Device Authentication
Most WiFi "things" have the following setup procedure:
There is no authentication. You have no way to make sure there is no man in the middle trying to steal your credentials. And once this happens you will want to change the WiFi password. And the consequence will be to re-provision the 50 or so orphaned WiFi devices.
The WiFi security model does not work for IoT. This is serious.
- They start in an access point mode.
- You connect to the temporary access point and give it the network credentials to your home WiFi.
- The device reboots and uses the credentials to connect to the WiFi network.
There is no authentication. You have no way to make sure there is no man in the middle trying to steal your credentials. And once this happens you will want to change the WiFi password. And the consequence will be to re-provision the 50 or so orphaned WiFi devices.
The WiFi security model does not work for IoT. This is serious.
Comments
Post a Comment