Live data from Hacker News

Wanted to spy on my dog, ended up spying on TP-Link

kennedn.com

31–40 of 181 posts

Re: Wanted to spy on my dog, ended up spying on TP-Link

#32
post #20

Earlier quoted context omitted.

AT&T routers, for example, ship like this. There's a wifi network and a wifi password printed onto the device. But that also means then that often anyone with physical access can easily get into the device. The complicated password provides an additional layer of illusion of security, because people then figure "it's not a default admin password, it should be good". The fundamental problem seems to be "many people ar…

If you have physical access you can just factory reset the device and onboard it with the normal flow though

[deleted]

Re: Wanted to spy on my dog, ended up spying on TP-Link

#33
post #14
post #5

So we're at the point that finding hardcoded admin passwords is no big deal.

It's a hardcoded default password, not a permanent backdoor. If I'm understanding the post correctly, the user changes it as part of the onboarding flow. This is the way most apps work if they have a default password the user is supposed to change.

on the other hand "onboarding" seems to be a less offensive normalizing word which really means "ask permission to use device"...

Re: Wanted to spy on my dog, ended up spying on TP-Link

#34
post #18
post #14

Earlier quoted context omitted.

It's a hardcoded default password, not a permanent backdoor. If I'm understanding the post correctly, the user changes it as part of the onboarding flow. This is the way most apps work if they have a default password the user is supposed to change.

The device should ideally have some kind of secret material derived per device, like a passphrase generated from an MCU serial number or provisioned into EEPROM and printed on a label on the device. Some form of "enter the code on the device" or "scan the QR code on the device" could then mutually authenticate the app using proof-of-presence rather than hardcoded passwords. This can still be done completely offline w…

I agree that would be nice, but it also doesn't sound all that practical for a small vendor.

I used to sell a home networking device,[0] and I wouldn't do what you're describing. If there were an issue where the labels calculate the wrong password or the manufacturer screws up which device gets which label, you don't find out until months later when they're in customer hands and they start complaining, and now you have to unwind your manufacturing and fulfillment pipeline to get back all the devices you've shipped.

All that to protect against what attack? One where there's malicious software on the user's network that changes the device password before the user can? In that case, the user would just not use the camera because they can't access the feed.

[0] https://mtlynch.io/i-sold-tinypilot/

Re: Wanted to spy on my dog, ended up spying on TP-Link

#35
post #34
post #18

Earlier quoted context omitted.

The device should ideally have some kind of secret material derived per device, like a passphrase generated from an MCU serial number or provisioned into EEPROM and printed on a label on the device. Some form of "enter the code on the device" or "scan the QR code on the device" could then mutually authenticate the app using proof-of-presence rather than hardcoded passwords. This can still be done completely offline w…

I agree that would be nice, but it also doesn't sound all that practical for a small vendor. I used to sell a home networking device,[0] and I wouldn't do what you're describing. If there were an issue where the labels calculate the wrong password or the manufacturer screws up which device gets which label, you don't find out until months later when they're in customer hands and they start complaining, and now you ha…

TP-Link is far from being a small vendor, though.

Re: Wanted to spy on my dog, ended up spying on TP-Link

#36
post #15
post #9

Earlier quoted context omitted.

Home Assistant is making more and more sense to make your own fully local and private home automation system.

I love it! But my setup has a lot of sharp edges. It's a combo of things where the "standards compatible" way to connect to HA lacks things like camera control, by dastardly vendors like Chamberlain who basically killed HA support for spite, and finally, by having to use Google or Amazon for voice assistants. My #1 wish would be for someone to build a HA-native voice assistant speaker. I'd pay $100 each for a smart s…

Chamberlain can't change MyQ to get around the fact that HA can operate the switch in your garage with a simple controller attached to it. It is very annoying that they are anti-hacker though.

Re: Wanted to spy on my dog, ended up spying on TP-Link

#37
really like how this blog is written. a lot of writeups like this recently have been generated by an LLM, and it's quite distracting to read - this was a pleasant surprise. it strikes a good balance between technical and laid-back

(yes i know the cover image is AI-generated, that's incidental to the content)

Re: Wanted to spy on my dog, ended up spying on TP-Link

#38
post #35
post #34

Earlier quoted context omitted.

I agree that would be nice, but it also doesn't sound all that practical for a small vendor. I used to sell a home networking device,[0] and I wouldn't do what you're describing. If there were an issue where the labels calculate the wrong password or the manufacturer screws up which device gets which label, you don't find out until months later when they're in customer hands and they start complaining, and now you ha…

TP-Link is far from being a small vendor, though.

Ah, I see. I thought OP used TP-Link for their router. I missed that Tapo (the camera manufacturer) is a subsidiary of TP-Link.

Re: Wanted to spy on my dog, ended up spying on TP-Link

#39
post #20

Earlier quoted context omitted.

AT&T routers, for example, ship like this. There's a wifi network and a wifi password printed onto the device. But that also means then that often anyone with physical access can easily get into the device. The complicated password provides an additional layer of illusion of security, because people then figure "it's not a default admin password, it should be good". The fundamental problem seems to be "many people ar…

If you have physical access you can just factory reset the device and onboard it with the normal flow though

That's fair, though at least resetting would indicate that an attack happened. Default passwords and printed passwords can result in undetected attacks, which are arguably worse.

Re: Wanted to spy on my dog, ended up spying on TP-Link

#40
post #35
post #34

Earlier quoted context omitted.

I agree that would be nice, but it also doesn't sound all that practical for a small vendor. I used to sell a home networking device,[0] and I wouldn't do what you're describing. If there were an issue where the labels calculate the wrong password or the manufacturer screws up which device gets which label, you don't find out until months later when they're in customer hands and they start complaining, and now you ha…

TP-Link is far from being a small vendor, though.

I think he has it backwards: Easy for a small vendor, very hard for a large one.
Post reply on HN