3 ms·
No, those two points you raise are completely false. > Author has a personal preference for basic auth Adding web server basic auth (and thus adding multi lay
by throwaway89201 2y ago
No, those two points you raise are completely false.
> Author has a personal preference for basic auth
Adding web server basic auth (and thus adding multi layer security) is objectively more secure than only application level security. Of course some other way of adding web server authentication would be equally okay, but the Home Assistant app doesn't have support for it either.
> This is simply security through obscurity
A secret subpath is not security by obscurity at all. The path isn't obscured in any way; it's a secret. It does have the downside that user agents don't treat URLs as secrets (i.e. it's saved as history), but in this case that isn't too much of a concern.