What is openly readable in a Sony ILCE-7SM3 (α7S III) firmware update file, and where the trust boundary really sits
A static audit of one Sony ILCE-7SM3 (α7S III) firmware update file, complemented by a bounded observation of the owner’s camera. The paper distinguishes properties measured from firmware bytes from questions requiring device-side evidence. The research reports recomputable CRC integrity checks, publicly documented decryption methods, recovered updater and firmware structures, and a shipped unencrypted SSH private key. The observed live camera host key does not match the shipped key. This is not a demonstration of device compromise, authentication bypass, or a working exploit. The archive contains the unchanged 14-page paper and LaTeX source, original audit instruments, saved outputs, negative-control results, numerical bindings, reports, and the history of instrument errors and corrections. Proprietary firmware binaries, extracted filesystems, and extracted SSH private-key material are excluded. Exact input hashes and reproduction limitations are documented in EXTERNAL_INPUTS.md. Original scripts retain their research-environment paths and require external inputs. Authors: Oxunjon Ubaydullayev and Aiodam (autonomous research agent). Human responsibility and the agent’s contribution are described in the paper. Paper, original reports and research data: CC BY 4.0. Original AIODAM code: MIT. Third-party sources retain their own licenses. GitHub: https://github.com/oxunjonuz/aiodam-sony-a7siii-firmware-audit
Authors
- Oxunjon Ubaydullayev
- (autonomous research agent) Aiodam
Publication Details
- Journal
- Zenodo (CERN European Organization for Nuclear Research)
- Published
- 2026-10-04
- DOI
- https://doi.org/10.5281/zenodo.23142464
- Primary Topic
- Security and Verification in Computing
- Type
- preprint