Security researchers from MWR InfoSecurity have discovered some flaws in the Twinkly IoT lights that could be exploited to display custom lighting effects and to remotely turn off them. The experts were able to control the lights to play Snake, the popular game developed by Nokia in 1990s. The communications from the application to the lights is done through RESTful HTTP API endpoints on the lights on port 80. The communication is not encrypted, however the WiFi password is sent encrypted during set up (albeit trivial to decrypt)”]
Source: https://securityaffairs.co/wordpress/79130/hacking/twinkly-christmas-lights-hacking.html