Live data from Hacker News

A vigilante trying to improve IoT security

gizmodo.com

11–20 of 242 posts

Re: A vigilante trying to improve IoT security

#11

It's all fine and well until one of those improperly configured devices are a medical device or something critical. Yes I understand that's part of the problem, but proving a point with risk isn't the right answer either. Every Dialysis machine i've seen runs windows xp, which any security professional will tell you is game over, but given the market hasn't provided an alternative, it's becomes a necessity to figure…

I experience something akin to this at work all the time. There's the real-world pragmatists and the software purity philosophers.

Tell the family of someone killed that, "____ shouldn't have purchased a device without knowing how to secure it!"

Re: A vigilante trying to improve IoT security

#12
post #9

It takes a special kind of entitled to destroy people's things and to then blame others (the manufacturers) for it.

I think it's rather brilliant. It is the manufacturer's responsibility to ship secure products. Here a consumer with a bricked product will demand a replacement/refund, putting pressure on the manufacturers to not ship shitty products. It's directly applying market pressure to sellers of insecure hardware, and that's a great thing.

Re: A vigilante trying to improve IoT security

#13

It's all fine and well until one of those improperly configured devices are a medical device or something critical. Yes I understand that's part of the problem, but proving a point with risk isn't the right answer either. Every Dialysis machine i've seen runs windows xp, which any security professional will tell you is game over, but given the market hasn't provided an alternative, it's becomes a necessity to figure…

To be fair, we don't know that the malware doesn't have a whitelist of devices approved to attack.

Re: A vigilante trying to improve IoT security

#14
post #12
post #9

It takes a special kind of entitled to destroy people's things and to then blame others (the manufacturers) for it.

I think it's rather brilliant. It is the manufacturer's responsibility to ship secure products. Here a consumer with a bricked product will demand a replacement/refund, putting pressure on the manufacturers to not ship shitty products. It's directly applying market pressure to sellers of insecure hardware, and that's a great thing.

Yeah, it's a force to be reckoned with, but that does not mean it's ethical.

Re: A vigilante trying to improve IoT security

#15
post #12
post #9

It takes a special kind of entitled to destroy people's things and to then blame others (the manufacturers) for it.

I think it's rather brilliant. It is the manufacturer's responsibility to ship secure products. Here a consumer with a bricked product will demand a replacement/refund, putting pressure on the manufacturers to not ship shitty products. It's directly applying market pressure to sellers of insecure hardware, and that's a great thing.

Yes. In fact, I'm going to start stealing bikes that have insecure locks.

Re: A vigilante trying to improve IoT security

#16
post #15
post #12

Earlier quoted context omitted.

I think it's rather brilliant. It is the manufacturer's responsibility to ship secure products. Here a consumer with a bricked product will demand a replacement/refund, putting pressure on the manufacturers to not ship shitty products. It's directly applying market pressure to sellers of insecure hardware, and that's a great thing.

Yes. In fact, I'm going to start stealing bikes that have insecure locks.

What kind of stupid person would think that we could have a cooperative, functional society where I can just be careless with my bike, right?

What's the problem with these people?

Sarcasm aside, I live in Brazil, ask any Brazilian who stayed on an European country what was the biggest difference: "I could feel safe anytime, without worrying about my stuff".

That really shapes the mind and behaviour of people.

Re: A vigilante trying to improve IoT security

#17
post #15
post #12

Earlier quoted context omitted.

I think it's rather brilliant. It is the manufacturer's responsibility to ship secure products. Here a consumer with a bricked product will demand a replacement/refund, putting pressure on the manufacturers to not ship shitty products. It's directly applying market pressure to sellers of insecure hardware, and that's a great thing.

Yes. In fact, I'm going to start stealing bikes that have insecure locks.

Please don't. With some funding from China, I'm currently running a massive worldwide operation, which allows me to spy on hundreds of millions of unsuspecting Master Lock users; allowing me to track, among other things, where every bike user is at all time, as well as record what they are doing.

If only it weren't for you meddling kid.

Analogies, aren't they great?

(Since it's apparent that sarcasm can't be read: "Stealing bikes" isn't the same bloody thing. Why even make that analogy?)

Re: A vigilante trying to improve IoT security

#19

It's all fine and well until one of those improperly configured devices are a medical device or something critical. Yes I understand that's part of the problem, but proving a point with risk isn't the right answer either. Every Dialysis machine i've seen runs windows xp, which any security professional will tell you is game over, but given the market hasn't provided an alternative, it's becomes a necessity to figure…

I'm the author of the Gizmodo post. Having covered IoT hacks for a few years, it's obvious that drastic measures would be necessary to convince manufacturers to build more secure products. While I'm not necessarily endorsing this hacker's methods, I do salute his taking a stand. It might land him in jail. But still, the mission is worthwhile.

Re: A vigilante trying to improve IoT security

#20

It's all fine and well until one of those improperly configured devices are a medical device or something critical. Yes I understand that's part of the problem, but proving a point with risk isn't the right answer either. Every Dialysis machine i've seen runs windows xp, which any security professional will tell you is game over, but given the market hasn't provided an alternative, it's becomes a necessity to figure…

wait a fucking minute

people are connecting medical devices to the internet?

Post reply on HN