The ideal setup is having a separate vlan for your IoT things, that has no internet access. You then bridge specific hubs into it, so the hubs can control them and update their firmware.
If you have IoT devices that are unsafe but cannot be updated any other way, you can temporarily bridge the IoT VLAN to WAN.
Honestly, what IoT stuff needs is something similar to LVFS. Make it so all the hubs can grab updates from there, and can update any IoT device that supports Matter. It would also serve as a crapware filter because only brands that care about their products would upload the firmwares.
The real problem is those devices that actually don't let you control the device locally - Tuya being one notable example. There are thousands of products that just went and dropped in a Tuya board.
Tuya is completely cloud-controled. To control these locally you need a "local key" that is buried deep in their developer platform, and changes every time you re-pair the device, and getting it without registering the device is, on purpose, near-impossible without tricks like using an Android emulator with an old version of their app that stores the key, and even then requires effort to exfil the file out of Android. Horror. A device you physically own, only responds to control from the mothership.
So yes, you don't get those kinds of issues with RF protocols, of course unless you put the vendor's "bridge" on your network...
A friend of mine found Zigbee unreliable where he was, and just wired the home for 1-Wire. Temperature sensors, relays, heating PIDs etc. Not only it just won't die, but good luck to anyone hacking it without extra equipment and ripping wires from walls, and firstly being inside, unsupervised and undetected.
There are halfway decent hybrid controls available for ducted systems but you can't afaik buy anything off the shelf to merge hydronic + minisplits. And as far as I can tell, none of the off-the-shelf smart thermostats has any built in analog backup. I view that as absolutely critical for my use, if the power goes out and I'm not around I need to be 100% certain that when the power comes back on the heat will also.
EDIT: Digging around a little more it seems that Mitsubishi H2i minisplit systems don't speak zwave or zigbee, neither does Haier Arctic. I'm not 100% sure if that's accurate, but I haven't been able to find any documentation in the affirmative or negative. Those are the two heat pump options available locally. I'll be remodeling a small barn into an ADU this summer, that project will be more amenable to a forced air hybrid system, so maybe I'll be able to get away with a Honeywell smart zigbee capable thermostat that can drive it.
> EDIT: Digging around a little more it seems that Mitsubishi H2i minisplit systems don't speak zwave or zigbee, neither does Haier Arctic
There are no mini-splits in the US that speak anything remotely standard. If you want to go with ducted systems, TRANE and others have smart AC units that use "communicating thermostats". The protocol is based on Envirocom system and it's pretty basic.
Good news is that you can still control them by shorting the wires with a traditional thermostat, so you still can have an analog backup in case the regular digital thermostat fails.
Bare bi-metallic strips don't work as well because contacts tend to get oxidized and/or stuck. They are also a pain to calibrate.
A small microcontroller with a relay tends to be more reliable.
Until some bug surfaces that requires a reboot to -fix- work around, but since the device is powered by a battery (EDIT: still puzzling through what might happen when this battery runs out..) which isn't user serviceable and has no reset switch... The device I tore down this morning fits that description. I'll take my chances with a bit of calibration and some yearly maintenance. My vehicles all have grease points and maintenance schedules, I can handle also greasing my thermostat contacts ;)
That said, the regulators taking away the mercury switch isn't an excuse for the user hostility. They could have made a device that is less sketchy. Even if they actually did a great job and it's in fact much safer and more reliable than the analog device (in which case they should show data), I know I can open up the analog one and make it work. I can figure out how to keep it working. I can look at it and evaluate whether I trust it. I cannot do that with some proprietary blob on an MCU.
> I can look at it and evaluate whether I trust it. I cannot do that with some proprietary blob on an MCU.
Your air conditioner/heater likely has a controller. Probably several, at least for thermal protection and overcurrent.
I was very surprised to find the battery. This thermostat is designed to be compatible with older 3-wire systems, so I suspect they slapped a "10 year" battery in it and hope for the best. It's also marketed fairly deceptively. Or at least enough have fooled me--I thought I was buying an analog device.
EDIT: now I'm looking at the data sheets for an LM57 and getting some ideas
The HVAC guy probably thought that I was nuts for wanting the one that I got, since the price was similar. Six years later and I'm still controlling it from Z-Wave.