The system uses RS422, with a base64 encoded AES key in the aaservice binary, and I was contemplating building an esp32 based open source implementation of the controller.
That's a crazy weird coincidence.
The system uses RS422, with a base64 encoded AES key in the aaservice binary, and I was contemplating building an esp32 based open source implementation of the controller.
That's a crazy weird coincidence.
https://www.aliexpress.com/item/1005005918675239.html
The connectors on the small RJ45 daughter board are JST-SH 1.0
The yellow lead puts out 4.2v to replicate a Li-Ion battery (as far as I can tell). You can ignore this.
Red is positive
Black is negative
Green is usb d+
Blue is usb d-
Now back to connecting an orange-pi zero to the petcube cam someone bought me for Christmas. I've found TTL pins on there and I want to know what's going on...
https://www.wago.com/de-en/c/installation-terminal-blocks-an...
I do, have 2 spare USB-C to JST-SH adapters that suit the round advantage air circuit board if anyone wants one (Perth, Free). Email in profile.
Pin 1: RS422 +/B
Pin 2: RS422 -/A
Pin 3: ? - appears to be unused; connected to unpopulated pad on PCB
Pin 4: GND
Pin 5: ~14.2v DC unloaded
Pin 6: GND
Pin 7: ?
Pin 8: ?
Shield: GND
Note: the RS422 protocol has a basic bus arbitration built-in to allow both ends to communicate. The control unit sends <U>Ping</U=xx> messages, after which it opens a slot for the Tablet to communicate back to it. At least on my system xx represents a simple CRC value that can be used to validate message authenticity. I haven't seen any AES encryption in use, messages I've seen are all plaintext, maybe the AES encryption was introduced in a later revision.1 is RS422 B
2 is RS422 A
3 & 5 - GND
4 & 6 - VCC
Not sure what 7 and 8 do.
I got inspired, and have plugged in my scope, and then an RS422 to serial adapter, and I'm getting XML encoded (weird) CAN messages, which I presume are the same as what's on the CAN bus exposed on some of the control box's ports. I'll get out the can analyser tomorrow and check.
Now the trick will be to reverse engineer this protocol. Here's a tiny sample:
<U>setCAN 0201000000236000000000000 </U=ce><U>getCAN 1 </U=00><U>Ping</U=db> <U>ackCAN 1</U=aa><U>Ping</U=db> <U>setCAN </U=b2><U>getCAN 1 </U=00><U>Ping</U=db> <U>ackCAN 1</U=aa><U>Ping</U=db> <U>setCAN </U=b2><U>getCAN 1 </U=00><U>Ping</U=db> <U>ackCAN 1</U=aa><U>Ping</U=db> <U>setCAN </U=b2><U>getCAN 1 </U=00><U>Ping</U=db> <U>ackCAN 1</U=aa><U>Ping</U=db> <U>setCAN </U=b2><U>getCAN 1 </U=00><U>Ping</U=db> <U>ackCAN 1</U=aa><U>Ping</U=db> <string name="parse_block_tag_ping"><U>Ping</U=db></string>
...
private static final byte[] f2305f = "getCAN ".getBytes(Charset.defaultCharset());
private static final byte[] g = MyApp.a().getString(R.string.parse_block_tag_ping).getBytes(Charset.defaultCharset());
private static final byte[] h = MyApp.a().getString(R.string.parse_block_tag_startu).getBytes(Charset.defaultCharset());
private static final byte[] i = "<request>Unknown</request>".getBytes(Charset.defaultCharset());
You can do the same, or alternatively ping me if you'd like me to email you the source package.https://git.nethack.net/rob/aircon
Essentially it just talks to the android tablet API to do things so it's no help if (when) the tablet dies, but it means I can do things like:
- have the entire unit turn on/off as needed based on average zone temperatures
- open/close vents based on room owners' devices being online, or temperatures of nearby zones
- dump zone temperatures to influxdb
I'm willing to bet money on that it's planned obsolescence, especially considering their "technology keeps moving forward" bullshit.
They made the analysis, how long the flash will live and saw, that it will make it out of the warranty period. Thus they did not opt for more durable and expensive flash and/or software change.
I've seen this myself before. One process step before release of the control module was a write cycle analysis to make sure the unit will live for at least 10 years (i think) before the guaranteed write cycles of the flash memory were consumed.
Opting out of a more durable solution when you know the device will break right after warranty is still planned obsolescence.
I don't think actual malicious planned obsolescence is as prevalent as many believe. A device breaking right after warranty is not a good strategy to get repeat customers. It's also a huge risk if you miscalculated and you suddenly get a lot of warranty cases. You want a lot of margin there.
I've been involved in the design of a thing myself, where something the manufacturer hadn't clearly communicated - and we just barely caught - could have made the device die just around a typical warranty period for such a device. When we found out, of course we worked on this problem to make sure it didn't die prematurely.
Also, their claim is that they're not outsourcing. If you check their website, it claims everything is designed and manufactured in Australia.
Nevertheless, I'd have given them the benefit of the doubt if it were not for:
1. The only option being a full system replacement.
2. Communication protocol being encrypted.
3. App being locked down to certain hard-coded models.
None of these give me any hope that this is a well-meaning company that just has some issues.
Also, I think a company that sells a product most customers would only buy once or twice in their lives is not a company that expects many repeat customers.
Looking at pictures like [1] and [2]
I suppose it's possible they're making their own generic android tablet control panel,
designed and manufactured in Australia
and they just happened to add a camera, side-mounted USB charging connector, a headphone socket, microsd card slot, and a battery charge level indicator, loads of space for a battery that isn't present, a connector named VBAT
and also a chinese-language bootloader
but accidentally forgot to include the power and data connector they need, poking out the back of the device
so they had someone bodge it on afterwards by hand with a soldering iron
but IMHO it's more likely they mean
"manufactured in Australia from components sourced internationally"
and one of those components is a generic android tablet.
