A warning about Philips electric toothbrushes: you cannot turn off Bluetooth on them, even if you are not using the smart features. Also be careful with all Philips air purifiers that support Wi-Fi, because the remote control feature cannot be disabled. They create a Wi-Fi hotspot that you need to connect to with a smartphone to finish setting up the device, but if you don't use these features, the air purifier will…
You might not be able to turn bluetooth off, but you can choose not to pair them with anything (or remove the pairing after setting up the device).
Three million malware-infected smart toothbrushes used in Swiss DDoS attacks
61–70 of 182 posts
Re: Three million malware-infected smart toothbrushes used in Swiss DDoS attacks
#62Would make the shitty vendors think twice before creating piles of e-waste due to zero cost of entry.
Re: Three million malware-infected smart toothbrushes used in Swiss DDoS attacks
#63That's a really flimsy article. Someone is claiming 3 million smart toothbrushes were used in a DDoS, but no one is talking what/who/how. That seems like the kind of extraordinary claim that requires at least some kind of evidence. There is surely at least some technical details that enabled them to identify the toothbrushes, right?
It also seems odd that even if you (maybe unknowingly) connected your 'smart' toothbrush to wifi, it would be exposed to the public internet. Aren't most people using some kind of clunky cable modem etc. from their ISP, which would have a basic inbound firewall?
The most obvious is UPnP, where the device can ask the gateway router to forward ports.
The second is the fact that devices on the LAN are accessible to other devices on the LAN. Malicious JS in a webpage can scan for and compromise other local devices.
And the third is the fact that whatever serves code to the toothbrush (whether it's firmware updates, or an HTML5 dashboard) can be compromised. In the latter case, it could be something as simple as persistent XSS.
Re: Three million malware-infected smart toothbrushes used in Swiss DDoS attacks
#64Earlier quoted context omitted.
I have several gizmos which use Bluetooth. They're a little bit slower to connect to than the WiFi ones, but they work fine, and "a bit slower to connect" seems fine for a toothbrush. I also have several gizmos, including lightbulbs, which use WiFi. To my chagrin, I've had internet outages which meant that I can't turn on a given light until the Internet comes back. I put up with it, because telling my computer to ch…
> Somehow we've failed as a profession to provide people with a home network which continues to function as long as the router has power, and that sucks. This already existed for lightbulbs in the 70's: https://en.wikipedia.org/wiki/X10_(industry_standard) Wikipedia says the computer interface was 80's, but if you managed to have a computer in the seventies, you probably knew enough electronics to homebrew something.
That's worse. You see how that's worse, right?
Re: Three million malware-infected smart toothbrushes used in Swiss DDoS attacks
#65A warning about Philips electric toothbrushes: you cannot turn off Bluetooth on them, even if you are not using the smart features. Also be careful with all Philips air purifiers that support Wi-Fi, because the remote control feature cannot be disabled. They create a Wi-Fi hotspot that you need to connect to with a smartphone to finish setting up the device, but if you don't use these features, the air purifier will…
Re: Three million malware-infected smart toothbrushes used in Swiss DDoS attacks
#66Earlier quoted context omitted.
It also seems odd that even if you (maybe unknowingly) connected your 'smart' toothbrush to wifi, it would be exposed to the public internet. Aren't most people using some kind of clunky cable modem etc. from their ISP, which would have a basic inbound firewall?
There's lots of ways for this expectation to be broken. The most obvious is UPnP, where the device can ask the gateway router to forward ports. The second is the fact that devices on the LAN are accessible to other devices on the LAN. Malicious JS in a webpage can scan for and compromise other local devices. And the third is the fact that whatever serves code to the toothbrush (whether it's firmware updates, or an HT…
Which browser API enables that?
Re: Three million malware-infected smart toothbrushes used in Swiss DDoS attacks
#67Earlier quoted context omitted.
There's lots of ways for this expectation to be broken. The most obvious is UPnP, where the device can ask the gateway router to forward ports. The second is the fact that devices on the LAN are accessible to other devices on the LAN. Malicious JS in a webpage can scan for and compromise other local devices. And the third is the fact that whatever serves code to the toothbrush (whether it's firmware updates, or an HT…
> The second is the fact that devices on the LAN are accessible to other devices on the LAN. Malicious JS in a webpage can scan for and compromise other local devices. Which browser API enables that?
Re: Three million malware-infected smart toothbrushes used in Swiss DDoS attacks
#68A warning about Philips electric toothbrushes: you cannot turn off Bluetooth on them, even if you are not using the smart features. Also be careful with all Philips air purifiers that support Wi-Fi, because the remote control feature cannot be disabled. They create a Wi-Fi hotspot that you need to connect to with a smartphone to finish setting up the device, but if you don't use these features, the air purifier will…
The weird thing is I complained to the company's CSR people online and they had no idea why the battery was so bad and just told me to try and factory hard reset the phone as there must be something I changed in the settings.
I switched over to Polar and now the watch I have lasts 5 days on a single charge - quit the change from about a day or less.
Re: Three million malware-infected smart toothbrushes used in Swiss DDoS attacks
#69Earlier quoted context omitted.
Because the actual business model is selling the aggregated data?
What data though? How would it be valuable? From what I saw they are getting money from the device sale itself. These iot toothbrushes are like $400 and basically just track brushing time and pressure. Those don't seem like super valuable ad tracking metrics.
Let's assume we have the following data: the user's email address, some sort of smartphone identifying value, their ip address, and their brushing habits. That's not very much; who would want that?
Well, we know this is a person who will drop $400 on a toothbrush. They like shiny things, they have at least a middle-class disposable income, and they don't mind the headaches of internet-connected devices. Let's sell this information to big-box electronics retailers and other smart appliance manufacturers. Maybe this person would like to buy a $500 toaster too, or espresso machine, or soda machine, or bread machine, or microwave.
They care a little bit about oral hygiene. Have they seen a dentist lately? If they have $400 for a toothbrush, then they probably have better than average dental insurance. Let's also sell their information to the larger dental offices in their area (as determined by IP).
Do they need mouthwash? Let's pop up an ad for a subscription mouthwash service. How about floss? Would they perhaps also appreciate a razor made out of aerospace titanium?
Oh, but wait ... their IP address just changed, and they are brushing their teeth 3 hours later than typical. They're traveling! They're traveling and they took their expensive toothbrush with them. This opens up an entirely new set of possibilities. Travel insurance? A credit card with travel incentives? New luggage? How about offers for travel upgrades? There are hundreds of companies paying for the opportunity to contact pre-qualified customers that travel with disposable income.
Oh, wait ... they just bought a set of lightbulbs that we also make...
Re: Three million malware-infected smart toothbrushes used in Swiss DDoS attacks
#70A warning about Philips electric toothbrushes: you cannot turn off Bluetooth on them, even if you are not using the smart features. Also be careful with all Philips air purifiers that support Wi-Fi, because the remote control feature cannot be disabled. They create a Wi-Fi hotspot that you need to connect to with a smartphone to finish setting up the device, but if you don't use these features, the air purifier will…
Home assistant picked up my neighbours Bluetooth toothbrush and now I can see when they brush their teeth.
https://old.reddit.com/r/homeassistant/comments/1306pcw/home...