Live data from Hacker News

How to get root access to your Sleep Number bed

dillan.org

21–30 of 254 posts

Re: How to get root access to your Sleep Number bed

#21
post #2

Why does a bed need to run Linux? Why? Of all the possible timelines, we live in the dumbest. What was wrong with a plain old bed without 1GB of RAM and a full OS running on it?! It is the same everywhere. Finding a washing machine that was not WiFi-connected was a chore and I dread doing it again in ten years. As a person who's broken into O(1000) "smart" devices (for fun and for profit both), I do not want them in…

Sounds like the problem isn't Linux, it's insecure development practices. As mentioned in sibling comment, Linux development is far easier to hire for, iterate on, develop updating mechanisms for, etc - specialized embedded development is less popular.

> Sounds like the problem isn't Linux, it's insecure development practices.

No, it's making devices "smart". There doesn't need to be a wifi-connected computer inside a washing machine, cooker, or fridge. In fact all these things can run without a computer in them at all, and they're arguably better for it.

Re: How to get root access to your Sleep Number bed

#22

Earlier quoted context omitted.

Yea, that part is insane. At this point it is safe to say that any non open source device that has access to you home network and the Internet can function as a backdoor. Not to be a conspiracy theorist, but I guarantee the CIA has a list of common devices with this feature that they can use to get local access in most houses.

Why are you assuming that only non open source devices are vulnerable? We've seen enough open source vulnerabilities in broad daylight to know that open source does not mean secure.

You have it backwards. They're assuming non-open source is backdoor'ed. Not that open source isn't backdoor'ed.

Re: How to get root access to your Sleep Number bed

#23

Earlier quoted context omitted.

Why are you assuming that only non open source devices are vulnerable? We've seen enough open source vulnerabilities in broad daylight to know that open source does not mean secure.

Open source is auditable, and tends to get fixed.

I don't think you can say it tends to get fixed because you don't know the ratio between the number of vulnerabilities and the ones that get fixed. Closed source can also be audited. Auditing code for companies is an entire business model.

Re: How to get root access to your Sleep Number bed

#24

Earlier quoted context omitted.

Sounds like the problem isn't Linux, it's insecure development practices. As mentioned in sibling comment, Linux development is far easier to hire for, iterate on, develop updating mechanisms for, etc - specialized embedded development is less popular.

> Sounds like the problem isn't Linux, it's insecure development practices. No, it's making devices "smart". There doesn't need to be a wifi-connected computer inside a washing machine, cooker, or fridge. In fact all these things can run without a computer in them at all, and they're arguably better for it.

The reason is demand. There's nothing wrong with a smart device (even one you find to be useless) if it's secure. Just.. don't use its smart features.

I of course agree with you principally, I don't want smart devices, but it's not very malicious to have a sleep number bed sitting unconnected...

Re: How to get root access to your Sleep Number bed

#25

Earlier quoted context omitted.

Why are you assuming that only non open source devices are vulnerable? We've seen enough open source vulnerabilities in broad daylight to know that open source does not mean secure.

You have it backwards. They're assuming non-open source is backdoor'ed. Not that open source isn't backdoor'ed.

I don't have it backwards. That is what I said. They are assuming non open source is backdoored. That does not mean open source is not also backdoored.

Re: How to get root access to your Sleep Number bed

#26
post #15
post #9

Earlier quoted context omitted.

how else would you record and transmit measurements to a server? lower-level hardware and software is expensive to develop on and potentially be difficult to update.

[flagged]

Embedded linux is everywhere. Making the initial connection (connect to BED23234 wifi and do xyz on a web page) requires more than a microcontroller. There's no point trying to save a few bucks on such a ridiculously expensive item.

Re: How to get root access to your Sleep Number bed

#28
Funny part to me is that I fully assumed that this was a post about hacking Eight Sleep beds by someone who didn't want to explicitly name the company, presumably for vague legal reasons.

Then I got to a picture of an apparently real "Number Sleep Hub" and my mind was blown. WTF are we in a timeline so weird that there are two companies making water cooled beds, one is called Eight Sleep and the other is Sleep Number? It's like the RNG for this instance had a bad seed.

Re: How to get root access to your Sleep Number bed

#29

Earlier quoted context omitted.

This is what makes me suspicious about Chinese home products like govee and how cheap they are. You're required to hard code in your SSID and Wi-Fi password. And they consistently beg for your location, despite having no need for it.

Now think about 3D printers like the Bambu. A machine tool that can self-combust.

Shades of Iranian centrifuges.

Re: How to get root access to your Sleep Number bed

#30
post #6
post #4

Buried lede: “What I did find was a "convenient" backdoor that Sleep Number can use to SSH back into the hub (and my internal home network as a result).”

This was the most interesting point for me, and I assume most of my IOT type shit has this functionality.

some of the newer WiFi setups have an IoT subnet that works like a guest network.

Worth using if your gear has it.

Post reply on HN