447
people found this helpful, as of 2023
ranked #44,009 most helpful
out of 571,544,897 reviews
★★★★☆
and get into the app where you can easily register new devices and use them
It's 20 bucks, it's tiny, and it does what it says. The setup was a breeze, and the app lets you configure schedules, countdowns and just manually turn it on or off whenever. And it works from anywhere. It's almost magical. Oh, and it does seem to track electricity usage, which is neat.
However, there are a few things to be aware of:
- The android app requires permissions it really shouldn't need (Camera, Phone and Storage access). If you're on a recent enough Android version (6+), you can remove those permissions without seemingly breaking any functionality.
- The app asks you to register an account to use it, and requires you to receive an email with a validation code to do so, but the email never came, despite repeated attempts. However, you can "skip" the account login part, face some vaguely dire-ish warning for doing so, and get into the app where you can easily register new devices and use them.
- The whole package is made in China. The hardware, the firmware on the hardware, and the app. The app will send analytics to taobao.com, logs to umeng.com, etc. If you happen to browse the Settings->Feeback section of the app, you will be treated to a few seconds of chinese text before the english version loads.
- The hardware comes with a seemingly unlimited free subscription to a cloud service that mediates every operation. It maintains a constant websocket connection with one of two linode-hosted servers, from which it gets its instructions. This is how the mobile apps are able to operate the device from anywhere. This is great, up until the servers go away, and all those devices transform into pumpkins. This is a common situation with many IoT devices, but it bears to be repeated. Or maybe said once, since none of this product's descriptions mention this.
Which brings me to my current thought about this gizmo:
- the aforementioned websocket connection is not encrypted. A boot time, the device uses DHCP nicely, then resolves a hostname and proceeds to establish a websocket connection. From there, various bits of mostly self-documenting JSON fly back and forth to perform various functions.
- it is very likely possible to design a little websocket proxy that would put itself in between the device and its cloud, assuming the DNS server your DHCP server the device talks to is willing to point it at your proxy (custom router software like dd-wrt or tomato would be a great way to do that)
- at that point, it's not terribly hard to imagine short-circuiting their cloud service altogether. Or adding support for some IFTTT custom action.
In short, I strongly suspect this device can be hacked into being part of something greater than itself, although it seems like it may require having a little server sitting somewhere and being able/willing to tweak your LAN DNS configuration in slightly unusual ways.
February 2017 · Tools and Home Improvement · verified purchase