Live data from Hacker News

A vigilante trying to improve IoT security

gizmodo.com

31–40 of 242 posts

Re: A vigilante trying to improve IoT security

#31
post #25

Earlier quoted context omitted.

I'm the author of the Gizmodo post. Having covered IoT hacks for a few years, it's obvious that drastic measures would be necessary to convince manufacturers to build more secure products. While I'm not necessarily endorsing this hacker's methods, I do salute his taking a stand. It might land him in jail. But still, the mission is worthwhile.

Did you not have any input into this headline? It is a clear endorsement.

My editor thought it might be too extreme, but I was sure that careful readers would latch on to the tongue-in-cheek intentions. Maybe I was wrong. I still stand by the statement.

Re: A vigilante trying to improve IoT security

#32

It's all fine and well until one of those improperly configured devices are a medical device or something critical. Yes I understand that's part of the problem, but proving a point with risk isn't the right answer either. Every Dialysis machine i've seen runs windows xp, which any security professional will tell you is game over, but given the market hasn't provided an alternative, it's becomes a necessity to figure…

I'm the author of the Gizmodo post. Having covered IoT hacks for a few years, it's obvious that drastic measures would be necessary to convince manufacturers to build more secure products. While I'm not necessarily endorsing this hacker's methods, I do salute his taking a stand. It might land him in jail. But still, the mission is worthwhile.

Just FYI you have a small mistake here: "So why did the Janit0r result to destruction". Should be "resort" I think.

Re: A vigilante trying to improve IoT security

#33
post #20

It's all fine and well until one of those improperly configured devices are a medical device or something critical. Yes I understand that's part of the problem, but proving a point with risk isn't the right answer either. Every Dialysis machine i've seen runs windows xp, which any security professional will tell you is game over, but given the market hasn't provided an alternative, it's becomes a necessity to figure…

wait a fucking minute people are connecting medical devices to the internet?

Don't be too alarmed there are 3/4 classes of device all with differing risk profiles. Patient safety include things like protecting patient information so even systems used to transfer medical records can be regarded as a medical device. Not sure I'd want a pace maker updating online though...

Re: A vigilante trying to improve IoT security

#34
post #25

Earlier quoted context omitted.

I'm the author of the Gizmodo post. Having covered IoT hacks for a few years, it's obvious that drastic measures would be necessary to convince manufacturers to build more secure products. While I'm not necessarily endorsing this hacker's methods, I do salute his taking a stand. It might land him in jail. But still, the mission is worthwhile.

Did you not have any input into this headline? It is a clear endorsement.

I think the headline reads as personal, and therefore a lighter endorsement than something like "This Hacker is Our new Hero" or "This Hacker is a Hero".

Re: A vigilante trying to improve IoT security

#35
post #15
post #12

Earlier quoted context omitted.

I think it's rather brilliant. It is the manufacturer's responsibility to ship secure products. Here a consumer with a bricked product will demand a replacement/refund, putting pressure on the manufacturers to not ship shitty products. It's directly applying market pressure to sellers of insecure hardware, and that's a great thing.

Yes. In fact, I'm going to start stealing bikes that have insecure locks.

I feel like a more accurate analogy is that you are going to start breaking into poorly secured garages and destroy people's bikes so that the owner can't ride them anymore.

Re: A vigilante trying to improve IoT security

#36
post #20

It's all fine and well until one of those improperly configured devices are a medical device or something critical. Yes I understand that's part of the problem, but proving a point with risk isn't the right answer either. Every Dialysis machine i've seen runs windows xp, which any security professional will tell you is game over, but given the market hasn't provided an alternative, it's becomes a necessity to figure…

wait a fucking minute people are connecting medical devices to the internet?

If you connect it to a network, it's entirely plausible that there is a path to the internet. Even if it's on an airgapped network, laptops and phones end up on both through accidents...

Re: A vigilante trying to improve IoT security

#37
post #15
post #12

Earlier quoted context omitted.

I think it's rather brilliant. It is the manufacturer's responsibility to ship secure products. Here a consumer with a bricked product will demand a replacement/refund, putting pressure on the manufacturers to not ship shitty products. It's directly applying market pressure to sellers of insecure hardware, and that's a great thing.

Yes. In fact, I'm going to start stealing bikes that have insecure locks.

That market pressure already exists, and what do you know, the market strongly favors certain locks directly because of that pressure.

Re: A vigilante trying to improve IoT security

#38
post #32

Earlier quoted context omitted.

I'm the author of the Gizmodo post. Having covered IoT hacks for a few years, it's obvious that drastic measures would be necessary to convince manufacturers to build more secure products. While I'm not necessarily endorsing this hacker's methods, I do salute his taking a stand. It might land him in jail. But still, the mission is worthwhile.

Just FYI you have a small mistake here: "So why did the Janit0r result to destruction". Should be "resort" I think.

Fixed. I will now install a dead rat under our copy editor's desk...

Re: A vigilante trying to improve IoT security

#39
post #25

Earlier quoted context omitted.

Did you not have any input into this headline? It is a clear endorsement.

My editor thought it might be too extreme, but I was sure that careful readers would latch on to the tongue-in-cheek intentions. Maybe I was wrong. I still stand by the statement.

[deleted]

Re: A vigilante trying to improve IoT security

#40
post #16
post #15

Earlier quoted context omitted.

Yes. In fact, I'm going to start stealing bikes that have insecure locks.

What kind of stupid person would think that we could have a cooperative, functional society where I can just be careless with my bike, right? What's the problem with these people? Sarcasm aside, I live in Brazil, ask any Brazilian who stayed on an European country what was the biggest difference: "I could feel safe anytime, without worrying about my stuff". That really shapes the mind and behaviour of people.

Which is great, in theory. But devices in Europe are just as accessible to Brazilians as they are to anyone else. Unless a device is locked down to local access, you can't have "safe neighborhoods".
Post reply on HN