Earlier quoted context omitted.
Yes. In fact, I'm going to start stealing bikes that have insecure locks.
I feel like a more accurate analogy is that you are going to start breaking into poorly secured garages and destroy people's bikes so that the owner can't ride them anymore.
A vigilante trying to improve IoT security
41–50 of 242 posts
Re: A vigilante trying to improve IoT security
#42Earlier quoted context omitted.
Please don't. With some funding from China, I'm currently running a massive worldwide operation, which allows me to spy on hundreds of millions of unsuspecting Master Lock users; allowing me to track, among other things, where every bike user is at all time, as well as record what they are doing. If only it weren't for you meddling kid. Analogies, aren't they great? (Since it's apparent that sarcasm can't be read: "S…
If this danger is real, isn't it best to inform the consumer, or perhaps use a lawsuit to force a recall, rather than destroying other people's hardware? Does this concept apply to software? When the next large-scale RCE 0-day drops, does it make sense to use exploitation to destroy as much as possible in order to pressure the developers to ship a secure product? Since, the hacked machines certainly could allow an at…
Re: A vigilante trying to improve IoT security
#43Earlier quoted context omitted.
Yes. In fact, I'm going to start stealing bikes that have insecure locks.
Very different. If you can bust an insecure lock you can steal a bike. If you bust an insecure IoT device, you can steal data from potentially thousands or millions of people.
Re: A vigilante trying to improve IoT security
#44It's all fine and well until one of those improperly configured devices are a medical device or something critical. Yes I understand that's part of the problem, but proving a point with risk isn't the right answer either. Every Dialysis machine i've seen runs windows xp, which any security professional will tell you is game over, but given the market hasn't provided an alternative, it's becomes a necessity to figure…
Re: A vigilante trying to improve IoT security
#45Earlier quoted context omitted.
I think it's rather brilliant. It is the manufacturer's responsibility to ship secure products. Here a consumer with a bricked product will demand a replacement/refund, putting pressure on the manufacturers to not ship shitty products. It's directly applying market pressure to sellers of insecure hardware, and that's a great thing.
Yes. In fact, I'm going to start stealing bikes that have insecure locks.
Re: A vigilante trying to improve IoT security
#46It's all fine and well until one of those improperly configured devices are a medical device or something critical. Yes I understand that's part of the problem, but proving a point with risk isn't the right answer either. Every Dialysis machine i've seen runs windows xp, which any security professional will tell you is game over, but given the market hasn't provided an alternative, it's becomes a necessity to figure…
Re: A vigilante trying to improve IoT security
#47It takes a special kind of entitled to destroy people's things and to then blame others (the manufacturers) for it.
Re: A vigilante trying to improve IoT security
#48It's all fine and well until one of those improperly configured devices are a medical device or something critical. Yes I understand that's part of the problem, but proving a point with risk isn't the right answer either. Every Dialysis machine i've seen runs windows xp, which any security professional will tell you is game over, but given the market hasn't provided an alternative, it's becomes a necessity to figure…
wait a fucking minute people are connecting medical devices to the internet?
Re: A vigilante trying to improve IoT security
#49Earlier quoted context omitted.
I think it's rather brilliant. It is the manufacturer's responsibility to ship secure products. Here a consumer with a bricked product will demand a replacement/refund, putting pressure on the manufacturers to not ship shitty products. It's directly applying market pressure to sellers of insecure hardware, and that's a great thing.
Yes. In fact, I'm going to start stealing bikes that have insecure locks.
Additionally theft of property has a personal gain for you.
I'm not sure I ethically support the hacker's actions, but I don't think the bike example has the market/awareness effects that make it at all defensible.
Re: A vigilante trying to improve IoT security
#50Earlier quoted context omitted.
Did you not have any input into this headline? It is a clear endorsement.
My editor thought it might be too extreme, but I was sure that careful readers would latch on to the tongue-in-cheek intentions. Maybe I was wrong. I still stand by the statement.