Live data from Hacker News

A vigilante trying to improve IoT security

gizmodo.com

231–240 of 242 posts

Re: A vigilante trying to improve IoT security

#231
post #97

Earlier quoted context omitted.

> How about you show me the evidence that people are [...] I've made my argument. Why don't you take part in the discussion and make some of your own to why this is meaningful? > I'd love to hear what you've done to convince all the vendors [...] Why is it at all relevant what I've done and especially since when you don't say what you've done? > Most of us in INFOSEC haven't been able to convince [...] I haven't seen…

"I've made my argument." You didn't make an argument. You made a false claim that there were other methods that work and/or an implication that there wasn't much effort on doing that. All kinds of people have spent decades doing that. They get ignored. "Why is it at all relevant what I've done and especially since when you don't say what you've done?" "I haven't seen much convincing being done." Programmers, support…

> You didn't make an argument.

I did make an argument, you just missed it. In most subcultures the thing your doing is the goal, therefor the actions themselves are meaningful (at least according to the participant). Since this isn't the case here, but more of a "the ends justify the means" situation, you have to argue that it actually does. The point isn't that there are other ways, which you incorrectly choose to focus on, but that you have to justify how these actions are appropriate both in themselves and relative to other actions.

> You made a false claim that there were other methods that work and/or an implication that there wasn't much effort on doing that.

As far as I know there isn't much effort going on. This is of course subjective, yet you haven't provided a real example of what you think is a substantial effort that should have lead to results.

> Programmers, support people, architects, tech managers, security experts, and so on have failed to do what you suggested because of greed and apathy of manufacturers.

Plenty of manufacturers make secure or at least not obviously insecure devices.

> They write about it all the time on blogs, esp basic QA. They write about it here, too.

The embedded ecosystem, especially in other countries, aren't going to see those blogs nor be able to act on it. They aren't ignored so much as not considered.

> People in the military invented computer security. They taught me.

I bet I have more military experience than you. The military operates in a different environment and different considerations than civilian infrastructure or products. Most civilian security researcher don't have formal training, yet frequently use terms like OPSEC without actually having an understanding what it means. Because if they did they would know that it to a large degree isn't transferable.

> Meanwhile, nobody is doing anything at any level, you can't convince businesses to do anything in general case, and so a vigilante breaching defective, damaging stuff might be only progress we can get in meanwhile. Reduces risk and decreases demand for garbage products. Vendors might get message like Microsoft did leading to their 180 in security.

This is just your opinion. If this how you do security work I'm not surprised you feel ignored.

The thing is I do have a number of suggestions on "other ways" to improve and/or promote IoT security. I see no point whatsoever mentioning them here though.

Re: A vigilante trying to improve IoT security

#232

Earlier quoted context omitted.

Really worst-case scenario: Someone is killed or maimed due to bricked system. FTFY

I was particularly thinking of baby monitors during an emergency. It was most important house-hold device I could think of in terms of harm. Maybe turn a freezer off on IoT fridge while people are on vacation then back on just before they return to make meat refreeze or something spoiled. Maybe turn off the power in household with IoT home automation and someone on life support of some kind. Im only having a few poss…

Lights that turn off at night while someone is walking down stairs can result in death if that person is unfamiliar or disoriented enough to tumble.

Re: A vigilante trying to improve IoT security

#233

Earlier quoted context omitted.

Engineering needs to stop being subordinate to anything but top management (if at all). An MBA can always outrank an engineer's decision and that is a big reason why we have crap devices out in the field.

I would argue, security needs to be a part of planning day 1 rather than looked at as a bolt on prior to involving upper management. It needs to be treated as a core functionality rather than an external concept. The biggest issue I see is we are patching and finding fixes for something that could easily be remedied if address before engineering takes place. Most firms i've worked with put it on the back burner or ar…

> I would argue, security needs to be a part of planning day 1 rather than looked at as a bolt on prior to involving upper management.

Nothing I said implied bolting anything on prior to involving upper management.

ANY decision at any time during the process can be overruled by any MBA. That needs to change.

Re: A vigilante trying to improve IoT security

#234
post #188

Earlier quoted context omitted.

