Live data from Hacker News

The Mirai Botnet Is Proof the Security Industry Is Broken

blog.appcanary.com

131–140 of 260 posts

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#131

Earlier quoted context omitted.

The safety equipment on vehicles is also an externality but it's mandated because when a car is unsafe it affects other people who aren't the driver. I don't see how IoT is any different. If you don't want to secure your product, then don't build your product and save the rest of us from dealing with the fallout of your laziness.

The principle is no different, but the practice might differ significantly. With vehicle safety there's a reasonably common, agreed upon set of vehicle conditions which can be checked with a inspection; do your brake lights work, tires aren't bald, etc. There is also a framework of regulation (at the product level vehicles have to pass a set of design-level safety tests), as well as policing on actual roads to execut…

I feel that in the age of technological achievements we currently live in, figuring out a way where we can require a certain level of security on these devices without running afoul of "big brother" syndrome seems well within the realm of possibilities.

It's also worth noting had the IoT companies simply done the baseline level of security of making the user change the password that such regulation wouldn't even be needed, so forgive me if I'm unable to care about their stake in things.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#132

I wish more people would talk about the economics of why netsec is such a garbage industry. It's a few honest people screaming to be heard above the din of snake-oil salesmen, but there's an economic reason that goes beyond "dumb users, incompetent programmers and CTOs who just look and speeds and feeds". The problem is there's weak correlation, or at least very difficult-to-see correlation, between the amount of eff…

This sounds like an insurance problem. You've got events that occur rarely enough to an individual (company) that it's hard to work out what the best course of action is using the limited data that an individual can gather. If there were, say, a half dozen major security companies that everyone subscribed to one of, and they each published their statistics showing how many of their customers suffered various kinds of…

If the incidents were isolated, then I could see this working. In the case of the recent DNS blackout, that took out everyone. Wouldn't that bankrupt the insurance co?

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#133
post #91
post #40

Earlier quoted context omitted.

UL isn't a regulatory body. UL testing is voluntary. You may know this, but perhaps many others don't. I think a UL for internet connected devices is a fantastic idea. Just need to figure out how to get companies to volunteer for such testing. The way it works for UL is that they provide some insulation from litigation. Perhaps if users could litigate IOT manufacturers for inadequate security testing, something simil…

Retailers (Walmart) require UL for insurance propose. UL is created for by Insurance companies to gauge the safety of the products. At the end, the real cause is "The force of Lawyers" is strong for product safety in US. :-) "The force of the lawyers for IOT" is still weak. :-) The force of the Jedi (IT, hackers, SW Dev, EFF, OSF) still strong, for now.... The Empire will win when and if enough Jedi (SW Dev) turn to…

idk, seeing a comparison with UL gives me hope that consumer device security doesn't actually have to mean totalitarian dystopia.

Nothing is stopping anyone from building their own non-UL electronic devices, and even distributing them to tinkerers and early adopters. This is much preferable to some steep liability/mandatory insurance regime like automobiles where you've got to Soviet-style register your car and even yourself!

Sensationalists push a panicked narrative about insecure devices, but any disruption of third parties is entirely due to scale. Simply making it so the enormous group of low-effort consumers won't end up with negligently insecure devices would basically erase the problem.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#134

Earlier quoted context omitted.

The principle is no different, but the practice might differ significantly. With vehicle safety there's a reasonably common, agreed upon set of vehicle conditions which can be checked with a inspection; do your brake lights work, tires aren't bald, etc. There is also a framework of regulation (at the product level vehicles have to pass a set of design-level safety tests), as well as policing on actual roads to execut…

I feel that in the age of technological achievements we currently live in, figuring out a way where we can require a certain level of security on these devices without running afoul of "big brother" syndrome seems well within the realm of possibilities. It's also worth noting had the IoT companies simply done the baseline level of security of making the user change the password that such regulation wouldn't even be n…

My point is that it's not a technical problem. Some IoT devices have failed their "vehicle safety check". Now who has the authority to take them off the road? Who has the authority to ensure that their poor design isn't even allowed on the road? Do we actually want anyone to hold that authority?

