Live data from Hacker News

More awful IoT stuff

mjg59.dreamwidth.org

211–220 of 245 posts

Re: More awful IoT stuff

#211
post #193
post #115

Earlier quoted context omitted.

Would you feel comfortable with end-to-end encryption via an open, documented, free protocol? This is literally my raison d'être as a company, so I'd be interested to hear your comfort level. What I've got is a platform that 1.) makes it substantially easier for IoT developers to get their devices to market and 2.} enforces end-to-end encryption and affirmative consensual sharing. It works by running as a background…

I've been debating about hooking my garage door opener up using a built-in feature so I could open the door from my iPhone. I don't trust that whatever central site I'll be connected to is safe. If I _knew_ the vendor had implemented your protocol/software well, and I _knew_ your software was safe, yeah, I'd use it. But I don't know those two things, so no way am I hooking my home's door up to the Internet...

In my case you actually do know that the vendor is using the protocol. You would have to be running the protocol on (in this example) your iPhone in order to talk to it. Everything is client-side verified and enforced by encryption.

You wouldn't have any guarantee that the garage door opener isn't also running a separate web connection in the background, but arguably unless you're actively monitoring your LAN (or just plain radio) traffic you don't have that anyways.

Put a different way, you can't prevent your manufacturer from, for example, adding a SIM card and wireless connection to your garage door opener. At some point you have to trust them.

Re: More awful IoT stuff

#212

Earlier quoted context omitted.

This is exactly why the use of a remote server exists in so many IoT devices. Widely deployed home APs, even in USA, come with device isolation on by default or even not disableable.

I'm surprised that device isolation is common on home APs. Wouldn't that break some fairly mainstream things like Chromecast?

Yes. In fact, the Chromecast setup apps suggest disabling isolation if it cannot be connected to. Broken multicast support also prevents setup.

Re: More awful IoT stuff

#213

Earlier quoted context omitted.

I'd argue that these guys are actually supplying. Just firewall it out to a specific network segment for these devices, have one box that interacts with it and modify it to your own liking, you have root on it afterall. They're dirt cheap, they work, and you get root so it's completely upgradable and hackable. Can't beat that really if you have decent security practices outside of the device. It's definitely an inves…

heh, that's actually what I kind of do now with a couple of devices. Then I ban that vlan from the internet. I'm speaking more in general though: Too many IoT devices require cloud access to work properly. I don't want to put a hacky solution together, I'd rather things would out of the box. I don't like the idea of having to be defensive against my own equipment.

That's the part of the business model. IoT isn't about giving you some value - it's an extension of SaaS, but with the twist that it has to convince you to give service provider some value that they can then sell back to you.

Personally, I consider most of IoT products to be a waste of resources used to create them. It's a blatant promotion of shitty engineering in an attempt to get some money out of people.

Re: More awful IoT stuff

#214
post #32

Earlier quoted context omitted.

I'd love a list like that as well, but sadly I don't think one exists and I don't think there's any money in doing it. Nobody wants to hear about good IoT devices, they want to make fun of bad ones and feel superior, that's what sells clicks. Maybe i'm just being cynical...

I don't think there's enough profit margin in most IoT devices to allocate to something like this. F.ex. when's the last time you saw a commercial for a door knob?

I've been to a conference literally sponsored by a door knob manufacturer. But they don't target "end users", they target the people you hire to design and renovate your house.

Similarly, the home automation solution targeted at those people usually aren't shit cloud-based products.

Re: More awful IoT stuff

#215

The principal reason devices need to be connected is so that business can hold your devices ransom and charge you money to use them. Turn on lights with a phone? No need for Internet. Open doors with a fingerprint? No need for Internet. An auto-adjusting energy-saving thermostat? No need for Internet. A fridge that knows the milk is low? No need for Internet. Charge people money to use their toaster? You need the Int…

I would say the principal reason they need to be connected is because consumers expect it. But yes, some unscrupulous businesses will take advantage of that. People need to vote with their money and not buy from companies that do this.

Consumers don't expect it, but they are being told they should. That's marketing at work, literally trying to create the market for this shit-engineering non-solutions.

Re: More awful IoT stuff

#216
post #198

Earlier quoted context omitted.

I pretty vehemently disagree. We should be very reluctant to systematically break good things to protect badly written junk. Let badly written junk burn. Then people will learn it's junk and stop using it or the developers and vendors will be forced to fix it.

So you're in favor of Grandparents getting cryptowall from someone else connected to their WEP-encrypted wifi because screw them for using Windows XP and a cheap router? Off-switches for things like this are cool, because people who need them will find them, and people who don't won't. This is remarkably similar to defeatable traction-control; people who care enough to figure out what that button does will push it an…

Yes, if this is the cost. Loss of local connectivity is not a small degradation. It's like losing floating point math from your CPU or the ability of your car to go in reverse.

