Live data from Hacker News

Internet of Crappy Things

blog.kaspersky.com

21–30 of 95 posts

Re: Internet of Crappy Things

#21
post #3

I'd rather not have everything I own connected to the internet. My appliances do everything I want them to do already. It's not just about hacking, either. It would be pretty easy to chart someone's routine if you knew every time he used something electronic.

Not only would I prefer not to have everything connected to the internet, I believe it's imperative. In my first IT class at high school, my teacher told me something which has stuck with me as a golden rule of computer security: If you want to make a computer 100% secure, you should unplug all the cables, drop it in a vat of cement and then drop the entire block into the Mariana trench. He's right, but that's some n…

That assumes a two way connection, adn/or a persistent connection. Various existing fire alarms etc will only open a connection to the service provider when needed. This usually because it has a legacy from the POTS days.

That is perhaps the biggest issue with IOT, assuming a always present and bidirectional connection.

Re: Internet of Crappy Things

#22

IoT devices should not be connected directly to the Internet. I don't want my "smart" lightbulbs to be turned on or off through the Internet . I also don't want them to become yet another way for the NSA to spy on us. All things that are connected to the Internet can be hacked, let alone things that come with poor security and from manufacturers that never intend to update them either. In fact, the plaftform makers f…

Even if something is not directly connected to, or reachable from, the net they can still be a issue.

Consider something like a network printer.

Convenient as heck, but if your PC gets compromised only for a shot while the attacker may have left a little surprise in the printer firmware. End result is that even after you fully scrubbed the PC the attacker returns because the printer is acting as a proxy.

More and more it feels like a no win situation, unless you physically unplug the router between each time you need to do something online.

Re: Internet of Crappy Things

#24
post #3

I'd rather not have everything I own connected to the internet. My appliances do everything I want them to do already. It's not just about hacking, either. It would be pretty easy to chart someone's routine if you knew every time he used something electronic.

Your electricity usage patterns are enough to determine your schedule, especially if you have electric water heating. Browse through some systems at PVOutput.org until you find one that publishes power usage data; you can usually see when the occupants wake up, when they do their washing on the weekends, when they turn on the TV in the evening, and when they go to sleep.

With higher precision usage readings, you can determine what they're watching on their TV [0] [1].

I agree that the internet-of-things is another concerning layer of risk for privacy and security, though.

[0]: https://nakedsecurity.sophos.com/2012/01/08/28c3-smart-meter...

[1]: https://www.youtube.com/watch?v=YYe4SwQn2GE

Re: Internet of Crappy Things

#25

IoT devices should not be connected directly to the Internet. I don't want my "smart" lightbulbs to be turned on or off through the Internet . I also don't want them to become yet another way for the NSA to spy on us. All things that are connected to the Internet can be hacked, let alone things that come with poor security and from manufacturers that never intend to update them either. In fact, the plaftform makers f…

Even if something is not directly connected to, or reachable from, the net they can still be a issue. Consider something like a network printer. Convenient as heck, but if your PC gets compromised only for a shot while the attacker may have left a little surprise in the printer firmware. End result is that even after you fully scrubbed the PC the attacker returns because the printer is acting as a proxy. More and mor…

>More and more it feels like a no win situation

It feels like this because most people are just not willing enough to spend the time, effort and money to be secure. The only thing you (as an average consumer) can't be secure against even if you tried really really hard (why bother) is a well funded government organization (from any country). Security threats for everywhere else are more or less manageable if you really want.

Re: Internet of Crappy Things

#26
post #4

I hate to be running to the government for this, but... the FCC has regulations that require some level of testing for devices that are going to use certain parts of the spectrum. Some parts have been declared "free zones" and I believe that's where the wifi systems tend to operate. Perhaps we need the FCC to step in there and mandate some basic security certification for connected devices. At the very least the cert…

I agree with the sentiment but do you really trust the government can actually audit some giant codebase? The internet of things really includes your computer and your PS4 and every piece of software on them. It includes your router and your printer and your IP cam that's basically the same thing as your router with camera attached. I don't know what the solution is but I really can't imagine a government body able t…

Making companies liable for any hacking would be one way to go, which may be quite effective - granted the politicians will actually listen to the People on this, and not the army of lobbyists that will be set unto Washington against such a proposal.

Re: Internet of Crappy Things

#27
post #17

Earlier quoted context omitted.

Security certification doesn't work and can't guarantee products to be free from security holes. What we need is an obligation for the manufacturers to provide an automatic update mechanism and updates fixing security critical bugs for several years.

Sometimes "upgrades" breaks things for users, and they are reluctant to apply them. Users are trained to not apply upgrades. Ideally you'd need law that manufactors not do that.

Oh, the updates should definitely be automatic (like Chrome). For one, it would ensure the companies are a lot more careful with what they're sending for update so as to not break millions of devices at once, and second, as you said, it removes the hassle from users having to deal with tens of different devices.

Re: Internet of Crappy Things

#28

IoT devices should not be connected directly to the Internet. I don't want my "smart" lightbulbs to be turned on or off through the Internet . I also don't want them to become yet another way for the NSA to spy on us. All things that are connected to the Internet can be hacked, let alone things that come with poor security and from manufacturers that never intend to update them either. In fact, the plaftform makers f…

Even if something is not directly connected to, or reachable from, the net they can still be a issue. Consider something like a network printer. Convenient as heck, but if your PC gets compromised only for a shot while the attacker may have left a little surprise in the printer firmware. End result is that even after you fully scrubbed the PC the attacker returns because the printer is acting as a proxy. More and mor…

Or you can require the gateway to be formally verified, running something like this[0]

Of course, then you have to construct a spec which is foolproof.

[0]- http://www.ok-labs.com/_assets/image_library/NICTA-Technical...

Re: Internet of Crappy Things

#29
post #20

The push is that all devices will end up connected as commodity manufacturers continue to search for 'value-add' services (even if that value is dubious). In a few years, I wouldn't be surprised if 'smart TVs' were the only ones available. Security also becomes an afterthought as companies rush to get products in the market. This is mainly because the components used to build software rarely take account of security/…

I'm evangelising the term "value-subtracted" for things which make money for the vendor at the expense of the user. Lenovo is just the latest, biggest example of this.

Re: Internet of Crappy Things

#30
post #4

I hate to be running to the government for this, but... the FCC has regulations that require some level of testing for devices that are going to use certain parts of the spectrum. Some parts have been declared "free zones" and I believe that's where the wifi systems tend to operate. Perhaps we need the FCC to step in there and mandate some basic security certification for connected devices. At the very least the cert…

I agree with the sentiment but do you really trust the government can actually audit some giant codebase? The internet of things really includes your computer and your PS4 and every piece of software on them. It includes your router and your printer and your IP cam that's basically the same thing as your router with camera attached. I don't know what the solution is but I really can't imagine a government body able t…

> I agree with the sentiment but do you really trust the government can actually audit some giant codebase?

He didn't say that the government would do the code auditing (unless I missed it). It would be outside firms. I believe they do something similar for certifying hardware. The FCC certifies outside hardware testing labs as being qualified to certify that hardware satisfies FCC requirements. The hardware makers wishing to gain certification hire one of those labs.

Post reply on HN