<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
    <channel>
        <title>Remote Access on Smart Home? Sure — But Secure!</title>
        <link>https://smarthome-aber-sicher.de/en/categories/remote-access/</link>
        <description>Recent content in Remote Access on Smart Home? Sure — But Secure!</description>
        <generator>Hugo -- gohugo.io</generator>
        <language>en</language>
        <lastBuildDate>Sun, 31 Aug 2025 00:00:00 +0200</lastBuildDate><atom:link href="https://smarthome-aber-sicher.de/en/categories/remote-access/index.xml" rel="self" type="application/rss+xml" /><item>
        <title>Home Assistant Remote Access: Securely Access Your Smart Home from Anywhere</title>
        <link>https://smarthome-aber-sicher.de/en/blog/2025/08/31/home-assistant-remote-access-securely-access-your-smart-home-from-anywhere/</link>
        <pubDate>Sun, 31 Aug 2025 00:00:00 +0200</pubDate>
        
        <guid>https://smarthome-aber-sicher.de/en/blog/2025/08/31/home-assistant-remote-access-securely-access-your-smart-home-from-anywhere/</guid>
        <description>&lt;img src="https://smarthome-aber-sicher.de/blog/2025/08/31/home-assistant-fernzugriff-sicher-von-%C3%BCberall-auf-dein-smart-home-zugreifen/cover.png" alt="Featured image of post Home Assistant Remote Access: Securely Access Your Smart Home from Anywhere" /&gt;&lt;p&gt;Picture this: you&amp;rsquo;re relaxing on the beach, the sun is shining, waves are rolling in — and suddenly you wonder: &amp;ldquo;Did I actually turn off the lights?&amp;rdquo; In the past, that thought would have left you uneasy for the rest of the day. Today, you simply pick up your phone, check Home Assistant, and see immediately: everything&amp;rsquo;s fine. The lights are off, the doors are locked, the alarm is armed. Welcome to the world of secure remote access!&lt;/p&gt;
&lt;p&gt;But beware: the path to this convenience is paved with security traps that can turn your smart home into an open door for hackers. This video shows you how to balance comfort and security.&lt;/p&gt;
&lt;div class=&#34;video-wrapper&#34;&gt;
    &lt;div class=&#34;video-placeholder&#34; onclick=&#34;loadIframe(this)&#34;&gt;
        &lt;img src=&#34;https://smarthome-aber-sicher.de/img/sas_youtube.png&#34; alt=&#34;YouTube Video&#34;&gt;
        &lt;div class=&#34;play-button&#34;&gt;&lt;/div&gt;
        &lt;div class=&#34;privacy-notice&#34;  style=&#34;color: var(--card-text-color-main);&#34;&gt;
            To load the video, please click the image. Please note that by doing so, data will be transmitted to YouTube.
        &lt;/div&gt;
    &lt;/div&gt;
&lt;/div&gt;
&lt;script&gt;
    function loadIframe(element) {
        var iframe = document.createElement(&#39;iframe&#39;);
        iframe.setAttribute(&#39;loading&#39;, &#39;lazy&#39;);
        iframe.setAttribute(&#39;src&#39;, &#39;https://www.youtube-nocookie.com/embed/VOhgohQiTLI&#39;);
        iframe.setAttribute(&#39;allowfullscreen&#39;, &#39;&#39;);
        iframe.setAttribute(&#39;title&#39;, &#39;YouTube Video&#39;);
        element.parentNode.replaceChild(iframe, element);
    }
&lt;/script&gt;
&lt;style&gt;
    .video-placeholder {
        position: relative;
        cursor: pointer;
    }
    .video-placeholder img {
        width: 100%;
        height: auto;
    }
    .play-button {
        position: absolute;
        top: 50%;
        left: 50%;
        transform: translate(-50%, -50%);
        width: 60px;
        height: 60px;
        background: url(&#39;/img/youtube_button.svg&#39;) no-repeat center center;
        background-size: contain;
    }
    .video-placeholder:hover .play-button {
        position: absolute;
        top: 50%;
        left: 50%;
        transform: translate(-50%, -50%);
        width: 60px;
        height: 60px;
        background: url(&#39;/img/youtube_button_hover.svg&#39;) no-repeat center center;
        background-size: contain;
    }
    .privacy-notice {
        position: absolute;
        bottom: 50px;
        width: 100%;
        left: 50%;
        transform: translateX(-50%);
        background-color: rgba(0, 0, 0, 0.7);
        color: white;
        padding: 5px 10px;
        border-radius: 5px;
        font-size: 12px;
        text-align: center;
