4 ms·
It is impossible to secure IoT due to the awful state of lan security (thanks to google and apple's browser ssl policy). If an IoT device wants to host a web ap
by KyleBerezin 1y ago
It is impossible to secure IoT due to the awful state of lan security (thanks to google and apple's browser ssl policy). If an IoT device wants to host a web app, or .local page, all https/ssl content is off limits. This is because browsers won't allow a webpage to send encrypted content to a client unless the client has a valid SSL cert. The issue is you cannot issue a valid ssl cert to a lan ip address. It must target a dns address. This means that ALL DATA ON THE LAN MUST BE SENT VIA PLAINTEXT!
It's complete nonsense, and the only workaround is to install your own certificate authority on your network and add it as a trusted root cert. Imagine buying a device from amazon and being told to add their root ca to your machine. No non-tech person should ever be touching root ca's, and is 10x more dangerous than whatever this insane policy is trying to protect us from.
I believe all IoT devices should exist beyond a virtual airgap, and the router should by default, prevent the device from communicating with the internet. In order to send data to-and-from the cloud, it should pass through some kind of intelligent/auditable gateway. One that the router maintains, and can be updated independent of the devices.