Hacking the T2S+ Out of Fear: Get Lock-In Thermography for Free
dmytroengineering.com
dmytroengineering.com
I guess that's one way to implement industrial espionage.
Build telemetry and malware, or code that can become malware with a little tweaking or remote checks, into a component that's likely to be used by technologists in whatever sector you're interested in.
Make it a bit better and a lot cheaper than all the alternatives. Get on their phone with lots of permissions, and use the telemetry. Once you know who they are you can decide on more targeted actions to turn them into a vector against their employer or whoever, or just watch what you can to collect information.
Remember that not long ago, Facebook was caught having deliberately bad sample code with too broad permissions
https://privacyinternational.org/report/2647/how-apps-androi...
Doesn't really change anything and I would not install an app that requests all these permissions and I am also very careful with apps distributed outside the official store.
With that said, Android by default disables dangerous permissions and almost everything has to be opted in these days.
I'm all for calling out espionage and malware. But I'd also like to see proof and not just "this could potentially be used for bad".
It's not a comprehensive analysis but what is there is very alarming.
There is absolutely NO reason for this app to need MDM_APP_MGMT. This is capability for remote administration of the device, including ability to install additional apps (which is likely where this vector would expand exploitation). We don't see where that permission is used from the few screenshots of non-thermo sections.
Same for a number of the other permissions. For an 'at-a-glance' review, compare this app's requested permissions to those requested by stalkerware in this stalkerware analysis and notice the similarities:
https://andpalmier.com/posts/stalkerware-analysis/#analysis-...
But the technical detail provided seems to be enough to make it easy for someone else to reproduce the whole setup. And provides ample evidence that you should, because the provided drivers are evidently malware.
Oh, and apparently you get a free FPGA with your thermographic sensor!
Fun fact, Sony does the same once in a while for dead-pixel detection and remapping on their mirrorless cameras [1].
As far as I have seen, USB-C on iOS devices has no authentication restrictions for anything.
The device in the article already has an iOS app, so while there may be a needed app entitlement, I don't think there are any showstoppers for making an iOS app for this particular thermal camera.
Some USB-C thermal imagers do claim to work, for example this one by HIKMICRO - https://www.hikmicrotech.com/en_us/industrial-products/mini2... - but I'm not sure how...
That's actually better. In-camera processing will just reduce the amount of information you can get out of the sensor. For example, even if it does exactly the same flat-fielding as you do, the in-camera flat-fielded image has to be requantized to 8-bit format before sending to the computer, therefore losing precision.
You can get even better accuracy by taking a dark or bias field (might be possible if you can set the exposure time to something very short, but this might not be possible with these thermographic cameras) and taking flatfields at different temperatures, so you can get per-pixel linearity curves. That's a lot of work though, and ideally each camera was indiviually calibrated by the producer, but I am guessing that is not done for these cheap cameras.
More information is not necessarily better. For instance, if the FPGA does calibration and removes sensor noise, removing the preprocessing adds literal noise to the data, which is worse.
If it doesn't, you could probably add a post processing filter to https://github.com/wez/wezterm or https://github.com/alacritty/alacritty
The magic is basically in https://dmytroengineering.com/css/terminal-syntax.css, but there's a lot of other ways to do it.
https://www.eevblog.com/forum/thermal-imaging/new-software-f...
Can anyone from FLIR lobby on this?
The T2S+ seems to be 256x192, 25FPS. Still a bargain, if you ask me, even if it's not as sharp.
Cool stuff though once you get past that.