Show HN: I hacked my microwave with a Raspberry Pi
madebynathan.com
madebynathan.com
* a picture of a whole chicken
* one ice cube
* two ice cubes
* something that might have been a burger or a slice of bread
* 3 x straight lines
* 3 x wavy lines
Never being sure, I ignored all of those buttons. But even the basic 'set a time, a power and go' method was awful.
* Choose a power. There was no default. You had to do this before you'd set the time, or the time would reset back to 0.
* Turn a wheel which increases the time. The first two minutes increment 1 second. After that they increment in 10 seconds. So to get to 5 minutes, you had to spend ages turning it.
* Press 'Go'.
Next to the 'Go' button there was a 'Cook' button, which reset everything.
There was a defrost mode, which seemed to heat the contents for 2 minutes and 10 seconds (couldn't change the time). The results were identical to just heating it on full power.
Instead, we all have stories like this about microwaves with dials, modes, stages, levels, pre-programmed jobs, and recipe databases, but that lack a simple way to microwave something for 30 seconds!
I assume this is because every microwave designer wants to invent some new feature they can tout on the box. I have often fantasized about enacting a law that requires designers of new interfaces to be forced to use said interfaces in their personal lives for a month. Hopefully this would promote better design; alternatively, it could be used as a form of penance.
The best microwave UI I've used has several functions above the number pad, all of them completely optional. Typing a time on the number pad and pausing made the microwave start -- to rephrase, if you press 4 5 and didn't press anything for 3 seconds, the microwave would begin and operate for 45 seconds. Pressing 1 3 0 and walking away would run it for 1 minute 30 seconds. When it was done it beeped 3 times, then once every 10 minutes, until you open the door or press a button. At the bottom was a Power button which you could press to change the power level at any time, and a Start / +30 sec button which would add 30 seconds to the amount of time on the timer. And if the clock wasn't set, it would just display 00:00 solidly, not blinking.
Maybe this is a mis-remembered mix of the best UI elements from several microwaves, but to me it's ideal.
I'm also not a big fan of your "walk away while the microwave is off and it turns on after three seconds" model.
In reality, most food that you want to microwave has precise instructions on it, so I really only need quick and easy to use manual controls.
Some ideas for my ideal microwave (should any manufacturers be reading):
* Small camera with OCR that can read the instructions and program accordingly
* Thermometer which checks whether the food is ready.
* A way of mixing the food, instead of relying on me to stop it halfway through and do it manually.
* Cover which goes over the food automatically, so I don't realise I forgot only when there's a load of food baked onto the top.
* Something which cooks the food without heating the container to an untouchable heat.
My solution was to open up the microwave and (after shorting the capacitor) I removed the damn beeper. I still have that microwave today and while it's still a terrible user interface it brings me happiness each day when I hear the microwave finish cooking something without beeping.
But even worse, it would only work if you input the desired time and power... AND YOU HAD TO PRESS BUTTONS FOR THOSE.
Yes, neither of them were default, you had to seek for a "time" button, press it, then turn the knob, then seek the power button, press it, turn the knob, and if you did it wrong it would get into some weird states of waiting for a certain input that it was not clear what it wanted, and it was not clear how you could cancel it (it does have a cancel button, but it took me a while to realize I had to press it several times in a row to reset the thing so I could try again).
The microwave is so annoying that in the end I gave up and don't used it anymore, I only relied on food that was palatable without heating, or I used the old fashioned fire.
EDIT: I remembered another one: also had no number pad, instead it featured the following buttons (that required some good force to register a press): +5 seconds, +10 seconds, +30 seconds. Wanted to make a lasagna that take 16 minutes? Good luck.
Clearly designed by an evil bastard.
Its not as annoying as it sounds. Just decide how long you want to cook for, subtract that number from 5, hit the '5' button, and open the microwave when the countdown clock gets to the number you calculated earlier.
> There weren't any online microwave cooking databases around, so I made one
Brilliant.
You buy groceries, place them in their designated slots in the fridge. Robot arms know which slots hold each ingredient, and can measure and cut appropriately (using scale, food processor, and maybe some other specialized cutting appliance for trickier items). Stove top is easy to control and pans are all lined up for the robot arms to repeatedly grab. Most recipes could fit within this somewhat limited set of "building blocks" that the kitchen robot could easily perform: measure 8 oz of tomatoe, dice onion, boil pasta, slice chicken breast into strips, pour 2 oz of oil on pan, etc. The hardest part might be washing the dishes.. Heh
Surely you have the industrial machines do the pasta sauce in a factory, so no need to measure tomatoes and dice onions. Similarly the chicken breast can be cooked and pre-sliced (or cubed).
