2 ms·
If you are referring to the smart lights, if I recall correctly they used a side-channel attack to extract the keys used to decrypt/verify new firmwares in vari
by kenoph 10y ago
If you are referring to the smart lights, if I recall correctly they used a side-channel attack to extract the keys used to decrypt/verify new firmwares in various models. So they basically abused OTA firmware updates to take control of the lights.
Assuming that devices don't have cryptographic issues, IoT security is still a mess. So yes firmwares are probably full of BO vulnerabilities. As for more recent techniques, I'm aware of some of them but I'm no expert so I can't comment properly :)