Live data from Hacker News

Three million malware-infected smart toothbrushes used in Swiss DDoS attacks

tomshardware.com

41–50 of 182 posts

Re: Three million malware-infected smart toothbrushes used in Swiss DDoS attacks

#42
post #34

That's a really flimsy article. Someone is claiming 3 million smart toothbrushes were used in a DDoS, but no one is talking what/who/how. That seems like the kind of extraordinary claim that requires at least some kind of evidence. There is surely at least some technical details that enabled them to identify the toothbrushes, right?

It also seems odd that even if you (maybe unknowingly) connected your 'smart' toothbrush to wifi, it would be exposed to the public internet. Aren't most people using some kind of clunky cable modem etc. from their ISP, which would have a basic inbound firewall?

Re: Three million malware-infected smart toothbrushes used in Swiss DDoS attacks

#43
post #11

Earlier quoted context omitted.

Theory: you just don't connect them, right. Reality: connect or it won't start. Next step: integrated sim card.

This literally happened to me on Friday. I was setting up a smart TV for my uncle and he just uses it for his Chromecast so I thought "whatever, I'm not going to connect this TV to his wifi." Come to find out, the TV locks you out of EVERYTHING if you do not connect it to the internet. You see the homescreen but you aren't allowed to switch the input unless you connect to the wifi. Even after connecting to wifi, you…

TVs are the worst. Everything except OLED sets have been getting cheaper and cheaper and I'm certain these manufacturers aren't achieving this via production line optimizations. It starts with the connection to vacuum up the data, next comes overlay ads, in a few years it'll be subscription plans instead of a sticker price. and the general public will love it.

Re: Three million malware-infected smart toothbrushes used in Swiss DDoS attacks

#45

Why do toothbrushes need to be able to make web connections in the first place? I get that it's for tracking brushing habits, but can't that be done with local connectivity only, like LAN or something?

I was at the store looking at them recently and all the toothbrushes advertise having "AI", an app, wifi/bluetooth etc. I guess it's hard to come up with reasonable upsells on this stuff.

Re: Three million malware-infected smart toothbrushes used in Swiss DDoS attacks

#46
post #6

Why do toothbrushes need to be able to make web connections in the first place? I get that it's for tracking brushing habits, but can't that be done with local connectivity only, like LAN or something?

Because the actual business model is selling the aggregated data?

What data though? How would it be valuable? From what I saw they are getting money from the device sale itself. These iot toothbrushes are like $400 and basically just track brushing time and pressure. Those don't seem like super valuable ad tracking metrics.

Re: Three million malware-infected smart toothbrushes used in Swiss DDoS attacks

#47
post #26

Is nobody going to mention Java running on the toothbrush? One might guess the firmware included a battery controller, bluetooth or wifi stacks, a little storage, and business logic for buttons and brushing.

3 billion devices run Java!

;)

Re: Three million malware-infected smart toothbrushes used in Swiss DDoS attacks

#48
post #34

That's a really flimsy article. Someone is claiming 3 million smart toothbrushes were used in a DDoS, but no one is talking what/who/how. That seems like the kind of extraordinary claim that requires at least some kind of evidence. There is surely at least some technical details that enabled them to identify the toothbrushes, right?

It also seems odd that even if you (maybe unknowingly) connected your 'smart' toothbrush to wifi, it would be exposed to the public internet. Aren't most people using some kind of clunky cable modem etc. from their ISP, which would have a basic inbound firewall?

Hypothetically, let’s say these toothbrushes connect periodically to an API from which they fetch firmware updates. If you’re able to MitM that connection, you could deliver whatever you like as a firmware payload to the toothbrush. Or maybe someone designed the toothbrush to open ports using UPNP to enable a remote connection to tell the toothbrush that the update server has moved to a new URL?

Re: Three million malware-infected smart toothbrushes used in Swiss DDoS attacks

#49
A warning about Philips electric toothbrushes: you cannot turn off Bluetooth on them, even if you are not using the smart features.

Also be careful with all Philips air purifiers that support Wi-Fi, because the remote control feature cannot be disabled. They create a Wi-Fi hotspot that you need to connect to with a smartphone to finish setting up the device, but if you don't use these features, the air purifier will create a permanent Wi-Fi hotspot, waiting to be exploited.

Re: Three million malware-infected smart toothbrushes used in Swiss DDoS attacks

#50
post #37

Earlier quoted context omitted.

This also good: https://i.imgur.com/YnBnsKA.jpeg

“The door refused to open. It said, “Five cents, please.” He searched his pockets. No more coins; nothing. “I’ll pay you tomorrow,” he told the door. Again he tried the knob. Again it remained locked tight. “What I pay you,” he informed it, “is in the nature of a gratuity; I don’t have to pay you.” “I think otherwise,” the door said. “Look in the purchase contract you signed when you bought this conapt.” In his desk…

Warren Ellis at Thingscon 2017

"1. It’s hard. Don’t get me wrong. I know it’s hard. And Samsung and Apple and several other large corporations want in on it. On the bright side, that will give you lots of exit opportunities, and soon you could be drinking cocktails in Bali while Amazon deals with the backlash from the smart doorlock you sold them that still doesn’t work properly. And they’ll spend the money on iteration until the device either goes away or starts working properly, and the users will have to buy Amazon Prime membership for their houses. And then someone will hack your house through the buggy wifi thermostat you bought, and your house will start ordering DOWNTON ABBEY downloads and you’ll come home to find it’s 40 Celsius indoors and the sink is flooded and your fridge has been turned into a porn spambot and you’ll realise that your house is masturbating to DOWNTON ABBEY.

   If you can get in the front door."
Post reply on HN