Live data from Hacker News

A vigilante trying to improve IoT security

gizmodo.com

151–160 of 242 posts

Re: A vigilante trying to improve IoT security

#151

The method they're describing is only permanent for devices without a removable startup disk, right? If they run this on my raspberry pi, for example, just reformatting the sd card and following the same process as when I first got it should immediately fix this.

Yes, it makes every effort to corrupt the filesystem that the operating system is stored on and mess up the networking before shutting down the device or rebooting. If the device has its' OS on readonly media then this won't do much. Maybe it will turn off until someone cycles it. If you can reformat or reflash the disk then you can recover. For a raspberry pi that's cool. For an IP camera it's generally a problem.

Re: A vigilante trying to improve IoT security

#152

As someone who works as a software consultant for many IoT and connected device companies, how can I increase my understanding of IoT security? How can I ensure the devices I work with are secure?

Since posting this, I did some research, and it looks like the biggest security problem (currently) is manufacturers hardcoding default passwords into the firmware. Here I am thinking I need to become an expert in security to help my clients secure their devices, but is it really as simple as encouraging clients to set secure, default passwords?

Re: A vigilante trying to improve IoT security

#153
post #27

Earlier quoted context omitted.

Please don't. With some funding from China, I'm currently running a massive worldwide operation, which allows me to spy on hundreds of millions of unsuspecting Master Lock users; allowing me to track, among other things, where every bike user is at all time, as well as record what they are doing. If only it weren't for you meddling kid. Analogies, aren't they great? (Since it's apparent that sarcasm can't be read: "S…

If this danger is real, isn't it best to inform the consumer, or perhaps use a lawsuit to force a recall, rather than destroying other people's hardware? Does this concept apply to software? When the next large-scale RCE 0-day drops, does it make sense to use exploitation to destroy as much as possible in order to pressure the developers to ship a secure product? Since, the hacked machines certainly could allow an at…

>isn't it best to inform the consumer,

How, like 5% of people that buy electronics actually turn in the warranty cards. No, they will sit on the shelf for years polluting the internet with DDOS attacks and spam.

>es it make sense to use exploitation to destroy as much as possible in order to pressure the developers to ship a secure product?

Yes. That is also why I backup data using multiple methods including off line ones.

Vigilante or blackhat doesn't matter. The next RCE will gladly spit copies of CryptoLocker everywhere if they could get ahold of it.

The internet is a dangerous and well connected place. If lived China, I would think it's funny if I wiped a few large US corporations off the map because they used a DLINK webcam. And there is only a tiny chance in hell they would ever find me.

Re: A vigilante trying to improve IoT security

#154
post #16
post #15

Earlier quoted context omitted.

Yes. In fact, I'm going to start stealing bikes that have insecure locks.

What kind of stupid person would think that we could have a cooperative, functional society where I can just be careless with my bike, right? What's the problem with these people? Sarcasm aside, I live in Brazil, ask any Brazilian who stayed on an European country what was the biggest difference: "I could feel safe anytime, without worrying about my stuff". That really shapes the mind and behaviour of people.

>What kind of stupid person would think that we could have a cooperative, functional society where I can just be careless with my bike, right?

The same kind of stupid person that doesn't realize they live in a ghetto called "The Internet".

Re: A vigilante trying to improve IoT security

#155
post #60

Earlier quoted context omitted.

He's providing an economic benefit to society - internalizing (to consumers) the externality of IOT botnets. It's now on the consumers to further internalize to cost to manufacturers through product selection, class action, or both.

Not necessarily. If a consumer's device is bricked within the (usually 1-year) warranty period, then they're able to send it back to the manufacturer for a replacement, which pushes the cost right back to the manufacturer. Also, if the device is bricked very quickly after buying it and installing it, the consumer will very likely simply return it to the retailer as defective, which again pushes costs back to the manu…

I think that's actually the only solution to the IoT security problem: more people regularly scanning for and bricking these devices, until the return rates make it unprofitable to sell broken devices in the first place

Re: A vigilante trying to improve IoT security

#156

Earlier quoted context omitted.

The person bricking IoT's isn't getting money from that. If they did, I would hope they or you did, I would hope each of you would donate to charities.

You don't really know that for sure. That person could easily be shorting the shares of IoT device companies that they are targeting, hoping that articles like this one are written critical of the manufacturers.

