The report seems obviously AI generated, so I can't be bothered to read in its entirety, but based on my quick skim, "leaked home GPS" makes it sound worse than it is. Unless you're dumb enough to set DMZ on this device, this won't be exposed to the internet, and if it's LAN only, don't you already know the location? Even for a remote attacker who somehow got LAN access remotely, they can probably deduce the location…
> Unless you're dumb enough to (...) It sounds like you are blaming the user for providing data that a service can leak. That's like blaming a user for writing personal emails when faced with an email provider that leaks emails.
TP-Link Kasa cameras leaked home GPS via unauthenticated UDP for 6 years
31–40 of 96 posts
Re: TP-Link Kasa cameras leaked home GPS via unauthenticated UDP for 6 years
#32This underscores the principle that IoT devices should not be allowed to communicate over the public Internet. Pretty much all cheap, Chinese-made hardware of this kind has intentional or unintentional security holes waiting to be exploited.
Consumers just don't care about security. It is what it is.
Re: TP-Link Kasa cameras leaked home GPS via unauthenticated UDP for 6 years
#33Earlier quoted context omitted.
> Pretty much all cheap, Chinese-made hardware of this kind has intentional or unintentional security holes waiting to be exploited. Why single out bad Chinese coding? Bad US IoT coding has a longer history.
There’s bad, and then there’s egregious .
Re: TP-Link Kasa cameras leaked home GPS via unauthenticated UDP for 6 years
#34Earlier quoted context omitted.
> Unless you're dumb enough to (...) It sounds like you are blaming the user for providing data that a service can leak. That's like blaming a user for writing personal emails when faced with an email provider that leaks emails.
Really enjoying the picture of this user who logs into his router and decides that all unsolicited network traffic from the internet should go to his network camera. Absolute legend. God amongst men.
DMZs as a solution to port forwarding issues have been a misunderstood part of online games troubleshooting for at least 20 years.
Re: TP-Link Kasa cameras leaked home GPS via unauthenticated UDP for 6 years
#35Six months of coordinated disclosure on a TP-Link Kasa camera resulted in two CVEs, a triage failure where the vendor described a vulnerability that doesn't exist in the reported payload, a beta patch that permanently bricked my test device, and a factory reset that doesn't clear previous owner data. The GPS finding (CVE-2026-13230) has been publicly documented on this device class since 2020. A single UDP packet ret…
Re: TP-Link Kasa cameras leaked home GPS via unauthenticated UDP for 6 years
#36Earlier quoted context omitted.
Consumers just don't care about security. It is what it is.
There is no reasonable way to assess security for the average consumer.
Re: TP-Link Kasa cameras leaked home GPS via unauthenticated UDP for 6 years
#37Earlier quoted context omitted.
> Zigbee Requires no technical understanding. At least not more than e.g. a WIFI router. > devices randomly disconnect for hours even when they are 2ft from the coordinator, You present this like a fact. But it is at most an anecdote. I present you a different anecdote: I have ~30 zigbee devices, in two different houses (first a house with concrete floors and cellar and level 1..3) and now one old woodwork structure…
> Nowhere did I had even half an hour of disconnection. Well my garage door opener sensor has been disconnected for two 30 minute gaps today and my plant humidity sensors go offline for 2 weeks at a time. So yeah, it's not ready for prime time. > LORA No, let's not even go there. Tech nerd protocol here that's an awkward middle ground that creates even more problems. Average Joes aren't going to set that crap up.
Re: TP-Link Kasa cameras leaked home GPS via unauthenticated UDP for 6 years
#38Earlier quoted context omitted.
All of there IoT devices will be slop coded soon, and I wonder whether that will be an improvement or not. I bet that security will be better.
> I bet that security will be better. Not doxing myself, but... Company with a known name vibecoded a dashboard with Claude. Which also hardcoded a password into the client-side of the dashboard, which I caught. I reckon security will be about the same.
Re: TP-Link Kasa cameras leaked home GPS via unauthenticated UDP for 6 years
#39Re: TP-Link Kasa cameras leaked home GPS via unauthenticated UDP for 6 years
#40Earlier quoted context omitted.
> I bet that security will be better. Not doxing myself, but... Company with a known name vibecoded a dashboard with Claude. Which also hardcoded a password into the client-side of the dashboard, which I caught. I reckon security will be about the same.
When I'm reading reviews of plans created by an agent especially on security boundaries it's suggesting huge matrixes to test even the very obscure situations, but then I'm also reading things like this and I just don't understand. Are we even using the same tools?