Earlier quoted context omitted.
Bad actors are already trying to get that data, no?
Yes, but what does that have to do with the structure of a bounty?
Any better ideas of how to structure a bounty to get bugs and not confused users?
201–210 of 260 posts
Earlier quoted context omitted.
Bad actors are already trying to get that data, no?
Yes, but what does that have to do with the structure of a bounty?
Any better ideas of how to structure a bounty to get bugs and not confused users?
Earlier quoted context omitted.
Isn't the goal of security to remove the lowest hanging fruit and keep at it?
In one sense, sure. But IMO regulating the IoT "industry" in a general way is a bad idea because it will just shift the low hanging fruit around some, while ultimately stifiling innovation, which is what is needed for any deep, meaningful security to happen in the long term .
The blame for this debacle falls squarely on the heads of the vendors who produced these trusting (if not downright gullible) devices in the first place.
Earlier quoted context omitted.
Bad actors are already trying to get that data, no?
Yes, but what does that have to do with the structure of a bounty?
Earlier quoted context omitted.
> When I was your age I was leaving the security industry before it was cool I'm not interested in leaving the security industry. I'd rather work to change it. I'm a millennial, I guess :) > The "security industry" is not in fact chartered with stopping things like Mirai. So Mirai is a weird complaint to level at it. No one "chartered" the industry to do anything. You're right, a metal box or an AV isn't going to pre…
No? I am having a hard time seeing any intersection between either of the major two branches of the security industry (PC security and network security) and IoT botnets. There's a major failure happening, but it's not attributable to the security industry. It's a failure of the computing industry as a whole.
That doesn't try to stop IoT botnets; it just extracts rent for keeping some people safe from them.
My toaster has to be certified that it meets certain minimum safety standards. It really seems that IoT and safety critical software/firmware should be required to pass a similar (bare minimum) certification.
Toaster is required to pass safety standards because of the there is strong economic incentive (UL requirements) to do it. Without UL, it can't get on the shelf on any stores in US. There are no such thing and UL security requirements for IOT device. Time for such regulation? But "internet + regulation" normally raise a lot of objections internally from the IT industry. If someone (MSFT) proposes secure boot are requ…
Rightfully so. Anyone who argues signing without user override is necessary to achieve devices secure against external attackers is outright lying.
As I said previously, someone needs to bring negligence suits against some IoT vendors, wholesalers, and retailers. Start with the retailers, like Amazon. They'll find the supply chain for you as they try to pass the buck. It worked with hoverboards. There's a problem at the China end with crap low-end devices driving out the good ones. Here's a good example: solid state relays, useful little devices for safely switc…
I don't follow your comment. I'm not sure how you can claim that Solid state relay is fake. Also poor security practices in IoT devices and counterfeits sounds like 2 completely different topics. Let me play the devil's advocate: How can you be sure [1] is fake? To me the picture looks like the real one reported in [2]. It is also 2.5x the price of the fake one reported in [2]. You also say there are lots of unhappy…
That is the connection between the two topics. You go on Amazon and no one is selling quality. A lawsuit would kill the crap products and you are left with the certified / branded / or otherwise 'proven' good products.
Earlier quoted context omitted.
> You could have no security and just get lucky and never get hacked. It's been a decade and more since that was even remotely true (if it ever was). Back in 2008 the average survival time of an unpatched internet facing XP box was around 4 minutes [0]. Pwning an unpatched XP box was (very marginally) harder than pwning a system with no security at all. The Morris worm (Edit: which is heavily mentioned in TFA, my bad…
>>Back in 2008 the average survival time of an unpatched internet facing XP box was around 4 minutes [0]. Yep. And that's just the average. It was much, much lower for high-value targets, such as universities. The first thing we did at my Network Security class back in 2006 was to hook up an unpatched XP machine to the Internet. It got pwned in about 30 seconds.
Wouldn't multiple attackers have to be effectively flooding the network with pings or service/port access attempts to find a new computer so fast?
As I said previously, someone needs to bring negligence suits against some IoT vendors, wholesalers, and retailers. Start with the retailers, like Amazon. They'll find the supply chain for you as they try to pass the buck. It worked with hoverboards. There's a problem at the China end with crap low-end devices driving out the good ones. Here's a good example: solid state relays, useful little devices for safely switc…
As I said previously, someone needs to bring negligence suits against some IoT vendors, wholesalers, and retailers. Start with the retailers, like Amazon. They'll find the supply chain for you as they try to pass the buck. It worked with hoverboards. There's a problem at the China end with crap low-end devices driving out the good ones. Here's a good example: solid state relays, useful little devices for safely switc…
Given that most of the ddos attacks come from China, isn't it a reasonable assumption that the Chinese manufacturers are complicit in keeping the system broken?