I have this old TP-Link smart lightbulb, it’s the only thing that’s IoT and on WiFi in my house.
Looking through pfBlocker logs for fun, and noticed it’s been trying to connect to the Tor network.
Oh! Also, it’s been uploading and downloading 100+ MB of data a day.
You’re aware that you can send whatever traffic you want over any port right? Using 123/udp for NTP is just convention. A light bulb that is updating its time over Tor is suspect. TP-Link would have their own infrastructure or use public pools to update the device’s time.
The Tor analysis is suspect in the first place. The whole thing is much ado over nothing.