Hasty Briefsbeta

Bilingual

Operation Smart Kettle – Börzels Blog

5 days ago
  • Bought a wifi-controlled smart kettle and set it up using the Lidl Smart Home App.
  • Network scan revealed only port 6668 open, but no identifiable service or banner.
  • Set up a man-in-the-middle attack with a fake access point to capture traffic between app and kettle.
  • No direct app-to-kettle traffic was observed; only TLS-encrypted communication with Azure cloud servers.
  • Identified the WiFi module as Tuya, a major IoT-as-a-service provider with developer documentation available.
  • OTA firmware flashing to run without Tuya cloud was possible for older devices, but this kettle was too new.
  • No HTCPCP (HTTP 418) or direct local API was found on the kettle.
  • Future hardware hacking is considered for further exploration.