Live data from Hacker News

Three million malware-infected smart toothbrushes used in Swiss DDoS attacks

tomshardware.com

61–70 of 182 posts

Re: Three million malware-infected smart toothbrushes used in Swiss DDoS attacks

#61
post #56
post #49

A warning about Philips electric toothbrushes: you cannot turn off Bluetooth on them, even if you are not using the smart features. Also be careful with all Philips air purifiers that support Wi-Fi, because the remote control feature cannot be disabled. They create a Wi-Fi hotspot that you need to connect to with a smartphone to finish setting up the device, but if you don't use these features, the air purifier will…

You might not be able to turn bluetooth off, but you can choose not to pair them with anything (or remove the pairing after setting up the device).

The issue is what happens to these toothbrushes in a couple of years when their vulnerabilities will be discovered. Their inevitable exploitation could be prevented by simply allowing to turn off bluetooth. Or even better, only enable bluetooth if the user wants to set up and use these smart features, at least in that case the vulnerable firmware can be updated using the smartphone app.

Re: Three million malware-infected smart toothbrushes used in Swiss DDoS attacks

#62
Every internet-of-shit device should be legally required to go through a security audit, and the vendor should commit to mandatory 5 years of API being up + 5 years of security updates, with N days to fix CVEs with severity over a certain threshold.

Would make the shitty vendors think twice before creating piles of e-waste due to zero cost of entry.

Re: Three million malware-infected smart toothbrushes used in Swiss DDoS attacks

#63
post #34

That's a really flimsy article. Someone is claiming 3 million smart toothbrushes were used in a DDoS, but no one is talking what/who/how. That seems like the kind of extraordinary claim that requires at least some kind of evidence. There is surely at least some technical details that enabled them to identify the toothbrushes, right?

It also seems odd that even if you (maybe unknowingly) connected your 'smart' toothbrush to wifi, it would be exposed to the public internet. Aren't most people using some kind of clunky cable modem etc. from their ISP, which would have a basic inbound firewall?

There's lots of ways for this expectation to be broken.

The most obvious is UPnP, where the device can ask the gateway router to forward ports.

The second is the fact that devices on the LAN are accessible to other devices on the LAN. Malicious JS in a webpage can scan for and compromise other local devices.

And the third is the fact that whatever serves code to the toothbrush (whether it's firmware updates, or an HTML5 dashboard) can be compromised. In the latter case, it could be something as simple as persistent XSS.

Re: Three million malware-infected smart toothbrushes used in Swiss DDoS attacks

#64
post #55

Earlier quoted context omitted.

I have several gizmos which use Bluetooth. They're a little bit slower to connect to than the WiFi ones, but they work fine, and "a bit slower to connect" seems fine for a toothbrush. I also have several gizmos, including lightbulbs, which use WiFi. To my chagrin, I've had internet outages which meant that I can't turn on a given light until the Internet comes back. I put up with it, because telling my computer to ch…

> Somehow we've failed as a profession to provide people with a home network which continues to function as long as the router has power, and that sucks. This already existed for lightbulbs in the 70's: https://en.wikipedia.org/wiki/X10_(industry_standard) Wikipedia says the computer interface was 80's, but if you managed to have a computer in the seventies, you probably knew enough electronics to homebrew something.

Yeah, we've invented it several times over, and yet, what people buy and use is IoS crapware which craps out when the network does.

That's worse. You see how that's worse, right?

Re: Three million malware-infected smart toothbrushes used in Swiss DDoS attacks

#65
post #49

A warning about Philips electric toothbrushes: you cannot turn off Bluetooth on them, even if you are not using the smart features. Also be careful with all Philips air purifiers that support Wi-Fi, because the remote control feature cannot be disabled. They create a Wi-Fi hotspot that you need to connect to with a smartphone to finish setting up the device, but if you don't use these features, the air purifier will…

What risks could a WiFi hotspot on an air purifier expose if it's not connected to the network or a computer?

Re: Three million malware-infected smart toothbrushes used in Swiss DDoS attacks

#66
post #63

Earlier quoted context omitted.

It also seems odd that even if you (maybe unknowingly) connected your 'smart' toothbrush to wifi, it would be exposed to the public internet. Aren't most people using some kind of clunky cable modem etc. from their ISP, which would have a basic inbound firewall?

