Live data from Hacker News

I found a backdoor into my bed

trufflesecurity.com

171–180 of 403 posts

Re: I found a backdoor into my bed

#171
post #73

This is a bunch of nonsense, assumption and leaping to conclusions without evidence. "In the second screenshot, we have the public key that’s authorized to access the device. The email address attached to the public key, eng@eightsleep.com, to me suggests the private key is likely accessible to the entire engineering team." He has no evidence for this whatsoever and not really any good reason to assume it either. "In…

> He has no evidence for this whatsoever and not really any good reason to assume it either.

I'm not sure what kind of evidence or reason you're looking for, I think their assumption is pretty sensible.

> This isn't how SSH works

Maybe I'm just naive, but the wording of it to me seems nontechnical enough that I think the author is skipping over things on purpose. For example, how exactly that "far way" host he thinks is involved.

I'd personally imagine it's a reverse shell type deal going on, although why SSH needed to be involved in that I'm not sure. Could be just a hacky implementation. But it's really not that far removed from sensibility, vendors popping reverse shells without authorization really wouldn't be new.

> It is clearly intended to draw traffic to their company website, which is some kind of venture-backed security startup.

Didn't even notice that. Can't imagine too many other people did either. So maybe not so clearly?

Re: I found a backdoor into my bed

#172
post #73

This is a bunch of nonsense, assumption and leaping to conclusions without evidence. "In the second screenshot, we have the public key that’s authorized to access the device. The email address attached to the public key, eng@eightsleep.com, to me suggests the private key is likely accessible to the entire engineering team." He has no evidence for this whatsoever and not really any good reason to assume it either. "In…

> He has no evidence for this whatsoever and not really any good reason to assume it either. I'm not sure what kind of evidence or reason you're looking for, I think their assumption is pretty sensible. > This isn't how SSH works Maybe I'm just naive, but the wording of it to me seems nontechnical enough that I think the author is skipping over things on purpose. For example, how exactly that "far way" host he thinks…

Please see my reply to another person in this same thread. He didn't even verify that the bed is running an SSH server in the first place!

Re: I found a backdoor into my bed

#173

A $20/month bed subscription is objectively hilarious. I cant imagine how this company attracts a non-zero number of clients.

I also wonder what kind of bed costs $2000. Is it a bed made of gold and caviar? This article is confusing.

It's not actually a bed, it's a mattress cover. They are willing to sell you a mattress with it if you want, but the product itself is designed to go over your existing mattress. That said, good-quality beds cost money!

Re: I found a backdoor into my bed

#174
In case anyone is wondering why someone would pay so much to control their bed temp - I have a similar product the "Chillipad". Essentially I'm a furnace when I sleep and wake up covered in sweet. This thing keeping my bed cool was the biggest single thing I've done to improve sleep quality. Its not quite as stupid as Eight Sleep in terms of initial cost and there's no ongoing subscription but it was still expensive. I've also had to open it up and replace a faulty check valve, and it occasionally floods so I have it sitting in a tray. But damn... it works.

However now I want to try this aquarium chiller...

Re: I found a backdoor into my bed

#175
post #138

Earlier quoted context omitted.

*subjectively. Once you realize just how important quality sleep is, and how much this can help, $20/month bed subscription becomes a laughably small price to pay.

How much can this help?

Depends person to person. For me it's the difference between waking up 6-8 times throughout the night, and sleeping for a sound 8 hours without interruption. For my wife, not much difference, other than we are able to sleep together, where as before our wildly different temperature tolerances meant separate rooms. I've seen a few people in this thread state it negatively impacted their sleep.

Re: I found a backdoor into my bed

#176

- They can know when you sleep - They can detect when there are 2 people sleeping in the bed instead of 1 - They can know when it’s night, and no people are in the bed I'm probably naive, but I'm failing to see how any of this is exclusive to having remote SSH access to the bed. Who's to say this isn't already happening with other binaries in the firmware? Maybe they're already phoning home? [...]that bypasses all fo…

It is in fact already sending this data to their servers, because it doubles as a sleep tracker and everything goes through their servers. I really wish there was an option to do local-only connectivity, but very few internet-enabled products these days actually care about supporting a local-only mode, and I suspect the number of products that do would be even smaller if HomeKit didn't mandate it (sadly, temperature-controlled beds are not a HomeKit product category).

