Announcement

Collapse
No announcement yet.

Security Hardening HS4 hub

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

    Security Hardening HS4 hub

    Due to the placement of my HomeTroller Plus Smart Home Hub (HS4), I need to use Wi-Fi and connect using RDP. As with all electronics, I understand the need to restrict access to undesirables. Even if I do not use them, all suggestions are welcomed.

    For my Wi-Fi access point, I created a LAN just to connect with the hub. It uses L2 Isolation (probably not needed), PMF, the Wi-Fi name is hidden and it is filtered on the MAC address of the hub.

    On the hub, I gave it a static IP address, turned off network discovery and set the network profile to "Public." Also unchecked File and Printer Sharing for Microsoft Networks.

    Some of what I would like to do are:
    1. Change the host name from HomeTrollerPlusG1 to something else.
    2. Delete the homeseer account and create one with a different user name and password

    Will either 1 or 2 break anything?

    Any other suggestions on what I might want to do or to avoid? I'm fairly brave but do not want to brick my hub.

    #2
    Personally I wouldn't put an RDP enabled host on the Internet unless you put a gun to my head. The last Windows 10 RDP CVE was published less than 2 weeks ago. CVE-2021-31186 : Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability (cvedetails.com)


    Sent from my Pixel 2 using Tapatalk

    Comment


      #3
      I agree and would never put RDP on any system in any network. You might as well broadcast the systems presence and username/password for the Admin account.

      Originally posted by mterry63 View Post
      Personally I wouldn't put an RDP enabled host on the Internet unless you put a gun to my head. The last Windows 10 RDP CVE was published less than 2 weeks ago. CVE-2021-31186 : Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability (cvedetails.com)


      Sent from my Pixel 2 using Tapatalk

      Comment


        #4
        What about enabling RDP for the local network, requiring a VPN connection if you do want to use RDP?

        Comment

        Working...
        X