12 ms·
My smart sleep mask broadcasts users' brainwaves to an open MQTT broker
- deleted 7mo ago[deleted]
- yeetosaurusrex 7mo agoCodex would have refused to do any of this. For your "safety".
- williamsss 7mo agoThis weekend I was trying to figure out how I can use my smart meter’s electricity data. I had a poke around MQTT explorer and realized I could see personal data points out in the open without encryption across a plethora of devices.
- fy20 7mo agoThe local way is to use the P1 port . It's originally a Dutch thing, but most smart meters across Europe have it: https://www.tinytronics.nl/en/home-automation/sensors/energy/universal-p1-port-dongle-esp32-s3 https://www.tinytronics.nl/en/home-automation/sensors/energy...
- mnemotronic 7mo agoPardon the dumb question. How do you get Claude to run locally? And control hardware? The Claude I use at work is only accessible via web page and runs on an Nvidia DGX H200.
- ac29 7mo agoClaude Code presumably, or another agent
- morkalork 7mo ago>Since every device shares the same credentials and the same broker, if you can read someone's brainwaves you can also send them electric impulses. Amazing.
- baby_souffle 7mo agoWell that’s a brand new sentence.
- amelius 7mo agoBut not a beautiful sentence.
- bryanrasmussen 7mo agohuh, not sure if life imitates snark and bull https://medium.com/luminasticity/great-products-of-illuminati-ganga-8f1698c06a53 https://medium.com/luminasticity/great-products-of-illuminat... "The ZZZ mask is an intelligent sleep mask — it allows you to sleep less while sleeping deeper. That’s the premise — but really it is a paradigm breaking computer that allows full automation and control over the sleep process, including access to dreamtime." or if this is another scifi variation of the same theme, with some dev like embellishments.
- mrguyorama 7mo agoThat is the premise of HypnoSpace Outlaw, a neat game about 90s internet nostalgia and scifi.
- roywiggins 7mo agocyberpunk
- intellirim 7mo ago[dead]
- plagiarist 7mo agoIt is a governance failure. It is also technically a user failure to have purchased a connected device in the first place. Does the device require a closed-source proprietary app? Closed-source non-replaceable OS? Do not buy it.
- brabel 7mo agoVery few options available, if any, if you actually do that. The IoT market is unfortunately small and dominated by vendors that don’t want at all an open ecosystem. That would hinder their ability to force you to pay for a subscription which is where all the money is.
- jmb99 7mo agoYes, that’s right, don’t buy any new car, any phone, any television. Hell don’t buy any x86 laptop or desktop computer, since you can’t disable out replace Intel ME/etc.
- ai-x 7mo agoThere should be two separate lines of products. One in which privacy is priority and adheres to government regulations (around privacy) and probably costs 2x and one with zero government intervention (around privacy) which costs less and time-to-market is faster. I don't want a few irrationally paranoid people bottlenecking progress and access to the latest technology and innovation. I'm happy to broadcast my brainwaves on an open YouTube channel for the ZERO people who are interested in it.
- selkin 7mo agootoh: the non regulated should cost more. It’s kinda like “qualified investors” - you want to make sure people who are wiling to do something extremely stupid can afford it and acknowledge their stupidity. We don’t need regulation to protect those that can afford to buy protection: we need it for those who can’t.
- mystraline 7mo ago> For obvious reasons, I am not naming the product/company here, but have reached out to inform them about the issue. Coward. The only way to challenge this garbage is "Name and Shame". Light a fire under their asses. That fire can encourage them to do right, and as a warning to all other companies. My guess is this is Luuna https://www.kickstarter.com/projects/flowtimebraintag/luuna https://www.kickstarter.com/projects/flowtimebraintag/luuna
- everdrive 7mo agoEven if naming and shaming doesn't work, I sure want to know so I can always avoid them for myself and my family. Thanks for the call-out and the educated guess.
- deleted 7mo ago[deleted]
- deleted 7mo ago[deleted]
- a4isms 7mo agoDoesn't disclosing this to the world at the same time as you disclose it to the company immediately send hundreds of black hats to their terminals to see how much chaos they can create before the company implements a fix? Perhaps the author is not a coward, but is giving the company time to respond and commit to a fix for the benefit of other owners who could suffer harm.