    }
&lt;/style&gt;

&lt;h2 id=&#34;what-remote-access-really-means&#34;&gt;What Remote Access Really Means
&lt;/h2&gt;&lt;h3 id=&#34;the-invisible-bridge-between-you-and-your-home&#34;&gt;The Invisible Bridge Between You and Your Home
&lt;/h3&gt;&lt;p&gt;Remote access to Home Assistant is like an invisible bridge between you and your home. Whether you&amp;rsquo;re at the office, on vacation, or just out shopping — this digital connection gives you access to all your smart home&amp;rsquo;s features at any time.&lt;/p&gt;
&lt;p&gt;The key difference from local use: your data travels across the internet. That makes things both exciting and risky. The video gives you a clear picture of how the different connection methods work and where the dangers lurk.&lt;/p&gt;
&lt;h3 id=&#34;why-your-smart-home-needs-remote-access&#34;&gt;Why Your Smart Home Needs Remote Access
&lt;/h3&gt;&lt;p&gt;A smart home without remote access is like a sports car without a road — technically impressive, but practically useless the moment you leave the house. Home Assistant&amp;rsquo;s true power only unfolds when you can reach it from anywhere.&lt;/p&gt;
&lt;p&gt;Imagine getting a notification about unusual power consumption while you&amp;rsquo;re at work. Without remote access, you&amp;rsquo;re in the dark until you get home. With remote access, you can check immediately, identify the problem, and take action — potentially preventing serious damage.&lt;/p&gt;
&lt;h2 id=&#34;the-four-ways-into-your-smart-home&#34;&gt;The Four Ways Into Your Smart Home
&lt;/h2&gt;&lt;h3 id=&#34;option-1-vpn--the-classic-secure-channel&#34;&gt;Option 1: VPN — The Classic Secure Channel
&lt;/h3&gt;&lt;p&gt;VPN is like an armored tunnel through the wild internet. With solutions like WireGuard, Tailscale, or OpenVPN, you establish an encrypted connection to your home network. For your phone or laptop, it&amp;rsquo;s as if you were sitting right at home.&lt;/p&gt;
&lt;p&gt;The big advantage: maximum security and full control over your data. The downside: setup can get a bit technical. The video walks you through the most important VPN options and helps you find the right one for you.&lt;/p&gt;
&lt;h3 id=&#34;option-2-home-assistant-cloud--simplicity-at-a-price&#34;&gt;Option 2: Home Assistant Cloud — Simplicity at a Price
&lt;/h3&gt;&lt;p&gt;The Home Assistant Cloud from Nabu Casa is the premium option of remote access solutions: comfortable, reliable, and incredibly easy to set up. A few clicks, a monthly fee of around €5, and you&amp;rsquo;re ready to go.&lt;/p&gt;
&lt;p&gt;What makes it special: no port forwarding required, no complex network configuration. Nabu Casa handles everything. At the same time, you&amp;rsquo;re supporting Home Assistant&amp;rsquo;s development, since the revenue flows directly back into the project.&lt;/p&gt;
&lt;h3 id=&#34;option-3-reverse-proxy--for-the-tech-enthusiasts&#34;&gt;Option 3: Reverse Proxy — For the Tech Enthusiasts
&lt;/h3&gt;&lt;p&gt;A reverse proxy like Cloudflare Tunnel is the solution for those who like to tinker while still wanting professional-grade security. It becomes particularly compelling in combination with Cloudflare Access, an authentication layer that adds an extra line of defense.&lt;/p&gt;
&lt;p&gt;This approach offers maximum flexibility and can be run for free. The setup effort, however, should not be underestimated. The video gives you an overview and points you to a detailed Cloudflare tutorial.&lt;/p&gt;
&lt;h3 id=&#34;the-path-to-disaster-direct-port-forwarding&#34;&gt;The Path to Disaster: Direct Port Forwarding
&lt;/h3&gt;&lt;p&gt;There is a fourth option — one I&amp;rsquo;m mentioning only to warn you against it: direct port forwarding without additional protection. That&amp;rsquo;s like leaving your front door wide open with a sign that says: &amp;ldquo;Smart home owner lives here!&amp;rdquo;&lt;/p&gt;
&lt;p&gt;Hackers constantly scan the internet for exactly these kinds of open doors. An unprotected open port is an open invitation for attackers. For more on this topic — and how to do it right — check out my separate video on secure port forwarding.&lt;/p&gt;
&lt;h2 id=&#34;the-most-common-pitfalls-and-how-to-avoid-them&#34;&gt;The Most Common Pitfalls and How to Avoid Them
