Live data from Hacker News

A vigilante trying to improve IoT security

gizmodo.com

241–242 of 242 posts

Re: A vigilante trying to improve IoT security

#241
post #239

Earlier quoted context omitted.

"I don't really see in this case how they (or mostly anyone) is unable to improve IoT (or general) security through other means" Really? How about you show me the evidence that people are... through "other means"... improving IOT security of these devices enough that DDOS isn't a big problem any more. I'd love to hear what you've done to convince all the vendors to focus on secure devices instead of profit when targe…

Shouldn't the vigilantes try to DDOS the IoT vendor websites with their own devices (poetic justice) instead of what the bricker guy is doing? That way it seems the message he's sending would be as direct and unambiguous as it gets.

Attacks on the vendors are another good option if there's a low number of vendors. The DDOS idea has a weakness where they might barely be effective if sold through 3rd-party stores and ads.

Re: A vigilante trying to improve IoT security

#242

Earlier quoted context omitted.

Allowing a medical device that can kill or harm someone to be connected to the internet would be a dramatic failure of both the company that produced it and the government. Monitoring is one thing but it better be a one way street or air gapped. No one should be able to do anything to a medical device over the internet besides read information. Or even over a LAN. Even if it is much less convenient or practical.

One could make that argument in a hospital environment, but eventually patients go home. While they're at home, some telemedicine might save their lives. Should we expect e.g. pacemaker patients to know how to set up a VPN? Or maybe you're just saying that pacemakers must be controlled through direct contact only... that's on the device designers then, not on local network admins.

Yes, it should be direct contact. Even short range wireless would make me nervous without guarantees that it was just one way monitoring. I wouldn't blame network administrators for the safety of a device that should have never been on it in the first place.
Post reply on HN