Live data from Hacker News

A vigilante trying to improve IoT security

gizmodo.com

121–130 of 242 posts

Re: A vigilante trying to improve IoT security

#121
post #60

Earlier quoted context omitted.

He's providing an economic benefit to society - internalizing (to consumers) the externality of IOT botnets. It's now on the consumers to further internalize to cost to manufacturers through product selection, class action, or both.

How does your opinion change with Phishing attacks? I'm going to steal funds from businesses by phishing vulnerable people, because If I don't capitalize on it, then people won't understand the costs / risks.

The person bricking IoT's isn't getting money from that. If they did, I would hope they or you did, I would hope each of you would donate to charities.

Re: A vigilante trying to improve IoT security

#122

Earlier quoted context omitted.

How does your opinion change with Phishing attacks? I'm going to steal funds from businesses by phishing vulnerable people, because If I don't capitalize on it, then people won't understand the costs / risks.

The person bricking IoT's isn't getting money from that. If they did, I would hope they or you did, I would hope each of you would donate to charities.

What they get is irrelevant, it's someone using their skill set to make others aware of a flaw. I would argue it's the exact same premise. I'm going to phish people & cause them a financial cost to teach them to be safe.

Re: A vigilante trying to improve IoT security

#123

It's all fine and well until one of those improperly configured devices are a medical device or something critical. Yes I understand that's part of the problem, but proving a point with risk isn't the right answer either. Every Dialysis machine i've seen runs windows xp, which any security professional will tell you is game over, but given the market hasn't provided an alternative, it's becomes a necessity to figure…

Stoplights are often installed after {n} number of people die at an intersection to justify the cost. Is that cool?

Regulations are put on companies after their freedom of choice; when abused, starts harming people. I think IoT is a perfect example of this. Today the manufactures have a great deal of freedom. Their lack of self regulation will require others to step in and regulate them.

On the matter of vigilantes: This is a complicated topic, but I support them doing this, even if it harms myself or someone I care about. If this problem is not stopped sooner than later, it will explode into a much bigger economic and/or societal issue that will be difficult to contain. I have warned the people I care about already.

The current state of IoT is a complete lack of responsibility. I would even support someone bricking every piece of machinery they can, including cars, heavy equipment, power plants and anything else that was built without proper engineering.

Re: A vigilante trying to improve IoT security

#124
post #60

Earlier quoted context omitted.

I'm the author of the Gizmodo post. Having covered IoT hacks for a few years, it's obvious that drastic measures would be necessary to convince manufacturers to build more secure products. While I'm not necessarily endorsing this hacker's methods, I do salute his taking a stand. It might land him in jail. But still, the mission is worthwhile.

He's providing an economic benefit to society - internalizing (to consumers) the externality of IOT botnets. It's now on the consumers to further internalize to cost to manufacturers through product selection, class action, or both.

Not necessarily. If a consumer's device is bricked within the (usually 1-year) warranty period, then they're able to send it back to the manufacturer for a replacement, which pushes the cost right back to the manufacturer.

Also, if the device is bricked very quickly after buying it and installing it, the consumer will very likely simply return it to the retailer as defective, which again pushes costs back to the manufacturer.

Re: A vigilante trying to improve IoT security

#125

Earlier quoted context omitted.

"It's all fine and well until one of those improperly configured devices are a medical device or something critical. " It would be their fault. High-assurance industry has been telling SCADA and medical industry to get their shit together for a long time. This included pentests showing it could all be destroyed. They even have people at conferences talking about it with products or basic advice to deal with it. The r…

I've brought this up to others, how would you feel if someone decided to brick / modify your car without you knowing? What would you do if that fix backfired and caused damage, hard locked the controls on your car, or worse, simply shut it off at the wrong time? We absolutely need to fix these issues, the governments of the world need to enforce standards on products, but vigilantism no matter how much you may agree…

Whether the car is hijacked to carry out attacks, or bricked by a vigilante trying to prevent another attack, I'd be pissed. But the blame lies squarely on the manufacturer who decided "meh, securing our devices against attack sounds expensive".

Re: A vigilante trying to improve IoT security

#126
post #96
post #79

Earlier quoted context omitted.

Then fix your lightbulb so that someone can't tell you how to handle your lightbulbs. If you can't reach that low bar then why are you even connecting to the internet? You are implicitly allowing your tools to be used for botnets which should be a crime in itself.

