Live data from Hacker News

A vigilante trying to improve IoT security

gizmodo.com

191–200 of 242 posts

Re: A vigilante trying to improve IoT security

#191

It's all fine and well until one of those improperly configured devices are a medical device or something critical. Yes I understand that's part of the problem, but proving a point with risk isn't the right answer either. Every Dialysis machine i've seen runs windows xp, which any security professional will tell you is game over, but given the market hasn't provided an alternative, it's becomes a necessity to figure…

Why would a Dialysis machine even need an internet connection?

Because the sales guy insisted it'd help sales.

Re: A vigilante trying to improve IoT security

#192

Earlier quoted context omitted.

I've done intentionally insecure things because I simply straight-up did not have time to do them correctly. Shared keys, shared password across an entire infra--lots of stupid things because my deadline wasn't moving and hours counted. The difference, of course, is that I retain control of my stuff and I'm not pushing things out to other people. Pentests are, to be clear, great, and there are plenty of people who Du…

I agree, but think of it this way: imagine a doctor arguing against washing their hands. The analogy is pretty apt. Washing your hands is as effective in reducing disease as pentests are at improving security. So why are we still seeking ways to justify to ourselves that we can do without pentests? It just seems like pentests need to move from "nice" to "necessary." (Part of that is reducing their cost from $60k to $…

It pen testing necessarily expensive? I wonder if we could train QA to use something like kali (or even just some network tools) to find 99% of vulnerabilities.

Re: A vigilante trying to improve IoT security

#193

Earlier quoted context omitted.

Really worst-case scenario: Someone is killed or maimed due to bricked system. FTFY

I was particularly thinking of baby monitors during an emergency. It was most important house-hold device I could think of in terms of harm. Maybe turn a freezer off on IoT fridge while people are on vacation then back on just before they return to make meat refreeze or something spoiled. Maybe turn off the power in household with IoT home automation and someone on life support of some kind. Im only having a few poss…

Alarm system with remote fire alarm capability. Those things are everywhere and if they don't work people could easily die.

Re: A vigilante trying to improve IoT security

#194
post #20

Earlier quoted context omitted.

wait a fucking minute people are connecting medical devices to the internet?

It might not be connected to the internet in an IoT way, but it makes a lot of sense to connect a device to a wi-fi network if you need to wirelessly transmit any form of data.

[deleted]

Re: A vigilante trying to improve IoT security

#195
post #188

Earlier quoted context omitted.

Engineering needs to stop being subordinate to anything but top management (if at all). An MBA can always outrank an engineer's decision and that is a big reason why we have crap devices out in the field.

Yes, no engineer has ever made a bad design or decision, ever.

Perfect is the enemy of good.

Re: A vigilante trying to improve IoT security

#196
Didn't a grey hat similarly flash a ton of old routers following heartbleed? Search isn't providing results atm, but I do recall an uptick in retail routers failing post HB news wave, with little mentioned as to the "why". If memory serves, it didn't "brick" them, it broke DHCP(no longer assigned dynamic addressing; WAN or LAN).

Re: A vigilante trying to improve IoT security

#197
post #162

Earlier quoted context omitted.

This captures the essence of the type of activism that I so dislike — an unaffected, third party (a person who doesn't use your bluetooth lightbulb) taking the job upon himself to tell you what level of security your lightbulb should employ... By breaking it.

I don't see this as activism per se. I see this as similar to a virus or bacterium coming into existence, forcing us toward better hygiene practices. You don't blame a virus or bacteria for existing; it's just sort of... there, part of the ecosystem. Instead, you blame things for being vulnerable to it and therefore spreading it. You try to kill it not by eliminating its "source", but by eliminating the spread. Right…

If I created a virus to punish people for failing to wash their hands regularly, and instead of giving them diarrhea it started killing people, I should absolutely get the blame for creating it. Even if it doesn't kill anyone I should still be held accountable.

Yes, this a rotten situation, and I sympathize with the motivation. No, I don't think we should blithely disregard the fact that the worm is likely causing genuine harm and that it was in fact created to cause harm.

Re: A vigilante trying to improve IoT security

#198

It's all fine and well until one of those improperly configured devices are a medical device or something critical. Yes I understand that's part of the problem, but proving a point with risk isn't the right answer either. Every Dialysis machine i've seen runs windows xp, which any security professional will tell you is game over, but given the market hasn't provided an alternative, it's becomes a necessity to figure…

Stoplights are often installed after {n} number of people die at an intersection to justify the cost. Is that cool? Regulations are put on companies after their freedom of choice; when abused, starts harming people. I think IoT is a perfect example of this. Today the manufactures have a great deal of freedom. Their lack of self regulation will require others to step in and regulate them. On the matter of vigilantes:…

I don't think the connection will ever be direct enough for the masses to care, there will never been an equivalent of dead bodies hanging out of car wreckage at an intersection.

If someones dishwasher is streaming pirated movies would they care? If their children's bedroom were unknowingly being streamed to pedophiles would the care (obviously they wouldn't like it, but caring requires knowing)?

Vigalantes may be the least worst option.

Re: A vigilante trying to improve IoT security

#199

Earlier quoted context omitted.

I'm the author of the Gizmodo post. Having covered IoT hacks for a few years, it's obvious that drastic measures would be necessary to convince manufacturers to build more secure products. While I'm not necessarily endorsing this hacker's methods, I do salute his taking a stand. It might land him in jail. But still, the mission is worthwhile.

Engineering needs to stop being subordinate to anything but top management (if at all). An MBA can always outrank an engineer's decision and that is a big reason why we have crap devices out in the field.

Is it that simple? Having veto over certain decisions might solve some vectors, but security isn't an item to check off before you release a product, it's an ongoing maintenance concern because it's living in an ever evolving ecosystem.

Being able to put your foot down doesn't allocate resources for security updates.

Re: A vigilante trying to improve IoT security

#200
post #162

Earlier quoted context omitted.

I don't see this as activism per se. I see this as similar to a virus or bacterium coming into existence, forcing us toward better hygiene practices. You don't blame a virus or bacteria for existing; it's just sort of... there, part of the ecosystem. Instead, you blame things for being vulnerable to it and therefore spreading it. You try to kill it not by eliminating its "source", but by eliminating the spread. Right…

If I created a virus to punish people for failing to wash their hands regularly, and instead of giving them diarrhea it started killing people, I should absolutely get the blame for creating it. Even if it doesn't kill anyone I should still be held accountable. Yes, this a rotten situation, and I sympathize with the motivation. No, I don't think we should blithely disregard the fact that the worm is likely causing ge…

I didn't mean that someone is not "to blame"; more just that a framing which even brings up who's "to blame" vastly overstates the "use" of punishing humans in defending oneself against this problem. Indeed, even if we catch "cyberterrorists" at a constant rate, this problem will only get worse: there will be more people; each person will have more and more programmable automation available to them, more and more easily; and people will grow more proficient with technology earlier and earlier in their lives (i.e. long before they've built up any sort of idea of ethics.)

Right now we have script-kiddy teenagers; Real Soon Now there won't be much reason to expect your average 5-year-old with a Youtube account, won't be able to slap together something like a ransomware worm from readily-available components, that will spread itself a billionfold. And, amongst 7 billion people and growing, there's going to be a lot of kids thinking that that sounds like a fun time.

The only thing to really stop this from being the world we live in, is making worms irrelevant.

(And what we do in the short term, about this case? Honestly, I haven't bothered to think about it. Too "identity politics.")

Post reply on HN