Live data from Hacker News

Internet of Crappy Things

blog.kaspersky.com

71–80 of 95 posts

Re: Internet of Crappy Things

#71

Presumably the "things" are networked via wifi? In that case I just won't enter my wifi creds, and they'll remain off the network. Possibly some devices might be more valuable when networked with each other locally, and the WAP they use just won't get connected upstream. Of course the things will still be vulnerable if they just connect automatically to any visible rogue WAP, in which case maybe one could glue some l…

Some HP printers, P1102w, have wifi cards, and when not associated with an access point, they will broadcast their own open network. There is no way to disable this except to open it up and remove the wifi card. I think some Roku models will also broadcast a wifi access point for the remote control to connect to.

Our new Canon all-in-one will optionally run an AP, but it's off by default. I've seen roku APs before but I guess I just assumed they could be turned off or secured.

Re: Internet of Crappy Things

#72

Earlier quoted context omitted.

I think that connecting devices directly to the Internet is great nonsense and great danger to our privacy and security. Still it would make sense to have an possibility to connect them to local network.

local network = internet

No, it is rather:

Internet = Second party controlled server,

Local network = Your own controlled server.

Re: Internet of Crappy Things

#73
post #4

I hate to be running to the government for this, but... the FCC has regulations that require some level of testing for devices that are going to use certain parts of the spectrum. Some parts have been declared "free zones" and I believe that's where the wifi systems tend to operate. Perhaps we need the FCC to step in there and mandate some basic security certification for connected devices. At the very least the cert…

Perhaps this is what you're looking for.

http://www.ftc.gov/news-events/press-releases/2015/01/ftc-re...

It's a start at least.

Re: Internet of Crappy Things

#74
post #4

I hate to be running to the government for this, but... the FCC has regulations that require some level of testing for devices that are going to use certain parts of the spectrum. Some parts have been declared "free zones" and I believe that's where the wifi systems tend to operate. Perhaps we need the FCC to step in there and mandate some basic security certification for connected devices. At the very least the cert…

This is not a good idea. Now every time a want to sell a minor piece of connected hardware not only will I need a security professional on my team, but I'll need to pay someone (government approved) to audit my work. I want nothing to do with such laws.

To quote Dan Geer, "Yes, please! That was exactly the idea."

There are many industries that require this kind of auditing or similar regulation. I would think that the technology-based industries are clever enough to find a way to accomplish these checks quickly and cheaply.

Re: Internet of Crappy Things

#75
post #11

I continue to fail to see how connecting appliances or small electronics to a network adds actual value. Simply throwing technology at a thing doesn't automatically make it better. Yet, here we are, rushing headlong into the "IoT". We ought to recognize this for what it is: pursuit of profit from uninformed purchasers.

Ignore the junk that doesn't add value. You're right -- it's noise, and there's a lot of it right now.

Identify the specific long-term opportunities where the added technology can actually give users a superpower: a valuable ability they didn't have before. That's what we've tried to do with Pantelligent. (Disclaimer: co-founder / https://www.pantelligent.com/ ) For us, it's the ability for home chefs of any skill level [democratization] to cook any frying pan-based meals [versatility] perfectly [quality] every time [repeatability], even when you're multitasking in the kitchen [convenience]. If that isn't adding user value by adding a bit of connected intelligence to an everyday home appliance, then I don't know what is!

Re: Internet of Crappy Things

#76
post #4

I hate to be running to the government for this, but... the FCC has regulations that require some level of testing for devices that are going to use certain parts of the spectrum. Some parts have been declared "free zones" and I believe that's where the wifi systems tend to operate. Perhaps we need the FCC to step in there and mandate some basic security certification for connected devices. At the very least the cert…

Frankly, that sounds like a good way to kill open source IoT projects (which can't afford to hire Matasano) while helping TLAs by centralizing the information on just a few companies. I'd much rather have strong penalties to companies selling unreasonably insecure devices, with reimbursements to clients and rewards to the reporters of security flaws.

