The three million toothbrush botnet story isn't true
cyberplace.social
cyberplace.social
I have no idea why https://cyberplace.social/@GossiTheDog/111886558855943676 doesn't lead to that later post in the thread. Is there a way to guarantee that readers get the entire thread in these things? If people can only see the start, that's not much better than what Twitter does.
Scrolling down to see everything is what I'd expect, and had 733 shown up when I scrolled down, I wouldn't have changed the URL.
Starting at https://cyberplace.social/@GossiTheDog/111886558855943676
First reply is from the OP, and the visual "thread" (vertical line) on the left side is broken. Click on that reply ("The toothbrush thing has gone viral despite it being total bollocks.").
Now again scroll down through posts by the OP until the "thread" on the left side breaks. Click on that last reply ("Fortinet also declined to comment to me.").
Finally, the target post appears as a reply to that ("Fortigate have issued me a statement.")
Navigational issue. One might ask what is the difference between the follow-ups that show up automatically and the ones that don't show up until you navigate. I don't know.
https://www.aargauerzeitung.ch/wirtschaft/cyberangriff-die-g...
>Was nun von der Fortinet-Zentrale in Kalifornien als «Übersetzungsproblem» bezeichnet wird, hat sich bei den Recherchen noch ganz anders angehört: Schweizer Fortinet-Vertreter haben bei einem Gesprächstermin, bei dem es um aktuelle Bedrohungslagen ging, den Zahnbürsten-Fall als reale DDoS-Attacke geschildert.
Translation:
>What the Fortinet headquarters in California is now describing as a "translation problem" sounded very different during the research: Swiss Fortinet representatives described the toothbrush case as a real DDoS attack during a meeting to discuss current threat situations.
And
>Der Text wurde Fortinet vor der Publikation zur Verifizierung vorgelegt. Der Satz, wonach es sich um einen realen Fall handle, der sich wirklich so zugetragen hat, wurde nicht beanstandet.
>The text was submitted to Fortinet for verification before publication. The sentence stating that this was a real case that actually happened was not objected to.
Truth seems not to be part of their business model
2) Just because it was submitted for verification prior to publication doesn't mean that it was read, or read thoroughly. Or heck, maybe it was read by the very employees who mistakenly thought it was real. Plausible if it was, as indicated in your comment, a german article.
3) Violating a software license has nothing to do with "truth", but lawfulness. These would probably be highly correlated traits in many individuals, but they certainly don't have to be.
The lied about the use of GPL code by intentional obfuscation of GPL software use.
I don’t doubt that the article is wrong or they misunderstood their source though, since it’s just a random local news article about the dangers of ‘cybercrime’ which was apparently used as a source by these larger publications.
[1] (Public Law No: 116-207), https://www.congress.gov/bill/116th-congress/house-bill/1668
[2] NIST, IoT Guidance and Catalog, https://csrc.nist.gov/News/2021/updates-to-iot-cybersecurity...
[3] Trustworthy Network of Things, https://www.nist.gov/programs-projects/trustworthy-networks-...
[4] IoT Cybersecurity, https://www.nist.gov/itl/applied-cybersecurity/nist-cybersec...
Tend to fairly regularly check comments from at least the last week to see if anybody responded.
Notably, while following the situation, and knowing a bit about the IoT world, not deeply involved in microcontrollers or IoT design. Mostly aerospace personally. Some experience with Wifi and Bluetooth development for Windows and Android, with a bit of Arduino, yet that's the perspective for discussion / questions.
Can refer you to a few NIST folks and some NIST mailing lists.
> Das Beispiel, das wie ein Hollywood-Szenario daherkommt, hat sich wirklich so zugetragen.
Google translate:
> This example, which seems like a Hollywood scenario, actually happened.
So this article states that this actually happened.
So OP's claim that this article states it's just an example which didn't happen, is incorrect.
I'm not saying it did happen, just that the article does not state what OP says.
