Live data from Hacker News

More awful IoT stuff

mjg59.dreamwidth.org

51–60 of 245 posts

Re: More awful IoT stuff

#51

Earlier quoted context omitted.

So, the GPL never had much power?

If that's really how it works then does that mean that open source projects with no clear copyright owner can't enforce their license?

It depends.

If it has "no clear copyright owner" because it comes from an entire community and has a ton of copyright holders for little bits of the code here and there, then it means that every copyright holder can sue for breach of copyright.

If on the other hand it has "no clear copyright owner" because it was written by one person under a pseudonym and that holder is almost surely never going to come forward to prove that they are the person intended... then it's de facto public domain even if that's not its status de jure. If you really want to push it in court, you can say that you met the person in-person at a conference and that they verbally told you to do anything you want with it: unless they stand up to say "that's a total lie!" there's no way of proving, because just because some code C has been licensed to a million people under the GPL, it doesn't mean it hasn't been licensed to one other person under the WTFPL.

As for how this could happen... It could be that everything suggests that they never want to come back, like the apparent disappearance from Earth of Satoshi Nakamoto; it could also be something with more stake, for example if Ross Ulbricht had gotten out of the Silk Road business and GPLed his code as the Dread Pirate Roberts before he was caught; in that hypothetical universe, nobody would want to prove that they were the DPR until some statute of limitations for running the black market had passed.

Re: More awful IoT stuff

#52
post #44

Earlier quoted context omitted.

The commercial side of building automation is robust, but the components are pricey, the platforms proprietary* and end-user aavailibility seems to be limited. The beauty of the other side is every switch, sensor & controller's first objective is not to monetize the user but rather to simply do it's intended job. Look into building automation controls and you will find what you yearn for; Siemens, Johnson Controls, H…

That's what I'm getting at though, there is clearly a market for consumer ready devices that don't cost what solutions like that do and don't need a contractor to install them. I mean you can't tell me that in today's world we couldn't manufacture an outlet with electronic control of the flow of current out of it's outlets, and do it in such a way that uses proper SSL and endpoints, without having to price it so high…

I totally agree, the demand & the means exist. However, the intent of retail providers is anything but enabling simple, automated controls. Everything is about grabbing the data cash bag and, as an afterthought, let's personalize your experience. I have been pondering this and the only conclusion I can come up with is the market controllers(more than mere "forces") have much to gain by selling the perception instead of reality and their treasure troves of patents(from commercial side) allow them to maintain this position. IMO, the digital revolution of ours has transformed sharing into one way collecting and the consumers into commodities. Both of which I find quite offensive, and sometimes, outright hostile. Alas, our money is our only true vote. Vote accordingly.

Re: More awful IoT stuff

#53
post #18

So there is a great amount of lists, blogposts and information about awful/bad IoT things, but if someone like me want to have a list about IoT things that are actually secure and well-working, where would I find that?

It's not that easy. I stick with brands/products that are reviewed by people I trust or have seemed to pick up some momentum. My general rule of thumb is I NEVER buy anything IoT that is WiFi based. Zigbee or Z-Wave based devices will save you a lot of security nightmares (though definitely not all).

It doesn't bridge directly to real IP, there will be a 'hub' somewhere. You can't talk directly to the devices from any PC or mobile on the network, which is less convenient but reduces the attack surface to just the hub.

(It's also much more power-efficient; you can't really use wifi on battery powered devices unless you charge them frequently)

Re: More awful IoT stuff

#54
post #4

>It's running Linux and includes Busybox and dnsmasq, so plenty of GPLed code. I emailed the manufacturer asking for a copy and got told that they wouldn't give it to me, which is unsurprising but still disappointing. Has the GPL really lost it's power that much? I mean not responding to inquiries is one thing, but outright saying no?

This happens a lot. The GPL remains enforcable, but just because you have a copyright doesn't mean that people will bother to comply with it.

