|
|
|
|
|
by dlenski
121 days ago
|
|
I discovered a very similar vulnerability in Mysa smart thermostats a year ago, also involving MQTT, and also allowing me to view and control anyone's thermostat anywhere in the world:
https://news.ycombinator.com/item?id=43392991 Also discovered during reverse-engineering of the devices’ communications protocols. IoT device security is an utterly shambolic mess. |
|