So you think the consumers should be punished for something you think the producers do wrong? Do you apply this to other products as well? Would it be ok to soak peoples cigarettes in water, break the motor of your neighbours high fuel consuming SUV or destroy the guns of people since these products can cause damage to other people?

If a certain brand of cigarettes is creating secondhand smoke that causes a significant number of bystanders to die of anaphylactic shock somehow, and the government refuses to force a recall, and the manufacturer doesn't care, and the smokers don't care because it doesn't affect them, then YES, it is morally correct to destroy these cigarettes illegally.

Re: A vigilante trying to improve IoT security

#127

Earlier quoted context omitted.

Perhaps. But someone thought it was a good idea to put up a telnet port 23 default-admin-password interface. The point is, if you give that person two weeks to focus on securing the product, I'm not sure they would realize it's a bad idea to do that. People who are bad at security don't realize they're bad at security. Which is why it's probably important to bring in an outside team to break the product. Or to put it…

I've done intentionally insecure things because I simply straight-up did not have time to do them correctly. Shared keys, shared password across an entire infra--lots of stupid things because my deadline wasn't moving and hours counted. The difference, of course, is that I retain control of my stuff and I'm not pushing things out to other people. Pentests are, to be clear, great, and there are plenty of people who Du…

I agree, but think of it this way: imagine a doctor arguing against washing their hands. The analogy is pretty apt. Washing your hands is as effective in reducing disease as pentests are at improving security. So why are we still seeking ways to justify to ourselves that we can do without pentests?

It just seems like pentests need to move from "nice" to "necessary." (Part of that is reducing their cost from $60k to $6k.)

Re: A vigilante trying to improve IoT security

#128

Earlier quoted context omitted.

Okay but why does a dialysis machine need to be on the internet? Even if it's done to forward reports regarding the usage of the machine that can be done in a daily dump when you swap it out I'm guessing, right? So, it doesn't need to be an always-on device with respect to its NIC. Plus, there's no benefit to the user to have their life giving machinery be online. It's just another thing to overcharge the hospital fo…

It is not on the net, but it is on a LAN that has a firewall somewhere that is leaky. This because it is cheaper in the short run to string a single physical network and then use vlans etc to attempt to keep medical stuff from talking to accounting or the visitors WiFi. This so a single overworked nurse can monitor a number of patients from a bank of monitors hooked to a thin client near the ward entrance.

Then it seems to me that more nurses and less dependence on fragile technology is a better option. Costs can be economized by many other methods. Labor is something that should be the last thing to pare down.

Re: A vigilante trying to improve IoT security

#129
The writer of the story really tries hard to make vigelante justice narrative and glorify someone who is causing real damage to computer systems. We saw the same thing with the hack of Ashley Madison . They make the original vendors out to be scumbags. Things are much more complicated . Yes vendors and websites should keep things more secure. If you really want iot to be more secure I don't believe that large or small hacks is the best way to do this. The consumer is really the one that loses here.

Re: A vigilante trying to improve IoT security

#130

Earlier quoted context omitted.

I'm the author of the Gizmodo post. Having covered IoT hacks for a few years, it's obvious that drastic measures would be necessary to convince manufacturers to build more secure products. While I'm not necessarily endorsing this hacker's methods, I do salute his taking a stand. It might land him in jail. But still, the mission is worthwhile.

What would your perspective be if I took a stance to secure your vehicle, or the power company, or any myriad of others simply because I chose to? What do you do when I change my logic to, well this is a ZERO DAY exploit, but you need to be patched, without understanding the complexities of your device or network. Which we all know QA takes a while because of variables. Look at any microsoft patch for evidence of tha…

> What do you do when I change my logic to, well this is a ZERO DAY exploit, but you need to be patched, without understanding the complexities of your device or network.

I'd say you are changing topics. The topic at hand is about devices that are designed to be insecure, because the involved parties just don't care. The manufacturer KNOWS yet doesn't care because the issue doesn't cause him any harm, and the user just doesn't know.

We are talking about devices that willingly expose themselves to the internet (oftentimes without any valid reason to), that are all factory-setup with the same credentials (and no must-change on first use policy), etc.. This is just malpractice, not 0-day vulnerabilities.

Post reply on HN