Live data from Hacker News

The Mirai Botnet Is Proof the Security Industry Is Broken

blog.appcanary.com

101–110 of 260 posts

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#101
post #14
post #8

How about a law that requires computerized devices to be shipped with unique passwords. That would be a start. Second, any computerized device must pass FTC/FCC/UL (pick one) tests for computer security before going on sale. There's more that can be done, but let's go after the simple stuff first.

Not sure that solves the problem either, perhaps UK has more stringent laws, or perhaps the US does. But if it's not universal a sufficiently large market can still be exploited to attack another. The internet is global. We need global regulations.

Agreed. Given consensus will take forever, I'd like to see the US or EU, somebody at lest, take the lead. Over time this will probably get worked into trade agreements anyway.

But if we wait 10 years, it'll be too late, and we'll have killed the internet or given into draconian measures to stop the problem - which is what none of us want.

Frankly, I don't even care if a given government has great security review - as long as they put a process in place it's a start that can be improved upon.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#102

I wish more people would talk about the economics of why netsec is such a garbage industry. It's a few honest people screaming to be heard above the din of snake-oil salesmen, but there's an economic reason that goes beyond "dumb users, incompetent programmers and CTOs who just look and speeds and feeds". The problem is there's weak correlation, or at least very difficult-to-see correlation, between the amount of eff…

This sounds like an insurance problem. You've got events that occur rarely enough to an individual (company) that it's hard to work out what the best course of action is using the limited data that an individual can gather. If there were, say, a half dozen major security companies that everyone subscribed to one of, and they each published their statistics showing how many of their customers suffered various kinds of…

This is in theory a good track to start with. However there is one small hole in the theory. Self reporting by security companies on breaches is very tough to impose. We have seen what self regulation/reporting did for the banking industry. If security companies sidestep accurate self reporting on breaches they have no incentive (in fact they might be motivated to let things slide for economic reasons) to create rock solid security solutions because they know there is an insurance company who will absorb the hit.

However if you had an independent entity that rated the security companies' products that might work. Or the insurance company has a division that rates the security products and provided different rates based on which product a company decides to use.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#103
post #49

Earlier quoted context omitted.

That's a great point regarding the economics of why IoT manufacturers don't invest all that much on security. Here's another one. It's an externality. Botnet attacks don't harm the IoT manufacturers. They don't even harm the IoT products or their users. They harm completely innocent bystanders like DNS/github. What possible incentive do IoT manufacturers have to invest money on initiatives that bring no benefits to t…

The safety equipment on vehicles is also an externality but it's mandated because when a car is unsafe it affects other people who aren't the driver. I don't see how IoT is any different. If you don't want to secure your product, then don't build your product and save the rest of us from dealing with the fallout of your laziness.

The principle is no different, but the practice might differ significantly. With vehicle safety there's a reasonably common, agreed upon set of vehicle conditions which can be checked with a inspection; do your brake lights work, tires aren't bald, etc. There is also a framework of regulation (at the product level vehicles have to pass a set of design-level safety tests), as well as policing on actual roads to execute vehicle maintenance checks as needed.

I'm not sure we know what a similar framework would look like with consumer devices. I can see the utility, but I would also worry about regulatory overreach, and giving big brother another point of control to latch onto.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#104

I wish more people would talk about the economics of why netsec is such a garbage industry. It's a few honest people screaming to be heard above the din of snake-oil salesmen, but there's an economic reason that goes beyond "dumb users, incompetent programmers and CTOs who just look and speeds and feeds". The problem is there's weak correlation, or at least very difficult-to-see correlation, between the amount of eff…

This sounds like an insurance problem. You've got events that occur rarely enough to an individual (company) that it's hard to work out what the best course of action is using the limited data that an individual can gather. If there were, say, a half dozen major security companies that everyone subscribed to one of, and they each published their statistics showing how many of their customers suffered various kinds of…

I think a more feasible tactic would be to reverse the responsibility so that vendors that produce easily broken products ends up liable for damages unless they can show that they have done due diligence when it comes to securing the devices that they create. One way to get away from liability would then be to be vetted by a reputable security company.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#105
I have observed that "proof" should be translated as "evidence", and I generally think such article titles lead to pointless look-at-me hyperbole. Authors who fail to understand the important difference between those words will likely have nothing critically interesting to add to most discussions.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#106
As I said previously, someone needs to bring negligence suits against some IoT vendors, wholesalers, and retailers. Start with the retailers, like Amazon. They'll find the supply chain for you as they try to pass the buck. It worked with hoverboards.

