Hacker News new | ask | show | jobs
by userbinator 2856 days ago
Also this:

Moreover, the adversary needs to plant malware that encodes private data from the target device and sends it to the smart light bulbs.

...if you can already install/run code of your choice, why not just send the data out over the network and into the Internet?

3 comments

Maybe there is a firewall? Lots of people put smart bulbs on their own subnet that is cut off from the internet.
Honestly, that doesn't strike me as something lots of people know how to do, nor take the effort to.
Five people tops. Maybe six.
O HAI, other four people, maybe five.

I'd never have thought that I'd need to put my audio speakers and bathroom scale behind a firewall would be a thing, but it's 2018 and here we are.

I threw my smart lightbulbs out entirely.

> I threw my smart lightbulbs out entirely.

Smart move. Perhaps I'm becoming a dinosaur (at the tender age of 34 no less!) but I genuinely never saw the appeal of these things.

I’m in an early ‘60s model house where the electrical circuit demands were way less than they are today. When the house was flipped, the living area had 4 incadessant can lights added to the existing fan/light combo. All of that is on a single switch. So for me to have the fan on, it reuired the 4 heat generating can lights to be on at 100%. It was much cheaper to add 4 LED smart lights to the cans than to completely rewire the circuit to have multiple switch legs. That was the appeal to me that pushed me over the wdge to buy them. Plus, now I have energy saving bulbs, I havent had to replace a bulb since, and now they are dimmable which is a bigger deal now than I would have thought prior to having them.

I dont try to turn the lights on remotely or any of those features. I have taken steps to prevent them from being online. I know this works because the app is constantly reminding me that it cant check for updates.

In in an apartment where I can't install hardwired dimmers, so lightbulbs are the only way I can have my lighting at all adjustable. Color is a bonus.
Uploading data to a server leaves a trail. Theoretically there are allegedly untraceable servers leased in the underground but they're quite expensive and you never know who's actually running them. In this scenario the risk is limited.
Don’t smart bulbs have the ability to connect to and broadcast to arbitrary networks?