3 ms·
A device calling home and posting data is normality since many years already and does not directly represent a security risk for the normal user, based also on
by giov4 2mo ago
A device calling home and posting data is normality since many years already and does not directly represent a security risk for the normal user, based also on the fact that this communication is often covered by his vendor policy acceptance.
what's bad is if the vendor is sending data that should not be sent or collected and if the vendor leaves the device insecure, especially on purpose. In relation to the inverter case yes that can represent potential risk since it would be part of the grid too, hence near to crit infra and maybe even able to influence it.
Additionally network can be controlled, limited and inspected, that's a bit different for a hidden backdoor or hardcoded creds in a flashed firmware on a chip.
- lazide 2mo agopretty much anything could be hidden in a firmware update over SSL, yeah?