-
Notifications
You must be signed in to change notification settings - Fork 220
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Security? #376
Comments
The original firmware has no protection. https://github.com/pvvx/ATC_MiThermometer#custom-firmware-for-ble-thermometers-on-the-telink-chipset -> Key features: If the PIN code in the thermometer is active, setup and other functions (firmware updates) will not be available without connecting to a device that has the correct PIN code. |
Ok, so basically just do the firmware switch in a safe place. Is it possible without using a website? |
It is also possible to enter a PIN code in the "nRFConnect" program when connected to a thermometer by a special command. Plus, it is possible to enter a PIN code using a variety of Bluetooth utilities. |
From reading the instructions, it sounds like there's zero interaction with the device itself to flash? What prevents a malicious actor from putting their own firmware on? Is it even possible to secure these devices?
The text was updated successfully, but these errors were encountered: