4 ms·
I am running my own custom-built Debian-based router in a VM and architected an encapsulated networking infrastructure at a FAANG once, so I know perfectly well
by steelframe 2y ago
I am running my own custom-built Debian-based router in a VM and architected an encapsulated networking infrastructure at a FAANG once, so I know perfectly well how to get the device securely connected to the Internet while isolating it from the rest of my network. While I may trust the CoreELEC image I downloaded and audited at one point in time, I won't trust the people-and/or-org that controls the servers it connects to and pulls down updates from in perpetuity. So long as it is stable and has all the features I want in it, it won't ever be talking to anything on the Internet and will be left alone. If a feature or bug ever comes along that I feel I absolutely must get an update for, I'll be pulling an updated image, auditing it, and then flashing it to the eMMC device from another trusted host. But so far I don't imagine that will ever be necessary.