4 ms·
Separating these devices physically is more secure than looking for alternative or reverse engineered firmwares. A VLAN would also suffice as long as it's not u
by artiscode 6y ago
Separating these devices physically is more secure than looking for alternative or reverse engineered firmwares. A VLAN would also suffice as long as it's not under the same subnet as your main LAN. Same applies to Wi-Fi. Also, separating these cameras is something you can reliably do yourself and today.
- Nextgrid 6y agoYep, separate network segment with no internet access with a VPN gateway acting as a bridge. If you want to access the cameras you VPN into the gateway first. This will shield the insecure cameras from remote attacks, provide transport-layer security thanks to the VPN without depending on the cameras themselves supporting that and would neutralize most backdoors unless the cameras have code to search for public wifi networks or bruteforce private networks to use as a covert channel.
- Yc4win 6y agoYou bring up a point of interest to me about the potential for malicious code that would bruteforce private networks to use as a covert channel. In regards to IoT devices, is there any documented cases of this happening in the wild? I could possibly see actors inserting malicious code baked in that would search for public wifi networks in things like a smart TV.