5 ms·
I was just looking into this the other day. Nice to see someone do it. I wonder if making it more hackable by replacing the electronic guts with something like
by pharke 4y ago
I was just looking into this the other day. Nice to see someone do it. I wonder if making it more hackable by replacing the electronic guts with something like a ESP8266 would be worthwhile. I'd much rather be able to have a simple little server on this device that I can talk to over the network rather than having to go through some random company's servers. I imagine connecting it to the motor that turns the feeding mechanism wouldn't be too hard and the screen and buttons could simply be removed to prevent any, ahem, manual tampering. Adding some way to lock the food bin would also help with impulse control for those who need it.
Another upgrade would be to randomly reward the desired behavior instead of always rewarding it. This helps to both prevent gaming the system as well as keeping those dopamine spikes high when you unexpectedly get some candy. Using chocolate as a reward is perfect since it provides tryamine to help replenish your dopamine levels.
- Brybry 4y agoMight be possible to use DNS to point api.petkt.com to a local webserver and rewrite the API? I can't imagine it has that many endpoints or that much logic. I would think the main issue would be potential encryption/authentication but if they're using plaintext HTTP for the phone app then maybe the feeders are using plaintext HTTP too...
- Nextgrid 4y agoIf the device is using HTTPS, you'd need a valid certificate for that hostname - that's exactly the attack HTTPS is designed to defend against. And if they're using certificate pinning, it can't even be any certificate from a trusted authority, it has to be one particular authority or even that specific certificate that they use (they could very well be using an internal CA for this, as they control the other end of the connection).
- KMnO4 4y agoFrom the article: > You'll see that the data for these products is sent in plaintext to and from their servers... No HTTPS... That's just sketchy.
- morganpartee 4y agoI totally thought about that as a last resort, but their API is not well hidden or secured, I'm going to use it until they secure it lol. Randomizing is a great idea, I've got to drop the calories per commit somehow lol
- jonwest 4y agoThat’s what I ended up doing. ESP8266 wired to a motor driver and flashed with ESPHome. It worked really well, though I lost out on the screen on the feeder itself it was a worthy compromise since it was all kept local.