I am wondering about this for a long time now, so much so I made an account here (on recommendation). I see people into networking and homelab using various brands for sensitive purposes like networking or security. For example Unify (Ubiquity) for routers, switches, AP’s etc or Reolink cameras used with Frigate as a local only solution. But how do we know these devices are safe? I know you can basically cut Reolink from the internet, but there is still firmware that we are letting inside our home network and its not exactly open source firmware, is it? So how do we know it isn’t trying to poke holes in our security and “phone home”? And Ubiquity kinda scares me more, you have to let it on the network as it kinda IS the network, but how do we know unify is not sending some very sensitive data home?
So really, how do we know that we can trust these brands? And Unify and Reolink are only examples, there is so many popular brands out there, to which I see certain level of loyalty even from people in open-source or privacy/security space.
The long answer is that you have to pick your battles and figure out what your concerns are that are worth investing time and effort and money in resolving. Not every issue is worth your attention.
I don’t say this because I disagree in any way with your concerns, so please don’t take this as dismissive. I am guilty of spending inordinate amounts of time on plugging security and privacy gaps, but I also understand I do this because I want to and not because I am fighting an ideological war. If it were the latter, then I’ve already lost.
At one point, I have to give a certain degree of trust but I find it is important to me to choose consciously how much to give. I have an IoT vlan I put any “smart” device on that blocks internet access. They can only be accessed internally. I have unifi aps but when I realized they phone home for firmware update checks I moved them into that vlan. Anything that reaches out without my manual intervention gets that treatment.
I’ll only use edge networking products that are zero trust; they won’t do anything I don’t explicitly tell them to do. I like mikrotik for this.
I consider the business model of the products I use and prefer models that sell me products and services at higher prices over models that chase cheaper prices to advertise and data mine.
I choose to remove connectivity to devices that I don’t believe need it.
I removed the modem from my Tesla because I refuse to give Elon data, which means I had to set up an alternate computer for the screen to use to retain functionality. But I am ridiculous and I know that.
Some people won’t use anything internet connected. Some people swear by the convenience and don’t care what gets sent home.
As an old man in this space and with this ideological bent, I think the pragmatic thing to do is to assess your surface area, be clear about your objectives and redlines, and then go about implementing it for yourself in the decisions you make every day.
Things the manufacturer intended, like phoning home with telemetry. That’s a business choice they make.
Things the manufacturer didn’t intend as a result of security bugs or misconfiguration, like the routers becoming part of a botnet. That’s a function of business choices too, but more indirectly. Sadly embedded software has a well earned reputation for bad security, it seems features and ease of use sell well, both of which tend to reduce security. Quick security updates in a consumer router? Default secure configurations? The marketing doesn’t mention.
In either case the outcome is similar - the device is doing something you don’t want it to.
And I see roughly two common solutions:
Use platforms you trust, for instance I trust my routers running OpenBSD to do well at both these concerns
Sandbox things you don’t trust, as dd_honeybadger described using VLANs or similar
Nothing’s perfect, it’s risk management, there’s a whole formal world of treating this sort of stuff, eg: the hierarchy of controls
It’s a valid concern. But unlike what you see in the movies, something can’t phone home without leaving traces in the firewall/network logs.
I basically assume that if I have not loaded trusted firmware on it (ESPHome), then it’s trying to phone home.
I have more network devices that don’t need internet then do. Well over 100 IoT, CCTV camera, etc on the network and they don’t need internet access. So I setup a default vlan that does not have internet access. Then I have another vlan for devices that do need internet access.
Simple and solves the problem. Some exceptions exist. I added a TP-Link AP and it needs to be on the internet vlan. So I set the DHCP server to hand it out the same IP, then I blocked that IP from internet access.
My main router is a Mikrotik. Being mostly a business class router, it has a lot of eyeballs on it and what extra traffic it generates.
Ultimately, you should not. You can extend your question to virtually any interesting electronic device in your home, many of them have closed source firmware. The question with networking gear is, I guess, more interesting given its ability to build a relatively complete picture of your activity.
