I pay for the Nabu Casa subscription for remote access to Home Assistant. Mostly as a way to give them money for a great service, but it’s convenient and felt pretty secure. It should be the only remote way into Home Assistant. About an hour ago I got a login attempt notice that an IP was trying to access API/config. The IP is in some bad IP databases. What I found interesting was that the log shows an AI bot. A Google Gemini bot specifically. Makes me worry that AI is going to make yet another aspect of life frustrating and unfun.

  • Reannlegge@lemmy.ca
    link
    fedilink
    English
    arrow-up
    1
    ·
    2 hours ago

    The only place that I use port 22, is my crowdsec pi. I use some other port than the traditional port for HA. I am slowly moving all my things out of the Apple ecosystem once I do I will setup some other blocking system for outgoing stuff, kinda like pihole but in reverse.

    Would highly recommend using an alternative port other than the default one for HA and 22.

  • Decronym@lemmy.decronym.xyzB
    link
    fedilink
    English
    arrow-up
    1
    ·
    edit-2
    58 minutes ago

    Acronyms, initialisms, abbreviations, contractions, and other phrases which expand to something larger, that I’ve seen in this thread:

    Fewer Letters More Letters
    ISP Internet Service Provider
    TLS Transport Layer Security, supersedes SSL
    VPN Virtual Private Network

    3 acronyms in this thread; the most compressed thread commented on today has 7 acronyms.

    [Thread #102 for this comm, first seen 11th Sep 2026, 19:50] [FAQ] [Full list] [Contact] [Source code]

  • Lka1988@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    5
    ·
    8 hours ago

    My router (unifi dream machine) offers regional blocking, so I block Russia, China, and a few others that I’ve gotten hits from. So far so good.

  • 0x4f1@lemmy.world
    link
    fedilink
    English
    arrow-up
    6
    ·
    edit-2
    10 hours ago

    Wireguard can solve secure remote access without* passwords. Android and iPhone both have clients that can be configured to bring the VPN up once you leave wi-fi. Bringing a third party into your home is just not wise.

  • daniskarma@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    11
    ·
    14 hours ago

    You have anything online you will be hammered by bots trying to get through. That’s the sad reality of the world we live on. It has been like that forever. I get hundreds of bot malicious scans on my server each day.

    All that’s left is to secure everything as hard as you can so they cannot break through.

    • SirLeToet@lemmy.world
      link
      fedilink
      English
      arrow-up
      6
      ·
      10 hours ago

      It’s been that case since forever now. Nothing has really changed and the same rules still apply.

      I still remember ‘hacking’ my ISP ADSL router 2+ decades ago and listening to the WAN interface. Hundreds of thousands of attempts per day in the early 2000s. Mostly US, Russia and China.

      My personal #1 threat on the internet for the past 20 years has been DDOS and thanks to billions of IOT devices and privacy invading ‘smart’ appliances everywhere… The botnets have never been this plenty. DDOS as a Service for mere cents a day.

      LLM’s joined the fray in recent years but it still can’t do anything it hasn’t learned from us humans.

  • frongt@lemmy.zip
    link
    fedilink
    English
    arrow-up
    54
    arrow-down
    1
    ·
    24 hours ago

    Welcome to the Internet. If it’s exposed, people and bots are going to be banging on it.

  • 4am@lemmy.zip
    link
    fedilink
    English
    arrow-up
    8
    ·
    21 hours ago

    I’ve got Nabu Casa and IPs from the “googleusercontent.com” domain have been hitting my instance about once per day for the last week or so.

    Use strong passwords and let’s hope that the login page doesn’t have any vulnerabilities…

    • InEnduringGrowStrong@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      6
      ·
      19 hours ago

      and let’s hope that the login page doesn’t have any vulnerabilities…

      Home assistant also supports mTLS.
      home assistant is something you’d likely ever want to allow from a handful of trusted devices, so deploying a client certificate on them can make sense.
      This way a non-onboarded device doesn’t even get to the html part, it’s denied upstream by a reverse proxy before HA is involved.

      • captcha_incorrect@lemmy.world
        link
        fedilink
        English
        arrow-up
        5
        ·
        17 hours ago

        I follow a guide for authelia and caddy, making it so that I can put authelia infront of anything without it the service behind supporting it. Still have to authenticate on the service behind but that is a small inconvenience.

