6 ms·
How do you handle network security? I wouldn't trust an IoT device on the same network as any of my family's computers or phones for example.
by iandanforth 5y ago
How do you handle network security? I wouldn't trust an IoT device on the same network as any of my family's computers or phones for example.
- alufers 5y agoI personally just flash everything possible with open-source software. All my light switches and Wi-Fi lightbulbs run Tasmota, which I password protect and semi- regularly update. The one odball is my Gree AC unit, which is on a separate WiFi network and subnet (I just run hostapd on my RPi since it's close-by). But it's more to protect it from the outside, not the other way, because it's controlled with JSON sent over UDP, and if you send a malformed packet the microcontroller inside crashes. When this happens and the compressor is engaged it will freeze up, possibly destroying itself and start flooding the floor, because the condensation pump won't turn on.
- jve 5y agoHow did you find that out? You mean random UDP packet can destroy AC? /me having a Gree unit that is to be installed
- alufers 5y agoBefore I got a Raspberry Pi with home assistant, I was trying to write a simple client for this protocol in C so I could host it on my OpenWRT router. Of course my client bugged and sent some random junk which caused the unit to completely lock up, it displayed 88 on it;s display and didn't respond to the IR remote. After this I had to reset it via the circuit breaker. If I recall correctly, the data was encrypted using a static AES key, and I think the unit checked if the data decrypted correctly, but don't quote me on that.
- artificialLimbs 5y ago>> When this happens and the compressor is engaged it will freeze up, possibly destroying itself and start flooding the floor, because the condensation pump won't turn on. Do not buy Gree. Check.
- rcarmo 5y agoOr maybe not automate destructive devices. Might be simpler and more responsible anyway, since equivalent harm can be had if your kids ask Siri to warm up the house...
- sam345 5y agoAutomation bugs are dangerous on any home device. I once accidentally programmed an infinite recursive loop on all the lights in the house so had on and off signals being sent nearly simultaneously. Scary and not a good thing but easy to do particularly with wifi and mqtt messaging. Had to shut main power off. Luckily only one light switch broke.
- slingnow 5y ago> But it's more to protect it from the outside, not the other way, because it's controlled with JSON sent over UDP, and if you send a malformed packet the microcontroller inside crashes. When this happens and the compressor is engaged it will freeze up, possibly destroying itself and start flooding the floor, because the condensation pump won't turn on. Wow, the future is truly here folks!
- bliteben 5y agoWhat lightbulbs do you find are best for running tasmota? I'd prefer not to have to setup a zigbee setup in addition to my zwave.
- alufers 5y agoSmart lightbulbs are crappy, since If you turn them off using a light switch, you can't turn them back on via Wi-Fi. I've installed smart relays (Sonoff mini) behind light switches, which means I can control them localy and remotely at the same time. That being said, anything that can be flashed using tuya-convert will be good. But beware, because not all Tuya lightbulbs hava an ESP chip inside and they have patched the exploit tuya-convert uses in newer firmwares. So check your model on google.
- clownpenis_fart 5y ago
- tragictrash 5y agoif you flash openwrt/ddwrt to your router, you can create an isolated subnet with its own DHCP server and enter your own firewall rules (iptables) blocking all traffic from your local subnet to your IOT subnet. You can then bind that to a wifi ssid (the guest one). Its kind of a PITA to setup, but it works great once you get it. Netgear Nighthawk routers have worked great for me in the past. Don't forget to set up a reverse proxy with ssl and automatic cert renewsl, even in your home network. Wifi can be hacked with trivial ease. Caddy or nginx/certbot will do you well there. If you also run a pi-hole you can have the pi on your local network pass ssl checks by overriding some DNS entries.
- rhinoceraptor 5y agoOne, I avoid WiFi products entirely if there is a good alternative. Zigbee and ZWave are two good ecosystems, you get a USB radio, plug it Home Assistant machine and you're up and running. A second option is finding devices that can be flashed with Tasmota or ESPHome. This could also mean putting together your own devices with an ESP8266, ESPHome is basically plug and play for simple things like temperature sensors. You assemble the device, configure which pins to use via YAML, and then flash it to the ESP. You don't even need to download a local build toolchain, the ESPHome add-on to Home Assistant can flash devices plugged into your computer just from the web interface, and then do OTA firmware updates.
- clownpenis_fart 5y ago
- mindslight 5y agoI prohibit IoT devices from connecting to the Internet at all, and only use devices that can be controlled by the local network [0]. Thus firmware updates don't matter (as long as the manufacturer hasn't included any logic bombs), as the trust model is that devices are just an extension of the network segment. The least-involved way to set this up would be to set up an old wifi router to create a second network, don't connect this router to your existing network or uplink, and then set up your home automation server with two ethernet ports. [0] eg TP-Link Kasa, although I heard this may have changed for recent ones? Either way, with this setup you'll be immediately aware of whether local control functionality works, so you're well within the return window. FWIW I stay away from Amazon's GENSYM brands, even though they'd be easy to flash with Tasmota etc, because I don't trust them to get line voltage design considerations right and I don't feel like QAing every single device.
- syshum 5y agoFor me I mainly use Zigbee and Zwave Devices not WiFi Devices. I am sadden that wifi seems to be taking over and ZigBee and Zwave are starting to lose favor.
- nomel 5y agoI like to believe that it's because matter protocol is on its way, so hardware isn't being developed: https://en.wikipedia.org/wiki/Matter_(standard) https://en.wikipedia.org/wiki/Matter_(standard) But, I think it's actually because wifi is easier for the average person to get working. With Zigbee, you need a Zigbee hub, but sometimes you need a brand specific Zigbee hub, sometimes you don't (even though it's advertised that you do), and sometimes the Zigbee compliance is so bad that adding a device from another vendor break your whole Zigbee network (looking at you Aquara). Zwave throws more incompatible hubs to the mix. And, even within these, it's rare to have devices work with each other in a way that makes sense. Hopefully matter saves us, so I don't have to install 5 integrations in Home Assistant to remind me that my car isn't plugged in at night or my back window is open, while the heater is on, and then another to make any of it accessible to HomeKit.
- syshum 5y agoI must be lucky then because I have lot of Zigbee and Zwave devices all running Transmitting to Nortek GoControl USB stick attached to a rPI running Home Assistant. I have several vendors of both Zwave and Zigbee Sensors, HVAC thermostat, Bulbs, Switches, etc.. All of them play nice with each other, and FAR FAR simpler to setup than WiFi which often requires the use of some weird mobile app, and play hopsotch with the networks.. Zigbee I just pair them to the GoControl and it is done hell I even bought some no name used Door Sensors off ebay that were Zigbee, I mainly use them for Temp monitoring in various places.. They had no problem connecting to my network either
- nomel 5y agoYes, but you are not the average consumer, who is making Wi-Fi popular. > all running Transmitting to Nortek GoControl USB stick attached to a rPI running Home Assistant > and FAR FAR simpler to setup than WiFi These two sentences are absolutely silly, for that average consumer. An average consumer can install a proprietary app in a few minutes and is totally uninterested in installing operating systems on little computers.
- wyager 5y agoNot OP, but I make extensive use of VLANs to isolate off security cameras, IoT devices, etc. etc. into their own mutually isolated network environments. I also don't use Wifi for any of these devices anymore. It's usually a bad experience. Either use ethernet or a dedicated IoT-oriented wireless protocol. Z-wave seems OK but not very flexible, Zigbee is a pain in the rear (but the only option for many device classes), and I'm hopeful that Thread will actually be good.
- xxpor 5y agoIn addition to all of the "use Z-Wave/Zigbee as much as possible" comments (which I personally do), for stuff where there's no choice like Roombas, I have a separate SSID on a VLAN that can only talk to the internet, my DNS server running Adguard, and HA (which is on the main network). I also have stateful rules that allow connections to be initiated from the main network to the IOT network, but not vice versa. I also try to find things with ESP* controllers, as mentioned. I've really been trying to move away from cloud based stuff not only because of data privacy, but concerns about services going away and (most importantly) latency. My old wifi smart plugs had 2+ seconds of latency from when I'd hit the button in HA to actually turning on. Zigbee/Z-wave stuff is (from my meatsack perspective) instant. I have a zigbee door sensor on the door to get into my garage, and a zigbee smart plug connected to the overhead florescent lights. By the time the door opens enough for me to actually see inside the garage, the lights are on. Sometimes I think they never turned off. It's fantastic.
- vladgur 5y agoHow do you setup a separate VLAN and SSID? None of the "pro-sumer" wifi mesh setups under $500 support VLANs
- nybble41 5y agoThe Ubiquiti Access Point AC Mesh Pro[0] (~$200) appears to support multiple SSIDs and VLANs. Of course you'd need at least two of them to count as a "mesh", which is $400… was your $500 budget per access point or for the whole system (and if so, for how many APs)? [0] https://store.ui.com/products/unifi-ac-mesh-pro-ap https://store.ui.com/products/unifi-ac-mesh-pro-ap
- vladgur 5y ago2 will cover my needs. Do they actually work like a mesh? As in use backhaul radio to communicate between them and allow seamless switch from one to another as you travel around your home?
- 5y ago
- rcarmo 5y agoI just don't use Google or Alexa (devices from those ecosystems punch holes through my home gateway for a bunch of server-side glue that is extremely ill-advised, and a bigger risk than LAN security IMHO), moved most things (sensors, typically) to ZigBee, and reflashed everything I could with Tasmota. It's extremely inconvenient to have IoT devices segregated from, say, TVs and media devices, especially if you rely on AirPlay or Chromecast to get audio around the place, so I just secure my Macs (and PCs) properly as if we were still traveling and visiting clients. I keep tabs on Apple security bulletins (HomeKit has relatively few issues, and works mostly inside the LAN except if you're outside the house - it then switches to a variation of the old iCloud "back to my X" tunneling).
- sam345 5y agoI use mikrotik router with separate vlans. Also use open firmware (usually tasmota) on 95% of devices.