linuxct,
@linuxct@androiddev.social avatar

Waiting for someone with an early unit to dump the Rabbit R1 OS like crazy right now

ryne,
@ryne@androiddev.social avatar

@linuxct If no one does by the time mine gets here, happy to dump it for you (if you can lend a hand pulling it!)

linuxct,
@linuxct@androiddev.social avatar

@ryne It may be a bit trickier as I have seen most interfaces are locked down. I expect some eMMC/UFS desoldering (or otherwise, butchering of the device) may be involved to get it out for the first time before we can hook to the OTA server and pull it from there ;)

linuxct,
@linuxct@androiddev.social avatar

@ryne I also have one coming my way but it will take months to arrive, so until then I will keep an eye for more security researchers getting their hands on it 👀

linuxct,
@linuxct@androiddev.social avatar

Trivia: Did you know It Just Runs Android? TM

linuxct,
@linuxct@androiddev.social avatar

So I got bored, started poking the API and welp, I guess I now registered a Rabbit R1 in the rabbit hole?

This is as much as you will see day 1 btw

image/png
image/png
image/png

linuxct,
@linuxct@androiddev.social avatar

Oh wow, now this is sketchy. The login onto Spotify is performed on a remote machine via... VNC? What the...?

If I place the cursor outside of the Spotify login page, I can see Xorg's default X logo. And the page stutters upon scrolling. Why do they do that instead of normal API tokens? Is this remote machine going to store my browser session for the LAM's scrapping purposes?

video/mp4

linuxct,
@linuxct@androiddev.social avatar

By the way I was super late to the party and this was known since a few days ago. Check rabbit's bird site account for the details per their CTO. Someone before me saw this very thing and started a defamation campaign against rabbit, stating LAM was all just a Microsoft Playwright automation script. But it has been proven wrong already as the VNC'd machines had some source code which demonstrated they were only capable of account management and logging credentials for future use, not automation

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • kavyap
  • ngwrru68w68
  • thenastyranch
  • osvaldo12
  • InstantRegret
  • DreamBathrooms
  • cisconetworking
  • magazineikmin
  • normalnudes
  • Youngstown
  • everett
  • slotface
  • rosin
  • cubers
  • JUstTest
  • GTA5RPClips
  • tacticalgear
  • Durango
  • modclub
  • Leos
  • khanakhh
  • mdbf
  • tester
  • anitta
  • provamag3
  • ethstaker
  • megavids
  • lostlight
  • All magazines