Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
mediaphage
Mar 22, 2007

Excuse me, pardon me, sheer perfection coming through
fortunately we’re starting to see things like zigbee only thermostats which you can at least limit access to from outside of your network

Adbot
ADBOT LOVES YOU

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.

ate poo poo on live tv posted:

What's wrong with an old honeywell mercury switch thermostat? You set it to the temperature you want, and then leave it alone. Easy peasy.

mine works, i adjust it twice a year.

i also have radiant heat and no ac, so there's very little for it to do

obviously this isn't for everyone

Guy Axlerod
Dec 29, 2008
There are plenty of programmable thermostats without IOT. Mine even has a color touch screen. The schedule isn't that useful since we are WFH.

mediaphage
Mar 22, 2007

Excuse me, pardon me, sheer perfection coming through
lol classic nerd line of “works for me so everyone should have to do it”

mystes
May 31, 2006

I really wish there was some sort of non-stupid standard way to handle IOT devices in a secure way that wasn't reliant on being supported by the companies making them.

post hole digger
Mar 21, 2011

mystes posted:

I really wish there was some sort of non-stupid standard way to handle IOT devices in a secure way that wasn't reliant on being supported by the companies making them.

simply maintain a multi vlan network with a robust firewall ruleset at home op.

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
also, host all your own services on-premises

BlankSystemDaemon
Mar 13, 2009



mediaphage posted:

shouldnt be too hard, isn't it just a web server with a mongodb in the background?

i'm currently running it on windows but i have had some problems with my ap and router disconnecting from the server for no good reason so it's a little buggy still (they work fine, the server just can't see/control them and then since they've been provisioned by the controller they don't have local logins and i need to reset them, but the controller can reprovision and push out the settings so it's not a huge deal, just annoying).
yeah it looks fairly doable, but i'm just a docs committer, so for now i've added it to the list of wanted ports

Asleep Style
Oct 20, 2010

mystes posted:

I really wish there was some sort of non-stupid standard way to handle IOT devices in a secure way that wasn't reliant on being supported by the companies making them.

you know what they say, wish in one hand, request a 2FA token to flush your smart toilet with the other

infernal machines
Oct 11, 2012

we monitor many frequencies. we listen always. came a voice, out of the babel of tongues, speaking to us. it played us a mighty dub.
i can't get into my garage because my oauth provider is having dns issues

KirbyKhan
Mar 20, 2009



Soiled Meat
Requiring biometric authentication to only allow myself to adjust the thermometer. Child harvests blood and feeds it into the console to raise temp to f76

Celexi
Nov 25, 2006

Slava Ukraini!

mediaphage posted:

fortunately we’re starting to see things like zigbee only thermostats which you can at least limit access to from outside of your network

ecobee started with their first thermostats having zigbee along with wi-fi, not anymore though.

pseudorandom name
May 6, 2007

mystes posted:

I really wish there was some sort of non-stupid standard way to handle IOT devices in a secure way that wasn't reliant on being supported by the companies making them.

isn't that the point of HomeKit?

mystes
May 31, 2006

pseudorandom name posted:

isn't that the point of HomeKit?
I guess? I don't have any apple stuff but it does seems sort of like what I was imagining.

HELLOMYNAMEIS___
Dec 30, 2007

https://www.cyberkendra.com/2022/03/rce-0-day-exploit-found-in-spring-cloud.html

mediaphage
Mar 22, 2007

Excuse me, pardon me, sheer perfection coming through

Celexi posted:

ecobee started with their first thermostats having zigbee along with wi-fi, not anymore though.

aha i thought this was true but then i didn’t see it listed, that’s why

anyway that sort of thing could be very secure imo, put a zigbee hub on the network, ban it from accessing outside, and bing bong

Mustache Ride
Sep 11, 2001




It's spring4shell folks. Start getting your 5 hour energies lined up for another month of all-nighters.

evil_bunnY
Apr 2, 2003

akadajet posted:

the best part is that the people who stole the buttcoins made short calls on the entity they stole from in order to profit more from the news, but it took the operators much too long to figure it out and news to break so they lost money on those short bets lol
I wrote all the way down and I meant it.

evil_bunnY
Apr 2, 2003

Achmed Jones posted:

can i get a transcript or written version or something, i ain't gonna watch that but i wanna know the facts
just watch at 1,5x with captions on its fine

rafikki
Mar 8, 2008

I see what you did there. (It's pretty easy, since ducks have a field of vision spanning 340 degrees.)

~SMcD



So, the actual CVE is listed as medium sev - https://tanzu.vmware.com/security/cve-2022-22963. Anyone got some more insight into how painful this really is?

rafikki
Mar 8, 2008

I see what you did there. (It's pretty easy, since ducks have a field of vision spanning 340 degrees.)

~SMcD


rafikki posted:

So, the actual CVE is listed as medium sev - https://tanzu.vmware.com/security/cve-2022-22963. Anyone got some more insight into how painful this really is?

