Mobile phone APP intelligent lighting system such as Philips HUE

March 29, 2020

Philips' smart lighting products offer 16 million color changes and can be remotely adjusted using the mobile app. But this surprisingly novel system has been hacked and is at risk of being shut down remotely by humans.

Safety researcher Nitesh Dhanjani has demonstrated an attack technology for the Philips HUE intelligent lighting system that allows the victim to be completely in the dark. Due to authentication issues, HUE personal wireless systems may expose users to hackers, resulting in a light-off event.

The researcher said that the HUE system generates a token whitelist that can be used by the wireless bridge to authenticate commands. The token is the MD5 hash of the MAC address of the authentication device. This causes the malware to calculate the whitelist token by looking at the infected device's ARP cache, which can result in a continuous lighting system shutdown event.

Users can purchase HUE systems in the Apple Store and elsewhere, and configure 16 million color lighting bulbs through iOS and Android apps. A Philips spokesperson said in a statement that the company uses industry-standard encryption and authentication technology to ensure unauthorized access to the lighting system.

The spokesperson said that such an attack requires a computer in a proprietary local network to issue internal commands, which means that if the home network is effectively protected and traffic between the device and the Internet is in a secure state, there is no security risk.

Dhanjani pointed out that the wireless bridge of the HUE system uses a set of tokens to authenticate the request. Any user on the same network can issue an HTTP command to change the state of the light as long as it knows any token.

According to this study, when controlling the light bulb through the HUE website or iOS application, the token whitelist is not random, but the MD5 hash of the MAC address of the device such as desktop, notebook or iPhone.

The researchers say that lighting is critical to physical security. Intelligent lighting systems may be installed in residential and corporate buildings. Remotely shutting down the lighting of hospitals and other public places by intruders can have serious consequences.

Solid wire is based on the high end of the metal film capacitor market demand,the use of advanced production technology,with a better surface and inner quality and good stability,is a variety of film capacitor end of the iderl material,especially suitable for hig-end capacitor manufacturing.

Solid Solder Wire

Solid Solder Wire,Soldering Wire,Lead Free Solder Wire,Soldering Copper Wire

Shaoxing Tianlong Tin Materials Co.,Ltd. , https://www.tianlongspray.com