Comment on Security considerations of WiFi vs Zigbee for self-hosted IoT

vzq@lemmy.blahaj.zone ⁨1⁩ ⁨year⁩ ago

“Security” by itself is a meaningless concept. You need to formulate a threat model before you can say anything.

If your threat model is actors on the internet getting into your network using something related to the devices, then WiFi is many times worse. The devices are full network devices, and given for example a rogue firmware update, they can spawn a reverse shell let the actor into your network. This can and should of course be mitigated using the usual network engineering techniques. Zigbee is inherently different. Your light bulbs have no ip address, can’t route IP into your network on their own.

Another threat model is local information leak, someone in your area is listening to your radio emissions to determine if you’re home etc. This is about the same for zigbee and WiFi. They are both encrypted, but the real information is in whether there is communication, not the payload.

In terms of longevity, I would be wary of adding more 2.4 devices on your WiFi network. I can’t wait forcing the whole band.

source
Sort:hotnewtop