoming calls routed to voicemail. On broadband, no need to pay $8/month for the rest of my life when a $5 surplus answering machine would have done just as well at screening out telemarketers. And yet after I switched to DSL, I took three months to get off my ass and cancel the silly $8/month charge. D'oh.

    8. Re:Doesn't surprise me by Anonymous Coward · · Score: 0

      Why can't I buy a frame that simply displays a .RSS on the internet?

      You can. The Kodak W820 I picked up last month lets me enter arbitrary RSS feeds for display instead of their own Kodak Gallery, FrameChannel, and Flickr preset defaults.
      Setup your own RSS feed and server and remove the preset feeds. Done.

      Haven't run into the "fallback to onboard slideshow on wakeup" issue with the clock feature.

      It also plays mp4 rips in widescreen format and makes a nice small TV for the kitchen too.

    9. Re:Doesn't surprise me by Just+Some+Guy · · Score: 2, Informative

      Why can't I buy a frame that simply displays a .RSS on the internet? [snip etc etc etc ]

      You want a Chumby. Mine does all that, and you can SSH into it.

      --
      Dewey, what part of this looks like authorities should be involved?
    10. Re:Doesn't surprise me by Anonymous Coward · · Score: 0

      Why can't I buy a frame that simply displays a URL?

      You have pictures of URLs on your wall? Have my geek badge, I don't deserve it.

    11. Re:Doesn't surprise me by Anonymous Coward · · Score: 0

      We need somebody with Arduino and electronics knowhow that doesn't care about the product warranty to crack a few of those frames open and save us from the bullshittery. I'm sure once a particular inexpensive model is found with an easily hackable screen and sufficient room in the case, we'll have a conversion kit available.

      Then you can program it to screen grab whatever you want, or stream a webcam, or read from a SD card in any order, etc. with all that Linux goodness so it would be possible to know what's going on inside.

    12. Re:Doesn't surprise me by Anonymous Coward · · Score: 0

      Nice, but at $240+shipping you can do much better with a trashcan pc loaded with linux hooked up to a cheap 19" lcd.

    13. Re:Doesn't surprise me by Achra · · Score: 1

      Why can't I buy a frame that simply displays a .RSS on the internet? Not a monthly pay service. Not some 3rd party that'll probably be out of business before the batteries die. Not some special format only. Just freaking show me the pix.

      Actually, the Kodak EasyShare frames that we happen to be discussing have this feature. I own one, it's a weird little box, but you can definitely point it to whatever RSS feed you like. and No, mine isn't pointed to framechannel.

      --
      Each processor would proceed sequentially as if it had been better for them not to rise against Saul.
    14. Re:Doesn't surprise me by Anonymous Coward · · Score: 0

      I bought a kodak frame last year for the in-laws as a x-mas gift for the very purpose of being able to share photos from afar and it was a nightmare to get set up. This was a pre-frame channer model (not that Kodak ever told me that, despite my numerous hours spent with them on customer suport.) I never got Kodak's own system for sharing photos to work and I tried everything. The thing has wifi but it's useless and never did what was advertised. This debacle serves them right as far as I'm concerned.

    15. Re:Doesn't surprise me by netsharc · · Score: 1

      Hah, but you sort of can: set up your own DNS server on your router, resolve the server's name to your own server, and give it whatever feed you want. :)

      OK that's more steps than "buy a frame that simply displays a .RSS on the internet", but... it would be a neat hack.

      --
      What time is it/will be over there? Check with my iPhone app!
    16. Re:Doesn't surprise me by Anonymous Coward · · Score: 0

      As an owner of one of these, that uses it with his picasa account's RSS feed, and not through framechannel, i have no idea what you are talking about.

      These support *any* image rss feed I have tried.

    17. Re:Doesn't surprise me by Anonymous Coward · · Score: 0

      lol that made me laugh man.

  19. Re:How many people will get their brand new frame. by tom17 · · Score: 1
  20. Re:How many people will get their brand new frame. by couchslug · · Score: 1

    "How many people will get their brand new frame home, plug it in and find that it displays a "preloaded" goatse"

    I now have a gift idea my friends will remember.

    --
    "This post is an artistic work of fiction and falsehood. Only a fool would take anything posted here as fact."
  21. Looks like you can also reset accounts..... by Ernesto+Alvarez · · Score: 4, Interesting

    I was checking some of the links and noticed a few interesting parameters

    http://www.framechannel.com/feeds/pair/index.php/r=1/frameModelCode=KD9372/frameModelId=1/frameId=PAPAPA/reset=0/language=en/7072.jpg

    See that parameter named reset? I activated an account and verified it as activating. Then I triggered that reset parameter to 1 and it went back to the pre-activation state!

