{
  "id": 9687195,
  "title": "Home Assistant at Internet Scale: 2.7 Million Fingerprint Matches and the Automation Control Plane",
  "url": "https://urgent.news/2026/09/25/home-assistant-at-internet-scale-2-7-million-fingerprint-matches-and",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-25T02:40:35.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/kozhevniko/home-assistant-at-internet-scale-27-million-fingerprint-matches-and-the-automation-control-plane-39hg"
  },
  "original_language": "en",
  "account": "Home Assistant, a local-first automation platform, connects devices like lights, locks, cameras, thermostats, and alarm panels through a single interface. Designed to function independently from the internet, it operates on a small device inside the home. This design makes compromised credentials particularly valuable, as physical outcomes result from their breach.\n\nUsing ZoomEye's internet-facing service index, a query for \"Home Assistant\" yielded 2,711,859 fingerprint matches as of 2026-09-23 (UTC). It's important to note that these matches signify observed services, not confirmed installations or vulnerable hosts. A match indicates the service is observable from the internet, but verification is needed to ascertain the operator's intent and potential vulnerabilities.\n\nThe web interface operates on TCP port 8123, with HTTP integration settings governing trust and reverse proxy configuration. Many matches are behind reverse proxies terminating TLS, which may obscure the actual application. The platform supports multi-factor authentication, but older installations or those exposed via port forwarding warrant attention.\n\nLong-lived access tokens issued for integrations and scripts pose a risk since they lack expiration. Additionally, add-ons and the supervisor layer can extend the platform's reach into the host operating system, making an exposed instance more than just an automation interface.\n\nFingerprint matches reveal the existence of an automation platform surface, but they don't confirm weaknesses. The decision to accept this exposure depends on the specific installation, as the consequences can include control of doors and cameras. ZoomEye helps quantify the extent of exposure for consumer-grade automation platforms, which were initially designed for private networks and later connected to the public internet.\n\nDefenders should locate their installations, prefer authenticated access paths over port forwards, enable multi-factor authentication, and regularly audit long-lived access tokens. Keeping the platform and add-ons updated and treating the host as a device with physical authority are crucial steps to mitigate the risks associated with this exposure.",
  "summary": "Home Assistant at Internet Scale: 2.7 Million Fingerprint Matches and the Automation Control Plane Home Assistant is a local-first automation platform: one host that talks to lights, locks, cameras, thermostats and alarm panels, and presents them through a single interface. The design goal is that the house keeps working when the internet does not, which is why the software is commonly run on a…",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}