Raspberry Pi Z-Wave kit exposes private key
blog.simplicify.me
blog.simplicify.me
This actually seems okay, the script should be loaded over https definitely but this ssh key part is really just giving a password to each device for connection.
Just wanted to note that SSH doesn't really have anything to do with SSL (e.g., it doesn't operate over an SSL transport). Might just be a typo though. Still seems really sketchy that they're using a reverse bind to (presumably) punch through NAT rather than something sane like just using UPnP or simply requiring correct network configuration.
When the author says that the system "exposes the private key", well, it's by design that the user can see it - since they need to use it to identify themselves to the SSH server. It's not much different from being assigned a password by the server. What could be improved is if it was transferred over HTTPS rather than HTTP, and of course also the install script.
(I only speak about the usage of SSH, it's possible that they still do something insecure..)
Well, in this particular case, they're using
ssh [..] -o 'StrictHostKeyChecking no' -o 'UserKnownHostsFile /dev/null' [..]
So the remote authentication bits are already out the window. It would be nicer if they included the host's public key in the installation package rather than eschewing it completely.To be fair the author didn't, the submitter did. I'm not sure if they are the same person.
Actually, SSH tunneling is a very secure way of transporting your web requests.
* And everyone in between.
If anything it's probably safer since it's explicit and more likely to be audited.
Perhaps the one-liner should be amended to check the hash of the file first, and only run if it matches.
One could argue that signed packages are still harder to check because publicly facing web servers are easier to hack, but you need to get the signature somewhere which is usually included in you distribution you downloaded through an insecure http or ftp connection.
It may be hard to exploit, but executing a script before you have completely downloaded it is simply a really bad idea.