    1. Re:Looks like you can also reset accounts..... by benjymous · · Score: 3, Interesting

      Ok, now it's nasty - until now you could randomly initialise an inactive (possibly never real in the first place) account. Now it seems to can find the real accounts, and reset them into nastyness.

      Massive product recall ahoy

      --
      Help me! I'm turning into a grapefruit!
    2. Re:Looks like you can also reset accounts..... by mike260 · · Score: 1

      Yep, verified.
      Mod parent up - as someone else said, this enables a whole new level of nastiness.

    3. Re:Looks like you can also reset accounts..... by laughing_badger · · Score: 5, Funny

      So, a script that changes the content for a video of Obama looking around the room for a few seconds at a random time every few days and then restores the original content. That would probably send some paranoid folks nucular.

      --
      Help children born unable to swallow - www.tofs.org.uk
    4. Re:Looks like you can also reset accounts..... by Edzilla2000 · · Score: 1

      A simple script, and every single account wiped clean... That's even better than the goatse idea!!

    5. Re:Looks like you can also reset accounts..... by Anonymous Coward · · Score: 0

      Also verified, note I just reset the 'kodakisstupid' account created (and linked to) earlier using the above method.

      http://rss.framechannel.com//productId=KD9371/frameId=00:23:4D:B8:07:8a

      It's really easy to find regsitered photoframes by just banging in random mac addresses. They really need to take this site down now.

    6. Re:Looks like you can also reset accounts..... by mike260 · · Score: 1

      They really need to take this site down now.

      From your mouth to the framemedia's ears:
      "We are unable to activate your frame at this time. Please email support@framemedia.com for help resolving this issue."

    7. Re:Looks like you can also reset accounts..... by argStyopa · · Score: 1

      "That would probably send some paranoid folks nucular." ...or give the White House some new ideas. Thanks a bunch.

      --
      -Styopa
    8. Re:Looks like you can also reset accounts..... by Culture20 · · Score: 1

      So, a script that changes the content for a video of Obama looking around the room for a few seconds at a random time every few days and then restores the original content. That would probably send some paranoid folks nucular.

      *Smoke*


      *Smoke*

      Are you smoking yet?

    9. Re:Looks like you can also reset accounts..... by discojohnson · · Score: 1

      The firmware is self-updating over the web, so if they made the service smarter, it'd be a relatively easily implemented fix. I have one of these, but then again I use my local UPnP server for my frames.

  22. New Name for company (or device) by galego · · Score: 1

    PwnDak

    --

    Que Deus te de em dobro o que me desejas

    [May God give you double that which you wish for me]

  23. Re:FrameChannel content for goatse2600 by DevConcepts · · Score: 1

    http://rss.framechannel.com//productId=KD9371/frameId=00:23:4D:B8:07:6A Have fun just changing ID... FrameChannel content for goatse2600 http://www.framechannel.com/ Channel for user goatse2600 2 Gaping Bunghole goatse2600 FALSE My Photos http://fs.framechannel.com/31c8c815fb7ed72689d48793be853def.jpg My Photos Tue, 05 Jan 2010 14:15:57 -0500

  24. Switch activation codes, get someone elses pics? by Anonymous Coward · · Score: 1, Funny

    Could be funny to swap the default activation pics (with the activation codes) so you upload your photos to someone elses photo frame and you get some randoms...

  25. firstname and lastname are XML tags in the source by Anonymous Coward · · Score: 0

    3 is much easier -- users provide their first and last name for your convenience.

  26. Serves them right by wiredlogic · · Score: 1

    They deserve this for gutting their engineering operations in Rochester. This is what you get when you farm out your product design to the lowest bidder in a far off land.

    --
    I am becoming gerund, destroyer of verbs.
    1. Re:Serves them right by Anonymous Coward · · Score: 0

      > This is what you get when you farm out your product design to the lowest bidder in a far off land.

      Because Lord knows, American programmers never screw up.

  27. So so bored by Anonymous Coward · · Score: 0

    Too many 'junk' characters to post directly, however: http://pastebin.com/f16f4aedb

  28. Simple reason WHY they did it... by nweaver · · Score: 3, Insightful

    Its sloppy to do, but here's why they did it....

    Each device needs a unique serial number, something to identify it. But at the same time, they didn't want to customize the firmware for each device to include a serial number.

    So instead, some brilliant programmer observed that the embedded processor can get the MAC address from the NIC and use that as a serial number for accessing the web page.

