We're currently working on a consumer device that could well be classified in the IoT category. We're pushing hard to put in multiple good layers of security, even though the hackable potential of the device is low. The amount of personal or otherwise exploitable information is also low. But that is no excuse to leak anything, or to allow the device to be taken over by attackers. The path isn't easy... the library su…
Internet of Crappy Things
51–60 of 95 posts
Re: Internet of Crappy Things
#52Of course the things will still be vulnerable if they just connect automatically to any visible rogue WAP, in which case maybe one could glue some lead sheets around the antenna. The only government reaction to this phenomenon I would welcome would be a requirement for device vendors to clearly label devices that automatically connect to any visible WAP, or will only function when connected to the public internet.
Demanding that devices like this be "secure" is silly. Only devices the firmware of which is regularly, securely updated, which update process is regularly observed by human beings, can even hope to be effectively secure for any period. We probably can expect that from POS devices in corporate use. We probably can't expect that from a refrigerator in some random family kitchen.
Re: Internet of Crappy Things
#53There are two things that can break IoT, security and fracturing. But security is a necessary condition for IoT to succeed. I know Apple has surprised many of the companies that want to work with HomeKit with its security requirements. I heard from one company that, for example, was upset that locks cannot be remotely activated. The last thing anyone needs is their house getting hacked and robbed as well.
There seems to be a high risk for little benefit, or perhaps I don't have a lot of imagination.
Re: Internet of Crappy Things
#54I hate to be running to the government for this, but... the FCC has regulations that require some level of testing for devices that are going to use certain parts of the spectrum. Some parts have been declared "free zones" and I believe that's where the wifi systems tend to operate. Perhaps we need the FCC to step in there and mandate some basic security certification for connected devices. At the very least the cert…
The only reason we have wireless innovation outside of the military is that we have these "free zones". The problems we have today aren't radio problems -- which is what the FCC is there for. It's application layer issues that exist whether you are wired or unwired, private or public networks.
We're in an early adopter phase, so products are immature. You shouldn't be allowing IoT devices in high security environments, or incorporating devices into structures that cannot be retrofitted in 5 years until we move a little further up the lifecycle.
If you want high assurance controllers for light fixtures, motors, and other IoT use cases, you need to talk to Johnson Controls, Honeywell, and similar companies and pay for the privilege.
Re: Internet of Crappy Things
#55Re: Internet of Crappy Things
#56Presumably the "things" are networked via wifi? In that case I just won't enter my wifi creds, and they'll remain off the network. Possibly some devices might be more valuable when networked with each other locally, and the WAP they use just won't get connected upstream. Of course the things will still be vulnerable if they just connect automatically to any visible rogue WAP, in which case maybe one could glue some l…
I think some Roku models will also broadcast a wifi access point for the remote control to connect to.
Re: Internet of Crappy Things
#57I continue to fail to see how connecting appliances or small electronics to a network adds actual value. Simply throwing technology at a thing doesn't automatically make it better. Yet, here we are, rushing headlong into the "IoT". We ought to recognize this for what it is: pursuit of profit from uninformed purchasers.
I think that connecting devices directly to the Internet is great nonsense and great danger to our privacy and security. Still it would make sense to have an possibility to connect them to local network.
Re: Internet of Crappy Things
#58I hate to be running to the government for this, but... the FCC has regulations that require some level of testing for devices that are going to use certain parts of the spectrum. Some parts have been declared "free zones" and I believe that's where the wifi systems tend to operate. Perhaps we need the FCC to step in there and mandate some basic security certification for connected devices. At the very least the cert…
I agree with the sentiment but do you really trust the government can actually audit some giant codebase? The internet of things really includes your computer and your PS4 and every piece of software on them. It includes your router and your printer and your IP cam that's basically the same thing as your router with camera attached. I don't know what the solution is but I really can't imagine a government body able t…
Re: Internet of Crappy Things
#59Earlier quoted context omitted.
@tootie didn't say anything about the certificates being self-signed. Later this year, the new Let's Encrypt CA will make it free and easy to get certificates.[1] Moreover, it's my understanding that the default with HTTP/2 is for connections to be secure. [1] https://www.eff.org/deeplinks/2014/11/certificate-authority-...
But then you'd have to update the certs, which an appliance manufacturer isn't going to do.
Re: Internet of Crappy Things
#60I continue to fail to see how connecting appliances or small electronics to a network adds actual value. Simply throwing technology at a thing doesn't automatically make it better. Yet, here we are, rushing headlong into the "IoT". We ought to recognize this for what it is: pursuit of profit from uninformed purchasers.
All this seem to be the logical next step in the evolution of corporation trying to exploit the internet for their own needs and turn it into a massive surveillance tool. Something that started quite a while ago on the day advertising invited itself to the party.