If we're building endpoint networks to prohibit local traffic, we are forcing a terrible architecture with terrible long-term privacy and security implications. Because of this, we will have a future where the NSA (and vendors, and advertisers, and the Chinese PLA, and ...) will literally know when you flush your toilet. In the future every interaction you have with every device in your house will be broadcast to third parties across multiple national boundaries and clouds.

... because we had to protect Windows XP machines from rare, marginal threat profiles. (Has anyone actually seen malware spread this way in the past 10 years in the wild?)

The potential criminal and totalitarian applications of a cloud-powered IoT world are incredible. Look into "nudge theory" for a starting point, and then consider things like:

http://www.theatlantic.com/technology/archive/2014/02/when-y...

http://www.ibmbigdatahub.com/blog/power-behavioral-fingerpri...

The decision of how to architect our communications infrastructure today and whether to, for example, permit local traffic could in the future determine whether or not we evolve into a borg-like totalitarian collective or a cooperative society of sovereign individuals. Communications infrastructure affects... well... how we communicate... which in turn affects every single aspect of human society and culture over very long spans of time.

It's a special case of a larger phenomenon called path dependence. Small choices that you make today based on what seem like rational reasons today can have huge differences in the long term outcome of things in the distant future. While the future isn't fully knowable, sometimes conceptual reasoning from first principles can tell us what the likely outcome of a particular path might be.

Re: More awful IoT stuff

#217
post #192

The principal reason devices need to be connected is so that business can hold your devices ransom and charge you money to use them. Turn on lights with a phone? No need for Internet. Open doors with a fingerprint? No need for Internet. An auto-adjusting energy-saving thermostat? No need for Internet. A fridge that knows the milk is low? No need for Internet. Charge people money to use their toaster? You need the Int…

Completely agree except the light argument -- having my lights cloud connected allows me to control them remotely. The main use for this is for time or sunrise/sunset scheduling. However you could quite easily architecture this without cloud connectivity, it seems easiest to keep the bulb dumb and keep the 'smarts' elsewhere (whether that's on a phone locally or a server in the cloud).

Scheduling isn't stock market, you don't need a live feed for that. All such a bulb needs is an accurate date and time source - the rest, including (if you also add one-time geographical area input) the sunrise/sunset times can be determined with a little bit of trivial math on the uC that said "smart" bulb already has.

All that IoT stuff doesn't need Internet access. Hell, most of it doesn't need much of a network at all, but just having them default to intranet would deliver all the value without the problems (and the rent-seeking).

Re: More awful IoT stuff

#218
post #152

Earlier quoted context omitted.

Perhaps because the large mass of consumers only care about the first point (how the hardware looks in their home)? Point two comes in play only if the user experience is horrible, otherwise it's acceptable. Regular consumers rarely think about point three.

I wasn't suggesting consumers think about these issues. I was suggesting that founders think about them!

There's that Upton Sinclair quote about understanding and salary...

The point being, the business model of IoT is literally lending you a device that due to purposefully shitty engineering is not useful if you're not paying the rent. I wish there'd be a founder that cares about making stuff that's primarily delivering value to the customer, but in IoT space, I'm yet to hear about one.

Re: More awful IoT stuff

#219
post #216

Earlier quoted context omitted.

So you're in favor of Grandparents getting cryptowall from someone else connected to their WEP-encrypted wifi because screw them for using Windows XP and a cheap router? Off-switches for things like this are cool, because people who need them will find them, and people who don't won't. This is remarkably similar to defeatable traction-control; people who care enough to figure out what that button does will push it an…

Yes, if this is the cost. Loss of local connectivity is not a small degradation. It's like losing floating point math from your CPU or the ability of your car to go in reverse. If we're building endpoint networks to prohibit local traffic, we are forcing a terrible architecture with terrible long-term privacy and security implications. Because of this, we will have a future where the NSA (and vendors, and advertisers…

Also worth pointing out that the reason everything talks over HTTP now is because companies figured out that the only port on a typical user's computer that can be assumed to be free of bullshit pseudo-security rules is the port 80...

Re: More awful IoT stuff

#220

I just blogged about this yesterday. In short: > The line in the sand for me is: network vs cloud-based systems. I want things to be network connected, but I want it for my own network only. I want to be able to control my coffee pot, but only from home. If I choose to expose this over the internet, great! It's up to me to make sure it's secure. I don't want anyone making that decision for me. I also want it to be up…

Sounds like you want better hardware. Which is what we ALL want.
Post reply on HN