5 ms·
Everything has a purpose, unlike many "home labs" where people are just tinkering. There's nothing in here that would require fussy maintenance. It seems pretty
by rbranson 4y ago
Everything has a purpose, unlike many "home labs" where people are just tinkering. There's nothing in here that would require fussy maintenance. It seems pretty reasonable to me given the functionality.
- caust1c 4y agoIf they think this network is convoluted they should see mine!
- dgroshev 4y agoIn my experience, the main issue with setups like that is IoT/convenience devices being subtly broken because of all the firewalling. Then you suddenly find yourself trying to figure out why you can't just airprint from your ipad or why your guest's iphone sees a HomePod, tries to activate airplay, but it just silently fails. Really fun to debug, especially when you need that document printed right now or when you have a party going.
- neoromantique 4y agoBut what's the alternative? Unsafe home network where one rogue device can act as a tunnel for bad actors(bots more often tbh)?
- Tijdreiziger 4y agoIf you buy devices from trustworthy brands and replace them when they stop getting security updates, it should be fine, right? After all, aren't 99% of home networks 'unsafe' according to your definition?
- neoromantique 4y ago>After all, aren't 99% of home networks 'unsafe' according to your definition? Prevailance of home ip addresses in DDoS attacks and in proxy pools does suggest so ¯\_(ツ)_/¯
- dgroshev 4y agoIt doesn't follow. There are a lot of homes, so even if 1% of all home networks had "rogue" devices in them they'd dominate DDoS attacks. Besides, it's not HomePods or Withings smart scales or Hue bridges doing that as far as I'm aware, it's mostly cheap, unsupported, noname crap, so you can reduce your risks substantially by not buying questionable products.
- neoromantique 4y agoThere are plenty of CVEs in brand name things across IoT spectrum. Vetting devices you introduce to network is of course solid advice, but a little bit of paranoia never hurts in tech.
- dgroshev 4y agoHow many of those get exploited on firewalled networks before they're remotely patched though? My whole point above that it does actively hurt, with devices randomly misbehaving at exactly wrong times. It's not enough to set up everything once because devices get updated and change ports, domains, and protocols. It also makes everything more brittle, requiring multiple inter-VLAN proxies to be running at all times for seemingly unrelated devices to work. That SD card in your raspi died? You decided to update Docker on it and run into problems? No Sonos for anyone in the house until it's fixed. There's a real cost to that paranoia, it's just another case of security/convenience tradeoff.
- neoromantique 4y agoLet's agree to disagree, I think in the end it comes down to priorities and pain threshold for having to tinker with stuff.
- dgroshev 4y agoThe alternative is roughly what google called BeyondCorp — not trusting your network and doing explicit auth everywhere it matters, maybe with a sprinkle of Tailscale to simplify auth and encryption. If you're worried about your network being saturated for DDoS by a random IoT device, I suspect you'll notice it even without explicit monitoring. Besides, risks need to be weighed by their probabilities. It's a small chance of name-brand IoT devices "going rogue" vs the certainty of random things not working when they should, and I don't think this tradeoff leans towards VLANs for most people.