rjp
I understand that a connection can be kept alive, but that means that technically if you open a connection to GE, they can come in via that open door. That also means that data can be taken out of the inverter or in fact the connected network..
At no point is the user being asked to allow inbound connections, which frankly is not OK if that is what is being done.
If someone can remotely ask the inverter to download new firmware, there is nothing to stop new image being sent down which allows a shell or even just a routing configuration which allows direct access to a home network, which this device is already inside. At the very least I would expect a "GE have asked to initiate activity X APPROVE/DENY" type prompt in the app.
If it is as you say, then it's a pretty easy way to connect to the router, upload firmware or just connect to an unprotected NAS and then suck the data off to whoever is waiting.
I keep any products that have IoT/Cloudy interfaces very much separate, but this would be sitting in absolute isolation.
And this is before we even touch on the unencrypted piece. At least my reverse VPN tunnel would have used encryption and isolation of sessions, albeit only if the cloudy side of things also keeps data isolated.