- mystraline 7mo agoIt took me 30 seconds with ChatGPT by saying: Identify the kickstarter product talked around in this blog post: (link) To think some blackhat hasn't already did that is frankly laughable. What I did was like the lowest of low-bars these days.
- Barbing 7mo agoPut the product name in the title & maybe it sends thousands instead of hundreds of blackhats… We often treat doxxing the same way, prohibiting posting of easily discovered information.
- basedrum 7mo agoName the company, hiding it is irresponsible
- brabel 7mo agoIt’s probably safe to assume they are all like that.
- Jolter 7mo agoAuthor doesn’t spell out why they are not naming them, but my guess is they are trying to not promote the product to malicious actors who would be interested in the sleep data of others. I guess that’s not a huge problem, though, since all users are presumably at least anonymous.
- bstsb 7mo agoless sleep data, i imagine, and more the whole “send remote electrical impulses” thing
- dnw 7mo agoI would love to see the prompt history. Always curious how much human intervention/guidance is necessary for this type of work because when I read the article I come away thinking I prompt Claude and it comes out with all these results. For example, "So Claude went after the app instead. Grabbed the Android APK, decompiled it with jadx." All by itself or the author had to suggest and fiddle with bits?
- minimalthinker 7mo agoVery little intervention tbh. I will try to retrieve it and post.
- selkin 7mo agoBy default, Claude code keeps session history (as jsonl files in ~/.claude). It’s wasteful not to save and learn from those.
- dnw 7mo agoCheck this out: https://github.com/kulesh/catsyphon https://github.com/kulesh/catsyphon
- dnw 7mo agoThat's great to hear. I'd be interested to see the session. Yes, Claude Code keeps sessions in ~/.claude/projects/ by default. Thank you!
- minimalthinker 7mo agohere you go: https://gist.github.com/aimihat/a206289b356cac88e2810654adf06a55 https://gist.github.com/aimihat/a206289b356cac88e2810654adf0...
- cyanydeez 7mo agoReally is a derth of livestreams demostrating these things. Youd think if thetes so much Unaided AI work people would stream it.
- Aurornis 7mo agoKickstarter is full of projects like this where every possible shortcut is taken to get to market. I’ve had some good success with a few Kickstarter projects but I’ve been very selective about which projects I support. More often than not I can identify when a team is in over their heads or think they’re just going to figure out the details later, after the money arrives. For a period of time it was popular for the industrial designers I knew to try to launch their own Kickstarters. Their belief was that engineering was a commodity that they could hire out to the lowest bidder after they got the money. The product design and marketing (their specialty) was the real value. All of their projects either failed or cost them more money than they brought in because engineering was harder than they thought. I think we’re in for another round of this now that LLMs give the impression that the software and firmware parts are basically free. All of those project ideas people had previously that were shelved because software is hard are getting another look from people who think they’re just going to prompt Claude until the product looks like it works.
- lr4444lr 7mo agoAt this point, I trust LLMs to come up with something more secure than the cheapest engineering firm for hire.
- minimalthinker 7mo agothis.
- lukan 7mo agoAnd the cheapest engineering firm won't use LLMs as well, wherever possible?
- fc417fc802 7mo agoThe cheapest engineering firm will turn out to be headed up by an openclaw instance.
- TheRealPomax 7mo agofun fact, LLMs come in cheapest and useless and expensive but actually does what's being asked, too. So, will they? Probably. Can you trust the kind of LLM that you would use to do a better job than the cheapest firm? Absolutely.
- SubiculumCode 7mo agoHow about complaining that brain waves get sent to a server? I'm a neuroscientist, so I'm not going to say that the EEG data is mind reading or anything, but as a precedent, non privacy of brain data is very bad.
- minimalthinker 7mo agoI would presume data privacy laws already have good precedent for health data?
- baby_souffle 7mo ago> I would presume data privacy laws already have good precedent for health data? Google for a list of all the exceptions to HIPPA. There are a lot of things that _seem_ like they should be covered by HIPPA but are not...
- minimalthinker 7mo agoInteresting...
- freedomben 7mo agoOnly for "covered entities" under HIPAA (at least in the US)
- amarant 7mo agoHow useful could something like this be for research? I'm not a neuroscientist so I have no clue, but it seems like the only justification I can think of..
