Jump to content

Welcome to Smart Home Forum by FIBARO

Dear Guest,

 

as you can notice parts of Smart Home Forum by FIBARO is not available for you. You have to register in order to view all content and post in our community. Don't worry! Registration is a simple free process that requires minimal information for you to sign up. Become a part of of Smart Home Forum by FIBARO by creating an account.

 

As a member you can:

  •     Start new topics and reply to others
  •     Follow topics and users to get email updates
  •     Get your own profile page and make new friends
  •     Send personal messages
  •     ... and learn a lot about our system!

 

Regards,

Smart Home Forum by FIBARO Team


What about security


Seth57

Recommended Posts

Hello

 

I can see my mobile sending authentication in clear text to homecenter over the internet

could you please add SSL support ?

 

Mobile device is also accessing Fibaro servers frequently

Why ?

 

The homecenter is a personnal device and should not send informations to you without any notification and explanation

 

Personnaly, traffic to fibaro servers is blocked by firewall policies but i'm not able to control mobile trafic 

So please explain us what is this trafic for ?

 

Thanks in advance

 

 

Link to comment
Share on other sites

  • 2 weeks later...

Hello

 

I can see my mobile sending authentication in clear text to homecenter over the internet

could you please add SSL support ?

 

Mobile device is also accessing Fibaro servers frequently

Why ?

 

The homecenter is a personnal device and should not send informations to you without any notification and explanation

 

Personnaly, traffic to fibaro servers is blocked by firewall policies but i'm not able to control mobile trafic 

So please explain us what is this trafic for ?

 

Thanks in advance

 

Hello,

 

What connection do you have in mind? Local or remote?

Link to comment
Share on other sites

I'm sure mobile has been mentioned

Please login or register to see this image.

/emoticons/default_icon_wink.gif" alt=";-)" /> one would assume remote connection

Edited by Supernode
Link to comment
Share on other sites

  • 10 months later...

Regarding HTTPS, I got this response from Fibaro Support:

 

Quote

 

Hello,
At this moment we do not have in the plans to implement https protocol in local access.
The customer decides / insures the security of the home network – access to the eg router settings also is without https
The introduction of https for local access could increase the response time of the controller (due to additional security)

On our side, we strive to provide the highest level of security for remote access (including https)

But I will pass your suggestion to the department responsible for develop.
Have a nice day!

-- 
Pozdrawiam, 
Regards, 

Rafał Ciesielski 
Technical Support Engineer 

 

 

It's true what they say about the home router (generally) but you're not supposed to access the web page of the router at the same regularity of your domotic system!

They're also offering your system to hotels so I do not see how they can say http is secure to use. You say that if I can spoof the other guests credential over wifi the system is secure?
It's also true that the introduction of https for local access could increase the response time of the controller but I have not asked them to disable http, so that's a choice of the user.
So I do not see any obstacle to the introduction of this functionality but only benefits.
 
At the same time, they are incentivating the use of dynamic DNS (fixing bugs preventing it... 

Please login or register to see this link.

) which of course it's terrible since using that is sending clear-text passwords over the network (even remotely!).
The DDNS functionality would be extremely positive if the app could use the HTTPS connection (which it's inexistant on the HC2, but we can at least install a proxy)
 
Do not suggest the use of a VPN, of course it is possible but very unhandy to use just for Fibaro.
 
I wonder when we will see the light of the HTTPS...
Link to comment
Share on other sites

People who are running pfsense as their firewall could make use of the HAproxy package to create a ssl reverse proxy to http.

This way you can secure your public connection to your homecenter with ssl or tls, allowing for the basic auth taking place to be encrypted.

Someone sniffing on the internet would not be able to read your basic auth, since it would be encrypted by ssl or tls.

Link to comment
Share on other sites

  • 3 weeks later...

Have to agree, I can't see any reason why SSL should not be enabled and saying that it will "slow the system down" is a pathetic non-answer.

I would also like the ability to enable SSL (or disable SSL) and to have the ability to add my own SSL certificate, every other device and web appliance I have can do this.

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...