&lt;/h2&gt;&lt;h3 id=&#34;pitfall-1-weak-authentication&#34;&gt;Pitfall 1: Weak Authentication
&lt;/h3&gt;&lt;p&gt;&amp;ldquo;123456&amp;rdquo; or &amp;ldquo;password&amp;rdquo; may be easy to remember, but they&amp;rsquo;re just as easy to crack. When accessing your smart home remotely, a strong, unique password isn&amp;rsquo;t optional — it&amp;rsquo;s mandatory.&lt;/p&gt;
&lt;p&gt;Even better: enable two-factor authentication (2FA). Even if an attacker gets hold of your password, they can&amp;rsquo;t get in without the second factor. The video shows you how to enable and properly use 2FA in Home Assistant.&lt;/p&gt;
&lt;h3 id=&#34;pitfall-2-missing-access-restrictions&#34;&gt;Pitfall 2: Missing Access Restrictions
&lt;/h3&gt;&lt;p&gt;Not everyone should be able to access your smart home from anywhere. IP allowlists let you limit access to known locations. Role-based permissions ensure that guests can only see what they&amp;rsquo;re supposed to see.&lt;/p&gt;
&lt;p&gt;These techniques are more powerful than they might seem at first. The video walks you through practical examples and explains how to make the most of these security features.&lt;/p&gt;
&lt;h3 id=&#34;pitfall-3-unencrypted-connections&#34;&gt;Pitfall 3: Unencrypted Connections
&lt;/h3&gt;&lt;p&gt;HTTP is like sending a postcard — anyone can read it. HTTPS is like a sealed letter. When accessing your smart home remotely, always use encrypted connections, regardless of which method you choose.&lt;/p&gt;
&lt;h2 id=&#34;creative-uses-for-your-remote-access&#34;&gt;Creative Uses for Your Remote Access
&lt;/h2&gt;&lt;h3 id=&#34;smart-heating-control&#34;&gt;Smart Heating Control
&lt;/h3&gt;&lt;p&gt;Imagine you&amp;rsquo;re returning from vacation earlier than planned. Instead of coming home to a cold apartment, you start the heating from the highway. By the time you arrive, it&amp;rsquo;s comfortably warm — without wasting energy in the meantime.&lt;/p&gt;
&lt;h3 id=&#34;smart-doorbell-monitoring&#34;&gt;Smart Doorbell Monitoring
&lt;/h3&gt;&lt;p&gt;Expecting a package but still at work? With remote access, you&amp;rsquo;ll see immediately when someone rings the doorbell. You can talk to the delivery driver, tell them where to leave the package, or even unlock the door if you trust them.&lt;/p&gt;
&lt;h3 id=&#34;garage-door-timing&#34;&gt;Garage Door Timing
&lt;/h3&gt;&lt;p&gt;This is one of my favorite use cases: you open the garage door from your car while you&amp;rsquo;re still two streets away. By the time you arrive, the door is already open and you can drive straight in without stopping. A small convenience that meaningfully improves everyday life.&lt;/p&gt;
&lt;p&gt;The video shows these use cases in action and gives you ideas for your own creative solutions.&lt;/p&gt;
&lt;h2 id=&#34;why-you-should-watch-the-video&#34;&gt;Why You Should Watch the Video
&lt;/h2&gt;&lt;p&gt;This article gives you a solid overview of remote access options. But the video shows you the practical implementation. You&amp;rsquo;ll see:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Live demonstrations&lt;/strong&gt; of the different remote access methods&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Step-by-step guides&lt;/strong&gt; for setup&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Security checklists&lt;/strong&gt; to work through&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Real-world examples&lt;/strong&gt; of creative use cases&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Troubleshooting tips&lt;/strong&gt; for common issues&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Particularly valuable are the security notes that are hard to convey in article form. In the video, you&amp;rsquo;ll see concretely what to watch out for and how to avoid typical beginner mistakes.&lt;/p&gt;
&lt;h2 id=&#34;the-home-assistant-az-series&#34;&gt;The Home Assistant A–Z Series
&lt;/h2&gt;&lt;p&gt;This video is part of the &amp;ldquo;Home Assistant A to Z&amp;rdquo; series — a systematic introduction to all the important aspects of Home Assistant. Each video stands on its own and can be digested in about 5 minutes.&lt;/p&gt;
