Skhron on Nostr: I would not recommend changing router IP address as it is pretty useless and is ...
I would not recommend changing router IP address as it is pretty useless and is leaked using DHCP, so you gain no security benefit. However I would like to recommend implementing separate VLAN that has an access to admin UI and SSH or the router. OpenWRT allows you to dedicate physical Ethernet port to such VLAN so unless attacker gains physical access to the router, router's attack surface is pretty small.
Published at
2024-09-03 07:53:23Event JSON
{
"id": "d004567e342b4f08c5a8cad0bf47dacf44f7e79e84cf967f0218404c3d5a0a06",
"pubkey": "2641c5060e4eec82089fdb2c9eb84714660fddf7c23a01d731311481983f0175",
"created_at": 1725350003,
"kind": 1,
"tags": [
[
"e",
"b85ebda28f87d001fd6692c027a3462a04883b2329dd1168053100b3160f979e",
"",
"root"
],
[
"p",
"40caa6d12a82232b99478b68c2515e11b29e61eb4f60655c54fd889f6583d60f"
]
],
"content": "I would not recommend changing router IP address as it is pretty useless and is leaked using DHCP, so you gain no security benefit. However I would like to recommend implementing separate VLAN that has an access to admin UI and SSH or the router. OpenWRT allows you to dedicate physical Ethernet port to such VLAN so unless attacker gains physical access to the router, router's attack surface is pretty small. ",
"sig": "7daa9ef72562eb5dc095ad3e5104b108e1ed65c6e82fa3ea2819650b7bba6c0f053a53e7cbea6e1920444e373c34f1129f06d9d9d65eef58c995c050b72220af"
}