topic.
I have hundreds of devices I want to securely give remote commands via MQTT/pubsub.
How can a (readonly) subscriber verify the published message is correct and legit from one authorized publisher? My assumption is you can't. Once a hacker gets access to the credentials (no matter if certificate or username/password) you can't tell the two senders apart anymore. Not sure how certificates help here.
once a hacker gets
Обсуждают сегодня