Threat Model Your Apartment Like You Threat Model Your Laptop

Threat Model Your Apartment Like You Threat Model Your Laptop

像威胁建模笔记本电脑一样,对你的公寓进行威胁建模

Your threat model has a hole shaped like your house. You run endpoint protection on your Mac. You have 2FA, passkeys, hardened browser, DNS filtering. You would never install random software from a forum. Then you walk into your living room that has 14 always-on microphones, 6 cameras, 3 devices that map your floor plan, and a router you have never audited, all running firmware you have never read. We need to talk. 你的威胁建模中存在一个以你家为形状的漏洞。你在 Mac 上运行终端防护,使用双重验证 (2FA)、通行密钥 (passkeys)、加固浏览器和 DNS 过滤。你绝不会从论坛安装来路不明的软件。然而,当你走进客厅时,那里有 14 个常开的麦克风、6 个摄像头、3 个绘制你户型图的设备,以及一个你从未审计过、运行着你从未阅读过固件的路由器。我们需要谈谈。

In cybersec we threat model laptops. We never threat model apartments. That is backwards. Your laptop leaves your house. Your house never leaves. If your home is compromised, every device you bring into it is compromised by proximity. Here is how I started threat modeling my apartment the same way I threat model my infra. It takes an afternoon and it will make your home actually sovereign. 在网络安全领域,我们对笔记本电脑进行威胁建模,却从不对公寓进行威胁建模。这完全是本末倒置。你的笔记本电脑会离开家,但你的家永远不会离开。如果你的家被入侵,你带入其中的每一台设备都会因近距离接触而受到威胁。以下是我如何像对待基础设施一样,开始对我的公寓进行威胁建模。这只需要一个下午的时间,就能让你的家真正实现“主权独立”。

Step 1: Draw Trust Zones, Not Floor Plans

第一步:划分信任区域,而非户型图

Stop thinking in rooms. Start thinking in trust zones, exactly like network segmentation. I use 3 zones: 不要再按房间来思考,要像网络分段一样,按“信任区域”来思考。我使用三个区域:

  • Zone 0: The Dead Room. One room where no device can listen, watch, or transmit. No smart anything. No WiFi. No Bluetooth. This is where you think, talk for real, and store sensitive hardware. My bedroom is Zone 0. Nothing with a mic crosses the door. It has a mechanical door sweep and a faraday pouch for phones. 区域 0:死寂空间。 这是一个没有任何设备可以监听、监视或传输信号的房间。没有智能设备,没有 WiFi,没有蓝牙。这是你思考、进行真实对话以及存放敏感硬件的地方。我的卧室就是区域 0。任何带有麦克风的设备都不得进入。它配有机械门底密封条和用于存放手机的法拉第袋。

  • Zone 1: The Clean Network. Your own network that you control. Your router, your Pi-hole, your own hotspot. Devices you have audited. This is where your work laptop lives. It never touches landlord WiFi, coffee shop WiFi, or that free “Apartment_5G” that is actually a $30 camera streaming 24/7. 区域 1:纯净网络。 由你完全掌控的网络。包括你的路由器、Pi-hole 和个人热点。这些是你审计过的设备。这是你工作笔记本电脑所在的地方。它绝不会连接房东的 WiFi、咖啡馆的 WiFi,或者那个名为“Apartment_5G”实则是一个 24/7 全天候流媒体传输的 30 美元摄像头。

  • Zone 2: The Dirty Periphery. Everything else. Landlord’s smart lock, smart thermostat, package room cameras, your smart TV, robot vacuum, Alexa, LED strips with mics, that random air freshener that is plugged in at waist height. Assume Zone 2 is hostile and logs everything. Most people live entirely in Zone 2 and call it cozy. That is why they get doxxed by their own house. 区域 2:肮脏外围。 其他所有设备。房东的智能锁、智能恒温器、快递室摄像头、智能电视、扫地机器人、Alexa、带麦克风的 LED 灯带,以及那个插在腰部高度的随机空气清新剂。假设区域 2 是敌对的,并且会记录一切。大多数人完全生活在区域 2 中,还称其为“舒适”。这就是为什么他们会被自己的房子“人肉”出来。