This is why you will read about guys getting busted by Interpol or the FBI in a tiny internet cafe or coffee shop with public WiFi.
This could be summed up by generalizing the concept of zero trust: treat every device as if it is suspect. Bear in mind that there are probably just as many domestic exhortations by the CCP, Roskomnadzor, etc, to avoid American technology as we see with Chinese technology today.
More practically, the old Russian cold war saying can apply: “trust, but verify”. So you can use your device for online banking. Probably whichever three letter agency working in concert with or covertly to get access to Unifi, AMD, Intel, etc. isn’t interested in your bank account. But what if you are a political dissident? This may substantially change your decision as to which devices are sufficiently trustworthy to use for blowing the whistle or whatever.
Hi, thank you. I guess this is the way I have been mostly doing things as well. The networking and cameras are very actual for me right now as I have router which I “built” and installed openWRT but I am afraid that if I needed more than one AP’s it might be a hassle. And Cameras, I don’t have cameras yet, but want to dip my toes and try one.
Btw how do you use your AP’s if they can’t access internet? Or is it possible to set AP’s that they don’t have internet only for the firmware and stuff? I am curious because this is exactly what I am worndering about how to block networking gear but still use it for … well networking which often includes internet of course.
Thanks @ack , I actually already have my network segmented, I have a subnet for “untrusted” devices, but internet access is still handled mostly case by case, because for example my smart tv I need interned (I didn’t yet found and wife-approved alternative).
Thanks for the linked thread I will check that.
I think what I wanted to hear here mostly is basically what you or dd_honeybadger say, which is very helpful in more than one way and kinda confirms there is not something huge that I am missing here.
Thank you. And are you not afraid that some of those devices might have a malicious firmware that would try to poke hole and send stuff without and easy way to see it (trace)?
I have to check the Mikrotik, I didn’t even consider them before, but its not the first time I see them recommended.
I guess this is the part I have been struggling the most currently. I always pick based on the reputation of the company and based on recommendation from fellow homelabbers but ultimately, lately, I was wondering if I can trust anything But I guess I am taking the question too far. Though I need to say the reason for me to do this is mostly, as dd_honeybadger said, a hobby, if I took it seriously for ideology reason or so I would probably end up living in a wood somewhere
Sorry for the late replies Its because I created new account and wrote a post right away, which probably flagged me as suspicious and it took time for the account to be manually reviewed I guessed.
i cant give a realistic answer. but i can give an idealistic one from a principals standpoint.
in a perfect world, you can trust the software because youve read and understood the code and ensured that what youve read is actually whats running on your machine.
in reality, you attempt to achieve this goal, but its impossible, so you derive trust in products from trust in the person(s) making it. in this sense, trust and vulnerability become synonymous.
I have the AP connected on a trunk port on the switch because it serves multiple wifi networks depending on the security required. Each of those wifi networks has a defined VLAN and subnet with rules on the router. Even though the AP is on a trunk port and could access multiple VLANs (so LAN multicasting isnt going to be blocked), I assign the AP an IP through a static DHCP entry to get an IP on my internet-blocked subnet. That subnet is blocked from outside access in firewall rules on the router.
Since my goal is strictly that the AP itself can’t get to the internet, this achieves my goal. I’ve done the same to all my networking gear other than the router itself where I’ve paid more attention and care in product selection. But networking gear has no business, in my opinion, reaching outside of my LAN. Some of this IoT junk spams broadcasting too much too, if you ask me.
I am ok with downloading the firmware on demand and then loading it myself. The only danger I’m exposing myself to there is that someone with intent to exploit a 0-day is in my physical space.
I’m okay with that too.
I want to add that the entirety of human society is based on trust and reputation. There is a necessity to delegate some degree of trust - whether it’s based on product branding, or based on product reviews from others, you can pick where and how to do it. But at the scale we exist, it’s impossible to vet everything yourself or, as you said, you have to live in an isolationist island.