The greatest problem I foresee with this is maintaining hygiene. The machine will slop and mess, eg pouring ragu, cooking with oil that splatters. Those surfaces will need cleaning and ingredients that spoil readily (fresh diced chicken) will need disposing of and replenishing regularly. It certainly doesn't seem impossible but each section would need specialised washing equipment it seems, or maybe be entirely submersible and so allow the machine to be flushed from the top and then have a steam wand clean the individual stations.
I see it working for making dishes in an automat (http://en.wikipedia.org/wiki/Automat) but not really being efficient enough for a domestic situation.
Perhaps a digester for the expired foodstuffs and left overs could be built in to generate energy for heating and cooling required in the machine?
"Apartment complex burnt to the ground by toddler with iPad"
"Chinese hackers crash US power grid using Microwave exploit"
NFC or Bluetooth control might be better suited for this than full web connectivity.
That said, I HATE the UI on my microwave & would love to fix it. Do people really eat that much popcorn that it deserves it's own button??? For me, I want exactly 3 controls: a time wheel, power up/down & a start button. Hit start for a quick minute, twice for 2 minutes, etc.
The Raspberry Pi microwave is awesome, though I do wonder why the 1 second buttons exist.
Ever tried to soften a small piece of cold butter? 10 seconds is way too long for that
If it's over, I doubt a one-second difference will make one (difference).
That technology is called a 'Microwave Inverter'. A lot of Panasonic microwaves have it.
One thing that it seems to miss (that all microwaves that I know miss) and that would probably be very easy to implement is a mute button for late night snacks.
One of the problems I have with GE microwaves is that the number pad isn't always for entering time - if you touch "2" in preparation for entering 20 seconds, you get programmed time #2. Unless you hit the "Time" button first... Bad design, General Electric.
Circuit design, soldering, graphic design, firmware and even a standalone website.
If you've worked on electronics and software projects like this please give me a call (details at http://gridspy.com) because we need you.
1. Clock is automatically updated from the internet
2. The microwave has a web page so you can control it
from your phone (why not), and set up cooking
instructions for products
3. Tweets after it's finished cooking something
4. Can be controlled with voice commands ∗∗
∗∗ ...not that bad, but subject to pranks and false positive
microwave commands, from people in the same room
This is all REALLY bad from a safety perspective. Exposing household appliances to the wilds of the internet is all kinds of dangerous. You shouldn't advertise that this is a good idea, and leave readers with the assumption that maybe it's password protected or maybe not (it is: http://www.microwavecookingdb.com/products/new?upc=871100027...), or maybe it's wrapped up in TLS/SSL and maybe not (it's not: http://www.microwavecookingdb.com/users/sign_in). Is the internet control framework just security by obscurity, operated by arbitrarily obscure URL parameters? Who knows? Maybe? (here's the code: https://github.com/ndbroadbent/raspberry_picrowave) I mean, yeah it's just a DIY project, but immediately, I see some opportunities to wreak havoc.First of all, it's not merely polling an internet time server, but that's one port exposed to the internet, that anybody can just start dumping malicious payloads on. Second, and worst, it can be switched on from the internet. Third, it gives feedback that can be accessed by the entire internet, tells the internet what it is, and what it's doing, right now in real time, allowing an attacker to monitor the success of malicious efforts. This way, you'll know as soon as you're able to send a command to power up the microwave for one second, to test and prove the ability to control it.
People will attack these kinds of openings, just for the sheer amusement of running up a total stranger's electric bill, nevermind start a fire. This article seems relatively smart and competent, and so maybe we should ASSUME that proper security exists?
This is the kind of design inspiration that's going to encourage some other engineer (or worse, an MBA in charge of some stupid startup) to go out and expose the electric grid to twitter with some poorly tested SCADA system, and on a dark, stormy night, in the far flung future, I'm going to be eating cold beans from a can, in the dark, because of it.
Or, maybe the guy just likes playing around with electronics for fun? Perhaps he doesn't really consider this a production ready appliance and just wants to share his hobby with the world.
If everyone adhered to your cautious approach no experimentation would ever take place as all new things carry risks and lessons to be learned. You can't always nail it first time round, you have to make mistakes to make progress. And there is absolutely nothing wrong with sharing your experiments.
> This is the kind of design inspiration that's going to encourage some other engineer...
This makes me think your whole comment is just trolling.
The user name kind of gives the game away
What is the danger in having a port exposed that can receive updates for time? Are there huge vulnerabilities in the ntpd? Seems like a pretty small attack surface to me.
actually... Is that port even open?!
This is polling a time server through NAT right? So the ports get negotiated. We're not listening, were asking. So I guess the danger would be that your time server of choice could be compromised, and then start sending out malicious packets that... confuse ntpd? Seems like were back where we started.
