Live data from Hacker News

A vigilante trying to improve IoT security

gizmodo.com

111–120 of 242 posts

Re: A vigilante trying to improve IoT security

#111
post #12
post #9

It takes a special kind of entitled to destroy people's things and to then blame others (the manufacturers) for it.

I think it's rather brilliant. It is the manufacturer's responsibility to ship secure products. Here a consumer with a bricked product will demand a replacement/refund, putting pressure on the manufacturers to not ship shitty products. It's directly applying market pressure to sellers of insecure hardware, and that's a great thing.

> Here a consumer with a bricked product will demand a replacement/refund, putting pressure on the manufacturers to not ship shitty products.

If my shitty DLink camera suddenly stopped working, I wouldn't demand a refund - realistically, I'd just toss it in the bin and try to remember not to buy more DLink products. But I probably still would, if they were sufficiently cheap.

I imagine that calculus is similar for most people.

Re: A vigilante trying to improve IoT security

#112
post #20

Earlier quoted context omitted.

wait a fucking minute people are connecting medical devices to the internet?

and not just medical devices, but life-support machines running with known security vulnerabilities? There's nothing inherently wrong with connecting medical devices to the internet, and running an outdated OS on your specialized equipment is fine too as long as it's not being connected to any unsecured networks. But running a known insecure OS on an internet connected life support device has got to be a violation of…

Experience has shown that connecting a device to the open Internet is inherently risky. I'd say any act of connecting a life-support device to the open Internet would have to balance that inherent risk against any supposed benefit such a connection might involve, even if the device manufacture is doing best practices for such a connection.

Re: A vigilante trying to improve IoT security

#113

Earlier quoted context omitted.

I'm the author of the Gizmodo post. Having covered IoT hacks for a few years, it's obvious that drastic measures would be necessary to convince manufacturers to build more secure products. While I'm not necessarily endorsing this hacker's methods, I do salute his taking a stand. It might land him in jail. But still, the mission is worthwhile.

What would your perspective be if I took a stance to secure your vehicle, or the power company, or any myriad of others simply because I chose to? What do you do when I change my logic to, well this is a ZERO DAY exploit, but you need to be patched, without understanding the complexities of your device or network. Which we all know QA takes a while because of variables. Look at any microsoft patch for evidence of tha…

A bit like my neighbor's door is wide open. Some teenagers are taking over it.

Instead of just close/lock the door for my neighbor or call the cop, I use a bulldozer to level the house to the ground. (zero out the flash.)

In theory, the "vigilante" can offer his service to device manufacturer to help remotely clean/update the devices instead of just simply wiping them off the net.

Re: A vigilante trying to improve IoT security

#114
post #106

Earlier quoted context omitted.

Ok, but we do have "attractive nuisance" laws. If you leave out a trampoline next to barbed wire, you can be accountable even if you didn't actually permit anyone to use it. This actually seems much closer to the IoT issue than theft. The maker and user of the device have created an inviting target which will cause harm to someone other than themselves. Even if the eventual attack is illegal, they can still be held a…

Honestly, I've never heard of a law like that. The U.S. is a big place; whereas that may be the case in parts of the country, in the south where I'm from, that's never become known to me, especially in the rural areas where I grew up. Instead, the people using your things without permission are at the very least trespassing.

IANAL, and I can't find a definitive statement of where the doctrine applies, but I see it referenced in cases in many US southern states (AL, GA, AR, KY, FL, TX). I know that the particulars vary in many states, based on precedent and statute, but I'm not aware of anywhere it's absent entirely. Hopefully someone more knowledgeable will come along and clarify.

Note that "attractive nuisance" is specifically about trespassing children.

https://en.wikipedia.org/wiki/Attractive_nuisance_doctrine

Re: A vigilante trying to improve IoT security

#115
post #16

Earlier quoted context omitted.

What kind of stupid person would think that we could have a cooperative, functional society where I can just be careless with my bike, right? What's the problem with these people? Sarcasm aside, I live in Brazil, ask any Brazilian who stayed on an European country what was the biggest difference: "I could feel safe anytime, without worrying about my stuff". That really shapes the mind and behaviour of people.

