4 ms·
I'm not sure what the original commenter meant; however TLS is useful only when talking with your own server. What about other connections? NTP, DNS etc are all
by fmntf 9y ago
I'm not sure what the original commenter meant; however TLS is useful only when talking with your own server. What about other connections? NTP, DNS etc are all unencrypted (read: unsigned). Google "DNS client CVE" for instance. Or what about SSH? It may not be accessible from the Internet, but still exploitable from an infected host in the LAN. Someone has to keep all that software updated.
In those conditions, I would never connect a RaspberryPI or similar to my door / gate / car / ...
- komali2 9y agoHow is SSH exploited from an infected host within the LAN?
- fmntf 9y agoIf you connected an IoT device in the same network of an infected PC, the infected PC can talk to the IoT device directly if you do not block traffic somehow (eg. a firewall). Are there open ports with buggy services? Probably not today, what about in ten years?
- deadbunny 9y agoI assume they mean you can only ssh from your local network, the IoT device gets pwnd, it's on the same network as the rest of your computers, someone can use the IoT device as an entry point into your network. Easily solved with separate networks or vlans etc...
- IncRnd 9y ago> however TLS is useful only when talking with your own server. Are you saying that for the most trusted servers TLS is needed, but less trusted servers can be spoken to with less security?
- fmntf 9y agoNo no no. I am stating that, while TLS is good, your device will use other unprotected connections too (both on LAN and WAN) unless something else is done. until bugs or weaknesses are found, see SSL v1/2/3 deprecation, heartbleed, etc