Live data from Hacker News

The Internet of Onions

lwn.net

21–30 of 38 posts

Re: The Internet of Onions

#21
I'm actually working on something based on this idea - I've created a SIM card for the Internet of Things - basically a smartcard (microSD form factor) that offers a persistent crypto-secure identity for Internet-connected objects.

It works by holding the TOR hidden service private key inside a tamper-resistant smartcard and generating/signing hidden service descriptors with it (plus an entire mechanism to prevent you from signing future descriptors - meaning that the identity is closely tied to the physical SIM card, just like in the GSM world - whoever has the SIM has the identity, once you've removed the SIM the identity goes with it).

Discussion at https://lists.torproject.org/pipermail/tor-dev/2016-June/011... - I've made progress since that post, it's now fully operational and tested, just need to figure out a way to turn it into a product and get some funding for it.

Re: The Internet of Onions

#22

Earlier quoted context omitted.

Cars are also relatively expensive. iot products seem more in the disposable and non-essential space. You can always just throw it away without much inconvenience, so why put a lot of effort into the purchase process? Heck people don't even seem to care much about cell phones and keeping them up to date (iPhone and Nexus aside). And cell phones are far more important than lights etc. As for the last paragraph, perhap…

"Underwriters Laboratory" for devices is such a good idea. This is a world I want to live in. I can imagine warnings like "mothership required", "Uses personal information", etc.

UL plans to certify IoT devices, http://www.computerworld.com/article/3051147/internet-of-thi...

Re: The Internet of Onions

#23
post #11

Earlier quoted context omitted.

> Customers aren't witholding money from products I think part of the problem here is that everything is so new, relatively speaking, that almost no company can actually trade on their reputation. If today a company was able to advertise on having sold internet connected devices for a decade and their earlier devices still worked well in some manner, then people might actually use that in their purchase criteria. Who…

> A REST endpoint that supports a few well defined routes for discovery of routes and descriptions of them, as well as a route to return the entire configuration for backup, might work better We called that SNMP. Unfortunately, it was embraced and extended to death. It wasn't a bad idea though. The trick is, how do you get everyone to play fair, when there's incentive not to?

By making the ecosystem useful enough that the benefits of doing it your own way are often outweighed by the benefits of being conformant to a standard. If I have a nice dashboard to ties together all the items in my house, giving me easy access to them all, nice status info at a glance, and summaries of usage and/or problems, any device I want to buy that doesn't tie into that nicely is going to really have to justify its existence through some really nice features.

As for who would buy into a system like this initially? Lots of Asian manufacturers that aren't interesting in being software companies, and would rather give you some standard firmware that you can tie into some other management console or replace with what you want.

Re: The Internet of Onions

#24
post #16

Earlier quoted context omitted.

> Heck people don't even seem to care much about cell phones and keeping them up to date (iPhone and Nexus aside). I think that's inherently a feature of them being too closely linked with the companies that provide them. Phones are the extreme case of what IoT devices could become. Once the phone OS is no longer supported by provider, keeping it is both a liability, and increasingly problematic as things stop workin…

Note that certification could also include verifying there is a plan in place for whatever period of support is reasonable. (We could dig deeper on this.) Configuration options are hard to support. Say for example a "power level" setting is exposed (how much power is consumed to provide the device functionality). But it is also the case that more power shortens the lifespan of the device. A general client can end up…

I think any certification that requires a plan be in place for future support is going to be either too weak (if the company goes under, support is gone) or too burdensome (requiring some trust be in place for future support should the company go under is very inefficient). Just allow more control by the user. This lowers barriers to entry for the market, and allows for interesting and unique future uses.

As for non-standard methods of configuration and support, I see no problem with requiring your own software if you want it to be supported, and requiring it be set to default levels (or a verification that no values are outside norms) before a support incident is allowed. You want to permanently log whether any settings have been set that void your warranty? Go ahead. This is a solved problem. Try to get Apple to fix your phone if the little water sensor inside has been tripped.

I see no problem certifying hardware, I'm just not sure how something like UL for software works in practice.

Re: The Internet of Onions

#25
post #11

Earlier quoted context omitted.

What do you propose manufacturers do? (This is a serious question.) Customers aren't witholding money from products, so there isn't much in the way of economic incentives. Having and supporting open protocols is more work than internal only. Often times the mothership is using other products to provide the service which are proprietary and paid for, so nothing is free (as in beer) or free (as in speech). "Do more wor…

> Customers aren't witholding money from products I think part of the problem here is that everything is so new, relatively speaking, that almost no company can actually trade on their reputation. If today a company was able to advertise on having sold internet connected devices for a decade and their earlier devices still worked well in some manner, then people might actually use that in their purchase criteria. Who…

> Similarly, a standard for how to change settings for devices would be useful.

