Hacker News new | ask | show | jobs
by jordanab 2030 days ago
I'd imagine that the security implications for non-wifi devices are somewhat less than for wifi-enabled devices. ZigBee devices do not "phone home" over the internet, and in addition to that are not able to download and upgrade their own firmware without a supporting internet-connected gateway/bridge device. Most of the risk comes from the attack surface that the gateway/bridge provides, or from attackers having physical access to individual devices (eg. by obtaining keys from the device's memory). As for ZigBee gateway/bridge devices, in most cases you can replace it with an open source solution that gives you more control (eg. Home Assistant + a Conbee USB stick)