Vulnerabilities for Over Half a Million Belkin WeMo Users
1–8 of 8 posts
Re: Vulnerabilities for Over Half a Million Belkin WeMo Users
#2Re: Vulnerabilities for Over Half a Million Belkin WeMo Users
#3Re: Vulnerabilities for Over Half a Million Belkin WeMo Users
#4I'm in the process of designing a home automation system for my own cabin and news like this is giving me gas. Granted, mine probably won't be nearly as sophisticated (heat, lights, coffee machine etc...), but surely, it can't be an impossible task to combine convenience and security.
Re: Vulnerabilities for Over Half a Million Belkin WeMo Users
#5Re: Vulnerabilities for Over Half a Million Belkin WeMo Users
#6I'm in the process of designing a home automation system for my own cabin and news like this is giving me gas. Granted, mine probably won't be nearly as sophisticated (heat, lights, coffee machine etc...), but surely, it can't be an impossible task to combine convenience and security.
well, if you were even considering WeMo in the first place (even well before this vuln) you were 'doing it wrong'. a server with wifi in EVERY node is not the way to go about adding home automation. these devices you have no control over and rely on 'the cloud' have no business on your LAN.
Re: Vulnerabilities for Over Half a Million Belkin WeMo Users
#7Re: Vulnerabilities for Over Half a Million Belkin WeMo Users
#8My real worry here is that people are selling the devices short. "So what, someone can turn my lights off?". Each one of these devices can act as a WAP - they do so for the initial setup (you join the device's wap with your phone and initiate config from there). Each one of these devices has your network credentials - they have to, to join your LAN.
Being able to sign & push your own firmware updates makes this a troubling combination. It's well within each and every one of these "fire and forget" devices to sit there broadcasting your network credentials.
Asking the users to solve this is hugely ineffective. If you block outbound traffic, you don't receive firmware updates, and lose half the featureset. If you isolate them onto a 'guest lan' to prevent them having useful data to leak, then you lose the other half of the featureset.
The real failure here is bad key hygiene, a ball which is firmly in Belkin's court - and they're refusing to even acknowledge it as an issue.