By design these tools connect through the vendor's cloud relay, so any installed client is reachable from anywhere the attacker can reach that relay, which effectively means the internet, without the machine itself being directly internet-facing. That reach, combined with weak configuration, is the exposure. The two aspects are internet-reachable installations (any running client with a known ID and a weak/leaked password is connectable from outside) and insecure defaults, unattended access enabled, weak or no password policy, no connection allowlist or approval requirement, that leave the client open. The relay model means "internal only" is not a real boundary for these tools.
Subtopics#
- Internet exposure: reachability through the vendor relay.
- Insecure defaults: configurations that leave a client open.