| ▲ | jcgrillo 5 hours ago | |||||||||||||||||||
The "smart" thermostat stuff is scary. I have Haier minisplits in my house and they have some "smarts" built into each head unit. The way it works from the user's perspective is you connect to the device in the GE Home app via Bluetooth, enter your WiFi network's credentials, then the minisplit joins your wifi network and phones home to GE Cloud. Then your GE Home app can monitor and control your minisplit via GE Cloud. I haven't done anything to analyze it further, instead after trying that out once I promptly changed my WiFi password and never looked back. The long term solution will involve some ESP32s, AHT20 temp/humidity sensors, and IR rx/tx. But it just occurred to me reading this that if there's a similar vulnerability in HVAC system controls an attacker could cause one hell of an unanticipated power demand spike. | ||||||||||||||||||||
| ▲ | rpcope1 5 hours ago | parent | next [-] | |||||||||||||||||||
This is honestly why it's important to insist on Z-wave or Zigbee if you don't have control over the device firmware and must have smart controls. Why people don't seem to understand now that if it's "WiFi" it's suspect at best, I'll never understand. | ||||||||||||||||||||
| ||||||||||||||||||||
| ▲ | irishcoffee 4 hours ago | parent | prev [-] | |||||||||||||||||||
Edit: misread. | ||||||||||||||||||||