Earlier quoted context omitted.
What would your perspective be if I took a stance to secure your vehicle, or the power company, or any myriad of others simply because I chose to? What do you do when I change my logic to, well this is a ZERO DAY exploit, but you need to be patched, without understanding the complexities of your device or network. Which we all know QA takes a while because of variables. Look at any microsoft patch for evidence of tha…
A bit like my neighbor's door is wide open. Some teenagers are taking over it. Instead of just close/lock the door for my neighbor or call the cop, I use a bulldozer to level the house to the ground. (zero out the flash.) In theory, the "vigilante" can offer his service to device manufacturer to help remotely clean/update the devices instead of just simply wiping them off the net.
A vigilante trying to improve IoT security
141–150 of 242 posts
Re: A vigilante trying to improve IoT security
#142Earlier quoted context omitted.
I've done intentionally insecure things because I simply straight-up did not have time to do them correctly. Shared keys, shared password across an entire infra--lots of stupid things because my deadline wasn't moving and hours counted. The difference, of course, is that I retain control of my stuff and I'm not pushing things out to other people. Pentests are, to be clear, great, and there are plenty of people who Du…
I agree, but think of it this way: imagine a doctor arguing against washing their hands. The analogy is pretty apt. Washing your hands is as effective in reducing disease as pentests are at improving security. So why are we still seeking ways to justify to ourselves that we can do without pentests? It just seems like pentests need to move from "nice" to "necessary." (Part of that is reducing their cost from $60k to $…
Security needs to cost to demand talent. The real solution to this problem, I think is that failure to secure needs to cost (whether in monetary or criminal terms) or it isn't relevant to business concerns.
Re: A vigilante trying to improve IoT security
#143Re: A vigilante trying to improve IoT security
#144Earlier quoted context omitted.
What would your perspective be if I took a stance to secure your vehicle, or the power company, or any myriad of others simply because I chose to? What do you do when I change my logic to, well this is a ZERO DAY exploit, but you need to be patched, without understanding the complexities of your device or network. Which we all know QA takes a while because of variables. Look at any microsoft patch for evidence of tha…
A bit like my neighbor's door is wide open. Some teenagers are taking over it. Instead of just close/lock the door for my neighbor or call the cop, I use a bulldozer to level the house to the ground. (zero out the flash.) In theory, the "vigilante" can offer his service to device manufacturer to help remotely clean/update the devices instead of just simply wiping them off the net.
This is where your analogy breaks. Who is your neighbor on the internet? The most logical answer I have is "Everyone with a public IP".
Next, who is the internet police? Sorry folks, there isn't one. If my neighbors house is open, I would call the cops for two reasons. First I don't want to see their stuff damaged. But also, it creates a public nuisance. Some variant of criminals (say drug users or stupid teens) could take up residence in their house, possibly even burning it down, which would make it a direct threat to me.
And that's the problem with our current internet police. They will gladly try to arrest you for breaking into someones house. But they will not bust the 100,000 houses that leave their front door open inviting crime into the neighborhood.
Re: A vigilante trying to improve IoT security
#145Earlier quoted context omitted.
The person bricking IoT's isn't getting money from that. If they did, I would hope they or you did, I would hope each of you would donate to charities.
What they get is irrelevant, it's someone using their skill set to make others aware of a flaw. I would argue it's the exact same premise. I'm going to phish people & cause them a financial cost to teach them to be safe.
It's actually the main relevant part of the analogy.
It goes to veracity.
There's a person who gave a public talk about manipulating Bitcoins with weak private keys in order to alert the owners that they were vulnerable. But he did it in a way that verified to the owner he hadn't in fact stolen the coins (moving small portions around or maybe signing with the key, I can't remember). He also mentioned in the public talk that the owners of those Bitcoins were totally freaked out by this, and most were never convinced that he was acting in good faith (which is probably a smart assumption on their part).