- AnimalMuppet 7mo agoIf they're taking patient data for research without permission, they are not ethical researchers.
- 7mo ago
- bobim 7mo agoWon't they sue for the reverse engineering?
- speedgoose 7mo agoRemember that the S in IoT stands for Security. I have deployed open MQTT to the world for quick prototypes on non personal (and healthcare) data. Once my cloud provider told me to stop because they didn’t like it, that could be used for relay DDOS attacks. I would not trust the sleep mask company even if they somehow manage to have some authentication and authorisation on their MQTT.
- n4bz0r 7mo agoI don't think there is an S in IoT?..
- BenjiWiebe 7mo agoRight - the saying indicates that IoT stuff is well known for ignoring security.
- n4bz0r 7mo agoWent right over my head :)
- rationalist 7mo agoWhere I work, the saying is, "The H in ABC stands for Happiness." (Also, "We're not happy until you're not happy.")
- Terr_ 7mo agoIt does work a lot better with verbal inflection.
- BenjiWiebe 7mo agoIt did get me thinking - maybe there should be IoTS devices, where the S stands for Security. A commitment to updates for a certain amount of time, the source code in escrow to be released when updates/support ceases, probably other things I'm not thinking of.
- throw876987696 7mo agoWithout a brand name, how can we verify this is real?
- ohyoutravel 7mo agoWithout any skin in the game with your username, why should we take anything you say seriously?
- edgarvaldes 7mo agoInteresting position in a thread about the dangers of exposing yourself to the internet.
- digiown 7mo agoAs an aside, it seems cool that the bar to reverse engineering has lowered from all the LLMs. Maybe we'll get to take full control of many of these "smart" devices that require proprietary/spyware apps and use them in a fully private way. There's no excuse that any such apps solely to interact with devices locally need to connect to the internet, like dishwasher. https://www.jeffgeerling.com/blog/2025/i-wont-connect-my-dishwasher-your-stupid-cloud/ https://www.jeffgeerling.com/blog/2025/i-wont-connect-my-dis...
- autoexec 7mo agoThis guy bought an internet connected sleep mask so it's not surprising that it was collecting all kinds of data, or that it was doing it insecurely (everyone should expect IoT anything to be a security nightmare) so to me the surprising thing about this is that the company actually bothered to worry about saving bandwidth/power and went through the trouble of using MQTT. Probably not the best choice, and they didn't bother to do it securely, but I'm genuinely impressed that they even tried to be efficient while sucking up people's personal data.
- treesknees 7mo agoI took an IoT course in school, and one of the things they loved was using protocols like MQTT. I was more or less required to use it on my projects because “that’s how IoT communication works”. So to me, it feels more academic than efficient.
- 8n4vidtmkvmk 7mo agoMeanwhile streaming everyone's data, negating any benefit.
- SilentM68 7mo agoInteresting project. Here's a thought which I've always had in the back of my mind, ever since I saw something similar in an episode of Buck Rogers (70s-80s)! Many people struggle with falling asleep due to persistent beta waves; natural theta predominance is needed but often delayed. Imagine an "INEXPENSIVE" smart sleep mask that facilitates sleep onset by inducing brain wave transitions from beta (wakeful, high-frequency) to alpha (8-13 Hz, relaxed) and then theta (4-8 Hz, stage 1 light sleep) via non-invasive stimulation. A solution could be a comfortable eye mask with integrated headphones (unintrusive) and EEG sensors. It could use binaural beats or similar audio stimulation to "inject" alpha/theta frequencies externally, guiding the brain to a tipping point for abrupt sleep onset. Sensors would detect current waves; app-controlled audio ramps from alpha-inducing beats to theta, ensuring natural predominance. If it could be designed, it could accelerate sleep transition, improve quality, non-pharmacological.
- Jolter 7mo agoWhat’s your proposed mechanism for how audio waves would induce brain waves?
- pixl97 7mo agoNo idea about audio frequencies close to hearing, but I'm pretty sure it's common to manipulate the brain with ultrasonic frequencies these days.
