It's all fine and well until one of those improperly configured devices are a medical device or something critical. Yes I understand that's part of the problem, but proving a point with risk isn't the right answer either. Every Dialysis machine i've seen runs windows xp, which any security professional will tell you is game over, but given the market hasn't provided an alternative, it's becomes a necessity to figure…
A vigilante trying to improve IoT security
171–180 of 242 posts
Re: A vigilante trying to improve IoT security
#172Earlier quoted context omitted.
Ok, but we do have "attractive nuisance" laws. If you leave out a trampoline next to barbed wire, you can be accountable even if you didn't actually permit anyone to use it. This actually seems much closer to the IoT issue than theft. The maker and user of the device have created an inviting target which will cause harm to someone other than themselves. Even if the eventual attack is illegal, they can still be held a…
Honestly, I've never heard of a law like that. The U.S. is a big place; whereas that may be the case in parts of the country, in the south where I'm from, that's never become known to me, especially in the rural areas where I grew up. Instead, the people using your things without permission are at the very least trespassing.
Re: A vigilante trying to improve IoT security
#173It's all fine and well until one of those improperly configured devices are a medical device or something critical. Yes I understand that's part of the problem, but proving a point with risk isn't the right answer either. Every Dialysis machine i've seen runs windows xp, which any security professional will tell you is game over, but given the market hasn't provided an alternative, it's becomes a necessity to figure…
Medical or critical devices should never be exposed to the Internet, especially if badly configured. If there's something illegal involved here is putting lives at risk by not implementing proper security.
If I had to find an analogy, that's like someone hung a grand piano using a shoestring from a roof and the hacker cuts the string letting the piano fall at 4:00 in the morning before it breaks later with much higher probability of killing people. It's still a dangerous and wrong act, but it prevents a much worse one.
Re: A vigilante trying to improve IoT security
#174Earlier quoted context omitted.
I'm the author of the Gizmodo post. Having covered IoT hacks for a few years, it's obvious that drastic measures would be necessary to convince manufacturers to build more secure products. While I'm not necessarily endorsing this hacker's methods, I do salute his taking a stand. It might land him in jail. But still, the mission is worthwhile.
Engineering needs to stop being subordinate to anything but top management (if at all). An MBA can always outrank an engineer's decision and that is a big reason why we have crap devices out in the field.
On the one hand, this certainly makes a lot of sense, especially these days with so many stories about terrible engineering (either just bad or as a result of unethical behavior) causing real harm.
On the other hand, it's precisely organizations like this (effectively guilds or unions) that tech "leaders" try to disrupt. They tend to be pretty conservative.
Re: A vigilante trying to improve IoT security
#175As someone who works as a software consultant for many IoT and connected device companies, how can I increase my understanding of IoT security? How can I ensure the devices I work with are secure?
Since posting this, I did some research, and it looks like the biggest security problem (currently) is manufacturers hardcoding default passwords into the firmware. Here I am thinking I need to become an expert in security to help my clients secure their devices, but is it really as simple as encouraging clients to set secure, default passwords?
Anything else would be dependent on what the device is for and how it does it.
Re: A vigilante trying to improve IoT security
#176Earlier quoted context omitted.
I'm the author of the Gizmodo post. Having covered IoT hacks for a few years, it's obvious that drastic measures would be necessary to convince manufacturers to build more secure products. While I'm not necessarily endorsing this hacker's methods, I do salute his taking a stand. It might land him in jail. But still, the mission is worthwhile.
Engineering needs to stop being subordinate to anything but top management (if at all). An MBA can always outrank an engineer's decision and that is a big reason why we have crap devices out in the field.
Re: A vigilante trying to improve IoT security
#177Earlier quoted context omitted.
"It's all fine and well until one of those improperly configured devices are a medical device or something critical. " It would be their fault. High-assurance industry has been telling SCADA and medical industry to get their shit together for a long time. This included pentests showing it could all be destroyed. They even have people at conferences talking about it with products or basic advice to deal with it. The r…
I've brought this up to others, how would you feel if someone decided to brick / modify your car without you knowing? What would you do if that fix backfired and caused damage, hard locked the controls on your car, or worse, simply shut it off at the wrong time? We absolutely need to fix these issues, the governments of the world need to enforce standards on products, but vigilantism no matter how much you may agree…
1. A car is a necessity that cost a ton to replace. An internet-connected camera or TV isnt. They could just as easily not buy an Internet-enabled appliance.
2. These devices are being used as weapons when people leave them around insecure. Leaving loaded guns lying around is a bit closer but minus the lethality.
3. With cars, we have efforts on safety and security at user side, manufacturer side, and the law. There's no effort to buy secure IoT by these users, to do even minimum protections at manufacturing, or pass laws putting liability on users or manufacturers where it should be. Now, it's more like a car with defective parts that make it hit other cars. A city's worth are affected with nobody taking action but people are told armored cars are available for a fortune.
So, these comparisons to highly damaging thefts of legit goods on innocent people are nonsense. There's defective products damaging innocent people. Nobody with power to prevent or punish it legitimately is doing anything. Im happy that a vigilante is reducing risk to Internet hosts plus putti g cost on those responsible for that risk.
Re: A vigilante trying to improve IoT security
#178> if somebody launched a car or power tool with a safety feature that failed 9 times out of 10 it would be pulled off the market immediately. I don’t see why dangerously designed IoT devices should be treated any differently Really? He doesn't see how a car is different from a webcam? And why there are different safety standards for each? Their goal is laudable, but this seems like a fun way to engage in vandalism wh…
Re: A vigilante trying to improve IoT security
#179Earlier quoted context omitted.
He's providing an economic benefit to society - internalizing (to consumers) the externality of IOT botnets. It's now on the consumers to further internalize to cost to manufacturers through product selection, class action, or both.
How does your opinion change with Phishing attacks? I'm going to steal funds from businesses by phishing vulnerable people, because If I don't capitalize on it, then people won't understand the costs / risks.
That's what the IoT vendors did. ;)
Re: A vigilante trying to improve IoT security
#180Earlier quoted context omitted.
Engineering needs to stop being subordinate to anything but top management (if at all). An MBA can always outrank an engineer's decision and that is a big reason why we have crap devices out in the field.
Without labor laws to back something like this up, all it does is get engineers fired. Non-software engineering fields do have such laws, I believe. An MBA cannot make a civil engineer build a bridge that is unsafe because they want to save money. After all, it's the project engineer's signature on the final work. (Please correct me if I'm wrong.) On the other hand, a large proportion of startups are doing something…
So, yeah, even in softwarw one can do as you suggest. Multiple times it's been done with things improving across the board. In DO-178B, an additional effect is an ecosystem of tooling, reusable components, and consultants sprang up to make each project a bit cheaper and less risky.