back to article Hacking LED Halloween masks is frighteningly easy

Hacking makes the holidays so much more enjoyable, and nothing says trick or treat quite like pwning LED Halloween masks belonging to every neighborhood kid during candy-collection hours. After purchasing a Bluetooth Low Energy (BLE) enabled mask with a programmable app for his family's "anything that glows" themed Halloween …

  1. IGotOut Silver badge

    TBH

    I'd be surprised if there WAS security built in.

  2. elsergiovolador Silver badge

    Costume

    Take a photo of yourself today.

    Save clothes you have on right now.

    Next year at hello whine, wear those same clothes and take a photo.

    Rinse and repeat until you no longer can dress yourself and have no helpers.

    If someone asks you say it's me suspended in time.

  3. the hawk

    Leaving a trail of dead or zombified masks behind you as you walk the streets seems appropriately creepy, if there are enough of them to see the plague unfold.

    1. Valeyard

      if only each mask could in turn pair with and share the image with other masks it was near that'd be a great zombie theme

    2. JPCavendish

      To complete the zombie aspect; program each mask with a zombie image, AND to infect other masks it comes across and replace them with a zombie image. etc etc. Then send them out into the world to complete the spread of the zombie apocalypse...

  4. Pascal Monett Silver badge
    Facepalm

    "BLE enabled mask with a programmable app"

    Um, this is supposed to be a surprise ?

    You really think that a company selling Halloween masks is going to bother itself with security ?

    What's the worst than can happen ? Tell me, please.

    1. BebopWeBop
      Devil

      Re: "BLE enabled mask with a programmable app"

      Well,I have seen suggestions of a large number of comedy penises roaming the street, with others saying 'hit me you arese'

    2. A. Coatsworth

      Re: "BLE enabled mask with a programmable app"

      >>What's the worst than can happen ? Tell me, please.

      Given that each mask on the streets probably means one "Shining Mask" app installed, from a company with such ironclad approach to security, I can see the worst that could happen being really ugly

    3. Paul Hovnanian Silver badge
      Devil

      Re: "BLE enabled mask with a programmable app"

      Hundreds of little Jeffrey Epsteins wandering my neighborhood.

      1. Anonymous Coward
        Anonymous Coward

        Re: "BLE enabled mask with a programmable app"

        Worse, hundreds of little Trumps

  5. Anonymous Coward
    Anonymous Coward

    Fun fun fun

    The masks do look like fun, plus safer than tartrazine and related Mountain Dews ... but at 2,000 to 3,600 SMD RGB LEDs model 2121 eating 250 mW (max) of juice each, ain't they 400 to 900 Watt affairs (toaster range) that could run through batteries in a second flat at full tilt? The shop page just mentions 4-hour USB-C charging and 8-hours use which I'd guess corresponds to relatively low mean brightness levels ... or all LEDs off(?).

    Regular ole' masks, or even makeup, might provide as much fun with better mileage imho, plus safety from hackers and your face looking like crispy bread!

    1. Anonymous Coward
      Anonymous Coward

      Re: Fun fun fun

      LEDs are plenty bright at 20mW, and very usable at under 10mW, why would you want to run them at 250mW when they're against your face?

      1. Anonymous Coward
        Anonymous Coward

        Re: Fun fun fun

        Yeah, you and me both, but what about a hacker of the miscreant type ... should she be expected to respect safety limits?

    2. Anonymous Coward Silver badge
      Facepalm

      Re: Fun fun fun

      I don't know where you got your figures from, but those LEDs normally run on just a few milliamps, at about 3 volts, so let's call it 15mW each. Extrapolate that and you're looking at 2-3 watts, which ties in with battery capacity. Remember that for most designs only a subset of the LEDs will be illuminated.

      2121 as an SMD descriptor just tells you the physical size (2.1mm by 2.1mm) not a particular product.

      1. Anonymous Coward
        Anonymous Coward

        Re: Fun fun fun

        Good point! I based my calcs on the WS2816B-2121 that can pull 45 mA at 5.5 Volts (so 250 mW), but some common 64x64 flat panels (4096 LEDs) seem to pull less, like 19 W or 60 W ... yet some are puzzling, reporting 25 W of "module power" but 800 W of "maximum power consumption" (under which conditions ... who knows!? who cares? it's just fun????).

        Bottom line, the RGB LED mask vendors should definitely provide the electrical specs of their gizmos rather than vague geez-woowee-type statements (yes, on their websites). If the things can be easily hacked (per TFA), and they're using WS2816B-2121-type LEDs (for high brightness as they state) the potential for tangible harm may well be there ... which is quite frightening imho.