They could be. But that question of could it be is clearly different from the person outright stealing money directly from victims, for whom it is much more likely they are a scam artist trying to rationalize their bad behavior.

By saying clearly different, I don't mean to minimize the actions of the vigilante. One of the chief characteristics of civil disobedience, for example, is to resolve that could it be question. By receiving the unjust punishment the dissident displays good faith with proponents and opponents. I don't yet see how pseudonymous hacktivism keeps that good faith with the public. And that seems to relegate it either be small scale, symbolic acts like this or large-scale grey hat stuff that brings lots of unwanted risks/cooptation/etc.

Re: A vigilante trying to improve IoT security

#157

Earlier quoted context omitted.

I agree, but think of it this way: imagine a doctor arguing against washing their hands. The analogy is pretty apt. Washing your hands is as effective in reducing disease as pentests are at improving security. So why are we still seeking ways to justify to ourselves that we can do without pentests? It just seems like pentests need to move from "nice" to "necessary." (Part of that is reducing their cost from $60k to $…

The bigger problem with pentests is not the current cost but, as I see it, is that security is inherently and inescapably expensive somewhere in the chain, and that vendors have been getting a free lunch for too long. The viability of security analyses/pentests will go down if your goal is to reduce the cost by an order of magnitude because the people who are any good will find something better to do--and the consume…

I think the parent was arguing that this:

> security is inherently and inescapably expensive somewhere in the chain

...is the thing that needs to change. Presumably using more automation (e.g. employing more software like http://lcamtuf.coredump.cx/afl/), such that "pen-testing" shifts from being a labor cost to a capital cost.

Re: A vigilante trying to improve IoT security

#158

Earlier quoted context omitted.

The person bricking IoT's isn't getting money from that. If they did, I would hope they or you did, I would hope each of you would donate to charities.

What they get is irrelevant, it's someone using their skill set to make others aware of a flaw. I would argue it's the exact same premise. I'm going to phish people & cause them a financial cost to teach them to be safe.

I am OK with this as well. If you put up a script on github and email an org, asking for help debugging and your script drops an ssh key, then daemonize a reverse tunnel running as that user to a VM you control, then I would blame companies and the maintainers of ssh for allowing this to work. If their board members are unaware of the risk, then shame on any human layers that hid these capabilities or were too inept to fix it. It is their fiduciary responsibility to their investors to take security and privacy seriously to protect their investments. Companies that are cavalier in this regard need not survive.

Re: A vigilante trying to improve IoT security

#159
post #87

Earlier quoted context omitted.

Engineering needs to stop being subordinate to anything but top management (if at all). An MBA can always outrank an engineer's decision and that is a big reason why we have crap devices out in the field.

Without labor laws to back something like this up, all it does is get engineers fired. Non-software engineering fields do have such laws, I believe. An MBA cannot make a civil engineer build a bridge that is unsafe because they want to save money. After all, it's the project engineer's signature on the final work. (Please correct me if I'm wrong.) On the other hand, a large proportion of startups are doing something…

I am a structural EIT. Industry focus on safety is paramount. Seniority is very much respected so there are almost no young MBAs and they exist almost exclusively at the corporate level. Only a full engineer can legally stamp off on the final drawings and the accompanying calculations and I've never really seen a business type ever try to interfere in that.

Re: A vigilante trying to improve IoT security

#160

Earlier quoted context omitted.

Whether the car is hijacked to carry out attacks, or bricked by a vigilante trying to prevent another attack, I'd be pissed. But the blame lies squarely on the manufacturer who decided "meh, securing our devices against attack sounds expensive".

I think the problem is as often not about careing, and being unaware of anything outside their little subsystem. You used to have what was essentially airgapped and self contained. But then feature x needed an ongoing net connection, and it happens to run on the same soc as feature y that talk to the can bus, and boom. Neither of the teams responsible for the features considers that something can jump from x to y, al…

> VMs sharing hardware could talk to each other using the CPU cache

That sounds similar to a paper I read ~20 years ago that described a way to move data from a high privilege process, bypassing mandatory access control (>= TCSEC B), using page faults as a covert channel.

> it happens to run on the same soc as feature y that talk to the can bus

I wonder how many people will have to die to teach car manufacturers the lesson that there shouldn't be any electrical connection at all from the internet to the breaks.

Post reply on HN