To expand on the initial dramatized story:
> Sie steht zu Hause im Badezimmer, doch sie ist Teil einer gross angelegten Cyberattacke. Die elektrische Zahnbürste ist mit Java programmiert, und unbemerkt haben Kriminelle darauf eine Schadsoftware installiert – wie auf 3 Millionen anderen Zahnbürsten auch. Ein Befehl genügt, und die ferngesteuerten Zahnbürsten rufen gleichzeitig die Website einer Schweizer Firma auf. Die Seite bricht zusammen und ist für vier Stunden lahm gelegt. Es entsteht ein Schaden in Millionenhöhe.
The article claims that an electric toothbrush with Java-based software was the target of malware. Criminals then leveraged this malware to execute a ddos from the toothbrushes against the website of a swiss business.
The article further claims this led to a downtime for around five hours with expect damages in the millions.
Me: Damn garbage collector
The chef's kiss moment of this story would be that it was Log4J vuln that was unable to be patched because why would they make updates to a toothbrush. I'm guessing that would complete somebody's bingo card.
Who had DDoS attack, Botnet, IoT Device, Java, Log4J?
> Das Beispiel, das wie ein Hollywood-Szenario daherkommt, hat sich wirklich so zugetragen.
Correct translation:
> This example, which seems like a Hollywood scenario, actually happened.
But as you can see, if you miss the last part, it's easy to get the translation wrong.
(Interestingly, the Swiss article doesn't directly quote Fortinet as a source, but as an expert opinion. Maybe something was lost in translation there when the story went viral?)
Million dollar damage because a Swiss site wasn't reachable for 4 hours?
I doubt that.
If this is real, the article is beyond useless in informing people of what has happened and how it's happened.
> She's in the bathroom at home, but she's part of a large-scale cyber attack. The electric toothbrush is programmed with Java, and criminals have unnoticed installed malware on it - like on 3 million other toothbrushes.
(In German, toothbrushes are female, like all brushes.)
It means nothing other than that you need to remember the correct pronoun for every noun, which is absurd.
I just assumed they were gendering inanimate objects, which even non-gendered English speakers will do, but conveys more anthropomorphic intent.
Let's coin a term for this: misanthromorphism.
He elaborates farther down the thread:
> A botnet of 3 million toothbrushes would be twice the size on Mirai's various botnets put together, and a MAJOR infosec event. The person they were interviewing has only worked there about a year, and Fortigate staff don't appear to know about this botnet.
Edit to add:
Imagine you read on TechMeme that room-temperature superconductors are now confirmed to exist. But when you trace the story back, the original citation is an article in the Tucson Regional Business Journal about how scientific research benefits innovation. Would you think "wow, big scoop for the TRBJ!" Or something more like, "I bet that business reporter misunderstood something they heard."
This was a simple letter to the editor, written by a doctor, that became the driving force behind Oxycontin marketing.
[0] https://www.theatlantic.com/health/archive/2017/06/nejm-lett...
https://news.colgate.edu/magazine/2019/02/06/the-strange-cas...
Highly unlikely.
Highly suspicious and now confirmed it didn't happen.
"Be afraid, be very afraid" Wednesday Addams - Addams Family Values
It's not the pacemaker malware you want to worry about, it's the pacemaker ransomware!
[1] https://www.wired.com/2014/05/sentinl-gun-lock/
[2] https://www.bleepingcomputer.com/news/security/hacker-used-r...
If a company ever did this, I bet they'd charge at least 10 times more than that.
"Don't die during reboot"
Oh, the Convair B-36 Peacemaker definitely delivered malware.
They were clearly referring to the Colt Single Action Army revolver handgun.
But I eventually decided that wasn't a fruitful vein of humour, so I pared it back to mere mention of the weapon.
I.e., even though I no longer jad a reason to prefer the bomber over the pistol for the pun, I stayed with it out of mere joke-planning inertia.
Why mention just one or the other in my original comment? Well, because, as you probably know, brevity is the soul of wit.
https://www.tomshardware.com/networking/three-million-malwar...
Disclaimer: Maybe the image is clickable or there's a clickable link in the social media post for most people, but because Mastodon doesn't show posts without javascript enabled I can only ever see whatever shows up in the RSS feed.
