wespeakiot.bsky.social

@wespeakiot.bsky.social

The IoT & AI blog for those who actually build it. www.wespeakiot.com

Germany's regulator sees no grounds to ban Meta's camera glasses: the LED warns bystanders. Meta's own policy paper says that LED is off during AI features. We asked. The agency has never inspected the model in the complaint, and cannot share an assessment of the AI modes at present.

Meta's AI Modes Record Without the LED. Should Germany's Regulator Reconsider? - We speak IoT

Meta's own documents describe AI modes with the capture LED off. Germany's regulator has no assessment to share.

wespeakiot.com

Most cellular IoT modules run Android on a Cortex-A7 behind the radio. Researchers showed a hostile SIM card can reach it directly via a documented spec feature. Code execution on an EV charger, file theft, 2G downgrade. www.wespeakiot.com/proactive-si...

Proactive SIM: How a Hostile SIM Card Takes Over IoT Modems - We speak IoT

University of Birmingham at USENIX WOOT: six of eight IoT modules tested expose an AT command interface to the SIM card.

wespeakiot.com

"Set it and forget it" belongs to the past! The EU Cyber Resiliance Act forces IoT device manufacturers to put more effort in security-by-design! @prexclusiv.bsky.social 's Dirk Roebers "maybe manufacturers will learn something after all!" Read more now at #WeSpeakIoT

Set It and Forget It – Cyber Resilience Act Ends the Free Ride for Disposable IoT - We speak IoT

The Cyber Resilience Act ends disposable IoT: security-by-design, mandatory updates, 24-hour breach reporting. What manufacturers now face.

wespeakiot.com

Hoymiles solar inverters give up their serial number, the only thing "protecting" them, unencrypted, the moment anyone sends a simple radio query. Result: attackers within ~350m can shut them off, rewrite grid settings, or brick them via firmware as a security researcher with the @ccc.de discovered.

Unprotected Over the Air: The Security Flaws in Hoymiles Inverters

Hoymiles microinverters can be switched off and manipulated over radio without authentication. The flaws and how to protect your system.

wespeakiot.com

It reads like a scene from Stephen King's "Maximum Overdrive" — machines turning on their owners. But this time it's not a comet. It's a hardcoded backdoor a manufacturer built into every robot lawn mower it sold. A researcher hijacked one from across the planet. www.wespeakiot.com/when-the-man...

When the Manufacturer Steers Your Mower, Stephen King Comes to Mind - We speak IoT

Yarbo's robot mower shipped with a factory-built backdoor and a universal root password. Why a high price tag buys no security.

wespeakiot.com

💡 Your smart bulb (and more) was chatting in plain text: TP-Link Tapo L535E, P300, and D100C transmit setup data over Bluetooth without encryption. An attacker within 10–30 meters during initial setup could intercept configuration data or hijack the device. www.wespeakiot.com/tp-link-tapo...

Bluetooth Flaw in TP-Link Tapo Devices: When Smart Bulbs Broadcast in Plain Text - We speak IoT

TP-Link Tapo devices transmit setup data unencrypted via Bluetooth. CVE-2026-34126 affects smart bulbs, power strips, and doorbells.

wespeakiot.com

The IoT device you ship today may still be running when a quantum computer can break its encryption. NIST finalized post-quantum standards in 2024. The EU mandates migration of critical systems by 2030. The window is narrower than you think. www.wespeakiot.com/quantum-safe...

Quantum-Safe IoT: Why the Cryptography Migration Cannot Wait - We speak IoT

Post-quantum cryptography meets IoT: what NIST standards, the EU roadmap, and global algorithm divergence mean for developers and decision-makers.

wespeakiot.com

Your Android TV box might have a second job. A botnet called xlabs_v1 hijacks cheap smart TVs and IoT devices through an open developer port, then runs a bandwidth test to sort them into pricing tiers before renting them out for DDoS attacks.

xlabs_v1: The Botnet That Rents Out Your Android TV Box as a DDoS Weapon - We speak IoT

xlabs_v1 exploits open ADB port 5555 to hijack Android TV boxes for DDoS-for-hire attacks — with bandwidth profiling and 21 flood

wespeakiot.com

96 million SIM cards in Germany. Not in phones but in machines and devices. The VATM telecoms study 2026 has a quiet IoT story buried in its numbers. M2M is the only segment actually growing. And 5G area coverage still has a gap — right where the sensors are.

96 Million Devices on Mobile Networks: What the VATM Telecoms Market Study 2026 Reveals About the German IoT Market - We speak IoT

VATM 2026 study: 96M M2M SIM cards in Germany and a 5G coverage gap that hits IoT deployments in rural areas hardest.

wespeakiot.com

You bought the trackers. Datasheet said 5 years. 18 months later: silence. IoT battery life isn't a hardware spec, it's a system outcome. 5 factors decide what you actually get: transmission interval, retry behavior, sleep modes, temperature, and protocol choice. Full breakdown 👇

IoT Device Battery Life: What Datasheets Don't Tell You and the Questions Decision-Makers Should Ask - We speak IoT

IoT battery life: Why datasheets rarely deliver on their promises in the real world – and five questions every decision-maker should ask.

wespeakiot.com

The cheap AI era is over. OpenAI missed its targets. Anthropic is rationing capacity. GPU prices up 48% in two months. If your IoT project depends on cloud AI, you're sitting on a risk you may have never formally assessed. 👇 www.wespeakiot.com/the-end-of-c...

The End of Cheap AI: And What It Means for Connected Devices - We speak IoT

OpenAI and Anthropic face capacity crunches and rising prices. What the AI infrastructure crisis means for IoT projects and edge AI.

wespeakiot.com

Neato Cloud Shutdown Update: Vorwerk announces replacement of affected robot vacuums with a Kobold VR7. Two days earlier, Italy's consumer protection authority searched their offices. What this means for the IoT industry: www.wespeakiot.com/neato-shutdo...

Neato Shutdown: Vorwerk Swaps Devices as Italian Watchdog Investigates - We speak IoT

Italy's AGCM has opened formal proceedings against Vorwerk over the Neato cloud shutdown – a landmark case for the entire IoT industry.

wespeakiot.com