Live data from Hacker News

Three million malware-infected smart toothbrushes used in Swiss DDoS attacks

tomshardware.com

91–100 of 182 posts

Re: Three million malware-infected smart toothbrushes used in Swiss DDoS attacks

#91
post #80

Earlier quoted context omitted.

Anyone in Wi-Fi range can exploit the device. The sensors of the air purifier can be used for spying, and the device could also serve as a hopping point for exploiting other devices in your home.

> The sensors of the air purifier can be used for spying To be able to... know if your target's house has a lot of pollutants? Is particularly warm? There is practically no useful information that can't be gleamed by just looking through their windows, blinds and all. > and the device could also be used as a hopping point for exploiting other devices in your home. It's not connected to your home network, that's the w…

[deleted]

Re: Three million malware-infected smart toothbrushes used in Swiss DDoS attacks

#92
post #49

A warning about Philips electric toothbrushes: you cannot turn off Bluetooth on them, even if you are not using the smart features. Also be careful with all Philips air purifiers that support Wi-Fi, because the remote control feature cannot be disabled. They create a Wi-Fi hotspot that you need to connect to with a smartphone to finish setting up the device, but if you don't use these features, the air purifier will…

I finally got rid of one of my fitness watches that had dreadful battery life and I couldn't figure out why. After a few months of this, I finally realized the same thing, you can't turn off the bluetooth on it. The app on your phone and the watch are constantly searching for each other to always sync and the alternative is to unpair the watch, use it, re-pair, sync and go which became a total headache, but did in fa…

I've been using Garmin GPS watches for more than a decade, they get two weeks on a single charge (double or triple that if you don't use 24/7 heart rate, or GPS, or Bluetooth/Wifi, but even on long trips I don't need months without a charge). And they have Bluetooth that syncs with my phone for weather data and optionally shows notifications, but it doesn't need a phone connection to be a great watch.

Sure, my top-end Fenix 6 Pro cost $750 new in 2019, and very little of that is hardware BOM (there's a lot of price segmentation), but it's still just as good as it was then. It's honestly extremely refreshing to deal with a company and an app that tries to build and sell good hardware rather than tricking you into a subscription.

Re: Three million malware-infected smart toothbrushes used in Swiss DDoS attacks

#93
post #26

Is nobody going to mention Java running on the toothbrush? One might guess the firmware included a battery controller, bluetooth or wifi stacks, a little storage, and business logic for buttons and brushing.

"3 Billion Devices Run Java"

Maybe not all of them should.

Re: Three million malware-infected smart toothbrushes used in Swiss DDoS attacks

#94

Earlier quoted context omitted.

The users phone, via a Bluetooth connection?

It's possible but its really unreliable. A device trying to reach out to an app on your phone to proxy the data while your phone is sleeping/app not running just doesn't work that well. You don't want to have to open the app while using the device, you just want all the data to be there when you look in a week. These devices almost always have wifi since the chips usually have both anyway. And reaching out to a fixed…

If you have enough room to store WiFi credentials, then you probably have enough room to store toothbrush use statistics.

There is no need to copy that data to a phone immediately. It can be put off until it's convenient.

Re: Three million malware-infected smart toothbrushes used in Swiss DDoS attacks

#95
post #26

Is nobody going to mention Java running on the toothbrush? One might guess the firmware included a battery controller, bluetooth or wifi stacks, a little storage, and business logic for buttons and brushing.

Why does it matter? Embedded Java is quite popular. https://en.wikipedia.org/wiki/Embedded_Java

Re: Three million malware-infected smart toothbrushes used in Swiss DDoS attacks

#97

I had misremembered these as a single comic, but you can't have everything: https://i0.wp.com/www.litterboxcomics.com/wp-content/uploads... https://i0.wp.com/www.litterboxcomics.com/wp-content/uploads...

So do I drink my verification can before or after brushing?

Before. Otherwise, you're washing down all the fluoride instead of giving it time to bind to your enamel via chemical API calls.

Re: Three million malware-infected smart toothbrushes used in Swiss DDoS attacks

#98
post #80

Earlier quoted context omitted.

Anyone in Wi-Fi range can exploit the device. The sensors of the air purifier can be used for spying, and the device could also serve as a hopping point for exploiting other devices in your home.

> The sensors of the air purifier can be used for spying To be able to... know if your target's house has a lot of pollutants? Is particularly warm? There is practically no useful information that can't be gleamed by just looking through their windows, blinds and all. > and the device could also be used as a hopping point for exploiting other devices in your home. It's not connected to your home network, that's the w…

You're lacking in imagination, and maybe the conceptual idea of "sensor fusion". Multiple seemingly innocuous data streams in isolation can be combined to create sensors you wouldn't have imagined

Re: Three million malware-infected smart toothbrushes used in Swiss DDoS attacks

#99
This article is strange & many details are lacking. All the big smart toothbrushes use BLE and are not WiFi-connected. Tried to fact-check the article, but nothing.

A bunch of BLE chips are also WiFi capable, so not ruling out that someone compromised the firmware to enable WiFi functionality, but I wonder how they were able to connect to WiFi to trigger a botnet in the first place.

Quite skeptical of this article, while the premise of the danger of IoT devices still remains, nonetheless.

Re: Three million malware-infected smart toothbrushes used in Swiss DDoS attacks

#100
post #2

My theory is that every technology goes through a period of experimentation before it’s clear how it should be employed. That’s why we had project plowshare for the bomb and now internet connectivity for every imaginable device, even ones that only need an on-off switch. I am a bit mystified why we need connected toothbrushes, but I very much applaud the spirit of experimentation, even if it sometimes gives us toothb…

We're not taking about experimentation, though. We're talking about a fully hashed-out business model with its own casual acronym (SaaS).

The "why" is obvious: there is a market for any aggregate data on human behavior.

Post reply on HN