Live data from Hacker News

A vigilante trying to improve IoT security

gizmodo.com

91–100 of 242 posts

Re: A vigilante trying to improve IoT security

#91
post #63

Earlier quoted context omitted.

"I don't really see in this case how they (or mostly anyone) is unable to improve IoT (or general) security through other means" Really? How about you show me the evidence that people are... through "other means"... improving IOT security of these devices enough that DDOS isn't a big problem any more. I'd love to hear what you've done to convince all the vendors to focus on secure devices instead of profit when targe…

That's true. Altough i wonder: why didn't someone with deep security expertise, maybe ARM with it's mbed,created something developers can't harm, and on the other hand, issue a product label saying:"this is protected by our stack..." ? I could see that be attractive to some b2b buyers, attracting devs, further strengthening the value of said label , increasing marketshare and reducing costs, and creating a positive f…

They did. It's mostly bs, though, since they cut corners too or cant impact the software lifecycle enough. Few people trust those labels. It could still be done, though, in a way along lines of Underwriter Laboratories and Consumer Reports with private evaluations.

Re: A vigilante trying to improve IoT security

#92
post #25

Earlier quoted context omitted.

I'm the author of the Gizmodo post. Having covered IoT hacks for a few years, it's obvious that drastic measures would be necessary to convince manufacturers to build more secure products. While I'm not necessarily endorsing this hacker's methods, I do salute his taking a stand. It might land him in jail. But still, the mission is worthwhile.

Did you not have any input into this headline? It is a clear endorsement.

For those confused by this comment, the actual title of the piece is: "This Hacker Is My New Hero".

Re: A vigilante trying to improve IoT security

#93
post #76

Earlier quoted context omitted.

Think about it. If you have kids or pets or flowers, seems like it would be prudent trigger the event in a more safe, and known environment than to leave to chance (of injury to property or 3rd party). Seems like talking to the neighbor happened over a decade ago to me.

Sure, depending on the chances of it happening . The problem is that we don't know what the chances are, and as a species we're fairly bad at assessing stuff like that in general. If it's a million-to-one chance, there are probably plenty of other more worthy perils to be concerned with first. If it's a hundred-to-one chance, it may be an imminent threat. Which is it? How do you trust that the person telling you the…

I think the issue is less the chance of the lawnmower going wild by itself (because screw that, I don't care how small the chance is, it's not acceptable), and more the chance of the lawnmower exploding, taking out your eye when you trigger it's failure it yourself.

As in, "the chance of getting hacked" < "the chance of the vigilante creating dangerous situations".

Re: A vigilante trying to improve IoT security

#95
post #76

Earlier quoted context omitted.

Think about it. If you have kids or pets or flowers, seems like it would be prudent trigger the event in a more safe, and known environment than to leave to chance (of injury to property or 3rd party). Seems like talking to the neighbor happened over a decade ago to me.

Sure, depending on the chances of it happening . The problem is that we don't know what the chances are, and as a species we're fairly bad at assessing stuff like that in general. If it's a million-to-one chance, there are probably plenty of other more worthy perils to be concerned with first. If it's a hundred-to-one chance, it may be an imminent threat. Which is it? How do you trust that the person telling you the…

I disagree. We know that the probability of it happening again is very high, seeing as it has already happened multiple times, and no serious action has been taken to improve the situation. If we were speculating about a theoretical risk, I would agree with you.

Re: A vigilante trying to improve IoT security

#96
post #79

Earlier quoted context omitted.

This captures the essence of the type of activism that I so dislike — an unaffected, third party (a person who doesn't use your bluetooth lightbulb) taking the job upon himself to tell you what level of security your lightbulb should employ... By breaking it.

Then fix your lightbulb so that someone can't tell you how to handle your lightbulbs. If you can't reach that low bar then why are you even connecting to the internet? You are implicitly allowing your tools to be used for botnets which should be a crime in itself.

So you think the consumers should be punished for something you think the producers do wrong? Do you apply this to other products as well? Would it be ok to soak peoples cigarettes in water, break the motor of your neighbours high fuel consuming SUV or destroy the guns of people since these products can cause damage to other people?