There's a problem at the China end with crap low-end devices driving out the good ones. Here's a good example: solid state relays, useful little devices for safely switching AC power with a logic level signal. Look at this Fotek solid state relay on Amazon.[1] That's a counterfeit. Fake manufacturer name. Fake UL and CE marks. Here's UL's warning notice on counterfeit Fotek solid state relays, and how to recognize fakes.[2] There are lots of unhappy customers; the fake ones have been reported to overheat, melt, or stick in the ON condition. Every Fotek relay on Amazon that I can find is fake.

The fakes are real solid state relays with grossly exaggerated power ratings. For real ones, cost goes up with power. The fakes all cost about the same regardless of nameplate power rating. Here's an especially bad one: a "100 amp" version.[3] The real Fotek, in Taiwan, doesn't even make a 100 amp version in that form factor - the terminals aren't big enough for 100 amps.

The result is that nobody is selling legit solid state relays on Amazon. They exist; you can buy them through Digi-Key or Mouser. They cost about 2.5x the fake price. But Amazon has been totally conned. (The ones on eBay are fake, too.) Worse, if you're a legit solid state relay maker in China, you have a hard time selling. The counterfeits have pushed the price down too far.

Back to hoverboards. There are now UL-approved hoverboards. They don't catch fire. Heavy pressure on China suppliers worked. That needs to happen with insecure IoT devices.

[1] https://www.amazon.com/Frentaly-24V-380V-Solidstate-Arduino-... [2] http://www.ul.com/newsroom/publicnotices/ul-warns-of-solid-s... [3] https://www.amazon.com/Industrial-FOTEK-Protective-SSR-100DA...

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#107
post #96

Earlier quoted context omitted.

What "differences in traffic" do you mean exactly? Who gets to decide them - that's a political thing, no?

Traffic in general can be (roughly) summarized as application, infrastructure, and signaling. On top of this, it's clear that different address space is used by different organizations for different purposes. Classify the traffic based on these differences and carve up address space to suit the differences, and perhaps differences in the transport protocols that match the practical differences in how the traffic is u…

None of those examples are relevant to the Mirai case, though? I don't think it even relied on IP spoofing. It was just an enormous HTTP flood.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#108
On the very sub topic of "we don't know how to write secure code"; yes, we actually do.

Of course we know how to write secure code, code that meets a rigorous and well engineered design that eliminates invalid outcomes as a result. The problem is such code is slow and expensive to produce.

Good, Fast, Cheep; pick (at most) two. Security cameras optimize for Cheep first and fast second, so of course we see issues like this.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#109

This is not a failure of the security industry - the security industry is targeted at the enterprise, largely not the host of the vulnerable IoT devices involved. Don't get me wrong, there are tons of ways in which the security industry fails (the biggest IMHO is buying/selling things that only get implemented in a half-@$$ed manner or not at all), but this is like blaming the Airline industry for a train wreck. Perh…

Blaming the security industry is wrong, but so is blaiming the users. If a faulty lamp catch fire, then it is the one who made the lamp that is at fault, not the user. Make the vendors responsible for the damages that their products create!

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#110
post #15

Maybe we need liability for software vendors? With exemption for those who provide full source code.

Maybe we need liability for software vendors? That's a common suggestion, but since no-one knows how to make completely secure systems yet, I don't think it's that simple. If you're talking about a general presumption that anyone selling software that has a security vulnerability becomes liable for any consequential losses, then it seems likely to result in only large businesses with the war chest to fight a liabilit…

> That's a common suggestion, but since no-one knows how to make completely secure systems yet

We also do not know how to make completely secure cars, but still car makers are liable for faulty construction.

Post reply on HN