Live data from Hacker News

Internet of Crappy Things

blog.kaspersky.com

31–40 of 95 posts

Re: Internet of Crappy Things

#32
post #4

I hate to be running to the government for this, but... the FCC has regulations that require some level of testing for devices that are going to use certain parts of the spectrum. Some parts have been declared "free zones" and I believe that's where the wifi systems tend to operate. Perhaps we need the FCC to step in there and mandate some basic security certification for connected devices. At the very least the cert…

I agree with the sentiment but do you really trust the government can actually audit some giant codebase? The internet of things really includes your computer and your PS4 and every piece of software on them. It includes your router and your printer and your IP cam that's basically the same thing as your router with camera attached. I don't know what the solution is but I really can't imagine a government body able t…

> I don't know what the solution is but I really can't imagine a government body able to audit all that code in any meaningful way.

The NSA doesn't seem to have any trouble hiring top-notch reverse engineers. There's no reason to believe that the same approach couldn't work to benefit the country if the combination of mission & budget for competitive salaries were applied to defense instead.

That said, the first thing I'd start with would be much simpler: mandatory support where device manufacturers are required to issue security & reliability updates for 10 years[1] or release all of the source code, tools and signing keys into the public domain so there's at least the possibility of user support.

1. Most people expect a car or major appliance to last at least that long without becoming unsafe.

Re: Internet of Crappy Things

#33
I agree that not every device needs to be connected, and there are security implications for those devices that could benefit from being connected. IoT will continue in a big way, and just like the early deys of the Internet, security solutions will develop. It would have been nice if Kapersky would have offered something in the way of potential solutions in this post.

Re: Internet of Crappy Things

#34
post #11

I continue to fail to see how connecting appliances or small electronics to a network adds actual value. Simply throwing technology at a thing doesn't automatically make it better. Yet, here we are, rushing headlong into the "IoT". We ought to recognize this for what it is: pursuit of profit from uninformed purchasers.

One great feature would be to warn someone that they left the house with the stove on.

Certainly nothing is made better automatically, but there are a lot of features you can design and build.

Re: Internet of Crappy Things

#35
post #11

I continue to fail to see how connecting appliances or small electronics to a network adds actual value. Simply throwing technology at a thing doesn't automatically make it better. Yet, here we are, rushing headlong into the "IoT". We ought to recognize this for what it is: pursuit of profit from uninformed purchasers.

One great feature would be to warn someone that they left the house with the stove on. Certainly nothing is made better automatically, but there are a lot of features you can design and build.

That's solving the wrong end of the problem, which is the big problem of half of these devices.

For example, Halogen hobs turn off if there are no pans for a period of time. Much cleaner solution.

Re: Internet of Crappy Things

#36
I know these aren't all web-based hacks, but I'm guessing the majority of connected devices are using http. Simply switching to https everywhere would remove a huge amount of attack surface for almost no cost.

Re: Internet of Crappy Things

#37
post #7

There are two things that can break IoT, security and fracturing. But security is a necessary condition for IoT to succeed. I know Apple has surprised many of the companies that want to work with HomeKit with its security requirements. I heard from one company that, for example, was upset that locks cannot be remotely activated. The last thing anyone needs is their house getting hacked and robbed as well.

Ironically, fracturing has superficially improved security for the moment. Devices with the largest user base get a disproportionate amount of the attacks.

Re: Internet of Crappy Things

#38
post #36

I know these aren't all web-based hacks, but I'm guessing the majority of connected devices are using http. Simply switching to https everywhere would remove a huge amount of attack surface for almost no cost.

This is partly due to the big red warnings you get with self-signed certificates. Yes, it would certainly help, but to the user seeing a crossed-out https is worse than a simple http. And the user's perception matters much more than security does to these people.

Re: Internet of Crappy Things

#39
post #20

The push is that all devices will end up connected as commodity manufacturers continue to search for 'value-add' services (even if that value is dubious). In a few years, I wouldn't be surprised if 'smart TVs' were the only ones available. Security also becomes an afterthought as companies rush to get products in the market. This is mainly because the components used to build software rarely take account of security/…

- "In a few years, I wouldn't be surprised if 'smart TVs' were the only ones available. "

To your point: when I purchased a new TV last year, the only available "non-Smart" models were of generally inferior quality to the Smart models, from picture quality to physical design. I ended up purchasing one simply because it was the best TV at its price point—I had no interest in the "Smart" features.

Post reply on HN