Live data from Hacker News

Three million malware-infected smart toothbrushes used in Swiss DDoS attacks

tomshardware.com

111–120 of 182 posts

Re: Three million malware-infected smart toothbrushes used in Swiss DDoS attacks

#112
post #99

This article is strange & many details are lacking. All the big smart toothbrushes use BLE and are not WiFi-connected. Tried to fact-check the article, but nothing. A bunch of BLE chips are also WiFi capable, so not ruling out that someone compromised the firmware to enable WiFi functionality, but I wonder how they were able to connect to WiFi to trigger a botnet in the first place. Quite skeptical of this article, w…

>A bunch of BLE chips are also WiFi capable, so not ruling out that someone compromised the firmware to enable WiFi functionality The ESP32 is now used as a general-purposed chip even in applications where an 8-bit MCU would have been enough. A remotely exploitable vulnerability in the ESP32/SDK could have large-scale consequences.

[deleted]

Re: Three million malware-infected smart toothbrushes used in Swiss DDoS attacks

#114

I have an older Phillips toothbrush without Bluetooth, Internet or vendor-locked heads, and it charges wirelessly in a glass cup. I love it. I recently tried to buy a second one and could only find newer models with all these garbage features I don't want. Who the hell wants their toothbrush to connect to the internet? Wound up turning to eBay to find stock of the old one. It might sound cruel, but I hope the moron w…

Wifi is silly, but there really is a benefit to the Bluetooth/app connection -- it is used to see where you are brushing and spots you are missing. My dentist definitely has seen an improvement in the plaque in my back teeth since I started using a smart toothbrush that uses an app on my phone.

> spots you are missing

Just brush each tooth systematically. My dentist tells me "Just keep doing what you are doing." I have the cheapest Braun Oral-B with a two minute timer. I've worked out by trial and error that that is about the time to stroke each face of each tooth about twelve times. Now I do that even if it takes a bit longer than two minutes because I occasionally brush slower.

Re: Three million malware-infected smart toothbrushes used in Swiss DDoS attacks

#115
post #99

This article is strange & many details are lacking. All the big smart toothbrushes use BLE and are not WiFi-connected. Tried to fact-check the article, but nothing. A bunch of BLE chips are also WiFi capable, so not ruling out that someone compromised the firmware to enable WiFi functionality, but I wonder how they were able to connect to WiFi to trigger a botnet in the first place. Quite skeptical of this article, w…

>A bunch of BLE chips are also WiFi capable, so not ruling out that someone compromised the firmware to enable WiFi functionality The ESP32 is now used as a general-purposed chip even in applications where an 8-bit MCU would have been enough. A remotely exploitable vulnerability in the ESP32/SDK could have large-scale consequences.

Leaves open the question of how they joined the network - WiFi passwords and such. Maybe stolen from the phones/laptops and then sent to the device as part of the exploit?

Re: Three million malware-infected smart toothbrushes used in Swiss DDoS attacks

#116
post #99

This article is strange & many details are lacking. All the big smart toothbrushes use BLE and are not WiFi-connected. Tried to fact-check the article, but nothing. A bunch of BLE chips are also WiFi capable, so not ruling out that someone compromised the firmware to enable WiFi functionality, but I wonder how they were able to connect to WiFi to trigger a botnet in the first place. Quite skeptical of this article, w…

> but I wonder how they were able to connect to WiFi to trigger a botnet in the first place.

Wardriving for oral health?

Re: Three million malware-infected smart toothbrushes used in Swiss DDoS attacks

#117
post #10

Why do toothbrushes need to be able to make web connections in the first place? I get that it's for tracking brushing habits, but can't that be done with local connectivity only, like LAN or something?

Not every toothbrush user has a server at home and the skills to attach to it. I would even say that most of those users had no idea what they enabled when they activated their toothbrushes. And let's not forget about vacuum cleaners, refrigerators, washing machines, coffee makers and the other zillions of "smart" personal data channeling smart appliances. I'd dare a survey, how many HN people actually work on exactl…

Just have the toothbrush run a web server and then the user can point a web browser at it. It can also come with a mobile app that would scan the local network looking for the device in order to discover the IP.

Re: Three million malware-infected smart toothbrushes used in Swiss DDoS attacks

#118

Earlier quoted context omitted.

More recently see Cory Doctorow's "Unauthorized Bread": > The toaster wasn’t the first appliance to go (that honor went to the dishwasher, which stopped being able to validate third-party dishes the week before when Disher went under), but it was the last straw. She could wash dishes in the sink but how the hell was she supposed to make toast—over a candle? * https://arstechnica.com/gaming/2020/01/unauthorized-bread-…

This would funny but since it's pretty much exactly how printers behave it's more just a slap in the face

I guess it's time to echo the meme: "The band 'Rage against the machine' does not explicitly says what kind of machine they are enraged to, but I'm pretty sure it's a printer".

EDIT: screen of the original tweet: https://old.reddit.com/r/printers/comments/vqmbu4/rage_again...

Re: Three million malware-infected smart toothbrushes used in Swiss DDoS attacks

#119

Earlier quoted context omitted.

If you have enough room to store WiFi credentials, then you probably have enough room to store toothbrush use statistics. There is no need to copy that data to a phone immediately . It can be put off until it's convenient.

And then the user goes out for the day, opens up the app, and wonders why the last 3 days of data is missing. Meanwhile the chip that does Bluetooth also just has wifi bundled in. Aside from the security risk, directly connecting to wifi is a vastly superior experience.

How much data can a toothbrush collect? Surely just a few hundred bytes per brushing session. The ESP32 has 160 kB of usable RAM out of the 520 kB total capacity. Surely enough for weeks of data even if the data structures are badly designed.

Re: Three million malware-infected smart toothbrushes used in Swiss DDoS attacks

#120
post #89

Earlier quoted context omitted.

Yeah, we've invented it several times over, and yet, what people buy and use is IoS crapware which craps out when the network does. That's worse. You see how that's worse, right?

yeah, everything keeps getting reinvented worse or made worse by adding unwanted, poorly implemented features. My unstated point was that a version existed decades ago which was more robust than the new, reinvented version. I'm not sure that people (in general) want these things. It seems like product managers adding stuff to justify their existence and people buying what they find on the shelf. You get an internet c…

I find it a genuine quality-of-life improvement to adjust the color of light. The temperature matters more, but being able to do strong hues is really nice. Not everyone is into mood lighting, but I like it.

And I don't care as much about whether or not the bulb uses IP to reach my phone, but why should my outside connection going down ever matter? As long as the router has power, the internal network should continue to function. It's a shame is what it is. I figure I could put in the sweat to make it "work on my machine" but that doesn't solve Joe Normal's problem, and it doesn't sound like a fun hobby to me either.

Post reply on HN