Live data from Hacker News

Wanted to spy on my dog, ended up spying on TP-Link

kennedn.com

91–100 of 181 posts

Re: Wanted to spy on my dog, ended up spying on TP-Link

#91

IoT security is generally terrible, but the fact that consumer routers are essentially unaudited black boxes processing all your network traffic is genuinely concerning. Most people have no idea their router firmware hasn't been updated in years and is probably running known CVEs. The supply chain trust model for networking hardware is broken.

The solution is pfsense

The soulutions is iptables.

The solution is nftables.

The solution is bpf.

The solution is emacs-m-x-butterfly-bpf.

Re: Wanted to spy on my dog, ended up spying on TP-Link

#92

IoT security is generally terrible, but the fact that consumer routers are essentially unaudited black boxes processing all your network traffic is genuinely concerning. Most people have no idea their router firmware hasn't been updated in years and is probably running known CVEs. The supply chain trust model for networking hardware is broken.

The solution is pfsense

Or openWRT.

The bsd based distributions sure are powerful, but with the power/heat budget to match.

Re: Wanted to spy on my dog, ended up spying on TP-Link

#94

IoT security is generally terrible, but the fact that consumer routers are essentially unaudited black boxes processing all your network traffic is genuinely concerning. Most people have no idea their router firmware hasn't been updated in years and is probably running known CVEs. The supply chain trust model for networking hardware is broken.

The solution is pfsense

Better go OPNsense

Re: Wanted to spy on my dog, ended up spying on TP-Link

#95
post #59

Earlier quoted context omitted.

I don't think any vendor should be solving for "I want to do app RE and banking on the same device at the same time;" that seems rather foolish. These are sort of orthogonal rants. People view this as some kind of corporate power struggle but in this context, GrapheneOS, for example also doesn't let you do this kind of thing, because it focuses on preserving user security and privacy rather than using your device as…

GrapheneOS strongly recommends that you do not do it, but it will not stop you if you want to. You can root and leave your bootloader unlocked or create a custom user signed image with root support included. Plenty of user written guides out there how to do so.

Locking the bootloader is important as it enables full verified boot https://grapheneos.org/install/cli#locking-the-bootloader

Re: Wanted to spy on my dog, ended up spying on TP-Link

#96

Oh awesome, this is using my Frida scripts! These: https://github.com/httptoolkit/frida-interception-and-unpinn... . Nice project, great to see the scripts doing good work in the wild. If you needed any extra additions or tweaks to get them working, I'd love to hear about it.

Http toolkit is one of the best software i have used. I have used mitmproxy, proxyman and charles proxy and httptoolkit is the best and is open source too.

Re: Wanted to spy on my dog, ended up spying on TP-Link

#97

IoT security is generally terrible, but the fact that consumer routers are essentially unaudited black boxes processing all your network traffic is genuinely concerning. Most people have no idea their router firmware hasn't been updated in years and is probably running known CVEs. The supply chain trust model for networking hardware is broken.

IOT - "S" stands for "Security"!

Re: Wanted to spy on my dog, ended up spying on TP-Link

#98
post #55

Got one for my house but what really annoyed me was that I wasn't able to set a fixed IP for it

Really? Mine has a switch for static. You aren't seeing that in the app? Configuration -> Advanced settings -> Network

Confirmed here. I've got four of them, and they all have this setting. I know because I changed them from DHCP reservation to static IP recently.

Re: Wanted to spy on my dog, ended up spying on TP-Link

#99
post #87

Earlier quoted context omitted.

Why does most fraud come from locked down mobile devices and not open Windows/Linux PCs? If it's true that 90% of fraud comes from mobile despite all of the restrictions, what that tells me is that locking down devices doesn't actually prevent fraud. --- > before we even get into the mobile app having features the desktop one does not (P2P payments, check deposit, etc.) I think it would be reasonable to disable those…

> If it's true that 90% of fraud comes from mobile despite all of the restrictions Statistics on mobile vs. desktop banking will really shock you; the mobile usage penetration is easily well upwards of 90% in many markets. There's also a skewed distribution for fraud-vulnerable users and scenarios. > I think it would be reasonable to disable those specific features on mobile while leaving the rest of the app accessib…

> Statistics on mobile vs. desktop banking will really shock you; the mobile usage penetration is easily well upwards of 90% in many markets. There's also a skewed distribution for fraud-vulnerable users and scenarios.

But if my goal was to commit fraud, wouldn't I go to wherever it was easiest to commit fraud? The actual market penetration of each platform shouldn't matter.

Re: Wanted to spy on my dog, ended up spying on TP-Link

#100

Earlier quoted context omitted.

The solution is pfsense

Or openWRT. The bsd based distributions sure are powerful, but with the power/heat budget to match.

I love me some OpenWRT but updating it has always been a risky chore.
Post reply on HN