Earlier quoted context omitted.
Yeah, I have no idea how it could accomplish what is alleged. Just lots of very bad no good end of world comments. Have none of these people ever used public wifi?
Have none of these people ever used public wifi? This situation is totally totally unlike public wifi! When I connect to public wifi, the attack surface into my laptop is the external interface of the latest MacOS, with firewall on. Perhaps there are exploits against that, but they're not common. The Mac does have pf, but I'm sure it's a way out of date version! :) OTOH, "this thing" on the inside of a router/firewal…
Frankly yes, or at least it should be in the back of your mind when you inevitably need to upgrade some gear down the road anyway and thus the marginal cost is lower. People on HN talking about Ubiquiti probably sounds like a broken record at this point and there are certainly other providers and solutions, but you should recognize that solid centralized management and VLAN functionality and the like now has fairly good SoHo options at SoHo pricing too. You don't need to run right out and buy stuff, particularly since 802.11ax looks like it'll be a much more significant general upgrade then anything since the original AC with its focus on more efficient utilization rather then theoreticals.
But when you do, you should be getting something that lets you trivially soft-segment your network at will. At the least shoving IOT, any VoIP, and any cameras onto their own VLANs separate from your main systems is a good idea (not just for security but it can help performance too for VoIP, if you ever use it). At this point particularly with IOT I'd consider that a minimum required feature for any network gear to even be on the list for an upgrade.
>At what point does prudence and caution drift into paranoia?
At the point where hacks aren't trivially automatable for drive by and the difficulty of anything more is higher then the value of getting your stuff. When it comes to IOT though that point is regrettably a long long LONG way off, the security practices in that space are so utterly abysmal even before the typical practice of no updates ever comes in, assuming it's not actively backdoored. And of course this isn't just about you, IOT botnets are a threat to the whole net.
There certainly can be histrionics around this stuff that aren't justified, but I don't think basic segmentation, firewalling, pi-hole, and (if you must have your IOT on the public net though really you should consider using a VPN instead please) strict IP whitelist access or at least rate limits are unreasonable at all. Certainly not for the HN crowd. We can do our parts at least for our own benefit, and maybe[0] even help keep a few coworkers/family/friends/neighbors from contributing their uplinks to DDOSing our stuff too.
0: I genuinely mean "maybe" there, I know very well the payless thankless time sink it can be to take on any sort of IT work after hours. Depends on what family and friends are like. Still, sometimes though fairly low commitment/high return tips are available, or some simple trade of skills, an afternoon helping set up a better network for an afternoon of them helping with something.