Breaking
January 18, 2025

Fighting to Keep Bluetooth Thermometers Hackable Tom Nardi | usagoldmines.com

Back in 2020, we first brought you word of the Xiaomi LYWSD03MMC — a Bluetooth Low Energy (BLE) temperature and humidity sensor that could be had from the usual sources for just a few dollars each. Capable of being powered by a single CR2032 battery for up to a year, the devices looked extremely promising for DIY smart home projects. There was only one problem, you needed to use Xiaomi’s app to read the data off of the things.

Enter [Aaron Christophel], who created an open source firmware for these units that could easily be flashed using a web-based tool from a smartphone in BLE range and opened up all sorts of advanced features. The firmware started getting popular, and a community developed around it. Everyone was happy. So naturally, years later, Xiaomi wants to put a stop to it.

The good news is, [Aaron] and [pvvx] (who has worked on expanding the original custom firmware and bringing it to more devices) have found a workaround that opens the devices back up. But the writing is on the wall, and there’s no telling how long it will be until Xiaomi makes another attempt to squash this project.

We can’t imagine why the company is upset about an extremely popular replacement firmware for their hardware. Unquestionably, Xiaomi has sold more of these sensors thanks to the work of [Aaron] and [pvvx]. This author happens to have over a dozen of them all over the house, spitting out data in a refreshingly simple to parse format. Then again, the fact that you could use the devices without going through their software ecosystem probably means they loose out on the chance to sell your data to the highest bidder…so there’s that.

The duo aren’t releasing any information on how their new exploit works, which will hopefully buy them some time before Xiaomi figures out how to patch it. In the short video below, [Aaron] shows the modified installation process that works on the newer official firmware. Unfortunately you now have to connect each unit up to the Xiaomi app before you can wipe it and install the open firmware, but it’s still better than the alternative.

 

This articles is written by : Nermeen Nabil Khear Abdelmalak

All rights reserved to : USAGOLDMIES . www.usagoldmines.com

You can Enjoy surfing our website categories and read more content in many fields you may like .

Why USAGoldMines ?

USAGoldMines is a comprehensive website offering the latest in financial, crypto, and technical news. With specialized sections for each category, it provides readers with up-to-date market insights, investment trends, and technological advancements, making it a valuable resource for investors and enthusiasts in the fast-paced financial world.

Recent:

US Treasury Department Exposed As Chinese Hackers Breach 400 Devices, Including Janet Yellen’s Compu...

No Crystal Earpiece? No Problem! Jenny List | usagoldmines.com

‘Phantom Hacker’ Drains $20,000 From Bank of America Account – Now the Bank Refuses To Reimburse: Re...

Trinteract Mini Space Mouse Does It In 3D Kristina Panos | usagoldmines.com

Android Head Unit Gets Volume Knob Upgrade Lewin Day | usagoldmines.com

New Bambu Lab Firmware Update Adds Mandatory Authorization Control System Maya Posch | usagoldmines....

You Can Build Your Own Hubless Roller Blades and Ride Off Road Lewin Day | usagoldmines.com

Hackaday Podcast Episode 304: Glitching the RP2350, Sim Sim Sim, and a Scrunchie Clock Dan Maloney |...

This Week in Security: Rsync, SSO, and Pentesting Mushrooms Jonathan Bennett | usagoldmines.com

Modding a Toddler’s Ride-On For More Grunt Lewin Day | usagoldmines.com

Packing Even More Features Into a Classic Radio Heidi Ulrich | usagoldmines.com

Neat Ring Clock Relies On Addressable LEDs Lewin Day | usagoldmines.com

Building a Raycaster Within Bash Lewin Day | usagoldmines.com

Repairing a Samsung 24″ LCD Monitor With Funky Color Issues Maya Posch | usagoldmines.com

Building a 3D-Printed Strandbeest Lewin Day | usagoldmines.com

Taser Ring Is Scary Jewelry You Shouldn’t Build Lewin Day | usagoldmines.com

Gimbal Clock Relies On Servos For Its Cool Movements Lewin Day | usagoldmines.com

Forgotten Internet: UUCP Al Williams | usagoldmines.com

Simple Hardware Store Hack Keeps Your PCBs Right Where You Want Them Dan Maloney | usagoldmines.com

Piezo Buzzer Makes a Drum Jenny List | usagoldmines.com

A Direct Conversion Receiver Anyone Can Build Jenny List | usagoldmines.com

Chainalysis Acquires AI Fraud Detection Firm That Has Teamed Up With Binance and Coinbase Daily Hodl...

