Live data from Hacker News

The Mirai Botnet Is Proof the Security Industry Is Broken

blog.appcanary.com

41–50 of 260 posts

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#41
post #22
post #8

How about a law that requires computerized devices to be shipped with unique passwords. That would be a start. Second, any computerized device must pass FTC/FCC/UL (pick one) tests for computer security before going on sale. There's more that can be done, but let's go after the simple stuff first.

If you want to go after the simple stuff then blocking significant outbound traffic at the ISP level from a home user account until they agree it's something they want to do is the most straightforward solution. No need to change much infrastructure, no need to test devices, and no need to have costly manufacturing processes. You could even let specific traffic through (Facebook live streaming, online gaming services…

An attack can be quite effective even if the traffic from a single home is insignificant.

I don't need ISPs to mess with my connection any more than they do already.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#42
post #32
post #18

Earlier quoted context omitted.

Toaster is required to pass safety standards because of the there is strong economic incentive (UL requirements) to do it. Without UL, it can't get on the shelf on any stores in US. There are no such thing and UL security requirements for IOT device. Time for such regulation? But "internet + regulation" normally raise a lot of objections internally from the IT industry. If someone (MSFT) proposes secure boot are requ…

> There are no such thing and UL security requirements for IOT device. UL 2900-1.

Holy cow. That's awesome! Not sure if it's a good spec, but at least UL is trying to take this on. This is probably the best approach.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#43
post #19

Completely incorrect claim, the IoT industry doesn't spend a penny on security, and therefore will be vulnerable to these type of attacks. If anything this is proof that the security industry does work, these attacks are happening on devices where there is no security budget - not on servers with large investments in security.

So, "companies think that security is unnecessary" is a sign that the security industry is working?

TBF the comparison is against a well defended server of which there is a great many examples.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#45
I suspect we've already lost at "Security Industry".

Obviously defence in depth and dedicated security tools have their place in a networked environment, but you can't just outsource the problem or fix it with some bolted on extra.

Some concerns simply have to be addressed as an integral part of whatever software or device is being made. If we don't do that, well, we've just seen the result.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#47

It's actually proof that internet architecture in general is broken. Well, not broken; it was broken, and then healed in a weird way so there's extra cartilage sticking out causing annoyances and won't move as easily anymore. The security industry has absolutely nothing to do with the existence of a botnet that can take down massive internet infrastructure. The security industry just puts bandaids on shitty products.…

How do you tell illegitimate and legitimate traffic apart?

In many cases the only difference between a DDoS and normal operation is the volume of traffic at the victim host.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#48
post #32
post #18

Earlier quoted context omitted.

Toaster is required to pass safety standards because of the there is strong economic incentive (UL requirements) to do it. Without UL, it can't get on the shelf on any stores in US. There are no such thing and UL security requirements for IOT device. Time for such regulation? But "internet + regulation" normally raise a lot of objections internally from the IT industry. If someone (MSFT) proposes secure boot are requ…

> There are no such thing and UL security requirements for IOT device. UL 2900-1.

404 for every link to the standards. Awesome!

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#49

I wish more people would talk about the economics of why netsec is such a garbage industry. It's a few honest people screaming to be heard above the din of snake-oil salesmen, but there's an economic reason that goes beyond "dumb users, incompetent programmers and CTOs who just look and speeds and feeds". The problem is there's weak correlation, or at least very difficult-to-see correlation, between the amount of eff…

That's a great point regarding the economics of why IoT manufacturers don't invest all that much on security. Here's another one. It's an externality. Botnet attacks don't harm the IoT manufacturers. They don't even harm the IoT products or their users. They harm completely innocent bystanders like DNS/github.

What possible incentive do IoT manufacturers have to invest money on initiatives that bring no benefits to themselves, or their customers? What possible incentive do users have to follow "proper security protocols", when they can just do something simple/convenient, and if something goes wrong, some random internet website pays the price.

As idiotic as this sounds, the only non-regulatory solution I can think of is for all potential BotNet victims to collectively "bribe" the IoT companies into following proper security protocols.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#50
post #19

Completely incorrect claim, the IoT industry doesn't spend a penny on security, and therefore will be vulnerable to these type of attacks. If anything this is proof that the security industry does work, these attacks are happening on devices where there is no security budget - not on servers with large investments in security.

So, "companies think that security is unnecessary" is a sign that the security industry is working?

nope it's a sign of the strong market for lemons in IT products.

There's no adequate way for consumers to differentiate between well secured products and badly secured products (every company will tell you "security is their top priority" if you ask them).

Post reply on HN