Live data from Hacker News

A vigilante trying to improve IoT security

gizmodo.com

71–80 of 242 posts

Re: A vigilante trying to improve IoT security

#71
post #66

I toyed with a similar idea that would be limited to subnets or non-routable IP space, and open-source/community-driven, but I had to take it down almost immediately due to bad press/backlash. There's really no way to address this without government regulation on ISP's to assume the external cost of botnets coming from devices on their networks. And the only way to justify that is to modify our computer crime laws to…

Links to the press? Always interested in how these things are handled.

Re: A vigilante trying to improve IoT security

#72

It's all fine and well until one of those improperly configured devices are a medical device or something critical. Yes I understand that's part of the problem, but proving a point with risk isn't the right answer either. Every Dialysis machine i've seen runs windows xp, which any security professional will tell you is game over, but given the market hasn't provided an alternative, it's becomes a necessity to figure…

I'm the author of the Gizmodo post. Having covered IoT hacks for a few years, it's obvious that drastic measures would be necessary to convince manufacturers to build more secure products. While I'm not necessarily endorsing this hacker's methods, I do salute his taking a stand. It might land him in jail. But still, the mission is worthwhile.

This captures the essence of the type of activism that I so dislike — an unaffected, third party (a person who doesn't use your bluetooth lightbulb) taking the job upon himself to tell you what level of security your lightbulb should employ... By breaking it.

Re: A vigilante trying to improve IoT security

#73
post #62
post #9

It takes a special kind of entitled to destroy people's things and to then blame others (the manufacturers) for it.

It's sort of like your neighbor having an automated lawnmower, and you knowing that with a careful placement of rocks the image recognition will fritz and it will happily start mowing into your yard, over your petunias and possibly your small children and animals. You're fairly certain that there are other problems with it you don't know about as well. Do you force the situation and make it mow into your yard and ove…

Think about it. If you have kids or pets or flowers, seems like it would be prudent trigger the event in a more safe, and known environment than to leave to chance (of injury to property or 3rd party). Seems like talking to the neighbor happened over a decade ago to me.

Re: A vigilante trying to improve IoT security

#74
post #66

I toyed with a similar idea that would be limited to subnets or non-routable IP space, and open-source/community-driven, but I had to take it down almost immediately due to bad press/backlash. There's really no way to address this without government regulation on ISP's to assume the external cost of botnets coming from devices on their networks. And the only way to justify that is to modify our computer crime laws to…

do you really think it's a good idea to give a badge and a gun to corporate ISPs? that opens the door for so much invasion of privacy.

Re: A vigilante trying to improve IoT security

#75

Earlier quoted context omitted.

I'm the author of the Gizmodo post. Having covered IoT hacks for a few years, it's obvious that drastic measures would be necessary to convince manufacturers to build more secure products. While I'm not necessarily endorsing this hacker's methods, I do salute his taking a stand. It might land him in jail. But still, the mission is worthwhile.

This captures the essence of the type of activism that I so dislike — an unaffected, third party (a person who doesn't use your bluetooth lightbulb) taking the job upon himself to tell you what level of security your lightbulb should employ... By breaking it.

Is it an unaffected third party, when your unsecured lightbulb is participating in a DoS that knocks out some service he's relying on?

Re: A vigilante trying to improve IoT security

#76
post #62

Earlier quoted context omitted.

It's sort of like your neighbor having an automated lawnmower, and you knowing that with a careful placement of rocks the image recognition will fritz and it will happily start mowing into your yard, over your petunias and possibly your small children and animals. You're fairly certain that there are other problems with it you don't know about as well. Do you force the situation and make it mow into your yard and ove…

Think about it. If you have kids or pets or flowers, seems like it would be prudent trigger the event in a more safe, and known environment than to leave to chance (of injury to property or 3rd party). Seems like talking to the neighbor happened over a decade ago to me.

Sure, depending on the chances of it happening. The problem is that we don't know what the chances are, and as a species we're fairly bad at assessing stuff like that in general. If it's a million-to-one chance, there are probably plenty of other more worthy perils to be concerned with first. If it's a hundred-to-one chance, it may be an imminent threat. Which is it? How do you trust that the person telling you the odds isn't vastly over or under estimating the chances?

The answer falls into an area that's somewhat unknowable with current information, which is why I can't fault either behavior.

Re: A vigilante trying to improve IoT security

#77

Earlier quoted context omitted.

I'm the author of the Gizmodo post. Having covered IoT hacks for a few years, it's obvious that drastic measures would be necessary to convince manufacturers to build more secure products. While I'm not necessarily endorsing this hacker's methods, I do salute his taking a stand. It might land him in jail. But still, the mission is worthwhile.

This captures the essence of the type of activism that I so dislike — an unaffected, third party (a person who doesn't use your bluetooth lightbulb) taking the job upon himself to tell you what level of security your lightbulb should employ... By breaking it.

How is anyone unaffected when IoT devices with bad security break the net?

Re: A vigilante trying to improve IoT security

#78

Earlier quoted context omitted.

I'm the author of the Gizmodo post. Having covered IoT hacks for a few years, it's obvious that drastic measures would be necessary to convince manufacturers to build more secure products. While I'm not necessarily endorsing this hacker's methods, I do salute his taking a stand. It might land him in jail. But still, the mission is worthwhile.

This captures the essence of the type of activism that I so dislike — an unaffected, third party (a person who doesn't use your bluetooth lightbulb) taking the job upon himself to tell you what level of security your lightbulb should employ... By breaking it.

We're not unaffected anymore. Mirai did a lot of damage to a lot of people. Very diffuse damage, sure, but a lot of damage.

Note we've had worms and such for decades now and most of them don't deliberately break things. It's generally far more profitable to exploit the resources than simply destroy them. Brickerbot almost certainly wouldn't be if we weren't all getting affected.

Re: A vigilante trying to improve IoT security

#79

Earlier quoted context omitted.

I'm the author of the Gizmodo post. Having covered IoT hacks for a few years, it's obvious that drastic measures would be necessary to convince manufacturers to build more secure products. While I'm not necessarily endorsing this hacker's methods, I do salute his taking a stand. It might land him in jail. But still, the mission is worthwhile.

This captures the essence of the type of activism that I so dislike — an unaffected, third party (a person who doesn't use your bluetooth lightbulb) taking the job upon himself to tell you what level of security your lightbulb should employ... By breaking it.

Then fix your lightbulb so that someone can't tell you how to handle your lightbulbs. If you can't reach that low bar then why are you even connecting to the internet? You are implicitly allowing your tools to be used for botnets which should be a crime in itself.

Re: A vigilante trying to improve IoT security

#80

It's all fine and well until one of those improperly configured devices are a medical device or something critical. Yes I understand that's part of the problem, but proving a point with risk isn't the right answer either. Every Dialysis machine i've seen runs windows xp, which any security professional will tell you is game over, but given the market hasn't provided an alternative, it's becomes a necessity to figure…

I'm the author of the Gizmodo post. Having covered IoT hacks for a few years, it's obvious that drastic measures would be necessary to convince manufacturers to build more secure products. While I'm not necessarily endorsing this hacker's methods, I do salute his taking a stand. It might land him in jail. But still, the mission is worthwhile.

Engineering needs to stop being subordinate to anything but top management (if at all). An MBA can always outrank an engineer's decision and that is a big reason why we have crap devices out in the field.
Post reply on HN