← Back to context

Comment by amelius

15 days ago

> LAN only, no centralized cloud server.

Until one day they auto-update ...

Maybe I'm paranoid, but I have a separate VLAN with its own WiFi SSID for iot things like cameras, sensors, washing machine, dryer, solar panels and a bunch of ESP32 based projects. It has no internet access, and is only accessible from my home automation server. Those devices really only need to send data to Home Assistant and expose some basic APIs to it.

  • I take a simpler approach and block such devices in the router. This is a bit riskier as devices may in theory change their MAC address.

    How do you handle smartphone cameras?

Cameras (like other iot devices) should be forbidden from going outside LAN.

  • How do you deal with your smartphone camera(s)?

    • Are you asking outside the context of the home surveillance cams? just whether it's possible to prevent backdoors to your iphone camera?

      IME you have no control over the baseband chip of a cell phone, no reason to trust it's not enabling its camera or microphone at any time. I have a flip phone which comes in a non-camera version. I have an iphone without a SIM I can connect to its hotspot if I need to do something smartphoney.

      2 replies →