hessen.social ist einer von vielen unabhängigen Mastodon-Servern, mit dem du dich im Fediverse beteiligen kannst.
hessen.social ist die Mastodongemeinschaft für alle Hessen:innen und alle, die sich Hessen verbunden fühlen

Serverstatistik:

1,6 Tsd.
aktive Profile

#iot

8 Beiträge8 Beteiligte0 Beiträge heute

Apple’s tvOS is now on version 18.4 with the product being around since 2007–that’s pre-iPhone era!!

It’s been out longer than it took for Disney to “reimagine” Star Wars!

Still, there’s little happening in land of tvOS app development.

Aside from apps by major streaming providers, how else are you using your Apple TV? What’s worth a mention?

Please drop your thoughts in the comments or boost for visibility. 👇

apple.com/apple-tv-4k/
#apple #tvos #streaming #tech #iot

AppleApple TV 4KApple TV 4K. Our best audio and video quality. Dolby Vision, HDR10+, and Dolby Atmos. Works seamlessly with Apple devices, services, and smart home.

BSI-Bericht: Erhebliche Schwachstellen bei #Fitnesstrackern & Co.
heise.de/news/BSI-Bericht-Erhe

"Die Experten wählten demnach zehn Produkte für "eine detaillierte Sicherheitsuntersuchung" aus. Darunter waren sechs vernetzte Uhren wie #Smartwatches, drei #FitnessTracker und ein #SmartRing. Die Forscher deckten dabei insgesamt 110 Schwachstellen auf, die sie als "mittel" oder "hoch" einstuften. Keines der Geräte war komplett frei von #Sicherheitslücken."

Ist doch vollkommen egal, wohin man seine persönlichsten (Gesundheits-)Daten schickt. Oder? 🤔😈

heise online · BSI-Bericht: Erhebliche Schwachstellen bei Fitness-Trackern & Co.Von Stefan Krempl
#Sicherheit#Gesundheit#iot
Antwortete im Thread

Zwecks Auffindbarkeit ein paar Hastags dazu:
Untersuchte Hersteller: #Huawei #Sungrow #GinlongSolis #Goodwatt #GoodWe #SMA
Allgemein: #PV #WR #Wechselrichter #Solar #Inverter #SunDown #Forescout #China #Hacker #SmartHome #IoT
forescout.com/research-labs/su
@bsi

Recommendations
Manufacturers
Development • Devices: holistic security architecture including secure boot, binary hardening, anti-exploitation features, permission separation etc
• Applications: proper authorization checks on web applications, mobile applications and cloud backends
Testing • Regular penetration testing on applications and devices • Consider bug bounty programs
Monitoring Web Application Firewalls Remember that a WAF does not protect against logical flaws

Users
Residential and commercial users • Change default passwords and credentials • Use role-based access control • Configure the recording of events in a log • Update software regularly • Backup system information • Disable unused features • Protect communication connections
Commercial and utility installations (in addition) •
Include security requirements into procurement considerations
• Conduct a risk assessment when setting up devices • Ensure network visibility into solar power systems • Segment these devices into their own sub-networks • Monitor those network segments

#Microsoft used its #AI-powered #SecurityCopilot to discover 20 previously unknown vulnerabilities in the #GRUB2, #UBoot, and #Barebox #opensource #bootloaders.
GRUB2 (GRand Unified Bootloader) is the default boot loader for most #Linux distributions, including Ubuntu, while U-Boot and Barebox are commonly used in embedded and #IoT devices.
bleepingcomputer.com/news/secu #ITSec

Antwortete im Thread

@markd @revk @nowster @jasonkarns @jjcelery In other words, it is economy problem, not a tech problem.
There is no financial incentive to do it in a proper way, and in fact, there is financial incentive to do it sloppy, so user will be forced to buy another "better" version later.

So the solution is also economical - refuse to buy (and lobby others to refuse to buy) #IoT which are #DefectiveByDesign. If your IoT was #FOSS, you and other hobbyist would add that, as incentive is there.

Proof of concept. I hacked-up the AC power cable for a simple desk fan, added crimp connectors to the wires, and plugged it into this cheap Zigbee switch. I dislike the crimping job (the gray crimps make me nervous, and the red ones are a bit too long for the switch), but functionally this circuit works and the fan can be switched on/off.

My plan is to modify various lamps around the apartment, turning them into smart lamps. I bought several cheap Zigbee switches like this one for a few dollars each (China). I chose Zigbee instead of WiFi to ensure they couldn't "phone home", and to unify my IOT stuff under one app (Home Assistant). The goal is to replace my TP-Link Kasa WiFi smart switches with Zigbee alternatives managed by Home Assistant running on a Pi4.

#IOT#Zigbee#DIY