Firestalked - The Amazon Fire Tablet Security CoverUp Titelbild

Firestalked - The Amazon Fire Tablet Security CoverUp

Firestalked - The Amazon Fire Tablet Security CoverUp

Von: Dick Morrell
Jetzt kostenlos hören, ohne Abo

ZEITLICH BEGRENZTES ANGEBOT. Nur 0,99 € pro Monat für die ersten 3 Monate. 3 Monate für 0,99 €/Monat, danach 9,95 €/Monat. Bedingungen gelten. Jetzt starten.

Über diesen Titel

In 2023 Amazon were made aware at the highest levels of a massive security exploit made against its Amazon Fire tablets because of amazingly stupid flaws that had existed for many years in FireOS. Specifically security vulnerabilities in the privilege escalation and authentication libraries which allowed childs play simple exploits against upstream Amazon cloud architecture. Whilst the vulnerabilities were confirmed and subsequently patched, Amazon failed to publish security errata, CVE information of any description or to make public the extent of the huge vulnerabilities affecting millions of devices used in homes globally.


Fire tablets are fantastic devices that extend Amazon capabilities importantly into the home and have often been the first touch device for millions of children outside of the more expensive iPad world or more expensive Android tablets.


So why did Amazon, when they were aware of such massive vulnerabilities affecting tens of millions of users never publish a single solitary release of information for users in households across the world ? Conversely why didn't they inform any of their partners in any of the educational institutions globally that they support by way of donation or have sold Fire tablets to. Knowing those massive privacy impacting holes that were simply exploited had been discovered and now thanks to a UK security engineer detailing them to Amazon - patched.


A breach of confidence in the world's biggest consumer technology provider and online cloud retailer ?


But more worryingly, fully aware that the engineer reporting the vulnerability, one of the worlds most widely known Open Source engineers, was the victim of long term domestic abuse using the devices, went quiet.


A victim of actual domestic violence perpetuated using two of their devices.


They tried to cover up the story. This is the podcast that shines a light on what happened and ends with a full and unabridged explanation from the Principal Engineer involved in the security dilemma that explained how Amazon PR and Legal instructed a cover up and non reporting in errata and changelogs of the security holes.


Yet an SEC listed company freshly fined by the FTC deciding to do this is a shocker. So now is it appropriate that the FBI and the SEC now find themselves involved and Amazon forced to cooperate ?


Either way I want a rather plump damages cheque for the bugs I brought in and the impact and upset caused to my family.

Copyright 2025 Dick Morrell
Sozialwissenschaften True Crime
  • Episode 4: Ethical People do exist at Amazon
    Oct 8 2025

    There are good people in the world. Ethical folk who are engineers and programmers, programme leads and operational staff. Often they are managed by those who play the angles. Who would rather the bad news never saw the light of day.


    But when you're an SEC listed company, fined days prior by the US Department of Justice and the FTC for a smaller breach than the one you've just had walked in the door that now affects the legacy privacy of tens of millions of devices in the field then you have an absolute responsibility to communicate to your users.


    In fact the DoJ ruling stated that Amazon was orded "notify users of its retention and deletion practices and controls;". Immediately two major vulnerabilities which impacted that ruling were on the desk of the Head of Security regarding retention of data and privacy and cached credentials allowing a device to become a trusted hardware token.


    With the fourth major bug being the fact that software flaws in Cloudview and logging meant you were unable to deregister Kids Fire devices at all from the Web UI.


    So what happens when someone blows the whistle when Amazon tried to cover all this up ???


    Decent people do exist. Shame Amazon can't keep hold of them. Maybe they should send him a stock award and an apology.


    Mehr anzeigen Weniger anzeigen
    39 Min.
  • Episode 3: Setting Fire to Security Basics
    Oct 8 2025

    So knowing for absolute fact that I am the subject of industrial scale stalking and hacking, the devices left with my ex wife being subject to the flaws and bugs relating to cached credentials and the Amazon Photo and Amazon Alexa lack of forced authentication (alongside an aged device logging bug) I was determined to engage with Amazon properly. Engaging with the Head of Security at Amazon and Ring in Seattle one on one. With live data supplied from Cloudwatch the immutable tamperproof platform that Amazon use to log all retail and operational activity.


    I had no idea the storm that was about to break. But it's enough to put a Devizes girl in prison.

    Mehr anzeigen Weniger anzeigen
    24 Min.
  • Episode 2: Don't Play With Fire
    Oct 6 2025

    Amazon FireOS is a fork of stock Android. And what must be remembered it is it has to support a lot of software repo's and a lot of older libraries. However Amazon not licencing Android from Google and not partaking in the Play ecosystem is one matter. Amazon have only got to support a limited range of graphics chipsets and a limited range of hardware mainboards so it's NOT a lot of work. There are mainstream open source Linux distributions supporting PPC Intel ARM who have to do a lot more work than Amazon.


    Amazon FireOS tablets have always been two to three distributions behind Google. Have always failed to have security standards aligned with Google. No file encryption or SD card encryption. No Knox equivalent etc. So you'd expect if you have older stable dev trees that you would take security and privacy seriously.


    I proved categorically that Amazon did no such thing

    Mehr anzeigen Weniger anzeigen
    33 Min.
Noch keine Rezensionen vorhanden