This doesn't sound like a Nest vulnerability? Does Nest offer MFA?
This doesn't sound like a Nest vulnerability? Does Nest offer MFA?
Ideally, being susceptible to a leaked password-email-combination should be considered gross negligence.
How can you use any service then if in your mind any service should be be able to not be affected by a leak?
My username/password combo is everything I need to use my account fully. Should there be another factor to use my account? I should be forced to get set another factor to post on HN?
This is just absurd. We just can't keep increasing road block to let people not learn how to use something. There will always be an idiot to outsmart you.
Google defends Gmail users from malicious nation state actors [1]. Isn't Nest part of the Google identity ecosystem now?
[1] https://security.googleblog.com/2012/06/security-warnings-fo...
Thank you to Troy Hunt
The scenario I was looking at was..
User signs up with Site A with Password 1.
User signs up with Nest with Password 1.
Site A gets compromised.
Nest couldn't know if you'd used the same password on each site. The only way they could know is if they used the same hashing algo with the same salt or SHA-1 with no salt. Highly unlikely.
I suppose Nest could check the Pwned Passwords API every time they logged in, but I haven't seen anyone deploy that yet, IIRC all solutions I've seen check Pwned Passwords API when the set the password. Setting a password and checking a password are often different systems.
I have no idea if it's integrated with their primary login flow though. It's certainly integrated with the password manager in Chrome.
One easy fix. Send a verification email to users when a different device is detected before allowing log in.
I mean, even Steam does this.
Not perfect, but, its decent.
I still use it and will continue to do so until someone releases a better ecosystem.
Right now I get an alert on my phone if someone rings the bell, or leaves/removes a package. Plus with facial recognition I get alerts which include the person's name for common visitors (via facial recognition) and will announce visitors via a set of google home minis. Nest will alert my phone if the smoke detector sees smoke or CO. I'm obviously quite "all in" on their ecosystem.
I also will note I have an elderly relative at home as well as 3 dogs and we are not there most days so the ability to see what's going on at home and potentially take action like calling the police/fire/EMS is extremely valuable to me.
I don't remember what Nest used before being bought by Google (I believe SMS MFA was available), but they're transitioning accounts to sign in with your Google account.
A surprising number of sites that really should do not offer any MFA. Like bank accounts, credit cards, investing accounts, payroll, cars...
My money may not be safe, but at least my github commits are!