    This is an old and useful trick, but the only problem is although it gives you a unique serial number per device, it gives you a predictable serial number per device and because of the nature of the back-end service, they didn't just need a UNIQUE serial number, but also an UNPREDICTABLE serial number. Ooops.

    --
    Test your net with Netalyzr
    1. Re:Simple reason WHY they did it... by vlm · · Score: 1

      because of the nature of the back-end service, they didn't just need a UNIQUE serial number, but also an UNPREDICTABLE serial number

      Looks like the device also has a username ... A pity they didn't concatenate the username with the MAC and then MD5 hash it. That would be quite unpredictable, although there is no longer a guarantee of uniqueness (although collisions would be 'kind of rare')

      --
      "Science flies us to the moon. Religion flies us into buildings." - Victor Stenger
    2. Re:Simple reason WHY they did it... by iburrell · · Score: 1

      If they had just hashed the MAC address, it would be harder to predict and not obvious it came from the MAC address. Hashing it with a secret key (but shared key) would probably have been enough security. They would have a problem if the key was compromised but it could be model or firmware version specific.

    3. Re:Simple reason WHY they did it... by RealGrouchy · · Score: 1

      UNPREDICTABLE serial number

      Aren't serial numbers by definition produced in order?

      (Of course this is just semantic; "ID number" would work.)

      - RG>

      --
      Hey pal, this isn't a pleasantforest, so don't waste my time with pleasantries!
    4. Re:Simple reason WHY they did it... by Anonymous Coward · · Score: 0

      Well, any not completely insane programmer (are there still any?) would use public/private key to encode the MAC + salt and some checksum data into some hash like value, and send that one. Server would decypher by private key, validate MAC and salt and send content back.

        You can still break into the firmware and extract the public key + salt data, so you would be able to predict key values of other frames with guessed MAC address, but then again, there's some difference in effort needed to break into firmware vs copying plain text URL - then blindly change couple of numbers... (unless the firmware is some well known FOSS library with well know jpeg exploitable bug with some bash script generating the key value stored in unencrypted file in well known fs in some easily readable block device.... I mean, you can make this hack easy on so many levels, that maybe they should rather label the box "insecure" and sell it anyway)

  29. Re:How many people will get their brand new frame. by Anonymous Coward · · Score: 0

    Ow crap. Must get to living room...

  30. Re:How many people will get their brand new frame. by mortonda · · Score: 1

    I felt a great disturbance in the Force. As if millions of eyes all cried out in terror, and were suddenly blinded.

  31. Its all in a name! by Anonymous Coward · · Score: 0

    With a name like "EasyShare" what do you expect ?

    N...

  32. "Cloudfeature" by Errol+backfiring · · Score: 2, Funny

    Can somebody mod this up please?
    I like the sound of calling every security problem a "cloud feature". Suddenly it does not sound bad at all anymore!

    --
    Nae king! Nae laird! Nae yurrupiean pressedent! We willna be fooled again!
  33. Family Photos abound by Anonymous Coward · · Score: 2, Interesting
    1. Re:Family Photos abound by WuphonsReach · · Score: 1

      Looks like they've changed it so that unless you pass it a specific User Agent it won't display anything - anyone know what the user agent is?

      --
      Wolde you bothe eate your cake, and have your cake?
  34. Change the 6D to 6E by Anonymous Coward · · Score: 0

    NSFW - Change the example at the end from 6D to 6E for a nice viewing. Bet she isn't happy about her boyfriend's photostream.

  35. Looks like Kodak got Slashdotted... by Anonymous Coward · · Score: 0

    "Error generating activation code. We are unable to activate your frame at this time. Please email support@framemedia.com for help resolving this issue."

    Oh, and not to mention the streams near the example address (xx:B8:07:6C) seem to be having a high turnover in user name and content.

  36. The actual image storage filesystem.. by Anonymous Coward · · Score: 1, Informative

    http://fs.framechannel.com/

    returns an xml document with :

    fs.framechannel.com

    1000
    true .jpg
    2008-11-12T18:43:37.000Z
    "25b2916b5c49db617f52fa5ea48efee7"
    4
    STANDARD

    0000193a728fd00b6cff91b8840bbf8d.jpg
    2009-10-22T04:02:13.000Z
    "3ec327314496f0d6d92467f399bfdba8"

    http://fs.framechannel.com/0000193a728fd00b6cff91b8840bbf8d.jpg

    gives you the image ..

    This appears to be for all the "personal" content displayed in the frame..

  37. Re:How many people will get their brand new frame. by darthnoodles · · Score: 1

    All unregistered frames now go to an error image. It states that they can't provide a registration number at this time. Looks like they caught on.

