Hacker News new | ask | show | jobs
by paddlesteamer 2280 days ago
I think it's more than 'pretty low issue'. Someone already connected to the LAN may just sniff the login credentials since the Pi-hole web interface doesn't use https and then gain root access where all LAN clients trust with their DNS queries.