4 ms·
Tuya is so hilarious in this regard. The protocol is just TLS over TCP, but the app happily sprays your Wi-Fi password to every STA in the area every time you a
by exikyut 3y ago
Tuya is so hilarious in this regard. The protocol is just TLS over TCP, but the app happily sprays your Wi-Fi password to every STA in the area every time you add a new device.
(It's how pairing is done - the app blindly broadcasts packets to 255.255.255.255 and the target device (lightbulb, power outlet, et al) just sits in promiscuous mode. The packet contents are protected by WPA2 et al, but the packet lengths aren't, so the protocol sends a bajillion tiny packets with each packet's length set to the ASCII byte value of the next character in the setup handshake. I believe it sends it multiple times in a row. This is why pairing takes 2 minutes then always abruptly stops before the counter reaches zero.)
\o/
- londons_explore 3y agoVery clever. IoT pairing is a tricky problem because phone/laptop devices give a very limited API for communicating with a new WiFi device that isn't yet on your WiFi network.
- iforgotpassword 3y agoI've seen an iot app do it via multicast - the destination MAC isn't encrypted in the wifi frames, and the last one or two bytes of them are controlled by the sending app. I figured this out when I tried to debug why the pairing didn't work from my phone, but did from an old Samsung A2: the iot device only had a 2.4ghz module, my new phone was on 5ghz...
- treyd 3y agoIsn't this was bluetooth was supposed to be able to help with?
- exikyut 3y agoI suspect Tuya wants a solution that lets them implement a solution stack for Wi-Fi+BT and Wi-Fi-only MCUs alike. :/
- blincoln 3y agoAll of the decent WiFi-only IoT devices I've seen bootstrap the process by acting as an access point of their own until they're configured. There are some opportunities for securing that initial connection better, like ensuring that the WPA2 key for the temporary AP mode is complex and unique to each device, but I haven't come across a fundamental flaw in the approach. Are you aware of any? I'd prefer an out-of-band option, like "physically connect the new device to the IoT hub's 'new device' port to configure it automatically before moving it to its permanent location", or "scan the QR code on the new device, which contains a public key that the IoT hub will use to broadcast the WiFi credentials over RF", but I understand that at least for mass-market residential products, that's unlikely because it generally involves more components on each device.
- LocalH 3y agoThat sounds extremely greasy