Security Disclosures
Responsible vulnerability research and coordinated disclosure from OpenSensor Engineering LLC. All disclosures follow industry-standard coordinated disclosure practices.
Vulnerability Disclosure Policy
OpenSensor Engineering LLC notifies affected vendors prior to public disclosure and provides reasonable time to respond and remediate. Where vulnerabilities exist in mask ROM and cannot be patched by the vendor, we coordinate with downstream vendors and the relevant CNA before publishing. We file CVEs through MITRE when vendor CNAs are not applicable.
How to report
Send vulnerability reports to matt@opensensor.io with the recommended subject line Security Report — <target>. Include reproduction steps, affected versions, and any relevant artifacts. PGP available on request.
Response SLA
- Initial reply within 5 business days
- Triage update within 10 business days
- Remediation timeline coordinated with the affected vendor
Scope
lightnvr.comowlbooks.aiopensensor.io
Findings on third-party hardware we have researched (e.g., Ingenic SoCs) are coordinated through the relevant vendor and CNA.
Safe harbor
OpenSensor Engineering LLC will not pursue legal action against good-faith security research conducted within this scope and reported through this channel.
Acknowledgments
Reporter hall of fame — coming soon. We credit researchers who follow this policy unless they request anonymity.
Security Services
Security is a service line at OpenSensor Engineering. We bring the same hands-on approach from our public CVE work to private engagements.
Firmware Analysis
Static and dynamic analysis of vendor firmware, boot ROMs, and SPL chains. Reverse engineering, signature audits, and exploit-feasibility assessment on real silicon.
Secure Boot Review
Architecture review and adversarial testing of secure-boot implementations: signature verification correctness, key handling, anti-rollback, and pre-verification attack surface.
OSS Supply-Chain Review
Dependency provenance, build-pipeline integrity, and SBOM hygiene for projects that ship open-source firmware or rely on upstream embedded toolchains.
Active Disclosures
Ingenic T31 Boot ROM — Improper Secure Boot Verification
The Ingenic T31 boot ROM compares only a single 32-bit word during RSA-2048/SHA-256 SPL verification, reducing effective secure boot strength to 32 bits. Affects the entire T31 SoC family — all sub-variants (mask ROM; cannot be patched).
Ingenic T41 Boot ROM — Pre-Verification Init-Table Bypass
The Ingenic T32/T40/T41/A1 boot ROMs parse and execute an SPL init table before evaluating secure boot state, providing a memory write primitive that bypasses signature verification entirely. Hardware-validated on T32, T40, and T41 silicon (mask ROM; cannot be patched).
Press & Coordinated Disclosure
Journalists and vendor coordinators handling embargoed disclosures should use this dedicated channel. Please include any embargo dates and coordinating CNA in your initial message.
Press & Disclosure Inquiries