If IoT becomes a security or safety nightmare, which I think most of us will concede as possible if not likely, there will be a public outcry that will result in either gov't oversight and regulation or the industry being sued out of existence. So, assuming for the moment that the IoT industry does not want to be suffocated by lawsuits, the real question for it is by whose hand regulations emerge and are enforced; the industry itself or the gov't?

Industry-based regs, e.g. UL.com, will be the least burdensome. But almost always an industry cannot self-regulate because of free riders, et al., or out of a short-term focus over profit maximization. So, in steps gov't regulation. And gov't regulation is very often over-kill, like using a bazooka to kill a fly. Said bazooka does result in a dead bug but also a lot of collateral damage to the industry being regulated. Think the FAA and how it's Part 23 regulations have both guaranteed safe aircraft and stagnated the general aviation industry nearly to death.

With articles such as this one and Gawker's "Why is My Smarthome So Fucking Stupid", it's pretty obvious that the IoT industry as a whole should be embracing and spreading industry-wide security, safety, and UX standards. Yet, for now there seems to be no such industry initiative to do so, leaving the task to Apple and, to a much lesser degree, Google. With HomeKit, Apple is forcing partners to adhere to tight security and usability standards. With its large user-base of ApplePay-enabled, willing consumers, Apple can force its will upon IoT partners going through the HomeKit acceptance process. But as if on cue, some partners, exhibiting short-sightedness, have whined to the press that Apple's process is onerous. While I'm sure Apple is more than happy to let IoT manufacturers not affiliated with HomeKit IED themselves through lax security or UX, for the industry it's a big mistake.

Re: Internet of Crappy Things

#77
post #4

I hate to be running to the government for this, but... the FCC has regulations that require some level of testing for devices that are going to use certain parts of the spectrum. Some parts have been declared "free zones" and I believe that's where the wifi systems tend to operate. Perhaps we need the FCC to step in there and mandate some basic security certification for connected devices. At the very least the cert…

This is not a good idea. Now every time a want to sell a minor piece of connected hardware not only will I need a security professional on my team, but I'll need to pay someone (government approved) to audit my work. I want nothing to do with such laws.

> not only will I need a security professional on my team

It's almost as if that's the entire point...

Re: Internet of Crappy Things

#78
post #45

Earlier quoted context omitted.

@tootie didn't say anything about the certificates being self-signed. Later this year, the new Let's Encrypt CA will make it free and easy to get certificates.[1] Moreover, it's my understanding that the default with HTTP/2 is for connections to be secure. [1] https://www.eff.org/deeplinks/2014/11/certificate-authority-...

But then you'd have to update the certs, which an appliance manufacturer isn't going to do.

Only if the appliance is serving requests, not if it's requesting. For a piece of hardware like a carwash that is running servers, the manufacture should be maintaining that software routinely anyway.

Re: Internet of Crappy Things

#79

Earlier quoted context omitted.

local network = internet

No, it is rather: Internet = Second party controlled server, Local network = Your own controlled server.

Your local network is airgapped, then?

Because otherwise it's still internet-connected. If nothing else, the first person connecting to it with a cell phone is enough.

Re: Internet of Crappy Things

#80
post #3

I'd rather not have everything I own connected to the internet. My appliances do everything I want them to do already. It's not just about hacking, either. It would be pretty easy to chart someone's routine if you knew every time he used something electronic.

Not only would I prefer not to have everything connected to the internet, I believe it's imperative. In my first IT class at high school, my teacher told me something which has stuck with me as a golden rule of computer security: If you want to make a computer 100% secure, you should unplug all the cables, drop it in a vat of cement and then drop the entire block into the Mariana trench. He's right, but that's some n…

Connecting your fire alarms to the internet will, at some point, result in someone setting all your alarms off at 2am just to fuck with you.

Or, perhaps more sinisterly, someone remotely disabling all your alarms before committing arson.

Post reply on HN