My work is blacklisting this domain (eyaltro.net) for malware — this URL works for me: http://colinoflynn.com/iotworm/ (Is it the same content?)
IoT Goes Nuclear: Creating a ZigBee Chain Reaction
41–50 of 100 posts
Re: IoT Goes Nuclear: Creating a ZigBee Chain Reaction
#42Earlier quoted context omitted.
Fortunately, folks "woke up" a bit as a result of that event (granted, security wasn't really a concern at that time). Unfortunately, it was relatively quickly forgotten and it took another 10-15 years before security really became something that was looked at as anything other than an inconvenience or an impediment. I'm becoming more and more convinced that nothing is going to change (with regard to overall security…
The lack of liability changes in the wake of the Target breach (at the very least) means that companies can foist whatever security model they feel like upon the market without any possible repercussions. You basically have to be VW compromising a highly regulated industry for there to be any negative effects beyond PR, and internet-accessible data is so far completely unregulated.
"We can't keep driving these and feel good about ourselves. So something needs to be done and I just want an answer.… It's not about the initial mistake — it's what you do to make things better." http://www.cbc.ca/news/canada/toronto/vw-emissions-1.3708372
Re: IoT Goes Nuclear: Creating a ZigBee Chain Reaction
#43Earlier quoted context omitted.
It's a little hard to distinguish worthwhile warnings from the near-constant din of finger-wagging
ZigBee as a protocol was broken years ago. I saw a presentation at Ruxcon in Melbourne. The researchers have a pretty decent paper on it: http://cs.dartmouth.edu/~vibhu/wireless/PIPExploits.pdf Basically control frames run in the same band as the payload data, so if you put a ZigBee header half way down your packet and cause some noise, the inside application data turns into a new packet header. You can't do this on…
Re: IoT Goes Nuclear: Creating a ZigBee Chain Reaction
#44Re: IoT Goes Nuclear: Creating a ZigBee Chain Reaction
#45Wait Hue doesn't use asymmetric keys to sign its firmware updates?
Right. Using "standard cryptographic techniques" is not sufficient when you are using the wrong technique for the job.
Me: "Yes triple-DES is reasonably secure, how do you exchange keys?"
Them: "That is part of the connection setup."
Me: "Great, how do you protect the keys during setup?"
Them: "What do you mean?"
Me: "What form of encryption do you use when you're doing the setup, and sending over the keys?"
Them: "Well we really can't encrypt the setup part, after all we haven't even set up a connection yet."
Me: "Ok, and thanks. Now move along, we'll call you..."
Re: IoT Goes Nuclear: Creating a ZigBee Chain Reaction
#46Earlier quoted context omitted.
Tragedy of the commons. No individual manufacturer really cares about the issues created by the ecosystem of IoT, so they have no real incentive to address it.
Tragedy of the Commons really means "the structure of a market failed to produce the desired outcome". The common good may be the victim, but the market is the culprit. The solution of course is alternate economic structures that respect the commons. The distinguished economist Elinor Ostrom wrote a whole book called Governing the Commons which presents real-life alternatives to markets for commons-like economic acti…
Re: IoT Goes Nuclear: Creating a ZigBee Chain Reaction
#47Clearly, absolutely no one saw this coming, nor did anyone warn us. :-) How else do you explain how woefully unprepared we are?
The vendors of Thread devices probably care even less about security and, for instance, choose to make every single one of their devices Internet-accessible instead of creating gateway apps for a local mesh network of devices.
http://www.zigbee.org/zigbee-alliance-creating-end-to-end-io...
Re: IoT Goes Nuclear: Creating a ZigBee Chain Reaction
#48Philips may have fixed the vulnerability in an update, but that's insufficient if these devices don't have high update rates. I wonder how many years until there are fewer than 15000 vulnerable Hue devices in Paris... We should hold manufacturers accountable for not aggressively pushing security updates on their users.
There's really no way to /force/ companies to support products they release like that. The company may not even exist a few years down the road. You could force them to release the firmware source so the users/community can patch it themselves but I don't see a way to do what you're saying.
Re: IoT Goes Nuclear: Creating a ZigBee Chain Reaction
#49It's not even possible to get two ZigBee products from different manufacturers to operate (like a switch and a lamp).
The attack can't succeed at what the industry's been failing for 10 years.
Re: IoT Goes Nuclear: Creating a ZigBee Chain Reaction
#50Earlier quoted context omitted.
Right. Using "standard cryptographic techniques" is not sufficient when you are using the wrong technique for the job.
I had a discussion once, back when I was wearing a crypto hat, which went like this: Me: "Yes triple-DES is reasonably secure, how do you exchange keys?" Them: "That is part of the connection setup." Me: "Great, how do you protect the keys during setup?" Them: "What do you mean?" Me: "What form of encryption do you use when you're doing the setup, and sending over the keys?" Them: "Well we really can't encrypt the se…
This is how the top comment starts on the HN thread about the ZLL master key being published, two years ago:
"This may not be much of an attack. The master key is used only during "commissioning", when a controller is introduced to a light."