Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

So it seems that the nest itself was secured with a repeated password, and there was no 2FA on their account (which they could, and were encouraged, to add).

On one hand, it's easy to dismiss this as the nest owners being naive with internet security. This is incident was easily avoidable if the owners had put in the tiniest more effort. I think it's _fair_ to expect people who own these devices to know the basics about how to not get exploited from it.

On the flip side, although I think that knowing the basics is a _fair_ expectation, I don't think it's _pragmatic_. These devices are only going to get more powerful in their abilities, only going to get more ubiquitous in their distribution, and only going to get more opaque as to their inner workings. I don't think it's unreasonable that manufactures _force_ a higher level of security on such devices.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: