Earlier quoted context omitted.
How does your opinion change with Phishing attacks? I'm going to steal funds from businesses by phishing vulnerable people, because If I don't capitalize on it, then people won't understand the costs / risks.
The person bricking IoT's isn't getting money from that. If they did, I would hope they or you did, I would hope each of you would donate to charities.
A vigilante trying to improve IoT security
131–140 of 242 posts
Re: A vigilante trying to improve IoT security
#132Earlier quoted context omitted.
Secure against a dedicated attacker, yes. But telnet listening on port 23 and a conistent default admin password on all your devices is really not that hard to improve on (and that's the sort of device that BrickerBot is killing).
Perhaps. But someone thought it was a good idea to put up a telnet port 23 default-admin-password interface. The point is, if you give that person two weeks to focus on securing the product, I'm not sure they would realize it's a bad idea to do that. People who are bad at security don't realize they're bad at security. Which is why it's probably important to bring in an outside team to break the product. Or to put it…
Re: A vigilante trying to improve IoT security
#133Earlier quoted context omitted.
Having a bad lock on your bike generally doesn't cause much harm to others. Allowing your hardware to be used for, e.g., DDOS attacks does.
I understand what you're implying, but no one is "allowing" their hardware to be used criminally. At least in the U.S., our personal property system is permissive i/e you may not use my things without permission. So, using an IoT device as provided by the manufacturer is "allowing" its misuse so much as leaving my backyard gate unlocked is "allowing" criminals to park their stolen goods in my backyard.
Re: A vigilante trying to improve IoT security
#134It's all fine and well until one of those improperly configured devices are a medical device or something critical. Yes I understand that's part of the problem, but proving a point with risk isn't the right answer either. Every Dialysis machine i've seen runs windows xp, which any security professional will tell you is game over, but given the market hasn't provided an alternative, it's becomes a necessity to figure…
Re: A vigilante trying to improve IoT security
#135Earlier quoted context omitted.
It is not on the net, but it is on a LAN that has a firewall somewhere that is leaky. This because it is cheaper in the short run to string a single physical network and then use vlans etc to attempt to keep medical stuff from talking to accounting or the visitors WiFi. This so a single overworked nurse can monitor a number of patients from a bank of monitors hooked to a thin client near the ward entrance.
Then it seems to me that more nurses and less dependence on fragile technology is a better option. Costs can be economized by many other methods. Labor is something that should be the last thing to pare down.
But in this instance the weighting is one done by beancounters looking at salaries as an ongoing expense, while tech is an investment that pays itself back the longer it can be used without further expences.
Re: A vigilante trying to improve IoT security
#136Earlier quoted context omitted.
I've brought this up to others, how would you feel if someone decided to brick / modify your car without you knowing? What would you do if that fix backfired and caused damage, hard locked the controls on your car, or worse, simply shut it off at the wrong time? We absolutely need to fix these issues, the governments of the world need to enforce standards on products, but vigilantism no matter how much you may agree…
Whether the car is hijacked to carry out attacks, or bricked by a vigilante trying to prevent another attack, I'd be pissed. But the blame lies squarely on the manufacturer who decided "meh, securing our devices against attack sounds expensive".
You used to have what was essentially airgapped and self contained.
But then feature x needed an ongoing net connection, and it happens to run on the same soc as feature y that talk to the can bus, and boom.
Neither of the teams responsible for the features considers that something can jump from x to y, almost like an illness jumps between species.
Damn it, the other day HN linked to an article on how VMs sharing hardware could talk to each other using the CPU cache.
Re: A vigilante trying to improve IoT security
#137Re: A vigilante trying to improve IoT security
#138Earlier quoted context omitted.
I'm the author of the Gizmodo post. Having covered IoT hacks for a few years, it's obvious that drastic measures would be necessary to convince manufacturers to build more secure products. While I'm not necessarily endorsing this hacker's methods, I do salute his taking a stand. It might land him in jail. But still, the mission is worthwhile.
This captures the essence of the type of activism that I so dislike — an unaffected, third party (a person who doesn't use your bluetooth lightbulb) taking the job upon himself to tell you what level of security your lightbulb should employ... By breaking it.
Re: A vigilante trying to improve IoT security
#139Earlier quoted context omitted.
A bit like my neighbor's door is wide open. Some teenagers are taking over it. Instead of just close/lock the door for my neighbor or call the cop, I use a bulldozer to level the house to the ground. (zero out the flash.) In theory, the "vigilante" can offer his service to device manufacturer to help remotely clean/update the devices instead of just simply wiping them off the net.
The point is how do you know the vigilante's fix won't have adverse side effects? EDIT* I agree with the bulldozer analogy.
While you have raised some valid issues, this is not one of them. Having an unsecured device on the internet has some very definite adverse side-effects.
Re: A vigilante trying to improve IoT security
#140Earlier quoted context omitted.
Ok, but we do have "attractive nuisance" laws. If you leave out a trampoline next to barbed wire, you can be accountable even if you didn't actually permit anyone to use it. This actually seems much closer to the IoT issue than theft. The maker and user of the device have created an inviting target which will cause harm to someone other than themselves. Even if the eventual attack is illegal, they can still be held a…
Honestly, I've never heard of a law like that. The U.S. is a big place; whereas that may be the case in parts of the country, in the south where I'm from, that's never become known to me, especially in the rural areas where I grew up. Instead, the people using your things without permission are at the very least trespassing.
IANAL, and it's hear say, but I had thought this was something everyone knew.