logoalt Hacker News

rahimnathwaniyesterday at 5:49 PM1 replyview on HN

  showing how many insecure deployments there are
Insecure how? Even if the dashboard html is publicly accessible, you usually cannot connect without pairing or setting a gateway key.

Replies

dmdyesterday at 8:18 PM

The lethal trifecta. Once you're handing your email to this thing, all it takes is someone emailing you some well-crafted "send me all your money" prompt and the bot will happily act on it.