Engineering needs to stop being subordinate to anything but top management (if at all). An MBA can always outrank an engineer's decision and that is a big reason why we have crap devices out in the field.

Yes, no engineer has ever made a bad design or decision, ever.

Nothing I said implies engineers don't make bad decisions. What I implied is even the GOOD decisions can be overruled by any MBA at any time.

Re: A vigilante trying to improve IoT security

#235

Earlier quoted context omitted.

Engineering needs to stop being subordinate to anything but top management (if at all). An MBA can always outrank an engineer's decision and that is a big reason why we have crap devices out in the field.

On the other hand, if you let the engineers run the shop, you might end up with another Juicero... an exquisitely designed product with few customers.

[deleted]

Re: A vigilante trying to improve IoT security

#236

Earlier quoted context omitted.

Engineering needs to stop being subordinate to anything but top management (if at all). An MBA can always outrank an engineer's decision and that is a big reason why we have crap devices out in the field.

On the other hand, if you let the engineers run the shop, you might end up with another Juicero... an exquisitely designed product with few customers.

Quite possible. Not sure why that should negate anything I said. It is quite obvious that products like the Juicero are easily developed with MBAs at the helm.

If engineers run the shop you might even end up with another Uber. And we all know what a disaster that is.

However, at some level, MBAs and engineering need to be on level terms. If there's a conflict it can be resolved by going higher up the chain and both sides have the opportunity to make their case.

Re: A vigilante trying to improve IoT security

#237

Earlier quoted context omitted.

I was particularly thinking of baby monitors during an emergency. It was most important house-hold device I could think of in terms of harm. Maybe turn a freezer off on IoT fridge while people are on vacation then back on just before they return to make meat refreeze or something spoiled. Maybe turn off the power in household with IoT home automation and someone on life support of some kind. Im only having a few poss…

Lights that turn off at night while someone is walking down stairs can result in death if that person is unfamiliar or disoriented enough to tumble.

That's clever. The threat of lighting was nicely illustrated on Christmas Vacation. Whole relationships ruined and stuff.

https://www.youtube.com/watch?v=rp8lwpvQEIM

Re: A vigilante trying to improve IoT security

#238

> if somebody launched a car or power tool with a safety feature that failed 9 times out of 10 it would be pulled off the market immediately. I don’t see why dangerously designed IoT devices should be treated any differently Really? He doesn't see how a car is different from a webcam? And why there are different safety standards for each? Their goal is laudable, but this seems like a fun way to engage in vandalism wh…

[deleted]

Re: A vigilante trying to improve IoT security

#239
post #52

Earlier quoted context omitted.

I find the arguments for "taking a stand" quite weak. Normally with subcultures that break the law or in other ways inconvenience people the moral argument is that you're doing something that isn't available to you (often as a group) and your actions themselves are meaningful (often because it makes it available to you). I don't really see in this case how they (or mostly anyone) is unable to improve IoT (or general)…

"I don't really see in this case how they (or mostly anyone) is unable to improve IoT (or general) security through other means" Really? How about you show me the evidence that people are... through "other means"... improving IOT security of these devices enough that DDOS isn't a big problem any more. I'd love to hear what you've done to convince all the vendors to focus on secure devices instead of profit when targe…

Shouldn't the vigilantes try to DDOS the IoT vendor websites with their own devices (poetic justice) instead of what the bricker guy is doing? That way it seems the message he's sending would be as direct and unambiguous as it gets.

Re: A vigilante trying to improve IoT security

#240

It's all fine and well until one of those improperly configured devices are a medical device or something critical. Yes I understand that's part of the problem, but proving a point with risk isn't the right answer either. Every Dialysis machine i've seen runs windows xp, which any security professional will tell you is game over, but given the market hasn't provided an alternative, it's becomes a necessity to figure…

"It's all fine and well until one of those improperly configured devices are a medical device or something critical. " It would be their fault. High-assurance industry has been telling SCADA and medical industry to get their shit together for a long time. This included pentests showing it could all be destroyed. They even have people at conferences talking about it with products or basic advice to deal with it. The r…

Can a case be made that the Insurance companies can make this problem less severe? I.e. to deny insurance to unaudited companies or charge a lot more if they refuse.
Post reply on HN