What do you guys think of the idea of smart homes? I could make a basic setup using https://home-assistant.io to control my home temperature and lighting; the tools for doing this are everywhere nowadays and implementation doesn’t seem too horrific anymore.
But setting aside what I “can” do, is this something that I “should” do? How can a person implement this without connecting any devices to the internet?
Smart homes sound good in concept and I’d love to have one if there weren’t so many risks. But an entire home that can be controlled via computers just sounds like an opsec nightmare. Obviously there’s the plus that your average technologically illiterate granny isn’t going to be using these so it will most likely have strong security systems. But hackers love a challenge.
And a whole neighborhood? A systemwide attack could happen disrupting entire swaths of a city’s residential zone. Imagine showers suddenly spraying boiling water, targeted attacks on epileptic individuals with flashing lights, temperatures dropping to below freezing or up to dangerous levels of heat or lightbulbs overloading sending broken glass everywhere, speakers bursting eardrums.
Not to mention more subtle dangers of such voice activation systems being accessed by malicious actors, or more likely, corporate concerns. Someone gangstalked or targeted by powerful people who could just court order one of these smart home companies to hand over the data and they probably will without fuss.
The attack surface of a single electronic device is massive, with dozens of different apps and services, each with different system vulnerabilities to exploit that’s already hard enough. But just imagine the attack surface of an entire home! Everything from the LG Flatscreen in your living room, to the temperature control systems, to your Apple Smart Toaster can be hacked to gain access to the rest of the system. If any one of those isn’t completely secure (which of course is a pipe dream) then it could be the gateway to a smart home hacking story on a Defcon panel.
And finally, what’s stopping the company from just updating the software for your smart home and paylocking features like “Uh yeah, you need to pay 12.99$ a month to have your cctv cameras work.” And because all the framework that runs the systems is being hosted in proprietary servers, you can’t do shit. And you can’t host your own servers either. Does this sound familiar because it should?
To be fair, many of those problems are things you can mitigate by picking the right vendor and staying away from anything that needs to phone home or use the internet
What’s stopping the company from just updating the software
The fact that I buy zwave stuff designed never to connects to the internet
And you can’t host your own servers either
Home Assistant says otherwise
Okay that’s fair, you bring up good points. I’m actually glad there are counter to my points. Thanks 👍.
This. I have been slowly building my smart home for the last 4-5 years, and I’ve yet to have a dead piece of equipment outside of a failed plug-in outlet. Since i do run everything through home assistant, there isn’t really any worry on my end up about longer term support, and if something does break in 10 years then whatever, I got 10 years of automation and a fun hobby and I’ll just replace it with the switches and shit that I took out to begin with. But because my house is now built around zigbee and home assistant, the only thing I actually have to worry about is HASS going away.
I mean, sure, I’ll probably upgrade to other things over time anyway, but that is the nature of technology. I mean, I’m sure these articles have been written but this thread is the equivalent of “laptops - computers are already fine, isn’t it just going to be a headache to carry one with you?” Ditto for modern mobile phones.
Yeah, my favorite part is the stability, honestly. I don’t have my HA instance facing the internet in any way, only accessible via my Nebula overlay network. No pressure to update the OS regularly or expect that I’m suddenly going to lose features because some big tech company decided they wanted to paywall or disable it in an update.
The fact that I moved earlier this year and was able to bring my whole smart home setup with me, and have it working at the new house before we even had an Internet connection is just golden.
This sounds more and more like Watch Dogs 2 and HAUM
I was think about it when I was writing it XD.
I’ve been using Home Assistant for a while now. I do recommend setting up a VLAN that can’t communicate with the internet which is where any wifi devices live. However I really like ZigBee and/or Z-Wave devices as they don’t require any internet connection.
Lights alone are a game changer. Timers never really worked well for us because we’re pretty far north of the equator and sunrises/sunsets have a pretty big swing. I currently have the lights come on 1 hour before sunset so it adjusts to this swing without me having to do anything. Then I have a button on my nightstand that turns off all the lights that aren’t night lights.
The downsides are that it can be expensive. You start with a couple of light bulbs, maybe a couple of outlets, next thing you know you are pricing out how much it will cost to change all your switches and trying to figure out if they all have neutral wires or not. You’ll start watching youtube videos of people’s setups and looking for ways to do more with your smart home. It’s a fun hobby but can be a lot of work.
