jwildeboer, (edited )
@jwildeboer@social.wildeboer.net avatar

My newest weird conspiracy theory: A lot of those electronic door locks use a backend system which is called the Tuya app. It's an internet based service where you register yourself and your locks so you can "conveniently" control and lock/unlock "your" doors from everywhere. So the Tuya backend is technically able to unlock a lot of doors and it has geolocation data on all of these locks. What could possibly go wrong?

filid,
@filid@muenchen.social avatar

@jwildeboer traue keinem tuya

charlykuehnast,
@charlykuehnast@chaos.social avatar

@jwildeboer
The »S« in »IoT« is for Security.

byteborg,
@byteborg@chaos.social avatar

@jwildeboer
And the Tuya ecosystem is extremely cheapskate, so I'd don't trust their threat modeling (if they did any at all).
@koehntopp

jwildeboer,
@jwildeboer@social.wildeboer.net avatar

deleted_by_author

  • Loading...
  • byteborg,
    @byteborg@chaos.social avatar

    @jwildeboer
    Its basically crapware. I got several really cheap smart sockets that I flashed to openbk firmware which removes tuya and adds mqtt.
    @koehntopp

    jelmerdehaas,

    @byteborg @jwildeboer @koehntopp That sounds interesting as I have a few smart sockets connected to my through the tuya ecosystem. Can you expand on how to flash and install firmware?

    koehntopp,
    byteborg,
    @byteborg@chaos.social avatar

    @koehntopp
    No Tasmota, the chips they use are much smaller and cheaper than ESP and the like. Also, you need to solder a temporary 2mm pitch pinheader to the board and wire a programmer to tge board. Software lives here: https://github.com/openshwprojects/OpenBK7231T_App
    @jelmerdehaas @jwildeboer

    BenBen, (edited )
    @BenBen@chaos.social avatar

    deleted_by_author

  • Loading...
  • byteborg,
    @byteborg@chaos.social avatar

    @BenBen
    Thanks for pointing me there ❤️
    @koehntopp @jelmerdehaas @jwildeboer @esphome

    jwildeboer,
    @jwildeboer@social.wildeboer.net avatar

    deleted_by_author

  • Loading...
  • byteborg,
    @byteborg@chaos.social avatar

    @jwildeboer
    Nordic is much too expensive for those devices... BK7231*...
    @koehntopp @jelmerdehaas

    jwildeboer,
    @jwildeboer@social.wildeboer.net avatar

    deleted_by_author

  • Loading...
  • byteborg,
    @byteborg@chaos.social avatar

    @jwildeboer
    Interesting. Then it's probably a 40+€ device. Most of the Tuya devices are sub 15€. I'm looking forward to your experiences.
    @koehntopp @jelmerdehaas

    jwildeboer,
    @jwildeboer@social.wildeboer.net avatar

    deleted_by_author

  • Loading...
  • deavmi,

    @jwildeboer based on? Have you bought several before and got some sort of suspicion?

    jwildeboer,
    @jwildeboer@social.wildeboer.net avatar

    @deavmi It's a SPoF (Single Point of Failure) hiding in the background, IMHO. Highly centralised and run by a company that is still working hard on making break-even, according to their latest investor presentation, where they pride themselves on having drastically reduced expenses, mainly by reducing the workforce AKA firing a lot of people. Source: https://s27.q4cdn.com/751054641/files/doc_presentations/2023/Nov/29/tuya-23q3-presentation_vff.pdf

    lobingera,
    @lobingera@chaos.social avatar

    @jwildeboer you just reported facts. I'm waiting for the theory.

    jwildeboer,
    @jwildeboer@social.wildeboer.net avatar

    deleted_by_author

  • Loading...
  • jwildeboer,
    @jwildeboer@social.wildeboer.net avatar

    @lobingera At some point in time a master key leaks and all locks suddenly become a huge security risk. Insurances might refuse to pay when things get stolen from a house "secured" by Tuya. Etc.

    yacc143,
    @yacc143@mastodon.social avatar

    @jwildeboer @lobingera You are not thinking progressive enough.

    A second pillar for the company, providing data for "goods liberation industry".

    Technically, if Tuya is not located in one of the special jurisdictions that don't mirror US practice, you do not have an expectacy of privacy for the data stored with them.

    Any bored attorney fishing with subpoenas might get the data, state actors, but of course, a digital lock with remote cloud control like that is rather useless.

    jwildeboer,
    @jwildeboer@social.wildeboer.net avatar

    @yacc143 @lobingera TL;DR a lock connected to a cloud isn't a lock ;)

    lobingera,
    @lobingera@chaos.social avatar

    @jwildeboer @yacc143 There are quite many things that aren't when connected to a cloud.

    slink,
    @slink@fosstodon.org avatar

    @jwildeboer @yacc143 @lobingera also: a can not exist in a .

    marcel,
    @marcel@waldvogel.family avatar
    jwildeboer,
    @jwildeboer@social.wildeboer.net avatar

    deleted_by_author

  • Loading...
  • yacc143,
    @yacc143@mastodon.social avatar

    @jwildeboer @marcel @lobingera @hacks4pancakes

    Funny how the IT old hands are rushing to buy these smart locks.

    Sorry that's one of the use cases where even very lazy colleagues tend to want to know beforehand why it's supposed to be secure.

    That's not the case of outsourcing corporate security to a 3rd party (where I had in all cases a rough plan how to break in through our new weakness during the initial presentations of the products, but hey it saves money). This is often private.

    logorok,
    @logorok@procial.tchncs.de avatar

    @jwildeboer @lobingera the problem is not that someone can get in your house. The problem is, you won’t get in your house when the company has gone broke.

    jwildeboer, (edited )
    @jwildeboer@social.wildeboer.net avatar

    @logorok @lobingera Yep. Or when the company that sold you the lock doesn’t pay its bills to tuya …

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • DreamBathrooms
  • everett
  • tacticalgear
  • magazineikmin
  • thenastyranch
  • rosin
  • tester
  • Youngstown
  • khanakhh
  • slotface
  • ngwrru68w68
  • kavyap
  • mdbf
  • InstantRegret
  • megavids
  • osvaldo12
  • GTA5RPClips
  • ethstaker
  • normalnudes
  • Durango
  • cisconetworking
  • anitta
  • modclub
  • cubers
  • Leos
  • provamag3
  • JUstTest
  • lostlight
  • All magazines