Live data from Hacker News

A vigilante trying to improve IoT security

gizmodo.com

141–150 of 242 posts

Re: A vigilante trying to improve IoT security

#141
post #113

Earlier quoted context omitted.

What would your perspective be if I took a stance to secure your vehicle, or the power company, or any myriad of others simply because I chose to? What do you do when I change my logic to, well this is a ZERO DAY exploit, but you need to be patched, without understanding the complexities of your device or network. Which we all know QA takes a while because of variables. Look at any microsoft patch for evidence of tha…

A bit like my neighbor's door is wide open. Some teenagers are taking over it. Instead of just close/lock the door for my neighbor or call the cop, I use a bulldozer to level the house to the ground. (zero out the flash.) In theory, the "vigilante" can offer his service to device manufacturer to help remotely clean/update the devices instead of just simply wiping them off the net.

unfortunately, we know from past experience that a certain percentage of the manufacturers would attempt to sue anyone offering such a service into silence, or even attempt to have him prosecuted for a crime.

Re: A vigilante trying to improve IoT security

#142

Earlier quoted context omitted.

I've done intentionally insecure things because I simply straight-up did not have time to do them correctly. Shared keys, shared password across an entire infra--lots of stupid things because my deadline wasn't moving and hours counted. The difference, of course, is that I retain control of my stuff and I'm not pushing things out to other people. Pentests are, to be clear, great, and there are plenty of people who Du…

I agree, but think of it this way: imagine a doctor arguing against washing their hands. The analogy is pretty apt. Washing your hands is as effective in reducing disease as pentests are at improving security. So why are we still seeking ways to justify to ourselves that we can do without pentests? It just seems like pentests need to move from "nice" to "necessary." (Part of that is reducing their cost from $60k to $…

The bigger problem with pentests is not the current cost but, as I see it, is that security is inherently and inescapably expensive somewhere in the chain, and that vendors have been getting a free lunch for too long. The viability of security analyses/pentests will go down if your goal is to reduce the cost by an order of magnitude because the people who are any good will find something better to do--and the consumer will still pay through all the bullshit externalities.

Security needs to cost to demand talent. The real solution to this problem, I think is that failure to secure needs to cost (whether in monetary or criminal terms) or it isn't relevant to business concerns.

Re: A vigilante trying to improve IoT security

#143
I see a lot of people blaming the manufacturers, or blaming the hacker. Then coming up with analogies to support their point of view. I blame the users and don't feel bad for them at all. The analogy I'm going with is if one of your neighbors bought a canon as a piece of art, and left it pointed at your house. Ignorance is not an excuse.

Re: A vigilante trying to improve IoT security

#144
post #113

Earlier quoted context omitted.

What would your perspective be if I took a stance to secure your vehicle, or the power company, or any myriad of others simply because I chose to? What do you do when I change my logic to, well this is a ZERO DAY exploit, but you need to be patched, without understanding the complexities of your device or network. Which we all know QA takes a while because of variables. Look at any microsoft patch for evidence of tha…

A bit like my neighbor's door is wide open. Some teenagers are taking over it. Instead of just close/lock the door for my neighbor or call the cop, I use a bulldozer to level the house to the ground. (zero out the flash.) In theory, the "vigilante" can offer his service to device manufacturer to help remotely clean/update the devices instead of just simply wiping them off the net.

>Instead of just close/lock the door for my neighbor or call the cop,

This is where your analogy breaks. Who is your neighbor on the internet? The most logical answer I have is "Everyone with a public IP".

Next, who is the internet police? Sorry folks, there isn't one. If my neighbors house is open, I would call the cops for two reasons. First I don't want to see their stuff damaged. But also, it creates a public nuisance. Some variant of criminals (say drug users or stupid teens) could take up residence in their house, possibly even burning it down, which would make it a direct threat to me.

And that's the problem with our current internet police. They will gladly try to arrest you for breaking into someones house. But they will not bust the 100,000 houses that leave their front door open inviting crime into the neighborhood.

Re: A vigilante trying to improve IoT security

#145

Earlier quoted context omitted.

The person bricking IoT's isn't getting money from that. If they did, I would hope they or you did, I would hope each of you would donate to charities.

What they get is irrelevant, it's someone using their skill set to make others aware of a flaw. I would argue it's the exact same premise. I'm going to phish people & cause them a financial cost to teach them to be safe.

> What they get is irrelevant

It's actually the main relevant part of the analogy.

It goes to veracity.

There's a person who gave a public talk about manipulating Bitcoins with weak private keys in order to alert the owners that they were vulnerable. But he did it in a way that verified to the owner he hadn't in fact stolen the coins (moving small portions around or maybe signing with the key, I can't remember). He also mentioned in the public talk that the owners of those Bitcoins were totally freaked out by this, and most were never convinced that he was acting in good faith (which is probably a smart assumption on their part).

