Skip to content

Build1 publisher3 min readPublished

Your Threat Model Stops At The Front Door, And Your Laptop Sleeps On The Other Side

A dev.to post argues home hardening belongs in the same trust-zone model as network segmentation. The framework transfers cleanly. The $27 tooling claims need scrutiny.

The Engineer · Build desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened

  • A post on dev.to under the handle numbpill3d, titled "Threat Model Your Apartment Like You Threat Model Your Laptop", argues that people in cybersecurity threat model laptops but never threat model apartments, and calls that backwards.
  • The author's stated reasoning: the laptop leaves the house, the house never leaves, and if the home is compromised, every device brought into it is compromised by proximity.
  • The post describes a living room containing 14 always-on microphones, 6 cameras, 3 devices that map the floor plan, and a router the reader has never audited, all running firmware the reader has never read.
  • The described living room inventory totals 23 sensing devices.
  • Zone 0, the "Dead Room": one room where no device can listen, watch or transmit, with no smart devices, no WiFi and no Bluetooth. The author's bedroom serves this role, nothing with a microphone crosses the door, and it has a mechanical door sweep and a Faraday pouch for phones.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

A post on dev.to, published under the handle numbpill3d, argues that security people threat model laptops and never threat model the apartments those laptops return to every night, and calls that backwards [1]. The asymmetry it names is the useful part: the laptop leaves the house, the house never leaves, and by the author's reasoning anything compromised in the home compromises what you carry into it by proximity [2]. The framing device is an inventory of a typical living room: 14 always-on microphones, 6 cameras, 3 devices that map the floor plan, and a router whose firmware has never been read or audited [1][3]. That is 23 sensing devices in one room [4], every one of them inside the blast radius of the machine you use for production access, and none of them subject to the change control you would demand of a rack switch. The proposed fix is not a product. It is segmentation, renamed. The author defines three zones: Zone 0, a "Dead Room" where nothing listens, watches or transmits, with no WiFi and no Bluetooth, kept as a mechanical control with a door sweep and a Faraday pouch for phones [5]; Zone 1, a clean network on hardware you control, running your own router, Pi-hole or hotspot, where the work laptop lives and never touches landlord WiFi or coffee shop WiFi [6]; and Zone 2, the dirty periphery of landlord smart locks, thermostats, package room cameras, smart TVs, robot vacuums, voice assistants and LED strips with microphones, which the author says should be assumed hostile and assumed to log everything [7]. Most people, he argues, live entirely in Zone 2 [8]. Nothing in that model is new to anyone who has built a guest VLAN. What is new is applying it to assets you do not own, cannot patch, and in some cases cannot remove, because the landlord installed them. The author claims a Zone 0 room can be built for under $200 and documents it in a separate guide called "THE FARADAY ROOM: Your Home Is Listening" [9]. Detection is where the post gets thinner. The recommended first pass is a phone flashlight plus a $25 to $35 RF detector, no software defined radio, on the basis that the cheap detector beeps when something nearby transmits on Bluetooth, WiFi or cellular [10]. The ten minute routine is lights off and flashlight held next to the eyes to catch lens reflections, then 60 seconds with your own Bluetooth and WiFi disabled to drop the baseline, then a walk of outlets, power strips, smoke detectors, mirrors, frames, vents and thermostats [11]. That second step is an admission of the tool's limits: the detector will otherwise alarm on your own smartwatch [12]. A device that indicates only "something is transmitting" produces findings you cannot triage, which is why the author's claimed hits, an AirTag taped inside a couch, a fake USB charger with a camera module, and a thermostat still transmitting after its WiFi was supposedly disabled, are anecdotes rather than evidence [13]. His own line is that skipping RF means "you are doing compliance, not security" [14]. The inverse also holds: beeping is not triage. The layer 3 checks are more auditable. Scan the apartment network with a tool like Fing, and treat a count of 12 devices against 3 you own as either neighbours on your WiFi or something streaming [15]. Enumerate nearby SSIDs for names like HD_Cam_02, WIFI_CAM or a clone of your own network with -cam appended [16]. The author also describes a $17 drop box the size of a USB charger, which he calls a Specter Box, plugged into an Ethernet port behind a rental TV so it phones home with a POST when it gets power [17]. Watch three things. Whether the callback test is documented enough to reproduce, since the source cuts off mid-description [18].

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories