72

I pay for the Nabu Casa subscription for remote access to Home Assistant. Mostly as a way to give them money for a great service, but it's convenient and felt pretty secure. It should be the only remote way into Home Assistant. About an hour ago I got a login attempt notice that an IP was trying to access API/config. The IP is in some bad IP databases. What I found interesting was that the log shows an AI bot. A Google Gemini bot specifically. Makes me worry that AI is going to make yet another aspect of life frustrating and unfun.

you are viewing a single comment's thread
view the rest of the comments
[-] gdog05@lemmy.world 1 points 5 days ago

That is exactly it, yes. And I am thinking about reaching out to them about it and their blocklist. But after thinking about it, anyone with $16 in hosting can start an AI hacking instance. It's just going to get worse.

This kind of thing has been going on since long before "AI." Expect anything connected to the internet will have failed login requests. That's why there is a login system.

[-] Cyber@feddit.uk 1 points 5 days ago

I agree this is an old thing, my firewall has blocklists and allowlists to prevent known bad IPs and allow only the countries I travel to.

But if Nabu Casa is an outbound VPN, then my blocks won't work. I'd need them to block

Either way it would make sense for HA to also use some crowdsourced blocklists as a 2nd level defense

What do you do if somebody adds your IP to the crowdsourced blocklist used by your server?

[-] Cyber@feddit.uk 1 points 4 days ago

Ask for it to be removed

[-] Natanox@discuss.tchncs.de 2 points 5 days ago

Not just that, companies are using "smart" devices as AI scraper botnets to utilize private, basically unbanable IPs. There are only very few companies who I might believe them not doing it (AllenAI and maybe Mistral - tell me if I'm proven wrong pls). But OpenAI, Anthropic, fucking Google and Meta, they all treat your network as their personal internet extension. It's reasonable to assume any "Smart" device with wifi access that isn't FOSS most likely being your enemy.

Our family Nextcloud already got taken down by OpenAI swarming it… overloaded and crashed php-fpm within a minute. At least one client blasting all endpoints still advertised themselves as OpenAI crawler.

this post was submitted on 10 Sep 2026
72 points (98.6% liked)

Selfhosted

62116 readers
444 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

Detailed Rules Post

  1. Be civil.

  2. No spam.

  3. Posts are to be related to self-hosting.

  4. Don't duplicate the full text of your blog or readme if you're providing a link.

  5. Submission headline should match the article title.

  6. No trolling.

  7. Promotion posts require active participation, with an account that is at least 30 days old. F/LOSS without a paywall has exceptions, with requirements. See the rules link for details. Tags [CBH] or [AIP] are required, see the links in Rule 8 for details.

  8. AI-related discussions and AI-involved promotional posts have additional requirements for tagging, as noted in Rule 7 and the AI & Promotional Post Expanded Rules post, and find example disclosures here.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 3 years ago
MODERATORS