Hacked from a lightbulb
blog.checkpoint.com
blog.checkpoint.com
> And the answer is: Yes.
Does this surprise anyone? Was this really a question brought up by their research? A computer with a network connection is a computer with a network connection, no matter how small.
I mean, I didn't think it was impossible. But it's not as apparent an attack surface as a wi-fi gadget would seem.
You can be hacked from your doorbell, thermostat, or refrigerator now. Soon, hacks to vehicles will be able to propagate into home networks to install malware. It's an exciting time to be a cybercriminal...
My main control device is a VM running Home Assistant, so the underlying system (Hue and TRÅDFRI mainly) doesn't really matter much.
[0] Mostly. There's a port open for one device to do HTTP POSTs of data to one machine on the main network. MQTT is also open so that my ESP32/ESP8266 stuff can push data to the broker.
I have some router with Shibby Tomato laying around (DD-WRT is unsupported), but I'm not sure if I need some other hardware, software, or if it's just a matter of finding the right settings…
That is fairly unique (almost unknown in any simple physical device) and requires a very different purchasing/disposal/return policy.
It's pitiful.
A high end router with those features will definitely come with VLAN support.
Asus certainly does
Even the cheapest $20 routers are actually quite capable in terms of hardware, supporting at least 16 VLANs.
Maybe hard on your guests, though :(
e.g. with LIFX wifi light bulbs, you can control them with low latency (and no internet connection) via ip packets; or high latency via LIFX's cloud servers if you're not in the same subnet.
X10 had this sort of architecture, maybe if everyone started using Bluetooth or USB you could do something similar.
I’ve shopped a few times for consumer computer controlled lighting and it’s all crap (just like any consumer electronics niche) that needs to be put on a WiFi network and use the manufacture’s app (and often network services.)
If you want IOT either do it yourself or get industrial stuff.
DIY seems eminently possible with ESP32 etc, but mains power means I'd rather buy something off the shelf from a longstanding brand.
I doubt this will move the needle for consumer manufactures to embrace it, but it works right now (and is more responsive than X10). We're all cyber-gleaners until (hopefully) the market demands open standards.
I have four vlans - adults, kids, IOT and guests. Only the adults vlan has unfiltered access, the others are pretty heavily locked down.
Suppose your router does not have VLAN support, and you do not wish to replace it. Can you add sufficient VLAN support to your network by adding switches with VLAN support?
TP-Link has a couple of switches (TL-SG105E and TL-SG108E) [1] that are not full managed switches but do more than common unmanaged switches. They are priced about the same as unmanaged switches. I got the 8 port model for $30.
These switches have some VLAN capability, although I haven't looked into what it can do. (I got it for its port mirroring ability, not its VLAN ability).
If you are using your ISP's router/WiFi access point, and your IoT devices use WiFi then I'd guess there is not much you could do with switch-based VLANs. The Hue bulbs, though, talk to a Zigbee hub that you plug into your ethernet, so you can make all the Hue traffic go through a switch.
Another problem is that nearly all the documentation I've found on using VLANs gets real "enterprisey" real fast. For even fairly sophisticated home users it is probably really confusing, and so even if they have a router with good VLAN support they might not be able to figure out how to use it.
[1] https://www.tp-link.com/us/home-networking/5-port-switch/tl-... (SG108E is essentially the same, just with 8 ports instead of 5).
In any case, you're counting on the router to keep one LAN/vLAN isolated from the others.
The first plugs into your "Internet modem/router". Connect all of your "untrusted" devices to it. Your second router also connects to the first, just like the other devices do. Your "trusted" devices will connect to this second router.
Your "trusted" devices (PCs, laptops, tablets, etc.) will be subject to double NAT and, of course, NAT is not a security feature but this second router will provide a bit of separation between your trusted and untrusted devices by way of NAT and stateful firewalling, just as it would protect your internal network if it were connected directly to your upstream ISP's network.
Again, this isn't ideal but it would work for the average home user and it eliminates the need to deal with/learn about VLANs or buy special hardware that supports them.
This VM that I'm typing in is behind at least eight NAT routers. There's the pfSense perimeter router, and at least one router between that and the ISP. And then there are three pfSense VPN-gateway VMs, each with NAT by the VPN server, and local NAT to a VBox internal network.
Granted, an average user will not be able to figure out how to do this and a standard private VLAN guest network is going to prevent this from working.
What are the benefits anyways? Not having to physically get up and flick a light switch anymore? Getting a push notification from my fridge that we’re out of milk? Whyyy?
It is not worth it.