Re: I found a backdoor into my bed

#177
post #71

Earlier quoted context omitted.

It drives clicks! I don't understand why someone would buy a bed chiller. But perhaps the US is a unique market.

I’m in the market for one. I want a cool sleep in the summer with fresh air (not recycled AC air). I haven’t found one with good reviews and also no required spyware unfortunately. So AC plus humidifier is needed, but I still sweat on the parts of my body in contact with the mattress no matter how much I crank the AC in the middle of Aug.

What's the difference between recycled air thats been cooled and then blown into your bed and the air from your air conditioner?

Re: I found a backdoor into my bed

#178
post #82

Earlier quoted context omitted.

Are you denying the existence of an authorised ssh key on each of these beds allowing the holder of the key? Are you denying there is a config file pointing to a target called remote-connectivity-api.8slp.net? No there's not enough evidence to prove in a court of law who has access to the private key, or that the config file is enabling a return ssh connection, but it's pretty damning. The only thing that's not newsw…

> Are you denying there is a config file pointing to a target called remote-connectivity-api.8slp.net? Under the path ".ssh.endpoint", too. It's not like it's just a mystery hostname; it clearly has something to do with SSH. > The only thing that's not newsworthy about this is that large amounts of IOT shit does this. And - just to be clear - that doesn't mean it shouldn't be reported on! Talking about this stuff, an…

"I downloaded the firmware and I found an SSH key and a configuration file that mentions an SSH endpoint; therefore, I know that all of Eight Sleep’s engineers are allowed to remotely SSH into every customer’s bed and run arbitrary code!"

Do you not see a problem with this line of reasoning? That's literally what he says in the article, and he presents it as a near-certainty, not the wild leap of unsupported reasoning that it is.

Re: I found a backdoor into my bed

#179
post #166

The state of the product's security wasn't unexpected. I was, however, shocked by this part: > I was willing to overlook: > The bed costs $2,000 > It won’t function if the internet goes down > Basic features are behind an additional $19/mo subscription > The bed’s only controls are via mobile app Nothing about this bed should depend on off-site servers. Nothing about the product should necessitate a subscription fee.…

>The market is clearly too stupid to vote against the rent seeking tech industry. It makes me so sad. It is a $2000 dollar internet connected bed. The market in this case is probably people who could wipe their ass with that $20 every day and not miss it. I don't think they are stupid. This class of Americans has always been about paying for ongoing service instead of being pragmatic or doing things themselves. "Let…

I don't think the people buying the bed are stupid.

The collective mass of people who buy these "IoT" devices that (1) don't actually need to use Internet-hosted services to function, (2) don't actually need a subscription for their business model to work _except_ for having been unnecessarily tied to an Internet-hosted service, and (3) will fail to function when the Internet-hosted service is gone do not understand the ramifications of the buying decisions they're making.

They're enabling these awful companies and business models. They're making the world worse by buying this soon-to-be e-waste garbage.

Stupid is a bad word. Let's say ignorant, instead. They don't even know what they don't even know. Our asinine industry normalizes these practices because profit.

I think computers have tremendous power to make life better for humanity. I think that can happen without being contingent on this kind of business model.

The bed is an egregious example. There are certainly other lower-priced products that still have this kind of stupid unnecessary "tie" to Internet-hosted services and subscriptions.

Re: I found a backdoor into my bed

#180
If I'm reading this correctly, the product is just a temperature-controlled mattress?

Well, each bed contains a full Linux-based computer. If my estimations above are correct, all of Eight Sleep engineering can take full control of that computer any time they want.

I think that was already a given once you agree to silent automatic updates.

Post reply on HN