Live data from Hacker News

A vigilante trying to improve IoT security

gizmodo.com

131–140 of 242 posts

Re: A vigilante trying to improve IoT security

#131

Earlier quoted context omitted.

How does your opinion change with Phishing attacks? I'm going to steal funds from businesses by phishing vulnerable people, because If I don't capitalize on it, then people won't understand the costs / risks.

The person bricking IoT's isn't getting money from that. If they did, I would hope they or you did, I would hope each of you would donate to charities.

You don't really know that for sure. That person could easily be shorting the shares of IoT device companies that they are targeting, hoping that articles like this one are written critical of the manufacturers.

Re: A vigilante trying to improve IoT security

#132

Earlier quoted context omitted.

Secure against a dedicated attacker, yes. But telnet listening on port 23 and a conistent default admin password on all your devices is really not that hard to improve on (and that's the sort of device that BrickerBot is killing).

Perhaps. But someone thought it was a good idea to put up a telnet port 23 default-admin-password interface. The point is, if you give that person two weeks to focus on securing the product, I'm not sure they would realize it's a bad idea to do that. People who are bad at security don't realize they're bad at security. Which is why it's probably important to bring in an outside team to break the product. Or to put it…

Sounds like a good opportunity for something analogous to UL certification, albeit for security.

Re: A vigilante trying to improve IoT security

#133
post #64

Earlier quoted context omitted.

Having a bad lock on your bike generally doesn't cause much harm to others. Allowing your hardware to be used for, e.g., DDOS attacks does.

I understand what you're implying, but no one is "allowing" their hardware to be used criminally. At least in the U.S., our personal property system is permissive i/e you may not use my things without permission. So, using an IoT device as provided by the manufacturer is "allowing" its misuse so much as leaving my backyard gate unlocked is "allowing" criminals to park their stolen goods in my backyard.

A poor choice of words on my part. That aside, the point remains: poorly secured IoT devices cause real harm to others in a way that a poorly secured bike does not.

Re: A vigilante trying to improve IoT security

#134

It's all fine and well until one of those improperly configured devices are a medical device or something critical. Yes I understand that's part of the problem, but proving a point with risk isn't the right answer either. Every Dialysis machine i've seen runs windows xp, which any security professional will tell you is game over, but given the market hasn't provided an alternative, it's becomes a necessity to figure…

I agree, we should continue let all the badly configured IoT devices continually be used against the end user. Doing something about it is dangerous and no one likes danger.

Re: A vigilante trying to improve IoT security

#135

Earlier quoted context omitted.

It is not on the net, but it is on a LAN that has a firewall somewhere that is leaky. This because it is cheaper in the short run to string a single physical network and then use vlans etc to attempt to keep medical stuff from talking to accounting or the visitors WiFi. This so a single overworked nurse can monitor a number of patients from a bank of monitors hooked to a thin client near the ward entrance.

Then it seems to me that more nurses and less dependence on fragile technology is a better option. Costs can be economized by many other methods. Labor is something that should be the last thing to pare down.

Technology, done right, can be more reliable than humans.

But in this instance the weighting is one done by beancounters looking at salaries as an ongoing expense, while tech is an investment that pays itself back the longer it can be used without further expences.

Re: A vigilante trying to improve IoT security

#136

Earlier quoted context omitted.

I've brought this up to others, how would you feel if someone decided to brick / modify your car without you knowing? What would you do if that fix backfired and caused damage, hard locked the controls on your car, or worse, simply shut it off at the wrong time? We absolutely need to fix these issues, the governments of the world need to enforce standards on products, but vigilantism no matter how much you may agree…

Whether the car is hijacked to carry out attacks, or bricked by a vigilante trying to prevent another attack, I'd be pissed. But the blame lies squarely on the manufacturer who decided "meh, securing our devices against attack sounds expensive".

I think the problem is as often not about careing, and being unaware of anything outside their little subsystem.

You used to have what was essentially airgapped and self contained.

But then feature x needed an ongoing net connection, and it happens to run on the same soc as feature y that talk to the can bus, and boom.

Neither of the teams responsible for the features considers that something can jump from x to y, almost like an illness jumps between species.

Damn it, the other day HN linked to an article on how VMs sharing hardware could talk to each other using the CPU cache.

Re: A vigilante trying to improve IoT security

#138

Earlier quoted context omitted.

I'm the author of the Gizmodo post. Having covered IoT hacks for a few years, it's obvious that drastic measures would be necessary to convince manufacturers to build more secure products. While I'm not necessarily endorsing this hacker's methods, I do salute his taking a stand. It might land him in jail. But still, the mission is worthwhile.

This captures the essence of the type of activism that I so dislike — an unaffected, third party (a person who doesn't use your bluetooth lightbulb) taking the job upon himself to tell you what level of security your lightbulb should employ... By breaking it.

There's no such thing as an unaffected third party in a tragedy of the commons situation, which this is.

Re: A vigilante trying to improve IoT security

#139
post #113

Earlier quoted context omitted.

A bit like my neighbor's door is wide open. Some teenagers are taking over it. Instead of just close/lock the door for my neighbor or call the cop, I use a bulldozer to level the house to the ground. (zero out the flash.) In theory, the "vigilante" can offer his service to device manufacturer to help remotely clean/update the devices instead of just simply wiping them off the net.

The point is how do you know the vigilante's fix won't have adverse side effects? EDIT* I agree with the bulldozer analogy.

> The point is how do you know the vigilante's fix won't have adverse side effects?

While you have raised some valid issues, this is not one of them. Having an unsecured device on the internet has some very definite adverse side-effects.

Re: A vigilante trying to improve IoT security

#140
post #106

Earlier quoted context omitted.

Ok, but we do have "attractive nuisance" laws. If you leave out a trampoline next to barbed wire, you can be accountable even if you didn't actually permit anyone to use it. This actually seems much closer to the IoT issue than theft. The maker and user of the device have created an inviting target which will cause harm to someone other than themselves. Even if the eventual attack is illegal, they can still be held a…

Honestly, I've never heard of a law like that. The U.S. is a big place; whereas that may be the case in parts of the country, in the south where I'm from, that's never become known to me, especially in the rural areas where I grew up. Instead, the people using your things without permission are at the very least trespassing.

The only attractive nuisance laws I've heard of applied to children. If you have a swimming pool without a fence, and a child sneaks onto your property and drowns you are liable.

IANAL, and it's hear say, but I had thought this was something everyone knew.

Post reply on HN