logoalt Hacker News

coldbrewedyesterday at 10:41 PM1 replyview on HN

There are much better ways of device enrollment; at a minimum they could require device activation that doesn't blindly use a token with no further checks.


Replies

carefree-bobyesterday at 11:01 PM

I'm concerned about publicly accessible devices containing secrets also. These are not physically secure places to store keys, they are mounted on street lights where anyone with a ladder can get the key material out of the device.

It's like they have no threat model in place.