Earlier quoted context omitted.
> No matter what you’re doing you have to trust that your home router doesn’t have an externally accessible SSH port with no password set. No, you don't have to trust. I build my own routers precisely because I don't.
Pretty sure that just means that we trust Linux/Openwrt and the chip vendors.
TP-Link Kasa cameras leaked home GPS via unauthenticated UDP for 6 years
91–96 of 96 posts
Re: TP-Link Kasa cameras leaked home GPS via unauthenticated UDP for 6 years
#92This underscores the principle that IoT devices should not be allowed to communicate over the public Internet. Pretty much all cheap, Chinese-made hardware of this kind has intentional or unintentional security holes waiting to be exploited.
Also, all communication and telemetry should be opt-in and turned off by default.
Government-controlled server would prevent foreign countries from collecting intelligence and pushing malicious updates.
Re: TP-Link Kasa cameras leaked home GPS via unauthenticated UDP for 6 years
#93This underscores the principle that IoT devices should not be allowed to communicate over the public Internet. Pretty much all cheap, Chinese-made hardware of this kind has intentional or unintentional security holes waiting to be exploited.
Re: TP-Link Kasa cameras leaked home GPS via unauthenticated UDP for 6 years
#94Earlier quoted context omitted.
Management think models mean juniors can do senior work. Juniors don't know the footguns. Juniors can't read the code that the system outputs. Models get overwhelmed in any decent sized codebase. Why would you be surprised there are failures?
[flagged]
All of which was, of course, predicted by management, reported upwards, and ignored.
Re: TP-Link Kasa cameras leaked home GPS via unauthenticated UDP for 6 years
#95This underscores the principle that IoT devices should not be allowed to communicate over the public Internet. Pretty much all cheap, Chinese-made hardware of this kind has intentional or unintentional security holes waiting to be exploited.
> Pretty much all cheap, Chinese-made hardware of this kind has intentional or unintentional security holes waiting to be exploited. Why single out bad Chinese coding? Bad US IoT coding has a longer history.
You know precisely why anyone would single out China here. They are egregiously bad, and you know it, and everyone else knows. No amount of "what about this other bad thing that's also bad" could possibly allow any normal person to escape this conclusion.
Re: TP-Link Kasa cameras leaked home GPS via unauthenticated UDP for 6 years
#96Earlier quoted context omitted.
All of there IoT devices will be slop coded soon, and I wonder whether that will be an improvement or not. I bet that security will be better.
> I bet that security will be better. Not doxing myself, but... Company with a known name vibecoded a dashboard with Claude. Which also hardcoded a password into the client-side of the dashboard, which I caught. I reckon security will be about the same.
Seems irrelevant to the comment to add this, James. It just screams to do it a-la Streisand effect..