[1] https://www.myplacenz.co.nz/are-you-making-the-most-of-your-... [2] https://blog.hopefullyuseful.com/blog/advantage-air-ezone-ta...
It's very obvious they just went for the cheapest bottom-of-the-barrel tablet Alibaba has to offer on one of their main products. I wouldn't trust this company to do anything competently.
Straight out of Microsoft's playbook.
By contrast ACs are on the decadal scale.
Integrating a tablet can't work. It's a dumb idea from the outset.
Similar hardware can work. There are touchscreen UIs that do last for a long time, especially on an AC unit where they're not getting used all the time. But they aren't tablets. In particular I'd finger the lithium ion batteries optimized for tablet-style usage as something you don't put into a system you want to last about ten years. Most of my tablets "die" when the battery just becomes unusable.
And you probably want an LCD chosen for robustness rather than being the cheapest possible high resolution display... again, plenty of LCDs can last for a long time, but the trifecta of "high resolution", "cheap", and "lasts a long time" is asking an awful lot for a fleet of systems. ("Cheap" and "lasts a long time" is, by contrast, readily available; it just won't be pretty. But it'll work fine.) And by "high resolution" I don't mean "retina display", just anything suitable for a tablet. Ye Olde 640x480 is plenty for an AC display, even in monochrome.
You want something pretty, give it a way for a real app to access it on the network. Except don't bother, really, because there's no way you're going to maintain that for 10 years either.
Working in the electronics industry, I have never once heard anyone talk about this. Engineers love engineering, and if it was real their would be a whole field devoted to it. But there isn't.
Also, since this board is stacked with software guys...
Planned obsolescence is way easier to implement in software. How many of you have been asked to put a time bomb in a warrantied product?
Planned obsolescence is a term that lay people use to describe unfortunate breaking of things that are sufficiently complex to be considered "a magical black box". In reality it is just another apparition of Murphy's law.
I've been saying this for a while.
Consumers are insanely price-sensitive while also short-sighted. They'll buy a $20 blender that will die in a year rather than the $100 blender that will last a lifetime.
Manufacturers know this and there's a race to the bottom on pricing. To get pricing as low as possible, quality and durability take a hit.
It's so much worse than that... They'll buy a $500 blender that lasts 6 months if it comes with sufficient "smart" technology integration to make them feel like they're buying into a futuristic lifestyle that others can be jealous of.
Hence, home AC units controlled by fancy tablets (which are actually shit) instead of thermostats (analogue or even monochrome LCD digital units) on the wall. Because tracking down wherever your family members wandered off to with the control tablet is so much easier than simply turning a knob or pushing a button that never moves because it's screwed into place... It must be better, it's new and expensive....
One problem for consumers is that often it's very hard to tell which is which. There is no guarantee that a $60 item won't just be overpriced garbage which is as bad (or worse if they spent much of that money on unnecessarily complex features that reduce reliability) as the $20 one, so always picking the cheaper item that superficially might seem good enough is not necessarily irrational.
(of course this doesen't necessarily apply to all brands yet)
This device should not need to write to storage. It has to save settings when the user manually changes them, which can't be more than a few kilobytes per year. Any other writes are likely an oversight on the developer's part.
Unless this scummy manufacturer also works with the aircon makers to lock those to their controllers. (That would be a great lawsuit to watch.)
Source: my customers
It’s caused tons of headache for people doing home automation stuff, especially since Chamberlain has cut off API access to home assistant. Then the home assistant people figure they’ll just rig a raspberry pi or something to short two wires, but then they hit this encryption nonsense.
For what it's worth, I bought this for my old chamberlain. https://gotailwind.com
I was looking into replacing the old unit with a new one with myq but then read about all the problems and decided to give this a shot. 3 years in and it's been a good decision.
The protocol itself is crazy, with obfuscated ternary data (instead of binary). People who reversed it are heroes.
That being said it's more likely the hardware mfg is just trying to claw in more margin.
I should really write that up at some point too.
Shame on this manufacturer.
I usually get the 'oh did not think of that' because logging is a serious afterthought in many cases. It is boring and you just drop in log4j and log away right?
log4j had big vulnerability a while back and it was a huge pain to contact all our vendors and find out if they had patched for it or not.
https://www.quora.com/Why-are-West-Australians-called-sandgr...
Also congrats to the OP! Sadly, european aircon appliances are usually built the same way (last only as long as the warranty).
(in fact, replacing basic central heating thermostats with a tablet device has been very successful for one energy company in my country, see https://www.eneco.nl/energieproducten/toon-thermostaat/; it wouldn't have been possible if the thermostat data thing was some complicated / encrypted nonsense)
There is no single control for the whole house but on the other hand I never let it run when I am away and I am never in 2 rooms at the same time so I just close the door so I only have to keep one room cool. I fail to see the need of an aircon I could control remotely with a smartphone or any smart bullshit system that control every room at the same time. And I think if I ever needed that I would probably just control the individual aircon via small esp32 with irtransmitter driven by a home server. That way the individual remotes would still be usable in case of an individual failure.
It is also handy if it is extremely hot like now and we're both out to monitor if it gets over 30 inside, so we can remotely get it cooler so the plants, cats or server will not suffer too much.
Why do work when you can read HN?
Hi from east Asia!
Also, good morning from Poland, EU :).
OTOH, they can find an industrial display + a Linux SoM (system-on-module) that can run linux or Android for under $200 in quantity.
Same diff though: no one cared, so they got what was cheap.