Or maybe that CVE is unrelated - https://www.flashpoint-intel.com/blog/what-is-springshell-what-we-know-about-the-springshell-vulnerability/

ErrorInvalidUser
Aug 23, 2021

by Jeffrey of YOSPOS

rafikki posted:

So, the actual CVE is listed as medium sev - https://tanzu.vmware.com/security/cve-2022-22963. Anyone got some more insight into how painful this really is?

only time will tell my son

post hole digger
Mar 21, 2011

https://twitter.com/wdormann/status/1509225394561507333

post hole digger
Mar 21, 2011

spring4shell seems potentially like a case of pr and panic winding each other up. not stopping our green security guy from spazzing out about it though. not my problem (yet)

rafikki
Mar 8, 2008

I see what you did there. (It's pretty easy, since ducks have a field of vision spanning 340 degrees.)

~SMcD


yeah, I’m trying to sift through the noise to figure out how seriously to take all this

rafikki
Mar 8, 2008

I see what you did there. (It's pretty easy, since ducks have a field of vision spanning 340 degrees.)

~SMcD


https://venturebeat.com/2022/03/30/spring-core-vulnerability-doesnt-seem-to-be-log4shell-all-over-again/

Midjack
Dec 24, 2007



mystes posted:

I really wish there was some sort of non-stupid standard way to handle IOT devices in a secure way that wasn't reliant on being supported by the companies making them.

there is: throw them in the trash alongside my posts.

Celexi
Nov 25, 2006

Slava Ukraini!
Well several services are warning me state sponsored actors trying to get into my stuff. Why me lol?

Kesper North
Nov 3, 2011

EMERGENCY POWER TO PARTY

Celexi posted:

Well several services are warning me state sponsored actors trying to get into my stuff. Why me lol?

The local thespian's guild wants to know why you haven't paid your taxes

Jenny Agutter
Mar 18, 2009

Asleep Style posted:

you know what they say, wish in one hand, request a 2FA token to flush your smart toilet with the other

https://twitter.com/atdanwhite/status/1508578360217292802?s=21&t=r0QhmYsCvTsJGXfHKuf3Zw

Kitfox88
Aug 21, 2007

Anybody lose their glasses?
number 2 factor authentication

Kesper North
Nov 3, 2011

EMERGENCY POWER TO PARTY
just wait til we're making GBS threads on the blockchain!

oh wait, we do~

Amethyst
Mar 28, 2004

I CANNOT HELP BUT MAKE THE DCSS THREAD A FETID SWAMP OF UNFUN POSTING
plz notice me trunk-senpai
RCE exploit in spring core.

https://www.cyberkendra.com/2022/03/springshell-rce-0-day-vulnerability.html

Just ran this against a spring boot app in tomcat 9 and it worked

Shame Boy
Mar 2, 2010

Amethyst posted:

RCE exploit in spring core.

https://www.cyberkendra.com/2022/03/springshell-rce-0-day-vulnerability.html

Just ran this against a spring boot app in tomcat 9 and it worked

now run... your eyeballs up the thread a few posts, bud!!!

Shame Boy
Mar 2, 2010

i think that particular link has other information that wasn't posted so its not entirely fair but i wanted to make that joke so :colbert:

Amethyst
Mar 28, 2004

I CANNOT HELP BUT MAKE THE DCSS THREAD A FETID SWAMP OF UNFUN POSTING
plz notice me trunk-senpai
this random hackernews comment is the clearest technical explanation i've found so far https://news.ycombinator.com/item?id=30862953

Jabor
Jul 16, 2010

#1 Loser at SpaceChem
Wait, so the Spring POJO mapper sees you write "class" in the string to locate a particular subfield and says "why yes, I will call getClass() and continue digging around in that as though it were part of the POJO instead of an underlying JVM thing"?

And to "fix" this back in 2010 the Spring maintainers decided that yes rooting around in the Class object is totally fine and they would allow you to keep doing that, all they really needed to do was not let you access the classloader?

Amethyst
Mar 28, 2004

I CANNOT HELP BUT MAKE THE DCSS THREAD A FETID SWAMP OF UNFUN POSTING
plz notice me trunk-senpai
yeah they disallowed "class.classloader" as a whole but not "class" in general, which seems like a terrible idea.

Amethyst
Mar 28, 2004

I CANNOT HELP BUT MAKE THE DCSS THREAD A FETID SWAMP OF UNFUN POSTING
plz notice me trunk-senpai
mapping directly to pojos like that is a bad idea anyway given how dangerous deserialization is

Adbot
ADBOT LOVES YOU

distortion park
Apr 25, 2011


Really does seem like endpoints should only be interested in the data fields of your pojos and reject/ignore anything else. Serializing a class instead of "some data" across http query params seems kind of hosed up and not that interoperable anyway.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply