Network security versus facility

Words
544
Reading
3 min
Listen
Play
10y

Let's face it, the Internet is a nasty place at times. Ok, all the time. You can isolate yourself as much as you like, but the more you do that, the less you are able to do. It's a compromise.

There are plenty of guides on the Internet on how to build your own router or switch. I don't need to go into any of that. But there's only so much packet processing you can do in a given time, even if you buy $25,000 of ASICs and network processors, and many of the defined standards for network protocol out there are, well, not secure by default and you need a lot of packet inspection and session monitoring to get those to work with any degree of safety.

On the flip-side, most people have never experienced multicast, have heard vaguely of this IPv6 thing, have never designed their own overlay network for gaming, have never even played XTank!

Then there's the group that are playing with completely unsecured IoT protocols to control their home appliances, when some of those appliances probably already support BACNet or one of the CAN protocols, which (of course) standard home networking gear doesn't normally support but where it's not hard to get such networks up and running with a couple of expansion cards. A completely secure way of doing precisely the same things using much more mature software. And more effort.

Effort is, in the end, the key to the whole thing. Nobody wants to do more than necessary. Well, I do, but I'm weird. Nobody cares about the potential for richer experiences, because it's a lot of hard work to find out what those experiences even are, why you might want them, figuring out how to enable them and to then balance the security needs and the loss of performance that goes with extra security with the inevitable insecurity that comes from potential misconfigurations and bugs in little-used software.

Equally, why should anyone spend time ripping apart their router and adding cards (if there's any space for them) - is it really worth the time if it just prevents the refrigerator being turned into a zombie remailer that sends spam and eats brains?

Of course, it's not as if someone couldn't come up with a home router that sported all this as standard, with the configurations already secured, multicast, IPv6, MPLS and OpenFlow enabled, optional L7 routing, a CAN card, etc. All the bells and whistles. It would cost more (not by much) and it would be slower (not by much). Most people would not need even a fraction of what it had, which is why none of the DIY routers or switches do this, so it would be money for stuff not used rather than the usual discount for the deprivation of the option.

As a geek, I like the option. I like to make my own choices. But even I have to limit the superfluous at some point. Unless it involves tea or books. Then there's no limits, except for the bank's safeword of "you are over your limit". What do other people think? What, for you, is the right balance between technological freedom of choice you might never use and the added cost/insecurity that involves?

Network security versus facility | Ecency