Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Save the Plant - A man in the middle attack. #9

Open
mmaguigan opened this issue Oct 12, 2017 · 0 comments
Open

Save the Plant - A man in the middle attack. #9

mmaguigan opened this issue Oct 12, 2017 · 0 comments

Comments

@mmaguigan
Copy link

The killswitch should, at a minimum, make use of a secure connection (eg. TLS v1.2) to the server before the check. The published value should be digitally signed to prevent the anti-ficus alliance (they don't like zebra plants much either) or other plant-terrorist networks from infiltrating vital life-support systems.

https://github.com/tylerjaywood/pleasetakecareofmyplant/blob/579dac5224c52655d3559ab9559aacdd4a089c7f/config.py#L33

Similar vulnerabilities exist in the weather inquiry that when leveraged would allow plant-rights separatists to dissuade the public into a panic wherein the either drawn or starve our noble hero. Examine the vendor interface and determine if TLS is supported and if there exist any further forms of API verification. In the worst case, consider reading data from a secure local sensor safely ensconced behind the demilitarized zone.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant