Earlier quoted context omitted.
Tragedy of the commons. No individual manufacturer really cares about the issues created by the ecosystem of IoT, so they have no real incentive to address it.
Any manufacturer who has to recall a device cares very much about it.
IoT Goes Nuclear: Creating a ZigBee Chain Reaction
71–80 of 100 posts
Re: IoT Goes Nuclear: Creating a ZigBee Chain Reaction
#72Clearly, absolutely no one saw this coming, nor did anyone warn us. :-) How else do you explain how woefully unprepared we are?
I think ZigBee has already been deprecated in favor of Thread, which seems to be slightly more focused on security, although it's still probably nowhere near where it needs to be. The vendors of Thread devices probably care even less about security and, for instance, choose to make every single one of their devices Internet-accessible instead of creating gateway apps for a local mesh network of devices. https://www.t…
Re: IoT Goes Nuclear: Creating a ZigBee Chain Reaction
#73Clearly, absolutely no one saw this coming, nor did anyone warn us. :-) How else do you explain how woefully unprepared we are?
It's a little hard to distinguish worthwhile warnings from the near-constant din of finger-wagging
Anyone in tech with two braincells to rub together could tell you that security is a hard problem. And yet there has been a consistent pressure in IoT enthusiasm which rested on the premise that security was a solved problem. Everything about IoT went against decades of hard-won wisdom about internet security: lessen your surface area, keep as much stuff off the internet (behind firewalls) as possible, constant vigilance through patching and staying up to date on vulnerabilities is important, use strong credentials to secure anything that could ever be reached from the internet. In short, that internet security was a big and difficult job, and a constant battle that required careful risk management.
IoT enthusiasts dismissed all of that and never had a good counter-argument, just the insistence that nothing, not even security issues, should get in the way of how cool IoT devices could be.
It was obvious that this would be a problem. And every security expert made mention of it. There is no "oops, well how were we to know?" about it.
Re: IoT Goes Nuclear: Creating a ZigBee Chain Reaction
#74Everything will be fine =) It's not even possible to get two ZigBee products from different manufacturers to operate (like a switch and a lamp). The attack can't succeed at what the industry's been failing for 10 years.
Re: IoT Goes Nuclear: Creating a ZigBee Chain Reaction
#75Earlier quoted context omitted.
How is this "tragedy of the commons"? The only "common" they are using is the RF spectrum, which they are presumably not polluting too badly or the FCC would start smashing down doors. Let's not start claiming the internet itself somehow qualifies as a "common", because with common ownership rationally comes common censorship (as with the FCC and public broadcasts).
Seems unwise to reason backwards from your desired conclusion (commons implies censorship/regulation, so it can't be a commons). Security is indeed a commons because the overall security of the ecosystem only benefits each person weakly, and so every actor rationally benefits by neglecting security. External regulation isn't the only way to address commons problems. Manufacturers can see the writing on the wall and w…
Re: IoT Goes Nuclear: Creating a ZigBee Chain Reaction
#76Earlier quoted context omitted.
What's great about this argument is how versatile it is. Climate change got you down? How about deforestation, or antibiotic overuse? Tired of people telling you not to write web applications in C? Your one liner seamlessly shuts down discussion in any of those debates! In fact: the finger-waggers have been right about this issue since approximately 1988, when Paul Graham's friend shut down much of the Internet with…
Fortunately, folks "woke up" a bit as a result of that event (granted, security wasn't really a concern at that time). Unfortunately, it was relatively quickly forgotten and it took another 10-15 years before security really became something that was looked at as anything other than an inconvenience or an impediment. I'm becoming more and more convinced that nothing is going to change (with regard to overall security…
Re: IoT Goes Nuclear: Creating a ZigBee Chain Reaction
#77Earlier quoted context omitted.
> How else do you explain how woefully unprepared we are? What do you mean? This is an expected outcome of the "ship ASAP", "competition uber alles" culture, rewarding short term gains over everything else. Our whole technological ecosystem was built on this mindset.
Pretty sure that was sarcasm...
Re: IoT Goes Nuclear: Creating a ZigBee Chain Reaction
#78Everything will be fine =) It's not even possible to get two ZigBee products from different manufacturers to operate (like a switch and a lamp). The attack can't succeed at what the industry's been failing for 10 years.
> It's not even possible to get two ZigBee products from
> different manufacturers to operate (like a switch and a
> lamp).
It may require a distinct payload for each type of device/software, but it should be possible. You start by infecting a group of devices of one type with a specific payload, and from there see which other types of devices are in range, and either carry the required payloads with you or fetch one over a nearby wifi.And indeed, if someone were to implement this, they would basically have built a standard ZigBee inter-device communication protocol, by using existing software features (bugs), in otherwise incompatible devices.
This is not too far off from something like Stuxnet, so -- given enough available capital -- it should be possible.
Re: IoT Goes Nuclear: Creating a ZigBee Chain Reaction
#79Everything will be fine =) It's not even possible to get two ZigBee products from different manufacturers to operate (like a switch and a lamp). The attack can't succeed at what the industry's been failing for 10 years.
> It's not even possible to get two ZigBee products from > different manufacturers to operate (like a switch and a > lamp). It may require a distinct payload for each type of device/software, but it should be possible. You start by infecting a group of devices of one type with a specific payload, and from there see which other types of devices are in range, and either carry the required payloads with you or fetch one…
I was indeed half-joking, half-serious. Actually, aren't there cases where viruses (the biological kind) have ended up serving a function in the DNA machinery of multi-cellular life-forms? Would be a funny parallel.
Re: IoT Goes Nuclear: Creating a ZigBee Chain Reaction
#80Earlier quoted context omitted.
Seems unwise to reason backwards from your desired conclusion (commons implies censorship/regulation, so it can't be a commons). Security is indeed a commons because the overall security of the ecosystem only benefits each person weakly, and so every actor rationally benefits by neglecting security. External regulation isn't the only way to address commons problems. Manufacturers can see the writing on the wall and w…
I imagine that it can also get better once a company can gain competitive advantage by advertising that "our device is secure!" But I suppose a precondition for this is customer awareness of the issue, which probably requires some well publicized high impact/casualty incidents first? :/