this post was submitted on 29 Dec 2023
85 points (98.9% liked)

Asklemmy

43788 readers
859 users here now

A loosely moderated place to ask open-ended questions

Search asklemmy ๐Ÿ”

If your post meets the following criteria, it's welcome here!

  1. Open-ended question
  2. Not offensive: at this point, we do not have the bandwidth to moderate overtly political discussions. Assume best intent and be excellent to each other.
  3. Not regarding using or support for Lemmy: context, see the list of support communities and tools for finding communities below
  4. Not ad nauseam inducing: please make sure it is a question that would be new to most members
  5. An actual topic of discussion

Looking for support?

Looking for a community?

~Icon~ ~by~ ~@Double_[email protected]~

founded 5 years ago
MODERATORS
 

I bought a 3d printer off Ebay which got delivered not too long ago, and it came with 2 sd cards - one with a build video and some demo print files, but worryingly another card that has all the previous owner's personal files on there.

Not sure whether to format it, or to contact the seller offering to send the card back (free of charge)... how would you prefer to be approached in a similar situation?

Edit: No gcode files are on the card, just 30gb of pictures, music and videos. Sent the seller a message offering to upload it to cloud or to send the card back

you are viewing a single comment's thread
view the rest of the comments
[โ€“] [email protected] 5 points 10 months ago (1 children)

We're talking about an sd card here. The absolute majority of these attacks only work with USB drives.

And the rest either don't make sense or make use of a 0day, which, as I've already said, is inconceivable

[โ€“] [email protected] 2 points 10 months ago (2 children)

How do you read a SD card? I usually put it in my SD card reader which is USB.

[โ€“] [email protected] 11 points 10 months ago

The SD card is still speaking SD protocol, the card reader bridges between USB and SD.

This only works with USB sticks because they're plugged on directly over USB and you don't know whether it'll present itself as a storage device or as a keyboard that immediately starts typing stuff and running a bunch of commands.

The risk is not the flash storage part, it's the USB interface.

[โ€“] [email protected] 1 points 10 months ago

But I don't think OP is saying the package came with an sd card reader as well that they used