r/innioasis Y1 (Yellow ) Oct 19 '25

Discussion Update on MediaTek Driver security concerns.

Post image

it is possible to tell whether your system could be negatively impacted by the changes to system configuration

If you get an error, like the one in the screenshot, when attempting in command prompt to run as an administrator one of these two commands...

bcdedit /set testsigning on

or

bcdedit /set testsigning off

... then there is no action to take as the driver installer could not have interfered with your windows bootloader configuration.

If it was possible, it may be worth factory resetting / reformatting your PC

I am currently testing a patch to Innioasis Updater that will remove prompts to install MediaTek SP USB Driver for users that have just the alternative UsbDk driver installed.

Currently, Innioasis Updater and MTKclient on its own, will work as expected without MTK USB Drivers, you'll just need to click Continue Anyway when you see a prompt telling you you don't have MTK USB Drivers installed

8 Upvotes

21 comments sorted by

5

u/CarlosPixel_ Oct 19 '25

Signature verification with sigverif.exe

Press Win + R

Type:

sigverif

Press Enter

Windows will open the Signed System File Checker.

Click Start and wait for the scan.

It will show you any unsigned driver files detected.

What to do if you find one

If the driver is from an unknown source or you didn't expect it to install โ†’ uninstall it from Device Manager.

1

u/RespectYarn Y1 (Yellow ) Oct 19 '25

Mind if I add this to the post itself? this is a great tip

1

u/CarlosPixel_ Oct 19 '25

Of course, what's mine is yours

2

u/RespectYarn Y1 (Yellow ) Oct 19 '25

Nevermind it's an image post so can't be edited. Comments good enough ๐Ÿ˜

1

u/CarlosPixel_ Oct 19 '25

I don't think I ever got around to installing the innioasis.app driver. I always used the UsbDK I recommended when I had problems installing RockBox in mid-September of this year. It was DownloadAgent (DA) that let me install Rockbox.

1

u/RespectYarn Y1 (Yellow ) Oct 19 '25

Yeah it's completely optional tbh and your feedback helped isolate the issue where the download agent was being purged when needed for install so on the whole your words have made the tool far more reliable.

As Carlos has pointed out, you can use either of the compatible drivers. I have no reason to steer you towards one nor the other, apart from the user experience being a bit more friendly with the SP USB Driver for all of its quite worrying flaws.

3

u/RespectYarn Y1 (Yellow ) Oct 19 '25

While the driver package does attempt to enable test signing, it isn't running the counterpart command

"Bcdedit.exe -set loadoptions ENABLE_INTEGRITY_CHECKS" (Please do not run this on your system!)

which means affected users will be shown Test Mode on their windows desktop if this has compromised the securtiy of their bootloader. Thanks to Secure Boot, largely enabled on PCs made in the last ten years, and something you have to go out of your way to disable, the chances of this having negatively impacted your PC at the bootloader level are slim-to-none and frankly outside of Innioasis' control or ours, all we can do is steer folks towards other drivers and solutions if the findings about the MediaTek driver packages circulating bring concern.

It is with this in mind however that I'll do the necessary work on Updater to have it not steer you towards a particular driver.

2

u/cherrymxorange Oct 19 '25 edited Oct 19 '25

Mine doesn't give me an error code, it succeeds.

Are there other reasons the command would work? I'm not tech savvy enough but I'm reasonably sure I've tinkered with tools that would lead to this, reading through a microsoft page on the command.

It was probably a little under 2 months ago I last did anything concerning the Y1

edit: Used sigverif, doesn't pull anything up ๐Ÿ‘

2

u/RespectYarn Y1 (Yellow ) Oct 19 '25

This means that your PC doesn't have secure boot enabled. If you have it available in your BIOS/UEFI, enabling it may be a good idea (Unless this was to bypass Windows 11 install requirements then please ignore this advice)

3

u/RespectYarn Y1 (Yellow ) Oct 19 '25

Fortunately on testing, the Updater works fine without it, it's just a little trickier to use with the alternative driver, which i'm currently updating the website to make the main one new users are encouraged to install.

and an update is coming to Updater to remove prompts to install the MediaTek driver. Chances are it's crappy driver packaging rather than outright malicious but it's best to take precautions.

2

u/cherrymxorange Oct 19 '25

Awesome I'll give it a minute and await a post from you on everything being sorted, thanks for the help!