&lt;p&gt;Whether you&amp;rsquo;re just getting started or already have experience: this series is guaranteed to offer new tips and tricks. Remote access is a particularly important piece of the puzzle, because it transforms your local smart home into a truly flexible system.&lt;/p&gt;
&lt;h2 id=&#34;conclusion-security-before-convenience&#34;&gt;Conclusion: Security Before Convenience
&lt;/h2&gt;&lt;p&gt;Remote access to Home Assistant isn&amp;rsquo;t a luxury — it&amp;rsquo;s a necessity for a modern smart home. But as with all powerful tools: with great power comes great responsibility.&lt;/p&gt;
&lt;p&gt;The video shows you how to handle that responsibility correctly. You&amp;rsquo;ll learn not just how remote access works, but how to implement it securely. Because in the end, the best remote access solution is worthless if it turns your home into an open door for attackers.&lt;/p&gt;
&lt;nav class=&#34;ha-az-nav&#34; aria-label=&#34;Home Assistant A-Z Navigation&#34;&gt;
  &lt;div class=&#34;ha-az-nav-label&#34;&gt;📚 Home Assistant A–Z · Teil 6 von 15&lt;/div&gt;
  &lt;div class=&#34;ha-az-nav-inner&#34;&gt;&lt;a href=&#34;https://smarthome-aber-sicher.de/post/ha-az/05-entit%C3%A4ten/&#34; class=&#34;ha-az-nav-btn ha-az-nav-prev&#34;&gt;← E · Entitäten&lt;/a&gt;&lt;a href=&#34;https://smarthome-aber-sicher.de/post/ha-az/07-ger%C3%A4te/&#34; class=&#34;ha-az-nav-btn ha-az-nav-next&#34;&gt;G · Geräte →&lt;/a&gt;&lt;/div&gt;
&lt;/nav&gt;





&lt;blockquote&gt;
    &lt;p&gt;Note: Links marked with &lt;em&gt;affiliate link&lt;/em&gt; are affiliate links. As an Amazon Associate I earn from qualifying purchases. This means I receive a small commission if you purchase through these links — at no extra cost to you. The revenue helps me run this blog and YouTube channel and keep creating content. Thank you for your support!&lt;/p&gt;&lt;span class=&#34;cite&#34;&gt;&lt;span&gt;― &lt;/span&gt;&lt;span&gt;Joachim&lt;/span&gt;&lt;cite&gt;&lt;/cite&gt;&lt;/span&gt;&lt;/blockquote&gt;
</description>
        </item>
        <item>
        <title>Remote Access with Cloudflare – Done Right!</title>
        <link>https://smarthome-aber-sicher.de/en/blog/2025/04/18/remote-access-with-cloudflare-done-right/</link>
        <pubDate>Fri, 18 Apr 2025 00:00:00 +0000</pubDate>
        
        <guid>https://smarthome-aber-sicher.de/en/blog/2025/04/18/remote-access-with-cloudflare-done-right/</guid>
        <description>&lt;img src="https://smarthome-aber-sicher.de/blog/2025/04/18/fernzugriff-mit-cloudflare-richtig-sicher/cover.jpg" alt="Featured image of post Remote Access with Cloudflare – Done Right!" /&gt;&lt;p&gt;Many people set up a Cloudflare Tunnel, see that Home Assistant is reachable from anywhere — and stop right there. The problem: the tunnel is encrypted, but anyone can access it. No login, no access control, nothing. It&amp;rsquo;s like locking your apartment door while the building&amp;rsquo;s front door is wide open.&lt;/p&gt;
&lt;p&gt;I&amp;rsquo;ll show you how to do this properly: set up the tunnel, secure access — and at the end, make an honest assessment of what you&amp;rsquo;re trusting Cloudflare with.&lt;/p&gt;
&lt;div class=&#34;video-wrapper&#34;&gt;
    &lt;div class=&#34;video-placeholder&#34; onclick=&#34;loadIframe(this)&#34;&gt;
        &lt;img src=&#34;https://smarthome-aber-sicher.de/img/sas_youtube.png&#34; alt=&#34;YouTube Video&#34;&gt;
        &lt;div class=&#34;play-button&#34;&gt;&lt;/div&gt;
        &lt;div class=&#34;privacy-notice&#34;  style=&#34;color: var(--card-text-color-main);&#34;&gt;
            To load the video, please click the image. Please note that by doing so, data will be transmitted to YouTube.
        &lt;/div&gt;
    &lt;/div&gt;
&lt;/div&gt;
&lt;script&gt;
    function loadIframe(element) {
        var iframe = document.createElement(&#39;iframe&#39;);
        iframe.setAttribute(&#39;loading&#39;, &#39;lazy&#39;);
        iframe.setAttribute(&#39;src&#39;, &#39;https://www.youtube-nocookie.com/embed/-5ekUIhSIaM&#39;);
        iframe.setAttribute(&#39;allowfullscreen&#39;, &#39;&#39;);
        iframe.setAttribute(&#39;title&#39;, &#39;YouTube Video&#39;);
        element.parentNode.replaceChild(iframe, element);
    }
&lt;/script&gt;
&lt;style&gt;
    .video-placeholder {
        position: relative;
        cursor: pointer;
    }
