Bests & Worsts Reviews from Amazon

according to people

381
people found this helpful, as of 2023
ranked #57,324 most helpful out of 571,544,897 reviews
★★★★☆
Technical Info (network ports etc)
I looked at the smart socket briefly to see what it does over your network. Nothing seems unreasonable but you should know; It uses a mixture of HTTP and MQTT (messaging), with some encryption. Uses an ESP8266 processor. Your device has a unique ID which consists of some prefix (serial #?) and the device's MAC address, e.g. 0120073868c63a97eee4 (last 12 digits are the MAC) a) When powered up it connects to mq.gw.tuyays.com (TUYA US) via http to say hello and get the address of the messaging server b) Opens an MQTT TCP connection to that server on port 1883, and subscribes to a topic e.g. smart/device/in/0120073868c63a97eee4 c) The device pushes messages over MQTT when you push the physical on/off button on it, and recieves them from the server (which, for US users, is on Amazon AWS in Portland, Oregon) when you use e.g. Google Home to switch it. Essentially, your messages are going via a US situated server run by this company (Tuya). d) When the device starts up it checks for updated firmware (the request/reply appears to be signed thankfully). The company can presumably push down any firmware updates they like whenever they like. e) The device itself is certainly physically capable of "allowing intruders in" to your network, i.e. providing a tunnel from the outside into your LAN, say forwarding packets for someone exploring your network. This is scary, but it's an inevitable part of how this stuff works. There are no guarantees that current or future firmware on these things doesn't contain a back door. If you are concerned about security on your LAN clearly this device could be an attack vector (as could many home automation devices). Options: 1) You could set up separate wifi "guest" network that connects to your (cable modem) via an ethernet switch in parallel to your main home networking NAT; i.e. your ISP will see two separate client networks and give them separate IP addresses on the internet. 2) You could configure your wifi network to not allow these devices to communicate with other computers on your LAN; i..e lock them down so they can only connect out to the internet. This isn't at all a bad idea although not bulletproof (mac spoofing) If they sell millions of these it's quite possible someone will consider hacking their "update" server to be good fun/profit, likely with newsworthy results.
December 2017 · Unknown
the product in question
See the Product
worser bester