Is there some other way to achieve the same results without formal regulations - to review bad designs and keep them from being sold, and taking bad security designs/implementations off the internet?

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#135
Apparently the author of Mirai leaked the source code and even provided comments and build instructions. I found this a bit baffling.

He seems immature and vain, because his motive is apparently to taunt someone with how smart he is, but the code is indeed pretty awesome and educational. It's a little sad that commercial software is so ugly and that black hat software is elegant (though I guess it has to be, because it's under rather severe "environmental pressures").

https://github.com/jgamblin/Mirai-Source-Code/blob/master/Fo...

At first, I was also kinda shocked that it had this simplistic list of hard-coded user names and passwords (mentioned in the article). But I guess I've worked in the software industry long enough that it makes sense. Computers are so ubiquitous and on reflection it's not a surprise that you can pull down hundreds of thousands of machines with this technique!!!

Can anyone shed light on the economics of releasing source code? I would think this would make your botnet much less valuable. Apparently someone found a vulnerability in his HTTP parser, which I don't think would have happened without the source code.

So did the author shoot himself in the foot for reasons of pride, or is there something else going on?

https://github.com/jgamblin/Mirai-Source-Code/blob/master/mi...

    // Set up passwords
    add_auth_entry("\x50\x4D\x4D\x56", "\x5A\x41\x11\x17\x13\x13", 10);                     // root     xc3511
    add_auth_entry("\x50\x4D\x4D\x56", "\x54\x4B\x58\x5A\x54", 9);                          // root     vizxv
  ...

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#136
post #22
post #8

How about a law that requires computerized devices to be shipped with unique passwords. That would be a start. Second, any computerized device must pass FTC/FCC/UL (pick one) tests for computer security before going on sale. There's more that can be done, but let's go after the simple stuff first.

If you want to go after the simple stuff then blocking significant outbound traffic at the ISP level from a home user account until they agree it's something they want to do is the most straightforward solution. No need to change much infrastructure, no need to test devices, and no need to have costly manufacturing processes. You could even let specific traffic through (Facebook live streaming, online gaming services…

Almost, it would be a better idea to block incoming telnet traffic. I am having trouble coming up with a good reason for having telnet open to the internet.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#137
post #123
post #17

Earlier quoted context omitted.

But when you tell someone "That's not secure, you can easily get hacked. You need to [insert good security practices here]", what response do you get ? In my experience, most answer along the lines of "So what ? What could they get ? I have nothing important." or "Why would anyone ever hack me ?" or "But I have an antivirus, doesn't that make me safe ?". And then spend the next 15 minutes explaining to them how thing…

I think it's just a general misunderstanding of what privacy means. I've explained several times and even convinced a few people that just because they think they have nothing to hide, they generally do have something they don't want someone to know about or see. At best they will just revert back to the "I have nothing to hide" mentality after a week. I think people outside of tech just don't see how damaging it can…

You implement security in order to have privacy and I agree it's poorly understood in the digital realm, mostly because it's "out of sight and out of mind". I like to use an analogy I can't remember where I picked up and reductio ad absurdum to get them past this automatic response, because that's what it is and it's based in the horrid and dangerous "Nothing to hide, nothing to fear" saying.

- The usual conversation - I ask them: "Do you have curtains ?" and they say: "Yes, of course" and I ask "Why ? I mean you have nothing to hide right ? What does it matter if someone can see what you are doing inside your house ?", usually they freeze for a second, "Because it's creepy". I continue "Well if it's creepy that someone would watch you in your house, isn't it just as creepy if they watched you online, what you read, what porn you watch, what you talk to your friends about ? Which do you think tells more about who you are ?". At this point silence and an increasingly worried look is the norm. I keep going: "It's not about hiding anything, it's about what is private. Otherwise why not tell everyone your darkest secret, your greatest fears, the thing you are most ashamed of doing in your life ? And that's why you should do [this or that]"

But even so, it's true most default back quickly. Still a few call, ask, improve their practices. People only seem to take it seriously after they have been directly impacted in a powerfully damaging way.

