Live data from Hacker News

IoT Goes Nuclear: Creating a ZigBee Chain Reaction

iotworm.eyalro.net

71–80 of 100 posts

Re: IoT Goes Nuclear: Creating a ZigBee Chain Reaction

#71
post #37

Earlier quoted context omitted.

Tragedy of the commons. No individual manufacturer really cares about the issues created by the ecosystem of IoT, so they have no real incentive to address it.

Any manufacturer who has to recall a device cares very much about it.

Those IoT manufacturers must be lucky then. They haven't been sued because of a insecure lightbulb yet.

Re: IoT Goes Nuclear: Creating a ZigBee Chain Reaction

#72
post #47

Clearly, absolutely no one saw this coming, nor did anyone warn us. :-) How else do you explain how woefully unprepared we are?

I think ZigBee has already been deprecated in favor of Thread, which seems to be slightly more focused on security, although it's still probably nowhere near where it needs to be. The vendors of Thread devices probably care even less about security and, for instance, choose to make every single one of their devices Internet-accessible instead of creating gateway apps for a local mesh network of devices. https://www.t…

I would have thought that Zigbee had zero traction some years ago. But since then Hue (and Lightify and other Zigbee LightLink solutions) popped up and now are probably the most sold personal home automation things around. The manufacturers do want for sure to push the ecosystem and are announcing more products based on it. Compared to that Thread has next to zero available devices (don't know whether Nest uses it). So I think currently it's a bit too soon to talk of ZigBee being deprecated.

Re: IoT Goes Nuclear: Creating a ZigBee Chain Reaction

#73

Clearly, absolutely no one saw this coming, nor did anyone warn us. :-) How else do you explain how woefully unprepared we are?

It's a little hard to distinguish worthwhile warnings from the near-constant din of finger-wagging

It really isn't.

Anyone in tech with two braincells to rub together could tell you that security is a hard problem. And yet there has been a consistent pressure in IoT enthusiasm which rested on the premise that security was a solved problem. Everything about IoT went against decades of hard-won wisdom about internet security: lessen your surface area, keep as much stuff off the internet (behind firewalls) as possible, constant vigilance through patching and staying up to date on vulnerabilities is important, use strong credentials to secure anything that could ever be reached from the internet. In short, that internet security was a big and difficult job, and a constant battle that required careful risk management.

IoT enthusiasts dismissed all of that and never had a good counter-argument, just the insistence that nothing, not even security issues, should get in the way of how cool IoT devices could be.

It was obvious that this would be a problem. And every security expert made mention of it. There is no "oops, well how were we to know?" about it.

Re: IoT Goes Nuclear: Creating a ZigBee Chain Reaction

#74

Everything will be fine =) It's not even possible to get two ZigBee products from different manufacturers to operate (like a switch and a lamp). The attack can't succeed at what the industry's been failing for 10 years.

So what you're saying is that if someone does make it work, we should reverse engineer the worm for understanding how to achieve better device interop? ;-)

Re: IoT Goes Nuclear: Creating a ZigBee Chain Reaction

#75
post #56

Earlier quoted context omitted.

How is this "tragedy of the commons"? The only "common" they are using is the RF spectrum, which they are presumably not polluting too badly or the FCC would start smashing down doors. Let's not start claiming the internet itself somehow qualifies as a "common", because with common ownership rationally comes common censorship (as with the FCC and public broadcasts).

Seems unwise to reason backwards from your desired conclusion (commons implies censorship/regulation, so it can't be a commons). Security is indeed a commons because the overall security of the ecosystem only benefits each person weakly, and so every actor rationally benefits by neglecting security. External regulation isn't the only way to address commons problems. Manufacturers can see the writing on the wall and w…

I imagine that it can also get better once a company can gain competitive advantage by advertising that "our device is secure!" But I suppose a precondition for this is customer awareness of the issue, which probably requires some well publicized high impact/casualty incidents first? :/

Re: IoT Goes Nuclear: Creating a ZigBee Chain Reaction

#76
post #29

Earlier quoted context omitted.

