Live data from Hacker News

TP-Link Tapo C200: Hardcoded Keys, Buffer Overflows and Privacy

evilsocket.net

21–30 of 128 posts

Re: TP-Link Tapo C200: Hardcoded Keys, Buffer Overflows and Privacy

#21
I'm a little frustrated with articles like this that scattershot their critique by conflating genuine failures with problems that even FAANGs struggle with.

In particular, I don't love it when an article attacks a best practice as a cheap gotcha:

"and this time it was super easy! After some basic reversing of the Tapo Android app, I found out that TP-Link have their entire firmware repository in an open S3 bucket. No authentication required. So, you can list and download every version of every firmware they’ve ever released for any device they ever produced"

That is a good thing - don't encourage security through obscurity! The impact of an article like this is as likely to get management to prescribe a ham-handed mandate to lock down firmware as it is to get them to properly upgrade their security practices.

Re: TP-Link Tapo C200: Hardcoded Keys, Buffer Overflows and Privacy

#25
post #21

I'm a little frustrated with articles like this that scattershot their critique by conflating genuine failures with problems that even FAANGs struggle with. In particular, I don't love it when an article attacks a best practice as a cheap gotcha: "and this time it was super easy! After some basic reversing of the Tapo Android app, I found out that TP-Link have their entire firmware repository in an open S3 bucket. No…

Yep, I think it should always be that way, firmwares should be always available.

Re: TP-Link Tapo C200: Hardcoded Keys, Buffer Overflows and Privacy

#26
post #23

I more and more tend to not buy any network-connected product if there's no open-source firmware to run on it. (Phones is one notable exception. I need contactless payments to work.)

If you call up your contactless payment provider, most will send you a physical device that will do contactless payments on its own, for free even. You can tape it to the back of your phone, or anywhere else for that matter.

Re: TP-Link Tapo C200: Hardcoded Keys, Buffer Overflows and Privacy

#27
post #24

Thingino supports C200 https://thingino.com/#:~:text=SC3336%2C%20WQ9001%2C%208MB-,T...

I came here to post this, too :) What the thingino community managed to do with their firmware for these cameras is nothing short of amazing - if you happen to have a compatible camera, you really, really should give it a whirl!

Re: TP-Link Tapo C200: Hardcoded Keys, Buffer Overflows and Privacy

#29
This is why all my cameras internal or external live on an isolated VLAN with no internet access. It’s nice because HomeKit can still talk to them and I can see it online or locally without an additional app even though the camera themselves has no internet access .

Re: TP-Link Tapo C200: Hardcoded Keys, Buffer Overflows and Privacy

#30
post #5

As soon as i read the author used grok as an ai assistant, i was somehow less interested to keep on reading. Not because of the usage of ai, but the chosen provider. (I don’t know whether grok is just the best choice for this kind of work.) Is it wrong to judge people for their choice of ai providers?

I think it's hard to say. Grok is pretty good and also fairly free with good usage limits.

Every single AI company in my opinion is committing fairly grave misdeeds with the ruthless scraping of the internet and lack of oversight.

Not to mention the shady backdoor deals going on with big tech and the current administration.

Grok is also pretty bad with its whole gas turbines in one state and datacenter in another and some possible environmental issues

It's more of a pick your poison at this point

Post reply on HN