Earlier quoted context omitted.
A big factor might have been ISP-provided routers coming with random passwords printed on the underside of the router instead of uniform defaults. The same tactic would work with many IoT devices but the incentive isn't there.
What incentive pushed the manufacturers of those routers in that direction though?
Romanian Hackers Infiltrated 65% of DC Outdoor Surveillance Cameras
21–30 of 88 posts
Re: Romanian Hackers Infiltrated 65% of DC Outdoor Surveillance Cameras
#22Earlier quoted context omitted.
This is what makes me skeptical of the diversity movements in America. In Romania and even Russia it seems women are very well represented in tech and there are no movements there. It seems to me that these movements are mostly used for political maneuvering and are not helpful at all.
There is a big movement in the US! Many organizations akin to girlswhocode.com. However, with the right wing in control right now, there's a real effort to suppress the legitimacy of that movement.
Re: Romanian Hackers Infiltrated 65% of DC Outdoor Surveillance Cameras
#23DVR devices are insane. I do regular surveys of random IP addresses and find these devices everywhere . They're easily identified by the headers that the embedded servers respond with. Typically they're cheap devices from China using the same tech just with slightly different branding. They usually have default passwords like admin:admin that users aren't required to change and often have vulnerabilities that grant a…
A big factor might have been ISP-provided routers coming with random passwords printed on the underside of the router instead of uniform defaults. The same tactic would work with many IoT devices but the incentive isn't there.
For IoT devices it is harder to push through, there are no real incentives to spend on security except the potential for bad marketing once systems are compromised. In my company we usually have unique device and server generated public/private keys so compromising one device will not make the whole fleet vulnerable. This is just one of the methods. In most cases security is really hard to sell to the project managers at early stage of R&D unless they have had prior unpleasant experience or market mandated stringent requirements themselves. After all, making systems more secure is usually going to make projects longer and more costly on the paper. "Security is not part of the MVP and we will worry about it later" is way too common reaction.
Re: Romanian Hackers Infiltrated 65% of DC Outdoor Surveillance Cameras
#24Earlier quoted context omitted.
What incentive pushed the manufacturers of those routers in that direction though?
I suspect it was the ISPs who made the decision, not the manufacturers. Removing the common excuse of "my network is open, who knows who did it!" for torrenting may be the reason. Another could be to make open/easily accessible networks rarer as they started selling Wi-Fi via the provided routers.
Re: Romanian Hackers Infiltrated 65% of DC Outdoor Surveillance Cameras
#25When I was an irresponsible high school grey hat (2001) I was part of a small group of people that shared exploits. We weren't that talented, but one of the guys in our group was still able to get into the cameras in the parking lot of the CIA. This is the problem with cyber security: Even if you're the most knowledgeable organization on earth you still fuck it up. Any one person can fuck up any one thing and if it i…
Well, by now, 16 years later perhaps you will have learned about the concept of honeypots.
Re: Romanian Hackers Infiltrated 65% of DC Outdoor Surveillance Cameras
#26When I was an irresponsible high school grey hat (2001) I was part of a small group of people that shared exploits. We weren't that talented, but one of the guys in our group was still able to get into the cameras in the parking lot of the CIA. This is the problem with cyber security: Even if you're the most knowledgeable organization on earth you still fuck it up. Any one person can fuck up any one thing and if it i…
> . We weren't that talented, but one of the guys in our group was still able to get into the cameras in the parking lot of the CIA. Well, by now, 16 years later perhaps you will have learned about the concept of honeypots.
Re: Romanian Hackers Infiltrated 65% of DC Outdoor Surveillance Cameras
#27DVR devices are insane. I do regular surveys of random IP addresses and find these devices everywhere . They're easily identified by the headers that the embedded servers respond with. Typically they're cheap devices from China using the same tech just with slightly different branding. They usually have default passwords like admin:admin that users aren't required to change and often have vulnerabilities that grant a…
Re: Romanian Hackers Infiltrated 65% of DC Outdoor Surveillance Cameras
#28When I was an irresponsible high school grey hat (2001) I was part of a small group of people that shared exploits. We weren't that talented, but one of the guys in our group was still able to get into the cameras in the parking lot of the CIA. This is the problem with cyber security: Even if you're the most knowledgeable organization on earth you still fuck it up. Any one person can fuck up any one thing and if it i…
Re: Romanian Hackers Infiltrated 65% of DC Outdoor Surveillance Cameras
#29Earlier quoted context omitted.
I suspect it was the ISPs who made the decision, not the manufacturers. Removing the common excuse of "my network is open, who knows who did it!" for torrenting may be the reason. Another could be to make open/easily accessible networks rarer as they started selling Wi-Fi via the provided routers.
could be ISPs trying to improve user security generally to prevent lots of their customers becoming DDOS zombies resulting in more contention & customer complaints.
Re: Romanian Hackers Infiltrated 65% of DC Outdoor Surveillance Cameras
#30Earlier quoted context omitted.
> . We weren't that talented, but one of the guys in our group was still able to get into the cameras in the parking lot of the CIA. Well, by now, 16 years later perhaps you will have learned about the concept of honeypots.
How do you imagine a camera honeypot at the CIA parking lot? They'd still be leaking a lot of information if the image was true.