logoalt Hacker News

ttytty • yesterday at 10:15 PM • 5 replies • view on HN

It's so important to have a dedicated VLAN (or 2.4g SSID) for IoT devices and block access to your regular VLAN/SSID or enforce some more granular rules on what devices can communicate with each other.

Most non-ancient routers/gateways support this. There are way too many IoT devices running code that's _worse_ than what older LLMs produce.


Replies

Levitating • today at 8:22 PM

This is good advice but a simpler solution is to just not buy these things? Coffee machines don't need internet. Your thermostat doesn't either.

➕ show 2 replies
pjmorris • today at 8:29 PM

My Bialetti Moka pot doesn't attempt to acquire an IP address.

➕ show 1 reply
randerson • today at 9:16 PM

It's not enough to simply have a IoT VLAN that you put all your IoT devices on. Because those devices can see one another. In this case, if the coffee machine can see what type of smart fridge and smart toaster you're using, they can sell that data.

I default to adding IoT devices to a 2.4g "Guest" network where they can't see each other. Exceptions are IoT devices that need to see their friends to do what I bought them for, or devices I want to integrate with HomeAssistant. In those cases I create a separate IoT device per IoT brand. Excessive but necessary.

mindslight • today at 4:16 PM

Of course by VLAN, I presume you mean one that doesn't have access to the Internet.

FWIW preventing the harm that happened here would seem to require a second set of APs (radios) on a different channel.

pseudohadamard • today at 2:05 PM

I have a firewall that tells me how much data each device is uploading and downloading. One particular device pulled down 6GB a week and uploaded 1.5GB doing absolutely nothing. I mean literally nothing, I use the local API to communicate with it. Blocking the one domain it was doing this to dropped traffic to essentially zero with no loss in functionality.