Home Assistant can not be secured for internet access
frederikbraun.de
frederikbraun.de
1) No HTTP basic auth. This isn't a security issue in any way, shape, or form. Author has a personal preference for basic auth but this doesn't mean that changes the security posture.
2) No support for reverse proxy so you can change the root to something non-standard. This is simply security through obscurity and once again has zero bearing on the security posture.
I think the author would do well to understand basic web services security before he starts casting stones here. VPNs work fine if that's what you need, but of course they are too complicated for the author so that solution is dismissed.
I've solved it instead by using Wireguard and keeping home assistant on my private network. No idea why the author thinks VPN is not a good solution. It's also helpful for several other apps I don't feel safe exposing to the internet.
What is wireshark for? Or did you mean wireguard and get autocorrected?
But there's addons in the package manager:
> Want to protect the website with a username/password? Well, it can do that too!
This makes it seem like they advise against it on that page, which is not true. Nor would it make any sense, putting a reverse proxy in front of a web application before exposing it to the open internet is about as typical as things get.
https://companion.home-assistant.io/docs/getting_started/#tl...
Not to defend the author or the idea, but this is very clearly untrue. Something similar is routinely done to intentionally break hotlinking usually (tokenized URLs and URL signing). It's ages old and does work, as it's no different to cracking a long and difficult password.
> Author has a personal preference for basic auth
Adding web server basic auth (and thus adding multi layer security) is objectively more secure than only application level security. Of course some other way of adding web server authentication would be equally okay, but the Home Assistant app doesn't have support for it either.
> This is simply security through obscurity
A secret subpath is not security by obscurity at all. The path isn't obscured in any way; it's a secret. It does have the downside that user agents don't treat URLs as secrets (i.e. it's saved as history), but in this case that isn't too much of a concern.
Wouldn’t it just be the server which needs to be accessed from the outside? And the control interface is not that bandwidth-hungry.
> Bandwidth Limitations: A VPN could bottleneck the performance for some devices.
> Device Compatibility: Not all devices can reliably connect to a VPN.
Tailscale or wireguard are waaaaay easier to configure and maintain than HomeAssistant. Like, orders of magnitude easier.
I can set up the former in 15 minutes on any device I have. It took me two days to rebuild my HA and reconfigure all the integrations after a crash, and I had backups.
If you are already committed to HA, then adding a VPN is cake in 2024
Does it really need to be accessible from the internet? I've never used Home Assistant so maybe what follows would not work, but how about:
• Your mobile device could upload the location/presence notifications to a server outside of your LAN, such as virtual machine at an inexpensive hosting service like Hetzner or Amazon Lightsail.
Something on your LAN could poll that and talk to the Home Assistant server.
• Your mobile device could email the notifications to you. Something on your LAN could monitor your email and process the notifications. A good tool for that is imapfilter [1].
This is definitely not a Home Assistant specific deficiency, but they would do well to explain how to implement remote access to their users as it is an incredibly common use case.
It’s not as secure as VPN which is a better choice.
There are things like Tailscale that are free for private use and make managing / connecting to a VPN as easy as possible. The connection is only limited by your own home connection. You also don’t need to route all your traffic through it.
Put a reverse proxy in front of it for basic auth and path rewrite if you think that are the ultimate security mechanism for you (I don’t think so).
Personally I host all my applications behind a VPN because I don’t trust any software and don’t want to provide any attack surface or even the possibility to being made a possible target because someone scanned me.
This plus my own domain that points to the different local IP addresses makes it as convenient as surfing the public web.
This suggests to me the author is imagining a VPN setup that isn't split-tunnel. Why would anyone want that for this? And what device is "not reliably able to connect" via VPN that you'd want to reach Home Assistant through?
> No Basic Authentication Support: Home Assistant's mobile apps cannot handle URLs with embedded credentials (e.g., https://user:pass@hostname). Path Limitations: Home Assistant must be hosted at the root path (/), preventing the use of an obscure web host path to deter scanners.
... so put a reverse proxy in front of it?
Maybe I'm missing something, but there's nothing unusual here.
(and I pay for an account, so that I can help support this project)
Am I missing something obvious here?
Obscurity is not security.
If that's something the author wants to depend on, I'm not sure we should listen.
> Complexity: Routing general internet traffic through a VPN introduces unnecessary complexity.
I don't believe that it's that bad if your pefered option is a reverse proxy. Frankly, wireguard isn't that complex on its own merits.
> Bandwidth Limitations: A VPN could bottleneck the performance for some devices.
Nonsense; this is a VPN for a specific purpose that uses virtually no bandwidth. Obviously don't run all traffic over it, but with that done it should be fine.
> Device Compatibility: Not all devices can reliably connect to a VPN.
True... but I thought this was just for cell phones? Because wireguard at least works on (at least) iOS, Android, and postmarketos. (And I'm pretty sure most other popular VPNs do as well.)
---
> No Basic Authentication Support: Home Assistant's mobile apps cannot handle URLs with embedded credentials (e.g., https://user:pass@hostname).
> Path Limitations: Home Assistant must be hosted at the root path (/), preventing the use of an obscure web host path to deter scanners.
That is a shortcoming, but not necessarily fatal; can it sit behind a reverse proxy that handles (http basic) authentication but doesn't use another path? That should be secure enough.
Yes, but the author’s issue is, that the mobile app won’t work with basic auth.