Better WiFi Please Book a site visit

Guides / Security

Your smart devices are the weakest thing on your network

5 min read

A typical household now runs thirty to sixty connected devices. Most of them will never receive another software update as long as they're plugged in.

The problem in one paragraph

Your laptop and phone get patched constantly. A budget smart plug, a doorbell from a brand you've never heard of, or a camera bought four years ago may have stopped receiving updates long ago — or never received any. Those devices sit on your network permanently, and when a flaw is discovered in them, it stays open. On a flat network, a compromised device can reach every other device in your home.

What isolation does about it

Putting smart devices on their own network means a compromised one is stuck in a room by itself. It can reach the internet. It can't reach your laptop, your work files, your network drive, or your other devices.

Almost everything keeps working, because most smart home products communicate through the manufacturer's servers rather than directly with your phone. Your app talks to their cloud; their cloud talks to the device.

The exceptions are worth planning for:

  • Casting to a TV. Chromecast and AirPlay discovery doesn't cross networks by default. Fixable with a specific rule, but it has to be asked for.
  • Local-only smart home hubs. Some systems talk directly to devices without a cloud. These need rules written for them.
  • Printers. Often behave like smart devices and are often needed by everyone. Usually easier to leave on the main network.

These are setup decisions. Made at install, they take minutes. Discovered later, they're an annoying evening.

Cameras deserve particular attention

An internet-connected camera inside your home is the device with the most to lose. Three things matter:

Change the default password. Default credentials on cameras remain among the most exploited weaknesses anywhere. Whole websites index cameras left on factory passwords.

Know where footage goes. Some systems record to a drive in your house. Others upload everything to the manufacturer's servers, sometimes in another country. Neither is automatically wrong, but you should know which one you have, and decide whether it's acceptable.

Check the brand against restrictions. The FCC maintains a Covered List of communications equipment facing federal authorisation restrictions, which includes several well-known camera manufacturers. For a household this is a preference. For a business — particularly one working with government or larger corporate clients — it can become a procurement question.

Sensible practice without becoming paranoid

Buy fewer, better devices. A brand with a track record of shipping updates is worth more than three cheap ones.

Retire devices that stopped getting updates. If the manufacturer has abandoned it, it's a permanent open door. Old cameras are the common offender.

Keep a list. You can't secure devices you've forgotten you own. Most people underestimate their device count by half.

Rename them. "Garage camera" beats "IPC-2938-A" when you're looking at a device list trying to work out what something is.

The realistic threat

Nobody is targeting your house specifically. What actually happens is automated scanning: software sweeping the internet for known-vulnerable devices and taking whatever it finds. Your camera isn't interesting to a person — it's interesting to a script, which doesn't care who you are.

That's what makes isolation such good value. It costs nothing extra at setup, and it converts a whole-house problem into a one-device problem.

Bay Area

Want someone to just measure it?

We survey the property, show you the readings, and quote a fixed price. No charge for the visit.