|
|
|
|
|
by dns_snek
884 days ago
|
|
> 'Local' unfortunately isn't something decided at design time, it's decided when someone connects it to a network. It's obviously connected to the public internet when it talks to cloud servers, and that's somehow (claimed to be) secure. Comparing a good cloud API with a poorly designed local API is a false dichotomy. Would you set up your cloud servers with default credentials of admin:admin? Have a hidden physical switch that toggles local control, and require a physical button press to (re-)generate secure credentials. Have the user upload TLS certificates (non-optional), then hand over the credentials over a secure connection. There, the security of local API should now be up to par with the cloud connection. |
|
Asking why a Haier dishwasher doesn't have a local API is like asking why a Toyota Sienna doesn't have configurable launch control, power-take-off, or a fifth-wheel. The target market segment isn't looking for those features.