Customer Exposure To The Internet

30 comments started 2026-02-20 last 2026-05-04
Home AutomationHome Assistant
#1 Maxwell

It appears that one of our fellow GE customers may be oversharing to the web. Not sure if they are on here. But i have included some details here that may help someone identify themselves without further exposing their ip details.

They are exposing their GivTCP config web page (in the clear)

They also have their HA login exposed (in the clear without any encryption)

They also have a dashboard view exposed. But, there is something wrong with how they set this up as the data on the page hasn't changed since i first discovered it.

They are also exposing Mosquitto on port 1883, could be disabled as they are also using 8883

They are using Vodaphone as their ISP and use duckdns.

I can't see any other details that would allow me to reach out privately to GE with customer specific details like serial numbers etc. I appreciate that they may already be aware of how they have set this up and are content with it.

#2 hoggy

I find a few of these every few months. I just send them to Paul to get in contact with them. I'm not going to go into how, but you can get the serial number out of exposed ones.

W
#3 wrighar

I did this last January (2025), exposed rest calls etc.
Paul L pinged me a message and I closed it all down.

#4 Maxwell

hoggy Is there a GE email that i can reach Paul at as there are a couple of others with similar issues.

M
#5 M_J

Hmmm how do we check our own set-up?

M
#6 mrand31

Hmm, the only way I can see this happening is if one used port forwarding on ipv4 or a routed connection with no firewall on ipv4 or ipv6. Care to elucidate on the way that this is happening?

R
#7 Rubikcube

M_J how do we check our own set-up?

Just port scan your external IP address(es) from an external source.

If you don't know how to do that, just ask yourself have you ever blindly followed instructions (that you found on the internet) that mention port forwarding without understanding what you were doing?

G
#8 geoffreycoan

For most people their home broadband router acts as a NAT device so you’d have to create a wildcard port forward (if you can even do that) to expose the HA login, givtcp config, mqtt, etc.

The default duckdns config includes SSL and in fact that was part of the reason I stopped using it as I got fed up with SSL on my local network.

#9 Maxwell

M_J Start by getting the ip address from your router (the ip address that your internet service provider assigns). Then if you have set up Home Assistant and kept defaults then check if you have exposed it to the web by taking say your mobile and using mobile connection or connect your phone to your guest wifi (assuming you aren't using the guest wifi for your GE/HA set up). Then in your phone's browser address bar just type your isp assigned ip address followed by a colon and then 8123

eg if your isp assigned ip address was 353.395.374.333 then type

353.395.374.333:8123

(and i have deliberately chosen invalid numbers for the sample ip here in order to prevent someone from copying and pasting an actual address)

If you get your HA login, as shown in my earlier post then you have this exposed.

And as Rubikcube says this would be a sign you have set up port forwarding. And you would have to check your router's user manual to work out how to disable that.

#10 Maxwell

Still, GE customers are not alone. And I haven't tried clicking or changing any settings but the mouse pointer does change when you move over any of those selectable items. And they are using Homebridge rather than Home Assistant and again they have their HB login exposed

G
#11 geoffreycoan

Agree there a number of worrying services exposed here and all too many bad actors running port scans all the time.

I’m not sure that having HA exposed is immediately a risk as its login secured, and if 2FA is turned on then that gives extra protection. It would have been better if it was port forwarded to a different port from 8123 and even better if VPN secured.

Exposing Mosquitto and the GivTCP web config are more concerning as these don’t have any security login controls.

#12 ChrisLav

Assuming all these examples are from pics of graphs etc posted on the forum, surely the simplest solution would be for the user to NOT post the entire picture, ie, crop out the address bar. Easily enough done if you're on a PC, less so on a phone, but nevertheless not that hard to do...
Or am I missing something?

#13 Maxwell

ChrisLav I have redacted the ip address elements of the url. I included that line to show that those pages were using http rather than https. So any login details like username and password that gets sent from the user will be sent in the clear.
So geoffreycoan if one of these users is on a poorly secured public WiFi network then those credentials are at risk of compromise. Whilst robust MFA may help protect such logons I would suggest that based on the other evidence we can see that these users probably won’t have set up MFA, even if it is supported. I appreciate that everyone’s risk appetite is different. But, I am not a big fan of exposing management plane logins to the web.

#14 hoggy

Maxwell I have him on messenger normally. I think I have his email but I doubt he wants it posting on here.
We can try a summoning spell if we all hold hands in a circle and chant Saint Paul (@TheDragon (GivEnergy))

#15 ChrisLav

Maxwell I appreciate that you have redacted those details, but presumably the original (from whomever it was that posted it) was unredacted. Yes, they should be aware that they are exposing sensitive information on the web, but if they choose to do so then I would say Darwin's Law applies, and it's just Evolution in Action (pace L Niven & S Barnes)

#16 hoggy

ChrisLav these will have come directly from @Maxwell - there is a search engine for this kind of thing, so these won't be from another post but images taken directly from whoever this system's is by the op.

#17 Maxwell

ChrisLav I see it simply as helping a fellow community member make their community sourced solar home automation solution more secure. And also raising wider community awareness of the challenges when using such solutions. It’s great that there is a community provided range of solutions to help folks do this. But equally there is a big variation in user skill out there.

#18 ChrisLav

hoggy Ah. So I was missing something. Thanks for the explanation

#20 Maxwell

TheGuru I reckon ChrisLav is on their security email team 😉 I reached out at the weekend asking if this was the sort of thing they deal with. I didn't send the unredacted data. Alas, no response as yet. But one customer is still exposed.

#21 Maxwell

Just replied there to an email from security today.

#22 Maxwell

The 2 ip addresses remain exposed. Or have they both set up a honey trap ?

#23 Maxwell

hoggy As slow as ever me. Just twigged on how to do that. Doh………

#24 Maxwell

@TheDragon (GivEnergy) Are the remaining bods still dealing with exposed customers to the web via the security email. Or should I just pop their inverter serial number into the chat and hope they are on here and self identify ?

#25 TheDragon (GivEnergy)

Maxwell all of Giv made redundant.
Sorry.

S
#27 SteveCook

TheDragon (GivEnergy)
Sorry to hear your news and thankyou for all the support you have given me over the last 4 years

#28 Maxwell

So if you have an AC Gen1 Inverter with serial number CE2223G125 then you are exposing your givtcp setup and are also exposing the ability for someone to change settings on your device. If you are doing that intentionally then that is your risk to take. But, otherwise I would recommend checking your router's settings and removing any port forwarding you have set up.

T
#29 The_Engineer

TheDragon (GivEnergy) I think your contributions to the forum were welcomed by all, and certainly by me. I wish you and your colleagues every success. Remember it is the post/job that was made redundant, the person is still as capable and caring as they ever were.

R
#30 Rubikcube

It seems to me that both The Dragon and EV Man would make good Driving Instructors. Teaching in EVs is much easier without the gears and stalling the clutch. Just a thought, don't know if they want a career change.