    .video-placeholder img {
        width: 100%;
        height: auto;
    }
    .play-button {
        position: absolute;
        top: 50%;
        left: 50%;
        transform: translate(-50%, -50%);
        width: 60px;
        height: 60px;
        background: url(&#39;/img/youtube_button.svg&#39;) no-repeat center center;
        background-size: contain;
    }
    .video-placeholder:hover .play-button {
        position: absolute;
        top: 50%;
        left: 50%;
        transform: translate(-50%, -50%);
        width: 60px;
        height: 60px;
        background: url(&#39;/img/youtube_button_hover.svg&#39;) no-repeat center center;
        background-size: contain;
    }
    .privacy-notice {
        position: absolute;
        bottom: 50px;
        width: 100%;
        left: 50%;
        transform: translateX(-50%);
        background-color: rgba(0, 0, 0, 0.7);
        color: white;
        padding: 5px 10px;
        border-radius: 5px;
        font-size: 12px;
        text-align: center;
    }
&lt;/style&gt;

&lt;h2 id=&#34;the-false-sense-of-security-through-https&#34;&gt;The False Sense of Security Through HTTPS
&lt;/h2&gt;&lt;p&gt;Many people think: &amp;ldquo;If I use HTTPS, I&amp;rsquo;m safe.&amp;rdquo; But that&amp;rsquo;s a misconception. SSL encrypts the connection — it does not prevent your Home Assistant from being visible and vulnerable on the internet. That&amp;rsquo;s exactly what happens when you only set up a tunnel and do nothing else.&lt;/p&gt;
&lt;p&gt;Today we go one crucial step further: Cloudflare Tunnel plus access control. If you&amp;rsquo;ve already set up the tunnel, you can skip ahead to the next section.&lt;/p&gt;
&lt;p&gt;Info: The hands-on step-by-step walkthrough is in the video above. You&amp;rsquo;ll need your own domain to follow along. If you don&amp;rsquo;t have one yet, I recommend Netcup based in Karlsruhe:&lt;/p&gt;









&lt;blockquote&gt;
    &lt;p&gt;&lt;figure&gt;&lt;img src=&#34;https://smarthome-aber-sicher.de/img/netcup_logo.png&#34; width=&#34;20%&#34;&gt;
&lt;/figure&gt;
&lt;p&gt;Netcup is a German hosting provider I&amp;rsquo;ve been a customer of since &lt;strong&gt;2011&lt;/strong&gt; — now with &lt;strong&gt;nine products&lt;/strong&gt; (domains, web hosting, vServers and root servers). I&amp;rsquo;ve been consistently satisfied over all those years. I particularly want to highlight the &lt;strong&gt;reliable infrastructure&lt;/strong&gt;, &lt;strong&gt;excellent support&lt;/strong&gt;, and &lt;strong&gt;transparent pricing&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;A real standout feature: &lt;strong&gt;special offers at Netcup are often permanent&lt;/strong&gt;. That sets Netcup clearly apart from other providers where the price typically rises after the first year.&lt;/p&gt;
&lt;p&gt;If you want to support me and my content, I&amp;rsquo;d be happy if you book through my referral link:
👉 &lt;a class=&#34;link&#34; href=&#34;https://www.netcup.com/de/?ref=21226&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;https://www.netcup.com/de/?ref=21226&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;I also have &lt;strong&gt;vouchers for new customers&lt;/strong&gt; for various Netcup products. Just reach out — I&amp;rsquo;m happy to help!&lt;/p&gt;
&lt;p&gt;Thank you for your support! It helps me keep creating content for you.&lt;/p&gt;
&lt;/p&gt;&lt;span class=&#34;cite&#34;&gt;&lt;span&gt;― &lt;/span&gt;&lt;span&gt;Joachim&lt;/span&gt;&lt;cite&gt;&lt;/cite&gt;&lt;/span&gt;&lt;/blockquote&gt;


&lt;h2 id=&#34;the-weak-spot-in-many-cloudflare-setups&#34;&gt;The Weak Spot in Many Cloudflare Setups
&lt;/h2&gt;&lt;p&gt;Your smart home is now reachable from the internet — and many people stop there, satisfied. But there is one critical problem with this setup: while the tunnel connection is encrypted, &lt;em&gt;anyone&lt;/em&gt; can access it.&lt;/p&gt;
&lt;p&gt;It&amp;rsquo;s like locking your apartment door while the front door of the building stands wide open. Today we do better and add an additional layer of protection.&lt;/p&gt;
&lt;p&gt;Info: The hands-on step-by-step walkthrough is in the video above.&lt;/p&gt;
&lt;h2 id=&#34;how-trustworthy-is-cloudflare&#34;&gt;How Trustworthy Is Cloudflare?
