The method they're describing is only permanent for devices without a removable startup disk, right? If they run this on my raspberry pi, for example, just reformatting the sd card and following the same process as when I first got it should immediately fix this.
A vigilante trying to improve IoT security
151–160 of 242 posts
Re: A vigilante trying to improve IoT security
#152As someone who works as a software consultant for many IoT and connected device companies, how can I increase my understanding of IoT security? How can I ensure the devices I work with are secure?
Re: A vigilante trying to improve IoT security
#153Earlier quoted context omitted.
Please don't. With some funding from China, I'm currently running a massive worldwide operation, which allows me to spy on hundreds of millions of unsuspecting Master Lock users; allowing me to track, among other things, where every bike user is at all time, as well as record what they are doing. If only it weren't for you meddling kid. Analogies, aren't they great? (Since it's apparent that sarcasm can't be read: "S…
If this danger is real, isn't it best to inform the consumer, or perhaps use a lawsuit to force a recall, rather than destroying other people's hardware? Does this concept apply to software? When the next large-scale RCE 0-day drops, does it make sense to use exploitation to destroy as much as possible in order to pressure the developers to ship a secure product? Since, the hacked machines certainly could allow an at…
How, like 5% of people that buy electronics actually turn in the warranty cards. No, they will sit on the shelf for years polluting the internet with DDOS attacks and spam.
>es it make sense to use exploitation to destroy as much as possible in order to pressure the developers to ship a secure product?
Yes. That is also why I backup data using multiple methods including off line ones.
Vigilante or blackhat doesn't matter. The next RCE will gladly spit copies of CryptoLocker everywhere if they could get ahold of it.
The internet is a dangerous and well connected place. If lived China, I would think it's funny if I wiped a few large US corporations off the map because they used a DLINK webcam. And there is only a tiny chance in hell they would ever find me.
Re: A vigilante trying to improve IoT security
#154Earlier quoted context omitted.
Yes. In fact, I'm going to start stealing bikes that have insecure locks.
What kind of stupid person would think that we could have a cooperative, functional society where I can just be careless with my bike, right? What's the problem with these people? Sarcasm aside, I live in Brazil, ask any Brazilian who stayed on an European country what was the biggest difference: "I could feel safe anytime, without worrying about my stuff". That really shapes the mind and behaviour of people.
The same kind of stupid person that doesn't realize they live in a ghetto called "The Internet".
Re: A vigilante trying to improve IoT security
#155Earlier quoted context omitted.
He's providing an economic benefit to society - internalizing (to consumers) the externality of IOT botnets. It's now on the consumers to further internalize to cost to manufacturers through product selection, class action, or both.
Not necessarily. If a consumer's device is bricked within the (usually 1-year) warranty period, then they're able to send it back to the manufacturer for a replacement, which pushes the cost right back to the manufacturer. Also, if the device is bricked very quickly after buying it and installing it, the consumer will very likely simply return it to the retailer as defective, which again pushes costs back to the manu…
Re: A vigilante trying to improve IoT security
#156Earlier quoted context omitted.
The person bricking IoT's isn't getting money from that. If they did, I would hope they or you did, I would hope each of you would donate to charities.
You don't really know that for sure. That person could easily be shorting the shares of IoT device companies that they are targeting, hoping that articles like this one are written critical of the manufacturers.
By saying clearly different, I don't mean to minimize the actions of the vigilante. One of the chief characteristics of civil disobedience, for example, is to resolve that could it be question. By receiving the unjust punishment the dissident displays good faith with proponents and opponents. I don't yet see how pseudonymous hacktivism keeps that good faith with the public. And that seems to relegate it either be small scale, symbolic acts like this or large-scale grey hat stuff that brings lots of unwanted risks/cooptation/etc.
Re: A vigilante trying to improve IoT security
#157Earlier quoted context omitted.
I agree, but think of it this way: imagine a doctor arguing against washing their hands. The analogy is pretty apt. Washing your hands is as effective in reducing disease as pentests are at improving security. So why are we still seeking ways to justify to ourselves that we can do without pentests? It just seems like pentests need to move from "nice" to "necessary." (Part of that is reducing their cost from $60k to $…
The bigger problem with pentests is not the current cost but, as I see it, is that security is inherently and inescapably expensive somewhere in the chain, and that vendors have been getting a free lunch for too long. The viability of security analyses/pentests will go down if your goal is to reduce the cost by an order of magnitude because the people who are any good will find something better to do--and the consume…
> security is inherently and inescapably expensive somewhere in the chain
...is the thing that needs to change. Presumably using more automation (e.g. employing more software like http://lcamtuf.coredump.cx/afl/), such that "pen-testing" shifts from being a labor cost to a capital cost.
Re: A vigilante trying to improve IoT security
#158Earlier quoted context omitted.
The person bricking IoT's isn't getting money from that. If they did, I would hope they or you did, I would hope each of you would donate to charities.
What they get is irrelevant, it's someone using their skill set to make others aware of a flaw. I would argue it's the exact same premise. I'm going to phish people & cause them a financial cost to teach them to be safe.
Re: A vigilante trying to improve IoT security
#159Earlier quoted context omitted.
Engineering needs to stop being subordinate to anything but top management (if at all). An MBA can always outrank an engineer's decision and that is a big reason why we have crap devices out in the field.
Without labor laws to back something like this up, all it does is get engineers fired. Non-software engineering fields do have such laws, I believe. An MBA cannot make a civil engineer build a bridge that is unsafe because they want to save money. After all, it's the project engineer's signature on the final work. (Please correct me if I'm wrong.) On the other hand, a large proportion of startups are doing something…
Re: A vigilante trying to improve IoT security
#160Earlier quoted context omitted.
Whether the car is hijacked to carry out attacks, or bricked by a vigilante trying to prevent another attack, I'd be pissed. But the blame lies squarely on the manufacturer who decided "meh, securing our devices against attack sounds expensive".
I think the problem is as often not about careing, and being unaware of anything outside their little subsystem. You used to have what was essentially airgapped and self contained. But then feature x needed an ongoing net connection, and it happens to run on the same soc as feature y that talk to the can bus, and boom. Neither of the teams responsible for the features considers that something can jump from x to y, al…
That sounds similar to a paper I read ~20 years ago that described a way to move data from a high privilege process, bypassing mandatory access control (>= TCSEC B), using page faults as a covert channel.
> it happens to run on the same soc as feature y that talk to the can bus
I wonder how many people will have to die to teach car manufacturers the lesson that there shouldn't be any electrical connection at all from the internet to the breaks.