Live data from Hacker News

A vigilante trying to improve IoT security

gizmodo.com

61–70 of 242 posts

Re: A vigilante trying to improve IoT security

#61

It's all fine and well until one of those improperly configured devices are a medical device or something critical. Yes I understand that's part of the problem, but proving a point with risk isn't the right answer either. Every Dialysis machine i've seen runs windows xp, which any security professional will tell you is game over, but given the market hasn't provided an alternative, it's becomes a necessity to figure…

I experience something akin to this at work all the time. There's the real-world pragmatists and the software purity philosophers. Tell the family of someone killed that, "____ shouldn't have purchased a device without knowing how to secure it!"

If you want to tug on heartstrings with the "what about medical devices" argument, it's probably just as likely that a mirai botnet will impact a life support or public safety network than that brickerbot will.

Re: A vigilante trying to improve IoT security

#62
post #9

It takes a special kind of entitled to destroy people's things and to then blame others (the manufacturers) for it.

It's sort of like your neighbor having an automated lawnmower, and you knowing that with a careful placement of rocks the image recognition will fritz and it will happily start mowing into your yard, over your petunias and possibly your small children and animals. You're fairly certain that there are other problems with it you don't know about as well.

Do you force the situation and make it mow into your yard and over a bunch of rocks to destroy it, or do you live with the danger?

I don't have an answer. In this situation you could at least talk to your neighbor. Without the ability to feasibly do that, I'm not sure I would fault either action.

Re: A vigilante trying to improve IoT security

#63
post #52

Earlier quoted context omitted.

I find the arguments for "taking a stand" quite weak. Normally with subcultures that break the law or in other ways inconvenience people the moral argument is that you're doing something that isn't available to you (often as a group) and your actions themselves are meaningful (often because it makes it available to you). I don't really see in this case how they (or mostly anyone) is unable to improve IoT (or general)…

"I don't really see in this case how they (or mostly anyone) is unable to improve IoT (or general) security through other means" Really? How about you show me the evidence that people are... through "other means"... improving IOT security of these devices enough that DDOS isn't a big problem any more. I'd love to hear what you've done to convince all the vendors to focus on secure devices instead of profit when targe…

That's true.

Altough i wonder: why didn't someone with deep security expertise, maybe ARM with it's mbed,created something developers can't harm, and on the other hand, issue a product label saying:"this is protected by our stack..." ?

I could see that be attractive to some b2b buyers, attracting devs, further strengthening the value of said label , increasing marketshare and reducing costs, and creating a positive feedback.

Re: A vigilante trying to improve IoT security

#64
post #15

Earlier quoted context omitted.

Yes. In fact, I'm going to start stealing bikes that have insecure locks.

Having a bad lock on your bike generally doesn't cause much harm to others. Allowing your hardware to be used for, e.g., DDOS attacks does.

I understand what you're implying, but no one is "allowing" their hardware to be used criminally. At least in the U.S., our personal property system is permissive i/e you may not use my things without permission. So, using an IoT device as provided by the manufacturer is "allowing" its misuse so much as leaving my backyard gate unlocked is "allowing" criminals to park their stolen goods in my backyard.

Re: A vigilante trying to improve IoT security

#66
I toyed with a similar idea that would be limited to subnets or non-routable IP space, and open-source/community-driven, but I had to take it down almost immediately due to bad press/backlash. There's really no way to address this without government regulation on ISP's to assume the external cost of botnets coming from devices on their networks. And the only way to justify that is to modify our computer crime laws to allow them to scan, patch, maybe even brick (or just turn off the customer's Internet and notify them) when vulnerable devices are found.

Re: A vigilante trying to improve IoT security

#67
post #20

Earlier quoted context omitted.

wait a fucking minute people are connecting medical devices to the internet?

It might not be connected to the internet in an IoT way, but it makes a lot of sense to connect a device to a wi-fi network if you need to wirelessly transmit any form of data.

IoT way? I do not think you can trust traffic to stay local and not leak. This kind of thinking is what got is here.

Re: A vigilante trying to improve IoT security

#68

It's all fine and well until one of those improperly configured devices are a medical device or something critical. Yes I understand that's part of the problem, but proving a point with risk isn't the right answer either. Every Dialysis machine i've seen runs windows xp, which any security professional will tell you is game over, but given the market hasn't provided an alternative, it's becomes a necessity to figure…

Meh. This attack is going after the easiest of targets. If a medical device or something critical is victim to this, they should cease to exist. I find it easy to believe that this attack protects far more people in the long run than it will ever hurt right now, and I'm willing to take that side of the moral dilemma.

It would be nice if we could live in a world where we all trust each other, and maybe with physical things this is attainable. But the IoT is a worldwide attack surface. It's open to nefarious actors ranging from junkies with stolen laptops, all the way to state-sponsored hacking organizations with billion dollar budgets. Trust and goodwill aren't options anymore.

Re: A vigilante trying to improve IoT security

#69

It's all fine and well until one of those improperly configured devices are a medical device or something critical. Yes I understand that's part of the problem, but proving a point with risk isn't the right answer either. Every Dialysis machine i've seen runs windows xp, which any security professional will tell you is game over, but given the market hasn't provided an alternative, it's becomes a necessity to figure…

Is there any evidence that BrickerBot targets medical devices?

No. In fact there is evidence that it does not specifically target them. However, they belong to a set of devices that may be affected by it.

Re: A vigilante trying to improve IoT security

#70
post #59

It's all fine and well until one of those improperly configured devices are a medical device or something critical. Yes I understand that's part of the problem, but proving a point with risk isn't the right answer either. Every Dialysis machine i've seen runs windows xp, which any security professional will tell you is game over, but given the market hasn't provided an alternative, it's becomes a necessity to figure…

devices that can kill people have another level of security then random iot devices.

> Should
Post reply on HN