View Single Post
Old 05-01-2010, 05:28 AM   #14
Spiffy
Groupie
Spiffy has a complete set of Star Wars action figures.Spiffy has a complete set of Star Wars action figures.Spiffy has a complete set of Star Wars action figures.Spiffy has a complete set of Star Wars action figures.Spiffy has a complete set of Star Wars action figures.
 
Posts: 160
Karma: 416
Join Date: Apr 2010
Device: Astak EZ Reader Pro AND Sony PRS-505
Quote:
Originally Posted by Dave_S View Post
My antivirus software scans every download as a matter of course, but what possible effect could spyware or a virus have on standalone ARM processor firmware for a device with no Internet connectivity?
What does the Internet connectivity or lack thereof matter?

Anyone who uses Calibre connects their PC to the unit via a USB cable. If somehow the files unpacked from the .BIN contained a virus or other kind of spyware/malware, and you connected your reader to your PC via a USB cable, then at least in Windows you are subject to all kinds of potential infections.

The fact that the unit is Linux based doesn't even necessary stop the risk. The important thing is that when you hook up to the unit it reads it from Windows as just another file system, and can autorun stuff. It's exactly the same thing as people getting "autorun"-based malware from USB memory sticks. Something which happens all the time these days.

It's unlikely, true, but certainly far from impossible.

That said, thinking more about it I simply took the precaution of temporarily disabling the autorun on my Win box, installed the firmware, then did scanning virus/spyware scanning of the unit. Its clean. But it wasn't the stupid question its being posed as.

Last edited by Spiffy; 05-01-2010 at 05:37 AM.
Spiffy is offline   Reply With Quote