Recently, there was a discussion about VPNs on the Control4 forums. One of the comments was simply, “Whatever you do, don’t use port forwarding.”.
And then I thought – Surely no one port forwards their Control4 system, when Control4’s own VPN service, 4sight, is economically priced at $99 a year and requires no configuration or special router to use*…. and even if you didn’t want to use that, you can setup a VPN on a lot of commercially available routers these days for both desktop and mobile access…..
(*in rare cases, there is configuration required due to specialty/complex networks if all traffic is disallowed by default)
As it turns out, the number of people who have Control4 exposed on the Internet is much larger than it should be. >0, in fact. A search that takes less than 5 seconds to execute returned 612 unique results worldwide at the time of this writing – the bulk majority of which are in the USA. So why does this matter? For the sake of discussion, I’m not mentioning LAN security at this time, just WAN access.
By default, Control4 systems aren’t exposed to the Internet. Even a basic setup for testing with my controller connected to a generic ISP provided modem/router gateway returns no results on the search engine, and likewise in an open port checking utility. (Control4 publishes a guide for dealers that lists what ports on the network they use for different services, in the event that you need to allow ports on your network)
So, knowing that by default with no special equipment that the Control4 system is exposed through the Internet, with the functions of NAT and basic firewalls in modems, it is only logical to assume that the 600+ systems available online have been manually configured to allow remote access through exposing the ports needed in the firewalls – whether by using a DMZ or not. This means that steps had to be taken to open the systems up.
When this is done with port forwarding, it means that if you have certain software on your computer it is possible to get remotely connected to the Control4 system WITHOUT any authentication. Which is a huge, huge no-no. The whole concept of a system like Control4 is that it’s the bread of the smart home sandwich. You want to have the meat – the av distribution, the cheese – alarm integration, the mustard – garage door control, some lettuce – smart thermostats, tomato – lighting control. Individually the ingredients are good but the sum of the ingredients is the sandwich, and Control4 is the bread that holds the sandwich together and allows you to enjoy all of the tasty ingredients without having to eat (or interact with) them one at a time.
Port forwarding puts your sandwich on the open windowsill.
Now if I have access to your sandwich I can potentially turn off your lights, unlock your front door, or open the garage. Tasty!
So, what can you do to make sure that your system is secure? First if your system currently uses port forwarding for remote access, shame on your installing dealer (or you if you somehow managed to DIY a dealer sold and installed product)!
How do you know if your control4 system is exposed? Try a port checker like canyouseeme.org. Type in port 80. If it comes back with an error, thats a good start. If it says success, it means that something is being port forwarded and you may be at risk. Want to know more specifically if your Control4 system is exposed? Check ports 5020 and 5021. If it shows that those ports are open then you need to contact your dealer as soon as possible, and explain that your system is exposed to the internet via port forwarding. Perhaps there is a reason that it was done that way and they would be able to explain it to you. However, I suggest that the dealer come out to turn off port forwarding in your router/modem and instead set you up for either Control4’s 4Sight service or a VPN that is compatible with your needs.