    3. JPCavendish

      Re: Fun fun fun

      Forget light, 3,000 SMD LEDs at 250mW each would be enough to provide thrust. Point it downward and you could levitate on it.

      10-15mW each is far more likely.

  6. Pulled Tea
    Joke

    Meanwhile, your humble vulture has already shared the code with all of her friendly neighborhood teen hackers and can only hope that one of them tries it out while trick-or-treating.

    You know this is how you get goatse, right?

    1. Anonymous Coward
      Anonymous Coward

      or an IoT penis on your face. This could be a truly historic moment in history. The first digital dick facing.

    2. cyberdemon Silver badge
      Childcatcher

      To be fair, the dev has deliberately left out the bit that encodes a custom image for the masks. So anyone casually downloading and running this will only be able to display the standard fox face on some unsuspecting trick-or-treater.

  7. JLV Silver badge

    One thing about being a big Sci Fi reader is trying to project into a reverse Connecticut Yankee situation. Imagine you're a tech-savvy 1950s dude(tte) who went into a coma and has just been revived with the wonders of modern medicine...

    What is this article about? The words are English but make little sense. What is "hacking" and once you understand the term, what on earth does it have it to do with Halloween masks? Why would someone computerize a Halloween mask? Probably with more computing horse power than the Space Shuttle? Why would someone hack it?

    Jump forward to 2150 and think about the sweet summer children of the early 21st century that allowed unprotected computing nodes to proliferate. A hacked mask could do all sorts of things, including eavesdropping on nearby Bluetooth emissions and reporting back to far-removed surveillance nodes via other hacked consumer devices in a mesh.

    Much like late 1990s folk who would send each other meme .EXEs via email for entertainment. And run the ones they received.

    1. Jellied Eel Silver badge

      .. reporting back to far-removed surveillance nodes via other hacked consumer devices in a mesh.

      Surveillance nodes you say? So I'm kinda wondering what fun could be had with the HD mask vs facial recognition systems. Tempted to buy one now, especially if it's easy to load it with your own images. But also perhaps wait. 2.1mm pixels this year, and wonder how long it'll take to reduce that to 1mm or smaller.

  8. Elongated Muskrat Silver badge

    Compromising Children's Halloween Masks?

    What could possibly go wrong?

    It's almost time, kids.

    1. LBJsPNS Silver badge

      Re: Compromising Children's Halloween Masks?

      The most annoying song ever. Didn't even have to click on the link.

      1. Elongated Muskrat Silver badge

        Re: Compromising Children's Halloween Masks?

        The masks contain ear-worms. Amongst other things.

  9. John Brown (no body) Silver badge

    Trick or treat?

    Well, nice to the "trick" part of trick or treat being put to good effect. Mostly these days it's entirely about the treat part. Or demanding money with menaces as some would see it :-)

    It did, after all, get imported to the US from Scotland, via Canada, and was originally more about the participants performing some little act or song and then getting a treat for doing so.

  10. ComicalEngineer Silver badge
    Devil

    I love Halloween...

    Especially when our large dog hears people at the door and kicks off with his equally large and loud bark.

    No need for masks, the fear on the little monsters' faces is enough. ;-)

  11. Anonymous Coward
    Anonymous Coward

    Does it also work on Vapes ?

    From the discarded and smashed examples littering our streets there seems to be some electronics in there so I wouldn't be surprised if BLE was in there too.

    You could remotely turn the blighters off in public spaces.

    I just realized there are more "intimate" BT/BLE controlled "adult devices" that possibly don't require pairing ...

    1. JPCavendish

      Re: Does it also work on Vapes ?

      "I just realized there are more "intimate" BT/BLE controlled "adult devices" that possibly don't require pairing ..."

      There are. Walk around with a suitably configured RPI and all you have to do is listen for the unexpected gasp. Or shriek, depending on how you've configured it.

    2. sedregj
      Gimp

      Re: Does it also work on Vapes ?

      "Teledildonics" is a search term ...

    3. Anonymous Coward
      Anonymous Coward

      Re: Does it also work on Vapes ?

      Set them all to vibrate

      - 1812 overture

      - crazy frog theme

      - wah wah wah let down type sound

      - hotel California

      - medley of Disney songs

    4. Simon Harris Silver badge

      Re: Does it also work on Vapes ?

      From these very pages from a few years ago…

      https://www.theregister.com/2018/02/02/adult_fun_toy_security_fail/

  12. Anonymous Coward
    Anonymous Coward

    I see no downside.

    1. that one in the corner Silver badge

      My LED mask just came on full brightness; I see nothing at all except purple splodges.

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon