Never thought I'd be judging a toothbrush based on cybersecurity, but here we are...
Three million malware-infected smart toothbrushes used in Swiss DDoS attacks
131–140 of 182 posts
Re: Three million malware-infected smart toothbrushes used in Swiss DDoS attacks
#132Earlier quoted context omitted.
>A bunch of BLE chips are also WiFi capable, so not ruling out that someone compromised the firmware to enable WiFi functionality The ESP32 is now used as a general-purposed chip even in applications where an 8-bit MCU would have been enough. A remotely exploitable vulnerability in the ESP32/SDK could have large-scale consequences.
Leaves open the question of how they joined the network - WiFi passwords and such. Maybe stolen from the phones/laptops and then sent to the device as part of the exploit?
This does seem to be a debunked story though.
Re: Three million malware-infected smart toothbrushes used in Swiss DDoS attacks
#133This article is strange & many details are lacking. All the big smart toothbrushes use BLE and are not WiFi-connected. Tried to fact-check the article, but nothing. A bunch of BLE chips are also WiFi capable, so not ruling out that someone compromised the firmware to enable WiFi functionality, but I wonder how they were able to connect to WiFi to trigger a botnet in the first place. Quite skeptical of this article, w…
>A bunch of BLE chips are also WiFi capable, so not ruling out that someone compromised the firmware to enable WiFi functionality The ESP32 is now used as a general-purposed chip even in applications where an 8-bit MCU would have been enough. A remotely exploitable vulnerability in the ESP32/SDK could have large-scale consequences.
Re: Three million malware-infected smart toothbrushes used in Swiss DDoS attacks
#134Earlier quoted context omitted.
I'm reminded of this that I read a few days ago: Home assistant picked up my neighbours Bluetooth toothbrush and now I can see when they brush their teeth. https://old.reddit.com/r/homeassistant/comments/1306pcw/home...
Send them a message if they miss a brushing.
Re: Three million malware-infected smart toothbrushes used in Swiss DDoS attacks
#135This article is strange & many details are lacking. All the big smart toothbrushes use BLE and are not WiFi-connected. Tried to fact-check the article, but nothing. A bunch of BLE chips are also WiFi capable, so not ruling out that someone compromised the firmware to enable WiFi functionality, but I wonder how they were able to connect to WiFi to trigger a botnet in the first place. Quite skeptical of this article, w…
I know java me was a thing and there are micro jvm that can run on microcontrollers but still, it does not add up.
I think a DDoS attack happened (happens all the time) and security "experts" mentioned that these things could come from anywhere, even toothbrush, and the details got lost in translation / used for click bait.
Re: Three million malware-infected smart toothbrushes used in Swiss DDoS attacks
#136Earlier quoted context omitted.
The call if of course on device owners, and not device manufacturers whose responsibility it truly is to manufacture secure devices.
100% agree, but I have to wonder how much of the problem is that the cost of security is: A. Not mandated B. Increases cost of the product At what point would people just prefer a regular toothbrush if a smart one doesn't provide enough utility to justify the cost? This isn't specific to toothbrushes, but I wonder what products or services wouldn't exist if they were made to be secure (or safe/ethical/sustainable/etc…
IMHO, any commercial violations of human rights, like privacy, should have criminal penalties.
Re: Three million malware-infected smart toothbrushes used in Swiss DDoS attacks
#137Earlier quoted context omitted.
Ah ok, so we are talking about dumb old methods. I thought it was something like the fancy APIs that are all the rage these days.
There was a brief window when people knew that if they used non-HTTP protocols, then malicious webpages couldn't talk to it. But now even "native" apps are web apps, and IoT devices all use web APIs too. They can be locked down through CORS etc., but it's easier for devs to set `Access-Control-Allow-Origin: *` and worry about it "later".
The real mistake is mirroring the Origin header from the request in the `Access-Control-Allow-Origin` response header which allows credentials (unless you add other headers)
Of course this all relies on you not accepting form posts without auth.
Re: Three million malware-infected smart toothbrushes used in Swiss DDoS attacks
#138This article is strange & many details are lacking. All the big smart toothbrushes use BLE and are not WiFi-connected. Tried to fact-check the article, but nothing. A bunch of BLE chips are also WiFi capable, so not ruling out that someone compromised the firmware to enable WiFi functionality, but I wonder how they were able to connect to WiFi to trigger a botnet in the first place. Quite skeptical of this article, w…
It's not something that actually happened. It's just some bullshit that's gone viral. https://cyberplace.social/@GossiTheDog/111886558855943676
I don't see a mention of "NoName Ddosia".
Re: Three million malware-infected smart toothbrushes used in Swiss DDoS attacks
#139Earlier quoted context omitted.
You're lacking in imagination, and maybe the conceptual idea of "sensor fusion". Multiple seemingly innocuous data streams in isolation can be combined to create sensors you wouldn't have imagined
Do you understand what data is available in a smart air purifier? Please, explain exactly what sensor fusion would get you actionable data out of the PM2.5 sensor and "gas sensor" in a Philips smart air purifier.
Re: Three million malware-infected smart toothbrushes used in Swiss DDoS attacks
#140Earlier quoted context omitted.
You're lacking in imagination, and maybe the conceptual idea of "sensor fusion". Multiple seemingly innocuous data streams in isolation can be combined to create sensors you wouldn't have imagined
Do you understand what data is available in a smart air purifier? Please, explain exactly what sensor fusion would get you actionable data out of the PM2.5 sensor and "gas sensor" in a Philips smart air purifier.
It's not even far fetched, smart watches reporting physical actively at unexpected hours have revealed infidelity in the past.