Operation Smart Kettle – Börzels Blog
5 days ago
- Bought a wifi-controlled smart kettle and set it up using the Lidl Smart Home App.
- Network scan revealed only port 6668 open, but no identifiable service or banner.
- Set up a man-in-the-middle attack with a fake access point to capture traffic between app and kettle.
- No direct app-to-kettle traffic was observed; only TLS-encrypted communication with Azure cloud servers.
- Identified the WiFi module as Tuya, a major IoT-as-a-service provider with developer documentation available.
- OTA firmware flashing to run without Tuya cloud was possible for older devices, but this kettle was too new.
- No HTCPCP (HTTP 418) or direct local API was found on the kettle.
- Future hardware hacking is considered for further exploration.