SQ9MDD / TTGO-T-Beam-LoRa-APRS

Use TTGO T-Beam as LoRa APRS Tracker
64 stars 23 forks source link

Security Issue: Make default Wifi Password changeable #51

Closed mi-gri closed 2 years ago

mi-gri commented 2 years ago

If you start the tracker and there is no WLAN configured or the configured WLAN is not in range, the default WLAN hotspot is started. This uses the configured callsign and SSID as network SSID and is therefore very easy to find and identify. Since there is a default password for the WLAN that cannot be changed via the web interface, someone who knows this (publicly discoverable) data can connect and change the tracker.

I therefore suggest that the WLAN password is made configurable via the web interface.

iu2frl commented 2 years ago

will work on this in next days

iu2frl commented 2 years ago

guess we can close this as in latest pull #74