Web security 101. But why give a shit right? Just keep telling people to use VPN, which is ridiculous. So if I want to open my garage door and wifi does not reach the front driveway, I have to spend 30-40 seconds logging in to my VPN? Are you serious? I love how they claim the miniserver is unhackable. Maybe it is unhackable, but not secure.
Miniserver still has poor security
Einklappen
X
-
Miniserver still has poor security
I contacted loxone directly but have not since gotten any response, so I am just going to leave this here:
Web security 101. But why give a shit right? Just keep telling people to use VPN, which is ridiculous. So if I want to open my garage door and wifi does not reach the front driveway, I have to spend 30-40 seconds logging in to my VPN? Are you serious? I love how they claim the miniserver is unhackable. Maybe it is unhackable, but not secure.1 BildZuletzt geändert von Gast; 06.09.2015, 14:12.Stichworte: - -
this is known for quite some time now, no idea if loxone can't or just won't fix this..
who claimed the MS is unhackable? look at:
The Vulnerability Lab of SEC Consult is an internal security laboratory to guarantee an international know-how advantage over attackers in network and application security.
The Vulnerability Lab of SEC Consult is an internal security laboratory to guarantee an international know-how advantage over attackers in network and application security.
Kommentar
-
http://forum.loxone.com/cscz/satae-f...er-https.html# Here on the czech blog the "Loxonaut" claimed such. Just use google translate. I saw that audit, didnt noticve the part about plaintext authetication.Kommentar
Kommentar