So the fact that he didn't steal the coins is completely relevant-- it's the very reason he could give a public talk on what is still grey area behavior.

Your hypothetical thief, on the other hand, is clearly mendacious. You have him claiming, "If I don't capitalize on it, then people won't understand the costs/risks." That is clearly false from my real-world example above, and if he tried to give a public talk about how his theft benefited society he'd be arrested.

Re: A vigilante trying to improve IoT security

#146

The writer of the story really tries hard to make vigelante justice narrative and glorify someone who is causing real damage to computer systems. We saw the same thing with the hack of Ashley Madison . They make the original vendors out to be scumbags. Things are much more complicated . Yes vendors and websites should keep things more secure. If you really want iot to be more secure I don't believe that large or smal…

Well, yea, thats half the point. The point is manufacturers can't be bothered because it doesn't hurt them. There isn't a way to hurt them short of lawsuit or legislation. We don't really have the standing or power to effect change, so they hurt the consumers who complain to the manufacturers. Nobody thinks this is a nice solution, but is there a better alternative?

Re: A vigilante trying to improve IoT security

#147
post #12

Earlier quoted context omitted.

I think it's rather brilliant. It is the manufacturer's responsibility to ship secure products. Here a consumer with a bricked product will demand a replacement/refund, putting pressure on the manufacturers to not ship shitty products. It's directly applying market pressure to sellers of insecure hardware, and that's a great thing.

> Here a consumer with a bricked product will demand a replacement/refund, putting pressure on the manufacturers to not ship shitty products. If my shitty DLink camera suddenly stopped working, I wouldn't demand a refund - realistically, I'd just toss it in the bin and try to remember not to buy more DLink products. But I probably still would, if they were sufficiently cheap. I imagine that calculus is similar for mo…

And DLink will continue to try to save money by releasing products without following proper security procedures because you will keep buying them because they are cheap.

It's tough for security to affect purchasing decisions because it's difficult to measure. I can measure horsepower, megapixels, gigabytes, milliamp-hours, etc. so it's easy to make purchasing decisions based on which of those things are important to me.

Re: A vigilante trying to improve IoT security

#148

Earlier quoted context omitted.

"It's all fine and well until one of those improperly configured devices are a medical device or something critical. " It would be their fault. High-assurance industry has been telling SCADA and medical industry to get their shit together for a long time. This included pentests showing it could all be destroyed. They even have people at conferences talking about it with products or basic advice to deal with it. The r…

I've brought this up to others, how would you feel if someone decided to brick / modify your car without you knowing? What would you do if that fix backfired and caused damage, hard locked the controls on your car, or worse, simply shut it off at the wrong time? We absolutely need to fix these issues, the governments of the world need to enforce standards on products, but vigilantism no matter how much you may agree…

>how would you feel if

Feelings are irrelevant.

Some vigilantes hack that said "Turn the car off at 10mph or less" is a far better outcome than the attackers option of "Press the gas and turn the wheel left as hard as you can at 100mph".

Re: A vigilante trying to improve IoT security

#149
post #147

Earlier quoted context omitted.

> Here a consumer with a bricked product will demand a replacement/refund, putting pressure on the manufacturers to not ship shitty products. If my shitty DLink camera suddenly stopped working, I wouldn't demand a refund - realistically, I'd just toss it in the bin and try to remember not to buy more DLink products. But I probably still would, if they were sufficiently cheap. I imagine that calculus is similar for mo…

And DLink will continue to try to save money by releasing products without following proper security procedures because you will keep buying them because they are cheap. It's tough for security to affect purchasing decisions because it's difficult to measure. I can measure horsepower, megapixels, gigabytes, milliamp-hours, etc. so it's easy to make purchasing decisions based on which of those things are important to…

I think what you're suggesting is that enough bricked devices will cause consumers to demand security - maybe even some measurable metric, like a certification of external audit - as part of the standard product search.

But I don't think bricking a device necessarily ties into security in people's minds. If they permanently modified it to always show HACKED_BCUZ_DLINK_SUX whenever I try to load the camera feed, sure - but a bricked camera is just a failure. I don't even know if it got hacked, or if a capacitor blew, or if a rodent chewed through something crucial.

Re: A vigilante trying to improve IoT security

#150

Earlier quoted context omitted.

The person bricking IoT's isn't getting money from that. If they did, I would hope they or you did, I would hope each of you would donate to charities.

You don't really know that for sure. That person could easily be shorting the shares of IoT device companies that they are targeting, hoping that articles like this one are written critical of the manufacturers.

[deleted]
Post reply on HN