logoalt Hacker News

jabedudelast Friday at 8:55 PM1 replyview on HN

I didn't notice a negative tone at all when he talked about the firmwares being publicly hosted. You did?


Replies

AceJohnny2last Friday at 11:01 PM

Yes, heavily, because of the use of adjectives and repeating the points.

Here, I'll emphasize the words that elicit the tone:

> After some basic reversing of the Tapo Android app, I found out that TP-Link have their entire firmware repository in an open S3 bucket. No authentication required. So, you can list and download every version of every firmware they’ve ever released for any device they ever produced: [command elided] The entire output is here, for the curious. This provides access to the firmware image of every TP-Link device - routers, cameras, smart plugs, you name it. A reverse engineer’s candy store.

Highlighting (repeatedly) the ease and breadth of access is a basic writing technique to illustrate the weakness of a security system.

show 4 replies