← Back to context

Comment by ttytty

1 day ago

It's so important to have a dedicated VLAN (or 2.4g SSID) for IoT devices and block access to your regular VLAN/SSID or enforce some more granular rules on what devices can communicate with each other.

Most non-ancient routers/gateways support this. There are way too many IoT devices running code that's _worse_ than what older LLMs produce.

This is good advice but a simpler solution is to just not buy these things? Coffee machines don't need internet. Your thermostat doesn't either.

  • I agree on the coffee machine. On the thermostat, not so much. We keep pretty irregular hours so being able to control the thermostat remotely, so the house isn’t being heated unnecessarily but is warm on our return, is useful.

    • Honeywell Home T6 Pro Z-Wave.

      It's smart and supports only Z-Wave, not WiFi. So something like a machine running Home Assistant must sit between it and the Internet. And then its up to you to decide how you want to do remote access, but WireGuard overlay networks (e.g. Netbird, Tailscale) basically solve that problem at home-user scale.

    • That said, getting a Zigbee or Z-Wave thermostat and have Home Assistant or similar control it is a better option that buying a surveillance-ready WiFi-enabled one.

  • > Coffee machines don't need internet. Your thermostat doesn't either. reply

    Yours may not, but that's just your personal preference. A lot of folks enjoy these products. An argument could be made that no one needs a coffee machine or thermostat to begin with.

My Bialetti Moka pot doesn't attempt to acquire an IP address.

  • I'm in Rome right now.

    There's a Bialetti shop on the road between the flat I'm staying in, and the Metro station.

    If I'm not careful this is going to seriously damage my wealth.

It's not enough to simply have a IoT VLAN that you put all your IoT devices on. Because those devices can see one another. In this case, if the coffee machine can see what type of smart fridge and smart toaster you're using, they can sell that data.

I default to adding IoT devices to a 2.4g "Guest" network where they can't see each other. Exceptions are IoT devices that need to see their friends to do what I bought them for, or devices I want to integrate with HomeAssistant. In those cases I create a separate IoT device per IoT brand. Excessive but necessary.

Of course by VLAN, I presume you mean one that doesn't have access to the Internet.

FWIW preventing the harm that happened here would seem to require a second set of APs (radios) on a different channel.

I have a firewall that tells me how much data each device is uploading and downloading. One particular device pulled down 6GB a week and uploaded 1.5GB doing absolutely nothing. I mean literally nothing, I use the local API to communicate with it. Blocking the one domain it was doing this to dropped traffic to essentially zero with no loss in functionality.