Live data from Hacker News

IoT Goes Nuclear: Creating a ZigBee Chain Reaction

iotworm.eyalro.net

31–40 of 100 posts

Re: IoT Goes Nuclear: Creating a ZigBee Chain Reaction

#31
post #29

Earlier quoted context omitted.

It's a little hard to distinguish worthwhile warnings from the near-constant din of finger-wagging

What's great about this argument is how versatile it is. Climate change got you down? How about deforestation, or antibiotic overuse? Tired of people telling you not to write web applications in C? Your one liner seamlessly shuts down discussion in any of those debates! In fact: the finger-waggers have been right about this issue since approximately 1988, when Paul Graham's friend shut down much of the Internet with…

Fortunately, folks "woke up" a bit as a result of that event (granted, security wasn't really a concern at that time). Unfortunately, it was relatively quickly forgotten and it took another 10-15 years before security really became something that was looked at as anything other than an inconvenience or an impediment.

I'm becoming more and more convinced that nothing is going to change (with regard to overall security in general) until we have some huge event that negatively impacts a large portion of the population in a major way. Until then, things will continue as they are, and security won't be taken seriously.

I'm ready for the 2016 version of the 1988 sendmail worm (or perhaps something with the "average user"-visible impact of the 1990 AT&T crash), just to "get it over with" and get us moving forward.

Re: IoT Goes Nuclear: Creating a ZigBee Chain Reaction

#32

Clearly, absolutely no one saw this coming, nor did anyone warn us. :-) How else do you explain how woefully unprepared we are?

It's a little hard to distinguish worthwhile warnings from the near-constant din of finger-wagging

ZigBee as a protocol was broken years ago. I saw a presentation at Ruxcon in Melbourne. The researchers have a pretty decent paper on it:

http://cs.dartmouth.edu/~vibhu/wireless/PIPExploits.pdf

Basically control frames run in the same band as the payload data, so if you put a ZigBee header half way down your packet and cause some noise, the inside application data turns into a new packet header. You can't do this on 802.11b/g/n/etc because the control data is send out of band from the application layer data.

It's considerably different from the attack mentioned in this post, but we've know at least that the protocol has been broken for years.

Re: IoT Goes Nuclear: Creating a ZigBee Chain Reaction

#33
post #2

Domain gets tagged as distributing malware by my work's security system, FYI. Dunno what list it's gone on, but it's there.

uMatrix doesn't allow this site to show either.

View Source reveals that this site is actually an iframed version of http://www.wisdom.weizmann.ac.il/~eyalro/iotworm/.

Re: IoT Goes Nuclear: Creating a ZigBee Chain Reaction

#35
post #29

Earlier quoted context omitted.

What's great about this argument is how versatile it is. Climate change got you down? How about deforestation, or antibiotic overuse? Tired of people telling you not to write web applications in C? Your one liner seamlessly shuts down discussion in any of those debates! In fact: the finger-waggers have been right about this issue since approximately 1988, when Paul Graham's friend shut down much of the Internet with…

Fortunately, folks "woke up" a bit as a result of that event (granted, security wasn't really a concern at that time). Unfortunately, it was relatively quickly forgotten and it took another 10-15 years before security really became something that was looked at as anything other than an inconvenience or an impediment. I'm becoming more and more convinced that nothing is going to change (with regard to overall security…

The lack of liability changes in the wake of the Target breach (at the very least) means that companies can foist whatever security model they feel like upon the market without any possible repercussions. You basically have to be VW compromising a highly regulated industry for there to be any negative effects beyond PR, and internet-accessible data is so far completely unregulated.

Re: IoT Goes Nuclear: Creating a ZigBee Chain Reaction

#36

Earlier quoted context omitted.

Tragedy of the commons. No individual manufacturer really cares about the issues created by the ecosystem of IoT, so they have no real incentive to address it.

Tragedy of the Commons really means "the structure of a market failed to produce the desired outcome". The common good may be the victim, but the market is the culprit. The solution of course is alternate economic structures that respect the commons. The distinguished economist Elinor Ostrom wrote a whole book called Governing the Commons which presents real-life alternatives to markets for commons-like economic acti…

I thought neoliberalism was more about contorting society until they meet the needs of the market.

Re: IoT Goes Nuclear: Creating a ZigBee Chain Reaction

#37

Clearly, absolutely no one saw this coming, nor did anyone warn us. :-) How else do you explain how woefully unprepared we are?

Tragedy of the commons. No individual manufacturer really cares about the issues created by the ecosystem of IoT, so they have no real incentive to address it.

Any manufacturer who has to recall a device cares very much about it.

Re: IoT Goes Nuclear: Creating a ZigBee Chain Reaction

#38
post #29

Earlier quoted context omitted.

It's a little hard to distinguish worthwhile warnings from the near-constant din of finger-wagging

What's great about this argument is how versatile it is. Climate change got you down? How about deforestation, or antibiotic overuse? Tired of people telling you not to write web applications in C? Your one liner seamlessly shuts down discussion in any of those debates! In fact: the finger-waggers have been right about this issue since approximately 1988, when Paul Graham's friend shut down much of the Internet with…

> since approximately 1988, when Paul Graham's friend shut down much of the Internet

Spoiler: https://en.wikipedia.org/wiki/Morris_worm

Re: IoT Goes Nuclear: Creating a ZigBee Chain Reaction

#39
Philips may have fixed the vulnerability in an update, but that's insufficient if these devices don't have high update rates.

I wonder how many years until there are fewer than 15000 vulnerable Hue devices in Paris...

We should hold manufacturers accountable for not aggressively pushing security updates on their users.

Post reply on HN