4 ms·
I think I'm missing a few major points. I wonder if someone here might be able to clarify. 1. The real meat of this "pwning" was (it seems) a google search to
by mixedmath 6y ago
I think I'm missing a few major points. I wonder if someone here might be able to clarify.
1. The real meat of this "pwning" was (it seems) a google search to identify the WEB API endpoint. Then it turns out that sending POST requests to this endpoint can turn the light on/off, change its temperature, and change its brightness.
2. In order to turn a light on/off using the "found" api, it is first necessary to connect to the lamp's network. So if I were doing this on my own linux machine, which cannot as far as I can tell connect to multiple wireless networks at the same time, my script to change the settings on the light would include disconnecting from my true wifi network, connecting to the lamp's network, sending the signal to the lamp, disconnecting from the lamp, and then reconnecting to my own network. Is that right? Is this what the bash scripts and apps mentioned in the post are doing?
3. If I lived in the apartment above the OP's (say), and I were malicious, I could even now also access the lamps' networks and, say, set their values to be whatever I wanted. And there is simply no way of stopping this (S in IoT, after all).
- Spivak 6y agoYeah this is so far from pwning that it’s hilarious to be presented as such. This is literally authorized access. He built an integration for his smart bulbs the same way Google Home or HomeKit would access it but with some weird Wi-Fi paranoia that actually made him less secure. The security model of pretty much all smart lighting "if you can reach me on the network you're trusted" just like the security of light switches "if you can reach the switch you can flip it."
- spongechameleon 6y agoI mean the alternative was installing the propietary app so I would say this is still a big win. But also yes, any wifi capable device in your home with no authorization is clearly a disaster waiting to happen.
- Spivak 6y agoI don't disagree that it's a huge improvement over some proprietary app but I still don't think "using the light's API as designed" counts as pwning it. It's the same API that openHAB or Home Assistant would consume to control it.
- shp0ngle 6y agoYeah this article is mostly ranting disguised as something more
- adolph 6y agoI thought it was mostly sales for "for PureOS and the Librem 5" on "my Librem 5 phone as well as Librem Mini desktop" to do something an alias to curl performs perfectly fine.
- porbelm 6y agoThis is pretty much how I read it, but I thought maybe it's worse: I would bet that when you connect to the lamp's network and set it up to connect to your network as you should the lamp's internal WiFi ceases to broadcast, and you'd need the reset switch to enable setup again. What this guy seems to have found out is possibly (and how, I don't know--the article is horribly lacking in detail) that the lamp accepts API calls /when it is in hotspot mode for setup/ as well as in HAZ_EXT_CONNECSHUN=1 mode So what I think is that /anyone/ close to the lamp can send the API calls and affect it. Because the lamp is in perpetual setup mode with its unsecured hotspot active... "A browser hitting that returned a page to connect the lamp to local WiFi. That is a no-go, so maybe there is a web API…" he said the dumbass e: Sorry, I misread your post on the lamp network part. I'll leave this here but now you know I spotted it. My apologies.
- sdlion 6y agoOne way to solve 3 and maybe 2 would be adding to the ecuation an ESP32/8266 and use it as an access point for the lamps. Then you might create any physical controls for the lamps or with some network magic add it to your infrastructure through a segmented network. I'm not sure if this can be done with an ESP alone (hence "network magic") or you could just use a second ESP connected to your private network and passthrough your commands via a serial port to the Lamp's ESP AP. ESP32's are fairly cheap, easy to use and can even be programmed through micropython.