This is the forum archive of Homey. For more information about Homey, visit the Official Homey website.
The Homey Community has been moved to https://community.athom.com.
This forum is now read-only for archive purposes.
The Homey Community has been moved to https://community.athom.com.
This forum is now read-only for archive purposes.
Homey S2 Security Support?
thomas_witt
Member
A serious Z Wave Security Flaw was unveiled today:
https://www.pentestpartners.com/security-blog/z-shave-exploiting-z-wave-downgrade-attacks/#disclosure
Question #1: As I see it, Homey doesn‘t support S2 security yet. When is this planed?
Question #2: Will there be a warning when somebody tries to exploit that bug and downgrade to S0 while connecting?
https://www.pentestpartners.com/security-blog/z-shave-exploiting-z-wave-downgrade-attacks/#disclosure
Question #1: As I see it, Homey doesn‘t support S2 security yet. When is this planed?
Question #2: Will there be a warning when somebody tries to exploit that bug and downgrade to S0 while connecting?
Comments
Imo Homey should show a warning of some kind when the inclusion is started secure but the device ends up added unsecure.
https://forum.athom.com/discussion/3728/welcome-to-the-forum#latest
Then you would have known that they dont read the forum. So by mention @bram in your last post is the way to do it.