Researchers Hack Philips Hue Smart Bulbs Using a Drone (pcworld.com)
schwit1 quotes a report from PCWorld: "Researchers were able to take control of some Philips Hue lights using a drone. Based on an exploit for the ZigBee Light Link Touchlink system, white hat hackers were able to remotely control the Hue lights via drone and cause them to blink S-O-S in Morse code. The drone carried out the attack from more than a thousand feet away. Using the exploit, the researchers were able to bypass any prohibitions against remote access of the networked light bulbs, and then install malicious firmware. At that point the researchers were able to block further wireless updates, which apparently made the infection irreversible. 'There is no other method of reprogramming these [infected] devices without full disassemble (which is not feasible). Any old stock would also need to be recalled, as any devices with vulnerable firmware can be infected as soon as power is applied,' according to the researchers. The researchers notified Philips of the vulnerability. The company then delivered a patch for it in October." It wasn't long ago that claiming "Drones are controlling my lightbulbs!" would have gotten you locked up for your own protection.
then someone gets sued. then some lawyers make bonus.
Not everything needs to be on the damn fucking internet.....unplug motherfuckers...
I'm a big fan of automation but wireless automation, especially the IoT blight is a horrible idea. If your primary defense is obscurity then accepting a broadcast from anywhere is a recipe for disaster. Wired automation is intrinsically safer because it requires physical access though I do not believe that should be it's only defense.
Anons need not reply. Questions end with a question mark.
don't turn them on.
Being heavily invested in home automation including Phillips Hue, it's been my experience that you can trust only the major IoT players when it comes to pushing frequent security updates, something Hue does well. So does Ring.
I wish non-techie people knew about routers that can isolate the IoT stuff to its own network, or that buying cheap IoT stuff is no bargain in the long term.
Alright! I know I'm in there! If I don't come out, I'll have to come in after me!
Who needs to patch a lightbulb?
Analog for the win!
We will bankrupt ourselves in the vain search for absolute security. -- Dwight D. Eisenhower
$15 per bulb and they STILL suck.
I like the part where they can make the infection "irreversible". Nice touch.
Guess what brand of bulb I won't be buying, even though it's supposedly patched?
Just cruising through this digital world at 33 1/3 rpm...
ZigBee issued a press release today about this. They say the attack exploited a bug in one vendor's implementation of the protocol, not a weakness in the protocol itself.
Was the drone 3D printed? That is the really important question here. How else would those researchers get enough followers to accomplish their goal of exposing the evil security company?
I'm sure the next thing is these guys get sued under some DMCA provision or clause, instead of getting appreciation for the effort the researchers put into exposing the vulnerability so the vendor can evolve their product.
I know it sounds cynical, but can you remember a time where a vendor of these products actually thanked those who hacked it for letting them know the problem?
My ism, it's full of beliefs.
Now I will need a candle at night to read, because somebody might --you know tinker with my lights-- and force me to turn them off.
Both TFS and TFA are really light on technical details - can anyone shed some light on where the drone comes in play? And also the vulnerability itself - a default password or something more obscure?
Another question would be of course why would those lights even have the ability to install new software in the first place. Is it really that hard to do software right, that no updates are needed for something as simple as a lamp?
Thanks For share. Today I learned a lot from your website,, If you have a problem we come with a recommendation for us, please visit my website Obat Sinusitis
Oooh, now I understand what happened in Stranger Things.
My first program:
Hell Segmentation fault
FTFY
Sent from my ASR33 using ASCII
Curso NR 10 online curso NR 10 curso NR 10 online
**********HACK TODAY AND GET FREE MONEY FOR CHRISTMAS************
We are hackers, We just succeeded with a new invention. We've got hacked ATM cards for sale. These hacked ATM cards have been programmed to work on any ATM machine. The cards have been topped up with $100,000 With a daily withdrawal of $3000 per day ( depending on how it is programmed ). The cards have got some special features which includes;
*Deactivating the CCTV cameras when inserted in the ATM machine,
* It comes with a 4 digit pin just like every other ATM card,
* It can be topped up when the money in it has been exhausted,
*It is untraceable and undetected.
The cards were successfully programmed with the hard-work of our hackers in USA. And they are cloned using a writer (MSR 606).
If you need to get the cards, order one today and it will be shipped to your location. Contact us on to get one..
SIMPLEHACKERS2@GMAIL.COM
***********Serious buyers only**********