Live data from Hacker News

Hacking my “smart” toothbrush

kuenzi.dev

31–40 of 311 posts

Re: Hacking my “smart” toothbrush

#31

Earlier quoted context omitted.

> Because it's a feature customers ask for? Aren't switches to temporarily bypass emissions controls in cars illegal, despite being a feature customers ask for? > What laws do you want written? I want all e-fuses to be banned, as well as any other means for manufacturers to permanently reduce, restrict, or remove functionality from products after they've been sold. > How "secure" am I allowed to make my product befor…

It's just a toothbrush.

It's not just a toothbrush. A lot of products do this kind of thing. https://hackaday.com/2022/10/26/flashing-booby-trapped-cisco... is another example.

Re: Hacking my “smart” toothbrush

#33

> that the tag is configured to permanently disable all write access after three wrong password attempts Why is this kind of thing legal? For how many politicians and activist groups claim to care about the environment, why hasn't anyone introduced a bill to ban intentionally turning useful equipment into waste? Any legitimate security needs would be fulfilled just as well by doing a full wipe and factory reset inste…

Why is this kind of thing legal? For starters, my experience says that, unlike an HP printer, your toothbrush still works just fine[0] if you ignore anything that tells you to replace the head. [0] At least as fine as a toothbrush with a worn-out head is going to work.

I'm curious but will totally forget to report back in a few months when mine wears out. I'm... not sure, but somewhat confident that it starts to limit the more aggressive brushing modes once its "worn out", although it's possible it was just gummed up internally with toothpaste residue. Last time I changed the head on mine (Philips Sonicare), it definitely felt significantly more powerful with the replacement head.

Re: Hacking my “smart” toothbrush

#34
post #8

Earlier quoted context omitted.

How about when the blue part goes away, as documented? :-) I've used a Sonicare for, what, ten years or more? And I don't think I've ever seen an indication that the NFC is communicating anything to me. That's not to say that it isn't, but if I'm going to ignore something[0] and replace the head when I damned well please, I just ignore the blue part of the bristles. I could probably adjust my behavior to ignore whate…

what is this "as documented" of which you speak? /s toothbrushes come with documentation???

Brush for 2 minutes.

No more, no less.

One is not enough.

Three is too much.

Four is right out.

Re: Hacking my “smart” toothbrush

#35
post #10

Earlier quoted context omitted.

It works happily with a brush head without NFC. That was the first thing I tried with my new toothbrush.

It works /right now/. Revisit this comment in 3-5 years and see if the behavior of new brushes and brush heads has changed for the worse...

locking down heads will hurt what market share philips still has far more than it hurts their consumers. there are alternatives, and even a locked brush is an alternative - it still works, and actively pisses off the user.

people skip brushing their teeth for all sorts of reasons. (yes you do. stop lying. your dentist doesn’t believe you, either.)

people go out of their way to not skip coffee.

Re: Hacking my “smart” toothbrush

#37

Earlier quoted context omitted.

I just change the brush head on the 1st of every month. They say it lasts for 3 months, I must press too hard. So it goes.

The version of the brush I have buzzes at you if you’re brushing too hard.

Mine does too, a light on the bottom lights up as well. I sometimes absentmindedly activate that feature but it's not normal.

Re: Hacking my “smart” toothbrush

#38

Earlier quoted context omitted.

Why is this kind of thing legal? For starters, my experience says that, unlike an HP printer, your toothbrush still works just fine[0] if you ignore anything that tells you to replace the head. [0] At least as fine as a toothbrush with a worn-out head is going to work.

I'm curious but will totally forget to report back in a few months when mine wears out. I'm... not sure, but somewhat confident that it starts to limit the more aggressive brushing modes once its "worn out", although it's possible it was just gummed up internally with toothpaste residue. Last time I changed the head on mine (Philips Sonicare), it definitely felt significantly more powerful with the replacement head.

I think it's just that the bristles are all nicely aligned on a new head - after a while they start splaying, so pressure is going in more directions over a larger area.

I do love the feeling of a fresh sonicare brush.

Re: Hacking my “smart” toothbrush

#39

Earlier quoted context omitted.

I just change the brush head on the 1st of every month. They say it lasts for 3 months, I must press too hard. So it goes.

> I must press too hard a dental hygienist told me to hold it with just the thumb and forefinger. I can't quite manage that, but if you look at how drummers hold their sticks, it's never in a fist. Their arms wouldn't last through one show like that. So if you at least take your little finger off it, the amount of pressure goes down.

> but if you look at how drummers hold their sticks, it's never in a fist

Watch Roy Mayorga.

Re: Hacking my “smart” toothbrush

#40

Earlier quoted context omitted.

Why is this kind of thing legal? For starters, my experience says that, unlike an HP printer, your toothbrush still works just fine[0] if you ignore anything that tells you to replace the head. [0] At least as fine as a toothbrush with a worn-out head is going to work.

I don't really mean about the toothbrush. I mean, why is it legal for NXP to make chips that permanently brick instead of just factory resetting when too many wrong passwords are tried?

I'm inclined to take the common HN position of "trying to lock people out of modifying their own stuff is bad", however there are plenty of situations in which someone who is not the owner might access an NFC tag and try to make it do things the owner does not want it to. Bricking it seems like the nuclear option, but it's not inherently evil to offer the option of NFC tags that are both tamper-resistant and tamper-evident.
Post reply on HN