Monday, August 5, 2013

Don't Hack Computers, Hack the Satis Toilet Instead

Hacking a computer is the past. Welcome to the future, where hackers can take control of Bluetooth enabled toilets.

Cyber security firm Trustwave sent out an advisory last Thursday explaining how to hack a Satis automatic toilet. The high-tech toilet can play music and even spray deodorant in the stall in addition to doing the normal function. The toilet comes with the My Satis Android application that allows you to control the toilet. “Attackers could cause the unit to unexpectedly open/close the lid, activate bidet or air-dry functions, causing discomfort or distress to user,” the advisory says.

Also, the attacker could continually flush the toilet, driving the owner's water bill up the wall.

The security issue is that the My Satis app uses the Bluetooth pin of 0000 to connect to the toilet as seen in its code:
BluetoothDevice localBluetoothDevice =

BluetoothManager.getInstance().execPairing(paramString, “0000″)

 

No comments:

Post a Comment