Earlier quoted context omitted.
Given that most of the ddos attacks come from China, isn't it a reasonable assumption that the Chinese manufacturers are complicit in keeping the system broken?
Do most of the ddos attacks actually come from China? I thought they came from botnets of pwned PC's all over the world.
The Mirai Botnet Is Proof the Security Industry Is Broken
211–220 of 260 posts
Re: The Mirai Botnet Is Proof the Security Industry Is Broken
#212Earlier quoted context omitted.
Ok, I am aware of how it works, but I'm not talking pentests or hardening. I'm talking simple, cheap design choices in this case, that could've eliminated the whole Mirai debauchery. In your app you already have a setup wizard, right ? Add one more page to the end "Hey, we're almost done! We just need to make sure your device is secure. Please choose a username and (strong) password." Edit: Because if you have a logi…
" Ok, I am aware of how it works, but I'm not talking pentests or hardening. I'm talking simple, cheap design choices in this case, that could've eliminated the whole Mirai debauchery." Then you are not talking about the security industry or its failure to work are you? Its a failure in the development industry to have basic security awareness. If you don't engage the security industry for pentests or consulting. You…
Is that really it? Surely even a high-school level developer will realise that having a device connected to the wild web with a default user:pass will be hacked easily.
I'd have thought the problem is not wanting to support customer calls saying "we changed the password and now can't access our device". So default user:pass and no prompt to change it (and a backdoor just in case) means lower support costs.
Re: The Mirai Botnet Is Proof the Security Industry Is Broken
#213I guess we can draw a conclusion here: security assumptions about who the users are is not in sync with human nature.
Security is failing the same way as architects would fail making the assumption stairs with one meter high steps are okay.
IT security is failing because their model of human beings is plain and flat wrong, hence, computer security as designed by our brightest mind is wrong.
Don't force feed to human requirements of fuck given they don't have.
Re: The Mirai Botnet Is Proof the Security Industry Is Broken
#214Earlier quoted context omitted.
Counterfeit component risk and bad security for an assembled IoT device are two separate issues. Sourcing components on Amazon in the first place is ludicrous to me, to be honest, and I'd be shocked if any reputable EMS companies do it. As an aside, a couple years ago I saw some guys from NXP do a talk on component counterfeiting. People will apparently remove them from dead boards, shave a few microns of material of…
"Sourcing components on Amazon in the first place is ludicrous to me, to be honest" I'm a hobbyist, I have Amazon Prime, and I would like to use components in a project. What's ludicrous about that?
Re: The Mirai Botnet Is Proof the Security Industry Is Broken
#215Earlier quoted context omitted.
That'll work until the database of device credentials is breached from company X which provides call center support services for manufacturers A through Z and needs said credentials at hand.
Pretty much every home router sold in the UK is shipped with a unique default wifi network name and password printed on a sticker and stuck to the device. Manufacturers don't need to keep a credential database, as legitimate users can simply look at the label.
Re: The Mirai Botnet Is Proof the Security Industry Is Broken
#216Earlier quoted context omitted.
The major flaw with that proposal is that the government has shown itself to be exceptionally incompetent (just like everyone else) when it comes to security. For example, the NSA 's security -- not some underfunded, minor agency, but the NSA itself, the world's leading cybersecurity agency -- has had its security breached on a large scale basis, multiple times. And that is just the beginning of the very long list. I…
Fair, but we are not expecting manufacturers to make bullet-proof devices. We are expecting them to make devices that do not let you achieve root access over the internet using an unchanged username and password combination. That's a very easy and specific thing to regulate.
Re: The Mirai Botnet Is Proof the Security Industry Is Broken
#217I wish more people would talk about the economics of why netsec is such a garbage industry. It's a few honest people screaming to be heard above the din of snake-oil salesmen, but there's an economic reason that goes beyond "dumb users, incompetent programmers and CTOs who just look and speeds and feeds". The problem is there's weak correlation, or at least very difficult-to-see correlation, between the amount of eff…
That's a great point regarding the economics of why IoT manufacturers don't invest all that much on security. Here's another one. It's an externality. Botnet attacks don't harm the IoT manufacturers. They don't even harm the IoT products or their users. They harm completely innocent bystanders like DNS/github. What possible incentive do IoT manufacturers have to invest money on initiatives that bring no benefits to t…
If there are actual consequences for people's computers and IoT devices being 'hacked', they will start to look for ways to avoid the inconvenience in the future. They might start using better passwords, not installing every toolbar under the sun, demand better products (and accountability) from the companies they purchase items from.
tl;dr;
The only way to get some of these problems fixed is to introduce some level of pain, somewhere in the system. I say penalize the consumer who decided to buy the cheapest thing online - turn off their Internet connection when an infected device is found.
Re: The Mirai Botnet Is Proof the Security Industry Is Broken
#218As I said previously, someone needs to bring negligence suits against some IoT vendors, wholesalers, and retailers. Start with the retailers, like Amazon. They'll find the supply chain for you as they try to pass the buck. It worked with hoverboards. There's a problem at the China end with crap low-end devices driving out the good ones. Here's a good example: solid state relays, useful little devices for safely switc…
http://www.wtsp.com/money/family-sues-amazon-after-hoverboar...
The control points are rapidly becoming retail and payment systems. Suing Amazon, Walmart, Visa, MasterCard, Paypal, etc., for facilitating the commerce of counterfeit and manifestly harmful products seems to be the logical evolution.
Re: The Mirai Botnet Is Proof the Security Industry Is Broken
#219Re: The Mirai Botnet Is Proof the Security Industry Is Broken
#220The free market has decided security of IoT doesn't matter.
Simple systems are easy to assess and communicate. Complex systems are hard (expensive) to assess and communicate. This results in several asymmetries:
1. Complex systems are communicated in an oversimplified mode.
2. Asymmetries exist between buyers and sellers of products (Akerloff's "Market for Lemons".
3. Asymmetries exist for all parties over time in realising the long-term costs (or benefits) of systems. In the most pathological instance, a party (or parties) actively frustrate the process of widespread awareness of these costs -- lead, asbestos, tobacco, sugar, CO2, etc., etc.
Corollary: security is a complex product.