&lt;/h2&gt;&lt;p&gt;So now, to stay with the analogy, the front door is also securely locked and only someone with keys to both doors can get through. Right? Unfortunately, no. Because there&amp;rsquo;s one player you may not have on your radar — and that&amp;rsquo;s Cloudflare itself.&lt;/p&gt;
&lt;p&gt;We&amp;rsquo;ve set up two layers of protection: the authentication in Home Assistant and Cloudflare Access. For a hacker to access your smart home now, they&amp;rsquo;d need to successfully bypass both security mechanisms — Cloudflare&amp;rsquo;s and Home Assistant&amp;rsquo;s. The odds of that are orders of magnitude lower than if the system were just sitting open on the internet. Sounds like a perfect setup? Almost — because there&amp;rsquo;s one small but important catch.&lt;/p&gt;
&lt;p&gt;Cloudflare itself has unencrypted access to everything passing through the connection in this setup. And Cloudflare is a US company, which means it is not subject to the strict data protection regulations that apply here in Europe. You therefore have to place a certain degree of trust in the company behind Cloudflare. If that makes you uncomfortable — what are the alternatives? You could set up your own VPN access with WireGuard or Tailscale — technically a bit more demanding, but privacy-friendly. Or you use Home Assistant Cloud — it&amp;rsquo;s a paid service, but offers a straightforward and secure solution with considerably more concrete privacy rules than Cloudflare. However, you still have to extend some trust here too, because Nabu Casa — the company behind Home Assistant Cloud — is also a US company and is not bound by EU rules. That said, they do advertise that they don&amp;rsquo;t log user activity or analyze it for advertising purposes. That may matter to some of you.&lt;/p&gt;
&lt;h2 id=&#34;my-take&#34;&gt;My Take
&lt;/h2&gt;&lt;p&gt;If you use Cloudflare correctly — with Tunnel &lt;em&gt;and&lt;/em&gt; Access — you have a free, highly secure solution for remote access to Home Assistant, without opening a single port.&lt;/p&gt;
&lt;p&gt;Cloudflare is, however, a US company with unencrypted access to your connection. If that&amp;rsquo;s not acceptable to you, consider WireGuard, Tailscale, or Home Assistant Cloud instead. More on those coming soon here on &amp;ldquo;Smart Home? But Secure!&amp;rdquo;&lt;/p&gt;
</description>
        </item>
        <item>
        <title>Why Port Forwarding into Your Smart Home Is So Dangerous</title>
        <link>https://smarthome-aber-sicher.de/en/blog/2025/04/10/why-port-forwarding-into-your-smart-home-is-so-dangerous/</link>
        <pubDate>Thu, 10 Apr 2025 00:00:00 +0000</pubDate>
        
        <guid>https://smarthome-aber-sicher.de/en/blog/2025/04/10/why-port-forwarding-into-your-smart-home-is-so-dangerous/</guid>
        <description>&lt;img src="https://smarthome-aber-sicher.de/blog/2025/04/10/so-gef%C3%A4hrlich-sind-portfreigaben-ins-smart-home/cover.png" alt="Featured image of post Why Port Forwarding into Your Smart Home Is So Dangerous" /&gt;&lt;p&gt;I&amp;rsquo;ve been diving deep into the topic of remote access to smart home systems lately – and one thing quickly becomes clear: there are now quite a few interesting options available, depending on your security needs, budget, and technical expertise.&lt;/p&gt;
&lt;p&gt;Which makes it all the more alarming that many users still simply rely on port forwarding to make their home network services accessible from the internet. Why is that dangerous? Let&amp;rsquo;s take a closer look.&lt;/p&gt;
&lt;div class=&#34;video-wrapper&#34;&gt;
    &lt;div class=&#34;video-placeholder&#34; onclick=&#34;loadIframe(this)&#34;&gt;
        &lt;img src=&#34;https://smarthome-aber-sicher.de/img/sas_youtube.png&#34; alt=&#34;YouTube Video&#34;&gt;
        &lt;div class=&#34;play-button&#34;&gt;&lt;/div&gt;
        &lt;div class=&#34;privacy-notice&#34;  style=&#34;color: var(--card-text-color-main);&#34;&gt;
            To load the video, please click the image. Please note that by doing so, data will be transmitted to YouTube.
        &lt;/div&gt;
    &lt;/div&gt;
&lt;/div&gt;
&lt;script&gt;
    function loadIframe(element) {
        var iframe = document.createElement(&#39;iframe&#39;);
        iframe.setAttribute(&#39;loading&#39;, &#39;lazy&#39;);
        iframe.setAttribute(&#39;src&#39;, &#39;https://www.youtube-nocookie.com/embed/ExyqoW_Sslo&#39;);
        iframe.setAttribute(&#39;allowfullscreen&#39;, &#39;&#39;);
        iframe.setAttribute(&#39;title&#39;, &#39;YouTube Video&#39;);
        element.parentNode.replaceChild(iframe, element);
    }
&lt;/script&gt;
&lt;style&gt;
    .video-placeholder {
        position: relative;
        cursor: pointer;
    }
    .video-placeholder img {
        width: 100%;
        height: auto;
    }
    .play-button {
        position: absolute;
        top: 50%;
        left: 50%;
        transform: translate(-50%, -50%);
        width: 60px;
        height: 60px;
        background: url(&#39;/img/youtube_button.svg&#39;) no-repeat center center;
        background-size: contain;
    }
    .video-placeholder:hover .play-button {
        position: absolute;
        top: 50%;
        left: 50%;
        transform: translate(-50%, -50%);
        width: 60px;
        height: 60px;
        background: url(&#39;/img/youtube_button_hover.svg&#39;) no-repeat center center;
        background-size: contain;
    }
    .privacy-notice {
        position: absolute;
        bottom: 50px;
        width: 100%;
        left: 50%;
        transform: translateX(-50%);
        background-color: rgba(0, 0, 0, 0.7);
        color: white;
        padding: 5px 10px;
        border-radius: 5px;
        font-size: 12px;
        text-align: center;
    }
&lt;/style&gt;

&lt;p&gt;Hi and welcome! My name is Joachim and this is Smart Home? But Secure! I originally just wanted to put together a video showing you how I&amp;rsquo;ve been handling secure remote access to Home Assistant for years.
