Live data from Hacker News

Hacking my “smart” toothbrush

kuenzi.dev

231–240 of 311 posts

Re: Hacking my “smart” toothbrush

#231

Earlier quoted context omitted.

Many security applications, situations where you're providing equipment to others and want to make sure it's not modified, etc. It's not that hard to come up with legitimate uses for this. In any case, that sortof doesn't matter. Even if there was no legitimate use for them, that doesn't in and of itself mean they should be illegal. You should at the least demonstrate that their existence is causing great societal ha…

> Many security applications, situations where you're providing equipment to others and want to make sure it's not modified, etc. It's not that hard to come up with legitimate uses for this. Why isn't just making sure the expected private key didn't get wiped a good enough way of making sure it's not modified? > You should at the least demonstrate that their existence is causing great societal harm. Okay, how about t…

> Why isn't just making sure the expected private key didn't get wiped a good enough way of making sure it's not modified?

What's to stop someone from extracting and restoring the private key?

> Okay, how about that it destroys the secondhand CPU market?

Sure, then how about addressing that issue rather than proposing to outlaw an entire mechanism entirely? We have a lot of things that can be misused, but (generally) only in extreme cases do we outlaw the tech itself. More usually, we have laws targeting the misuse of the tech.

Re: Hacking my “smart” toothbrush

#232

Earlier quoted context omitted.

> Many security applications, situations where you're providing equipment to others and want to make sure it's not modified, etc. It's not that hard to come up with legitimate uses for this. Why isn't just making sure the expected private key didn't get wiped a good enough way of making sure it's not modified? > You should at the least demonstrate that their existence is causing great societal harm. Okay, how about t…

> Why isn't just making sure the expected private key didn't get wiped a good enough way of making sure it's not modified? What's to stop someone from extracting and restoring the private key? > Okay, how about that it destroys the secondhand CPU market? Sure, then how about addressing that issue rather than proposing to outlaw an entire mechanism entirely? We have a lot of things that can be misused, but (generally)…

> What's to stop someone from extracting and restoring the private key?

Isn't the whole point of these chips that you can't extract the private key, so that if it gets wiped, it's definitely gone forever?

> Sure, then how about addressing that issue rather than proposing to outlaw an entire mechanism entirely? We have a lot of things that can be misused, but (generally) only in extreme cases do we outlaw the tech itself. More usually, we have laws targeting the misuse of the tech.

But this particular technology doesn't seem to have any legitimate uses.

Re: Hacking my “smart” toothbrush

#233

Earlier quoted context omitted.

As a bachelor who lives alone, it would actually be very motivating if I overheard my appliances making hushed comments about how I "look a little more plump than usual."

only if it is true, but for that they would also need cameras on you at all times.

Just a scale on your smart toilet seat would do.

Re: Hacking my “smart” toothbrush

#234
post #4

Great article, the most interesting part of which is that you can lock your self out of your toothbrush head after three wrong password attempts. I didn't dig into the data sheet for the NFC chip very deeply, but I imagine that it's just the default that the chip ships with. Or maybe Philips really wants that $25 for a new toothbrush head. :-) EDIT: nope, not the default. From the data sheet, last sentence: "To preve…

Next up: 2FA for your toothbrush

Re: Hacking my “smart” toothbrush

#235

Earlier quoted context omitted.

No. I'm pretty sure it is an exaggeration for rhetorical effect. You have to try really hard to put yourself in a situation where the only bathroom scale you can buy is non-connected. OP is either really intellectually lazy on this or is exaggerating to make a point. Maybe if you go to an electronics retailer that also sells appliances like Best Buy, that's all you can find. But I live in a very techy area (San Franc…

I'm just saying that calling someone a liar is a pretty extreme thing, and you should be really certain that they're lying before you do so. I don't see how you can have that level of certainty in this case. Now, saying that they're wrong is much more supportable and doesn't require you to engage in the tricky business of trying to read someone's mind.

Notice I didn't use the word lie or liar, because the traditional definitions require intent to deceive. We rarely have access to each other's true intentions, so I don't think it is a useful term to use in these discussions.

What I believe is that we shouldn't be afraid of calling out people who casually spout easily disproven bullshit to make their argument. Saying you can only call out someone for being wrong doesn't go far enough. OP was arguing the position that there is too much connected tech, so much that in the future we may not even be able to buy a non-connected toothbrush in the future. I'm also IoT-skeptical, as many HNers are. It's a popular position that we don't want a world where IoT is mandatory. But as evidence, they gave an anecdote about shopping for a bathroom scale. I tried to be intellectually charitable to that position and assume good faith, but it didn't hold up without devolving into absurdity.

