Live data from Hacker News

The Mirai Botnet Is Proof the Security Industry Is Broken

blog.appcanary.com

211–220 of 260 posts

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#211

Earlier quoted context omitted.

Given that most of the ddos attacks come from China, isn't it a reasonable assumption that the Chinese manufacturers are complicit in keeping the system broken?

Do most of the ddos attacks actually come from China? I thought they came from botnets of pwned PC's all over the world.

We're talking about who controls the ddos. Where the devices end up is different.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#212
post #125

Earlier quoted context omitted.

Ok, I am aware of how it works, but I'm not talking pentests or hardening. I'm talking simple, cheap design choices in this case, that could've eliminated the whole Mirai debauchery. In your app you already have a setup wizard, right ? Add one more page to the end "Hey, we're almost done! We just need to make sure your device is secure. Please choose a username and (strong) password." Edit: Because if you have a logi…

" Ok, I am aware of how it works, but I'm not talking pentests or hardening. I'm talking simple, cheap design choices in this case, that could've eliminated the whole Mirai debauchery." Then you are not talking about the security industry or its failure to work are you? Its a failure in the development industry to have basic security awareness. If you don't engage the security industry for pentests or consulting. You…

>Its a failure in the development industry to have basic security awareness. //

Is that really it? Surely even a high-school level developer will realise that having a device connected to the wild web with a default user:pass will be hacked easily.

I'd have thought the problem is not wanting to support customer calls saying "we changed the password and now can't access our device". So default user:pass and no prompt to change it (and a backdoor just in case) means lower support costs.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#213
Just remember how Feynman described how he was opening military safe during los alamos project (one of the most super highly sensitive project of WWII) : 25% of the safe where having default combinations.

I guess we can draw a conclusion here: security assumptions about who the users are is not in sync with human nature.

Security is failing the same way as architects would fail making the assumption stairs with one meter high steps are okay.

IT security is failing because their model of human beings is plain and flat wrong, hence, computer security as designed by our brightest mind is wrong.

Don't force feed to human requirements of fuck given they don't have.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#214
post #200
post #160

Earlier quoted context omitted.

Counterfeit component risk and bad security for an assembled IoT device are two separate issues. Sourcing components on Amazon in the first place is ludicrous to me, to be honest, and I'd be shocked if any reputable EMS companies do it. As an aside, a couple years ago I saw some guys from NXP do a talk on component counterfeiting. People will apparently remove them from dead boards, shave a few microns of material of…

"Sourcing components on Amazon in the first place is ludicrous to me, to be honest" I'm a hobbyist, I have Amazon Prime, and I would like to use components in a project. What's ludicrous about that?

The "reputable EMS companies" part was an important qualifier. But, as the guy I originally replied to demonstrates, counterfeit risk is a lot higher. I order parts for my projects from Digi-Key.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#215

Earlier quoted context omitted.

That'll work until the database of device credentials is breached from company X which provides call center support services for manufacturers A through Z and needs said credentials at hand.

Pretty much every home router sold in the UK is shipped with a unique default wifi network name and password printed on a sticker and stuck to the device. Manufacturers don't need to keep a credential database, as legitimate users can simply look at the label.

Which gives the appearance of security, but do any of those routers have backdoors or superuser accounts with defaults or have access via remote management (TR-069?) that's not properly set-up? Should we shoot so low as just to get unique passwords?

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#216

Earlier quoted context omitted.

The major flaw with that proposal is that the government has shown itself to be exceptionally incompetent (just like everyone else) when it comes to security. For example, the NSA 's security -- not some underfunded, minor agency, but the NSA itself, the world's leading cybersecurity agency -- has had its security breached on a large scale basis, multiple times. And that is just the beginning of the very long list. I…

Fair, but we are not expecting manufacturers to make bullet-proof devices. We are expecting them to make devices that do not let you achieve root access over the internet using an unchanged username and password combination. That's a very easy and specific thing to regulate.

But they pretty much do have to be bulletproof. Every single device connected to the Internet now effectively has a fully automated machine gun firing at it all the time. One gap in the armor is all it takes.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#217
post #49

I wish more people would talk about the economics of why netsec is such a garbage industry. It's a few honest people screaming to be heard above the din of snake-oil salesmen, but there's an economic reason that goes beyond "dumb users, incompetent programmers and CTOs who just look and speeds and feeds". The problem is there's weak correlation, or at least very difficult-to-see correlation, between the amount of eff…

That's a great point regarding the economics of why IoT manufacturers don't invest all that much on security. Here's another one. It's an externality. Botnet attacks don't harm the IoT manufacturers. They don't even harm the IoT products or their users. They harm completely innocent bystanders like DNS/github. What possible incentive do IoT manufacturers have to invest money on initiatives that bring no benefits to t…

If ISPs turned off your connection if it was found that something on your network is part of an active attack of a botnet until the problem is cleaned up. Now the 'victim' (I'd not really say victim because they chose the cheapest webcam online) has to figure out (or hire somebody to) clean up their network.

If there are actual consequences for people's computers and IoT devices being 'hacked', they will start to look for ways to avoid the inconvenience in the future. They might start using better passwords, not installing every toolbar under the sun, demand better products (and accountability) from the companies they purchase items from.

tl;dr;

The only way to get some of these problems fixed is to introduce some level of pain, somewhere in the system. I say penalize the consumer who decided to buy the cheapest thing online - turn off their Internet connection when an infected device is found.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#218

As I said previously, someone needs to bring negligence suits against some IoT vendors, wholesalers, and retailers. Start with the retailers, like Amazon. They'll find the supply chain for you as they try to pass the buck. It worked with hoverboards. There's a problem at the China end with crap low-end devices driving out the good ones. Here's a good example: solid state relays, useful little devices for safely switc…

A Nashville, TN, family are suing Amazon for $30 million following a hoverboard fire which destroyed their $1m home.

http://www.wtsp.com/money/family-sues-amazon-after-hoverboar...

The control points are rapidly becoming retail and payment systems. Suing Amazon, Walmart, Visa, MasterCard, Paypal, etc., for facilitating the commerce of counterfeit and manifestly harmful products seems to be the logical evolution.

Re: The Mirai Botnet Is Proof the Security Industry Is Broken

#220

The free market has decided security of IoT doesn't matter.

Markets consistently under-assess complexity, in both value and const components.

Simple systems are easy to assess and communicate. Complex systems are hard (expensive) to assess and communicate. This results in several asymmetries:

1. Complex systems are communicated in an oversimplified mode.

2. Asymmetries exist between buyers and sellers of products (Akerloff's "Market for Lemons".

3. Asymmetries exist for all parties over time in realising the long-term costs (or benefits) of systems. In the most pathological instance, a party (or parties) actively frustrate the process of widespread awareness of these costs -- lead, asbestos, tobacco, sugar, CO2, etc., etc.

Corollary: security is a complex product.

Post reply on HN