Skip Navigation

InitialsDiceBearhttps://github.com/dicebear/dicebearhttps://creativecommons.org/publicdomain/zero/1.0/„Initials” (https://github.com/dicebear/dicebear) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)AC
Posts
3
Comments
439
Joined
2 yr. ago

  • The chicken coop controller needs access to use whatever drivers (Bluetooth?) to connect. On the other hand, they could have used Wi-Fi instead. The financial app, however, definitely should be a website. However, apps are a way to increase the longevity of the login token because apps on a non-rooted phone supposedly cannot leak the login token and can be trusted to keep it safe on the device.

  • that's really concerning because it bypasses a browser password manager security measure. Since the domain is the same but the server ip and the server's https certificate chain is different, a poorly written password manager may auto-login or automatically send cookies to a website owned by a completely different entity on the same domain name. Big security flaw in domain name trust?