Internet of Crappy Things
81–90 of 95 posts
Re: Internet of Crappy Things
#82I'd rather not have everything I own connected to the internet. My appliances do everything I want them to do already. It's not just about hacking, either. It would be pretty easy to chart someone's routine if you knew every time he used something electronic.
Not only would I prefer not to have everything connected to the internet, I believe it's imperative. In my first IT class at high school, my teacher told me something which has stuck with me as a golden rule of computer security: If you want to make a computer 100% secure, you should unplug all the cables, drop it in a vat of cement and then drop the entire block into the Mariana trench. He's right, but that's some n…
I disagree. The "at some point" argument can be applied to anything. Having a smartphone connected to the internet will, at some point, result in someone hacking into your phone and calling 911 using your phone number, tens times a day. At some point, it's going to happen to someone.
By your argument, we should ban smartphones because they are not 100% secure. Phones should just be phones, and web browsers should be separate devices. Phones should not be internet accessible because then they can be hacked into.
Re: Internet of Crappy Things
#83Earlier quoted context omitted.
No, it is rather: Internet = Second party controlled server, Local network = Your own controlled server.
Your local network is airgapped, then? Because otherwise it's still internet-connected. If nothing else, the first person connecting to it with a cell phone is enough.
Re: Internet of Crappy Things
#84IoT devices should not be connected directly to the Internet. I don't want my "smart" lightbulbs to be turned on or off through the Internet . I also don't want them to become yet another way for the NSA to spy on us. All things that are connected to the Internet can be hacked, let alone things that come with poor security and from manufacturers that never intend to update them either. In fact, the plaftform makers f…
Seriously?
By the same argument, phones should "not" be connected. It will just make it easier for the NSA to hack your phone through your data/internet connection, read all your call logs and maybe even take over your phone and start making random calls on your behalf.
Phones should just be phones. Why in the world would we want to make phones "smart"? Phones should not be connected to the Internet. What a dumb idea it is to make a phone that's connected to the Internet--that is going to be a HUGE security disaster. The world is going to explode because everyone's phones will be hacked
Re: Internet of Crappy Things
#85Earlier quoted context omitted.
Not only would I prefer not to have everything connected to the internet, I believe it's imperative. In my first IT class at high school, my teacher told me something which has stuck with me as a golden rule of computer security: If you want to make a computer 100% secure, you should unplug all the cables, drop it in a vat of cement and then drop the entire block into the Mariana trench. He's right, but that's some n…
"Connecting your fire alarms to the internet will, at some point, result in someone setting all your alarms off at 2am just to fuck with you." I disagree. The "at some point" argument can be applied to anything. Having a smartphone connected to the internet will, at some point, result in someone hacking into your phone and calling 911 using your phone number, tens times a day. At some point, it's going to happen to s…
It's a shame we still have illiterates in this day and age, truly a black mark on modern education.
To review: my argument was that we should make devices no smarter then they need to be.
Phones gain tangible benefits from being smart. Do kettles gain tangible benefits from being smart?
Re: Internet of Crappy Things
#86Earlier quoted context omitted.
"Connecting your fire alarms to the internet will, at some point, result in someone setting all your alarms off at 2am just to fuck with you." I disagree. The "at some point" argument can be applied to anything. Having a smartphone connected to the internet will, at some point, result in someone hacking into your phone and calling 911 using your phone number, tens times a day. At some point, it's going to happen to s…
>By your argument It's a shame we still have illiterates in this day and age, truly a black mark on modern education. To review: my argument was that we should make devices no smarter then they need to be. Phones gain tangible benefits from being smart. Do kettles gain tangible benefits from being smart?
Back before smartphones became popular, everyone I knew used to make the same argument for phones. "Do phones gain tangible benefits from being smart?" "Sure, you can check email on your phone, but I can do that at home--I don't want to check email on my phone" "I'd rather have a small flip phone than a huge PDA--too bulky to fit in my pocket."
If Steve Jobs held the same attitude, smartphones wouldn't be the industry it is today. It would still just be an idea, being dismissed as "a toy" and not useful
Have you used a kettle that is smart? I assume you must have given the conviction in the way you dismiss IoT as not useful. What pros / cons have you experienced from using a smart kettle that led you to dismiss it as being not useful? Was the smart kettle you were using designed well? How could it have been improved?
Re: Internet of Crappy Things
#87We're currently working on a consumer device that could well be classified in the IoT category. We're pushing hard to put in multiple good layers of security, even though the hackable potential of the device is low. The amount of personal or otherwise exploitable information is also low. But that is no excuse to leak anything, or to allow the device to be taken over by attackers. The path isn't easy... the library su…
Will you have automatic upgrades for the life of the device?
Re: Internet of Crappy Things
#88Earlier quoted context omitted.
But then you'd have to update the certs, which an appliance manufacturer isn't going to do.
Why not? If they're going to go to all the trouble to "Internet enable" a refrigerator, surely they can include yearly certificate changes as part of their maintenance plan.
Re: Internet of Crappy Things
#89Re: Internet of Crappy Things
#90I hate to be running to the government for this, but... the FCC has regulations that require some level of testing for devices that are going to use certain parts of the spectrum. Some parts have been declared "free zones" and I believe that's where the wifi systems tend to operate. Perhaps we need the FCC to step in there and mandate some basic security certification for connected devices. At the very least the cert…
Frankly, that sounds like a good way to kill open source IoT projects (which can't afford to hire Matasano) while helping TLAs by centralizing the information on just a few companies. I'd much rather have strong penalties to companies selling unreasonably insecure devices, with reimbursements to clients and rewards to the reporters of security flaws.
I would, however, like to see a general rule requiring software and hardware makers to take "reasonable steps" to secure their products, and opening them up to liability if they do not. A few class-action lawsuits would go a long way towards encouraging everyone to put in a secure SDLC.