Comment on AI bot hacking/scraping Home Assistant
Cyber@feddit.uk 14 hours ago
I’ve not looked into Nabu Casa much, is it an outbound VPN from our HA instances to their servers? If so, maybe the Nabu Casa admins need a blocklist?
Comment on AI bot hacking/scraping Home Assistant
Cyber@feddit.uk 14 hours ago
I’ve not looked into Nabu Casa much, is it an outbound VPN from our HA instances to their servers? If so, maybe the Nabu Casa admins need a blocklist?
gdog05@lemmy.world 13 hours ago
That is exactly it, yes. And I am thinking about reaching out to them about it and their blocklist. But after thinking about it, anyone with $16 in hosting can start an AI hacking instance. It’s just going to get worse.
Not just that, companies are using “smart” devices as AI scraper botnets to utilize private, basically unbanable IPs. There are only very few companies who I might believe them not doing it (AllenAI and maybe Mistral - tell me if I’m proven wrong pls). But OpenAI, Anthropic, fucking Google and Meta, they all treat your network as their personal internet extension. It’s reasonable to assume any “Smart” device with wifi access that isn’t FOSS most likely being your enemy.
Our family Nextcloud already got taken down by OpenAI swarming it… overloaded and crashed php-fpm within a minute. At least one client blasting all endpoints still advertised themselves as OpenAI crawler.
i_am_not_a_robot@discuss.tchncs.de 11 hours ago
This kind of thing has been going on since long before “AI.” Expect anything connected to the internet will have failed login requests. That’s why there is a login system.
Cyber@feddit.uk 6 hours ago
I agree this is an old thing, my firewall has blocklists and allowlists to prevent known bad IPs and allow only the countries I travel to.
But if Nabu Casa is an outbound VPN, then my blocks won’t work. I’d need them to block
Either way it would make sense for HA to also use some crowdsourced blocklists as a 2nd level defense