I found a backdoor into my bed
251–260 of 403 posts
Re: I found a backdoor into my bed
#252This looks a lot more like the device fetches updates via SSH to a remote update server, and the authorized_keys entry is vestigial.
Re: I found a backdoor into my bed
#253If I'm reading this correctly, the product is just a temperature-controlled mattress? Well, each bed contains a full Linux-based computer. If my estimations above are correct, all of Eight Sleep engineering can take full control of that computer any time they want. I think that was already a given once you agree to silent automatic updates.
Re: I found a backdoor into my bed
#254> For someone who suffers from insomnia this seemed worth a shot. I can relate, having suffered the same for most of my life. One thing that really helped me was a simple white noise machine, typically used to help babies sleep. Good: I sleep great with it. Also, it's not connected to the internet and doesn't require an app. Bad: I basically can't sleep without it. I have to travel with it (camping!). I even purchase…
I used wireless headphones back then. My choice of "white noise" was popcorn in a microwave (because the neighborhood was that noisy)
Re: I found a backdoor into my bed
#255> For someone who suffers from insomnia this seemed worth a shot. I can relate, having suffered the same for most of my life. One thing that really helped me was a simple white noise machine, typically used to help babies sleep. Good: I sleep great with it. Also, it's not connected to the internet and doesn't require an app. Bad: I basically can't sleep without it. I have to travel with it (camping!). I even purchase…
Re: I found a backdoor into my bed
#256Earlier quoted context omitted.
The market deserves some blame here.
My partner has difficulty sleep unless it is the perfect environment (black out curtains, noise cancellation, sound bath, temperature), and is more prone to the effects of a single bad nights sleep. For people like her, $20/mo + $2000 fee is a small price to pay for a solution to a very difficult problem. I would of course, attempt to veto unnecessary IoT devices and subscriptions for usage, but this would be a fight…
https://sleep.me/product/cube-sleep-system
It works rather well, I’m tempted to reverse-engineer the remote control protocol for home automation purposes.
Re: I found a backdoor into my bed
#257Earlier quoted context omitted.
Totally agree. I got a philips hue dimmer switch for next to the bed. One of the best things I got for the home automation. Just click it and everything in the house goes into night mode. no phone needed.
My room mate had one of these and I found out there was a script online someone put together on github I think to control it over a shell. Was hilarious because I kept turning off their light at weird times.
Re: I found a backdoor into my bed
#258> For someone who suffers from insomnia this seemed worth a shot. I can relate, having suffered the same for most of my life. One thing that really helped me was a simple white noise machine, typically used to help babies sleep. Good: I sleep great with it. Also, it's not connected to the internet and doesn't require an app. Bad: I basically can't sleep without it. I have to travel with it (camping!). I even purchase…
Re: I found a backdoor into my bed
#259"When I say backdoor, what am I referring to? Sure, Eight Sleep needs a way to push updates, provide service, and offer support. That’s expected. What goes too far in my opinion, is allowing all of Eight Sleep’s engineers to remotely SSH into every customer’s bed and run arbitrary code that bypasses all forms of formal code review process. And yes, I found evidence that this is exactly what’s happening." ^ wow, this…
I’m the founder and CEO of a company called Memfault, we make observability SaaS for hardware companies.
I constantly get asked if we could just offer a remote access solution. Many of our competitors do! But we think it’s (a) a huge security liability and (b) too ripe for abuse.
But fundamentally consumers do not care, and until that changes you can expect any embedded Linux device to have this kind of backdoor (they do more often than not).
Re: I found a backdoor into my bed
#260Earlier quoted context omitted.
Even if it were a nightstand device rather than a phone. The immediate loss of functionality when loss of signal to the mothership is an egregious design flaw. There's no reason the thing can't have a bit of storage so it can then upload the logged data when the signal returns. Of course, they'll probably claim AI running in the cloud is making the decisions which makes the local first controller not possible.
It’s not a design flaw, they created a hardware loss-leader and then couldn’t come up with any useful services you couldn’t write yourself.
This is profit and more profit.