Skip to main content

Internet-connected hot tubs can be hacked and controlled remotely

Lars Plougmann/Flickr

Hot tubs are supposed to be a great way to relax, but that’s a little harder to do when you aren’t in control of them. Thousands of hot tubs running a system made by Balboa Water Group have exploits that can be hacked to allow malicious actors to remotely control them, according to a recent report from the BBC.

The issue, discovered by security researchers at the U.K.-based security firm Pen Test Partners, stems from lapses in a mobile app that enables hot tub owners to control their tubs from their phone. Attackers could theoretically gather information found on public resources to find homes with the vulnerable hot tubs and target them. The malicious actors could use third-party databases to find the GPS location data of a given tub and hijack it. There is no authentication that would prevent the attackers from getting into the system.

Recommended Videos

Once the attackers have picked their target, they can assume control of the tub remotely. That means they can make the temperature hotter or colder, take over the pumps and jets, and change the lights. The entire attack can be carried out over a smartphone or laptop.

Please enable Javascript to view this content

According to the BBC, Balboa Water Group was caught off guard by the report and said it was “surprised” to learn of the vulnerability. The mobile app that gives users the ability to remotely control their hot tub has been available for about five years and users have never reported any issues or hacking attempts, according to the company.

Balboa Water Group is in the process of addressing the security flaw and plans to have it patched up by the end of February — which is a long time to leave a known flaw unpatched and available to exploit. The company is working with its customers to set up individual usernames and passwords so they can secure their apps. It previously opted not to have users set up personal accounts because it wanted to simplify the activation process. While that might have made things more convenient, the decision also exposed users to having their personal time in the hot tub interrupted by hackers.

AJ Dellinger
AJ Dellinger is a freelance reporter from Madison, Wisconsin with an affinity for all things tech. He has been published by…
Apple’s AI hiccups might have delayed its iPad-like smart home hub
Amazon Echo Hub against Apple background.

It was late in 2024 when we first heard rumors of a new HomeKit device that would essentially blend a HomePod and iPad, and serve it atop an AI software platter. It was later reported that Apple is developing two versions of this device, and one of them could arrive in 2025.

It seems those plans have been pushed further into the future, thanks in no part to Apple’s struggles with AI development. “At one point, the company had hoped to announce this product in March. But because the device, to an extent, relies on the delayed Siri capabilities, it has been postponed as well,” says a Bloomberg report.

Read more
Dryers hurt the wallet and our planet. Research gives a simple solution
LG Dryer with an open door.

A couple of years ago, experts at the City University of Hong Kong reported that a single clothes dryer can pump up to 120 million microfibers into the environment. When ingested or inhaled, especially if they are synthetic in nature, they can lead to numerous health problems, while also carrying other pollutants.

Now, another research says the humble drying appliance in our homes contributes to tons of carbon dioxide blasted into the air and costs thousands of dollars in electricity bills each year. The findings are quite an eye-opener, and so is the solution.
A massive cost and emission headache
As per the research published by the University of Michigan’s School for Environment and Sustainability, over 80% homes in the United State have a dryer, much higher than any other country in the world. They consume nearly 3% of a household’s electricity budget each year.

Read more
iRobot reveals gigantic lineup of affordable Roomba robot vacuums
All the upcoming Roomba robots on display

iRobot is one of the most popular manufacturers of robot vacuums, and its lineup is about to grow much more enticing. Several new models will be up for presale on March 18 -- all of which feature prices under $1,000. That makes them affordable alternatives to expensive options like the Roomba Combo 10 Max or Roborock Saros 10R, both of which carry hefty price tags of around $1,500. This is the largest product launch in the history of iRobot (featuring eight products), and it’s designed to offer a solution for every budget.

The most expensive of the bunch is the Roomba Plus 505 Combo Robot + AutoWash Dock. Designed with dual rotating mop pads that can swing outward, 70 times more suction than the older Roomba 600 series, and a LiDAR system that should deftly maneuver your home day or night, it looks like a well-equipped robot for $999.

Read more