Skip to content

Comment on How Apple Watch Unexpectedly Measured My Vitals During a Car Crashparent

Comments

I can hijack a DNS entry and host a server pretending to be you

Not for long.[1]

[1] https://blog.mozilla.org/security/2015/04/30/deprecating-non...

The solution to this is very simple: cut off their access entirely.

I use an SSL proxy at home and if you attempt to pin certificates such that the local certificate store is ignored or inaccessible. Your device can be guaranteed to not have access from my network. End of story.

I don't think these watches use a browser to reach their servers (i.e. the cloud).

Once it's the norm for browsers it wouldn't make much sense not to use HTTPS everywhere.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.