news.volyx.in

My smart sleep mask broadcasts users' brainwaves to an open MQTT broker (aimilios.bearblog.dev)

620 points by minimalthinker · 156 days ago · 260 comments on HN

Article summary

A user purchased a smart sleep mask from a Kickstarter campaign and, with the help of a tool called Claude, reverse-engineered the device's Bluetooth protocol and app, discovering that it broadcasts users' brainwaves to an open MQTT broker. The device's app uses hardcoded credentials, allowing anyone to access and control the device. The user was able to read brainwaves from other users and potentially send them electric impulses. The company has been informed of the issue.

Main themes

  • Smart device security
  • Reverse engineering
  • IoT vulnerabilities
  • Data privacy
  • Kickstarter product quality

What commenters say

  • The company should be named and shamed for their security oversight to prompt them to fix the issue and warn other users.
  • Disclosing the company's name could lead to black hats exploiting the vulnerability before a fix is implemented, putting users at risk.
  • The device's ability to send remote electrical impulses is a more significant concern than the sleep data itself.
  • The use of hardcoded credentials and lack of security measures is a common problem in IoT devices, particularly those from small companies or Kickstarter projects.
  • Some argue that naming the company would not be effective in prompting change and could lead to unnecessary harm to the company's reputation.
  • Others believe that the company's responsiveness to the disclosure and commitment to fixing the issue is a positive step, but more transparency is needed.
  • There is a debate about the balance between responsible disclosure and the potential consequences of revealing vulnerabilities in consumer devices.
  • The incident highlights the importance of prioritizing security and data privacy in the development of smart devices and IoT products.