news.volyx.in

I found a backdoor into my bed (trufflesecurity.com)

980 points by riverdroid · 528 days ago · 385 comments on HN

Article summary

The author discovered a backdoor in their Eight Sleep bed, allowing the company's engineers to remotely access and control the device. The bed's firmware can be downloaded, and the author found evidence of a live AWS key and a public key that could grant access to the device. The author argues that this level of access is a security liability and a potential invasion of privacy. They opted to replace the bed's temperature control system with an aquarium chiller to avoid these issues.

Main themes

  • IoT security
  • Data privacy
  • Smart home devices
  • Subscription-based models
  • Hardware security risks

What commenters say

  • The presence of a backdoor in the Eight Sleep bed is a significant security risk that could allow unauthorized access to the device and potentially other devices on the same network.
  • The need for a subscription and internet connection to use the bed's features is unnecessary and a potential point of failure.
  • Some commenters argue that the benefits of the bed's smart features, such as improved sleep quality, outweigh the potential security risks and costs.
  • Others believe that the market is to blame for the proliferation of insecure IoT devices, while some argue that engineers and companies have a responsibility to prioritize security and privacy.
  • The use of a remote access solution for customer support and updates is seen as a huge security liability and ripe for abuse by some, while others see it as a necessary feature.
  • There are alternative solutions, such as using an aquarium chiller, that can provide similar functionality without the security risks and costs associated with the Eight Sleep bed.