But in my research, I realized: there are now quite a few ways to solve the remote access problem elegantly and securely. Yet there are still a large number of users who rely on simple port forwarding (more technically known as port forwarding) to access their smart home systems while on the go. And honestly, that surprised me a bit.&lt;/p&gt;
&lt;p&gt;If you&amp;rsquo;re thinking: &amp;ldquo;Sure, old news – you don&amp;rsquo;t need to explain that to me!&amp;rdquo; – then I&amp;rsquo;d invite you to subscribe to the channel. I have a feeling this topic has potential for more than one video, and there will definitely be a few more technical deep-dives to come.
But if you&amp;rsquo;re thinking: &amp;ldquo;Huh? What&amp;rsquo;s actually the problem with port forwarding?&amp;rdquo; – then let&amp;rsquo;s take a closer look right now.&lt;/p&gt;
&lt;h2 id=&#34;why-port-forwarding-is-so-popular&#34;&gt;Why Port Forwarding Is So Popular
&lt;/h2&gt;&lt;p&gt;First of all: it&amp;rsquo;s understandable why so many users go this route. It&amp;rsquo;s simple, quick to set up, and generally involves no additional costs.
And even the problem of a dynamic IP address can be solved quickly using a dynamic DNS service. But:
You have to be aware of what you&amp;rsquo;re doing: you&amp;rsquo;re putting your service – for example Home Assistant or OpenHAB – directly onto the internet, exposed exactly the same way it is on your local network.&lt;/p&gt;
&lt;h2 id=&#34;first-risk-the-protection-layer-of-your-home-network-disappears&#34;&gt;First Risk: The Protection Layer of Your Home Network Disappears
&lt;/h2&gt;&lt;p&gt;Even if you&amp;rsquo;ve set a strong password for your service: your home network itself is an additional layer of protection. In general, far fewer malicious actors are lurking there than on the open internet.
With port forwarding, you remove exactly that protective layer. Your service is now directly reachable from the internet – for millions of users, hackers, and other bad actors.
And even if you use a secure password and 2FA – nobody can guarantee that a new security vulnerability doesn&amp;rsquo;t already exist that bypasses authentication entirely. Sure, you can install updates diligently, but those only protect against known and already-patched vulnerabilities.
That&amp;rsquo;s why you should replace that second protective layer – your home network – with something else whenever you want to expose your services on the internet.&lt;/p&gt;
&lt;h2 id=&#34;second-risk-unencrypted-connections&#34;&gt;Second Risk: Unencrypted Connections
&lt;/h2&gt;&lt;p&gt;There&amp;rsquo;s another factor to consider. As soon as your data travels over the internet, it must be encrypted – otherwise anyone can read or manipulate it.
Take Home Assistant as an example: the default connection is not encrypted. If you simply open a port to the internet, access is unsecured – just like at home, where that&amp;rsquo;s usually less of a concern.
Of course, you can secure it – for example with a free Let&amp;rsquo;s Encrypt certificate. But that means additional software and configuration. The &amp;ldquo;simple&amp;rdquo; port forwarding quickly turns into a complex software project – and that makes it not only more error-prone but often more insecure as well. A vicious cycle.&lt;/p&gt;
&lt;h2 id=&#34;my-recommendation&#34;&gt;My Recommendation
&lt;/h2&gt;&lt;p&gt;My clear recommendation: don&amp;rsquo;t use port forwarding to make your smart home accessible from the internet.
