My Smart Bulb Shares a Network With My Production Keys.
Nineteen devices on one flat home LAN: my work laptop with prod access, a 2021-firmware bulb, a camera from a dead brand, and an ESP_4F2A nobody admits to buying. The fix: split the network, promote the router to perimeter, and treat home like a café - tunnels, scoped contexts, no standing creds. I opened my router's device list like you open a fridge at midnight - without a plan, slightly guilty. Nineteen devices. My work laptop, which can reach production, was on the same flat home network as a $12 smart bulb with 2021 firmware, a camera from a brand whose website no longer exists, a TV phoning home to an unplaceable timezone, and something labeled ESP_4F2A nobody in my household admits to buying. A home LAN is flat: everything trusts everything. The security of the machine holding my prod keys was, that evening, partially defined by a light bulb I bought on sale. The living-room test The café test for laptops has a home version: if the cheapest device on your network gets popped, what's the path from there to the thing you'd cry about? On a flat LAN the answer is usually "a scan, then a try." Not because the bulb is an evil mastermind - because flat networks turn one weak device into a viewing position over everything else. First, see the whole estate: # who actually lives on your LAN (router DHCP list is the honest source; this cross-checks) nmap -sn 192.168.1.0/24 | grep -E 'Nmap scan report|MAC' The split (free, boring, an afternoon) work vlan : laptop, work phone → reaches SSH endpoints, nothing else inbound iot vlan : bulb, camera, TV, ESP_* → internet only; sandbox where blast radius = each other guest wlan : visitors → internet only, timed # exceptions are deliberate, visible, few: # laptop → printer (print only) # phone → doorbell app Router settings, zero dollars. The bulb keeps bulbing; it just loses its view of my laptop. Then the router itself got promoted to perimeter: admin password off the sticker, auto-update on, remote management off. It's the only device in the house actually doing security - it deserved the ceremony. Home is a café now The laptop rules travel home: no standing production credentials, short-lived sessions, and services reached by tunnel - nothing listens publicly just because I'm on the couch: #!/bin/bash # home-is-a-cafe.sh krova context use home # scoped: create/wake/ssh ok; delete prod = no krova ssh db-1 -L 5432:localhost:5432 & # postgres over the encrypted channel krova ssh web-1 -L 8080:localhost:8080 & # app same; internet gets nothing # local clients now hit localhost; the databases never "listened for me" psql -h localhost -p 5432 -U app app_db A popped bulb's "scan, then try" now finds localhost ports bound to encrypted tunnels it can't join, and a context whose worst day is a forgotten dev box - visible in one list, deleted in one word. The honest part - Segmentation is messy in real life. The printer needs the laptop; the doorbell wants the phone; convenience files weekly complaints. The goal isn't a perfect diagram - it's that the default path from popped bulb to prod keys is gone, and exceptions are deliberate. - You can't audit a household. Kids' tablets, a partner's phone, the in-laws visiting Wi-Fi. The split is the admission that you'll never control every device - so control what they can see instead. - Home hygiene doesn't fix the castle. The walls still live server-side: no public IP by default, own kernel per Cube, default-deny inbound, scoped secrets. Segmentation shrinks the path to those walls; it doesn't replace them. Go look at your device list Not tomorrow. Now. Count the devices, find the oldest firmware, and ask the only question that matters: does that device share a network with the keys? Mine did - neighbors for two years, and the bulb had the worse posture. The fix cost an afternoon and a new SSID name. Best security review I've done all year, and the arithmetic was free. Top comments (0)
Comments
No comments yet. Start the discussion.