The Tapplock IoT padlock has multiple security vulnerabilities
nakedsecurity.sophos.com
The Tapplock IoT padlock has multiple security vulnerabilities
1–10 of 102 posts
Re: The Tapplock IoT padlock has multiple security vulnerabilities
#2Re: The Tapplock IoT padlock has multiple security vulnerabilities
#3Genuinely curious how people still manage to fuck up this kind of super basic secure coding practices
Who knows but after learning this I would be highly cautious to buy anything from this company until they‘ve proofen to be more careful in the future.
Re: The Tapplock IoT padlock has multiple security vulnerabilities
#4Re: The Tapplock IoT padlock has multiple security vulnerabilities
#5Genuinely curious how people still manage to fuck up this kind of super basic secure coding practices
I've worked as a developer for a number of companies who handle sensitive data and I could have fairly easily have pushed malicious code. Even with mandatory code reviews, significantly complicated code with a well placed security hole would likely be missed.
Re: The Tapplock IoT padlock has multiple security vulnerabilities
#6Genuinely curious how people still manage to fuck up this kind of super basic secure coding practices
Re: The Tapplock IoT padlock has multiple security vulnerabilities
#7>Tapplock user? Get and install any and all patches provided. Apparently, the company has now addressed the most obvious web portal holes (guessable account IDs and no HTTPS), but we assume an app update will be needed as well.
Also, stop being a Tapplock user
Re: The Tapplock IoT padlock has multiple security vulnerabilities
#8Never heard of this product before but what a hilarious read. They seem to fix some of the issues pretty quick. But what a nightmare IoT are. I’m stressed out by not keeping up to date with computer/phone updates (mostly because I wait a bit to ensure programs I use still work). Can’t imagine owning even more products that I have to maintain software updates on...
Re: The Tapplock IoT padlock has multiple security vulnerabilities
#9Is that the best advice to web programmers they can give based on this story? That's the "obscurity" part in the security by obscurity scheme. If you've got your security otherwise nailed down fine, some obscurity on the top doesn't hurt: security-in-depth, people seem to call that. But use only the obscurity, and only one person has to find out how your scheme works, and it's game over.
I'd, you know, recommend to think about authentication. Your authentication state is not "logged in", it's "logged in as user X". So the code that decides whether a client can see a specific page can and should (!) depend on what specifically you're authenticated as.
Oh, and yes, this company has proved that they don't know the least thing about security. But that was clear already.
Re: The Tapplock IoT padlock has multiple security vulnerabilities
#10With that in mind - which are you more worried about? Something spoofing your Bluetooth pass code using some advanced tech, physically unscrewing the back and deconstructing the padlock, or the third option: chop open the shackle?
What I find amazing is that they thought they advertise this product as more secure than any other padlock with the same mechanism. This padlock is a finger print padlock, maybe people like that convenience, but don't try and pretend physical security isn't a concern.