  38. Any firmware hacks for older models? by Oyjord · · Score: 1

    I have Kodak's Easyshare EX811, one of their earlier models, and like some of the above posters, it's simply shocking how poor the firmware is in the device. It's a real near miss. The tech is there, the hardware is there, but the software feels like shackles on the user. Surely there are folks smarter than I in the open source community who've come up with their own, better firmware. I tried to Google some, but came up empty.

    1. Re:Any firmware hacks for older models? by dfsmith · · Score: 1

      You can get a little ways by playing with UPnP, but it's still a horrible system. I took a quick look at the firmware in the EX811, but it would be cheaper to get a netbook and detach the screen than try to hack this picture frame. B-(

  39. "Easyshare" - no kidding. by kriegsman · · Score: 1
    I gave a couple of these for the holidays this year thinking that this would be a great way for family to share pictures but we had an unbelievably difficult time getting them to share what we wanted when we wanted.

    Thank goodness that's all solved now!

  40. Other things to think about by Anonymous Coward · · Score: 1, Interesting

    remember that framechannel also has plugins for ROKU boxes and many many other devices other than frames.

  41. Hack: Use other RSS feed via redirects by superswede · · Score: 1

    The hardware seems to be hardwired to framechannel.com. By using a (wireless) router that can either

      1. do URL redirects, or
      2. use a custom DNS service

    it should be possible to use an alternative service, or setup your own RSS feed. There are lots of things you then could to.

    Also, it would be possible to "hide" behind a hard-to-guess RSS URL, or possibly have the RSS server to only respond to certain IP numbers.

  42. Unique IDs are there, but unused by Exp315 · · Score: 1

    I have the Kodak W1020 10" WiFi frame. It does have a unique serial number which is available on the web interface. When I signed up for FrameChannel, I had to provide a 4-digit ID displayed by the frame (don't remember now what it was, or whether it was related to the serial number or the MAC address, and it can't be displayed again without re-initializing the frame). To connect to my Kodak Gallery online account, I had to provide the frame with my email address and password. To sign in to FrameChannel on the web, I have to provide a username and password. In the My FrameChannel Advanced Settings there is a 4-digit PIN number (purpose undocumented).

    So, in summary, every bit of capability needed for security is there, awaiting a quick firmware update. It was just a bit of carelessness that FrameChannel didn't think hard enough about security in the first place. I'm willing to forgive this as long as they get together with Kodak quickly and issue a security update - it's a pretty new service, and they are still evolving rapidly. I certainly would never put any private/confidential photos on a web server of any kind. Anyone that does is naive to think it's secure. But I don't want morons defacing my frame contents.

  43. Re:How many people will get their brand new frame. by Anonymous Coward · · Score: 0

    And how many of them will realize they like it?

  44. FrameChannel has already made a change by Exp315 · · Score: 1

    In the last 15 minutes the RSS url field has disappeared from the FrameChannel Advanced Settings dialog box. What good this will do I don't know, since the main vulnerability is that anyone can enter an existing predictable RSS url.

  45. "Flight to Vegas Delayed" by DingerX · · Score: 3, Interesting

    Well, someone sure is getting a jump on the pre-CES media hype. A conspiracy theorist would suggest that this Corey Halverson dude over in Seattle was slipped some info by his buddies over in Redmond working on a competing product, and looking to exclude a VC-funded startup right when they start gaining traction. That would explain why his blog only has three posts, and why he brought this up right before CES.

    Me, I take this as an object lesson for what happens when you dump your product on woot, and when you don't bother to make even the slightest effort at security.

    This truly is a PR nightmare, but will make a good plot mechanic in next season's procedural dramas.

  46. 1st try, found nudity by Anonymous Coward · · Score: 0

    I just picked up the URL on the blog and change last cipher... et voila!

    http://rss.framechannel.com//productId=KD9371/frameId=00:23:4D:B8:07:6E

    Usually MAC addresses are progressive like serial numbers.

