Live data from Hacker News

Home Assistant blocked from integrating with Garage Door opener API

home-assistant.io

271–280 of 655 posts

Re: Home Assistant blocked from integrating with Garage Door opener API

#271

Earlier quoted context omitted.

Nope, a Microsoft account is not enough. It must be an @outlook.com address, or any registered company/school/university address. It took me almost 3 days to find the problem. Microsoft changed that and between all "answers" there is only one single thread in the Microsoft forums that had the solution.

What does "any registered company/school/university address" mean? Some years ago, I activated some Office licenses using my company email; we never did any hosting with O365 or whatever was it's predecessor, and at the time, everything went fine. All I had to do was to create live account using that email address.

The error message is along the lines: "You can't sign in here with a personal account. Use your work or school instead".

Which means, that you need to associate your existing account with an @outlook.com address. It seems, that Microsoft changed that requirement somewhere in 2020/2021.

Yes, previously Microsoft account with whatever email address was enough. But they changed that.

I stumbled upon that while upgrading to new hardware, which requires new activation of the Office products.

Re: Home Assistant blocked from integrating with Garage Door opener API

#272

Earlier quoted context omitted.

Why not simply allow HA to integrate on site rather than to have to go through some crappy service that likely will not last the lifetime of the doors in the first place?

I'm not saying owners should be completely barred from modifying their systems but there are security implications to bypassing their centralized / cloud-based authentication. It'd be possible for a knows-enough-to-be-dangerous customer to modify their system in such a way that they unwittingly allow unauthenticated local access. From my point of view, Chamberlain/MyQ should be totally indemnified in such scenarios b…

Deadbolt companies aren't liable for customers leaving their products unlocked, right? Is this so different?

Re: Home Assistant blocked from integrating with Garage Door opener API

#273
post #138
post #15

Based on my local big box store and garage installer availability, Chamberlain has a de facto monopoly. They also pulled the rug out from under customers: that behavior had been in Home Assistant since 2017, and it's their own recent changes that caused the alleged "DDoS". They say it's to promote official products, but the company previously had a local hub that didn't require their cloud service and discontinued it…

Huh, nice. I went with a dry contact kit from Athom but status feedback is tempting (mine just uses a reed switch to detect state): https://www.athom.tech/blank-1/garage-door-opener-for-esphom...

Getting status information from the door is the entire value prop from something like the ratgdo. It's the only reason I ordered one. Otherwise, momentary switches with HA integration are readily and cheaply available.

Re: Home Assistant blocked from integrating with Garage Door opener API

#274
post #7

From company statement: > Our customers rely on us to make access simple without sacrificing quality and reliability. Unauthorized app integrations, stemming from only 0.2% of myQ users, previously accounted for more than half of the traffic to and from the myQ system, and at times constituted a substantial DDOS event that consumed high quantities of resources. Yeah, that sounds plausible, because: - Home Assistant u…

> - Home Assistant users are power users, thus more likely to actually use the devices in question; >50% traffic from 0.2% of the users is far too big of a discrepancy to just explain it away with powerusers. Customers too have to follow a fair level of usage. > designed to discourage effective use (while maximizing data collection). What valuable data can they collect, if nobody is using it?

Valuable data is in the eye of the beholder: such as burglars, home invaders, stalkers, panty-sniffers, voyeurs, blackmailers, robbers, kidnappers, spies, squatters, vagrants, wild teenagers and dumb adults that are scouting for their next juicy target.

Re: Home Assistant blocked from integrating with Garage Door opener API

#275

Partially responsible for this. (Sold Lockitron to Chamberlain in 2017 which became the basis for Amazon Key integrations.) Contrary to the popular sentiment in a lot of the comments here, there’s not much value in the analytics. As we all painfully found out in the 2010’s, there are only two viable recurring revenue streams in the IoT space - charging for video storage and charging for commercial access. Chamberlain…

This is what I love hacker news, a comment from an actual subject matter expert.

