A Homelabber's Tour of IP KVMs: From PiKVM to the $70 Box That Drew FBI Attention
IP KVMs let you control a machine remotely at the hardware level, picking up where VNC, RDP, and SSH fall short—when a system is locked, powered off, or you need BIOS-level access without burning resources on the host. Enterprise servers handle this through iLO, iDRAC, or IPMI, but consumer-grade IP KVMs have proliferated since PiKVM launched its open source stack in 2017, with prices now ranging from sub-$50 clones to $400 fully featured rigs.
PiKVM remains the reference design, with its GPLv3 codebase forming the basis for nearly every Raspberry Pi-powered competitor, including BliKVM and GL-iNet’s Comet line. Cheaper rivals cut cost by swapping the Pi for Allwinner or Rockchip SoCs and forking the UI, while Sipeed’s NanoKVM family runs on RISC-V chips and undercuts everyone at around $70. The Pro tiers across vendors converge on roughly the same feature set: 4K capture, HDMI passthrough, WiFi, touchscreens, ATX power control, and PoE.
The security caveats matter more than the spec sheets. These devices are open doors into a network—remote BIOS access is a serious attack surface, several models have shipped with notable vulnerabilities, and the cheap, inconspicuous NanoKVM Cube was reportedly used by North Korean operatives to infiltrate US corporate networks, which earned the author a visit from the FBI. Sipeed also shipped the Cube with an undisclosed microphone on its dev board and took its time open-sourcing firmware. The recommendation: firewall these aggressively, patch them, and don’t deploy hardware from vendors you don’t trust.
Read the full article
Continue reading at Hacker News →This is an AI-generated summary. Read the original for the full story.