That's why I didn't say their anecdote was a lie. I can entertain the logical possibility that someone who sincerely does not want to buy a connected household appliance can go shopping for one and have difficulty finding one to buy. But it just doesn't play out, especially for someone who is on a specialist tech forum like HN and has clearly skeptical views on IoT. I said you have to work really hard to put yourself in a position where you can go shopping for such a scale, but face such difficulty that it took "far too long" to find one that is not "demanding I connect it to the Wi-Fi and download a smartphone app."

If you wanted to make a video of yourself not being able to buy a dumb scale, you could go to an tech-heavy electronics retailer that also sells appliances (like Best Buy, Microcenter) or a boutique high-tech gadgets store (like Sharper Image or Brookstone) and only find connected bathroom scales. I just checked what is in stock in a San Francisco Best Buy and the only scale is an IoT connected on. But that would be twisting the truth, because who in their right mind would check only Best Buy in order to buy a dumb scale. it takes a couple minutes on major retailers websites (Target, Walmart, Home Depot) to show that even if you limit to items in stock in tech-heavy places like San Francisco (if there is a place where retailers might assume their customers don't want dumb scales, it's SF), the first and usually cheapest options are dumb scales.

So let's Occam's Razor this. What is more likely? An IoT-skeptical HN poster actually went out to buy a non-connected bathroom scale and genuinely struggled to do so? Or an IoT-skeptical HN poster had to click or sort through a few different options and actually read product descriptions, then exaggerated this anecdote (or totally fabricated it) to advance their position?

But does that even matter? If they aren't a liar, then they are at best intellectually dishonest, and at worst intellectually incompetent. We don't have access to their mind and so can never know which of these three they are. No matter which of these three they are, any of them is a reason to invalidate their argument and call out their anecdote.

Re: Hacking my “smart” toothbrush

#236
post #233

Earlier quoted context omitted.

only if it is true, but for that they would also need cameras on you at all times.

Just a scale on your smart toilet seat would do.

Hm, maybe I'll apply to YC. Except my version also has a sniffer and can detect C. difficile and SARS-CoV-2.

Re: Hacking my “smart” toothbrush

#238
post #220

Earlier quoted context omitted.

I have it as well and at this point used the same head for 5 months. There's no visible deterioration and I exceed the recommended brushing time by doing 5 instead of 3 minutes. Why exactly is the head only good for 3 months?

You probably don't brush correctly: you need to apply sufficient pressure on your teeth so the bristles can scrub the enamel well enough. Or else there is no way your head has no visible deterioration after 5 months at 5 min per brushing.

The toothbrush has an integrated pressure sensor and starts vibrating when you apply too much

Re: Hacking my “smart” toothbrush

#239

Earlier quoted context omitted.

> Why isn't just making sure the expected private key didn't get wiped a good enough way of making sure it's not modified? What's to stop someone from extracting and restoring the private key? > Okay, how about that it destroys the secondhand CPU market? Sure, then how about addressing that issue rather than proposing to outlaw an entire mechanism entirely? We have a lot of things that can be misused, but (generally)…

> What's to stop someone from extracting and restoring the private key? Isn't the whole point of these chips that you can't extract the private key, so that if it gets wiped, it's definitely gone forever? > Sure, then how about addressing that issue rather than proposing to outlaw an entire mechanism entirely? We have a lot of things that can be misused, but (generally) only in extreme cases do we outlaw the tech its…

> Isn't the whole point of these chips that you can't extract the private key, so that if it gets wiped, it's definitely gone forever?

I don't think these chips include TPM. But if that's the case, wouldn't you object to that on the same grounds that you object to efuses?

> But this particular technology doesn't seem to have any legitimate uses.

Myself and at least one other commenter has mentioned a few legitimate uses.

Re: Hacking my “smart” toothbrush

#240

Earlier quoted context omitted.

Why should it not be legal to make such chips?

Because they take control away from the actual owners of devices, and they, unnecessarily contribute to e-waste, for no increase in real security.

> they take control away from the actual owners of devices

Only if they're used that way. They don't take control away from the actual owners of the devices if its the owners who put them in there, for instance. Again, I think you're conflating the existence of a mechanism with the abuse of the mechanism. If you were just railing against the abusive uses, I'd be behind you 100%.

I just don't see why we should outlaw a common and useful mechanism entirely, rather than outlaw certain uses of that mechanism.

Post reply on HN