Even if you don&amp;rsquo;t have particularly high security requirements, there are better alternatives:&lt;/p&gt;
&lt;h3 id=&#34;vpn&#34;&gt;VPN
&lt;/h3&gt;&lt;p&gt;VPN: If you have a FRITZ!Box or another router that supports it, a VPN can be a great choice. It&amp;rsquo;s free, significantly more secure, and usually easy to set up. The VPN authentication provides the second protective layer that I believe is so important for internet access.&lt;/p&gt;
&lt;h3 id=&#34;home-assistant-cloud&#34;&gt;Home Assistant Cloud
&lt;/h3&gt;&lt;p&gt;Home Assistant Cloud: The service from the HA team at Nabu Casa is easy to set up and takes care of encryption for you. You don&amp;rsquo;t have to deal with dynamic DNS either. But: it costs a monthly subscription fee – though at least that money goes to the company developing Home Assistant. The downside is that the second protective layer is still missing – the login screen is directly reachable from the internet, which you&amp;rsquo;ll quickly notice from &amp;ldquo;login failed&amp;rdquo; messages in your Home Assistant log.&lt;/p&gt;
&lt;h3 id=&#34;cloudflare&#34;&gt;Cloudflare
&lt;/h3&gt;&lt;p&gt;Reverse proxies such as Cloudflare: here you build an encrypted tunnel from your home network to the proxy. There are already many great videos about this from the big smart home channels on YouTube, but I strongly recommend enabling an additional authentication layer on the proxy (called &amp;ldquo;Access&amp;rdquo; in Cloudflare) – that gives you your second protective layer here as well. Cloudflare is a US-based provider, which may be a dealbreaker for those with privacy concerns. In my research I haven&amp;rsquo;t found a comparable European alternative – if you know of one, let me know in the comments!&lt;/p&gt;
&lt;h3 id=&#34;twingate&#34;&gt;Twingate
&lt;/h3&gt;&lt;p&gt;Twingate is a provider that enables zero-trust networking and promises a modern VPN alternative. Setup is surprisingly straightforward, clients are available for all platforms, and access to individual services can be controlled in a very granular way. Even though the service is primarily aimed at businesses, it can be interesting in a smart home context – especially if you want to secure multiple devices or users.&lt;/p&gt;
&lt;h3 id=&#34;tailscale&#34;&gt;Tailscale
&lt;/h3&gt;&lt;p&gt;Tailscale takes a different approach: using WireGuard, it builds a private mesh network in which all your devices can reach each other directly – wherever they are. Particularly interesting is the newer Tailscale Funnel feature: it lets you expose a home network service publicly over the internet, including HTTPS and access control. Funnel isn&amp;rsquo;t available everywhere yet, but it&amp;rsquo;s a promising approach – especially for technically minded users.&lt;/p&gt;
&lt;p&gt;I haven&amp;rsquo;t taken a closer look at either of these two options (Twingate and Tailscale) myself yet.&lt;/p&gt;
&lt;p&gt;What role does remote access play in your smart home setup? Which solution are you using – or which one are you considering? Leave a comment below.&lt;/p&gt;
&lt;h2 id=&#34;what-i-use-personally&#34;&gt;What I Use Personally
&lt;/h2&gt;&lt;p&gt;I&amp;rsquo;ve set up my own reverse proxy with the German hosting provider &lt;strong&gt;netcup&lt;/strong&gt;. From my home network I establish an SSH tunnel that exposes only selected services toward the reverse proxy. The proxy itself is responsible for authentication and controls who can access what. I&amp;rsquo;ve configured it so that a client certificate is required for authentication. That&amp;rsquo;s how I&amp;rsquo;ve implemented my second protective layer – without opening any ports. At the same time it&amp;rsquo;s incredibly convenient, because authentication happens in the background and I don&amp;rsquo;t need to connect to a VPN or enter additional passwords. It&amp;rsquo;s certainly not the right solution for everyone – but for technically experienced users, it&amp;rsquo;s in my opinion a very elegant approach for the level of protection it provides.&lt;/p&gt;









&lt;blockquote&gt;
    &lt;p&gt;&lt;figure&gt;&lt;img src=&#34;https://smarthome-aber-sicher.de/img/netcup_logo.png&#34; width=&#34;20%&#34;&gt;
&lt;/figure&gt;
&lt;p&gt;Netcup is a German hosting provider I&amp;rsquo;ve been a customer of since &lt;strong&gt;2011&lt;/strong&gt; — now with &lt;strong&gt;nine products&lt;/strong&gt; (domains, web hosting, vServers and root servers). I&amp;rsquo;ve been consistently satisfied over all those years. I particularly want to highlight the &lt;strong&gt;reliable infrastructure&lt;/strong&gt;, &lt;strong&gt;excellent support&lt;/strong&gt;, and &lt;strong&gt;transparent pricing&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;A real standout feature: &lt;strong&gt;special offers at Netcup are often permanent&lt;/strong&gt;. That sets Netcup clearly apart from other providers where the price typically rises after the first year.&lt;/p&gt;
&lt;p&gt;If you want to support me and my content, I&amp;rsquo;d be happy if you book through my referral link:
👉 &lt;a class=&#34;link&#34; href=&#34;https://www.netcup.com/de/?ref=21226&#34;  target=&#34;_blank&#34; rel=&#34;noopener&#34;
    &gt;https://www.netcup.com/de/?ref=21226&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;I also have &lt;strong&gt;vouchers for new customers&lt;/strong&gt; for various Netcup products. Just reach out — I&amp;rsquo;m happy to help!&lt;/p&gt;
&lt;p&gt;Thank you for your support! It helps me keep creating content for you.&lt;/p&gt;
&lt;/p&gt;&lt;span class=&#34;cite&#34;&gt;&lt;span&gt;― &lt;/span&gt;&lt;span&gt;Joachim&lt;/span&gt;&lt;cite&gt;&lt;/cite&gt;&lt;/span&gt;&lt;/blockquote&gt;


&lt;h2 id=&#34;whats-next&#34;&gt;What&amp;rsquo;s Next
&lt;/h2&gt;&lt;p&gt;In the upcoming videos we&amp;rsquo;ll take a detailed look at each of these alternatives – so you can find the right solution for your situation.&lt;/p&gt;
</description>
        </item>
        
    </channel>
</rss>