I like that the ZigBee and z-wave devices don’t need internet, but the biggest reason in my opinion is the relay function where they extend the network, and the binding options so they work even if your hub or wireless goes down.
Yeah, the mesh features is really nice.
Smarthome well done is good and I think it will be necessary to tackle some challenges of the future - we need smart solutions to use ressources much more efficiently.
But: 85% of all smart home products are neither smart nor good. They are glorified remote controls. Nothing more.
AMAZON ALEXA IS NOT A SMART HOME PRODUCT.
A smart house doesn’t need you to use your phone/voice/etc. to turn down the blinds or switch on a light. It knows when the blinds need to be where depending on your location, the weather (blind based cooling in summer, heating in winter), the time, etc. It inherently doesn’t need a internet connection to control itself - it only does need the internet to expand its knowledge of the outside world,e.g. by getting disaster alerts, weather forecasts or off-site-location. When done this way there isn’t much “hacking” that can be done. There aren’t many components that can turn into botnets.
This is all possible for ages and it is all easily achieved - KNX and other systems are good examples. Matter can possibly achieve that. But currently it’s the big hype to call everything that can be voice controlled smart.
For fucks sake. It takes me longer to say “Alexa turn on the living room lights” than to do it myself or use a Clapping sensor from the 80ies.
Smart homes in centralized hands, such as Google? Nightmare.
Smart homes controled from your home, like home assistant? Awesome. I have home assistant and done some lights, water sensor, even my security cameras. It’s a lot of work, but it works so well it’s crazy.
I sorta wonder about these when selling the house to the next person. What if a little old lady buys your house?
I thought I’d remove them if the buyer isn’t interested. They still work like normal light switches without a smart home hub.
Just remember, the S in IOT stands for security.
I do have some IOT devices on my network, however they are kept off the internet and on their own vlan. No phoning home (or anywhere else) for these devices.
They can be great if they are set up properly, but too many people just take them out of the box, toss them on their network and think they are just fine.
I’d wager 90% of users do that. I see way too much phoning home former to ever be comfortable with that.
I’m a bit more pessimistic about that percentage… maybe 90% of people with the technical ability and inclination to micromanage their devices. But I’d wager the majority of users just want a remote control mood light and do not care that it’s using the WiFi
The S in IoT stands for security
That’s actually what I made the SSID for the wireless access point for the VLAN i have isolated for any wifi specific smart devices.
I didn’t buy any, but my wife did without realizing they were incompatible with my existing home assistant setup due to being cheap Chinese crap
I don’t see anyone in here talking about HomeKit, which is also a good solution for secure IOT. Many HomeKit accessories can be set up to only communicate with your LAN and to not need 3rd party apps or accounts.
I also have my system connect to a router that supports HomeKit secure, which blocks any phoning home to 3rd parties.
Big problem with HomeKit is 1) Siri is meh 2) fewer IOT accessories
As others have said, you can sequester IoT devices to a VLAN that has no internet access. Most of the common devices (lights, switches, sensors) added to smart homes work perfectly fine without access to the internet. Voice assistants are the biggest security/privacy hole since all commercial options are from big tech companies and phone home constantly. If you set up a local homeassistant instance you can get a ton of functionality out of smart devices with no direct connection to the internet. You need to decide how you handle accessing homeassistant from outside your home if that’s something you want but there are plenty of options to choose from for that.
One thing I will say that I refuse to add to my home is any kind of smart locks. No matter how much I trust my security setup, I don’t trust it with the ability to unlock my doors. If there was one that could only lock them electronically but required being manually unlocked, them maybe. But I haven’t seen a lock like that out there.
Agreed on all points.
I just wanted to add that I’m very glad smart locks exist. My friend with cerebral palsy can now secure his home with a lock and be able to get back in independently.
In general, smart devices are huge for him, and others with physical disabilities.
Also, I should say that I really enjoy the convenience of having Google Assistant in the house. Verbal timers, alarms, reminders, podcasts, and music mostly. Those and the pirate FireTV Stick are our only devices to date. I just don’t care enough to put the legwork in to getting IoT set up. Switches are fine.
