Jump to content
View in the app

A better way to browse. Learn more.

Universal Devices Forum

A full-screen app on your home screen with push notifications, badges and more.

To install this app on iOS and iPadOS
  1. Tap the Share icon in Safari
  2. Scroll the menu and tap Add to Home Screen.
  3. Tap Add in the top-right corner.
To install this app on Android
  1. Tap the 3-dot menu (⋮) in the top-right corner of the browser.
  2. Tap Add to Home screen or Install app.
  3. Confirm by tapping Install.

Insteon Hub Security issue

Featured Replies

Is anyone familar with this reported issue on the hub?  Any workarounds?  Is Smarthome addressing this issue? I know some are running Insteon hubs in parallel to the ISY, so I thought this might be relevant.  Is this even something to be concerned about? 

 

Quote from article: "Rapid7 discovered two unpatched issues related to authentication and radio transmission security of the Insteon Hub. Firstly the account login and passwords for both Insteon services and the Hub hardware are stored unencrypted. In addition the radio transmissions between the hub and connected devices are unencrypted. This means malicious actors can easily capture the radio signals at any time to manipulate any device being managed via the Insteon Hub."

 

https://www.theregister.co.uk/2017/09/25/home_hub_insecurity/

 

 

Is anyone familar with this reported issue on the hub?  Any workarounds?  Is Smarthome addressing this issue? I know some are running Insteon hubs in parallel to the ISY, so I thought this might be relevant.  Is this even something to be concerned about? 

 

Quote from article: "Rapid7 discovered two unpatched issues related to authentication and radio transmission security of the Insteon Hub. Firstly the account login and passwords for both Insteon services and the Hub hardware are stored unencrypted. In addition the radio transmissions between the hub and connected devices are unencrypted. This means malicious actors can easily capture the radio signals at any time to manipulate any device being managed via the Insteon Hub."

 

https://www.theregister.co.uk/2017/09/25/home_hub_insecurity/

 

Great article and its interesting how quickly Wink offered a patch to the Android platform. I can't honestly say this will be the case for the Insteon Hub as way back in the day the Hub v1 had similar issues. The Smartlabs company never resolved that issues for existing users and simply released a Hub v2. Then, later released what many know as the Hub which is technically called the Hub II.

 

If this article pushes the new owner of Smartlabs to finally push for encryption in all aspects. good! 

I saw that in a link on Insteon.com forums. A few days ago.

Since it is put out as a User To User Forum. There are no posts to it from anyone yet.

I suspect Smartlabs may read it but will not comment on it.

I saw that in a link on Insteon.com forums. A few days ago.

Since it is put out as a User To User Forum. There are no posts to it from anyone yet.

I suspect Smartlabs may read it but will not comment on it.

 

One would hope they do more than just read the forum thread. But, if history is any indicator a break fix won't be forth coming very quickly ~ if at all. You all know what they say about *Hope*. 

 

Hope don't float . . .

 

Interesting...

 

In addition the radio transmissions between the hub and connected devices are unencrypted. This means malicious actors can easily capture the radio signals at any time to manipulate any device being managed via the Insteon Hub
This is a feature of Insteon, not a flaw. It’s why you shouldn’t use Insteon to control a garage door.

Is anyone familar with this reported issue on the hub?  Any workarounds?  Is Smarthome addressing this issue? I know some are running Insteon hubs in parallel to the ISY, so I thought this might be relevant.  Is this even something to be concerned about? 

 

Quote from article: "Rapid7 discovered two unpatched issues related to authentication and radio transmission security of the Insteon Hub. Firstly the account login and passwords for both Insteon services and the Hub hardware are stored unencrypted. In addition the radio transmissions between the hub and connected devices are unencrypted. This means malicious actors can easily capture the radio signals at any time to manipulate any device being managed via the Insteon Hub."

 

https://www.theregister.co.uk/2017/09/25/home_hub_insecurity/

We have been hearing this for years and yet nobody has been able to make it happen despite some pretty smart ones trying.

 

The protocol was found to not follow the white papers SH published.

 

I think it all comes back to the perceived end gain is not worth the effort for criminals. My "Protected by Insteon" stickers are doing the job as well as any of the other security brands ever did. :)

  • Author

I think it all comes back to the perceived end gain is not worth the effort for criminals. My "Protected by Insteon" stickers are doing the job as well as any of the other security brands ever did. :)

 

I prefer the security sign "Protected by the Smith & Wesson Protocol" myself.  :-P

I prefer the security sign "Protected by the Smith & Wesson Protocol" myself. :-P

A number of years ago a large group of us banded together in hopes of cross knowledge sharing.

 

In almost every area from agriculture, medical, plumbing, electrical, engineering, framing, networking, fire fighting, deep well drilling, security, industrial applications, solar PV / off grid, force protection, winter survival, hand to hand combat, communications, and many other soft skills.

 

Since many of us enjoy shooting and plinking.

 

As an inside joke, Team 86 put this out at a few locations in the field and at home.

 

6588181f4787eb991a35fbe7972a56de.jpg

 

 

Archived

This topic is now archived and is closed to further replies.

Configure browser push notifications

Chrome (Android)
  1. Tap the lock icon next to the address bar.
  2. Tap Permissions → Notifications.
  3. Adjust your preference.
Chrome (Desktop)
  1. Click the padlock icon in the address bar.
  2. Select Site settings.
  3. Find Notifications and adjust your preference.