TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

The three million toothbrush botnet story isn't true

212 pointsby WhyUVoteGarbageover 1 year ago

26 comments

gnabgibover 1 year ago
Related: &quot;Three million malware-infected smart toothbrushes used in Swiss DDoS attacks&quot; (226 points, 136 comments)<p>[0]: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=39277990">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=39277990</a>
dangover 1 year ago
I changed the URL from <a href="https:&#x2F;&#x2F;cyberplace.social&#x2F;@GossiTheDog&#x2F;111886558855943676" rel="nofollow">https:&#x2F;&#x2F;cyberplace.social&#x2F;@GossiTheDog&#x2F;111886558855943676</a> to <a href="https:&#x2F;&#x2F;cyberplace.social&#x2F;@GossiTheDog&#x2F;111892646485958733" rel="nofollow">https:&#x2F;&#x2F;cyberplace.social&#x2F;@GossiTheDog&#x2F;111892646485958733</a>, as suggested here: <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=39297612">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=39297612</a>. Readers should probably look at both.<p>I have no idea why <a href="https:&#x2F;&#x2F;cyberplace.social&#x2F;@GossiTheDog&#x2F;111886558855943676" rel="nofollow">https:&#x2F;&#x2F;cyberplace.social&#x2F;@GossiTheDog&#x2F;111886558855943676</a> doesn&#x27;t lead to that later post in the thread. Is there a way to guarantee that readers get the entire thread in these things? If people can only see the start, that&#x27;s not much better than what Twitter does.
评论 #39305751 未加载
croesover 1 year ago
Seems like Fortinet lied about the whole translation error thing:<p><a href="https:&#x2F;&#x2F;www.aargauerzeitung.ch&#x2F;wirtschaft&#x2F;cyberangriff-die-gehackten-zahnbuersten-gehen-medial-um-die-welt-und-loesen-fragen-aus-wie-es-dazu-kam-ld.2577182" rel="nofollow">https:&#x2F;&#x2F;www.aargauerzeitung.ch&#x2F;wirtschaft&#x2F;cyberangriff-die-g...</a><p>&gt;Was nun von der Fortinet-Zentrale in Kalifornien als «Übersetzungsproblem» bezeichnet wird, hat sich bei den Recherchen noch ganz anders angehört: Schweizer Fortinet-Vertreter haben bei einem Gesprächstermin, bei dem es um aktuelle Bedrohungslagen ging, den Zahnbürsten-Fall als reale DDoS-Attacke geschildert.<p>Translation:<p>&gt;What the Fortinet headquarters in California is now describing as a &quot;translation problem&quot; sounded very different during the research: Swiss Fortinet representatives described the toothbrush case as a real DDoS attack during a meeting to discuss current threat situations.<p>And<p>&gt;Der Text wurde Fortinet vor der Publikation zur Verifizierung vorgelegt. Der Satz, wonach es sich um einen realen Fall handle, der sich wirklich so zugetragen hat, wurde nicht beanstandet.<p>&gt;The text was submitted to Fortinet for verification before publication. The sentence stating that this was a real case that actually happened was not objected to.<p>Truth seems not to be part of their business model<p><a href="https:&#x2F;&#x2F;gpl-violations.org&#x2F;news&#x2F;20050414-fortinet&#x2F;" rel="nofollow">https:&#x2F;&#x2F;gpl-violations.org&#x2F;news&#x2F;20050414-fortinet&#x2F;</a>
评论 #39306201 未加载
__jonasover 1 year ago
The linked archived article says quite specifically that while the example sounds like a hollywood story it really did happen.<p>I don’t doubt that the article is wrong or they misunderstood their source though, since it’s just a random local news article about the dangers of ‘cybercrime’ which was apparently used as a source by these larger publications.
nonrandomstringover 1 year ago
This fake story is propagated in anticipation of significant changes coming into effect in Europe this year wrt the E.U. &quot;Cybersecurity Act&quot; and &quot;Cyber Resilience Act&quot; which specifically targets IoT device security. In the US you will have &quot;Cybersecurity Improvement Act&quot; with serious consequences for non-compliant devices under EO 14028. Expect more &quot;March of the Killer Toothbrushes&quot; stories soon.
评论 #39317671 未加载
SushiHippieover 1 year ago
The article says:<p>&gt; Das Beispiel, das wie ein Hollywood-Szenario daherkommt, hat sich wirklich so zugetragen.<p>Google translate:<p>&gt; This example, which seems like a Hollywood scenario, actually happened.<p>So this article states that this actually happened.<p>So OP&#x27;s claim that this article states it&#x27;s just an example which didn&#x27;t happen, is incorrect.<p>I&#x27;m not saying it <i>did</i> happen, just that the article does not state what OP says.
评论 #39283097 未加载
评论 #39283040 未加载
评论 #39283032 未加载
Aaronmacaronover 1 year ago
Proof? This is just some random person claiming it&#x27;s not true but they link to an article which explicitly states that it is in fact true. Am I missing something?
评论 #39282934 未加载
评论 #39282825 未加载
评论 #39282834 未加载
评论 #39300385 未加载
评论 #39283740 未加载
m_stover 1 year ago
I was wondering because the toothbrushes I know use BT(LE) and aren&#x27;t connected to the Internet. However, some light bulbs do have WIFI and sure one day could be exploited. And there are definitely more light bulbs than toothbrushes around here.
评论 #39304142 未加载
评论 #39301203 未加载
autoexecover 1 year ago
Here&#x27;s the link to the actual article instead of someone&#x27;s social media post that contains a screenshot that contains an unclickable link to the article:<p><a href="https:&#x2F;&#x2F;www.tomshardware.com&#x2F;networking&#x2F;three-million-malware-infected-smart-toothbrushes-used-in-swiss-ddos-attacks-botnet-causes-millions-of-euros-in-damages" rel="nofollow">https:&#x2F;&#x2F;www.tomshardware.com&#x2F;networking&#x2F;three-million-malwar...</a><p>Disclaimer: Maybe the image is clickable or there&#x27;s a clickable link in the social media post for most people, but because Mastodon doesn&#x27;t show posts without javascript enabled I can only ever see whatever shows up in the RSS feed.
评论 #39282718 未加载
评论 #39282670 未加载
stairlaneover 1 year ago
While part of me wishes the story were true, as it’s just hilarious thinking about _a toothbrush_ carrying out someone else’s ill will. I am glad it’s not.
评论 #39282548 未加载
nevi-meover 1 year ago
It&#x27;s hard to believe that toothbrushes run Java. There&#x27;s just not enough space in them for that. Plus 3 million is a huge number.
评论 #39282827 未加载
评论 #39282465 未加载
评论 #39282586 未加载
评论 #39282499 未加载
评论 #39282357 未加载
评论 #39283122 未加载
评论 #39282631 未加载
评论 #39282620 未加载
评论 #39282730 未加载
评论 #39282725 未加载
tempest_over 1 year ago
My &quot;smart&quot; tooth brush wants my location data to use the app....
评论 #39282653 未加载
评论 #39282619 未加载
jfosterover 1 year ago
Reminds me a little of Stuxnet, which certainly happened: <a href="https:&#x2F;&#x2F;www.quora.com&#x2F;What-is-the-most-sophisticated-piece-of-software-ever-written-1&#x2F;answer&#x2F;John-Byrd-2" rel="nofollow">https:&#x2F;&#x2F;www.quora.com&#x2F;What-is-the-most-sophisticated-piece-o...</a><p>Things like this combined with AI are the scariest version of the future, I think. If we ask a very capable AI to solve climate change, what if it decides to solve it by creating something like Stuxnet for human infrastructure?
评论 #39283898 未加载
评论 #39284012 未加载
2024throwawayover 1 year ago
The story isn&#x27;t true _yet_.
c0baltover 1 year ago
Related: <a href="https:&#x2F;&#x2F;filestore.fortinet.com&#x2F;fortiguard&#x2F;research&#x2F;toothbrush.pdf" rel="nofollow">https:&#x2F;&#x2F;filestore.fortinet.com&#x2F;fortiguard&#x2F;research&#x2F;toothbrus...</a><p>A research presentation by fortinet covering a BLE-enabled toothbrush that communicates with the cloud over a mobile app.<p>Also mentioned by a comment on the original post.
jakedataover 1 year ago
3M (the Minnesota Mining and Manufacturing Company) makes many products but teethbrushes are not among them. However they are well equipped to satisfy all your PFOA and PFAS needs forever.
评论 #39302293 未加载
评论 #39302025 未加载
xg15over 1 year ago
A translation problem. Between a Swiss company and the Swiss newspaper that interviewed them. Of course.
croesover 1 year ago
Fortinet confirmed it wasn&#x27;t a real attack<p><a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=39300373">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=39300373</a>
Havocover 1 year ago
I did think it was kinda sus because those are usually Bluetooth not WLAN connected but hey maybe there are wifi brushes now
评论 #39282988 未加载
xp84over 1 year ago
I&#x27;m more surprised people took that seriously.<p>I really don&#x27;t think even 1 million toothbrushes exist that have any IP connectivity at all, let alone three million all being pwned. I would assume that if anyone had sold that many Wi-fi models, one of the big manufacturers would have some, and as far as I&#x27;m aware, none do, they all use Bluetooth. Not sure I buy that a bluetooth toothbrush can DDOS a website.
评论 #39282960 未加载
WeylandYutaniover 1 year ago
I bought a frankly too expensive iO10 and it only connects to my phone via Bluetooth.
camdenlockover 1 year ago
Ugh, god. This link led me to read the mastodon front page for a while (popular posts across the mastodon fediverse).<p>Total ideological lockstep combined with intense self-righteousness, and not a single contrarian opinion in sight.
RobCodeSlayerover 1 year ago
Wasn’t this a Silicon Valley plot line, but with fridges?
jokoonover 1 year ago
Too bad because it was quite a funny story.<p>I mean in retrospect, I can imagine it would be almost impossible to find all those toothbrushes and hack them remotely, unless they were all connected to a central server that would have been hijacked, so yeah.
compiler-guyover 1 year ago
I mean, are you sure your toothbrush is getting security updates?<p>Because not many other devices on the internet of things are.
mysterydipover 1 year ago
isn&#x27;t true... yet.