There's lots of ways for this expectation to be broken. The most obvious is UPnP, where the device can ask the gateway router to forward ports. The second is the fact that devices on the LAN are accessible to other devices on the LAN. Malicious JS in a webpage can scan for and compromise other local devices. And the third is the fact that whatever serves code to the toothbrush (whether it's firmware updates, or an HT…

> The second is the fact that devices on the LAN are accessible to other devices on the LAN. Malicious JS in a webpage can scan for and compromise other local devices.

Which browser API enables that?

Re: Three million malware-infected smart toothbrushes used in Swiss DDoS attacks

#67
post #63

Earlier quoted context omitted.

There's lots of ways for this expectation to be broken. The most obvious is UPnP, where the device can ask the gateway router to forward ports. The second is the fact that devices on the LAN are accessible to other devices on the LAN. Malicious JS in a webpage can scan for and compromise other local devices. And the third is the fact that whatever serves code to the toothbrush (whether it's firmware updates, or an HT…

> The second is the fact that devices on the LAN are accessible to other devices on the LAN. Malicious JS in a webpage can scan for and compromise other local devices. Which browser API enables that?

HTTP, it's all the rage these days. (via , fetch, XMLHttpRequest, et al)

Re: Three million malware-infected smart toothbrushes used in Swiss DDoS attacks

#68
post #49

A warning about Philips electric toothbrushes: you cannot turn off Bluetooth on them, even if you are not using the smart features. Also be careful with all Philips air purifiers that support Wi-Fi, because the remote control feature cannot be disabled. They create a Wi-Fi hotspot that you need to connect to with a smartphone to finish setting up the device, but if you don't use these features, the air purifier will…

I finally got rid of one of my fitness watches that had dreadful battery life and I couldn't figure out why. After a few months of this, I finally realized the same thing, you can't turn off the bluetooth on it. The app on your phone and the watch are constantly searching for each other to always sync and the alternative is to unpair the watch, use it, re-pair, sync and go which became a total headache, but did in fact give me better battery life.

The weird thing is I complained to the company's CSR people online and they had no idea why the battery was so bad and just told me to try and factory hard reset the phone as there must be something I changed in the settings.

I switched over to Polar and now the watch I have lasts 5 days on a single charge - quit the change from about a day or less.

Re: Three million malware-infected smart toothbrushes used in Swiss DDoS attacks

#69
post #6

Earlier quoted context omitted.

Because the actual business model is selling the aggregated data?

What data though? How would it be valuable? From what I saw they are getting money from the device sale itself. These iot toothbrushes are like $400 and basically just track brushing time and pressure. Those don't seem like super valuable ad tracking metrics.

This might be a fun exercise.

Let's assume we have the following data: the user's email address, some sort of smartphone identifying value, their ip address, and their brushing habits. That's not very much; who would want that?

Well, we know this is a person who will drop $400 on a toothbrush. They like shiny things, they have at least a middle-class disposable income, and they don't mind the headaches of internet-connected devices. Let's sell this information to big-box electronics retailers and other smart appliance manufacturers. Maybe this person would like to buy a $500 toaster too, or espresso machine, or soda machine, or bread machine, or microwave.

They care a little bit about oral hygiene. Have they seen a dentist lately? If they have $400 for a toothbrush, then they probably have better than average dental insurance. Let's also sell their information to the larger dental offices in their area (as determined by IP).

Do they need mouthwash? Let's pop up an ad for a subscription mouthwash service. How about floss? Would they perhaps also appreciate a razor made out of aerospace titanium?

Oh, but wait ... their IP address just changed, and they are brushing their teeth 3 hours later than typical. They're traveling! They're traveling and they took their expensive toothbrush with them. This opens up an entirely new set of possibilities. Travel insurance? A credit card with travel incentives? New luggage? How about offers for travel upgrades? There are hundreds of companies paying for the opportunity to contact pre-qualified customers that travel with disposable income.

Oh, wait ... they just bought a set of lightbulbs that we also make...

Re: Three million malware-infected smart toothbrushes used in Swiss DDoS attacks

#70
post #49

A warning about Philips electric toothbrushes: you cannot turn off Bluetooth on them, even if you are not using the smart features. Also be careful with all Philips air purifiers that support Wi-Fi, because the remote control feature cannot be disabled. They create a Wi-Fi hotspot that you need to connect to with a smartphone to finish setting up the device, but if you don't use these features, the air purifier will…

I'm reminded of this that I read a few days ago:

Home assistant picked up my neighbours Bluetooth toothbrush and now I can see when they brush their teeth.

https://old.reddit.com/r/homeassistant/comments/1306pcw/home...

Post reply on HN