Skip to main content
← CyberSafe@Home index

Decision matrix

Products and patterns: examples, not endorsements

Product names help make advice concrete, but the real rule is support lifecycle, updates, maintainability, recovery and trust model.

Short version

Current, supported, patched, configured and understandable beats brand loyalty. Fancy gear nobody maintains is just expensive dust.

Source imagery

Swipe examples

Ubiquiti UniFi Dream Router 7

Image 1/3

Wikimedia Commons: UniFi Dream Router 7
YubiKey 5C NFC security key

Image 2/3

Wikimedia Commons: YubiKey 5C NFC
Password manager concept

Image 3/3

Wikimedia Commons: password manager

Product decision matrix

Do not buy more maintenance than the house can carry

Product names are useful examples, not magic words. The right answer changes when the household has no maintainer, weak recovery, manual updates or a trust model nobody can explain.

On phones, start with the ownership checks, then swipe the example cards. The goal is to copy a support habit, not collect logos.

choicefamily defaultwhen ownedrouterauto-updating edgeowned rulesidentityvault + passkeysbackup keyVPNonly when neededknown providerappsofficial sourcestinker lane2 ownership checks unresolved

Scenario: Busy family

Default to boring, auto-updating choices. The family needs fewer dashboards, not more Saturday maintenance.

Examples, not endorsements

Brand confidence is premature until ownership and recovery are clear.

Pattern examples

Copy the maintenance pattern, not the logo

Swipe one card at a time on phones. Each card ties a concrete image to the ownership question behind it.

Ubiquiti UniFi Dream Router 7

Wikimedia Commons: UniFi Dream Router 7

Example 1/3

Router pattern

Good: Supported edge device, auto-update where possible, one named owner.

Watch: Prosumer gear that becomes family infrastructure nobody checks.

Ubiquiti Trust Center
YubiKey 5C NFC security key

Wikimedia Commons: YubiKey 5C NFC

Example 2/3

Identity pattern

Good: Passkeys or security keys plus a password manager and backup route.

Watch: A strong login that fails when the only phone or key disappears.

Passkeys.dev
Password manager concept

Wikimedia Commons: password manager

Example 3/3

Vault pattern

Good: Family sharing, emergency access and recovery notes people can find.

Watch: A vault nobody else can recover, or passwords still living in chats.

1Password passkeys

Explain the jargon

Small terms, big consequences

Tap a term for the plain-English version and the practical move. No fake mystique, just the bit that changes what you do at home.

Swipe the terms one at a time below desktop width. Glossary cards can get wordy, and squeezing three of them into a tablet row helps nobody.

?Support lifecycle

The period when a vendor still ships security fixes. A product can still work perfectly while being unsafe to keep on the internet.

Do this: Check support before buying or keeping routers, cameras, phones and smart-home gear. Replace unsupported edge devices.

?Maintainer

The person who will notice updates, read warnings, keep recovery details and fix the thing when it breaks.

Do this: If nobody owns it, choose the boring auto-updating option instead of advanced gear.

?Trust model

Who can see, route, store or act on your data because you bought or installed the product.

Do this: Ask what changed: did traffic move to a VPN, passwords move to a vault, or admin power move to an app/account?

?Example, not endorsement

A named product makes the advice concrete, but it does not mean S6 is telling every household to buy that brand.

Do this: Copy the pattern: supported, maintained, recoverable and understandable. Do not copy the logo blindly.

Read these as three short household checklists. They stay stacked below desktop width so the action text does not get squeezed.

Do this

  • Choose products by support and usability, not marketing claims.
  • Prefer auto-updating options for non-technical households.
  • Use security keys/passkeys for high-value identity.
  • Treat VPNs and advanced routers as use-case dependent, not default upgrades.
  • Avoid EOL routers, mystery imports, free VPNs, residential-proxy apps, cracks, keygens and unsupervised agents.

Check

  • Who maintains it?
  • Does it auto-update?
  • Is recovery documented?
  • Is the trust model understandable?
  • What happens when support ends?

Avoid

  • Shopping list pretending to be security strategy.
  • Buying prosumer gear for a household with no maintainer.
  • Treating a VPN subscription as a personality trait.
  • Vendor certainty where only examples are justified.

Self-check questions

Questions that expose the real habit

Use these quick checks to find the next practical fix. The useful answer is not perfect security; it is whether the safer path is obvious when someone is tired, embarrassed or in a hurry.

On phones, swipe one question at a time. Use the first uncomfortable answer as the next household fix, not as a lecture.

check 1/3

Can we carry it?

If this product breaks, needs a security update or throws an alert, who in the household knows what to do?

Good sign: There is a named maintainer, a recovery route and a simpler fallback if the maintainer is away.

Watch for: Advanced gear without an owner is just another unsupported device with better marketing.

check 2/3

Trust-model question

What changed because this product exists: who can see traffic, store passwords, control cameras, route traffic or act as an admin?

Good sign: The household can explain the trade in plain English before buying or installing it.

Watch for: If the answer is 'it makes us secure' without naming what changed, the product is being treated like magic.

check 3/3

Example-not-endorsement test

Are you copying the maintainable pattern, or buying the logo because someone security-ish mentioned it?

Good sign: The choice matches the household's skill, support needs, budget, recovery plan and risk.

Watch for: A good product in the wrong house becomes a bad system.

Full guidance

More than a slide title

A decision matrix for what I would tell family without pretending every household is the same.

Swipe one guidance note at a time below desktop width. The receipt cards appear first; these notes are the deeper explanation, not a wall to skim in one go.

  1. Note 01/05

    Recommend patterns

    Family password manager, passkeys/security keys, current supported routers, automatic updates, boring defaults and recovery documentation. Those are patterns, not a brand shrine. If a different product gives the household the same maintainable result, fine.

  2. Note 02/05

    Router examples without shopping-list nonsense

    For a low-maintenance family, a current ISP router or simple auto-updating mesh may beat a prosumer dashboard. UniFi, OpenWrt, pfSense and OPNsense can be excellent when somebody owns the rules, updates and recovery path. Without that owner, complexity becomes another unsupported device.

  3. Note 03/05

    Identity products have to survive a bad day

    A password manager, passkeys and security keys are useful only if recovery is documented. Enrol a backup key where appropriate, keep recovery codes somewhere safe, and make sure a lost phone does not become a locked email, locked bank and locked cloud account at the same time.

  4. Note 04/05

    Caution patterns

    Reputable paid VPNs, DNS filtering, parental controls and advanced routers are use-case tools. They are not default upgrades. They change who can see traffic, who can break the household's internet, and who gets called when it fails.

  5. Note 05/05

    Avoid patterns

    Unsupported routers, unknown imports, cracked apps, keygens, mystery APKs, free VPNs, free unblockers, residential-proxy participation and unsupervised AI agency. These do not fail politely. They usually fail by touching accounts, devices or bandwidth that people thought were unrelated.

Scenario

Swipe one real-world mess at a time

Scenario 1/1

Prosumer router gift

Someone buys a complex firewall for relatives who just want Wi‑Fi.

Better response

  • Choose maintainable gear
  • Document owner and update process
  • Keep setup simple

Worse habit

Leaving them with a dashboard nobody opens.