It's all fine and well until one of those improperly configured devices are a medical device or something critical. Yes I understand that's part of the problem, but proving a point with risk isn't the right answer either. Every Dialysis machine i've seen runs windows xp, which any security professional will tell you is game over, but given the market hasn't provided an alternative, it's becomes a necessity to figure…
I experience something akin to this at work all the time. There's the real-world pragmatists and the software purity philosophers. Tell the family of someone killed that, "____ shouldn't have purchased a device without knowing how to secure it!"
A vigilante trying to improve IoT security
81–90 of 242 posts
Re: A vigilante trying to improve IoT security
#82It's all fine and well until one of those improperly configured devices are a medical device or something critical. Yes I understand that's part of the problem, but proving a point with risk isn't the right answer either. Every Dialysis machine i've seen runs windows xp, which any security professional will tell you is game over, but given the market hasn't provided an alternative, it's becomes a necessity to figure…
To be fair, we don't know that the malware doesn't have a whitelist of devices approved to attack.
First, Second, erases and corrupts? Unless I'm missing my mark, bricking a device that's running on firmware takes a fair bit more targeting than just adding it to a botnet.
edit: Ars has more info: https://arstechnica.com/security/2017/04/brickerbot-the-perm...
Apparently it specifically targets devices open to Mirai, and claims a 2,000,000+ kill count. Not sure what that means for medical gear, but it does mean XP is safe.
Re: A vigilante trying to improve IoT security
#83Earlier quoted context omitted.
I'm the author of the Gizmodo post. Having covered IoT hacks for a few years, it's obvious that drastic measures would be necessary to convince manufacturers to build more secure products. While I'm not necessarily endorsing this hacker's methods, I do salute his taking a stand. It might land him in jail. But still, the mission is worthwhile.
This captures the essence of the type of activism that I so dislike — an unaffected, third party (a person who doesn't use your bluetooth lightbulb) taking the job upon himself to tell you what level of security your lightbulb should employ... By breaking it.
Re: A vigilante trying to improve IoT security
#84It's all fine and well until one of those improperly configured devices are a medical device or something critical. Yes I understand that's part of the problem, but proving a point with risk isn't the right answer either. Every Dialysis machine i've seen runs windows xp, which any security professional will tell you is game over, but given the market hasn't provided an alternative, it's becomes a necessity to figure…
Re: A vigilante trying to improve IoT security
#85Earlier quoted context omitted.
Yes. In fact, I'm going to start stealing bikes that have insecure locks.
What kind of stupid person would think that we could have a cooperative, functional society where I can just be careless with my bike, right? What's the problem with these people? Sarcasm aside, I live in Brazil, ask any Brazilian who stayed on an European country what was the biggest difference: "I could feel safe anytime, without worrying about my stuff". That really shapes the mind and behaviour of people.
Isn't this actually a really common sentiment, though? I've lived in several places where leaving a bike unlocked for 5 minutes, or sloppily locked for an hour, means you're going to lose it.
That doesn't make the theft acceptable, but if a friend borrowed your bike and left it unlocked you'd still get mad at them.
Reshaping society so this stuff doesn't happen is great, but on an inside-view level we treat crime as sort of an inevitable "someone will do it" force.
Re: A vigilante trying to improve IoT security
#86Earlier quoted context omitted.
I'm the author of the Gizmodo post. Having covered IoT hacks for a few years, it's obvious that drastic measures would be necessary to convince manufacturers to build more secure products. While I'm not necessarily endorsing this hacker's methods, I do salute his taking a stand. It might land him in jail. But still, the mission is worthwhile.
This captures the essence of the type of activism that I so dislike — an unaffected, third party (a person who doesn't use your bluetooth lightbulb) taking the job upon himself to tell you what level of security your lightbulb should employ... By breaking it.
Very few people that use the internet were unaffected by shitty IoT security. And that seems like it was just the start of it's capabilities. Something needs to be done to destroy these cyber weapons. If your stupid light bulb is recruited into a cyber weapon, then it should be prevented from harming others.
Re: A vigilante trying to improve IoT security
#87Earlier quoted context omitted.
I'm the author of the Gizmodo post. Having covered IoT hacks for a few years, it's obvious that drastic measures would be necessary to convince manufacturers to build more secure products. While I'm not necessarily endorsing this hacker's methods, I do salute his taking a stand. It might land him in jail. But still, the mission is worthwhile.
Engineering needs to stop being subordinate to anything but top management (if at all). An MBA can always outrank an engineer's decision and that is a big reason why we have crap devices out in the field.
Re: A vigilante trying to improve IoT security
#88Earlier quoted context omitted.
I'm the author of the Gizmodo post. Having covered IoT hacks for a few years, it's obvious that drastic measures would be necessary to convince manufacturers to build more secure products. While I'm not necessarily endorsing this hacker's methods, I do salute his taking a stand. It might land him in jail. But still, the mission is worthwhile.
Engineering needs to stop being subordinate to anything but top management (if at all). An MBA can always outrank an engineer's decision and that is a big reason why we have crap devices out in the field.
I know it's fashionable to blame the MBAs instead of blame ourselves, but at the end of it, we're the ones who write insecure code. And I don't think that if you give an engineer an extra week or two to focus on security that you'd end up with a measurably more secure device. Securing something is a different skillset from building it.
Pentests are probably the answer.
Re: A vigilante trying to improve IoT security
#89Earlier quoted context omitted.
Having a bad lock on your bike generally doesn't cause much harm to others. Allowing your hardware to be used for, e.g., DDOS attacks does.
I understand what you're implying, but no one is "allowing" their hardware to be used criminally. At least in the U.S., our personal property system is permissive i/e you may not use my things without permission. So, using an IoT device as provided by the manufacturer is "allowing" its misuse so much as leaving my backyard gate unlocked is "allowing" criminals to park their stolen goods in my backyard.
This actually seems much closer to the IoT issue than theft. The maker and user of the device have created an inviting target which will cause harm to someone other than themselves. Even if the eventual attack is illegal, they can still be held accountable for making it so likely.
Re: A vigilante trying to improve IoT security
#90Slightly OT, but not too long ago I read that it is not uncommon for viruses to remove other known, competing, malware. Does anyone know if anyone has ever made a virus who's only purpose is to remove other malware? Perhaps the same aggressive approach used by Janit0r is needed to stop the spread of worms, kill off botnets etc.?