

9·
11 days agoThe good news is that there are a billion no-name brands in China etc. manufacturing drop-in replacement Arduino-compatible boards.
I got into microcontrollers through Arduino but very quickly moved to much cheaper (and tbh, better) third-party options.
Allowing a certificate without proper validation for local only networks is a terrible, terrible idea. I could super easily use this as a loophole to set up a honeypot public free wi-fi, redirect all traffic through a reverse proxy and man-in-the-middle every single HTTPS connection, effectively allowing me to harvest everyone’s passwords in a really quick and easy way.
Just use DNS verification. It’s not that hard.