I wonder if OPC UA could serve this role. It's something I only discovered recently due to a work project, but it seems pretty relevant to IoT and also is used in the industry (as in, industrial industry, not the shiny startup cloud party).

Re: The Internet of Onions

#26
post #10
post #6

Earlier quoted context omitted.

Supporting Tor is a niche thing, but... it would be very very helpful if everything in the IoT could be persuaded to go through a customer-controlled local gateway, which could proxy, rate-limit, redirect, and firewall connections according to the owner's policy. Every device that reaches back to the mothership with a proprietary protocol is another device which gets discarded when the mothership loses interest in su…

I'm not sure what you mean by "persuaded", since unless the IoT device has its own cellular connection, it can't prevent being passed through a consumer-controlled device. Do you have such a device right now that is being bypassed? Because if the answer is no, that's your real problem.

The problem with IoT is that the 'I' expands to "Internet" instead of "Intranet". A device should not be rendered useless because it can't connect to manufacturer's servers. The cloud is a good value-add option, but should not be considered a primary and required element.

The other thing is that most of those devices are gimmicks, toys - a good device intended to be useful should embrace interoperability - devices working alone have only a fraction the of potential of devices working together[0].

As for bypassing your device, at some point a "clever" entrepreneur will discover SSL and certificate pinning, and then you'll be SOL.

[0] - that's why e.g. I recently shelled out and got myself Hues. It's not the cheapest option, but it's reliable, works perfectly well over LAN, has a decent API exposing pretty much all possible functionality and then some over said LAN, no cloud registration or other bullshit. Also I kind of trust Phillips not to burn my house down with crappy manufacturing.

Re: The Internet of Onions

#27
post #23

Earlier quoted context omitted.

> A REST endpoint that supports a few well defined routes for discovery of routes and descriptions of them, as well as a route to return the entire configuration for backup, might work better We called that SNMP. Unfortunately, it was embraced and extended to death. It wasn't a bad idea though. The trick is, how do you get everyone to play fair, when there's incentive not to?

By making the ecosystem useful enough that the benefits of doing it your own way are often outweighed by the benefits of being conformant to a standard. If I have a nice dashboard to ties together all the items in my house, giving me easy access to them all, nice status info at a glance, and summaries of usage and/or problems, any device I want to buy that doesn't tie into that nicely is going to really have to justi…

I'm with you all the way. That is the world I want to live in as well.

I simply think the real it turns out somewhat different. Sadly.

Re: The Internet of Onions

#28
post #6
post #2

I work for a large IoT PaaS provider. Would this be valuable for customers on our platform if we supported something like this? I'm trying to think through all the problems with this and while I think the redesign of our platform will actually make this harder, there's no reason it wouldn't be possible . I also don't really understand how Tor works. Does this break anything like persistent connections or letting scre…

Supporting Tor is a niche thing, but... it would be very very helpful if everything in the IoT could be persuaded to go through a customer-controlled local gateway, which could proxy, rate-limit, redirect, and firewall connections according to the owner's policy. Every device that reaches back to the mothership with a proprietary protocol is another device which gets discarded when the mothership loses interest in su…

> but... it would be very very helpful if everything in the IoT could be persuaded to go through a customer-controlled local gateway, which could proxy, rate-limit, redirect, and firewall connections according to the owner's policy.

They all already do? What IoT devices supply their own internet connection?

Re: The Internet of Onions

#29
post #21

I'm actually working on something based on this idea - I've created a SIM card for the Internet of Things - basically a smartcard (microSD form factor) that offers a persistent crypto-secure identity for Internet-connected objects. It works by holding the TOR hidden service private key inside a tamper-resistant smartcard and generating/signing hidden service descriptors with it (plus an entire mechanism to prevent yo…

I'm working on something that may be a complement to this. My email is in my profile if you want to chat.

Re: The Internet of Onions

#30
post #5

Off topic ish, am I supposed to be able to read this without a subscription?

Yes, LWN has a feature that lets subscribers share a subscriber-only article with non-subscribers. I think there should be a message on the page along the lines of "A subscriber has made this available to you, would you like to subscribe?"

There is a message to that effect when non-subscribers read a sublinked article like this. Sometimes with a trial offer. The occasional (occasional!) posting of subscriber links is, I think, one of the best marketing tools we have.
Post reply on HN