  47. An interesting feed.... by Anonymous Coward · · Score: 0
  48. FrameChannel is on facebook and twitter by Anonymous Coward · · Score: 0

    Get the word out to non-slashdot reading folks.. this is too ridiculous for this company not to have it spread all over the internet. http://www.facebook.com/pages/Wellesley-Hills-MA/FrameChannel/103020166321?v=wall http://twitter.com/FrameChannel

  49. Not Just Kodak? by ralphrmartin · · Score: 1

    If you go to the framechannel website, you can find a link claiming you can share photos with a whole bunch of manufacturers' devices:

    The FAQ here:http://www.framechannel.com/FAQ/#FRAME_LIST
    sends you here: http://www.wirelesspictureframe.com/company-listing/
    where you can see this list:

    FrameChannel Wireless Digital Picture Frames
    Kodak
    D-Link
    Philips Electronics
    Samsung
    Digital Spectrum, Inc.
    PhotoVu
    Edge Tech Corporation
    InTouch
    Motorola
    Pix-Star
    Toshiba

    Other Digital Picture Frames
    Bigeframe
    Fidelity Electronics, Inc.
    KoolVu
    Pandigital
    Parrot
    PF Digital, Inc.
    Polaroid Corpoation [their typo, not mine!]
    Portable USA
    Royal
    Sungale Group, Inc.
    Westinghouse Digital Electronics

  50. MIT's Account? by Anonymous Coward · · Score: 0

    http://rss.framechannel.com//productId=KD9371/frameId=00:23:4D:B8:07:A6

  51. Wonder if they can block by User-Agent by Bretski · · Score: 1

    A quick fix that would get 99.9% of us out of people's pics, if the User-Agent string is something unique to the frames. This would only allow HTTP requests from frames, not from desktop browsers. Yes, we can change our user agent string on the desktop browser to match, but like I say - 99.9% of people wouldn't know how.

    1. Re:Wonder if they can block by User-Agent by Mr.+DOS · · Score: 1

      99.9% of people don't know how to do the simple URL-based thing we're doing here, either.

            --- Mr. DOS

    2. Re:Wonder if they can block by User-Agent by Anonymous Coward · · Score: 1, Insightful

      All FrameChannel has to do is immediately turn off the ability to connect to RSS feeds by MAC address. They already have an alternative capability to connect by username/password, and the Kodak frames already support it. Users may be temporarily annoyed at having to change their connect method on the frame, but Kodak can fix that later with a firmware update.

      As for registering a frame in the first place, each frame also has a unique serial number, so it would be pretty easy for FrameChannel to tighten up the registration procedure by requiring all new registrations of Kodak frames to provide their serial number as well as the ID code.

  52. to be fair by Anonymous Coward · · Score: 0

    To be fair to kodak, yes, their frames are "hackable". However, it is framechannel that is completely wide open. The frames also talk to the kodak gallery. I'm not sure how that part works as I've never set up an account.

    So they're somewhat not to blame for that.

    However, they *are* to blame for the fact that the web interface of the frame doesn't have a password, nor does it allow the user to set one.

    So, if you connect this frame to any public-ish network, anyone can administer your frame (adding other rss feeds, changing settings ... ) by its http admin interface.

  53. Or photoshop their existing pictures by tlambert · · Score: 1

    Or you could photoshop their existing pictures to put their subjects into compromising or illegal situations.

    The resolution on these things and the typical images uploaded to the server is low enough that you could probably make it very hard for even an expert to detect that they were fakes, just by looking at the picture.

    -- Terry

  54. Kodak frantically deleting/resetting feeds by Areyoukiddingme · · Score: 1

    This one is long gone, as are the other two featuring nudity.

    Ok, people, prove the old adage. If it's uploaded to the Internet, it's there forever. I expect links to a picture sharing site (that allows explicit pictures) before the day is out, with corroborating posts from those who saw them.

    Aka pics or it didn't happen. :)

    1. Re:Kodak frantically deleting/resetting feeds by iPhr0stByt3 · · Score: 1

      Well, it DID happen... but it looks like the above method no longer works, so at least until someone takes the time to sniff the "new" rss url for the framechannel feed we're safe ;).

    2. Re:Kodak frantically deleting/resetting feeds by iPhr0stByt3 · · Score: 1

      It would seem that the originally mentioned framechannel URL is not the only privacy issue. That particular RSS feed (with the MAC address in the URL) only pulls public information. "Wait" you say, "I put my naked butt in my private flickr collection, not the public one". The next privacy breach is the picture store of framechannel. Try

      http://fs.framechannel.com

      Then chose a random .jpg from the XML and add to the end of that URL. Like this:

      http://fs.framechannel.com/47df05c1e351a795fe95a66feb09ad64.jpg

  55. redirect... by Anonymous Coward · · Score: 1, Interesting

    It seems they now redirect everything to there default National Geographic feed.. Did they already implement Bretski's idea and starting filtering on useragent ? Anybody got this model that can validate if its still working on the device and if so sniff and see what useragent it is using..

  56. agent by Anonymous Coward · · Score: 0

    does anyonone know what software the useragent "AVOS/1.1" belongs to?