Live data from Hacker News

A vigilante trying to improve IoT security

gizmodo.com

201–210 of 242 posts

Re: A vigilante trying to improve IoT security

#201

Earlier quoted context omitted.

I was particularly thinking of baby monitors during an emergency. It was most important house-hold device I could think of in terms of harm. Maybe turn a freezer off on IoT fridge while people are on vacation then back on just before they return to make meat refreeze or something spoiled. Maybe turn off the power in household with IoT home automation and someone on life support of some kind. Im only having a few poss…

Alarm system with remote fire alarm capability. Those things are everywhere and if they don't work people could easily die.

That's a great one. Good catch.

Re: A vigilante trying to improve IoT security

#202
post #169

Earlier quoted context omitted.

Of course the other way around most often just gives you devices in the field nobody buys. In this, like most things, you need a balance. If you aren't commercially driven in some fundamental way you probably won't last long enough for any of this to make a difference. Of course if you apply that the wrong way, you end up with devices that suck and/or harm users. This way leads to regulation typically, since Smiths i…

> Smiths invisible and myopic hand I'm intrigued by this phrase, could you explain it please?

https://en.m.wikipedia.org/wiki/Invisible_hand

Adam Smith used the phrase "invisible hand" to describe the way markets reward certain business ventures. The previous poster called the invisible hand "myopic" in reference to consumers being focused on cheap devices with features that immediately benefit themselves.

Re: A vigilante trying to improve IoT security

#203

It's all fine and well until one of those improperly configured devices are a medical device or something critical. Yes I understand that's part of the problem, but proving a point with risk isn't the right answer either. Every Dialysis machine i've seen runs windows xp, which any security professional will tell you is game over, but given the market hasn't provided an alternative, it's becomes a necessity to figure…

> until one of those improperly configured devices are a medical device or something critical. Medical or critical devices should never be exposed to the Internet, especially if badly configured. If there's something illegal involved here is putting lives at risk by not implementing proper security. If I had to find an analogy, that's like someone hung a grand piano using a shoestring from a roof and the hacker cuts…

To play devil's advocate on that, if there's some super sensitive life support system that's indirectly connected to the internet it's probably going to be turned off until it's actually in use.

Re: A vigilante trying to improve IoT security

#204
post #97

Earlier quoted context omitted.

"I don't really see in this case how they (or mostly anyone) is unable to improve IoT (or general) security through other means" Really? How about you show me the evidence that people are... through "other means"... improving IOT security of these devices enough that DDOS isn't a big problem any more. I'd love to hear what you've done to convince all the vendors to focus on secure devices instead of profit when targe…

> How about you show me the evidence that people are [...] I've made my argument. Why don't you take part in the discussion and make some of your own to why this is meaningful? > I'd love to hear what you've done to convince all the vendors [...] Why is it at all relevant what I've done and especially since when you don't say what you've done? > Most of us in INFOSEC haven't been able to convince [...] I haven't seen…

"I've made my argument."

You didn't make an argument. You made a false claim that there were other methods that work and/or an implication that there wasn't much effort on doing that. All kinds of people have spent decades doing that. They get ignored.

"Why is it at all relevant what I've done and especially since when you don't say what you've done?"

"I haven't seen much convincing being done."

Programmers, support people, architects, tech managers, security experts, and so on have failed to do what you suggested because of greed and apathy of manufacturers. They write about it all the time on blogs, esp basic QA. They write about it here, too. I asked what you had done since you might have seen people successful at convincing greedy, hardware manufacturers at doing security at a loss. We obviously haven't.

""INFOSEC" (all caps of course because we want to be cool like the military)"

People in the military invented computer security. They taught me. Don't get excited because they called it "COMPUSEC" to differentiate between it and "COMSEC." CompSci and business called it information security w/ INFOSEC being a short-hand. Later, many in business started calling it IT Security or ITSEC. It's a business term that people from high-security, regulated backgrounds, some civilians, and military all use these days. We speak differently to laypersons in management or policy-making vs how we talk to HN techies. Nice try at trolling, red herring, though.

"Yes, you're still not making an argument why these actions would in any way would be a effective way to regulation."

