Home Assistant Security Bulletin

This page summarizes the projects mentioned and recommended in the original post on /r/homeassistant

Our great sponsors
  • InfluxDB - Power Real-Time Data Analytics at Scale
  • WorkOS - The modern identity platform for B2B SaaS
  • SaaSHub - Software Alternatives and Reviews
  • Home Assistant

    :house_with_garden: Open source home automation that puts local control and privacy first.

  • This delta makes me think that they've caught some code trying to do some pretty nasty things via the HTTP based API. I'd like to think that this would be easily caught by any of the eyes that routinely work on the core, but I don't think it'd be super difficult to skirt by all that just by manipulating a library that one of the things in core depends on.

  • haaska

    Home Assistant Alexa Skill Adapter that supports v3 of the Alexa Smart Home Skill API

  • For example I use haaska to connect Alexa to my HA instance without the need for a cloud bridge service like Nabu Casa. This is not a malicious add on, it just exposes HomeAssistant commands as a REST API that is easy for Alexa/AWS Lambda to interface with. But when I open my instance up to the internet anyone can find my HA instance and start sending bogus commands to that API to try and trick it into leaking data.

  • InfluxDB

    Power Real-Time Data Analytics at Scale. Get real-time insights from all types of time series data with InfluxDB. Ingest, query, and analyze billions of data points in real-time with unbounded cardinality.

    InfluxDB logo
NOTE: The number of mentions on this list indicates mentions on common posts plus user suggested alternatives. Hence, a higher number means a more popular project.

Suggest a related project

Related posts