A developer reverse engineered a defunct Estonian scooter company's Bluetooth protocol to restore functionality after the cloud service shut down. The investigation revealed a critical security vulnerability: all scooters used a hardcoded default key ("ffffffffffffffff") that was never changed by the manufacturer, allowing anyone to unlock and control any Äike scooter. The IoT module vendor confirmed this was a default value that should have been customized during development.
307 Impressions