ATO being hacked.

Basic / Standard Reef Angel hardware
Post Reply
butcherman
Posts: 44
Joined: Thu Apr 05, 2012 11:14 am

ATO being hacked.

Post by butcherman »

What can I do about someone hacking my RA unit. I will get home after work and the ato is stuck in the on position and all my ro has been dumped and the pump is running dry. if I access the unit via my cell it need the green dot cleared in order to stop. Please help asap
User avatar
lnevo
Posts: 5422
Joined: Fri Jul 20, 2012 9:42 am

Re: ATO being hacked.

Post by lnevo »

Click on the green dot?
butcherman
Posts: 44
Joined: Thu Apr 05, 2012 11:14 am

Re: ATO being hacked.

Post by butcherman »

Well done! I click the dot and its stops. That does not explain why the dot came up in the first place. Ir the fact that the entire ro tank has been dumped or that the pump has run dry for 7 hours

Sent from my GT-I9500 using Tapatalk
butcherman
Posts: 44
Joined: Thu Apr 05, 2012 11:14 am

Re: ATO being hacked.

Post by butcherman »

Ie someone other that me is turning the ato pump on

Sent from my GT-I9500 using Tapatalk
butcherman
Posts: 44
Joined: Thu Apr 05, 2012 11:14 am

Re: ATO being hacked.

Post by butcherman »

correct me if I am wrong but all that is needed to access and remote control another persons RA is the DNS name and the portal name no password or authentication?
KRavEN
Posts: 104
Joined: Sun Mar 17, 2013 8:21 am

Re: ATO being hacked.

Post by KRavEN »

You can set a password on it. Also possible you accidentally clicked the ATO manual override when you were using the web interface. More plausible than someone maliciously accessing your RA and knowing to dump your ATO.

Perhaps Roberto would consider adding a new feature to confirm manual override?
User avatar
lnevo
Posts: 5422
Joined: Fri Jul 20, 2012 9:42 am

Re: ATO being hacked.

Post by lnevo »

butcherman wrote:correct me if I am wrong but all that is needed to access and remote control another persons RA is the DNS name and the portal name no password or authentication?
They would also need to either download the app or understand the RA api to control it through an http interface. You can set a portal key which would require that be added to the http strings and set inside the app. This is effectively the password and the only way someone could get that is sniffing your traffic. The portal is already password protected by your forum password. Your best method is to add a security key.

What KraVen said is probably accurate. You most likely hit the button by mistake and overrode it yourself.

What I've done for critical ports (like dosers) is add a variable called OverridePorts that you can set which ports can not be overriden manually. This would be good to add on your ATO pump. It would still run the normal program but anytime someone tries to manually change the port it will get removed automatically.

You can set another condition like a memory variable change or another relay being on/off to change the OverridePort variable and then allow you to control the port you want.
butcherman
Posts: 44
Joined: Thu Apr 05, 2012 11:14 am

Re: ATO being hacked.

Post by butcherman »

Its happened several times I did not hit it by mistake. Once was while I was sleeping at night

Sent from my GT-I9500 using Tapatalk
butcherman
Posts: 44
Joined: Thu Apr 05, 2012 11:14 am

Re: ATO being hacked.

Post by butcherman »

I belive is a vindictive reefer

Sent from my GT-I9500 using Tapatalk
User avatar
lnevo
Posts: 5422
Joined: Fri Jul 20, 2012 9:42 am

Re: ATO being hacked.

Post by lnevo »

I would definitely add a portal key and then I would look at using my OverridePorts functionality to ensure it can never happen again key or no key
User avatar
lnevo
Posts: 5422
Joined: Fri Jul 20, 2012 9:42 am

Re: ATO being hacked.

Post by lnevo »

The only issue with the override ports is that it may not work right if you are disabling the ato during feeding or water change modes. A one line piece of code would fix that too.
ReEfnWrX
Posts: 232
Joined: Tue Nov 05, 2013 8:40 am
Location: Houston TX

Re: ATO being hacked.

Post by ReEfnWrX »

lnevo wrote:The only issue with the override ports is that it may not work right if you are disabling the ato during feeding or water change modes. A one line piece of code would fix that too.

There is a difference between overriding and coding for the ATO to turn off during certain events.... So I don't see that being an issue.
Image
User avatar
lnevo
Posts: 5422
Joined: Fri Jul 20, 2012 9:42 am

Re: ATO being hacked.

Post by lnevo »

You dont understand how that is working...

When you go into feeding mode or water change modes, whatever ports you have set to go off get an override off command. After that you can do whatever you want so if you cancel one of those overrides the device will turn on.

With the OverridePorts option any override mask will be removed before it gets power. So if you disable ATO as part of you water change ports then when you go into water change mode the override will get removed. Therefore you will need a line of code to hard code the port off during water change mode... Does that make sense?
mls228
Posts: 19
Joined: Thu Mar 21, 2013 6:40 pm

Re: ATO being hacked.

Post by mls228 »

Also check for noisy wiring. I had a similar situation where the pwm signal wiring was tripping my ato. I isolated the two and no more issues.
butcherman
Posts: 44
Joined: Thu Apr 05, 2012 11:14 am

Re: ATO being hacked.

Post by butcherman »

Changed my dns name. Has not happened since. Happened a total of 9 times in 6 days.

Sent from my GT-I9500 using Tapatalk
Post Reply