A Japanese version of this is on Zenn.
My desk has a MacBook and, permanently parked next to it, a ThinkPad running Arch Linux that I use for build chores. I was setting up a smart plug I'd just bought when it occurred to me: this random lump of firmware is on the same network as my Mac.
So I decided to simulate "one cheap IoT device got popped" and see how far I could get attacking the Mac from the ThinkPad. My Mac also runs a defense app I built myself — RoamSwitch — so this doubled as a check on how much of this it would actually catch.
Ground rules: the attacker (ThinkPad) has no special privileges, and there's no malware on the Mac. Just "one sketchy machine on the same LAN."
Port scan: how does the Mac look from outside?






