This is SOP for IOT devices. I am beginning to think we need to regulate this stuff, because it is ubiquitous. The device manufacturers do not have a culture of security.
This is SOP for IOT devices. I am beginning to think we need to regulate this stuff, because it is ubiquitous. The device manufacturers do not have a culture of security.
There are much better ways of device enrollment; at a minimum they could require device activation that doesn't blindly use a token with no further checks.
I'm concerned about publicly accessible devices containing secrets also. These are not physically secure places to store keys, they are mounted on street lights where anyone with a ladder can get the key material out of the device.
It's like they have no threat model in place.