‹ BackHN Continuity

Thread

Big Tech ruined the cloud, so we're renaming ours

212 points · 108 comments · 2sf5

  1. voidnullvalue · · focus · HN ↗
    Nabu Kasa keeps ignoring the elephant in the room of security and permissions. They have no native ability to set user groups and permissions. There is no serious RBAC. I guess it doesn't sell cloud subscriptions. I cant keep my children from affecting devices they shouldn't. I ended up replacing my automation with mqtt
    1. montjoy · · focus · HN ↗
      This is false. <a href="https:&#x2F;&#x2F;developers.home-assistant.io&#x2F;docs&#x2F;auth_permissions&#x2F;" rel="nofollow">https:&#x2F;&#x2F;developers.home-assistant.io&#x2F;docs&#x2F;auth_permissions&#x2F;
      1. voidnullvalue · · focus · HN ↗
        <a href="https:&#x2F;&#x2F;community.home-assistant.io&#x2F;t&#x2F;wth-no-rbac-role-based-access-control-users-groups-rights&#x2F;219581" rel="nofollow">https:&#x2F;&#x2F;community.home-assistant.io&#x2F;t&#x2F;wth-no-rbac-role-based...

        This thread is relevant. Their permissions system is just on entities, and isn&#x27;t a real EBAC system.

      2. hobofan · · focus · HN ↗
        I&#x27;m usually not one to jump quickly to that, but that&#x27;s a joke of a permission system.
        1. wildzzz · · focus · HN ↗
          I don&#x27;t understand, why is it a joke? HA permissions are just to lock certain users or groups out of controlling certain things. You wouldn&#x27;t be randomly giving out accounts to people you don&#x27;t know or trust. It&#x27;s the controls to your smarthome after all, not a shell account on an open sign-up server.
          1. hobofan · · focus · HN ↗
            &gt; HA permissions are just to lock certain users or groups out of controlling certain things

            Yes, but only very coarsly granular things.

            - Permissions only work with entities. There are about ten different kinds of objects besides entities, that would also benefit a lot from being part of a uniform permission system.

            - Permissions can only be defined for groups, not users, which is quite annoying if you want granular permissions

            - With permissions only acting on groups, it also isn&#x27;t possible to base permissions on user attributes. So you ultimately always have to model a permission set as a group, and then essentially have to have a synchronization mechanism that ensures that the right people are in the right groups

            - This also makes scoped integration access impossible. You can&#x27;t grant a third party app access to e.g. only your energy sensor data.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.