Re: More awful IoT stuff

#55
post #6

IoT devices can be fine, but there are lots of companies involved in it that don't know what they're doing and would be better off staying out of the market. I always advice friends / family to look for upgrading capabilities, ability to do useful work when not connected to the Internet proper, user control (do you own this device or effectively borrow it per licensing etc.?), and other similar things before purchasi…

And it sounds like this one was like 80% of the way there. I mean they used encryption (badly, but they still used it), had a way to update the software on the device (even if only over http), and uses passwords (although doesn't enforce them).

So everything it does, it does badly? To me, that's not 80% of the way there, that's more like -80%.

Re: More awful IoT stuff

#56
post #18

So there is a great amount of lists, blogposts and information about awful/bad IoT things, but if someone like me want to have a list about IoT things that are actually secure and well-working, where would I find that?

It's not that easy. I stick with brands/products that are reviewed by people I trust or have seemed to pick up some momentum. My general rule of thumb is I NEVER buy anything IoT that is WiFi based. Zigbee or Z-Wave based devices will save you a lot of security nightmares (though definitely not all).

If it's not connected to the Internet, isn't that just a Network of Things?

Re: More awful IoT stuff

#57
post #12

> Eventually I plugged my phone into my laptop and ran adb logcat, and the Android debug logs told me that the app was trying to modify a network that it hadn't created. Apparently this isn't permitted as of Android 6, but the app was handling this denial by just trying again. I deleted the network from the system settings, restarted the app, and this time the app created the network record and could modify it. It st…

As a counter example, my brother who never uses a computer setup his chromecast in 5 minutes with zero help from me. I know b/c he called me and asked for help. I told him he wouldn't need it, but he didn't believe me.

Things are getting better. There will always be more crap out there than good stuff. That's why walmart is so popular, but things will generally improve.

Re: More awful IoT stuff

#58
post #55

Earlier quoted context omitted.

And it sounds like this one was like 80% of the way there. I mean they used encryption (badly, but they still used it), had a way to update the software on the device (even if only over http), and uses passwords (although doesn't enforce them).

So everything it does, it does badly? To me, that's not 80% of the way there, that's more like -80%.

Come on, the last thing he reviewed sent everything in plaintext, had no root password, called out to multiple chinese servers, ran ssh via a hardcoded password that was something like a simple word, and didn't have any way of actually updating the code on the device. Oh, and it barely even functioned as a lightbulb...

This is lightyears better than that, and yeah they fucked up a bunch of stuff, but it at least shows they tried. Even shitty AES is going to increase security over plaintext...

Re: More awful IoT stuff

#59
post #48

Earlier quoted context omitted.

Why is Z* preferable to Wifi-based?

One of the reasons would be that it isn't used that often and won't allow access to your network with commodity hardware.

Isn't this idea hiding the problem though? While using uncommon hardware and protocols may thwart certain users, it's really not solving the problem of security. It's somewhat similar to the idea of using a hidden wireless network and calling that security instead of securing your network with WPA2, etc.

As these devices become more popular, we'll start seeing more Zigbees and Z-wave devices become commodity hardware.

Re: More awful IoT stuff

#60
post #4

>It's running Linux and includes Busybox and dnsmasq, so plenty of GPLed code. I emailed the manufacturer asking for a copy and got told that they wouldn't give it to me, which is unsurprising but still disappointing. Has the GPL really lost it's power that much? I mean not responding to inquiries is one thing, but outright saying no?

Lost its power? This is just copyright apathy. Nothing new, especially in China. Look at it from the manufacturer's point of view. They know how expensive this would be to take to China and prosecute and they know they're a tiny fish. It's simply a reasoned gamble that saying no is the fastest, most efficient way to get this dealt with. Much easier than auditing the code, having the developer separate out sensitive data, etc. Well before you consider the long term archiving of this stuff. They're probably already making the next generation of this rubbish.

I dare say if this were a major manufacturer, more effort would be made to make them behave, but we're talking about a short-run switch here.

If there ever becomes a mechanism to DMCA-takedown physical products on an international level, we might see some movement here. But China (et al) would never, ever agree to that. It's hard enough to get them to block things that clearly break international safety standards.

Post reply on HN