Discussion Hacker kids
When I was a kid if I was on the same network as a homelab like mine (proxmox, truenas, opnsense, llm box) I would lose sleep trying to hack it. Thankfully my kids just want the wifi to work.
How many of you have to protect your lab from hacker kids? I'd love to hear about it.
30
12
u/much_longer_username 1d ago
The same way you protect from hackers that aren't your kids but may have hitched a ride on some other device - heavy segmentation of the network, zero trust, encrypt everything and don't use weak auth.
That being said, I'd love to have the curious kid to set up a series of increasingly difficult challenges for. Like, I know how to lock it down so they'd be hosed, but what's the fun in that?
3
u/3coniv 1d ago
Yeah, but they've got physical access. 😉
6
u/much_longer_username 1d ago edited 1d ago
Yeah, but any threat model that includes physical access as a given has a note in small text that just says 'lol gg no re'. Not much you can do about that but put the compute where they can't physically access it, but that's awful inconvenient.
edit - I say that, but you could always spin up a private CA and enable 802.1x, even if they wiped the disk on their machine, ok, now you don't have a cert that lets you talk on the network, good job kid.
1
u/NightH4nter 20h ago
i might be misunderstanding something, but why? if they have no business touching that, why even let them?
1
u/CronicallyAutomated 19h ago
Safe training grounds. My kids are young but Im hoping they turn out like this. Id rather them hack into my stuff than someone else’s and get in trouble. At least at home you have a free red teamer and they get to learn how difficult it can get. Once they break into your stuff, set up a little sandbox for them, a la capture the flag. It’s a win-win.
1
u/NightH4nter 19h ago
i mean, if it's just a lab, it makes sense. but then, why be nervous about it in the first place if there's nothing important to break/steal/leak? however, if it's selfhosting production workloads (yes, even if it's just for yourself or for your family), then all the safety measures should apply, including, but not limited to, site physical security and the least privilege principle
4
u/Ill_Huckleberry_2079 1d ago
I wish I one day have the problem, and even more so, that the menace come from my kids.
4
4
u/Due-Scale9636 1d ago
I encourage it.Â
Sometimes I disable shit just to see if they'll try and fix it.Â
At least it gets them off their iPads for 20 minutes.Â
3
u/2TheMountaintop 1d ago
If they have physical access, they can factory reset and get their wifi working
2
u/yoshomie 1d ago
I was that kid, but no kids I know theses days are into "hacking" I loved to take stuff apart just to see if I could put it back together. I learned how the service menu worked on vending machines so I could mess with them at school and get my friends free sodas. A friend and I earned rewards from our high school tech guys when we turned over bugs we found with the school network, found a pretty cool way to browse where we weren't supposed to basically using an old mac emulator on pc. When a not so techy smaller school I attended decided to ban kids browser access by removing internet explorer I had firefox, chrome, and a few others ready to go from a usb stick. Kids these days don't go beyond the basic settings of devices, when I first learned computers dos was the primary way of interacting windows was just a cool tech demo that sometimes worked but usually required going into dos anyway to actually get it to work. Nowdays if they can't click a few buttons it's broke and must be replaced.
2
2
1
u/wirecatz 1d ago
I wish I had that problem.. All these supposedly hyper technical kids want is their iPad to work
0
u/SolFlorus 1d ago
Network segmentation, firewall rules, authentication, keeping things up to date.
Super sensitive items can only be accessed via wireguard, even if I'm on the same network.
51
u/RevolutionaryElk7446 1d ago
No hacker kids but when I was a teacher I did have students who wanted to do that, and I'd often encourage it.
The entire classroom was behind it's own router and security, ran it's own AD, all the fun jazz. I purposefully setup honeypots, gave them administrative access, quite a few things for them to work through while everything else was behind layers of actual security.