Also laut DB Doku (ich selber habe noch keine) kann sowohl eine Basic, als auch Digest Authentifizierung verwendet werden:
Wenn also ein Angreifer in dein Netz kommt (sei es durch das LAN Kabel an der DB oder evtl. übers WLAN, hat er ja noch immer die Hürde mit deinem Logikserver, der hinter der Firewall steht. Da würde schon ein einfacher MAC Filter reichen (ja ja, können auch geclont werden etc.)...
AUTHENTICATION
Please use Basic or Digest authentication as defined in RFC 2617 for each HTTP request. Use the same credentials as you are using to add a device to the DoorBird App.
Alternatively to authentication as defined in RFC 2617 you can you can use the plain- text HTTP parameters "http-user" and "http-password" to authenticate (more insecure because of plain-text, but some third-party home automation platforms support only HTTP parameters), e.g. "http://<device-ip>/bha-api/video.cgi?http- user=xxxxxx0001&http-password=xxxxxxx".
Copyright © 2021 by Bird Home Automation Gmb
Please use Basic or Digest authentication as defined in RFC 2617 for each HTTP request. Use the same credentials as you are using to add a device to the DoorBird App.
Alternatively to authentication as defined in RFC 2617 you can you can use the plain- text HTTP parameters "http-user" and "http-password" to authenticate (more insecure because of plain-text, but some third-party home automation platforms support only HTTP parameters), e.g. "http://<device-ip>/bha-api/video.cgi?http- user=xxxxxx0001&http-password=xxxxxxx".
Copyright © 2021 by Bird Home Automation Gmb
Kommentar