Re: Home Assistant blocked from integrating with Garage Door opener API

#276

Any IOT device that requires the cloud for functionality is a trap. I bought a Miku baby monitor specifically because of the 2 devices that offered a feature I wanted, Miku had no subscription fees. And they advertised that they never would. It cost $400. Then they went bankrupt and during bankruptcy they sent out a proposal to start charging for previously free features. Then they retracted that proposal. Not sure i…

Sounds like bait and switch to me, which is illegal. You can report this action to the ftc https://reportfraud.ftc.gov/#/

Especially that it was a new company deliberately disabling the devices, it sounds like a straightforward criminal CFAA violation. Of course, such laws are really only for persecuting little guys doing uppity things like trying to make scientific knowledge available to the public. Even if you could convince any six-degrees-of-golf-buddies prosecutor to take the case, I'm sure the malicious crackers have some fake contract to hide behind that claims a transferable right to remotely destroy your property.

Re: Home Assistant blocked from integrating with Garage Door opener API

#277
They can lock you out of the API, but they can't stop you from installing hardwired devices that simulate a press of the open/close button.

I just chucked my MyQ device and replaced it with a Meross MSG100HK--it works perfectly and natively with HomeKit--no cloud service required. Incidentally, the latency is much lower too.

The device is basically a wifi-enabled, USB powered "dry contact" switch. You connect the pigtail in parallel with your existing wired open/close button. There's also a magnetic sensor (similar to what old door alarms used) that goes near the door to verify it has closed.

Re: Home Assistant blocked from integrating with Garage Door opener API

#278

Earlier quoted context omitted.

I'm quite confident my parents and the many people like them in the world would not find running VPN/Tailscale/ZeroTier to be "easy." Nor would they have any idea how to troubleshoot when those services have issues. Nor would they want to play intermediary between Tailscale and myQ customer support to figure out which one is broken and fix it. Having options like this is great for powerusers, but the vast majority of…

My wife doesn't understand what I do on the computer all the time and she's pretty doubtful of my claim that server racks are normal household items. Nevertheless setting up the HA app on her phone with a Wireguard VPN was super simple and she's got a good handle on that. That being said, setting up the HA and Wireguard server is definitely a more demanding experience. Although once setup it's pretty much a once and…

>she's pretty doubtful of my claim that server racks are normal household items.

Haha, she's got you there.

Re: Home Assistant blocked from integrating with Garage Door opener API

#279

Earlier quoted context omitted.

I'm not saying owners should be completely barred from modifying their systems but there are security implications to bypassing their centralized / cloud-based authentication. It'd be possible for a knows-enough-to-be-dangerous customer to modify their system in such a way that they unwittingly allow unauthenticated local access. From my point of view, Chamberlain/MyQ should be totally indemnified in such scenarios b…

Deadbolt companies aren't liable for customers leaving their products unlocked, right? Is this so different?

That makes sense to me but I'm not sure your average judge/juror would see it so simply--especially given that in most cases it'd be a lot easier to tell if/when a deadbolt has been modified.

Re: Home Assistant blocked from integrating with Garage Door opener API

#280

Partially responsible for this. (Sold Lockitron to Chamberlain in 2017 which became the basis for Amazon Key integrations.) Contrary to the popular sentiment in a lot of the comments here, there’s not much value in the analytics. As we all painfully found out in the 2010’s, there are only two viable recurring revenue streams in the IoT space - charging for video storage and charging for commercial access. Chamberlain…

So you're saying that retailers will pay Chamberlain to act as more or less a clearinghouse for package deliveries in my garage, and that in order to successfully operate this model Chamberlain needs to funnel all users through their proprietary channels in order to fully vet the delivery transaction? Or at least to prevent HA users from nibbling at Chamberlain's lunch with DIY equivalents? Do you think that they will pull back from this move given the pushback?
Post reply on HN