Re: A vigilante trying to improve IoT security

#97
post #52

Earlier quoted context omitted.

I find the arguments for "taking a stand" quite weak. Normally with subcultures that break the law or in other ways inconvenience people the moral argument is that you're doing something that isn't available to you (often as a group) and your actions themselves are meaningful (often because it makes it available to you). I don't really see in this case how they (or mostly anyone) is unable to improve IoT (or general)…

"I don't really see in this case how they (or mostly anyone) is unable to improve IoT (or general) security through other means" Really? How about you show me the evidence that people are... through "other means"... improving IOT security of these devices enough that DDOS isn't a big problem any more. I'd love to hear what you've done to convince all the vendors to focus on secure devices instead of profit when targe…

> How about you show me the evidence that people are [...]

I've made my argument. Why don't you take part in the discussion and make some of your own to why this is meaningful?

> I'd love to hear what you've done to convince all the vendors [...]

Why is it at all relevant what I've done and especially since when you don't say what you've done?

> Most of us in INFOSEC haven't been able to convince [...]

I haven't seen much convincing being done. "INFOSEC" (all caps of course because we want to be cool like the military) by itself tends to be a label for people who are relatively far from the development process.

> The only time vendors ever delivered secure or safe solutions was when sound regulations were forced on them with a requirement they were followed before a purchase was made.

Yes, you're still not making an argument why these actions would in any way would be a effective way to regulation.

Re: A vigilante trying to improve IoT security

#98

It's all fine and well until one of those improperly configured devices are a medical device or something critical. Yes I understand that's part of the problem, but proving a point with risk isn't the right answer either. Every Dialysis machine i've seen runs windows xp, which any security professional will tell you is game over, but given the market hasn't provided an alternative, it's becomes a necessity to figure…

Okay but why does a dialysis machine need to be on the internet? Even if it's done to forward reports regarding the usage of the machine that can be done in a daily dump when you swap it out I'm guessing, right? So, it doesn't need to be an always-on device with respect to its NIC. Plus, there's no benefit to the user to have their life giving machinery be online. It's just another thing to overcharge the hospital fo…

It is not on the net, but it is on a LAN that has a firewall somewhere that is leaky.

This because it is cheaper in the short run to string a single physical network and then use vlans etc to attempt to keep medical stuff from talking to accounting or the visitors WiFi.

This so a single overworked nurse can monitor a number of patients from a bank of monitors hooked to a thin client near the ward entrance.

Re: A vigilante trying to improve IoT security

#99

Earlier quoted context omitted.

Engineering needs to stop being subordinate to anything but top management (if at all). An MBA can always outrank an engineer's decision and that is a big reason why we have crap devices out in the field.

It's simply difficult to secure devices. It's hard the same way engineering is hard. I know it's fashionable to blame the MBAs instead of blame ourselves, but at the end of it, we're the ones who write insecure code. And I don't think that if you give an engineer an extra week or two to focus on security that you'd end up with a measurably more secure device. Securing something is a different skillset from building i…

Secure against a dedicated attacker, yes. But telnet listening on port 23 and a conistent default admin password on all your devices is really not that hard to improve on (and that's the sort of device that BrickerBot is killing).

Re: A vigilante trying to improve IoT security

#100

Earlier quoted context omitted.

It's simply difficult to secure devices. It's hard the same way engineering is hard. I know it's fashionable to blame the MBAs instead of blame ourselves, but at the end of it, we're the ones who write insecure code. And I don't think that if you give an engineer an extra week or two to focus on security that you'd end up with a measurably more secure device. Securing something is a different skillset from building i…

Secure against a dedicated attacker, yes. But telnet listening on port 23 and a conistent default admin password on all your devices is really not that hard to improve on (and that's the sort of device that BrickerBot is killing).

Perhaps. But someone thought it was a good idea to put up a telnet port 23 default-admin-password interface. The point is, if you give that person two weeks to focus on securing the product, I'm not sure they would realize it's a bad idea to do that. People who are bad at security don't realize they're bad at security. Which is why it's probably important to bring in an outside team to break the product.

Or to put it another way, if we're not proposing to bring in an outside team to conduct a pentest, what's the alternative?

Post reply on HN