Live data from Hacker News

A vigilante trying to improve IoT security

gizmodo.com

101–110 of 242 posts

Re: A vigilante trying to improve IoT security

#101

It's all fine and well until one of those improperly configured devices are a medical device or something critical. Yes I understand that's part of the problem, but proving a point with risk isn't the right answer either. Every Dialysis machine i've seen runs windows xp, which any security professional will tell you is game over, but given the market hasn't provided an alternative, it's becomes a necessity to figure…

Meh. This attack is going after the easiest of targets. If a medical device or something critical is victim to this, they should cease to exist. I find it easy to believe that this attack protects far more people in the long run than it will ever hurt right now, and I'm willing to take that side of the moral dilemma. It would be nice if we could live in a world where we all trust each other, and maybe with physical t…

Where do you draw the line, I could argue because we know that certain vehicles are remotely hackable we should just disable all the cars without regard to their status of use. Literally 0 difference in argument, yet the results would somehow dictate a different response.

Re: A vigilante trying to improve IoT security

#102
post #59

It's all fine and well until one of those improperly configured devices are a medical device or something critical. Yes I understand that's part of the problem, but proving a point with risk isn't the right answer either. Every Dialysis machine i've seen runs windows xp, which any security professional will tell you is game over, but given the market hasn't provided an alternative, it's becomes a necessity to figure…

devices that can kill people have another level of security then random iot devices.

Sadly, they don't. What about a car that has vulnerable software? It's not a medical device but could have a real world effect if the same actions were taken.

Re: A vigilante trying to improve IoT security

#103

It's all fine and well until one of those improperly configured devices are a medical device or something critical. Yes I understand that's part of the problem, but proving a point with risk isn't the right answer either. Every Dialysis machine i've seen runs windows xp, which any security professional will tell you is game over, but given the market hasn't provided an alternative, it's becomes a necessity to figure…

"It's all fine and well until one of those improperly configured devices are a medical device or something critical. " It would be their fault. High-assurance industry has been telling SCADA and medical industry to get their shit together for a long time. This included pentests showing it could all be destroyed. They even have people at conferences talking about it with products or basic advice to deal with it. The r…

I've brought this up to others, how would you feel if someone decided to brick / modify your car without you knowing? What would you do if that fix backfired and caused damage, hard locked the controls on your car, or worse, simply shut it off at the wrong time? We absolutely need to fix these issues, the governments of the world need to enforce standards on products, but vigilantism no matter how much you may agree with, has to be treated the same across the line.

Re: A vigilante trying to improve IoT security

#104

It's all fine and well until one of those improperly configured devices are a medical device or something critical. Yes I understand that's part of the problem, but proving a point with risk isn't the right answer either. Every Dialysis machine i've seen runs windows xp, which any security professional will tell you is game over, but given the market hasn't provided an alternative, it's becomes a necessity to figure…

I'm the author of the Gizmodo post. Having covered IoT hacks for a few years, it's obvious that drastic measures would be necessary to convince manufacturers to build more secure products. While I'm not necessarily endorsing this hacker's methods, I do salute his taking a stand. It might land him in jail. But still, the mission is worthwhile.

What would your perspective be if I took a stance to secure your vehicle, or the power company, or any myriad of others simply because I chose to?

What do you do when I change my logic to, well this is a ZERO DAY exploit, but you need to be patched, without understanding the complexities of your device or network. Which we all know QA takes a while because of variables. Look at any microsoft patch for evidence of that. Your argument makes it seem like if I decide to weaponize the Shadow Brokers toolkit to lockdown and secure networks around the globe, i'm ok because my intentions are good and manufacturers should have secure code without 0 days. What happens when a proprietary driver or component fails because of a change made to the kernel or the way it handles driver functionality? Now I've broken / disabled something because I didn't know the intricacies and instead chose to do what I thought was right.

"No good deed goes unpunished"

Re: A vigilante trying to improve IoT security

#105
> if somebody launched a car or power tool with a safety feature that failed 9 times out of 10 it would be pulled off the market immediately. I don’t see why dangerously designed IoT devices should be treated any differently

Really? He doesn't see how a car is different from a webcam? And why there are different safety standards for each?

Their goal is laudable, but this seems like a fun way to engage in vandalism while hiding behind an ideological aegis. The sort of thing I'd do when I was 15.

Re: A vigilante trying to improve IoT security

#106
post #64

Earlier quoted context omitted.

