Live data from Hacker News

A vigilante trying to improve IoT security

gizmodo.com

181–190 of 242 posts

Re: A vigilante trying to improve IoT security

#181
post #96
post #79

Earlier quoted context omitted.

Then fix your lightbulb so that someone can't tell you how to handle your lightbulbs. If you can't reach that low bar then why are you even connecting to the internet? You are implicitly allowing your tools to be used for botnets which should be a crime in itself.

So you think the consumers should be punished for something you think the producers do wrong? Do you apply this to other products as well? Would it be ok to soak peoples cigarettes in water, break the motor of your neighbours high fuel consuming SUV or destroy the guns of people since these products can cause damage to other people?

I addressed that here:

https://news.ycombinator.com/item?id=14207953

Re: A vigilante trying to improve IoT security

#183

Earlier quoted context omitted.

The problem is, I think, what choice do we have (we == rest of the world) when somebody's messed up camera starts spamming the entire Internet? And how much does cost the mirai botnet to everyone when some client rents it? Best case scenario: users claim warranty and replace their devices something better Worst case scenario: users need to buy new gear, they probably won't buy from that same manufacturer because last…

Really worst-case scenario: Someone is killed or maimed due to bricked system. FTFY

I was particularly thinking of baby monitors during an emergency. It was most important house-hold device I could think of in terms of harm. Maybe turn a freezer off on IoT fridge while people are on vacation then back on just before they return to make meat refreeze or something spoiled. Maybe turn off the power in household with IoT home automation and someone on life support of some kind.

Im only having a few possibilities come to mind that are life-threatening. Most are just annoying or financial drain. If we add painful, maybe make an epileptic's screen on SmartTV blink fast like the attack on the web site. Turn off people's alarm clock enough they get fired and loose health insurance before major operation. Im really having to stretch it here.

Re: A vigilante trying to improve IoT security

#184
post #96
post #79

Earlier quoted context omitted.

Then fix your lightbulb so that someone can't tell you how to handle your lightbulbs. If you can't reach that low bar then why are you even connecting to the internet? You are implicitly allowing your tools to be used for botnets which should be a crime in itself.

So you think the consumers should be punished for something you think the producers do wrong? Do you apply this to other products as well? Would it be ok to soak peoples cigarettes in water, break the motor of your neighbours high fuel consuming SUV or destroy the guns of people since these products can cause damage to other people?

The analogy would be, someone leaves their cigarettes or their gun out on the stoop all night, or their SUV on the street unlocked with the keys in the ignition. If they do that, something is going to happen to it eventually. Especially if they live on a street that actually spans the entire world, and whose entire length can be traversed in one second.

John J. Citizen should be thankful if the person who finds it only wants to deactivate it rather than use it to poison him / shoot him / run him over. No matter who finds it though, it's tough luck for that person; they're the owner of that item in name only, if they don't secure it.

Society has decided in some cases (in domains well-understood by legislators, unlike IoT) that the person doesn't deserve to keep that item if they don't secure it. Example: "Improper storage of a firearm" or the like, is literally a crime in many jurisdictions and can result in losing your gun license. Creating a burden on or a danger to society through your neglect has in that case been affirmed to be unacceptable. The law will catch up with this too, I hope.

Re: A vigilante trying to improve IoT security

#185
post #169

Earlier quoted context omitted.

Engineering needs to stop being subordinate to anything but top management (if at all). An MBA can always outrank an engineer's decision and that is a big reason why we have crap devices out in the field.

Of course the other way around most often just gives you devices in the field nobody buys. In this, like most things, you need a balance. If you aren't commercially driven in some fundamental way you probably won't last long enough for any of this to make a difference. Of course if you apply that the wrong way, you end up with devices that suck and/or harm users. This way leads to regulation typically, since Smiths i…

> Smiths invisible and myopic hand

I'm intrigued by this phrase, could you explain it please?

Re: A vigilante trying to improve IoT security

#186
It's simple for manufacturers to make their devices secure from corruption. Put the firmware in ROM. Malware will not survive rebooting the device.

If you really must be able to update the firmware, add a physical "write enable" switch, not a software enabled one.

Re: A vigilante trying to improve IoT security

#188

Earlier quoted context omitted.

I'm the author of the Gizmodo post. Having covered IoT hacks for a few years, it's obvious that drastic measures would be necessary to convince manufacturers to build more secure products. While I'm not necessarily endorsing this hacker's methods, I do salute his taking a stand. It might land him in jail. But still, the mission is worthwhile.

Engineering needs to stop being subordinate to anything but top management (if at all). An MBA can always outrank an engineer's decision and that is a big reason why we have crap devices out in the field.

Yes, no engineer has ever made a bad design or decision, ever.

Re: A vigilante trying to improve IoT security

#189

It's all fine and well until one of those improperly configured devices are a medical device or something critical. Yes I understand that's part of the problem, but proving a point with risk isn't the right answer either. Every Dialysis machine i've seen runs windows xp, which any security professional will tell you is game over, but given the market hasn't provided an alternative, it's becomes a necessity to figure…

Why would a Dialysis machine even need an internet connection?

Re: A vigilante trying to improve IoT security

#190
post #188

Earlier quoted context omitted.

Engineering needs to stop being subordinate to anything but top management (if at all). An MBA can always outrank an engineer's decision and that is a big reason why we have crap devices out in the field.

Yes, no engineer has ever made a bad design or decision, ever.

That's totally besides the point.

The idea here is that no engineer would knowingly sign off on something bad.

Post reply on HN