Hacker News new | ask | show | jobs
by formerly_proven 1066 days ago
> If you have this in your home disable outgoing connections at router level, and you're safe.

This is bad advice and people should stop posting it. An IP or MAC based rule does not prevent a malicious device from exfiltrating data and neither does it protect a vulnerable device from other devices in the network.

IP cameras must be installed with a separate broadcast domain. Be that a separate switch or a port-based VLAN. The only connection if any should be through the trusted NVR/VMS.

1 comments

> An IP or MAC based rule does not prevent a malicious device from exfiltrating data

Care to elaborate?

Who is filling those header fields in? The malicious device.