  • Ebby@lemmy.ssba.com
    link
    fedilink
    English
    arrow-up
    20
    ·
    1 day ago

    I get frequent login attempts from Google servers too. I got the impression they offer a SaaS service some script kiddie uses to attack home assistant installations.

    Make sure passwords are unique and activate incorrect login bans.

    • SirLeToet@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      10 hours ago

      How are they casually finding these home assistant servers? I sure hope people dont have port 8123 exposed publicly like that? Are you all broadcasting it in to the ether?

      • dean@discuss.tchncs.de
        link
        fedilink
        English
        arrow-up
        2
        ·
        3 hours ago

        If you use a publicly trusted TLS certificate (either directly, or via Nabu Casa offering), domain will be recorded in Certificate Transparency logs.

        You can slightly hide it if you use a wildcard domain in the TLS certificate (e.g. *.example.com), and then use a subdomain for the service. Ideally, something that’s not home/hass/ha.example.com, or otherwise easily guessable.

      • Lka1988@lemmy.dbzer0.com
        link
        fedilink
        English
        arrow-up
        1
        ·
        8 hours ago

        Nabu Casa offers a reverse proxy through their own services. I run mine this way. Haven’t really had any problems with it in the year I’ve been subscribed.

      • Ebby@lemmy.ssba.com
        link
        fedilink
        English
        arrow-up
        1
        ·
        8 hours ago

        Haha heck no, at least not in my case. It’s not impossible to just stumble on the domain. An infinite monkey sorta thing.

  • Godnroc@lemmy.world
    link
    fedilink
    English
    arrow-up
    8
    ·
    1 day ago

    104.28.222.47? That one showed up in a log yesterday for me. Super glad the latest update added the option to see the IP for login attempts.

    • gdog05@lemmy.worldOP
      link
      fedilink
      English
      arrow-up
      8
      ·
      24 hours ago

      This one was 66.187.5.19. I tried to find a way to report their behavior on hostodo (the service they’re using) but they don’t seem to have a report option. I’m guessing because they don’t want to prevent this kind of thing.

  • SayCyberOnceMore@feddit.uk
    link
    fedilink
    English
    arrow-up
    2
    ·
    1 day ago

    I’ve not looked into Nabu Casa much, is it an outbound VPN from our HA instances to their servers? If so, maybe the Nabu Casa admins need a blocklist?

    • gdog05@lemmy.worldOP
      link
      fedilink
      English
      arrow-up
      2
      arrow-down
      1
      ·
      23 hours ago

      That is exactly it, yes. And I am thinking about reaching out to them about it and their blocklist. But after thinking about it, anyone with $16 in hosting can start an AI hacking instance. It’s just going to get worse.

      • Natanox@discuss.tchncs.de
        link
        fedilink
        English
        arrow-up
        1
        ·
        11 hours ago

        Not just that, companies are using “smart” devices as AI scraper botnets to utilize private, basically unbanable IPs. There are only very few companies who I might believe them not doing it (AllenAI and maybe Mistral - tell me if I’m proven wrong pls). But OpenAI, Anthropic, fucking Google and Meta, they all treat your network as their personal internet extension. It’s reasonable to assume any “Smart” device with wifi access that isn’t FOSS most likely being your enemy.

        Our family Nextcloud already got taken down by OpenAI swarming it… overloaded and crashed php-fpm within a minute. At least one client blasting all endpoints still advertised themselves as OpenAI crawler.

      • i_am_not_a_robot@discuss.tchncs.de
        link
        fedilink
        English
        arrow-up
        2
        ·
        21 hours ago

        This kind of thing has been going on since long before “AI.” Expect anything connected to the internet will have failed login requests. That’s why there is a login system.

        • SayCyberOnceMore@feddit.uk
          link
          fedilink
          English
          arrow-up
          1
          ·
          16 hours ago

          I agree this is an old thing, my firewall has blocklists and allowlists to prevent known bad IPs and allow only the countries I travel to.

          But if Nabu Casa is an outbound VPN, then my blocks won’t work. I’d need them to block

          Either way it would make sense for HA to also use some crowdsourced blocklists as a 2nd level defense