Even trusted devices are segregated by vendor.
Even trusted devices are segregated by vendor.
Curious.. are there any recorded instances of air gapped networks being breached?
Unfortunately, all is not rainbows and unicorns. Ubiquiti's GUI doesn't treat IPv6 as a first-class citizen; if you want IPv6 you need to head for the CLI and hope you hit upon the right recipe to enable it for your provider - and make sure you set up your firewall rules to only open IPv6 addresses/ports you want open.
The article asserts, "It expands the attack surface and most of this isn't covered by traditional defenses", which is bogus. It's just another device that doesn't need to be on the same network as critical services.
From memory, there was an "untrusted trusted entertainment system" network segment, and a firewall which allowed one-way traffic out of the "trusted" vehicle management network (so the entertainment system could get car speed and similar), and the firewall could have it's firmware updated. From the untrusted network segment...
IMO "the problem" isn't the CAN priority system, it's that a remotely programmable device (the CAN gateway) was connected to both the control network and the internet (via the entertainment center). For something so security critical, it should have been kept as dumb as a box of rocks, and certainly never made network-updatable.