e.g. IOTs that will happily accept commands from anything on the local net.
Yesterday I was surprised my hass.io could control a tp link power plug...I never gave it any auth...it just scanned the lan for things to control
(Its not necessarily true, but tons of engineers assume its true. Hence, when making a low-cost product for home consumers, security is purposefully neglected.)
e.g. IOTs that will happily accept commands from anything on the local net.
Yesterday I was surprised my hass.io could control a tp link power plug...I never gave it any auth...it just scanned the lan for things to control