Edit: I have obviously had this conversation enough times to make this script in dealing with it. If you have to do it more than twice, automate it. :)

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#138
Maybe someone with a public level of accountability--say the government--should start an adversarial inspection and certification program. Think about how we don't let cars on public roads unless they pass inspection, to verify that they aren't a ticking time-bomb in the middle of the highway--or no more so than usual.

Unlike vehicle registration, it wouldn't require you to have to do anything other than keep your system maintained. If you want to put your computer on the internet, be prepared to get port-scanned by the US Digital Service once a year/month/week/whatever, attempting to take your computer off the 'net. If it succeeds, then that's one machine that could have been--but now won't be--part of a botnet.

ChoasMonkey as a public works project.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#139
post #122

Earlier quoted context omitted.

For the sake of argument, why don't they deserve what happens to them? Most people don't understand how their car works. But if you own a car and you neglect to change the oil for 50k miles, or you put diesel into your tank and ruin your car, we don't blame the automotive industry for not informing you on proper maintenance. Just like with computers, the information is out there, and it's not the job of the automaker…

However, if it is a very wide spread problem then they will eventually install a light on your dash to notify you to change your oil. My wife's car currently does this. Since this is the first car she's ever owned, it's good because I don't think she would have known. We also have check engine lights and indicators for when a turn signal light bulb stops working. New cars even keep track of things like tire pressure.…

> However, if it is a very wide spread problem then they will eventually install a light on your dash to notify you to change your oil. My wife's car currently does this. Since this is the first car she's ever owned, it's good because I don't think she would have known. We also have check engine lights and indicators for when a turn signal light bulb stops working. New cars even keep track of things like tire pressure.

This is getting off subject, but I'm of the opinion that this trend is primarily motivated by locking people into a dealer for maintenance, not helping people maintain their vehicles. For example, I think BMW dealers are the only ones who have the ability to calibrate tire pressure sensors on bimmers, and some new cars are abandoning OBD-II ports.

http://www.roadandtrack.com/car-culture/a30505/new-car-servi...

> My argument is in the similar vein of those who aren't physically fit to win a fist fight. Doesn't mean they deserve to pushed around, robbed or beaten just because I'm stronger and a better fighter.

I don't think it's fair to compare these things. Of course no one deserves to be assaulted. And likewise, if someone sabotages your car or has a remote exploit for your computer, I find it hard to dish out blame. But beyond this, I think the only person who could possibly be responsible for the condition of their possessions is the owner, and I don't see why computers should be any different. Not knowing better or being too busy is not an excuse to be a party to a DDoS attack.

You bought this computer, you plugged it in, and it was setup in a way where it was able to receive signals that made it send out signals that violate the contract you signed with your ISP and violate the laws that your representatives passed. "I didn't know" isn't an excuse in any other comparable situation. Just because computers are hard doesn't mean we should rework our entire legal framework. We shouldn't codify into law the idea that some subjects are obvious and should be enforced consistently, while some are beyond understanding (for most, for now), and ignorance is a viable excuse. It will inevitably become outdated.

I'm held responsible if I have an old car rusting away in my backyard and it pollutes my neighbors well-water. And sure, it's harder to claim ignorance about a rusty car than it is to claim ignorance about a misconfigured computer, but I think the law has to be impartial about that.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#140
post #135

Apparently the author of Mirai leaked the source code and even provided comments and build instructions. I found this a bit baffling. He seems immature and vain, because his motive is apparently to taunt someone with how smart he is, but the code is indeed pretty awesome and educational. It's a little sad that commercial software is so ugly and that black hat software is elegant (though I guess it has to be, because…

The best theory I've heard about the authors motivations is that after knocking Krebs offline, with a world record dos, they wanted to muddy the waters a little.

By releasing the source code and letting everyone else fight for control of the botnet, it would be much harder for anyone to trace the original attack back to them.

Post reply on HN