That’s great that they help your friend like that! As someone that doesn’t face any kind of accessibility issues myself, it’s easy to overlook those kinds of benefits that these devices can provide. In situations like your friend’s, I’d agree that any potential security cons are outweighed by the pros (especially if the alternative before was having to leave the doors unlocked anyways).
Agree on the convenience of voice assistants. I’ve got various models of Google homes in my house that I use for voice controls on anything I don’t have a good way to truly automate. Different people will have different tolerances for how okay they are with the data things like that can gather. One day I might try to set up one of the local network voice assistants but those can take a lot of work to get just right. Always a tradeoff of convenience and privacy.
Or better yet: only use zigbee devices which work offline without the need to access your wifi network.
Oh that’s interesting. Does Google Home work on an unconnected VLAN for lights? I use it for lights and kitchen timers. I don’t see myself adding anything more complicated or invasive though.
I don’t think Google home would work without an internet connection. I believe google devices and the google home app expect a connection to Google’s servers.
I personally use homeassistant to control everything without an external internet connection and I know you can lock Philips Hue lights off from the internet and the official Hue app will still work.
Yeah no. As a former IT guy the last thing I want is be tech support for my family’s light switch
I’ve been using smarthome stuff for quite a while now, and my conclusion is this:
- You absolutely have to stay local. Home Assistant is the only software I know that can pull that off at the moment, but never ever use commercial devices that have to talk to their servers. Once the servers are down or your internet connection is down, those devices are just bricks, and you don’t want that at home.
- The setup is only really usable by the person who set it up. If you’re living alone that’s fine, but anybody else will have a hard time tapping in your secret code to turn on the lights. All trained behavior like pushing a light switch to turn the lights on and off are violated in a smart home, even if it’s just because the delay between pushing the button and the lights going on is increased by 100ms.
- You have to monitor battery levels of sensors and replace them to keep the system working. There are dozens of coin cells in your home, they are going to run out eventually (after a few months).
- Have a fallback mechanism when the network goes down. It’s not great when you can’t turn on the lights to check why the WiFi router isn’t responding.
All trained behavior like pushing a light switch to turn the lights on and off are violated in a smart home, even if it’s just because the delay between pushing the button and the lights going on is increased by 100ms.
This is only true if you’re controlling bulbs instead of switches. Virtually all of my lights are on z-wave switches that work almost exactly the same as regular switches, the only difference being that the switch paddle doesn’t stick in an on or off position. Smart control is strictly in addition to the primary control.
Completely agreed on your other points, though. Absolutely no chance I’d use anything other that a local Home Assistant server that handles all processing locally.
I’ve installed an Aqara wall switch in a public room, and people are complaining that it doesn’t feel as well as a regular light switch. It’s really hard to get it right.
Yeah, unfortunately there’s not much that can be done there, at least not without adding little motors to the switch so it can match state with whatever it’s controlling. My experience has been that there’s an adjustment period, but eventually it’s not a big deal. Sort of like switching to paddle switches from toggle switches; at first it’s different, and people don’t like different when it comes to things they don’t think about, like light switches. But eventually the new thing becomes normal, and it’s not a problem anymore.
That said, the z-wave toggle switches are garbage, it’s much easier to adjust to paddles.
The rate at which the go obsolete is my issue. If you invest in a system, just be prepared to replace everything every five years, and there is almost nothing yoiu can ‘fix’…it is all disposable.
Yeah the main problem is that companies that do this kind of thing want you to subscribe to a recurring payment and if you find something that works “offline” it’s codged together and quite fragile. So you either pay and upgrade when companies say so (see: Arlo cameras) or you spend lots of time trying to fix stuff.
I’m leaning towards the second option, having been burned already by subscription models, but at the moment I don’t have any of the smart stuff and I’m waiting for wife to forget the fiasco…
Not all of them! I really like my athom smart home gear, everything they sell runs on FOSS firmware and they even have github repos to host any device-specific modifications! As long as WLED and EspHome continue supporting the ESP8266 my devices should keep getting updates!
