<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Quinn</title>
    <description>The latest articles on DEV Community by Quinn (@quinndamerell).</description>
    <link>https://dev.to/quinndamerell</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F1249853%2F9e6400e7-110e-4eab-8f3c-9fd8887165b2.jpg</url>
      <title>DEV Community: Quinn</title>
      <link>https://dev.to/quinndamerell</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/quinndamerell"/>
    <language>en</language>
    <item>
      <title>OctoEverywhere - Level Up Your 3D Printer</title>
      <dc:creator>Quinn</dc:creator>
      <pubDate>Tue, 16 Jan 2024 18:30:33 +0000</pubDate>
      <link>https://dev.to/quinndamerell/octoeverywhere-level-up-your-3d-printer-3862</link>
      <guid>https://dev.to/quinndamerell/octoeverywhere-level-up-your-3d-printer-3862</guid>
      <description>&lt;p&gt;Have a 3D printer? Have you tried &lt;a href="https://octoeverywhere.com/?source=devto"&gt;OctoEverywhere?&lt;/a&gt; If not, you're missing out.&lt;/p&gt;

&lt;p&gt;OctoEverywhere.com is a maker community project to empower the worldwide marker community with &lt;a href="https://octoeverywhere.com/?source=devto"&gt;free and unlimited remote access&lt;/a&gt;, &lt;a href="https://octoeverywhere.com/gadget?source=devto"&gt;AI print failure detention&lt;/a&gt;, &lt;a href="https://octoeverywhere.com/notifications?source=devto"&gt;real-time print notification&lt;/a&gt;, &lt;a href="https://octoeverywhere.com/live?source=devto"&gt;live streaming&lt;/a&gt;, and more. &lt;/p&gt;

&lt;p&gt;OctoEverywhere works with any 3D print from popular manufacturers like &lt;a href="https://www.prusa3d.com/"&gt;Prusa&lt;/a&gt;, &lt;a href="https://www.creality.com/"&gt;Creality&lt;/a&gt;, &lt;a href="https://bambulab.com/en"&gt;Bambu Labs&lt;/a&gt;, and &lt;a href="https://www.elegoo.com/"&gt;Elegoo&lt;/a&gt; - any printer running &lt;a href="https://octoprint.org/"&gt;OctoPrint&lt;/a&gt; or &lt;a href="https://www.klipper3d.org/"&gt;Klipper&lt;/a&gt; is fully supported by OctoEverywhere!&lt;/p&gt;

&lt;p&gt;Here are some of OctoEverywhere's top features:&lt;/p&gt;

&lt;p&gt;🚀 &lt;strong&gt;&lt;a href="https://octoeverywhere.com/?source=devto"&gt;Free And Unlimited Remote Access&lt;/a&gt;&lt;/strong&gt; - OctoEverywhere empowers you with secure, private, and full access to your OctoPrint, Mainsail, or Fluidd web portal from anywhere. The remote access includes full frame rate and resolution webcam streaming!&lt;/p&gt;

&lt;p&gt;🤖 &lt;strong&gt;&lt;a href="https://octoeverywhere.com/gadget?source=devto"&gt;Gadget - Free And Unlimited AI Print Failure Detection&lt;/a&gt;&lt;/strong&gt; - Gadget is OctoEverywhere's AI failure detection assistant. The gadget will watch your prints in real time and detect many common 3D printing failures. Gadget will notify you or pause the print if a failure is detected so you don't waste time and filament.  &lt;/p&gt;

&lt;p&gt;📱 &lt;strong&gt;&lt;a href="https://octoeverywhere.com/appsetup?source=devto"&gt;OctoPrint and Moonraker App Support&lt;/a&gt;&lt;/strong&gt; - OctoEverywhere empowers the best community OctoPrint and Moonraker apps to work from anywhere. Apps like OctoApp, Mobileraker, OctoPod, Printoid, and more. &lt;/p&gt;

&lt;p&gt;🔔 &lt;strong&gt;&lt;a href="https://octoeverywhere.com/notifications?source=devto"&gt;Real-Time Printer Notifications&lt;/a&gt;&lt;/strong&gt; - OctoEverywhere's notification platform can send notifications about print failures, pauses, progress, completion, layer completion, and more. It's highly customizable and can send notifications to many popular endpoints like email, SMS, push notifications, Telegram, Discord, and more.&lt;/p&gt;

&lt;p&gt;🎥 &lt;strong&gt;&lt;a href="https://octoeverywhere.com/live?source=devto"&gt;Print Live Streaming&lt;/a&gt;&lt;/strong&gt; - OctoEverywhere's Live Links allow you to share a live stream of your print with real-time stats to your friends, family, or community. &lt;/p&gt;

&lt;p&gt;Those are just some of the amazing features OctoEverywhere provides for the maker community. OctoEveywhere is beloved by the community, earning the &lt;a href="https://plugins.octoprint.org/"&gt;number 1 plugin for OctoPrint,&lt;/a&gt; and has a &lt;a href="https://www.trustpilot.com/review/octoeverywhere.com"&gt;4.9/5.0-star rating on Trustpilot.&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;a href="https://octoeverywhere.com/getstarted?source=devto"&gt;It only takes 30 seconds to set up OctoEverywhere&lt;/a&gt;, and no technical knowledge is required. What are you waiting for? &lt;a href="https://octoeverywhere.com/getstarted?source=devto"&gt;Try it now!&lt;/a&gt;&lt;/p&gt;