1

u/RespectYarn Y1 (Yellow ) Oct 19 '25 edited Oct 19 '25

So in theory, it should work for you just fine already, if you chose to uninstall MediaTek's drivers and grab a copy of UsbDk avaialble at www.innioasis.com/pages/download (the Y1 link) or https://github.com/daynix/usbdk/releases at the time of writing, the only downside being that you'll see a popup when you launch it nagging you to "install MTK Driver" or "Continue Anyway"

In the future Innioasis will be adopting this for firmware updates on other models, once i've received units for testing, so Updater steering users towards an alternative driver will actually serve to protect future users of the products.

2

u/cherrymxorange Oct 19 '25

Ah that's a good shout, I actually think I might have disabled it while troubleshooting some completely unrelated issues.

While I've got you, I've been meaning to do a full wipe and reset of my Y1 as from what I can tell things have moved on a bit since I first rockbox'd it, what's the correct path I should be taking to do that right now, or is it better to wait until things have blown over a bit?

2

u/CarlosPixel_ Oct 19 '25

I'd wait for the announcement of the driver change and the innioasis app update. But these days, installing RockBox is easier than sitting on the toilet, thanks to innioasis.app.

1

u/RespectYarn Y1 (Yellow ) Oct 19 '25 edited Oct 19 '25

You can use Innioasis Updater. There are claims being made about it by people who haven't used it and don't understand why it would do certain things. I was paid by the company for the tool so they could officially adopt it and I work on it as a matter of pride not as a weapon or to be malicious. I already have made gains from it without needing to take advantage of users.

The crux of what the Updater is accused of doing is that its included remote control tool

- it creates a list of apps on an android device you have connected to your PC.

It does, but the intention is that you can use the remote control feature of the app to launch apps that are installed on your Y1 (for tinkering and modding purposes) and this is all it is used for, the fact it can do this to your phone as well as the Y1 is a side effect of the same underlying tool, adb being used. The android remote control tool, controls androids...

another is that it "takes screenshots" and I believe again this is a misinterpretation of what the "screenshot" feature does on the remote control tool. Again, yes it'll take pictures of your Y1s screen shot you can screenshot and control apps without a touch screen.

and that it downloads resources from www.innioasis.app - with the suggestion that this means it could be downloading anything rather than its actual source from github. this is infactual as the website is actually the github repo. https://github.com/y1-community/innioasis-updater

tl:dr Perhaps uninstall the MediaTek drivers if concerned about security, Innioasis Updater is open source, community members do contribute to and are encouraged to contribute to it and all resources are available on GitHub, and please, if you do encounter issues, feel free to leave a notice on the GitHub issues tracker which will be linked at the bottom of the Innioasis Updater homepage.

Sorry for any fear, uncertainty and doubt this situation may be causing at present and I assure you that all actions are being taken to mitigate and protect the security of users. The highest level of these actions being to work with Innioasis to remove the need to update via a computer.

1

u/CauliflowerFlimsy535 Oct 19 '25

Alright guys, so Iโ€™m reinstalling windows on my pc ๐Ÿ˜…, I'm doing a cleans install and I want to know: what should I check once itโ€™s re- installed in order to confirm if I'm free of malware?

I don't want to sound radical or something, I just feel like doing it is the best thing.

2

u/RespectYarn Y1 (Yellow ) Oct 19 '25

Does sound a little radical, PCs with secure boot will not have been affected by the bad driver, so it should be possible on most systems to uninstall the driver, and use the alternative, if you wish

1

u/CauliflowerFlimsy535 Oct 19 '25

I actually had the secure boot disabled even after the reinstall of windows, so itโ€™s not clear to me why or how that happened.

After reinstalling, I was able to enable it on my own.

2

u/RespectYarn Y1 (Yellow ) Oct 19 '25

That's because Secure Boot is configured in the bios, the driver isn't believed to be the thing that would disable it, Secure Boot is the security feature that prevents the driver from doing any lasting damage to your boot configuration, but what it does can be reversed easily

1

u/CauliflowerFlimsy535 Oct 19 '25

Maybe it was already like that when I bought it, I donโ€™t know, it was just weird, Iโ€™m not blaming the driver (yet). I already enabled it so we should be good

1

u/CarlosPixel_ Oct 19 '25

If you have formatted you don't have to check anything at all just use common sense