Live data from Hacker News

Internet of Crappy Things

blog.kaspersky.com

51–60 of 95 posts

Re: Internet of Crappy Things

#51
post #6

We're currently working on a consumer device that could well be classified in the IoT category. We're pushing hard to put in multiple good layers of security, even though the hackable potential of the device is low. The amount of personal or otherwise exploitable information is also low. But that is no excuse to leak anything, or to allow the device to be taken over by attackers. The path isn't easy... the library su…

Will you have automatic upgrades for the life of the device?

Re: Internet of Crappy Things

#52
Presumably the "things" are networked via wifi? In that case I just won't enter my wifi creds, and they'll remain off the network. Possibly some devices might be more valuable when networked with each other locally, and the WAP they use just won't get connected upstream.

Of course the things will still be vulnerable if they just connect automatically to any visible rogue WAP, in which case maybe one could glue some lead sheets around the antenna. The only government reaction to this phenomenon I would welcome would be a requirement for device vendors to clearly label devices that automatically connect to any visible WAP, or will only function when connected to the public internet.

Demanding that devices like this be "secure" is silly. Only devices the firmware of which is regularly, securely updated, which update process is regularly observed by human beings, can even hope to be effectively secure for any period. We probably can expect that from POS devices in corporate use. We probably can't expect that from a refrigerator in some random family kitchen.

Re: Internet of Crappy Things

#53
post #7

There are two things that can break IoT, security and fracturing. But security is a necessary condition for IoT to succeed. I know Apple has surprised many of the companies that want to work with HomeKit with its security requirements. I heard from one company that, for example, was upset that locks cannot be remotely activated. The last thing anyone needs is their house getting hacked and robbed as well.

Remotely activated locks? What's the use case for this? Call your girlfriend when you're locked outside your house and ask her to open the door with her cellphone?

There seems to be a high risk for little benefit, or perhaps I don't have a lot of imagination.

Re: Internet of Crappy Things

#54
post #4

I hate to be running to the government for this, but... the FCC has regulations that require some level of testing for devices that are going to use certain parts of the spectrum. Some parts have been declared "free zones" and I believe that's where the wifi systems tend to operate. Perhaps we need the FCC to step in there and mandate some basic security certification for connected devices. At the very least the cert…

Noooooooo!

The only reason we have wireless innovation outside of the military is that we have these "free zones". The problems we have today aren't radio problems -- which is what the FCC is there for. It's application layer issues that exist whether you are wired or unwired, private or public networks.

We're in an early adopter phase, so products are immature. You shouldn't be allowing IoT devices in high security environments, or incorporating devices into structures that cannot be retrofitted in 5 years until we move a little further up the lifecycle.

If you want high assurance controllers for light fixtures, motors, and other IoT use cases, you need to talk to Johnson Controls, Honeywell, and similar companies and pay for the privilege.

Re: Internet of Crappy Things

#55
I was hoping to read more about the crappy quality of most "things" in the Internet of Things (The Nest thermostat is an exception to the rule). To cut costs, the sensors involved are usually very simple, "dumb", often built poorly with low quality components and not integrated very well. It's up to the software, which often isn't written that well either, to compensate. Just getting the system to work is difficult enough with the budget, time, and resources available. Never mind securing it. So, welcome to the Internet of Things that don't work half the time and could probably hurt or kill by accident.

Re: Internet of Crappy Things

#56

Presumably the "things" are networked via wifi? In that case I just won't enter my wifi creds, and they'll remain off the network. Possibly some devices might be more valuable when networked with each other locally, and the WAP they use just won't get connected upstream. Of course the things will still be vulnerable if they just connect automatically to any visible rogue WAP, in which case maybe one could glue some l…

Some HP printers, P1102w, have wifi cards, and when not associated with an access point, they will broadcast their own open network. There is no way to disable this except to open it up and remove the wifi card.

I think some Roku models will also broadcast a wifi access point for the remote control to connect to.

Re: Internet of Crappy Things

#57
post #11

I continue to fail to see how connecting appliances or small electronics to a network adds actual value. Simply throwing technology at a thing doesn't automatically make it better. Yet, here we are, rushing headlong into the "IoT". We ought to recognize this for what it is: pursuit of profit from uninformed purchasers.

I think that connecting devices directly to the Internet is great nonsense and great danger to our privacy and security. Still it would make sense to have an possibility to connect them to local network.

local network = internet

Re: Internet of Crappy Things

#58
post #4

I hate to be running to the government for this, but... the FCC has regulations that require some level of testing for devices that are going to use certain parts of the spectrum. Some parts have been declared "free zones" and I believe that's where the wifi systems tend to operate. Perhaps we need the FCC to step in there and mandate some basic security certification for connected devices. At the very least the cert…

I agree with the sentiment but do you really trust the government can actually audit some giant codebase? The internet of things really includes your computer and your PS4 and every piece of software on them. It includes your router and your printer and your IP cam that's basically the same thing as your router with camera attached. I don't know what the solution is but I really can't imagine a government body able t…

The government wouldn't be doing the work. We just need the legal framework in place. The industry would do it themselves, but they don't now since there are no real consequences. There should be. We have plenty of rules around how medical records are treated. There needs to be similar rules for all this stuff.

Re: Internet of Crappy Things

#59
post #45

Earlier quoted context omitted.

@tootie didn't say anything about the certificates being self-signed. Later this year, the new Let's Encrypt CA will make it free and easy to get certificates.[1] Moreover, it's my understanding that the default with HTTP/2 is for connections to be secure. [1] https://www.eff.org/deeplinks/2014/11/certificate-authority-...

But then you'd have to update the certs, which an appliance manufacturer isn't going to do.

Why not? If they're going to go to all the trouble to "Internet enable" a refrigerator, surely they can include yearly certificate changes as part of their maintenance plan.

Re: Internet of Crappy Things

#60
post #11

I continue to fail to see how connecting appliances or small electronics to a network adds actual value. Simply throwing technology at a thing doesn't automatically make it better. Yet, here we are, rushing headlong into the "IoT". We ought to recognize this for what it is: pursuit of profit from uninformed purchasers.

It adds value, just not for the consumer or user. Note that I didn't say owner as this internet of thing is actually the internet of someone else's things, typically the manufacturer. Think apple devices meets with giving away ownership and control of your data to a third party provider, the current obvious is facebook.

All this seem to be the logical next step in the evolution of corporation trying to exploit the internet for their own needs and turn it into a massive surveillance tool. Something that started quite a while ago on the day advertising invited itself to the party.

Post reply on HN