you are viewing a single comment's thread
view the rest of the comments
[–] 4 points 3 days ago (10 children)

Well barring an insecure neighbor wifi. An isolated vlan does the trick.

  • source
  • parent
  • hideshow 10 child comments
  • [–] 2 points 3 days ago (8 children)

    You really just replied to my comment saying that is insufficient, under an article saying that is insufficient, with 'that is sufficient'?

  • source
  • parent
  • hideshow 8 child comments
  • [–] 3 points 3 days ago* (7 children)

    Um... What does blocking all internet access not prevent here? By isolated VLAN I mean isolated. I.e. fully blocked from internet access LAN local replies only. 0 WAN access.

  • source
  • parent
  • hideshow 7 child comments
  • [–] 6 points 3 days ago* (3 children)

    if a device manufacturer is so hell bent on their devices phoning home that they'll connect to an insecure wifi or a wifi network run by a 'partner' provider.. they're gonna be doing that whenever it can't phone home via a configured network connection, too, and not just when there isn't one set up.

  • source
  • parent
  • hideshow 3 child comments
  • [–] 4 points 3 days ago* (2 children)

    It doesn't prevent exactly what my comment said it doesn't prevent 'an adversarial entity physically residing within the space'. If I showed up with a pi bristling with antennas, loaded with an unknown, encrypted payload, and plopped it into your living room, would you just hook it into a vlan and be like "there, now I'm safe"?

  • source
  • parent
  • hideshow 2 child comments