π Home Assistant
Get started with local smart home platform.

Smart home also means responsibility. An insecure setup can give hackers access to your network, cameras, and data. Take security seriously from the start.
| Action | Why | How |
|---|---|---|
| Strong passwords | Weak passwords = easy access | Use password manager, 16+ characters |
| Two-factor on HA | Extra protection | Settings β Users β 2FA |
| Update everything | Security holes get patched | Check for updates weekly |
| Change default passwords | Everyone knows them | Router, cameras, everything! |
| Action | Why | How |
|---|---|---|
| Separate IoT network | Isolates devices | VLAN or guest WiFi |
| Local DNS (Pi-hole) | Blocks tracking | Run Pi-hole or AdGuard |
| VPN for remote access | Secure access from outside | WireGuard, Tailscale |
| Avoid cloud devices | Smaller attack surface | Choose local alternatives |
| Action | Why | How |
|---|---|---|
| Firewall rules | Control traffic | pfSense, OPNsense |
| IDS/IPS | Detect attacks | Suricata, Snort |
| Log analysis | Detect misuse | Graylog, Grafana |
Home Assistant and ESPHome run locally on your network. This is a BIG security advantage:
| Local | Cloud |
|---|---|
| β Works without internet | β Requires internet |
| β Faster response | β Slower |
| β Private - no data to vendor | β Your data sent to cloud |
| β Works if company shuts down | β Stops if service is discontinued |
| β You have full control | β Vendor has control |
Keep IoT devices on a separate network:
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββ ROUTER ββββββββββββββββββββββββββββββββββββββββββββββββββββββββ β β β ββββββ΄βββββ ββββββ΄βββββ ββββββ΄βββββ β VLAN 1 β β VLAN 2 β β VLAN 3 β β Primary β β IoT β β Guest β β β β β β β β PC β β Sensors β β Guests β β Phone β βββΊ β Cameras β β β β HA β β Bulbs β β β βββββββββββ βββββββββββ ββββββββββββ Bad: password123β Bad: MyDog2024β Bad: qwertyβ
Good: correct-horse-battery-stapleβ
Good: Xk9#mP2$vL8@nQ4&| Manager | Price | Comment |
|---|---|---|
| Bitwarden | Free | β Recommended, open source |
| 1Password | $3/mo | Polished, family sharing |
| KeePass | Free | Offline, full control |
Want to access Home Assistant from outside? Do it securely:
| Method | Security | Difficulty |
|---|---|---|
| Nabu Casa | βββββ | Easy |
| Tailscale VPN | βββββ | Easy |
| WireGuard VPN | βββββ | Medium |
| Reverse proxy + cert | ββββ | Hard |
| Port forwarding | β | AVOID! |
π Home Assistant
Get started with local smart home platform.
π§ ESP32
Build 100% local sensors yourself.