- SilentM68 7mo agoYeah, I'm sure that technology has existed for decades. Common folks just not allowed to know about it. It's "for our own good!" sarcastically speaking :(
- SilentM68 7mo agoThat's a toughie, but if it were me and I had the energy, I'd start by looking at the following patents: - US20030171688A1: Mind controller - Induces alpha/theta brainwaves via audio messages. - US20070084473A1: Brain wave entrainment in sound - Modulates music for desired brain states. - US11309858: Inducing brainwaves by sound - Adjusts volume gains for specific frequencies. - US5036858A: Changing brain wave frequency - Generates binaural beats to alter waves. - US3951134: Remotely altering brain waves - Monitors and modifies via RF/EM waves. - US5306228A: Brain wave synchronizer - Uses light/sound for entrainment. - US6587729: RF hearing effect - Transmits speech via microwaves to brain. - US6488617: Desired brain state - Electromagnetic pulses for mind states. - US4858612: Microwave hearing simulation - Induces sounds in auditory cortex. - US6930235B2: EM to sound waves - Relates waves for brain influence. - EP0747080A1: Brain wave inducing - Sine waves via speaker for alpha waves. - US5954629A: Brain wave system - Feedback light stimulation. - US5954630A: FM theta sound - Superposes low frequencies for theta induction. - US5159703A: Silent subliminal - Ultrasonic carriers for brain inducement. - US6017302A: Acoustic manipulation - Subaudio pulses for nervous system control.
- rbbydotdev 7mo ago> I was not expecting to end up with the ability to read strangers' brainwaves and send them electric impulses in their sleep. But here we are. Almost out of a Phillip K Dick novel
- nephihaha 7mo agoJust what I was thinking. China has a recent history of spying on personal data. https://www.telegraph.co.uk/news/2026/01/26/china-hacked-downing-street-phones-for-years/ https://www.telegraph.co.uk/news/2026/01/26/china-hacked-dow...
- tomsmithtld 7mo agothe shared MQTT credentials pattern is unfortunately super common in budget IoT. seen the exact same thing in smart plugs and air quality sensors. the frustrating part is per-device auth is not even hard to set up, mosquitto supports client certs and topic ACLs with minimal config. manufacturers skip it because per-device key provisioning adds a step to the assembly line and nobody wants to think about key management. so they hardcode one set of creds and hope nobody runs strings on the binary.
- RyJones 7mo agoWhy is it that almost all ODB-II dongles you buy have the same MAC address? If you buy two, one for each car, your app can never tell which car you're connected to. They all come with Bluetooth certified logos, as well. The ones that don't reuse everything cost like $120, not $15.
- flax 7mo agoThis smells like bullshit to me, although I am admittedly not experienced with Claude. I find it difficult to believe that a sleep mask exists with the features listed: "EEG brain monitoring, electrical muscle stimulation around the eyes, vibration, heating, audio." while also being something you can strap to your face and comfortably sleep in, with battery capacity sufficient for several hours of sleep. I also wonder how Claude probed bluetooth. Does Claude have access to bluetooth interface? Why? Perhaps it wrote a secondary program then ran that, but the article describes it as Claude probing directly. I'm also skeptical of Claude's ability to make accurate reverse-engineered bluetooth protocol. This is at least a little more of an LLM-appropriate task, but I suspect that there was a lot of chaff also produced that the article writer separated from the wheat. If any of this happened at all. No hardware mentioned, no company, no actual protocol description published, no library provided. It makes a nice vague futuristic cyperpunk story, but there's no meat on those bones.
- RachelF 7mo agoYes, it is very lacking in details. The Claude output would have been interesting, or a few logs or protocol dumps. The lack of detail makes me suspect the truth of most of the story.
- llm_nerd 7mo agohttps://www.kickstarter.com/projects/selepu/dreampilot-ai-guided-sleep-mask https://www.kickstarter.com/projects/selepu/dreampilot-ai-gu... Found that in seconds. EEG, electrical stimulation, heat, audio, etc. Claims a 20 hour battery. As to the Claude interactions, like others I am suspicious and it seems overly idealized and simplified. Claude can't search for BT devices, but you could hook it up with an MCP that does that. You can hook it up with a decompiler MCP. And on and on. But it's more involved than this story details.
- simonbw 7mo agoOk, obviously unethical to do it, but this sounds like you've got the power to create some sci-fi shared dreaming device, where you can read people's brainwaves and send signals to other people's masks based on those signals. Or send signals to everyone at the same time and suddenly people all across the world experience some change in their dream simultaneously. Like, don't actually do it, but I feel like there's inspiration for a sci-fi novel or short story there.
- Larrikin 7mo agoThis feels like a reason to buy the device to me? I would want to block all of the data going to the cloud and would only want operations happening locally. But the MQTT broadcast then allows me to create a local only integration in Home Assistant with all of the data. What's the real risk profile? Robbers can see you are asleep instead of waiting until you aren't home? I have not implemented MQTT automations myself, but it's there a way to encrypt them? That could be a nice to have
- matthewfcarlson 7mo agoSounds like you cannot control which MQTT endpoint it is headed to? It just goes to the server of the device. Assuming you could modify the firmware, you could program it to send to a local MQTT.
- andai 7mo agoI thought the author was going to change the hardcoded server (or override DNS) and set up his own.
- ThouYS 7mo agothe headlines these days
- _slih 7mo ago[dead]
- roysting 7mo ago> nobody budgets time for security architecture on v1 It’s quite literally why the internet is so insecure, because at many points all along the way, “hey, should we design and architect for security?” is/was met with “no, we have people to impress and careers to advance with parlor tricks to secure more funding; besides, security is hard and we don’t actually know what we are doing, so tow the line or you’ll be removed.”
- skibz 7mo agoIt's disappointing to see. It doesn't take much work to configure a MQTT server to require client certificates for all connections. It does require an extra step in provisioning to give each device a client certificate. But for a commercial product, it's inexcusably negligent. Then there's hardening your peripheral and central device/app against the kinds of spoofing attacks that are described in this blog post. If your peripheral and central device can securely [0] store key material, then (in addition to the standard security features that come with the Bluetooth protocol) one may implement mutual authentication between the central and peripheral devices and, optionally, encryption of the data that is transmitted across that connection. Then, as long as your peripheral and central devices are programmed to only ever respond when presented with signatures that can be verified by a trusted public key, the spoofing and probing demonstrated here simply won't work (unless somebody reverse engineers the app running on the central device to change its behaviour after the signature verification has been performed). To protect against that, you'd have to introduce server-mediated authorisation. On Android, that would require things like the Play Integrity API and app signatures. Then, if the server verifies that the instance of the app running on the central device is unmodified, it can issue a token that the central device can send to the peripheral for verification in addition to the signatures from the previous step. Alternatively, you could also have the server generate the actual command frames that the central device sends to the peripheral. The server would provide the raw command frame and the command frame signed with its own key, which can be verified by the peripheral. I guess I got a bit carried away here. Certainly, not every peripheral needs that level of security. But, into which category this device falls, I'm not sure. On the one hand, it's not a security device, like an electronic door lock. And on the other hand, it's a very personal peripheral with some unusual capabilities like the electrical muscle stimulation gizmo and the room occupancy sensor. [0]: Like with the Android KeyStore and whichever HSMs are used in microcontrollers, so that keys can't be extracted by just dumping strings from a binary.
- techsocialism 7mo ago[dead]
- anonymousiam 7mo agoThe narrator in the article acts as a third person observer and identifies "Claude" as the active hacker. So assuming the (unidentified) company that sells/manages the product wants to prosecute a CFAA violation, who do they go after? Was Claude the one responsible for all of the hacking?
- wongogue 7mo agoThe narrator. It doesn’t matter to the law the kind of intimate relationship you have with your tool.
- ssener2001 7mo ago[dead]
- arter45 7mo agoWhat do you mean? IANAL, but Claude doesn't just "wake up" (whatever that means) and decide to reverse engineering/hack stuff, so if this is a CFAA violation the person who prompted Claude is indeed responsible. At best, one could argue that the company producing Claude is partially responsible because it didn't prevent people from using it to reverse engineer stuff, but there's no way Claude is "responsible for all of the hacking", regardless of how many times the blog posts says "Claude did X".
- yumraj 7mo agoWhile most comments are focused on the issue that they found, I’m more intrigued by the fact that Claude was able to reverse engineer so well. Lowering the skills bar needed to reverse engineer at this level could have its own AI-related implications.
