Live data from Hacker News

A vigilante trying to improve IoT security

gizmodo.com

41–50 of 242 posts

Re: A vigilante trying to improve IoT security

#41
post #15

Earlier quoted context omitted.

Yes. In fact, I'm going to start stealing bikes that have insecure locks.

I feel like a more accurate analogy is that you are going to start breaking into poorly secured garages and destroy people's bikes so that the owner can't ride them anymore.

While I am on the fence with a lot of what is happening, I would have thought a more appropriate analogy would be to: Break into a poorly secured garage, that has been sold as a single unit to the customer, seal the door and any other access via welding so that no one can ever use the garage ever again.

Re: A vigilante trying to improve IoT security

#42
post #27

Earlier quoted context omitted.

Please don't. With some funding from China, I'm currently running a massive worldwide operation, which allows me to spy on hundreds of millions of unsuspecting Master Lock users; allowing me to track, among other things, where every bike user is at all time, as well as record what they are doing. If only it weren't for you meddling kid. Analogies, aren't they great? (Since it's apparent that sarcasm can't be read: "S…

If this danger is real, isn't it best to inform the consumer, or perhaps use a lawsuit to force a recall, rather than destroying other people's hardware? Does this concept apply to software? When the next large-scale RCE 0-day drops, does it make sense to use exploitation to destroy as much as possible in order to pressure the developers to ship a secure product? Since, the hacked machines certainly could allow an at…

a lawsuit requires people 'smart' enough to even know they were hacked, and for a recall they need to decide if the cost of a recall is cheaper than legal/settlement fees, ( i learned this from Fight club) lol -- however -- WARRANTY replacements of devices because a hacker breached security and bricked it--this could be a LOT faster way to force them to recall.

Re: A vigilante trying to improve IoT security

#43
post #23
post #15

Earlier quoted context omitted.

Yes. In fact, I'm going to start stealing bikes that have insecure locks.

Very different. If you can bust an insecure lock you can steal a bike. If you bust an insecure IoT device, you can steal data from potentially thousands or millions of people.

Not only that but use it as a botnet to make it so the entire internet becomes unusable.

Re: A vigilante trying to improve IoT security

#44

It's all fine and well until one of those improperly configured devices are a medical device or something critical. Yes I understand that's part of the problem, but proving a point with risk isn't the right answer either. Every Dialysis machine i've seen runs windows xp, which any security professional will tell you is game over, but given the market hasn't provided an alternative, it's becomes a necessity to figure…

Is there any evidence that BrickerBot targets medical devices?

Re: A vigilante trying to improve IoT security

#45
post #15
post #12

Earlier quoted context omitted.

I think it's rather brilliant. It is the manufacturer's responsibility to ship secure products. Here a consumer with a bricked product will demand a replacement/refund, putting pressure on the manufacturers to not ship shitty products. It's directly applying market pressure to sellers of insecure hardware, and that's a great thing.

Yes. In fact, I'm going to start stealing bikes that have insecure locks.

Having a bad lock on your bike generally doesn't cause much harm to others. Allowing your hardware to be used for, e.g., DDOS attacks does.

Re: A vigilante trying to improve IoT security

#46

It's all fine and well until one of those improperly configured devices are a medical device or something critical. Yes I understand that's part of the problem, but proving a point with risk isn't the right answer either. Every Dialysis machine i've seen runs windows xp, which any security professional will tell you is game over, but given the market hasn't provided an alternative, it's becomes a necessity to figure…

The thing is, either way, someone is getting harmed. If these devices are left to run unpatched, they'll take part in attacks against whoever, and someone somewhere suffers. Possibly a lot of someones, Mirai wasn't exactly a joke.

Re: A vigilante trying to improve IoT security

#48
post #20

It's all fine and well until one of those improperly configured devices are a medical device or something critical. Yes I understand that's part of the problem, but proving a point with risk isn't the right answer either. Every Dialysis machine i've seen runs windows xp, which any security professional will tell you is game over, but given the market hasn't provided an alternative, it's becomes a necessity to figure…

wait a fucking minute people are connecting medical devices to the internet?

It might not be connected to the internet in an IoT way, but it makes a lot of sense to connect a device to a wi-fi network if you need to wirelessly transmit any form of data.

Re: A vigilante trying to improve IoT security

#49
post #15
post #12

Earlier quoted context omitted.

I think it's rather brilliant. It is the manufacturer's responsibility to ship secure products. Here a consumer with a bricked product will demand a replacement/refund, putting pressure on the manufacturers to not ship shitty products. It's directly applying market pressure to sellers of insecure hardware, and that's a great thing.

Yes. In fact, I'm going to start stealing bikes that have insecure locks.

There's a few things missing in this comparison, most notably the bike manufacturer isn't claiming the bike is already secure ("auto-locking" bikes) or making additional security challenging (bikes that locks are very hard to install on) or generally profiting from an environment of misinformation about bike theft and bike safety.

Additionally theft of property has a personal gain for you.

I'm not sure I ethically support the hacker's actions, but I don't think the bike example has the market/awareness effects that make it at all defensible.

Re: A vigilante trying to improve IoT security

#50
post #25

Earlier quoted context omitted.

Did you not have any input into this headline? It is a clear endorsement.

My editor thought it might be too extreme, but I was sure that careful readers would latch on to the tongue-in-cheek intentions. Maybe I was wrong. I still stand by the statement.

Oh please. Your "editor" was probably like: "gr8 b8 m8."
Post reply on HN