4 ms·
Would it still be possible to get at the data and disable connection to the actual cloud service if the device did check the certificate properly?
by shellfishgene 2y ago
Would it still be possible to get at the data and disable connection to the actual cloud service if the device did check the certificate properly?
- jon-wood 2y agoPossibly, it wouldn't be anywhere near this trivial though. With proper certificate validation you'd need to dismantle the device and find a way to get into the OS it's running, which can range in difficulty from finding a serial header and entering root/password to log in, up to near impossible if it's one of the few devices that bother to encrypt their storage.
- alias_neo 2y agoIt really depends on the type of device, and how much effort was put in. Many devices have very little effort; It'd easier however for something that might be storing its filesystem on EEPROM or NAND than say, a microcontroller storing it on-module. My experience is that most devices I've tested, that use something like an ESP32, make little to no effort to validate the CA; even if you don't have the resources to do it cryptographically, you could still do it with a fingerprint check or at the very least a server name validation, but often none of these things are done. I have a "smart" room heater which requires an app to control, the heater talks to their server using MQTT; pointing the DNS name on my LAN at a local IP, and starting an MQTT server, I can get full control even with a server cert that isn't signed by the CA they use and doesn't even contain the server name of their server; so long as it's an unexpired certificate, it'll happily accept it.