I understand what you're implying, but no one is "allowing" their hardware to be used criminally. At least in the U.S., our personal property system is permissive i/e you may not use my things without permission. So, using an IoT device as provided by the manufacturer is "allowing" its misuse so much as leaving my backyard gate unlocked is "allowing" criminals to park their stolen goods in my backyard.

Ok, but we do have "attractive nuisance" laws. If you leave out a trampoline next to barbed wire, you can be accountable even if you didn't actually permit anyone to use it. This actually seems much closer to the IoT issue than theft. The maker and user of the device have created an inviting target which will cause harm to someone other than themselves. Even if the eventual attack is illegal, they can still be held a…

Honestly, I've never heard of a law like that. The U.S. is a big place; whereas that may be the case in parts of the country, in the south where I'm from, that's never become known to me, especially in the rural areas where I grew up. Instead, the people using your things without permission are at the very least trespassing.

Re: A vigilante trying to improve IoT security

#107
post #96
post #79

Earlier quoted context omitted.

Then fix your lightbulb so that someone can't tell you how to handle your lightbulbs. If you can't reach that low bar then why are you even connecting to the internet? You are implicitly allowing your tools to be used for botnets which should be a crime in itself.

So you think the consumers should be punished for something you think the producers do wrong? Do you apply this to other products as well? Would it be ok to soak peoples cigarettes in water, break the motor of your neighbours high fuel consuming SUV or destroy the guns of people since these products can cause damage to other people?

The problem is, I think, what choice do we have (we == rest of the world) when somebody's messed up camera starts spamming the entire Internet? And how much does cost the mirai botnet to everyone when some client rents it?

Best case scenario: users claim warranty and replace their devices something better

Worst case scenario: users need to buy new gear, they probably won't buy from that same manufacturer because last one died for no apparent reason. Really worst case scenario: users buy again the same cr*p and dies again, until they realize that brand is worthless and buy something a bit better. Doesn't seem so bad, if the alternative is having their machines taking down businesses and users...

Re: A vigilante trying to improve IoT security

#108
post #60

Earlier quoted context omitted.

I'm the author of the Gizmodo post. Having covered IoT hacks for a few years, it's obvious that drastic measures would be necessary to convince manufacturers to build more secure products. While I'm not necessarily endorsing this hacker's methods, I do salute his taking a stand. It might land him in jail. But still, the mission is worthwhile.

He's providing an economic benefit to society - internalizing (to consumers) the externality of IOT botnets. It's now on the consumers to further internalize to cost to manufacturers through product selection, class action, or both.

How does your opinion change with Phishing attacks? I'm going to steal funds from businesses by phishing vulnerable people, because If I don't capitalize on it, then people won't understand the costs / risks.

Re: A vigilante trying to improve IoT security

#109

Earlier quoted context omitted.

I'm the author of the Gizmodo post. Having covered IoT hacks for a few years, it's obvious that drastic measures would be necessary to convince manufacturers to build more secure products. While I'm not necessarily endorsing this hacker's methods, I do salute his taking a stand. It might land him in jail. But still, the mission is worthwhile.

Engineering needs to stop being subordinate to anything but top management (if at all). An MBA can always outrank an engineer's decision and that is a big reason why we have crap devices out in the field.

I would argue, security needs to be a part of planning day 1 rather than looked at as a bolt on prior to involving upper management. It needs to be treated as a core functionality rather than an external concept. The biggest issue I see is we are patching and finding fixes for something that could easily be remedied if address before engineering takes place. Most firms i've worked with put it on the back burner or are stuck with the notion of i'm an engineer i'm smart so deal with it.

Re: A vigilante trying to improve IoT security

#110
post #96
post #79

Earlier quoted context omitted.

Then fix your lightbulb so that someone can't tell you how to handle your lightbulbs. If you can't reach that low bar then why are you even connecting to the internet? You are implicitly allowing your tools to be used for botnets which should be a crime in itself.

So you think the consumers should be punished for something you think the producers do wrong? Do you apply this to other products as well? Would it be ok to soak peoples cigarettes in water, break the motor of your neighbours high fuel consuming SUV or destroy the guns of people since these products can cause damage to other people?

> Would it be ok to soak peoples cigarettes in water,...

How about in arsenic? The Internet of Things is mostly insecure trash that will only be fixed by throwing it away. The manufacturers know this, and simply don't care.

Post reply on HN