this post was submitted on 18 Jun 2023
        
      
      125 points (100.0% liked)
      Technology
    40580 readers
  
      
      419 users here now
      A nice place to discuss rumors, happenings, innovations, and challenges in the technology sphere. We also welcome discussions on the intersections of technology and society. If it’s technological news or discussion of technology, it probably belongs here.
Remember the overriding ethos on Beehaw: Be(e) Nice. Each user you encounter here is a person, and should be treated with kindness (even if they’re wrong, or use a Linux distro you don’t like). Personal attacks will not be tolerated.
Subcommunities on Beehaw:
This community's icon was made by Aaron Schneider, under the CC-BY-NC-SA 4.0 license.
        founded 3 years ago
      
      MODERATORS
      
    you are viewing a single comment's thread
view the rest of the comments
    view the rest of the comments
 
          
          
Buddy of mine moved into a new apartment and they have a couple of "smart features": Temp, blinds, lights. No cameras (except the front door) or other fancy stuff.
However the apartment can be reached from any browser with a hash. So if you know the hash, you can easily access his apartment controls. No password, 2FA or anything necessary to identify him.
When he told me I was looking at him with wide eyes and he just laughed and said "Yeah, I know.".
Soo...what's the hash?
I mean, you'd have to guess it and that's the hard part, but if you can, you can probably also guess the hash of all other apartments. Unless they add some random string into the hashable info, you can guess your own hash with your own apartment info (every apartment has a house ID and apartment ID etc.).
Would be a funny weekend project to see if we could get anywhere with it. He could turn down the heat from his neighbors.
If you are at least familiar with technology and search engines you can find pretty much any smart device on shodan.io