There was some stupid stuff in that article, twitter updates being perhaps the most colossal (and voice control coming in a neat second, web control @ 3). However, once you take flame decals off and remove the card in the spokes, this ceases to be the danger it once was.
Then you have arbitrary code execution as ntpd. Unless you have apparmor, or some other MAC.
Given that the same ntpd code is running on many many internet connected computers around the world, I don't think a microwave is worth a 0day remote root exploit on.
Wait... are you saying this as reason why this guy shouldn't be doing what he's doing? Because somebody somewhere who might be in a position of public trust might be incompetent? SCADA security is a big deal, but I think your energy is a bit misplaced here...
Party on, Mr. Broadbent. Keep making that Raspberry Pi make you some Raspberry Pie.
But if I live in an apartment building, and my belongings can be burned to the ground because the apartment above me decided to put their microwave on the internet, I wouldn't want any of my neighbors doing this. It's not a good idea for everyone, everywhere, all the time.
* EDIT: Just the "internet enabled" parts mostly (unless you're qualified/experienced enough to understand the hazards), not all the other hardware hacks (i would estimate that anybody etching their own circuit boards would have a pretty firm understanding of electrical safety).
Well yeah that would be a bit crazy.
I agree that the microwave webpage should be password-protected or disabled, because really, it's not the most important feature. If I was living in an apartment with a shared network, everything would be running behind a firewall.
The cooking database website is the only part accessible from the internet, and is running on a separate server. I've added a temporary lock for my products, so no-one can edit or delete them at the moment. In the future I might implement some better ways to prevent abuse. I haven't set up SSL yet, but will do it if the site starts getting some use. I've added the following notice for now:
> This website is not currently secure. If you submit your password on this form, a hacker will be able to read it, especially if you are using an unsecured wifi connection. However, it is safe to sign in with Facebook, Google, or GitHub.
Linux (Raspbian) is in charge of setting the time via NTP, so any vulnerability is not specific to my project. The tweeting is dumb, but just a fun thing to put in a blog post. And voice commands must be prefixed with the 'microwave' keyword, unless the microwave door has been closed less than 10 seconds ago.
As zanny pointed out (https://news.ycombinator.com/item?id=6030206), since we know the chipset, and can anticipate available features, given that we know the networked device is a Raspberry Pi, and that we have the source code of the project, this provides us with enough information to craft possible payloads to drop onto the system. It's certainly not a huge attack surface, but there might be _just_ enough wiggle room to bust in.
As for the QR Code concept, any chance of some plans for adding a small low-end camera?
Even if the camera is not very good (maybe a $20 USB webcam), and the picture is poor quality (perhaps a ~0.3 megapixel image), as long as the image of the QR Code can be captured, the software that attempts to discover the QR Code and pull the information out of the low-quality image will do the rest. Then, it's just up to the user to print out some QR code stickers. Actually, come to think of it, I bet there are probably some burritos out there with QR codes on the wrappers, pointing to some burrito website, that could be re-purposed to trigger the microwave.
There is a funny scene at the end of Disney's Carousel of Progress ride that shows exactly this - a "futuristic" family is gathered for the holidays while their voice-activated oven cooks in the background. As they make various unrelated comments that contain words like "up," "heat" etc, the oven responds and continues to increase the temperature on their Christmas turkey (while the family obliviously chatters on) until it is burnt to a crisp.
So far my efforts have been limited to hacking electricity and gas meters but this microwave is much more complex. I gave a talk on this last night at the HN London meetup. Slides will be online at http://unop.co.uk/dev/raspberry-pi-electricity-monitor/ soon. The videos will be online soon too I hope.
The Jetsons-eque toaster oven still requires you to put the bread in.
I suppose another way to put it is that "these things can work together" is far worse than "these things work together".
> If cooking instructions are posted for a 1000W microwave, you can request the instructions for a 700W microwave, and the cooking times will be automatically adjusted
http://www.google.com/patents/US6124583
Makes you realize why there are no commercial implementations of this and why patents are terrible.
Appliance makers sit around all day thinking of new ways to entice people to buy new appliances, but in reality they know that the complexity comes back to bite them eventually and the majority of users just use the microwaves for heating water and making popcorn.
This whole "scan the UPC" thing? Not disruptive. It's been done before:
http://www.smarthome.com/13041/Beyond-Microwave-Oven/p.aspx
So the question is, do you really need disruption in this area? Are people really clamoring for an easier way to heat up their Lean Cuisine even though all they really need to do now is push the "4" button?
Both require radios of some stripe, though. At that point, you might as well get away from the IR transmission method completely.
"Would you like a waffle?"