|
|
|
|
|
by frazar0
545 days ago
|
|
> If the device was validating the server certificate, it wouldn’t make it this far, so that shows that our certificate was accepted. One more very good reason for preventing requests to "the cloud". However, I find it funny that the lack of proper certificate validation (which is a security issue in principle) is a pre-requisite for the "de-cloudification" process. |
|
I avoid as much as possible, devices with cloud connections, but those which I somehow end up with anyway that do have such services, I've found almost none of them do any sort of certificate validation.
Load up any certificate you like on your MiTM proxy and go to town.
Sadly, despite embedded hardware being much more capable, some of them having hardware secure-elements and cryptographic extensions, people making these devices either don't have the expertise or just don't care.
Once upon a time I dreamt of creating IoT devices with security, openness and longevity in mind.