> What kind of stupid person would think that we could have a cooperative, functional society where I can just be careless with my bike, right? Isn't this actually a really common sentiment, though? I've lived in several places where leaving a bike unlocked for 5 minutes, or sloppily locked for an hour, means you're going to lose it. That doesn't make the theft acceptable, but if a friend borrowed your bike and left…

> Reshaping society so this stuff doesn't happen is great, but on an inside-view level we treat crime as sort of an inevitable "someone will do it" force.

I don't disagree with you, however I think there are some levels to this concept, e.g. how two different locations would differ if it was: a lost wallet, a somewhat clear opportunity for embezzlement, a bike stopped in front of a coffee shop?

Re: A vigilante trying to improve IoT security

#117
post #113

Earlier quoted context omitted.

What would your perspective be if I took a stance to secure your vehicle, or the power company, or any myriad of others simply because I chose to? What do you do when I change my logic to, well this is a ZERO DAY exploit, but you need to be patched, without understanding the complexities of your device or network. Which we all know QA takes a while because of variables. Look at any microsoft patch for evidence of tha…

A bit like my neighbor's door is wide open. Some teenagers are taking over it. Instead of just close/lock the door for my neighbor or call the cop, I use a bulldozer to level the house to the ground. (zero out the flash.) In theory, the "vigilante" can offer his service to device manufacturer to help remotely clean/update the devices instead of just simply wiping them off the net.

The point is how do you know the vigilante's fix won't have adverse side effects?

EDIT* I agree with the bulldozer analogy.

Re: A vigilante trying to improve IoT security

#118
post #113

Earlier quoted context omitted.

What would your perspective be if I took a stance to secure your vehicle, or the power company, or any myriad of others simply because I chose to? What do you do when I change my logic to, well this is a ZERO DAY exploit, but you need to be patched, without understanding the complexities of your device or network. Which we all know QA takes a while because of variables. Look at any microsoft patch for evidence of tha…

A bit like my neighbor's door is wide open. Some teenagers are taking over it. Instead of just close/lock the door for my neighbor or call the cop, I use a bulldozer to level the house to the ground. (zero out the flash.) In theory, the "vigilante" can offer his service to device manufacturer to help remotely clean/update the devices instead of just simply wiping them off the net.

It does say the bot tries to secure the device and then resorts to bricking it if it can't. Not condoning the janitors actions but at least bricking isn't his first action.

Re: A vigilante trying to improve IoT security

#119

Earlier quoted context omitted.

Secure against a dedicated attacker, yes. But telnet listening on port 23 and a conistent default admin password on all your devices is really not that hard to improve on (and that's the sort of device that BrickerBot is killing).

Perhaps. But someone thought it was a good idea to put up a telnet port 23 default-admin-password interface. The point is, if you give that person two weeks to focus on securing the product, I'm not sure they would realize it's a bad idea to do that. People who are bad at security don't realize they're bad at security. Which is why it's probably important to bring in an outside team to break the product. Or to put it…

I've done intentionally insecure things because I simply straight-up did not have time to do them correctly. Shared keys, shared password across an entire infra--lots of stupid things because my deadline wasn't moving and hours counted. The difference, of course, is that I retain control of my stuff and I'm not pushing things out to other people.

Pentests are, to be clear, great, and there are plenty of people who Dunning-Kruger their way through security decisions. But time is definitely a factor in this stuff.

Re: A vigilante trying to improve IoT security

#120
post #12
post #9

It takes a special kind of entitled to destroy people's things and to then blame others (the manufacturers) for it.

I think it's rather brilliant. It is the manufacturer's responsibility to ship secure products. Here a consumer with a bricked product will demand a replacement/refund, putting pressure on the manufacturers to not ship shitty products. It's directly applying market pressure to sellers of insecure hardware, and that's a great thing.

No. The product is going to be out of warranty, the manufacturer is going to refuse to replace the device, and suddenly a customer is out hundreds or thousands of dollars out of their own pocket. IoT devices are not cheap.

I find it reprehensible that the Gizmodo author (who is using his position as a journalist to encourage criminals) and HN commenters are applauding this hacker as if he's a hero of the people, fighting for a better future. He's directly harming individuals who have purchased products. This is not a friendly reminder to manufacturers to get their shit together. It's some guy illegally connecting to, taking control of, and bricking computers.

I've seen him referred to as a greyhat. No. Everything about this is strictly blackhat. This hacker deserves prison time. What a piece of lowlife scum. It really does sound like a 15 year old getting off on making waves, rather than someone who gives a damn about security.

Post reply on HN