You can change the name of the device after setup. So it’s still vulnerable to this attack post setup.One question that I may not have found the answer to because I didn't read every little bit of their blog post... It sounds like this is an issue that can only happen in the setup, like when you already have access to it's wifi network because it isn't paired?
Can you get to this state once it is setup and connected to your local network? Or is this just
IF you are setting it up.. and there is an attacker in wifi range, and they happen to exploit it in the 3 minutes you are setting it up, THEN once it finishes it could have remote access?
If that's the case it is really a non-issue
It doesn’t give them full access, or really any access, to “the devices on the network”. If that were the case, any visitor using your wifi has full acchess to your computer, which is not the case.This is really far reaching and doesn’t just allow the attacker to control the plug. It gives them full access to your network and the devices on the network.
Yeah, they might switch your lamp on and off to annoy you![]()
So people can have their new Belkin smart plug become obsolete in 4 years because that's how long Belkin thinks things should be supported for? Fool me once, shame on you. Fool me twice... nope, not going to happen.I think Belkin should have, if not possible to fix with an update, offered a 50% on a replacement plug.
Several years ago before the pandemic, I bumped into a colleague at Home Depot. He was running around with a cart collecting various smart devices to use in his home: lights, switches, whatnots. He was very excited about it. A few weeks or a month later, I bumped into him again at Home Depot and asked him how his smart home was doing and he said he returned all the smart devices because it was too much headache getting them to work in a way he wants.How frustrating. I have four of these. It’s already frustrating enough to have to incorporate new ones into my existing HomeKit automations, but now I have to spend $120+ just to have the same lights turn on and off in my existing setup without risking a network attack of some sort. All because Belkin chooses profit over responsibility and customer care. Gross.
This does make me wonder if someone on Github will come up with updated firmware for this device.Well, if Belkin is basically telling me to live with the flaw or buy a new plug, I'll buy a new plug - from a different company.
Several years ago before the pandemic, I bumped into a colleague at Home Depot. He was running around with a cart collecting various smart devices to use in his home: lights, switches, whatnots. He was very excited about it. A few weeks or a month later, I bumped into him again at Home Depot and asked him how his smart home was doing and he said he returned all the smart devices because it was too much headache getting them to work in a way he wants.
That's how I feel about these IoT's. In theory, they sound great. In practice, it's like you need to be a technical administrator of your house just to run things electronic. Sorry, I am really not interested in playing IT at home. I'm not an IT at work but I'm geeky enough such that colleagues turn to me to ask for IT help when we actually have a whole IT department we can turn to. Nope thank you![]()
I'm surprised people are surprised Belkin pulled this. Planned obsolescence for these sort of things is pretty common. Planned obsolescence is why I don't have many smart home/internet of things stuff in my house.
Belkin told Sternum that it has no plans to update the Wemo Mini Smart Plug V2 because it is at the end of its life after four years
It sounds fairly trivial to exploit, so there's a good chance someone will. A well-packaged, WiFi-enabled device like this could be useful for a number of purposes. The ability to run generic code on it might be really attractive.This does make me wonder if someone on Github will come up with updated firmware for this device.
The smarter and more capable hacker-bot will never give you any evidence that your Belkin device is infected.Yeah, they might switch your lamp on and off to annoy you![]()