Live data from Hacker News

How to get root access to your Sleep Number bed

dillan.org

41–50 of 254 posts

Re: How to get root access to your Sleep Number bed

#41
post #4

Buried lede: “What I did find was a "convenient" backdoor that Sleep Number can use to SSH back into the hub (and my internal home network as a result).”

Yea, that part is insane. At this point it is safe to say that any non open source device that has access to you home network and the Internet can function as a backdoor. Not to be a conspiracy theorist, but I guarantee the CIA has a list of common devices with this feature that they can use to get local access in most houses.

I wouldn’t consider that a conspiracy theory, I would consider it common sense that an intelligence agency has a list of common potential sources of intelligence.

In fact it would be extremely surprising if they didn’t have that list.

Re: How to get root access to your Sleep Number bed

#42
> r: Following this guide will require modifying internal files on your Sleep Number hub. This will void your warranty

People, stop spreading this BS.

Just like those stickers that say "warranty void if removed" are not legally enforceable, nothing "automatically" invalidates your product's warranty except misuse or poor maintenance.

If your Smart Bed stops working, you having poked around in the controller does not relieve the manufacturer from their warranty obligations (including implied warranty.) The onus is on them to prove that you damaged it, subjected it to "unreasonable" use, or did not properly maintain it.

You fry the bed's brain trying to hook up a JTAG when you accidentally bridge 5V to a 3.3V logic circuit? That's on you.

The controller fails because the power supply blows? The fact that you installed a JTAG header, googly eyes, and painted it pink is irrelevant. They need to fix your shit.

Even if you modify the firmware, it's on them to prove your modifications caused the failure.

Would you expect to have your laptop's warranty invalidated because you use it to game (which generates lot of heat)? Of course not. How about if you install Firefox? Or install Linux? Again, of course not. So why do you think the rules change just because a device is "dumber"?

Re: How to get root access to your Sleep Number bed

#43
post #9

Earlier quoted context omitted.

how else would you record and transmit measurements to a server? lower-level hardware and software is expensive to develop on and potentially be difficult to update.

I don't need my bed to transmit measurements to a server . I need my bed to be comfortable to sleep on. I need exactly zero interactions with a server for that. So, yeah, back to the question. Why does my bed have an SSH server? Because it needs to be able to talk to some machine on the internet. And why does my bed need that? It's a bed. [Edit: Wait a minute. Even if I do want to transmit measurements, why is my bed…

> I don't need my bed to transmit measurements to a server. I need my bed to be comfortable to sleep on. I need exactly zero interactions with a server for that.

Then don’t buy this specific bed?

These features are part of why people buy this product. Nobody is accidentally purchasing this as “just a bed” and then discovering that it has an app and smart controls as a surprise later.

> And why does my bed need that? It's a bed.

This is a very dishonest take. If you don’t understand or don’t want the product, then don’t buy it. But the smart controls exist because people (other than you) want them.

Re: How to get root access to your Sleep Number bed

#44

Earlier quoted context omitted.

Yea, that part is insane. At this point it is safe to say that any non open source device that has access to you home network and the Internet can function as a backdoor. Not to be a conspiracy theorist, but I guarantee the CIA has a list of common devices with this feature that they can use to get local access in most houses.

This is what makes me suspicious about Chinese home products like govee and how cheap they are. You're required to hard code in your SSID and Wi-Fi password. And they consistently beg for your location, despite having no need for it.

oh believe me, american manufacturers are absolutely no better

Re: How to get root access to your Sleep Number bed

#45
post #31

Earlier quoted context omitted.

I don't have it backwards. That is what I said. They are assuming non open source is backdoored. That does not mean open source is not also backdoored.

No, you you said >Why are you assuming that only non open source devices are vulnerable?

Yes, the word "only" is causing the confusion.

Re: How to get root access to your Sleep Number bed

#46
post #9

Earlier quoted context omitted.

how else would you record and transmit measurements to a server? lower-level hardware and software is expensive to develop on and potentially be difficult to update.

I don't need my bed to transmit measurements to a server . I need my bed to be comfortable to sleep on. I need exactly zero interactions with a server for that. So, yeah, back to the question. Why does my bed have an SSH server? Because it needs to be able to talk to some machine on the internet. And why does my bed need that? It's a bed. [Edit: Wait a minute. Even if I do want to transmit measurements, why is my bed…

> Why does my bed have an SSH server?

because you bought it. sitting across the show room floor or one of the other pics on the sales website were other beds that did not have these features. instead, you let the sales person push you into a sale of a product you weren't happy with or you did not pay attention to the product listing. or your spouse bought it. none of these says anything positive about your situation though, so some inner reflecting on why you're such a bad consumer is warranted

Re: How to get root access to your Sleep Number bed

#47
post #15
post #9

Earlier quoted context omitted.

how else would you record and transmit measurements to a server? lower-level hardware and software is expensive to develop on and potentially be difficult to update.

[flagged]

I’m embedded every night for 6 to 8 hours.

Re: How to get root access to your Sleep Number bed

#48

> r: Following this guide will require modifying internal files on your Sleep Number hub. This will void your warranty People, stop spreading this BS. Just like those stickers that say "warranty void if removed" are not legally enforceable, nothing "automatically" invalidates your product's warranty except misuse or poor maintenance. If your Smart Bed stops working, you having poked around in the controller does not…

There's a difference between law on paper and law in practice. If the manufacturer refuses to honor the warranty, there's very little customers can do.

Re: How to get root access to your Sleep Number bed

#49
post #30
post #6

Earlier quoted context omitted.

This was the most interesting point for me, and I assume most of my IOT type shit has this functionality.

some of the newer WiFi setups have an IoT subnet that works like a guest network. Worth using if your gear has it.

For those who know their stuff, setting up a dedicated VLAN for IoT and putting devices in it based on MAC addresses (allow or disallow lists) is a solid option as well and fun to learn.

Re: How to get root access to your Sleep Number bed

#50
post #29

Earlier quoted context omitted.

Shades of Iranian centrifuges.

Really really light shades. Destroying a country's ability to produce weapons grade nuclear fuel vs potentially burning down a hacker's/tinkerer's house; I don't think these are any where near the same level

It's very similar. It's a nation state using exploits to target individuals. It doesn't really matter why they're doing it, they're promulgating an unsafe environment, simply to create convenience for intelligence agencies.

As if they're at a lack of options when it comes to addressing problems on the world stage like this. Stuxnet was both an exceptionally morally lazy and destructive act.

As an American citizen, I genuinely wish my government did NOT do that.

Post reply on HN