I just told you regulations on information security were passed that worked and led to secure devices hitting the market. It happened twice at least. Obviously, that means there's a good chance regulating in a similar way with modern knowledge would do the same thing again. Meanwhile, nobody is doing anything at any level, you can't convince businesses to do anything in general case, and so a vigilante breaching defective, damaging stuff might be only progress we can get in meanwhile. Reduces risk and decreases demand for garbage products. Vendors might get message like Microsoft did leading to their 180 in security.

Re: A vigilante trying to improve IoT security

#205

It's all fine and well until one of those improperly configured devices are a medical device or something critical. Yes I understand that's part of the problem, but proving a point with risk isn't the right answer either. Every Dialysis machine i've seen runs windows xp, which any security professional will tell you is game over, but given the market hasn't provided an alternative, it's becomes a necessity to figure…

If someone has life-sustaining medical equipment on a public network, they have lost their minds. Everything about that is likely subject to privacy regulations of some kind. It would violate best practices of network security with a vengeance.

If someone has life-sustaining medical equipment and they're not maintaining it by ensuring it gets it's patches in a timely fashion, then that right there is where the blame starts. Doing so is no better than ignoring frayed wires on an extension cord.

The real horror is that such poorly designed devices would ever be deployed for such important uses. Things like BrickerBot don't even show up on the same scale.

Re: A vigilante trying to improve IoT security

#206
post #87

Earlier quoted context omitted.

Without labor laws to back something like this up, all it does is get engineers fired. Non-software engineering fields do have such laws, I believe. An MBA cannot make a civil engineer build a bridge that is unsafe because they want to save money. After all, it's the project engineer's signature on the final work. (Please correct me if I'm wrong.) On the other hand, a large proportion of startups are doing something…

I am a structural EIT. Industry focus on safety is paramount. Seniority is very much respected so there are almost no young MBAs and they exist almost exclusively at the corporate level. Only a full engineer can legally stamp off on the final drawings and the accompanying calculations and I've never really seen a business type ever try to interfere in that.

Keyword: legally. Spftware is often built to the cheapest spec that'll sell. Even peacemaker are often carring vulnerabilities.

Re: A vigilante trying to improve IoT security

#207
post #60

Earlier quoted context omitted.

He's providing an economic benefit to society - internalizing (to consumers) the externality of IOT botnets. It's now on the consumers to further internalize to cost to manufacturers through product selection, class action, or both.

How does your opinion change with Phishing attacks? I'm going to steal funds from businesses by phishing vulnerable people, because If I don't capitalize on it, then people won't understand the costs / risks.

Probably it doesn't change, because those aren't at all analogous situations.

Re: A vigilante trying to improve IoT security

#208
post #188

Earlier quoted context omitted.

Yes, no engineer has ever made a bad design or decision, ever.

That's totally besides the point. The idea here is that no engineer would knowingly sign off on something bad.

A rather optimistic idea, I'd contend.

Re: A vigilante trying to improve IoT security

#209
post #60

Earlier quoted context omitted.

He's providing an economic benefit to society - internalizing (to consumers) the externality of IOT botnets. It's now on the consumers to further internalize to cost to manufacturers through product selection, class action, or both.

Not necessarily. If a consumer's device is bricked within the (usually 1-year) warranty period, then they're able to send it back to the manufacturer for a replacement, which pushes the cost right back to the manufacturer. Also, if the device is bricked very quickly after buying it and installing it, the consumer will very likely simply return it to the retailer as defective, which again pushes costs back to the manu…

I was on the fence about this vigilante bricking until reading your comment. Pushing the cost back to the manufacturer in this case should make considerable difference since these are low-cost devices and therefore the cost to the manufacturer of each return will probably cancel the profit of the last ten sold. Those proportions will become hard to ignore.

Re: A vigilante trying to improve IoT security

#210
I am fascinated by the somewhat Darwinian trajectory that this might take. Let's project forward ten or twenty year to when that smart lighbulb has the computing power of 1990s era supercomputer. Might all the lighbulbs in my neighborhood form an intelligent swarm? Will the be engaged in inter-swarm battles? It's not like there's an "off" button. Has any good sci-fi explored this topic?
Post reply on HN