3 ms·
Put it on a private VLAN (eg guest Network that can't be reached from main network), pull the Sim card, uninstall all non-essential software, turn off all non-e
by Thriptic 7y ago
Put it on a private VLAN (eg guest Network that can't be reached from main network), pull the Sim card, uninstall all non-essential software, turn off all non-essential services.
- Mister_Snuggles 7y agoThis is good advice for any sort of camera system, not just a repurposed phone. I do this for my cameras, there's too much risk associated with them phoning home to set them up any other way.
- stevehawk 7y agoEVERYONE SHOUlD PUT ALL IO(S)T* DEVICES ON A PRIVATE VLAN :-D * "internet of shitty things"
- saagarjha 7y agoNo, that doesn’t work. Everyone knows the S in IOT stands for security.
- bigiain 7y agoI propose IOCT (where C = Crappy). Although I prefer "Internet of un-updated linux boxes". (A thing to which I'm ashamedly a party to. I was in a startup ~5 years back where I was responsible for the backend that provided the software and OS updates (a customised ARCH Repo and pacman config) for our hardware. The startup went under, having shipped the first production run. I kept the Arch repo up on my own dime for as long as I could, but eventually the control over the domain dried up and the subdomains it relied on no longer existed... There weren't many of our devices still connecting to them that last time the log files showed connections, but I'm looking at two of them right now which I've been occasionally doing security updates to by hand. I feel bad each time I do it, knowing there's customers out there who bought our stuff who are no longer getting any updates...)
- surround 7y agoI have some crappy IOT devices, but I cannot control them unless they are on the same WiFi network as my phone (e.g. Sonos). What should I do?
- gcb0 7y agoFirst, you should get rid of them. Really. That failing, learn to set up virtual networks (vlan as mentioned earlier) properly. Put rules to prevent a device from scanning and initiating connections to other devices. And despite all the work, you will always be vulnerable if your switch or whichever network device doing the filtering has a zero day ...or let's be honest, have a 739-day, because nobody patch home network gear So, that's why you should not use outdated android devices and specially "crappy IOT devices" as you put it. Accept your phone has an expiration date because you were fine buying it "with the hood welded" in the first place. You can either dump them at an e-waste site or sell on the used market. Either way you are going to pass your problem to someone less privileged than you. Sucks to be them. I personally mail my devices to the manufacturer, without a return address. It's their problem now.
- squarefoot 7y agoA small router device put in between might help, say a repurposed (OpenWRT?) WiFi access point, or a small Microtik or similar devices. By having forcing all IoT devices on a second private WiFi network would allow to set rules so that for example they can be reached by devices on the home network but are prevented to connect anywhere else on the outside.
- Thriptic 7y agoThat's going to be hard to deal with, principally because I'm sure many of the control apps only search for devices on your local subnet and don't allow manual specification of IP. If they do allow manual specification of IP, then you could probably do what the other person who replied to your question suggested: multihome a router, establish a hardened second network, and leverage port forwarding. If they don't, then you need to put them on a separate network and put a controller on that second network too (eg an old phone, tablet, smart speaker). Alternatively, you could set up a bridge by hardwiring the device to a raspberry pi and then use the pi's WiFi to connect to your existing network. You then set up traffic forwarding across the NICs, man in the middle all the traffic, and only allow certain traffic in and out. This avoids the need to create a new network.