If you’re smart about it, doing home automation can be really rewarding and useful. Automating lights to turn on when it gets dark is probably the most useful thing. I also have a window fan to bring in cool night air, which automatically clicks off at 60°. All of this runs locally on a raspberry pi via home assistant and z-wave, no sus devices on my network!
You can connect devices locally now. Eg. Zigbee/Z-wave network protocol without the need to use the internet. I know some builders started to implement smart devices for Apartments in the city which is easy to set the standards but for individual homes, would be harder to sell as it’s costly…
Your neighbors are a security threat too, not just Internet criminals.
I really like this statement I heard recently, which I think came from the YouTube Adventurous Way - “Dumb Control, Smart Monitoring”. Make sure that any devices you install have failure models that make sense - you should still be able to control your appliances when the network is down.
That said, the option to remotely control lights, etc is fantastic. I also recommend setting up some temperature sensors in various places - I have quite a few ESP33 boards scattered around with sensors (and and one with an IR blaster) attached.
Making sure you are still able to control everything when the network is down seems like a good idea.
In our house, the smart plugs have a physical button that can be used to toggle them on or off. The lights are still connected to a physical power switch, so they can be reset by flipping the switch a few times, in which case they will probably just act as a normal light. Air conditioning units have an IR remote.
All important automations should run fully locally. I also find that focused and simple automations are often most useful. When I say simple I mean in terms of automation logic, not necessarily in terms of interfacing devices, which can be tricky at times. Example of simple automations I like most would be switching amplifiers on/off based on audio state changes, switching lights on/off relative to sunset, and switching electric water and floor heating elements on/off depending on energy price.
I agree, I also make sure everything is fully local. I have separate subnets for the server that runs home assistant, the IoT devices, and the trusted home network. Then I have some firewall rules that ensure that the IoT network cannot communicate with the WAN or the trusted LAN network at all, only with home assistant.
We have some simple automations at home to turn on the boiler in the afternoon when we have an abundance of solar power, and some basic automation to turn off aquarium lights at night such that the fish can sleep. Anything more complex just becomes unreliable and annoying.
I’ve been using homeassistant since the start of the year and I’m never going back! Took a while to get the hang of it but being able to make my own smart electronics on the cheap is bloody awesome.
None of my smart-home stuff is closed source which helps a lot with trust, and I’ve even tested it to ensure that everything works even if my flat’s internet goes down! Having all my light bulbs running the FOSS WLED firmware also means that I can hook them up to my HyperHDR setup so all the lighting in my room changes colour to match my TV.
I’m super interested in all these projects! Would you mind sharing guides you found helpful when designing and building then?
For HyperHDR I started with this guide along with a bunch of YouTube tutorials and a lot of trial and error given it was my first time soldering and first time using a microcontroller in a project!
With the cannabis vape I basically used the skills I learned making my HyperHDR setup along with a multimeter and the EspHome documentation (and even more trial and error) to emulate the potentiometer that was originally wired to the temperature controller and to control an LED I wired up to it.
Other than the official documentation the main thing that I found super helpful was the official HomeAssistant forums and (unfortunately) Reddit.
Thank you so much for all these details, this will help a ton! I taught myself to solder a few years ago to do custom LEDs in my kitchen and kid’s bedroom, and it was super fun. I’m really excited to try out some of the stuff you did, thanks again!
Harmful, the internet of things in general is.
You don’t need stuff that is 100% in a bot net caus its completely unsecured.
Great advice by Yoda!
𓁹‿𓁹
Buddy of mine moved into a new apartment and they have a couple of “smart features”: Temp, blinds, lights. No cameras (except the front door) or other fancy stuff.
However the apartment can be reached from any browser with a hash. So if you know the hash, you can easily access his apartment controls. No password, 2FA or anything necessary to identify him.
When he told me I was looking at him with wide eyes and he just laughed and said “Yeah, I know.”.
Soo…what’s the hash?
I mean, you’d have to guess it and that’s the hard part, but if you can, you can probably also guess the hash of all other apartments. Unless they add some random string into the hashable info, you can guess your own hash with your own apartment info (every apartment has a house ID and apartment ID etc.).
Would be a funny weekend project to see if we could get anywhere with it. He could turn down the heat from his neighbors.
If you are at least familiar with technology and search engines you can find pretty much any smart device on shodan.io