All The Attacks on the RP2350 Elliot Williams | usagoldmines.com

Forget the Coax, Wire Up Your Antennas with Cat 6 Cable Dan Maloney | usagoldmines.com

FLOSS Weekly Episode 816: Open Source AI Jonathan Bennett | usagoldmines.com

Avian-Inspired Drones: How Studying Birds of Prey Brings More Efficient Drones Closer Maya Posch | u...

A Game Boy Speedometer, Just Because You Can Heidi Ulrich | usagoldmines.com

No Ham License? Listen Anyway in Your Browser Al Williams | usagoldmines.com

Using the ESP8266 for Low-Cost Fault Injection Tom Nardi | usagoldmines.com

Nice PDF, But Can It Run DOOM? Yup! Donald Papp | usagoldmines.com

Turning GLaDOS into Ted: A Tale of a Talking Toy Heidi Ulrich | usagoldmines.com

New York Attorney General Freezes $2,200,000 Worth of Crypto Stolen From Victims Across the US in ‘C...

Repairing a Real (and Broken) Apollo-era DSKY Maya Posch | usagoldmines.com

Head to Head: Servos vs Steppers Al Williams | usagoldmines.com

Audio on a Shoestring: DIY Your Own Studio-Grade Mic Heidi Ulrich | usagoldmines.com

Hackaday Europe 2025 Tickets on Sale, and CFP Extended Until Friday Elliot Williams | usagoldmines.c...

Procedurally Generated Terrain in OpenSCAD Tom Nardi | usagoldmines.com

The Many Leaning Towers of Santos, Brazil Lewin Day | usagoldmines.com

It’s a Doughnut, In Hardware Jenny List | usagoldmines.com

New Frontiers for Nissan Leaf Motor and Battery Bryan Cockfield | usagoldmines.com

Homebrew Retro Console Runs On PIC32 Lewin Day | usagoldmines.com

Selectively Magnetizing an Anti-Ferromagnet With Terahertz Laser Maya Posch | usagoldmines.com

Fluid Simulation Pendant Teaches Lessons in Miniaturization Dan Maloney | usagoldmines.com

Electromechanical 7-Segment Display Is High Contrast Brilliance Lewin Day | usagoldmines.com

Clever PCBs Straighten Out the Supercon SAO Badge Tom Nardi | usagoldmines.com

How Nyan Cat Was Ported To UEFI Lewin Day | usagoldmines.com

Raspberry Pi Hack Chat with Eben Upton Dan Maloney | usagoldmines.com

Keebin’ with Kristina: the One with the Holey and Wholly Expensive Keyboard Kristina Panos | usagold...

Using Audio Hardware To Drive Neopixels Super Fast Lewin Day | usagoldmines.com

Modern AI on Vintage Hardware: LLama 2 Runs on Windows 98 Donald Papp | usagoldmines.com

Custom Case Turns Steam Deck Into Portable Workstation Donald Papp | usagoldmines.com

Carnarvon’s Decommissioned NASA Satellite Dish Back In Service After 40 Years Maya Posch | usagoldmi...

Crypto Founder Pleads Guilty to $9,400,000 Ponzi Scheme That Defrauded Thousands of Investors Rhodil...

Hackaday Links: January 12, 2025 Dan Maloney | usagoldmines.com

Gaming Table has Lights, Action Al Williams | usagoldmines.com

Usagi’s PDP-11 Supercomputer and Appeal for Floating Point Systems Info Maya Posch | usagoldmines.co...

