Live data from Hacker News

Hacking my “smart” toothbrush

kuenzi.dev

21–30 of 311 posts

Re: Hacking my “smart” toothbrush

#21

I'm curious to see, but I don't think the algorithm for calculating the password from the identifier would be very sophisticated. Assuming they didn't want to add costs to prevent easy retrieval of any secret key from the device, a complex algorithm would be kind of a waste.

I mean, even something as simple as `md5("very-long-secret-only-phillips-knows" + uid)[:4]` would be effectively unguessable. Not hard if you have the code for the firmware, but nigh-impossible otherwise.

Re: Hacking my “smart” toothbrush

#22
post #8

I have one, but it never occurred to me to want to hack it. "But how do you know when it's time to change the brush?" Well, how about when it starts getting soft?

How about when the blue part goes away, as documented? :-) I've used a Sonicare for, what, ten years or more? And I don't think I've ever seen an indication that the NFC is communicating anything to me. That's not to say that it isn't, but if I'm going to ignore something[0] and replace the head when I damned well please, I just ignore the blue part of the bristles. I could probably adjust my behavior to ignore whate…

Probably depends on which body you are using. In mine it both flashes a tiny LED and does an extra little buzz-buzz buzz-buzz signal with the ultrasonics when you turn it on (or off, can't recall which) when the head has 'expired'. Continues to work fine, though.

You might be interested in this YouTube video from Applied Science with electron micrographs of 'new' and 'worn' toothbrush bristles - there is a very marked invisible change that happens: https://www.youtube.com/watch?v=cwN983PnJoA

Re: Hacking my “smart” toothbrush

#23

Earlier quoted context omitted.

Why is this kind of thing legal? For starters, my experience says that, unlike an HP printer, your toothbrush still works just fine[0] if you ignore anything that tells you to replace the head. [0] At least as fine as a toothbrush with a worn-out head is going to work.

I don't really mean about the toothbrush. I mean, why is it legal for NXP to make chips that permanently brick instead of just factory resetting when too many wrong passwords are tried?

Because it's a feature customers ask for? What laws do you want written? How "secure" am I allowed to make my product before the Feds come a-knockin'?

And what does a "factory reset" accomplish? The hacker trying to get company IP (or whatever the password is protecting) gets three more attempts at it after the reset?

Finally, and I'm not saying this makes it okay, but e-fuses are common as dirt these days. I don't know that you're going to get that toothpaste back in the tube.

Re: Hacking my “smart” toothbrush

#24
Now that the industrial design and manufacturing are figured out, Philips could do a number of additional things with NFC. (Especially with network access, possibly through an app, and more securely with a different NXP chip.)

Re: Hacking my “smart” toothbrush

#25
post #8

Earlier quoted context omitted.

How about when the blue part goes away, as documented? :-) I've used a Sonicare for, what, ten years or more? And I don't think I've ever seen an indication that the NFC is communicating anything to me. That's not to say that it isn't, but if I'm going to ignore something[0] and replace the head when I damned well please, I just ignore the blue part of the bristles. I could probably adjust my behavior to ignore whate…

I just change the brush head on the 1st of every month. They say it lasts for 3 months, I must press too hard. So it goes.

> I must press too hard

a dental hygienist told me to hold it with just the thumb and forefinger.

I can't quite manage that, but if you look at how drummers hold their sticks, it's never in a fist. Their arms wouldn't last through one show like that.

So if you at least take your little finger off it, the amount of pressure goes down.

Re: Hacking my “smart” toothbrush

#26

Earlier quoted context omitted.

I don't really mean about the toothbrush. I mean, why is it legal for NXP to make chips that permanently brick instead of just factory resetting when too many wrong passwords are tried?

Because it's a feature customers ask for? What laws do you want written? How "secure" am I allowed to make my product before the Feds come a-knockin'? And what does a "factory reset" accomplish? The hacker trying to get company IP (or whatever the password is protecting) gets three more attempts at it after the reset? Finally, and I'm not saying this makes it okay, but e-fuses are common as dirt these days. I don't k…

> Because it's a feature customers ask for?

Aren't switches to temporarily bypass emissions controls in cars illegal, despite being a feature customers ask for?

> What laws do you want written?

I want all e-fuses to be banned, as well as any other means for manufacturers to permanently reduce, restrict, or remove functionality from products after they've been sold.

> How "secure" am I allowed to make my product before the Feds come a-knockin'?

If the one you're trying to make it "secure" against is the product's owner, then I'd say "not at all" would be a fine answer.

> And what does a "factory reset" accomplish? The hacker trying to get company IP (or whatever the password is protecting) gets three more attempts at it after the reset?

The point is that the factory reset would delete the company IP.

> Finally, and I'm not saying this makes it okay, but e-fuses are common as dirt these days. I don't know that you're going to get that toothpaste back in the tube.

Wasn't asbestos also as common as dirt before it was banned?

Re: Hacking my “smart” toothbrush

#27

Earlier quoted context omitted.

I just change the brush head on the 1st of every month. They say it lasts for 3 months, I must press too hard. So it goes.

...I must press too hard Could be. My wife presses so hard, I hear the motor bog down. "JFC, honey, let up a bit", to no avail. She's constantly replacing her heads. I literally can't remember the last time I popped a new one on mine. I could easily believe it's been six months (and, yeah, it's about due).

That’s probably really bad for your wife’s teeth.

Re: Hacking my “smart” toothbrush

#28
post #8

Earlier quoted context omitted.

How about when the blue part goes away, as documented? :-) I've used a Sonicare for, what, ten years or more? And I don't think I've ever seen an indication that the NFC is communicating anything to me. That's not to say that it isn't, but if I'm going to ignore something[0] and replace the head when I damned well please, I just ignore the blue part of the bristles. I could probably adjust my behavior to ignore whate…

I just change the brush head on the 1st of every month. They say it lasts for 3 months, I must press too hard. So it goes.

The version of the brush I have buzzes at you if you’re brushing too hard.

Re: Hacking my “smart” toothbrush

#29

Earlier quoted context omitted.

Because it's a feature customers ask for? What laws do you want written? How "secure" am I allowed to make my product before the Feds come a-knockin'? And what does a "factory reset" accomplish? The hacker trying to get company IP (or whatever the password is protecting) gets three more attempts at it after the reset? Finally, and I'm not saying this makes it okay, but e-fuses are common as dirt these days. I don't k…

> Because it's a feature customers ask for? Aren't switches to temporarily bypass emissions controls in cars illegal, despite being a feature customers ask for? > What laws do you want written? I want all e-fuses to be banned, as well as any other means for manufacturers to permanently reduce, restrict, or remove functionality from products after they've been sold. > How "secure" am I allowed to make my product befor…

It's just a toothbrush.

Re: Hacking my “smart” toothbrush

#30
post #11

Kind of concerning this could turn into another toner ink situation

That's exactly why they did this. They can lock out 3rd party vendors and also force you to buy new heads at an interval of their choosing all in the name of "ensuring quality".

Keurig did the same thing with their later models. The coffee I used (SF Bay pods) just shipped a widget that tricks the Keurig into accepting the pod. I drink cold brew now, but I wonder if that cat & mouse is still happening.
Post reply on HN