Jump to content

Welcome to Smart Home Forum by FIBARO

Dear Guest,

 

as you can notice parts of Smart Home Forum by FIBARO is not available for you. You have to register in order to view all content and post in our community. Don't worry! Registration is a simple free process that requires minimal information for you to sign up. Become a part of of Smart Home Forum by FIBARO by creating an account.

 

As a member you can:

  •     Start new topics and reply to others
  •     Follow topics and users to get email updates
  •     Get your own profile page and make new friends
  •     Send personal messages
  •     ... and learn a lot about our system!

 

Regards,

Smart Home Forum by FIBARO Team


Recommended Posts

Posted

Worth reading and considering if you are safe.

Please login or register to see this link.

Posted
Worth reading and considering if you are safe.

Please login or register to see this link.

There is a reason why my HC2 cannot connect to the internet at all.

Please login or register to see this image.

/emoticons/default_wink.png" alt=";)" srcset="https://forum.fibaro.com/uploads/emoticons/[email protected] 2x" width="20" height="20" />

  • Topic Author
  • Posted

    Not even for upgrades? It is hard to avoid all connectivity.

    Posted

    At least there should be firewall on between internet and HCx. Or any device.

    But securing your own network is only half of the problem. By attacking against home.fibaro.com you could get access to devices. And even more simple - spoofed DNS-data could get users to install modified firmware with backdoors.

    Posted
    Not even for upgrades? It is hard to avoid all connectivity.

    Whenever i read about a new release, i allow the device access. It is also on a completely separate VLAN from my other devices. Apart from that, i just allow the device to talk to 80 and 443 of some of my other devices for integration purposes.

    The same goes for the ethernet-adapter to my alarm system. It too is on a separate subnet, and no traffic to my "internal" networks are allowed from it. Same reason there: I have absolutely no idea what is in that box, or what it can do. All i know is that it runs a SSL-tunnel to a C&C somewhere.

    All inbound initiated traffic is either via OpenVPN or IPSec.

  • Topic Author
  • Posted

    Good advice to keep it separated and not risk attacks on unprotected ports.

    I tend to also limit outgoing to the internet. Not a lot of good to these guys for their evil purposes if the device is trapped in a zone.

    Posted

    I use a separate router for all my connected stuff, and none is connected to the internet. I don't use the remote functions anyway and all my controllers are stand alone units not used for anything else. This also means that it doesn't disturb my already busy internet router as 802.11 protocol is actually pretty bad at handling a sea of small packets as is being send between my home control units.

    Only stuff that is available for hacking is a weight and a television... And if they want to know what my girlfriend weighs or I watch on the telly, be my guest... No personal information or codes on those devices (well my girl friend might think otherwise, but that is a different discussion).

    But in general, I think this is a very good observation and an important thing to consider - especially on components which have some sort of interaction to physical components such as lights, alarms or especially connected deadbolts (which I will NEVER install in my home - access should always require a physical token).

    Join the conversation

    You can post now and register later. If you have an account, sign in now to post with your account.

    Guest
    Reply to this topic...

    ×   Pasted as rich text.   Paste as plain text instead

      Only 75 emoji are allowed.

    ×   Your link has been automatically embedded.   Display as a link instead

    ×   Your previous content has been restored.   Clear editor

    ×   You cannot paste images directly. Upload or insert images from URL.

    ×
    ×
    • Create New...