I have this old TP-Link smart lightbulb, it’s the only thing that’s IoT and on WiFi in my house.

Looking through pfBlocker logs for fun, and noticed it’s been trying to connect to the Tor network.

Oh! Also, it’s been uploading and downloading 100+ MB of data a day.

    •  Auzy   ( @Auzy@beehaw.org ) 
      link
      fedilink
      3
      edit-2
      5 months ago

      How do you know it is? Dpi is often wrong about both protocol. And size

      123 isn’t the normal protocol though, so let’s assume it is malicious (I will admit I could be wrong here). Packet dumps is the way to prove it. If op posts packet dumps, that would be useful (as I could be wrong, the normal protocol is a different port generally though).

      Also, important to note that if they’re uk hs100 plugs, they have different firmware too… The UK ones have one of the protocols shut off