Earlier quoted context omitted.
You realize that a lot of these devices have been found to phone home to servers in the motherland, right? Without informing the user they were doing so? Or would be expected for the class and function of device? You wanna explain how that was just “buggy and insecure”?
A device calling home and posting data is normality since many years already and does not directly represent a security risk for the normal user, based also on the fact that this communication is often covered by his vendor policy acceptance. what's bad is if the vendor is sending data that should not be sent or collected and if the vendor leaves the device insecure, especially on purpose. In relation to the inverter…
Re: FCC bans foreign-produced solar inverters, grid lockout begins today
#51pretty much anything could be hidden in a firmware update over SSL, yeah?