Discussion
Loading...

Post

  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
Terence Eden
@Edent@mastodon.social  ·  activity timestamp 2 weeks ago

Got the email that Belkin are killing off the WeMo cloud & app for their smartplugs.

Local control still works fine though. Easily integrated into HomeAssistant.

Lots of cheap WeMo bits on eBay if you want a local-first smarthome.

#WeMo #Belkin #HomeAssistant #IoT

  • Copy link
  • Flag this post
  • Block
Royce Williams
@tychotithonus@infosec.exchange replied  ·  activity timestamp 2 weeks ago

@Edent

Hey, great idea!

An idea: depending on your threat model, blocking WeMo domains / hostnames at your outbound border might be useful, as a hedge against Someone Bad registering the domains if Belkin forgets to renew it in a few years.

Looking around, there appear to be quite a few WeMo hostnames, but all appear to fall under these four domains:

xbcs.net
xwemo.com
wemo2.com
lswf.net

(Or fully isolate your IoT segment, but YTMMV - Your Threat Model May Vary!)

  • Copy link
  • Flag this comment
  • Block
Royce Williams
@tychotithonus@infosec.exchange replied  ·  activity timestamp 2 weeks ago

@Edent

Hey, great idea!

An idea: depending on your threat model, blocking WeMo domains / hostnames at your outbound border might be useful, as a hedge against Someone Bad registering the domains if Belkin forgets to renew it in a few years.

Looking around, there appear to be quite a few WeMo hostnames, but all appear to fall under these four domains:

xbcs.net
xwemo.com
wemo2.com
lswf.net

(Or fully isolate your IoT segment, but YTMMV - Your Threat Model May Vary!)

  • Copy link
  • Flag this comment
  • Block
Paul Hart
@paulhart@herester.ca replied  ·  activity timestamp 2 weeks ago

@Edent interesting… and it appears you can just discover the devices in HASS (and there’s essentially zero security locally? Quality IoT stuff…)

  • Copy link
  • Flag this comment
  • Block
Log in

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.0 no JS en
Automatic federation enabled
  • Explore
  • About
  • Members
  • Code of Conduct
Home
Login