This situation is totally totally unlike public wifi!
When I connect to public wifi, the attack surface into my laptop is the external interface of the latest MacOS, with firewall on. Perhaps there are exploits against that, but they're not common. The Mac does have pf, but I'm sure it's a way out of date version! :)
OTOH, "this thing" on the inside of a router/firewall has complete unrestricted access to the LAN. At my house I have (and I just checked) 35 active IPs behind my firewall. It's not hard to get to that number for 4 people: iPhones, TiVos, laptops, desktops, access points, printers, gaming consoles.
I confess I don't secure my LAN computers very well. I have, e.g. 3 letter passwords. That's simply to keep my kids from accidentally going where they shouldn't be.
I'm not alone in my lax security. I do occasionally peruse exit traffic and check firewall logs, which probably puts me somewhere in the most secure 1% of "typical" households.
And even if I were totally paranoid, what can I do about the Internet of shit? Am I supposed to strictly segment everything? At what point does prudence and caution drift into paranoia?
That eliminates a surprising number of IOT devices, but given the flood of crap I think that's no bad thing. These days being able to have something be LAN only with zero service tie-ins seems a decent low pass filter to narrow down choices before diving any deeper.
Frankly yes, or at least it should be in the back of your mind when you inevitably need to upgrade some gear down the road anyway and thus the marginal cost is lower. People on HN talking about Ubiquiti probably sounds like a broken record at this point and there are certainly other providers and solutions, but you should recognize that solid centralized management and VLAN functionality and the like now has fairly good SoHo options at SoHo pricing too. You don't need to run right out and buy stuff, particularly since 802.11ax looks like it'll be a much more significant general upgrade then anything since the original AC with its focus on more efficient utilization rather then theoreticals.
But when you do, you should be getting something that lets you trivially soft-segment your network at will. At the least shoving IOT, any VoIP, and any cameras onto their own VLANs separate from your main systems is a good idea (not just for security but it can help performance too for VoIP, if you ever use it). At this point particularly with IOT I'd consider that a minimum required feature for any network gear to even be on the list for an upgrade.
>At what point does prudence and caution drift into paranoia?
At the point where hacks aren't trivially automatable for drive by and the difficulty of anything more is higher then the value of getting your stuff. When it comes to IOT though that point is regrettably a long long LONG way off, the security practices in that space are so utterly abysmal even before the typical practice of no updates ever comes in, assuming it's not actively backdoored. And of course this isn't just about you, IOT botnets are a threat to the whole net.
There certainly can be histrionics around this stuff that aren't justified, but I don't think basic segmentation, firewalling, pi-hole, and (if you must have your IOT on the public net though really you should consider using a VPN instead please) strict IP whitelist access or at least rate limits are unreasonable at all. Certainly not for the HN crowd. We can do our parts at least for our own benefit, and maybe[0] even help keep a few coworkers/family/friends/neighbors from contributing their uplinks to DDOSing our stuff too.
0: I genuinely mean "maybe" there, I know very well the payless thankless time sink it can be to take on any sort of IT work after hours. Depends on what family and friends are like. Still, sometimes though fairly low commitment/high return tips are available, or some simple trade of skills, an afternoon helping set up a better network for an afternoon of them helping with something.
To be honest, I found that easier than prudence and caution. New access point, stick all my IoT devices on there, then I don't have to particularly worry about what they are doing, they can't access anything interesting anyway (no outbound traffic, inbound traffic is only allowed from one device on my LAN).
A "smart" TV is presumably running content ID on everything that shows up on its screen, a fitness tracker is (of necessity) monitoring your physical activity, ... you get the picture.
I'm not paranoid that someone is tracking me in particular, or even that they would find anything interesting if they did (I'm really pretty boring in the greater scheme of things). Rather, not knowing what is being collected, by who, where it is stored, how long it is retained for, what metadata is attached to it, if their database has been (or is likely to be) breached, etc, means that there's no way for me to confidently assess what my future risks might be. Keep in mind that anonymous data often isn't so anonymous (https://en.wikipedia.org/wiki/De-anonymization).
At this point, something not being an IoT device is a major selling point for me.
And? There's no outbound traffic, so it can't do anything with it. The only risk is if it caches everything indefinitely and if I happen to connect to another network. I should have added that anything that _needs_ Internet access gets vetted much more closely.
I was also thinking more of home automation like devices, where it does _almost_ eliminate the risk. It can't access my main network, so it can't see any of my traffic, it can't phone home, and I don't have to worry about security vulnerabilities (it's not exposed to the Internet, so you'd probably have to compromise my main device first-at which point I have bigger problems and even if it was compromised it can't initiate any outward connections, blocking, e.g., its use in a botnet).
> Our software for the Internet of Things creates a Proximate Internet, intelligently discovering and connecting edge devices when they are in offline environments with poor or non-existent network connectivity. This opens up new edge networking solutions for data trapped in IoT sensors, controllers, or mobile computing devices in challenging environments.
I'm willing to bet your cell phone has a data connection, and while I'm sure yours is running LineageOS or an equivalent, what about that friend you invited over for dinner later?
At that point I'd have to reconsider. I did wonder about the devices finding a open WiFi point, but at some point you have to draw the line between reasonable precautions and paranoia, and there are none near me (currently) anyway.