Live data from Hacker News

A vigilante trying to improve IoT security

gizmodo.com

81–90 of 242 posts

Re: A vigilante trying to improve IoT security

#81

It's all fine and well until one of those improperly configured devices are a medical device or something critical. Yes I understand that's part of the problem, but proving a point with risk isn't the right answer either. Every Dialysis machine i've seen runs windows xp, which any security professional will tell you is game over, but given the market hasn't provided an alternative, it's becomes a necessity to figure…

I experience something akin to this at work all the time. There's the real-world pragmatists and the software purity philosophers. Tell the family of someone killed that, "____ shouldn't have purchased a device without knowing how to secure it!"

Tell the family that the device was defective, and the manufacturer is entirely to blame. It's the simple truth, no need to try to blame the deceased.

Re: A vigilante trying to improve IoT security

#82
post #13

It's all fine and well until one of those improperly configured devices are a medical device or something critical. Yes I understand that's part of the problem, but proving a point with risk isn't the right answer either. Every Dialysis machine i've seen runs windows xp, which any security professional will tell you is game over, but given the market hasn't provided an alternative, it's becomes a necessity to figure…

To be fair, we don't know that the malware doesn't have a whitelist of devices approved to attack.

The description in the article did imply it's seeking very specific targets.

First, Second, erases and corrupts? Unless I'm missing my mark, bricking a device that's running on firmware takes a fair bit more targeting than just adding it to a botnet.

edit: Ars has more info: https://arstechnica.com/security/2017/04/brickerbot-the-perm...

Apparently it specifically targets devices open to Mirai, and claims a 2,000,000+ kill count. Not sure what that means for medical gear, but it does mean XP is safe.

Re: A vigilante trying to improve IoT security

#83

Earlier quoted context omitted.

I'm the author of the Gizmodo post. Having covered IoT hacks for a few years, it's obvious that drastic measures would be necessary to convince manufacturers to build more secure products. While I'm not necessarily endorsing this hacker's methods, I do salute his taking a stand. It might land him in jail. But still, the mission is worthwhile.

This captures the essence of the type of activism that I so dislike — an unaffected, third party (a person who doesn't use your bluetooth lightbulb) taking the job upon himself to tell you what level of security your lightbulb should employ... By breaking it.

I'll choose a boogeyman you can perhaps appreciate: You bluetooth lightbulb is enabling pedophiles with anonymity, and you may take the fall when you're mistaken as the source of the requests. (You can swap out the boogeyman with terrorists, spammers, credit card thiefs, etc)

Re: A vigilante trying to improve IoT security

#84

It's all fine and well until one of those improperly configured devices are a medical device or something critical. Yes I understand that's part of the problem, but proving a point with risk isn't the right answer either. Every Dialysis machine i've seen runs windows xp, which any security professional will tell you is game over, but given the market hasn't provided an alternative, it's becomes a necessity to figure…

Okay but why does a dialysis machine need to be on the internet? Even if it's done to forward reports regarding the usage of the machine that can be done in a daily dump when you swap it out I'm guessing, right? So, it doesn't need to be an always-on device with respect to its NIC. Plus, there's no benefit to the user to have their life giving machinery be online. It's just another thing to overcharge the hospital for all in the false name of productivity.

Re: A vigilante trying to improve IoT security

#85
post #16
post #15

Earlier quoted context omitted.

Yes. In fact, I'm going to start stealing bikes that have insecure locks.

What kind of stupid person would think that we could have a cooperative, functional society where I can just be careless with my bike, right? What's the problem with these people? Sarcasm aside, I live in Brazil, ask any Brazilian who stayed on an European country what was the biggest difference: "I could feel safe anytime, without worrying about my stuff". That really shapes the mind and behaviour of people.

> What kind of stupid person would think that we could have a cooperative, functional society where I can just be careless with my bike, right?

Isn't this actually a really common sentiment, though? I've lived in several places where leaving a bike unlocked for 5 minutes, or sloppily locked for an hour, means you're going to lose it.

That doesn't make the theft acceptable, but if a friend borrowed your bike and left it unlocked you'd still get mad at them.

Reshaping society so this stuff doesn't happen is great, but on an inside-view level we treat crime as sort of an inevitable "someone will do it" force.

Re: A vigilante trying to improve IoT security

#86

Earlier quoted context omitted.

I'm the author of the Gizmodo post. Having covered IoT hacks for a few years, it's obvious that drastic measures would be necessary to convince manufacturers to build more secure products. While I'm not necessarily endorsing this hacker's methods, I do salute his taking a stand. It might land him in jail. But still, the mission is worthwhile.

This captures the essence of the type of activism that I so dislike — an unaffected, third party (a person who doesn't use your bluetooth lightbulb) taking the job upon himself to tell you what level of security your lightbulb should employ... By breaking it.

https://www.theguardian.com/technology/2016/oct/26/ddos-atta...

Very few people that use the internet were unaffected by shitty IoT security. And that seems like it was just the start of it's capabilities. Something needs to be done to destroy these cyber weapons. If your stupid light bulb is recruited into a cyber weapon, then it should be prevented from harming others.

Re: A vigilante trying to improve IoT security

#87

Earlier quoted context omitted.

I'm the author of the Gizmodo post. Having covered IoT hacks for a few years, it's obvious that drastic measures would be necessary to convince manufacturers to build more secure products. While I'm not necessarily endorsing this hacker's methods, I do salute his taking a stand. It might land him in jail. But still, the mission is worthwhile.

Engineering needs to stop being subordinate to anything but top management (if at all). An MBA can always outrank an engineer's decision and that is a big reason why we have crap devices out in the field.

Without labor laws to back something like this up, all it does is get engineers fired. Non-software engineering fields do have such laws, I believe. An MBA cannot make a civil engineer build a bridge that is unsafe because they want to save money. After all, it's the project engineer's signature on the final work. (Please correct me if I'm wrong.) On the other hand, a large proportion of startups are doing something illegal or unethical and the only recourse for the engineer there is to quit or be fired. In some egregious cases, that may be worth it. Mostly, it's not. That's how our labor system is set up. I've always said, if you want to kill someone, start a corporation. It's the easiest way to get have someone else do it for you and get away with it. Anything less than murder in business is not even a consideration (unless the business gets punished which it most likely won't be).

Re: A vigilante trying to improve IoT security

#88

Earlier quoted context omitted.

I'm the author of the Gizmodo post. Having covered IoT hacks for a few years, it's obvious that drastic measures would be necessary to convince manufacturers to build more secure products. While I'm not necessarily endorsing this hacker's methods, I do salute his taking a stand. It might land him in jail. But still, the mission is worthwhile.

Engineering needs to stop being subordinate to anything but top management (if at all). An MBA can always outrank an engineer's decision and that is a big reason why we have crap devices out in the field.

It's simply difficult to secure devices. It's hard the same way engineering is hard.

I know it's fashionable to blame the MBAs instead of blame ourselves, but at the end of it, we're the ones who write insecure code. And I don't think that if you give an engineer an extra week or two to focus on security that you'd end up with a measurably more secure device. Securing something is a different skillset from building it.

Pentests are probably the answer.

Re: A vigilante trying to improve IoT security

#89
post #64

Earlier quoted context omitted.

Having a bad lock on your bike generally doesn't cause much harm to others. Allowing your hardware to be used for, e.g., DDOS attacks does.

I understand what you're implying, but no one is "allowing" their hardware to be used criminally. At least in the U.S., our personal property system is permissive i/e you may not use my things without permission. So, using an IoT device as provided by the manufacturer is "allowing" its misuse so much as leaving my backyard gate unlocked is "allowing" criminals to park their stolen goods in my backyard.

Ok, but we do have "attractive nuisance" laws. If you leave out a trampoline next to barbed wire, you can be accountable even if you didn't actually permit anyone to use it.

This actually seems much closer to the IoT issue than theft. The maker and user of the device have created an inviting target which will cause harm to someone other than themselves. Even if the eventual attack is illegal, they can still be held accountable for making it so likely.

Re: A vigilante trying to improve IoT security

#90
post #4

Slightly OT, but not too long ago I read that it is not uncommon for viruses to remove other known, competing, malware. Does anyone know if anyone has ever made a virus who's only purpose is to remove other malware? Perhaps the same aggressive approach used by Janit0r is needed to stop the spread of worms, kill off botnets etc.?

A brief history: https://en.wikipedia.org/wiki/Anti-worm
Post reply on HN