It's all fine and well until one of those improperly configured devices are a medical device or something critical. Yes I understand that's part of the problem, but proving a point with risk isn't the right answer either. Every Dialysis machine i've seen runs windows xp, which any security professional will tell you is game over, but given the market hasn't provided an alternative, it's becomes a necessity to figure…
I experience something akin to this at work all the time. There's the real-world pragmatists and the software purity philosophers. Tell the family of someone killed that, "____ shouldn't have purchased a device without knowing how to secure it!"
A vigilante trying to improve IoT security
61–70 of 242 posts
Re: A vigilante trying to improve IoT security
#62It takes a special kind of entitled to destroy people's things and to then blame others (the manufacturers) for it.
Do you force the situation and make it mow into your yard and over a bunch of rocks to destroy it, or do you live with the danger?
I don't have an answer. In this situation you could at least talk to your neighbor. Without the ability to feasibly do that, I'm not sure I would fault either action.
Re: A vigilante trying to improve IoT security
#63Earlier quoted context omitted.
I find the arguments for "taking a stand" quite weak. Normally with subcultures that break the law or in other ways inconvenience people the moral argument is that you're doing something that isn't available to you (often as a group) and your actions themselves are meaningful (often because it makes it available to you). I don't really see in this case how they (or mostly anyone) is unable to improve IoT (or general)…
"I don't really see in this case how they (or mostly anyone) is unable to improve IoT (or general) security through other means" Really? How about you show me the evidence that people are... through "other means"... improving IOT security of these devices enough that DDOS isn't a big problem any more. I'd love to hear what you've done to convince all the vendors to focus on secure devices instead of profit when targe…
Altough i wonder: why didn't someone with deep security expertise, maybe ARM with it's mbed,created something developers can't harm, and on the other hand, issue a product label saying:"this is protected by our stack..." ?
I could see that be attractive to some b2b buyers, attracting devs, further strengthening the value of said label , increasing marketshare and reducing costs, and creating a positive feedback.
Re: A vigilante trying to improve IoT security
#64Earlier quoted context omitted.
Yes. In fact, I'm going to start stealing bikes that have insecure locks.
Having a bad lock on your bike generally doesn't cause much harm to others. Allowing your hardware to be used for, e.g., DDOS attacks does.
Re: A vigilante trying to improve IoT security
#65Re: A vigilante trying to improve IoT security
#66Re: A vigilante trying to improve IoT security
#67Earlier quoted context omitted.
wait a fucking minute people are connecting medical devices to the internet?
It might not be connected to the internet in an IoT way, but it makes a lot of sense to connect a device to a wi-fi network if you need to wirelessly transmit any form of data.
Re: A vigilante trying to improve IoT security
#68It's all fine and well until one of those improperly configured devices are a medical device or something critical. Yes I understand that's part of the problem, but proving a point with risk isn't the right answer either. Every Dialysis machine i've seen runs windows xp, which any security professional will tell you is game over, but given the market hasn't provided an alternative, it's becomes a necessity to figure…
It would be nice if we could live in a world where we all trust each other, and maybe with physical things this is attainable. But the IoT is a worldwide attack surface. It's open to nefarious actors ranging from junkies with stolen laptops, all the way to state-sponsored hacking organizations with billion dollar budgets. Trust and goodwill aren't options anymore.
Re: A vigilante trying to improve IoT security
#69It's all fine and well until one of those improperly configured devices are a medical device or something critical. Yes I understand that's part of the problem, but proving a point with risk isn't the right answer either. Every Dialysis machine i've seen runs windows xp, which any security professional will tell you is game over, but given the market hasn't provided an alternative, it's becomes a necessity to figure…
Is there any evidence that BrickerBot targets medical devices?
Re: A vigilante trying to improve IoT security
#70It's all fine and well until one of those improperly configured devices are a medical device or something critical. Yes I understand that's part of the problem, but proving a point with risk isn't the right answer either. Every Dialysis machine i've seen runs windows xp, which any security professional will tell you is game over, but given the market hasn't provided an alternative, it's becomes a necessity to figure…
devices that can kill people have another level of security then random iot devices.