Step 2: RF Sweep — Find What Is Talking

第二步:射频扫描——找出正在通信的设备

Your apartment is loud. You just cannot hear it because it talks on frequencies you cannot hear. An RF sweep is how you listen. You need two things: your phone flashlight and a $25 to $35 RF detector from Amazon. No fancy SDR needed for the first pass. The cheap one beeps when something near it is transmitting on Bluetooth, WiFi, or cellular. 你的公寓其实很“吵”,只是你听不到,因为它在人类无法感知的频率上通信。射频扫描就是你的“听诊器”。你需要两样东西:手机手电筒和亚马逊上 25 到 35 美元的射频探测器。初次扫描不需要昂贵的软件定义无线电 (SDR)。廉价的探测器在检测到附近有蓝牙、WiFi 或蜂窝信号传输时会发出蜂鸣声。

Here is the 10 minute sweep I run in every rental and every Airbnb: 以下是我在每个出租屋和 Airbnb 都会进行的 10 分钟扫描流程:

  1. Kill the lights. Close curtains. Turn on your phone flashlight and hold it next to your eyes. Slowly scan for tiny lens reflections. Camera lenses reflect even when hidden in black plastic. Check smoke detectors directly over the bed, alarm clocks, air purifiers, TV bezels, and any small black box facing the bed. 关灯。 拉上窗帘。打开手机手电筒,将其放在眼睛旁边。缓慢扫描,寻找微小的镜头反光。即使隐藏在黑色塑料中,摄像头镜头也会反光。检查床正上方的烟雾探测器、闹钟、空气净化器、电视边框以及任何对着床的小黑盒。

  2. Power down your own noise. Turn off your phone Bluetooth and WiFi for 60 seconds. This drops your own baseline so the detector does not scream at your own Apple Watch. 关闭你自己的干扰源。 关闭手机的蓝牙和 WiFi 60 秒。这会降低基准噪声,防止探测器对你自己的 Apple Watch 发出警报。

  3. Walk the walls. Hold the RF detector near outlets, power strips, smoke detectors, mirrors, picture frames, vents, thermostats. If it screams near a “dumb” object like a picture frame or a smoke detector that should not transmit, you found something that is talking when it should be silent. 沿墙扫描。 将射频探测器靠近插座、排插、烟雾探测器、镜子、相框、通风口、恒温器。如果它在相框或烟雾探测器这种本不该传输信号的“哑”设备旁发出警报,说明你找到了一个本该静默却在通信的设备。

Step 3: Network Inventory — What Is Actually On Your WiFi?

第三步:网络盘点——你的 WiFi 上到底连着什么?

Open a network scanner like Fing. Connect to your apartment WiFi and scan. You should see your phone, your laptop, maybe your TV. If you see 12 devices and you only own 3, you have neighbors piggybacking or you have hidden devices streaming. Now check the SSIDs around you. You are looking for weird names: “HD_Cam_02”, “WIFI_CAM”, “Apt_3B_Security”, or a second network with the same name as yours but with “-cam” appended. 打开像 Fing 这样的网络扫描工具。连接到公寓 WiFi 并进行扫描。你应该只看到你的手机、笔记本电脑,也许还有电视。如果你只拥有 3 台设备却看到了 12 台,说明有邻居在蹭网,或者有隐藏设备在传输数据。现在检查你周围的 SSID。寻找奇怪的名称,如“HD_Cam_02”、“WIFI_CAM”、“Apt_3B_Security”,或者与你网络同名但后缀带有“-cam”的第二个网络。

For home threat modeling, network inventory answers one question: is your apartment’s network trustworthy enough to put your laptop on? Most rentals fail this test. The fix is simple: never trust rental WiFi. Run your own hotspot through a travel router you control. 对于家庭威胁建模,网络盘点回答了一个问题:你的公寓网络是否值得信任,以至于可以连接你的笔记本电脑?大多数出租屋都无法通过此测试。解决方法很简单:永远不要信任出租屋的 WiFi。通过你控制的旅行路由器运行自己的热点。

Step 4: Firmware — Read The Code Inside The Plastic

第四步:固件——阅读塑料外壳下的代码

You would not run a binary you downloaded from a random forum. But you will plug in a $20 smart plug from Amazon that runs a full Linux OS, has a mic, and phones home to an endpoint you have never read. If you cannot dump the firmware… 你绝不会运行从随机论坛下载的二进制文件。但你却会插上一个亚马逊上 20 美元的智能插座,它运行着完整的 Linux 系统,带有麦克风,并向一个你从未阅读过的端点发送数据。如果你无法转储固件……