Second CNC Machine is Twice as Nice Elliot Williams | usagoldmines.com

Fraens’ New Loom and the Limits of 3D Printing Elliot Williams | usagoldmines.com

It’s A Bench, But It’s Not Benchy Jenny List | usagoldmines.com

Bad Apple but it’s 6,500 Regex Searches in Vim Maya Posch | usagoldmines.com

Retrotechtacular: The 1951 Telephone Selector Al Williams | usagoldmines.com

iFixit Releases Command Line Docs for FixHub Iron Tom Nardi | usagoldmines.com

Blinkenlights-First Retrocomputer Design Elliot Williams | usagoldmines.com

$2,000,000 Drained From Customers’ Bank Accounts in Just 8 Days, Says Financial Giant, Warning Scamm...

In Praise of Simple Projects Elliot Williams | usagoldmines.com

Comparing Ways to Add Threads to Your 3D Prints Maya Posch | usagoldmines.com

Embedding Lenticular Lenses Into 3D Prints Donald Papp | usagoldmines.com

Tactility; The ESP32 Gets Another OS Jenny List | usagoldmines.com

AA Battery Performances Tested, So Get The Most For Your Money Donald Papp | usagoldmines.com

T-Mobile Sued Over Massive Data Breach That Leaked Sensitive Info on 79,000,000 Americans Henry Kana...

The Engineer Behind Mine Detection Al Williams | usagoldmines.com

Losses From Crypto Hacks and Scams Soar in 2024, Exceeding $3,010,000,000: Blockchain Security Firm ...

Springs and Things Make for a Unique Timepiece Dan Maloney | usagoldmines.com

Bit-Banging the USB-PD Protocol Bryan Cockfield | usagoldmines.com

Life Without Limits: A Blind Maker’s Take on 3D Printing Heidi Ulrich | usagoldmines.com

SerenityOS On Real Hardware Jenny List | usagoldmines.com

Hackaday Podcast Episode 303: The Cheap Yellow Display, Self-Driving Under $1000, and Don’t Remix th...

This Week in Security: Backdoored Backdoors, Leaking Cameras, and The Safety Label Jonathan Bennett ...

RISC-V Microcontroller Lights Up Synth with LED Level Meter Dan Maloney | usagoldmines.com

A Low Effort, Low Energy Doorbell Al Williams | usagoldmines.com

It’s IP, Over TOSLINK! Jenny List | usagoldmines.com

Engineering Lessons from the Super-Kamiokande Neutrino Observatory Failure Dan Maloney | usagoldmine...

Man Loses $188,000 in Crypto Scam to Fraudster Posing As Childhood Friend: Report Rhodilee Jean Dolo...

Sheet Metal Forming With 3D Printed Dies Maya Posch | usagoldmines.com

Toner Transfer, but Not for PCBs Al Williams | usagoldmines.com

Retrotechtacular: Soldering the Tek Way Dan Maloney | usagoldmines.com

Writing a RISC-V OS From Scratch Al Williams | usagoldmines.com

Physical Media is Dead, Long Live Physical Media Maya Posch | usagoldmines.com

3DBenchy Starts Enforcing its No Derivatives License Maya Posch | usagoldmines.com

All-Band Receiver Lets You Listen to All the Radio at Once Dan Maloney | usagoldmines.com

Retro Big Iron for You Al Williams | usagoldmines.com

A Street For Every Date Jenny List | usagoldmines.com

Investigators to Search Through Do Kwon’s Personal Emails, Twitter Messages and Mobile Devices in Te...

24-Year-Old Arrested for Alleged $4,600,000 Crypto Scam That Defrauded 300 People: Report Mehron Rok...

Try a PWMPot Al Williams | usagoldmines.com

38C3: It’s TOSLINK, Over Long Distance Fibre Jenny List | usagoldmines.com

FLOSS Weekly Episode 815: You Win Some, You Lose Some Jonathan Bennett | usagoldmines.com

Running AI Locally Without Spending All Day on Setup Al Williams | usagoldmines.com

Tech In Plain Sight: Security Envelopes Kristina Panos | usagoldmines.com

Remotely Controlled Vehicles Over Starlink Tom Nardi | usagoldmines.com

Leave a Reply