Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Password protection for web interface? #60

Closed
smadds opened this issue Feb 12, 2017 · 3 comments
Closed

Password protection for web interface? #60

smadds opened this issue Feb 12, 2017 · 3 comments
Labels
question Type - Asking for Information

Comments

@smadds
Copy link

smadds commented Feb 12, 2017

I would like to discuss the feasibility and appetite for adding password protection to the web interface.
It seems to me that at the moment the Sonoffs are vulnerable to anyone logged into the same wifi network. Clearly one option is to create a hidden SSID wifi access point for Sonoff use, but if that is not an option, how can we secure the devices?

Would an admin password setting option on the 192.168.4.1 initial setup page work? If the password was forgotten a full system reset could start from scratch. Also, setting/resetting the admin pw from MQTT could be possible as access to the MQTT server can be secured.

Thoughts?

@arendst
Copy link
Owner

arendst commented Feb 13, 2017

Quick solution: disable webserver with option 0.

@smadds
Copy link
Author

smadds commented Feb 13, 2017 via email

@hoekbrwr
Copy link

hoekbrwr commented Feb 13, 2017

🔒
🔓 through MQTT!
Very nice tip!

@arendst arendst added the question Type - Asking for Information label Feb 14, 2017
@arendst arendst closed this as completed Feb 15, 2017
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
question Type - Asking for Information
Projects
None yet
Development

No branches or pull requests

3 participants