Live data from Hacker News

Three million malware-infected smart toothbrushes used in Swiss DDoS attacks

tomshardware.com

51–60 of 182 posts

Re: Three million malware-infected smart toothbrushes used in Swiss DDoS attacks

#51
post #7

Earlier quoted context omitted.

I'm with you, but unless the brush stores the data on itself, which appliance should receive those data in a typical home?

The users phone, via a Bluetooth connection?

It's possible but its really unreliable. A device trying to reach out to an app on your phone to proxy the data while your phone is sleeping/app not running just doesn't work that well. You don't want to have to open the app while using the device, you just want all the data to be there when you look in a week.

These devices almost always have wifi since the chips usually have both anyway. And reaching out to a fixed wifi is so much more reliable.

Re: Three million malware-infected smart toothbrushes used in Swiss DDoS attacks

#52
post #11

Earlier quoted context omitted.

Theory: you just don't connect them, right. Reality: connect or it won't start. Next step: integrated sim card.

This literally happened to me on Friday. I was setting up a smart TV for my uncle and he just uses it for his Chromecast so I thought "whatever, I'm not going to connect this TV to his wifi." Come to find out, the TV locks you out of EVERYTHING if you do not connect it to the internet. You see the homescreen but you aren't allowed to switch the input unless you connect to the wifi. Even after connecting to wifi, you…

I had one like this (Toshiba), and I did the initial setup, then blocked it at my router from ever accessing the Internet again. Next TV purchase was a different brand (TCL) that didn't require such stupidity.

Re: Three million malware-infected smart toothbrushes used in Swiss DDoS attacks

#53

I dread the inevitable "Internet dildo wars of 2037" where millions of networked dildos and refrigerators wreaked havoc on the entire Internet causing billions in damage. "Suspects remain at large."

"ChatGPT-enabled Internet-Connected Dildo" is a devastating insult for internet commenters.

Re: Three million malware-infected smart toothbrushes used in Swiss DDoS attacks

#54
post #37

Earlier quoted context omitted.

This also good: https://i.imgur.com/YnBnsKA.jpeg

“The door refused to open. It said, “Five cents, please.” He searched his pockets. No more coins; nothing. “I’ll pay you tomorrow,” he told the door. Again he tried the knob. Again it remained locked tight. “What I pay you,” he informed it, “is in the nature of a gratuity; I don’t have to pay you.” “I think otherwise,” the door said. “Look in the purchase contract you signed when you bought this conapt.” In his desk…

More recently see Cory Doctorow's "Unauthorized Bread":

> The toaster wasn’t the first appliance to go (that honor went to the dishwasher, which stopped being able to validate third-party dishes the week before when Disher went under), but it was the last straw. She could wash dishes in the sink but how the hell was she supposed to make toast—over a candle?

* https://arstechnica.com/gaming/2020/01/unauthorized-bread-a-...

* From: https://en.wikipedia.org/wiki/Radicalized_(Doctorow_book)

Re: Three million malware-infected smart toothbrushes used in Swiss DDoS attacks

#55
post #10

Earlier quoted context omitted.

Not every toothbrush user has a server at home and the skills to attach to it. I would even say that most of those users had no idea what they enabled when they activated their toothbrushes. And let's not forget about vacuum cleaners, refrigerators, washing machines, coffee makers and the other zillions of "smart" personal data channeling smart appliances. I'd dare a survey, how many HN people actually work on exactl…

I have several gizmos which use Bluetooth. They're a little bit slower to connect to than the WiFi ones, but they work fine, and "a bit slower to connect" seems fine for a toothbrush. I also have several gizmos, including lightbulbs, which use WiFi. To my chagrin, I've had internet outages which meant that I can't turn on a given light until the Internet comes back. I put up with it, because telling my computer to ch…

> Somehow we've failed as a profession to provide people with a home network which continues to function as long as the router has power, and that sucks.

This already existed for lightbulbs in the 70's: https://en.wikipedia.org/wiki/X10_(industry_standard)

Wikipedia says the computer interface was 80's, but if you managed to have a computer in the seventies, you probably knew enough electronics to homebrew something.

Re: Three million malware-infected smart toothbrushes used in Swiss DDoS attacks

#56
post #49

A warning about Philips electric toothbrushes: you cannot turn off Bluetooth on them, even if you are not using the smart features. Also be careful with all Philips air purifiers that support Wi-Fi, because the remote control feature cannot be disabled. They create a Wi-Fi hotspot that you need to connect to with a smartphone to finish setting up the device, but if you don't use these features, the air purifier will…

You might not be able to turn bluetooth off, but you can choose not to pair them with anything (or remove the pairing after setting up the device).

Re: Three million malware-infected smart toothbrushes used in Swiss DDoS attacks

#57
post #11

Earlier quoted context omitted.

Theory: you just don't connect them, right. Reality: connect or it won't start. Next step: integrated sim card.

This literally happened to me on Friday. I was setting up a smart TV for my uncle and he just uses it for his Chromecast so I thought "whatever, I'm not going to connect this TV to his wifi." Come to find out, the TV locks you out of EVERYTHING if you do not connect it to the internet. You see the homescreen but you aren't allowed to switch the input unless you connect to the wifi. Even after connecting to wifi, you…

You're sure you read the instructions correctly? What's the make and model of that, please? I think people would like to know. That would certainly be illegal over here in Europe.

Re: Three million malware-infected smart toothbrushes used in Swiss DDoS attacks

#58
Assuming that the article accurately reports the facts (I have my doubts) and these unnamed toothbrushes were used in DDoS attacks, it seems like the obvious deterrent would be for the harmed party to sue for damages. That seems like it work to deter companies from making internet connected when they aren't really needed.

Re: Three million malware-infected smart toothbrushes used in Swiss DDoS attacks

#59
post #34

That's a really flimsy article. Someone is claiming 3 million smart toothbrushes were used in a DDoS, but no one is talking what/who/how. That seems like the kind of extraordinary claim that requires at least some kind of evidence. There is surely at least some technical details that enabled them to identify the toothbrushes, right?

I'd like to see more details too, but it's not that extraordinary in my opinion - par for the course for low-cost wifi-enabled appliances.
Post reply on HN