Live data from Hacker News

How to get root access to your Sleep Number bed

dillan.org

51–60 of 254 posts

Re: How to get root access to your Sleep Number bed

#52
post #30
post #6

Earlier quoted context omitted.

This was the most interesting point for me, and I assume most of my IOT type shit has this functionality.

some of the newer WiFi setups have an IoT subnet that works like a guest network. Worth using if your gear has it.

if my iot bed can talk to my iot camera, that's still not great. better than it talking to my NAS or laptop I suppose though

Re: How to get root access to your Sleep Number bed

#53
post #4

Buried lede: “What I did find was a "convenient" backdoor that Sleep Number can use to SSH back into the hub (and my internal home network as a result).”

Devil's advocate. As someone who has developed a Linux based appliance with over 100k live units across the globe, it seems insane to NOT have access to the thing you're selling and that you have to maintain. If your thing breaks or gets bricked by an update, you will call support and expect them to fix it. You don't want to send in your device or have a support technician come to your house to fix it.

So yes, to the conspiracy theorists it may look like a secret backdoor -- it sorta is. But in many cases I bet it's just a safety net for developers and support to fix things.

I speak for myself and my own experience working for $oldjob. Other companies or countries may of course use this differently. And of course companies get sold and such so you'll never know.

Re: How to get root access to your Sleep Number bed

#54

Earlier quoted context omitted.

Really really light shades. Destroying a country's ability to produce weapons grade nuclear fuel vs potentially burning down a hacker's/tinkerer's house; I don't think these are any where near the same level

It's very similar. It's a nation state using exploits to target individuals. It doesn't really matter why they're doing it, they're promulgating an unsafe environment, simply to create convenience for intelligence agencies. As if they're at a lack of options when it comes to addressing problems on the world stage like this. Stuxnet was both an exceptionally morally lazy and destructive act. As an American citizen, I…

Stuxnet was written to target a very specific bit of equipment for a nefarious purpose. This is just lazy development with no security or as a total after thought or worse deliberate weakening. This is just the state of software development/management we live in now. I really feel one of us have misreading of the situation.

Re: How to get root access to your Sleep Number bed

#56
post #9

Earlier quoted context omitted.

how else would you record and transmit measurements to a server? lower-level hardware and software is expensive to develop on and potentially be difficult to update.

I don't need my bed to transmit measurements to a server . I need my bed to be comfortable to sleep on. I need exactly zero interactions with a server for that. So, yeah, back to the question. Why does my bed have an SSH server? Because it needs to be able to talk to some machine on the internet. And why does my bed need that? It's a bed. [Edit: Wait a minute. Even if I do want to transmit measurements, why is my bed…

If you sleep alone, live in a comfortable climate, and don't have any sleep problems, or back pain problems, I'm happy for you. Your experience isn't universal though and sleep is the most important thing you can do for your body so getting good sleep is paramount. Furthermore, having data on how well you slept is very useful for figuring out your own body. We wear devices to log how many steps we take, a device to log how you sleep is just an extension of that.

Are you even taking care of yourself if you don't have one?

Okay no but seriously, a smart bed that helps you get really good sleep at night so you wake up rested and ready to face the whole world may not be your cup of tea, but that's what they're selling. You could get that without all the technology, but what's the sleep company going to do with the data? Know that you sleep at night? What's the privacy danger in that?

Re: How to get root access to your Sleep Number bed

#58
post #5

Wait, this is about an actual bed -- you know, the kind that you sleep on -- that runs an SSH server on Linux ? W. T. F. !?

There never was a Year of Linux on the Desktop, but there's been a year of linux on the phone, linux on the car, linux on the submarine, linux on the fridge, and so it's no surprise there's a year of linux in the bed.

Anything sufficiently complex (this bed: https://en.wikipedia.org/wiki/Sleep_Number#Sleep_Number_Bed) is going to have a microprocessor, and it makes sense to have an OS that lets you interact with it via a serial console, with Linux being the cheapest and most commonly supported OS in that context.

Re: How to get root access to your Sleep Number bed

#59

Earlier quoted context omitted.

It's very similar. It's a nation state using exploits to target individuals. It doesn't really matter why they're doing it, they're promulgating an unsafe environment, simply to create convenience for intelligence agencies. As if they're at a lack of options when it comes to addressing problems on the world stage like this. Stuxnet was both an exceptionally morally lazy and destructive act. As an American citizen, I…

Stuxnet was written to target a very specific bit of equipment for a nefarious purpose. This is just lazy development with no security or as a total after thought or worse deliberate weakening. This is just the state of software development/management we live in now. I really feel one of us have misreading of the situation.

> Stuxnet was written to target a very specific bit of equipment for a nefarious purpose

Except it didn't do that. It was found in dozens of networks in multiple countries. The vulnerabilities were discovered by other actors and used for other purposes.

The amount of collateral damage done here was far greater than the value of the initial operation. Importantly there were multiple different ways to achieve this particular outcome none of which required us to abuse vulnerabilities or release dangerous software to exploit them.

> This is just the state of software development/management we live in now.

Yes, and I think it's morally backwards, and I regret it.

> I really feel one of us have misreading of the situation.

I simply refuse to accept the intelligence agency marketing view of this action. It was incorrect. There were other less morally conflicted ways to solve this "problem."

Re: How to get root access to your Sleep Number bed

#60

Earlier quoted context omitted.

I don't need my bed to transmit measurements to a server . I need my bed to be comfortable to sleep on. I need exactly zero interactions with a server for that. So, yeah, back to the question. Why does my bed have an SSH server? Because it needs to be able to talk to some machine on the internet. And why does my bed need that? It's a bed. [Edit: Wait a minute. Even if I do want to transmit measurements, why is my bed…

> Why does my bed have an SSH server? because you bought it. sitting across the show room floor or one of the other pics on the sales website were other beds that did not have these features. instead, you let the sales person push you into a sale of a product you weren't happy with or you did not pay attention to the product listing. or your spouse bought it. none of these says anything positive about your situation…

Despite the way I worded my previous post, I didn't buy one of these. Your venom is misdirected.
Post reply on HN