So the fact that he didn't steal the coins is completely relevant-- it's the very reason he could give a public talk on what is still grey area behavior.
Your hypothetical thief, on the other hand, is clearly mendacious. You have him claiming, "If I don't capitalize on it, then people won't understand the costs/risks." That is clearly false from my real-world example above, and if he tried to give a public talk about how his theft benefited society he'd be arrested.
Re: A vigilante trying to improve IoT security
#146The writer of the story really tries hard to make vigelante justice narrative and glorify someone who is causing real damage to computer systems. We saw the same thing with the hack of Ashley Madison . They make the original vendors out to be scumbags. Things are much more complicated . Yes vendors and websites should keep things more secure. If you really want iot to be more secure I don't believe that large or smal…
Re: A vigilante trying to improve IoT security
#147Earlier quoted context omitted.
I think it's rather brilliant. It is the manufacturer's responsibility to ship secure products. Here a consumer with a bricked product will demand a replacement/refund, putting pressure on the manufacturers to not ship shitty products. It's directly applying market pressure to sellers of insecure hardware, and that's a great thing.
> Here a consumer with a bricked product will demand a replacement/refund, putting pressure on the manufacturers to not ship shitty products. If my shitty DLink camera suddenly stopped working, I wouldn't demand a refund - realistically, I'd just toss it in the bin and try to remember not to buy more DLink products. But I probably still would, if they were sufficiently cheap. I imagine that calculus is similar for mo…
It's tough for security to affect purchasing decisions because it's difficult to measure. I can measure horsepower, megapixels, gigabytes, milliamp-hours, etc. so it's easy to make purchasing decisions based on which of those things are important to me.
Re: A vigilante trying to improve IoT security
#148Earlier quoted context omitted.
"It's all fine and well until one of those improperly configured devices are a medical device or something critical. " It would be their fault. High-assurance industry has been telling SCADA and medical industry to get their shit together for a long time. This included pentests showing it could all be destroyed. They even have people at conferences talking about it with products or basic advice to deal with it. The r…
I've brought this up to others, how would you feel if someone decided to brick / modify your car without you knowing? What would you do if that fix backfired and caused damage, hard locked the controls on your car, or worse, simply shut it off at the wrong time? We absolutely need to fix these issues, the governments of the world need to enforce standards on products, but vigilantism no matter how much you may agree…
Feelings are irrelevant.
Some vigilantes hack that said "Turn the car off at 10mph or less" is a far better outcome than the attackers option of "Press the gas and turn the wheel left as hard as you can at 100mph".
Re: A vigilante trying to improve IoT security
#149Earlier quoted context omitted.
> Here a consumer with a bricked product will demand a replacement/refund, putting pressure on the manufacturers to not ship shitty products. If my shitty DLink camera suddenly stopped working, I wouldn't demand a refund - realistically, I'd just toss it in the bin and try to remember not to buy more DLink products. But I probably still would, if they were sufficiently cheap. I imagine that calculus is similar for mo…
And DLink will continue to try to save money by releasing products without following proper security procedures because you will keep buying them because they are cheap. It's tough for security to affect purchasing decisions because it's difficult to measure. I can measure horsepower, megapixels, gigabytes, milliamp-hours, etc. so it's easy to make purchasing decisions based on which of those things are important to…
But I don't think bricking a device necessarily ties into security in people's minds. If they permanently modified it to always show HACKED_BCUZ_DLINK_SUX whenever I try to load the camera feed, sure - but a bricked camera is just a failure. I don't even know if it got hacked, or if a capacitor blew, or if a rodent chewed through something crucial.
Re: A vigilante trying to improve IoT security
#150Earlier quoted context omitted.
The person bricking IoT's isn't getting money from that. If they did, I would hope they or you did, I would hope each of you would donate to charities.
You don't really know that for sure. That person could easily be shorting the shares of IoT device companies that they are targeting, hoping that articles like this one are written critical of the manufacturers.