5 ms·
This article is strange & many details are lacking. All the big smart toothbrushes use BLE and are not WiFi-connected. Tried to fact-check the article, but noth
by tjasko 3y ago
This article is strange & many details are lacking. All the big smart toothbrushes use BLE and are not WiFi-connected. Tried to fact-check the article, but nothing.
A bunch of BLE chips are also WiFi capable, so not ruling out that someone compromised the firmware to enable WiFi functionality, but I wonder how they were able to connect to WiFi to trigger a botnet in the first place.
Quite skeptical of this article, while the premise of the danger of IoT devices still remains, nonetheless.
- a321neo 3y ago>A bunch of BLE chips are also WiFi capable, so not ruling out that someone compromised the firmware to enable WiFi functionality The ESP32 is now used as a general-purposed chip even in applications where an 8-bit MCU would have been enough. A remotely exploitable vulnerability in the ESP32/SDK could have large-scale consequences.
- deleted 3y ago[deleted]
- exe34 3y agoLeaves open the question of how they joined the network - WiFi passwords and such. Maybe stolen from the phones/laptops and then sent to the device as part of the exploit?
- graypegg 3y agoI could imagine there’s a lot of toothbrushes near unsecured wifi hotspots. (Hotels, in backpacks of travellers in a cafe, a demo unit in a store) Could be as simple as polling continuously till one allows the device to phone home. This does seem to be a debunked story though.
- deleted 3y ago[deleted]
- greggsy 3y agoThe only way to load firmware to consumer esp platforms is usually via mobile apps… so, someone with privileged access to consumer’s apps, or the supply chain, used that access to load bespoke firmware to toothbrushes.. highly doubtful.
- Cpoll 3y ago> but I wonder how they were able to connect to WiFi to trigger a botnet in the first place. Wardriving for oral health?
- depereo 3y agoIt's not something that actually happened. It's just some bullshit that's gone viral. https://cyberplace.social/@GossiTheDog/111886558855943676 https://cyberplace.social/@GossiTheDog/111886558855943676
- tgsovlerkhgsel 3y agoThat toot references https://archive.is/2024.01.30-203406/https://www.luzernerzeitung.ch/wirtschaft/kriminalitaet-die-zahnbuersten-greifen-an-das-sind-die-aktuellen-cybergefahren-und-so-koennen-sie-sich-schuetzen-ld.2569480#selection-687.280-687.372 https://archive.is/2024.01.30-203406/https://www.luzernerzei... which attributes the story to Stefan Züger from the Swiss branch of Fortinet and claims it to be an actual event. I don't see a mention of "NoName Ddosia".
- rakslice_ 3y agoRe "Noname Ddosia": It's from the context, if you know your recent infosec history: "Jüngst wurden damit auch Server von Schweizer Regierungsstellen während des Weltwirtschaftsforums angegriffen – als Retourkutsche für die Teilnahme des ukrainischen Präsidenten Wolodimir Selenski. Eine russlandnahe Gruppierung bekannte sich zum Angriff." (translation: "Servers of Swiss government offices were recently attacked during the World Economic Forum - as a retaliation for the participation of Ukrainian President Volodymyr Zelensky. A group close to Russia claimed responsibility for the attack.") Background: https://www.ncsc.admin.ch/ncsc/en/home/aktuell/im-fokus/2023/ddos.html https://www.ncsc.admin.ch/ncsc/en/home/aktuell/im-fokus/2023... But it's not clear to me that's right, isn't WEF in the summer? Ah, they've been ongoing, here's the earlier one: https://www.ncsc.admin.ch/ncsc/en/home/aktuell/im-fokus/2023/ddos.html https://www.ncsc.admin.ch/ncsc/en/home/aktuell/im-fokus/2023...
- tschoesi 3y agoWEF is in winter
- fiprisoner 3y ago
- smashed 3y agoI tried to fact check it also. They talk about a "java-based" os that could have been the cause. I know java me was a thing and there are micro jvm that can run on microcontrollers but still, it does not add up. I think a DDoS attack happened (happens all the time) and security "experts" mentioned that these things could come from anywhere, even toothbrush, and the details got lost in translation / used for click bait.