- Neywiny 7mo agoI wholeheartedly disagree. Running strings and a decompiler explicitly written for that language is kinda the first thing that comes to mind. Trying hundreds of random ways to talk to it before even doing any real reverse engineering is just a waste of compute. You're never going to guess the JSON to send to it or the random bytes. But it's not my tokens getting spent on it so meh
- yieldcrv 7mo agoI love that it shows you the thought process that to a Senior or Staff level person would be expected to know in their approach to a reverse engineering problem with no documentation Levels up the way I think about things
- flutas 7mo agoOne of my earlier experiences with codex was actually reverse engineering, far before it was good at actual coding. It was able to decompile a react native app (Tesla Android app), and fully trace from a "How does X UI display?" down to a network call with a payload for me to intercept. Granted it did it by splitting the binary into a billion txt files with each one being a single function and then rging through it, but it worked.
- madeofpalk 7mo agoI heard about this and tried quite a bit to reverse engineer a decompiled binary from a big game to find struct/schema information but could never get anything useful.
- dlenski 7mo agoI discovered a very similar vulnerability in Mysa smart thermostats a year ago, also involving MQTT, and also allowing me to view and control anyone's thermostat anywhere in the world: https://news.ycombinator.com/item?id=43392991 https://news.ycombinator.com/item?id=43392991 Also discovered during reverse-engineering of the devices’ communications protocols. IoT device security is an utterly shambolic mess.
- minimalthinker 7mo agoI’m not super familiar with MQTT. I wonder how common this is..
- dlenski 7mo agoMQTT is a very simple pub/sub messaging protocol. It's used in a enormous number of IoT devices. The "IoT gateway" service from AWS supports MQTT and a whole lot of IoT devices are tethered to this service specifically.
- stevage 7mo agoThat is terrifying. Messing with thermostats could be enough to kill vulnerable people.
- dlenski 7mo agoYes. An excerpt from my initial email to Mysa's security contact… > I stumbled upon these vulnerabilities on one of the coldest days of this winter in Vancouver. An attacker using them could have disabled all Mysa-connected heaters in the America/Vancouver timezone in the middle of the night. That would include the heat in the room where my 7-month-old son sleeps.
- t3chd33r 7mo agoIs this some kind of joke? Claude hallucinated everything, including capacity of device to accurately measure EGG of brain waves and hallucinated the process of decoding APK to some paranoidal user who has posted his conspiracy level AI hallucinations “finds” to his blog post and everyone is like “Yeah, Claude can do this”. Is everyone here insane? I am insane?
- logicprog 7mo agoWhy do you think it's all hallucinated? You have no evidence of that, and it seems very unlikely unless you're intentionally wildly assuming the craziest possible scenario, as if you're paranoid or insane. You do realize the user can see the tool calls running and check their real, actual output, during this process, right? You do realize that there are several sleep masks on Kickstarter that actually have these features, right? The user has also shared the Claude transcript: https://gist.github.com/aimihat/a206289b356cac88e2810654adf06a55 https://gist.github.com/aimihat/a206289b356cac88e2810654adf0...
- t3chd33r 7mo ago[flagged]
- snayan 7mo agoAre you ok?
- pedalpete 7mo agoI'm the founder of neurotech/sleeptech company https://affectablesleep.com https://affectablesleep.com, and this post shows the major issue with current wellness device regulation. I believe there was some good that came from last months decision to be more open to what apps and data can say without going through huge regulatory processes (though because we apply auditory stimulation, this doesn't apply to us), however, there should be at least regulatory requirements for data security. We've developed all of our algorithms and processing to happen on device, which is required anyway due to the latency which would result from bluetooth connections, but even the data sent to the server is all encrypted. I'd think that would be the basics. How do you trust a company with monitoring, and apparently providing stimulation, if they don't take these simple steps?
- secbear 7mo agoAmazing to see claude's reasoning and process through reversing this
- abeppu 7mo agoOk so obviously this is a security disaster. But also ... is there a hackable consumer EEG device that gets useful data and is as comfortable as a sleep mask (and presumably you're not slathering electrode every time you put on your sleep mask)? Cuz once the thing can't phone home, that sounds pretty cool.
- neuroelectron 7mo agoOK, but can we get a teledildonics device that records all thrusts onto the Blockchain?
