10 ms·
Haven't checked the code. Any obvious security flaws? Or is it the fact that it's not peer tested and proven?
by marcelnita 7y ago
Haven't checked the code. Any obvious security flaws? Or is it the fact that it's not peer tested and proven?
- yakshaving_jgt 7y agoI'm more concerned about non-obvious security flaws.
- RL_Quine 7y agoThe intended use of this is "maintaining" internet of things devices. So it's not really meant to be a secure system, think of it as a botnet CnC and this makes a lot more sense. It's why the system is supposed to be run on OpenWRT (which most cheap IOT things are based on), it why there's not hostnames, it's why it supports hundreds or thousands of devices.
- tastroder 7y ago> The intended use of this is "maintaining" internet of things devices. > So it's not really meant to be a secure system, think of it as a botnet CnC and this makes a lot more sense. Is there anything to back this up? While the mtls initialization looks less than ideal and there's downright stupid stuff in the README like credentials in URI parameters, this doesn't look any different than the other web terminal gateways we've seen on HN over the last few weeks. > which most cheap IOT things are based on Most cheap IoT devices I'm aware of aren't remotely capable of running OpenWRT, do you happen to have examples for this?
- deleted 7y ago[deleted]