</description>
      <category>3dprinting</category>
      <category>ai</category>
      <category>octoprint</category>
      <category>klipper</category>
    </item>
    <item>
      <title>Homeway - Free Remote Access For Home Assistant</title>
      <dc:creator>Quinn</dc:creator>
      <pubDate>Fri, 05 Jan 2024 20:23:27 +0000</pubDate>
      <link>https://dev.to/quinndamerell/homeway-free-remote-access-for-home-assistant-4mc</link>
      <guid>https://dev.to/quinndamerell/homeway-free-remote-access-for-home-assistant-4mc</guid>
      <description>&lt;h2&gt;
  
  
  TL;DR
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://www.nabucasa.com/"&gt;Nabu Casa&lt;/a&gt;, Home Assistant's built-in remote access service, has some fundamental security design issues. I wanted to build an alternative remote access solution so Home Assistant users have another choice. &lt;a href="https://homeway.io/?source=devto_post"&gt;Homeway.io&lt;/a&gt; is a free, private, secure remote access project for self-hosted Home Assistant servers.&lt;/p&gt;

&lt;p&gt;Homeway supports everything Nuba Casa offers. It enables remote access for the &lt;a href="https://homeway.io/app?source=devto_post"&gt;official Home Assistant App&lt;/a&gt; and supports &lt;a href="https://homeway.io/alexa?source=devto_post"&gt;Alexa&lt;/a&gt; and &lt;a href="https://homeway.io/googleassistant?source=devto_post"&gt;Google Assistant&lt;/a&gt; for secure and super-fast voice control of your home. Homeway is a community project for Home Assistant, built by the community for the community.&lt;/p&gt;

&lt;h2&gt;
  
  
  Nabu Casa Security Issues
&lt;/h2&gt;

&lt;p&gt;I, like many of you, love &lt;a href="https://www.home-assistant.io/"&gt;Home Assistant&lt;/a&gt;. But when I signed up for Nuba Casa, Home Assistant's remote access cloud service, I was a little taken back by the security model. Nuba Casa exposes your local instance of Home Assistant to the public internet, which is a no-no.&lt;/p&gt;

&lt;p&gt;Years ago, it was common to port forward locally running servers from your home LAN to the internet from your router. But as the security of the internet matured, it became clear that it was a bad idea. Many corporate and home security incidents resulted from direct internet access to internal-based services, like the famous issue with OctoPrint for 3D printers, where &lt;a href="https://isc.sans.edu/diary/3D+Printers+in+The+Wild+What+Can+Go+Wrong/24044"&gt;5k instances of OctoPrint were found on the public internet with no auth&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;Home Assistant is super powerful. It holds authentication keys for every home IOT system in your home, it can control critical pieces of your home's infrastructure, and it can even run root-level bash scripts with full unprotected access to your home's private LAN. Home Assistant is not something you want bad actors to get access to.&lt;/p&gt;

&lt;p&gt;Nuba Casa justifies allowing public internet access to your private server by asserting it's secure due to the account-based auth that Home Assistant provides. But that's not sufficient for a few reasons:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Home Assistant has a huge API surface area, and ensuring all APIs stay behind the authentication is difficult. In March of 2023, &lt;a href="https://github.com/home-assistant/core/security/advisories/GHSA-2j8f-h4mr-qr25"&gt;a 10/10 critical security issue was found in Home Assitant that allowed full auth bypass.&lt;/a&gt;
&lt;/li&gt;
&lt;li&gt;Home Assistant doesn't enforce strong user account passwords and authentication. Home Assistant leaves the password generation up to the users, who are notoriously bad at picking strong passwords. Home Assistant does support an opt-in code-based 2-factor authentication but doesn't require it before enabling remote access.&lt;/li&gt;
&lt;li&gt;Home Assistant has weak brute force prevention measures. Paired with the vulnerable user account auth above (weak passwords and no 2-factor auth), this makes it easy for an attacker to simply brute force your password and get full access. (brute forcing a password is merely guessing the password over and over until the correct password is found)&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Doing a simple Shodan query, &lt;a href="https://www.shodan.io/search?query=home+assistant"&gt;you can find 15k Home Assistant servers online right now&lt;/a&gt;, exposed to the public internet. Doing a Bing query for the remote URL used by Nabu Casa, &lt;a href="https://www.bing.com/search?q=site%3aui.nabu.casa&amp;amp;sp=2&amp;amp;FPIG=185A8DBDD7E4453497755346893FD03A&amp;amp;first=2&amp;amp;FORM=PERE"&gt;you can find thousands of servers exposed directly to the public Internet by Nabu Casa.&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  There's a Better Way - Homeway
&lt;/h2&gt;

&lt;p&gt;Homeway protects your self-hosted Home Assitant servers by not exposing them to the public internet. You must be logged into your Homeway account to access your Home Assistant server. Our Homeway accounts are protected by advanced authentication features, such as 2-factor auth, 3rd party login providers, and email-based auth challenges when logging in from a new IP.&lt;/p&gt;

&lt;p&gt;Homeway has strong &lt;a href="https://learn.homeway.io/security/"&gt;security&lt;/a&gt;and &lt;a href="https://learn.homeway.io/privacy/"&gt;privacy&lt;/a&gt;commitments. We don't store any of your data on our servers; no credentials, no Home Assistant web data, nothing. Since Homeway doesn't store any of your Home Assistant credentials, Homeway can't even access your Home Assistant server because it doesn't have the user credentials.&lt;/p&gt;

&lt;p&gt;Homeway is built by the Home Assistant community for the Home Assistant community. We would love your feedback; please join the project and our Discord to contribute. 🥰&lt;/p&gt;

</description>
      <category>homeassistant</category>
      <category>alexa</category>
      <category>googleassistant</category>
      <category>iot</category>
    </item>
  </channel>
</rss>