- Insanity 7mo agoReading a blog post where Claude did all the actual work is kinda sad.
- sodapopcan 7mo agoWho cares. I'm so tired.
- victor106 7mo agoI asked ChatGPT which product this could be and it came up with https://www.kickstarter.com/projects/selepu/dreampilot-ai-guided-sleep-mask https://www.kickstarter.com/projects/selepu/dreampilot-ai-gu... Claude could not tell which one
- Jang-woo 7mo agoReally interesting read. This feels less like a security bug and more like a missing execution boundary.
- 4gotunameagain 7mo ago> Claude ran strings on the binary and this was the most productive step of the whole session. After $150 in tokens, inflating GPU prices by 10%, spending $550 of VC money, and increasing the earth's temperature by 0.2 degC, claude did what a 16 year old that read two blog posts about reverse engineering would do.
- dash2 7mo agoI think the number of people who could do this in half an hour is low.
- therein 7mo agoArticle is saying it was the most productive step and crediting it to Claude. However it is indeed what anyone would do pretty much as a first step.
- azan_ 7mo agoThe impact of AI on environment is overblown.
- nilsherzig 7mo agoCan someone explain the other iot devices using the same broker? I tried cross referencing the feature list, information about the user base, kickstarter origin and flutter app with some search results and I’m pretty sure that I found the company and product in question. But they don’t (publicly) produce iot devices? Sooo I’m wondering if different companies are streaming their data into a shared sink and why they would do that?
- rglover 7mo agoThey were scanning BLE so any device using that protocol in range would be picked up. Similar to seeing your neighbor's Wi-Fi router from your couch.
- treesknees 7mo agoThat has nothing to do with the MQTT broker.
- rglover 7mo ago> The first thing Claude did was scan for BLE (Bluetooth Low Energy) devices nearby. It found mine among 35 devices in range, connected, and mapped the interface -- two data channels. One for sending commands, one for streaming data. Read the article before you unholster your weapon next time.
- nilsherzig 7mo agoyes but https://aimilios.bearblog.dev/reverse-engineering-sleep-mask/#:~:text=It%20connected,occupancy https://aimilios.bearblog.dev/reverse-engineering-sleep-mask... reads like they connected to MQTT and received data from IOT devices on there, not using BLE
- treesknees 7mo agoI’ve read the article. Sounds like you don’t understand the difference between MQTT and Bluetooth.
- mr_toad 7mo ago> I recently got a smart sleep mask from Kickstarter. I was not expecting to end up with the ability to read strangers' brainwaves and send them electric impulses in their sleep. But here we are. One of the best opening paragraphs in a SF novel that I’ve ever read. Oh, wait.
- PunchyHamster 7mo ago> For obvious reasons, I am not naming the product/company here, but have reached out to inform them about the issue. It's working as intended
- bronlund 7mo agoThat's exactly what I need. A radio transmitter as close as possible to my brain when I sleep.
- HeartofCPU 7mo agoHow is the smart sleep mask called?
- wildylion 7mo ago> and send them electric impulses in their sleep. So, it's like Lovense, but for dreams? Sorry, I know it's horrible, but I couldn't resist.
- nephihaha 7mo agoA lot of so called "smart" devices have little or no concept of privacy or personal boundaries built into them.
- thedougd 7mo agoAgents are excellent for reverse engineering. I was also recently working on a BLE reverse engineering exercise and followed a similar path. I ran into lots of headaches with BLE on my Mac and tabled it. Author or others who know, did you perform this on Linux? I imagine it lacks the tooling challenges I had with BLE on MacOS.
- minimalthinker 7mo agoIt was on a MBP, didn’t run into any issues
- thedougd 7mo agoWhat sort of tools did it use? I suppose the path mine took may have been a dead end. The Tuya app (I was also using decompiled APK) downloads the BLE definitions on-demand and weren't embedded in the app. It wanted me to capture traffic on a device with the app. I punted but plan to resume with an emulator setup or real device connected with adb.
- avanai 7mo ago“Ask an LLM to hack your app” should be a production-readiness step from now on.
- nrenegar 7mo agoYou should financialize this by creating a prediction market around it.
- eatrocs_allday 7mo agodamn, this would make a cool midi controller