Smart home security: locking down cameras, bulbs, and voice assistants
IoT botnets, default passwords, guest Wi-Fi segmentation, and a practical checklist so your lights do not open a door into your network.
The smart home sells comfort: lights that listen, cameras that text you, thermostats that learn, locks that open from a phone. The same features create a new kind of household risk — dozens of little computers on your Wi-Fi, often built cheaply, updated rarely, and talking to cloud servers you never visit on purpose.
You do not need to throw the gadgets out. You do need to treat them like what they are: network devices with microphones, lenses, and default passwords.
What goes wrong with IoT devices?
Default credentials that never get changed. Open ports exposed to the internet by bad UPnP habits. Firmware abandoned after eighteen months. Cloud accounts with weak recovery. A baby monitor or camera found on a search engine for open devices because someone left remote access on. Botnets have recruited armies of hijacked DVRs and routers for years — Mirai was the famous wake-up call, and the pattern never fully left.
Voice assistants add a social layer: always-listening mics, human reviewers in edge cases, and skills/actions that can be poorly vetted. Convenience and recording sit in the same box.
How should you put them on your network?
Segment when you can. Many routers let you make a guest or IoT network so a compromised bulb cannot see your laptop. Turn off universal plug-and-play if you do not need it. Disable remote access you will not use. Change the default password before the thing phones home. Keep the hub (HomeKit, Google, Alexa, SmartThings) on two-factor authentication.
Prefer local control when a device offers it. A bulb that only works through a vendor cloud is a bulb that stops working when the vendor does — and a bulb that uploads usage patterns forever.
Cameras and mics deserve extra paranoia
Point cameras thoughtfully. Cover or power down what you do not need. Read whether video is end-to-end encrypted or merely "encrypted in transit" to a company that can still view it. For locks and garages, assume phone account takeover equals physical access and protect that account like a house key.
If a device has no history of security updates, do not put it on the same Wi-Fi as your tax documents. Cheap no-name cameras are often the worst offenders.
A practical baseline
Update firmware when vendors ship it. Unique passwords via a manager. IoT on a separate SSID. Remote access off unless required. Review connected apps yearly and delete what you forgot. Check your public IP habits the same way you would after any network change — new gear sometimes means new exposure.
The smart home is not dumb by nature. It gets dumb when we install it like furniture and never treat it like software. Furniture does not open ports. These things do.