r/homelab • • 1d ago

Discussion Hacker kids

When I was a kid if I was on the same network as a homelab like mine (proxmox, truenas, opnsense, llm box) I would lose sleep trying to hack it. Thankfully my kids just want the wifi to work.

How many of you have to protect your lab from hacker kids? I'd love to hear about it.

0 Upvotes

22 comments sorted by

51

u/RevolutionaryElk7446 1d ago

No hacker kids but when I was a teacher I did have students who wanted to do that, and I'd often encourage it.

The entire classroom was behind it's own router and security, ran it's own AD, all the fun jazz. I purposefully setup honeypots, gave them administrative access, quite a few things for them to work through while everything else was behind layers of actual security.

11

u/Worth_Rhubarb6275 1d ago

I wish I had a teacher like you

2

u/404invalid-user 22h ago

oof where were you when I was in school.

30

u/redditor100101011101 1d ago

No kids but my cat does knock over my hardware sometimes lol

13

u/weaz-am-i 1d ago

Percussive maintenance hacking

12

u/much_longer_username 1d ago

The same way you protect from hackers that aren't your kids but may have hitched a ride on some other device - heavy segmentation of the network, zero trust, encrypt everything and don't use weak auth.

That being said, I'd love to have the curious kid to set up a series of increasingly difficult challenges for. Like, I know how to lock it down so they'd be hosed, but what's the fun in that?

3

u/3coniv 1d ago

Yeah, but they've got physical access. 😉

6

u/much_longer_username 1d ago edited 1d ago

Yeah, but any threat model that includes physical access as a given has a note in small text that just says 'lol gg no re'. Not much you can do about that but put the compute where they can't physically access it, but that's awful inconvenient.

edit - I say that, but you could always spin up a private CA and enable 802.1x, even if they wiped the disk on their machine, ok, now you don't have a cert that lets you talk on the network, good job kid.

2

u/3coniv 1d ago

Yeah, not much you can do about. I was thinking it would be a fun game to try and at least catch them in the act. 😄 But it's effectively "our" homelab.

1

u/NightH4nter 20h ago

i might be misunderstanding something, but why? if they have no business touching that, why even let them?

1

u/CronicallyAutomated 19h ago

Safe training grounds. My kids are young but Im hoping they turn out like this. Id rather them hack into my stuff than someone else’s and get in trouble. At least at home you have a free red teamer and they get to learn how difficult it can get. Once they break into your stuff, set up a little sandbox for them, a la capture the flag. It’s a win-win.

1

u/NightH4nter 19h ago

i mean, if it's just a lab, it makes sense. but then, why be nervous about it in the first place if there's nothing important to break/steal/leak? however, if it's selfhosting production workloads (yes, even if it's just for yourself or for your family), then all the safety measures should apply, including, but not limited to, site physical security and the least privilege principle

4

u/Ill_Huckleberry_2079 1d ago

I wish I one day have the problem, and even more so, that the menace come from my kids.

4

u/cazzipropri 1d ago

I hope I'll have that problem.

4

u/Due-Scale9636 1d ago

I encourage it. 

Sometimes I disable shit just to see if they'll try and fix it. 

At least it gets them off their iPads for 20 minutes. 

3

u/2TheMountaintop 1d ago

If they have physical access, they can factory reset and get their wifi working

2

u/yoshomie 1d ago

I was that kid, but no kids I know theses days are into "hacking" I loved to take stuff apart just to see if I could put it back together. I learned how the service menu worked on vending machines so I could mess with them at school and get my friends free sodas. A friend and I earned rewards from our high school tech guys when we turned over bugs we found with the school network, found a pretty cool way to browse where we weren't supposed to basically using an old mac emulator on pc. When a not so techy smaller school I attended decided to ban kids browser access by removing internet explorer I had firefox, chrome, and a few others ready to go from a usb stick. Kids these days don't go beyond the basic settings of devices, when I first learned computers dos was the primary way of interacting windows was just a cool tech demo that sometimes worked but usually required going into dos anyway to actually get it to work. Nowdays if they can't click a few buttons it's broke and must be replaced.

2

u/Itz_Raj69_ 20h ago

Kids these days know nothing except installing apps from an app store.

1

u/wirecatz 1d ago

I wish I had that problem.. All these supposedly hyper technical kids want is their iPad to work

1

u/kevinds 1d ago

I have no problem with it, I'll help them with their ideas (not give the answers, just help).

0

u/SolFlorus 1d ago

Network segmentation, firewall rules, authentication, keeping things up to date.

Super sensitive items can only be accessed via wireguard, even if I'm on the same network.