You can go down the rabbit hole and endlessly packet trace every device until you’re satisfied. You will find the traffic, but you’re right there could be a firmware time bomb that doesn’t trigger until certain conditions are met so all your tracing will never reveal the flaw. But at that point, you have to consider the effort necessary to target you, specifically. No one is going to do that unless you have something demonstrably valuable worth exploiting - you don’t spend that much effort targeting en masse. Exploits are like spam: low value high volume is the typical path. To do a high value exploit it has to be targeted. Being honest, are you worth that kind of targeting? Are you a multi-national with billion dollar IP worth trying to steal?
I know I’m not, so I expend effort with that in mind. Most threats I come across are simplistic - they want to data mine me for advertising and profile/usage data and send it back home. They want to serve me ads in products I’ve bought from them, or turn me into an ad funnel. I do not consent.
I see, I didn’t know this is possible. Do you have some good tutorial or article about this? If not I will search for it, now that I know what I am looking for.
I’d suggest searching for a VLAN guide with whoever you switch/router vendors are. Most vendors have pretty good guides that describe how it works, and you’ll get their specific walkthrough for setting it up so you can hit the ground running.
You need to define the threat, the chance of it happening, and the risk to the rest of your infrastructure.
Taking the case of an CCTV camera, since I can’t put trusted firmware on them, the risk if they are internet connected is that they will be connecting to their cloud service to check in, even if I have the cloud features disabled. They might auto update firmware, or turn on cloud recording based on instructions they got from the cloud.
So the view from my living room may be available on the internet without my knowledge.
That is about as far as the threat I expect to go.
I am assuming the firmware that come on the device is not actively malicious and that an IP camera does not have enough smarts to be running exploits against my other services. It tries the phone home, and if that fails, nothing else happens.
So blocking the camera from the internet solves the most of the security issues. Having the camera get a fixed IP from the DHCP server, then blocking that IP from internet access is good enough. It’s the easy thing to do without getting into vlans.
I am not expecting an off the shelf camera to be so compromised that it’s actively scanning my network, identifying devices on my network, trying to log in with default or common credentials, and compromising them in an attempt to built it’s own internal bot net and attempt to “poke a hole”. All with firmware that came on the camera. That is normally something reserved for targeted attacks.
Regardless, I do have several home vlans setup and stuff on my DMZ vlan can’t get out to the internet. Period. There is no hole it can poke. We are not yet living in the days where a $100 CCTV camera can run a billion whatever AI model that will find an open SNMP port on a switch and attempt to run exploit attacks and create a buffer overflow on the switch and hop vlans. It would make a great Defcon talk when that becomes common.
+1 you don’t trust them. Avoid gambling with money you mind losing; avoid giving Internet access to random bullshit. The corporations are all evil when they’re not negligent when they’re not incompetent. IMO, this all gets very rapidly into virtue, culture, and then politics.
Myself, I’d probably be willing to tolerate a business-class router while accepting certain compromise by nation states, figuring they probably aren’t interested in hacking me personally until the LLM revolution makes it cost-effective. What I’m actually running is OpenBSD as a router, sort of… figure that’s my best chance, but still probably inadequate. Most corporate trash doesn’t get Internet access. Most apps don’t get installed. Don’t forget, “No” is always an option, and it’s very frequently your best option.
I consider the ISP and their network equipment to be the bigger threat. Like comcast using motion sensing with their routers. And i see plenty of stories of ISP’s shutting off peoples internet for piracy. And reporting people for illegal activity. While other ISP’s don’t seem to care what you do. So maybe look at the ISP first. Some seem to care more about reporting you to the police than others. However they all could be snooping in your traffic.
Every person has different privacy requirements. But i think not having any internal cameras in your house is less of a threat than having exterier cameras. Outside of them being used to access other parts of your network.
Yeah, makes sense. Though for me for example my government was never a concern until US showed us that you can never count on it into the future. And that might be the same with foreign governments as well. I might accept it now, but who know what risks will be related to that in the future?