[1] https://archive.ph/2024.01.30-203406/https://www.luzernerzei...
The German article says it got the information from a report by fortinet. I didn't notice anything about the DDoS attack there, but i did find these:
https://filestore.fortinet.com/fortiguard/research/mobileiot...
https://filestore.fortinet.com/fortiguard/research/toothbrus...
Someday a headline like this will actually be true.
I think of it more like accidentally publishing a prewritten celebrity obituary.
[edit]
No, Java ME CLDC can run on devices with as little as 160kB of ROM and 8kb of RAM.
While not exactly, small, the first Java product was remote controller with touchscreen...
[1] https://en.wikipedia.org/wiki/Java_Card [2] https://en.wikipedia.org/wiki/Java_Platform,_Micro_Edition
Of course the availability of multiple OS for these devices reinforces the idea that you can run a lot of things on some very low power devices these days.
At the same time, it's important to understand that JavaCard is a very constrained version of Java. Most JavaCard platforms have no support for IP networking, which would make it an unlikely source of DDoS (besides the fact that it requires relatively specialized developer tooling).
I'm not claiming that you could use a smart card for DDoS (the idea seems absurd, but somebody is probably going to prove me wrong one of these days), merely that if some version of Java runs on a smartcard, I don't find it that unimaginable for a toothbrush to have a good enough chip to run Java, perhaps with enough resources for a TCP / IP stack. Something equivalent in performance to an old, WAP-capable phone that also ran Java ME, perhaps.
[0]: https://en.m.wikipedia.org/wiki/Jazelle in [1]: https://developer.arm.com/documentation/ddi0406/c/Applicatio...
if you use an iPhone, my apologies
When I saw your comment I figured I should check and see and it looks like they dropped the location permission.
https://play.google.com/store/apps/details?id=com.philips.cd...
You don't need bluetooth to do that. By keeping track of your public/private ip (which requires no special permissions), and correlating it to time of day, it's fairly easy to infer whether you're home or not. If there's a network you're regularly connected to during the evening and weekends, it's highly probable that you're "home".
Things like this combined with AI are the scariest version of the future, I think. If we ask a very capable AI to solve climate change, what if it decides to solve it by creating something like Stuxnet for human infrastructure?
Highly recommended!
[0] https://www.relicradio.com/otr/2021/12/a-logic-named-joe-by-...
A research presentation by fortinet covering a BLE-enabled toothbrush that communicates with the cloud over a mobile app.
Also mentioned by a comment on the original post.
'PFAS bad' is about as sophisticated a viewpoint as 'nuclear bad'.
Also, 3M is exiting PFAS tech since it only accounts for a few % of their business: https://news.3m.com/2022-12-20-3M-to-Exit-PFAS-Manufacturing...
Moving beyond eating lead doesn't mean not using it intelligently when the risk profile is low. Also, lead-based glass is also an important component of the world's high-efficiency perovskite solar cells.
Many of the industrial products materials we wouldn't want to eat, this just means we have to be better about recycling.
It all has to do with how medical billing is structured. Xrays were already cheap before the current model was put in place so they are the go to method for diagnostic. Even though there are better ubiquitous options available, price fixing keeps those out of reach for triage and simple diagnostics.
Is PFAS denialism going to be as bad as climate change denialism is today, or tobacco disease denialism used to be? I'm tired of all these people refusing to acknowledge widespread scientific consensus. (Assuming you're not a 3M or DuPont astroturfer, of course.)
I really don't think even 1 million toothbrushes exist that have any IP connectivity at all, let alone three million all being pwned. I would assume that if anyone had sold that many Wi-fi models, one of the big manufacturers would have some, and as far as I'm aware, none do, they all use Bluetooth. Not sure I buy that a bluetooth toothbrush can DDOS a website.
Total ideological lockstep combined with intense self-righteousness, and not a single contrarian opinion in sight.
I mean in retrospect, I can imagine it would be almost impossible to find all those toothbrushes and hack them remotely, unless they were all connected to a central server that would have been hijacked, so yeah.
Because not many other devices on the internet of things are.