Closed Oliv59 closed 5 years ago
Tasmota is not meant for being reached from outside.
You need to use your home automation software for that.
If you do port forwarding in your router to reach the device you have a security problem! Not recommended and no support...
Sorry, isn't it the entire point of that sort of devices ? I don't have a home automation device at this place, but, even if i had a jeedom, for example, that wouldn't fix any security issues, right ? I don't see what are the differences between the one or the other ? Thanks for your help ;)
If you setup a Home Automation correct, you dont expose Tasmota and other devices to the "outside" world. You have a secured way to your HA System which is in the "inside" world and is controlling the this "things" So for secure use from apart a HA System is a must have...
Hey again, thanks for your explanations. Can you give me one (or more, if you feel patient enough today ;) ) examples of securities differences between this simple Sonoff (tasmota based, or original firmware), and a HA system ? For example, i use Jeedom at home (but this one is not for me), and i can't find why my jeedom is more secure than this simple Sonoff basic ? Though, i've been hitting my head on this question for the last 3 days ... Thanks for your help ;)
I didnt say that a setup with a HA system is general more secure. BUT on the platform where the HA is running are enough resources from hardware to do this via TLS VPN or or... use a firewall which only one route to one device! Security does need performance. Esp82xx just hasnt enough ressources to do this AND running Tasmota or similar stuff So i use for example OpenHab which just uses a https connecting from inside to a secured cloud service where just a web frontend exits. There is no mqtt traffic leaving home nor is a direct connection to devices
Remember that Tasmota has OTA capacity so, you can update the firmware from web. That means that if you port forward your Tasmota, a hacker can easily upload its own firmware to your sonoff and hack all your network broadcasting all your passwords and stuff. So, do not port forward a device that was not meant for that.
Please, search and read about securing your local network
A brief description of networking.
Your local network can't be reached using IP addresses from internet unless you port forward ports in your router. Doing that, you are opening paths for hackers to attack and steal information from you. Tasmota is not meant to be exposed to internet.
Tasmota is meant to be part of your home automation system, so you need a mqtt broker for that. If your broker is local (like running in a raspberry pi) all your information is not being shared with anyone outside you own LAN.
The case of the stock software of the sonoff devices, they use a server that is in china. So they connect to it and also your phone app connects to the same server. So, everything you do with your devices is being shared with iTead.
That is why, having an automation software that runs in your home only, in a raspberry pi for example, will give you independence from all the manufacturers. So, you will own your own information.
Then, this home automation softwares (like openhab, domoticz, home assistant, node red, etc etc) have some options for you to control them safely from Internet.
Hope this helps.
Hello,
First, thanks to all of you for all those information. Indeed, the MQTT and firmware update possibilities didn't come to my mind, that can be a good explanation. Thus, as this devis was bought especially for this part (and i don't have, and don't plan to but a complete HA), is there a firmware, working on this sonoff basic Device, who would JUST allow me to do what i planned to do basically by a web interface, meaning just send an impulse to the out ? Or is it totally unsafe / unreal dream ? Once more, thanks for your answers ;)
Short answer, unsafe not recommended. Because device is limited in resources.... To be on the safe side communication from device has to be from Inside to Outside. This can be reached via own HA system Inside or using a Cloud Service Outside (like eWelink) If you communicate direct from Outside to Inside to your device you have to Open your Inside world -> Unsafe
Hello there,
I've searched, but didn't find any information about this, and my issue is pretty simple, but impossible for me to fix it : i can't access my sonoff basic, flashed with Tasmota Firmware (Sonoff-Tasmota 6.2.1 by Theo Arends) a few days ago. I can access it form inside (same wifi network connection), but once my wifi is disconnected, and i'm connected through data (4G), no way to access it, always the ERR_CONNECTION_TIMED_OUT error. Tried through many browsers (Chrome, FF, IE), tried to forward different ports from my box to my sonoff (80, 82, 84), no way. Same ports redirected to other devices work fine from outside. I triple checked the destination IP forwarding, nothing wrong.
Any lead, any further test appreciated ;) Thanks,
Olivier.