How we hacked our office doorbell using Slack, MessageBird and Now
blog.mollie.com
blog.mollie.com
KISS and all that...
they would just pipeline in the GCP TensoFlow based automatic friendly/hostile classification. We need cloud version of KISS...
I suspect they'd be better off switching to a RFID / nfc swipe system
Also, please note, this was just a fun small project for us. Making an image with a camera and posting to Slack would be better. We had much fun making this without putting a lot effort in it, that was for now the point.
We are aware of all the security issues and are not using this in production at our main office.
> MessageBird sends a couple of extra parameters with each request, including a callID. When a new request comes in, we’ll make an API call to MessageBird, to verify whether this voice call actually happened and if it happened within the last 2 minutes. We also used the query parameters destination and source from the incoming webhook call and matched these against the data from MessageBird. This would make sure that only “real” doorbell calls would trigger Slack notifications.
This approach seems to be reinventing the wheel of validating MessageBird webhook calls. From their docs (https://developers.messagebird.com/docs/voice-calling#handle...):
> Each callback HTTP request is signed with a signature, a base64 encoded HMAC found in the X-MessageBird-Signature HTTP header. To ensure the callback is coming from the MessageBird platform, we strongly advise to validate its signature by calculating the HMAC of the callback and base64 encoding it. Using HMAC-SHA256, the HTTP body is the message and the token of the related webhook resource is the secret. Only handle the webhook if the computed value matches the signature in the HTTP header.
It's an email alert - but it'd obviously be trivial to connect up the slack API to pass the message + image to a channel.
https://github.com/calltracking/doorbell
It's not the most beautiful thing, but it gets the job done of letting us know when someone is at any of our 3 doors.
> How we automated our office doorbell using 3 products already available.
Wrong usage of the word 'hacked' in the original title.
A more hacky way to do it, would have been getting a voice modem dongle that takes SIM cards, and writing software directly to detect/answer the incoming call, verify it's the doorbell, post to slack and wait for auth., then play a WAV back out through the dongle (like a voicemail greeting). Same result, less dependence on 3rd party services, learn a lot in the process.
It's all well and good using 3rd party services if they are available, but sometimes these articles are akin to me writing a post on 'how I found something on the internet using google'.