Why single out bad Chinese coding? Bad US IoT coding has a longer history.
Not doxing myself, but... Company with a known name vibecoded a dashboard with Claude. Which also hardcoded a password into the client-side of the dashboard, which I caught.
I reckon security will be about the same.
Why would you be surprised there are failures?
For example, if secret storage methods aren't specified in the prompts, a model might decide to be clever and implement a generic secret access interface, with a default implementation that hardcodes everything. It will probably tell you that this is not production ready and you should write or specify your preferred secret storage implementation, but if you don't read or understand that, you'll just leave it as is and push to prod.
Seems irrelevant to the comment to add this, James. It just screams to do it a-la Streisand effect..
Soon?
I've already seen multiple of TP-Link's firmware engineers leave their LLM history public and indexed by search engines.
It's quite obviously them as well.
Yeah, I agree - at least Chinese Roborock gives very granular controls for privacy.
You know precisely why anyone would single out China here. They are egregiously bad, and you know it, and everyone else knows. No amount of "what about this other bad thing that's also bad" could possibly allow any normal person to escape this conclusion.
Honestly, I'd rather it leak my GPS to the Chinese government than the US government. They don't have jurisdiction over me anyway.
> should not be allowed to communicate over the public Internet
It would be a no-go for non-techies. One of the biggest draws to IoT devices for "average Joes" is being able to view and control them from remotely, and they aren't going to have the skills or know-how to set up a VPN correctly with dynamic DNS so that their phone can VPN into their home and then sideload/jailbreak their phone to load a custom app to control it. "It just works from anywhere" is a big sell for them.
There are better solutions, like Apple’s HomeKit. I’m able to watch a camera that has no internet access because it passed through my Apple TV, which serves as a home hub. I didn’t have to set any of this up, it just works when you have the required hardware.
There are various non-internet protocols for IoT devices, none of them good:
* Zigbee: Requires some technical understanding to set up, devices randomly disconnect for hours even when they are 2ft from the coordinator, all-around horrible experience for non-techies
* Non-standard Zigbee variants: even worse
* Matter-over-Thread: horrendously designed from a UX perspective. Easy-to-lose barcodes stuck on cards in the packaging, weird 12-letter codes, and your non-techie cannot understand what the hell Matter or Thread is. Pairing is an absolute nightmare.
Requires no technical understanding. At least not more than e.g. a WIFI router.
> devices randomly disconnect for hours even when they are 2ft from the coordinator,
You present this like a fact. But it is at most an anecdote. I present you a different anecdote: I have ~30 zigbee devices, in two different houses (first a house with concrete floors and cellar and level 1..3) and now one old woodwork structure house with 2 floors. Nowhere did I had even half an hour of disconnection.
> all around-horrible
... excellent experience even for my ex-spouse, which is/was non-techie.
However, that you present Zigbee here at all is weird. Zigbee doesn't have any way to transport a camera stream. It's mean for low-powered battery devices. My temperature sensors got a 1500mAh AAA chargeable batteries and they lasts now for over one year. Note that I have sensors from ~ 15 different brands. Mostly battery powered sensors and mains power switchable plugs.
I also enjoy that these Zigbee devices are by design completely disconnected from any IP traffic. This, and their (intentional) low data rate make them almost impossible to misuse. E.g. as denial-of-service originators or amplifiers.
It's like you present WIFI as long-range thingy but actually you'd want LORA for that. I'm not assuming that knowing for what kind of usage a tech was designed as "needing technical understanding". After all, no one would claim "you need technical understanding" to know that you better use a truck instead of a Porsche Cayman to transport 50 cubic meters of sand.
Well my garage door opener sensor has been disconnected for two 30 minute gaps today and my plant humidity sensors go offline for 2 weeks at a time.
So yeah, it's not ready for prime time.
> LORA
No, let's not even go there. Tech nerd protocol here that's an awkward middle ground that creates even more problems. Average Joes aren't going to set that crap up.
There are also some devices which advertise ZigBee compatibility but the manufacturers don't seem to test them against coordinators other than their own (and ConBee 2 seems to have the most problems in this regard).
The protocol is complex, they all are, implementing it correctly isn't a given, but I think the issues people have are more often a factor of how long a protocol has been in use than any fundamental aspect of it.
As soon as cheap hardware manufacturers get on board you get this problem.
Quality hardware works fine with ZigBee. It's by no means perfect technology, if you want that, use copper wires, but it doesn't work as badly as you claim if you are not unlucky with coordinators and devices.
Also, it's not like 860-930 MHz (depending on the country) is without interference.
You meant rechargeable? You seem to know more about Zigbee than about rechargeable batteries.
I don't think that's normal. Like, to the point where I'm wondering if you have a bad opinion of the whole protocol because you got a faulty device.
How exactly does this prevent the same kind of issue for Apple devices? Aren't you just trusting that Apple handles your data better than TP-Link? Not saying they don't but routing through another device doesn't really add security on its own.
I am, yes. Ultimately you’re going to need to trust some hardware, somewhere. No matter what you’re doing you have to trust that your home router doesn’t have an externally accessible SSH port with no password set.
Personally I trust Apple more than I trust TP Link with this stuff.
No, you don't have to trust. I build my own routers precisely because I don't.
What if a TP-Link camera supported HomeKit Secure Video? You access the camera through Apple but all of these cameras are still directly connected to the internet, meaning you still need to trust the camera manufacturer.
Pissed off script kiddies have been confused as government plenty of times by unsuspecting victims.
In most cases companies don't want to give you Matter or HomeKit, because it means they cannot sell you more through their app.
Wyze has ads everytime you open it. So does Honeywell. Hell, even the internet-loved Ecobee has a banner that shifts everything down most of the time that you open the app. And for that last one, you _have_ to use their app to control the fan, as they don't expose separate fan controls over HomeKit...
Then don't buy those devices. All of my home devices are either Zigbee (local-only) or were bought specifically because they can be reflashed with open firmware to liberate them from the cloud.
> Hell, even the internet-loved Ecobee has a banner that shifts everything down most of the time that you open the app.
I don't want such apps. The only app I need is Home Assistant, and installing proprietary software on my phone (running GrapheneOS) is out of the question.
Also, all communication and telemetry should be opt-in and turned off by default.
Government-controlled server would prevent foreign countries from collecting intelligence and pushing malicious updates.
TP-Link is a prominent maker of network hardware, including home and mesh routers.
It's had the Huawei treatment?
It's one of the primary networking electronics brands in Australia.
As I write this, there are all kinds of TP-Link routers, mesh nodes, and cameras (oh my!) in stock at a nearby Wal-Mart, with pickup promised within a few hours from now.
But if people knew how easy it was to use the camera they bought to spy on their family, then I bet many would care.
But the only solution here is very expensive marketing, so...
You can ask chatgpt.not a great way.
And when you ask it you the secure answers cost 3x more. And than require an installar. And some(Google) require a monthly subscription.
And even about the good systems, the chat recommends, since there's no mathematical guarantee for security, that you "Switch them off or physically cover the lenses while you are home.".
99% of consumers won't know how to setup a firewall but could handle a checkbox
only problem I have is I can't seem to punch a hole for time sync and it won't use my local intranet time server
No idea if that helps with your particular devices; they are, of course, free to ignore those fields.