|
|
|
|
|
by alias_neo
545 days ago
|
|
It is funny, but it's also the defacto-standard. I avoid as much as possible, devices with cloud connections, but those which I somehow end up with anyway that do have such services, I've found almost none of them do any sort of certificate validation. Load up any certificate you like on your MiTM proxy and go to town. Sadly, despite embedded hardware being much more capable, some of them having hardware secure-elements and cryptographic extensions, people making these devices either don't have the expertise or just don't care. Once upon a time I dreamt of creating IoT devices with security, openness and longevity in mind. |
|