What's great about this argument is how versatile it is. Climate change got you down? How about deforestation, or antibiotic overuse? Tired of people telling you not to write web applications in C? Your one liner seamlessly shuts down discussion in any of those debates! In fact: the finger-waggers have been right about this issue since approximately 1988, when Paul Graham's friend shut down much of the Internet with…

Fortunately, folks "woke up" a bit as a result of that event (granted, security wasn't really a concern at that time). Unfortunately, it was relatively quickly forgotten and it took another 10-15 years before security really became something that was looked at as anything other than an inconvenience or an impediment. I'm becoming more and more convinced that nothing is going to change (with regard to overall security…

Even if a big event occurs I think the security drive will be short-lived. You'll then find a few manufacturers taking shortcuts to beat their security-minded colleagues to market... then the floodgates open again as everyone races to the bottom.

Re: IoT Goes Nuclear: Creating a ZigBee Chain Reaction

#77
post #12

Earlier quoted context omitted.

> How else do you explain how woefully unprepared we are? What do you mean? This is an expected outcome of the "ship ASAP", "competition uber alles" culture, rewarding short term gains over everything else. Our whole technological ecosystem was built on this mindset.

Pretty sure that was sarcasm...

unfortunately it is not.

Re: IoT Goes Nuclear: Creating a ZigBee Chain Reaction

#78

Everything will be fine =) It's not even possible to get two ZigBee products from different manufacturers to operate (like a switch and a lamp). The attack can't succeed at what the industry's been failing for 10 years.

   > It's not even possible to get two ZigBee products from 
   > different manufacturers to operate (like a switch and a  
   > lamp).
It may require a distinct payload for each type of device/software, but it should be possible. You start by infecting a group of devices of one type with a specific payload, and from there see which other types of devices are in range, and either carry the required payloads with you or fetch one over a nearby wifi.

And indeed, if someone were to implement this, they would basically have built a standard ZigBee inter-device communication protocol, by using existing software features (bugs), in otherwise incompatible devices.

This is not too far off from something like Stuxnet, so -- given enough available capital -- it should be possible.

Re: IoT Goes Nuclear: Creating a ZigBee Chain Reaction

#79
post #78

Everything will be fine =) It's not even possible to get two ZigBee products from different manufacturers to operate (like a switch and a lamp). The attack can't succeed at what the industry's been failing for 10 years.

> It's not even possible to get two ZigBee products from > different manufacturers to operate (like a switch and a > lamp). It may require a distinct payload for each type of device/software, but it should be possible. You start by infecting a group of devices of one type with a specific payload, and from there see which other types of devices are in range, and either carry the required payloads with you or fetch one…

> And indeed, if someone were to implement this, they would basically have built a standard ZigBee inter-device communication protocol, by using existing software features (bugs), in otherwise incompatible devices.

I was indeed half-joking, half-serious. Actually, aren't there cases where viruses (the biological kind) have ended up serving a function in the DNA machinery of multi-cellular life-forms? Would be a funny parallel.

Re: IoT Goes Nuclear: Creating a ZigBee Chain Reaction

#80
post #75

Earlier quoted context omitted.

Seems unwise to reason backwards from your desired conclusion (commons implies censorship/regulation, so it can't be a commons). Security is indeed a commons because the overall security of the ecosystem only benefits each person weakly, and so every actor rationally benefits by neglecting security. External regulation isn't the only way to address commons problems. Manufacturers can see the writing on the wall and w…

I imagine that it can also get better once a company can gain competitive advantage by advertising that "our device is secure!" But I suppose a precondition for this is customer awareness of the issue, which probably requires some well publicized high impact/casualty incidents first? :/

Of course, anyone can say "our device is secure", and if the industry is left to its own devices to create a standard for being allowed to say that, they'll pick the cheapest standard possible. Then, so long as they can say "we were following the standards", and the standards company can say "we're updating the standard" every time, nobody cares.
Post reply on HN