Live data from Hacker News

The Mirai Botnet Is Proof the Security Industry Is Broken

blog.appcanary.com

191–200 of 260 posts

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#191

Earlier quoted context omitted.

> Sure, as a customer I could insist on my manufacturer having taken security seriously and having their products thoroughly tested and reviewed and hardened and patchable and all that good stuff How exactly would you insist on that? Ask them? Aren't they going to tell you, "Yes, it's very secure, no worries"?

> How exactly would you insist on that? How about "show me three different independent security audits by researchers or firms I trust who didn't find major issues in your product"? Sure, there needs to be a sizable group of people demanding that (and be willing to have it be the difference between a $500 and a $5K smart TV), but it is possible. For corporate IoT in certain settings, it might even be plausible.

You're going to need either hard regulation, or liability for such breaches to change behaviour.

Mostly because, as Mirai shows, the costs are external to the consumer of the broken device.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#192
post #40
post #18

Earlier quoted context omitted.

Toaster is required to pass safety standards because of the there is strong economic incentive (UL requirements) to do it. Without UL, it can't get on the shelf on any stores in US. There are no such thing and UL security requirements for IOT device. Time for such regulation? But "internet + regulation" normally raise a lot of objections internally from the IT industry. If someone (MSFT) proposes secure boot are requ…

UL isn't a regulatory body. UL testing is voluntary. You may know this, but perhaps many others don't. I think a UL for internet connected devices is a fantastic idea. Just need to figure out how to get companies to volunteer for such testing. The way it works for UL is that they provide some insulation from litigation. Perhaps if users could litigate IOT manufacturers for inadequate security testing, something simil…

I am not sure, but it might be that it is difficult to gain 'standing' in a civil suit.

It is really hard to show you were directly hurt, and even harder to show whom by.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#193
The way i see it is that we are using general purpose computers to do the job of single purpose electronics.

But a GPC will always remain a GPC, and thus they are susceptible to being re-purposed no matter the number of "safeguards" we put in place to prevent it.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#194
This could be fixed by legalizing purely destructive hacking of IoT devices. To gain immunity from prosecution the hacker would need to demonstrate that the device is completely bricked and no remote access is possible. IoT manufacturers would then be able to post bounties for destruction of competitor's products and the free market would solve the problem very quickly.

This will result in harm to third parties who did not act maliciously, but that's already happening now. With this change in law the total harm will probably be less because the problem will be solved for real, which will dramatically reduce or eliminate the possibility of "black swan" events causing very serious harm (eg. shutdown of critical infrastructure).

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#195
post #184

Earlier quoted context omitted.

With IoT, this may catch the low hanging fruit, sure. Negligence for poor defaults, fine? But then attackers will just evolve to the next lowest fruit. Keep in mind that to some attackers, finding a software or hardware bug to exploit (and weaponising that), even in highly "secure" systems, is probably just a step or two beyond playing with default credential lists. The author of this article compares the complexity…

Isn't the goal of security to remove the lowest hanging fruit and keep at it?

In one sense, sure. But IMO regulating the IoT "industry" in a general way is a bad idea because it will just shift the low hanging fruit around some, while ultimately stifiling innovation, which is what is needed for any deep, meaningful security to happen in the long term .

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#196
post #194

This could be fixed by legalizing purely destructive hacking of IoT devices. To gain immunity from prosecution the hacker would need to demonstrate that the device is completely bricked and no remote access is possible. IoT manufacturers would then be able to post bounties for destruction of competitor's products and the free market would solve the problem very quickly. This will result in harm to third parties who d…

"As long as the thief drives my car straight into the ocean, it's ok for him to take it"

I'm glad you're thinking outside the box, but that kind of "immunity", if it were ever to be authorized in an emergency (attacks on power grids lasting hours or days), it should only be carried out by the government with a warrant, and with the understanding that people may die or lose property due to the sudden, public destruction of millions of devices.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#197
post #194

This could be fixed by legalizing purely destructive hacking of IoT devices. To gain immunity from prosecution the hacker would need to demonstrate that the device is completely bricked and no remote access is possible. IoT manufacturers would then be able to post bounties for destruction of competitor's products and the free market would solve the problem very quickly. This will result in harm to third parties who d…

"As long as the thief drives my car straight into the ocean, it's ok for him to take it" I'm glad you're thinking outside the box, but that kind of "immunity", if it were ever to be authorized in an emergency (attacks on power grids lasting hours or days), it should only be carried out by the government with a warrant, and with the understanding that people may die or lose property due to the sudden, public destructi…

If you wait for that emergency then it's already too late, because any attacker competent enough to carry out that attack is likely competent enough to close the vulnerability they used to get access.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#198

Earlier quoted context omitted.

This sounds like an insurance problem. You've got events that occur rarely enough to an individual (company) that it's hard to work out what the best course of action is using the limited data that an individual can gather. If there were, say, a half dozen major security companies that everyone subscribed to one of, and they each published their statistics showing how many of their customers suffered various kinds of…

If the incidents were isolated, then I could see this working. In the case of the recent DNS blackout, that took out everyone. Wouldn't that bankrupt the insurance co?

Good insurance companies do not go bankrupt because they measure risk correctly and do not take too much of it on themselves. Essentially it is their job to distribute the risk such that the company remains profitable. A global reaching event would simply be uninsurable.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#200
post #160

As I said previously, someone needs to bring negligence suits against some IoT vendors, wholesalers, and retailers. Start with the retailers, like Amazon. They'll find the supply chain for you as they try to pass the buck. It worked with hoverboards. There's a problem at the China end with crap low-end devices driving out the good ones. Here's a good example: solid state relays, useful little devices for safely switc…

Counterfeit component risk and bad security for an assembled IoT device are two separate issues. Sourcing components on Amazon in the first place is ludicrous to me, to be honest, and I'd be shocked if any reputable EMS companies do it. As an aside, a couple years ago I saw some guys from NXP do a talk on component counterfeiting. People will apparently remove them from dead boards, shave a few microns of material of…

"Sourcing components on Amazon in the first place is ludicrous to me, to be honest"

I'm a hobbyist, I have Amazon Prime, and I would like to use components in a project. What's ludicrous about that?

Post reply on HN