Responses from alliance and vendors

Responses from Philips Hue

We here show the confirmation email from Philips, which acknowledged our reported vulnerabilities.

Responses from SmartThings

We here show the confirmation email from SmartThings. Specifically, analysts (1) acknowledged the seriousness of our reported vulnerabilities, (2) highlighted the potential widespread impacts, (3) admitted that addressing these vulnerabilities is difficult, and (4) showed interest in our Zigbee testing tool.

Amendment Report from Zigbee Alliance

We further collaborate with the Zigbee Alliance for the specification update. Attached is the confirmation from the alliance. Since the updates are still being finalized, we are sorry that currently we cannot share the detailed specification language (see requirements of Zigbee Alliance in the confirmation report). Please check our paper (Section 7) for the update description.


Amendment Report from Zigbee Alliance: Broken Aging Mechanism