Even then, and with the limited 'damage' that could be done, each and every single room got its own VLAN. That was certainly a little ugly to manage at times, especially in a 1200 room hotel, but yes.
VLANs.
Authentication.
Something.
Anything.
101–110 of 325 posts
Even then, and with the limited 'damage' that could be done, each and every single room got its own VLAN. That was certainly a little ugly to manage at times, especially in a 1200 room hotel, but yes.
VLANs.
Authentication.
Something.
Anything.
Earlier quoted context omitted.
Great my fridge just rebooted for a firmware update and bricked itself now the peas are rapidly defrosting and I am in a panic. Edit: Shoutout to Internet of Shit https://twitter.com/internetofshit
Add a physical switch for firmware updates, on an opt-in basis. How does Tesla implement updates?
Tesla has a pretty vested interest in shit keeping working considering it's a pretty luxurious and high-profile product. The cut-price manufacturer of your $20 lightbulb or $300 fridge? Not so much.
prepare to be arrested for various violations as a punishment for pointing out these obvious and dangerous flaws.
Maybe it's worse: If these are really off the shelf tablets, presumably the camera can be turned on remotely. Though I'm sure the hotel would have put a piece of black tape over it, right?
This is why I don't understand the "Internet of Things." A light switch is a pretty effective solution to the problem; there seems little advantage to networking it. Ditto for a toaster, refrigerator, et cetera, et cetera. Now get off my lawn!
You want to add motion detection to lights turning on.
You want to attach light sensors to have variable intensity bulbs be brighter or dimmer depending on ambient lighting conditions.
You want your lights to turn on inside your garage when the garage door opens.
You want your front hallway light to come on when your door is opened.
You want to be able to check all the lights in your house at a glance to make sure you did not accidentally leave any on.
You want to have all your lights auto-off when your kids should be in bed.
And of course, most importantly:
You want to turn your house into a rave party, or an epileptic seizure inducing disaster, and I don't think there is actually a difference there.
Your networked toaster might have online profiles for how to optimally toast bread, bagels, rolls, etc based on the type of bread and they would be available on a per-toaster basis. Rather than just odd balling how you want your toast done, you could buy a toaster that has profiles with high ratings that will toast your bread to your exact desire with your given model of toaster.
For your fridge, it could have isolated temperature and humidity per compartment, give alerts when different foods are low in quantity / going bad, track the expiration dates of all your food, and have the same lighting features as your house lights.
There are plenty of applications of "smart" devices. The problem with the IoT is that once you put software in a device you need to be responsible for it, and I don't believe there is actually a single hardware manufacturer on Earth right now who is legitimately responsible for their hardware and respectful of their users (particularly their software freedoms in relation to that hardware).
The 'Internet of Things' or whatever you want to call it – controllable peripherals, ubiquitous connections, stuff like that – is a pretty cool concept. I want to be easily able to do things like ask 'when will my laundry be finished?', or have my central heating come on when I start heading home. Not because it's massively beneficial, but because it removes some minor annoyances.
The technology is there, and has been for a while. But the proliferation of mindless, unforgiveable security flaws, pervasive surveillance, proprietary cloud-based networks, shitty software and bad UX generally – it's really mad. It really makes it difficult to want to use any of these devices.
I'd love some kind of proper, non-half-baked-and-riddled-with-holes solution for home automation, but I reckon I'd probably have to build it myself.
Earlier quoted context omitted.
Also, for the particular case of MODBUS over TCP, MODBUS itself doesn't have any security aspect (by design) it is a very simple byte read/write protocol really. http://www.modbus.org/docs/Modbus_Application_Protocol_V1_1b...
Just read over their FAQ. They claim that Modbus over TCP is an internet protocol. No where do they even mention security. I wonder how many devices are sitting on IPv4 addresses that are completely controllable over the net without a shred of security. Lovely.
> For example, you might know that Shodan crawls the Internet for industrial control systems (ICS). One of the most popular protocols in ICS is called Modbus that runs on port 502. At the moment, there are about 17,000 devices listening to Modbus on the default port. It turns out there are also 700 devices listening on port 503, again a one-off sort of situation.
Probably over 20k by now
Hotel name and address was not mentioned. As long as people complain but fail to name-and-shame, these practices will continue.
I feel like I'm missing out on a huge bulk of money simply because when I have ideas of "Internet of Things", I cant get over the security obstacles and cancel the ideas. If only I just didn't care (or didnt know) and just implemented whatever the heck brought in money from oblivious customers.
The difference between you and the dunces building things like this hotel light system is that you know that there's a problem and will work to fix it. As the market matures, security will become more important. But the only companies with the chance to fix it will be the ones with substantial market share. And the people who will fix it best will be the ones, like you, thinking about security from the beginning. But that can only happen if people like you get in early and lay down the infrastructure in a way where security will at least be possible.