Live data from Hacker News

IoT Goes Nuclear: Creating a ZigBee Chain Reaction

iotworm.eyalro.net

81–90 of 100 posts

Re: IoT Goes Nuclear: Creating a ZigBee Chain Reaction

#81
post #75

Earlier quoted context omitted.

Seems unwise to reason backwards from your desired conclusion (commons implies censorship/regulation, so it can't be a commons). Security is indeed a commons because the overall security of the ecosystem only benefits each person weakly, and so every actor rationally benefits by neglecting security. External regulation isn't the only way to address commons problems. Manufacturers can see the writing on the wall and w…

I imagine that it can also get better once a company can gain competitive advantage by advertising that "our device is secure!" But I suppose a precondition for this is customer awareness of the issue, which probably requires some well publicized high impact/casualty incidents first? :/

> But I suppose a precondition for this is customer awareness of the issue, which probably requires some well publicized high impact/casualty incidents first? :/

I'd say it absolutely requires a high-impact case, something like downing of an airplane, or a cyberattack that sets half of the city in flames. Otherwise, any concern of people about security will quickly get papered over by marketing - as it always is.

Re: IoT Goes Nuclear: Creating a ZigBee Chain Reaction

#82

Earlier quoted context omitted.

Tragedy of the commons. No individual manufacturer really cares about the issues created by the ecosystem of IoT, so they have no real incentive to address it.

Tragedy of the Commons really means "the structure of a market failed to produce the desired outcome". The common good may be the victim, but the market is the culprit. The solution of course is alternate economic structures that respect the commons. The distinguished economist Elinor Ostrom wrote a whole book called Governing the Commons which presents real-life alternatives to markets for commons-like economic acti…

The opposing viewpoint is that only public resources suffer from tragedies of the common (they become a free-for-all), whereas with private ownership there's usually a natural incentive to make your profit-producing resource sustainable. Of course, it's always more nuanced than that (mining and resource extraction industries are problematic), the ideal is probably somewhere in the middle. So we argue about exactly where it should be :)

Re: IoT Goes Nuclear: Creating a ZigBee Chain Reaction

#83

Clearly, absolutely no one saw this coming, nor did anyone warn us. :-) How else do you explain how woefully unprepared we are?

Tragedy of the commons. No individual manufacturer really cares about the issues created by the ecosystem of IoT, so they have no real incentive to address it.

The situation you are lamenting (and I agree with your sentiment) is not a "tragedy of the commons." I think you are trying to describe a collective action problem. Collective action problems are frequently brought up during a discussion of the tragedy of the common but the existence of a collective action problem does not imply that there is a tragedy of the commons. If you are interested in these types of issues Mancur Olsen's "The Logic of Collective Action" is the standard introduction.

Re: IoT Goes Nuclear: Creating a ZigBee Chain Reaction

#84
post #62
post #39

Philips may have fixed the vulnerability in an update, but that's insufficient if these devices don't have high update rates. I wonder how many years until there are fewer than 15000 vulnerable Hue devices in Paris... We should hold manufacturers accountable for not aggressively pushing security updates on their users.

Hue forces updates on you every time you go into the app if there's one available, and you can't use the app until you've updated. Granted this isn't ideal if you primarily use your light switch or an amazon echo to control the lights, and fully automatic updates would probably be better, but it comes pretty close to aggressively pushing updates.

It's pretty aggressive alright. I'm working on my own (RPi-based) controller but for now, I'm still primarily using Hue app for controlling the lights at my home. So every two weeks or so, when I come home in the evening, I'm forced to sit in darkness for 10 minutes as the update installs itself (they say lights must stay powered, so I don't dare powercycle them during the update).

First world problems and all.

Re: IoT Goes Nuclear: Creating a ZigBee Chain Reaction

#85
post #68

Earlier quoted context omitted.

the quality of light from your average energy bulb is typically terrible. I like warm light and whilst I know I can't see infra-red frequencies I want to see a concentration of light towards that end of the spectrum. It just makes for a much more relaxed feeling. I stockpiled too. and I have dimmers on pretty much every lamp (including the toilet), so the bulbs last for a very long time. when you don't burn them on f…

They make warm-light LED bulbs.

The perceived color temperature of the light is not the main issue in light quality, but rather the smoothness of the frequency composition of the light. Cheap LED bulbs have a "gappy" spectrum. "High CRI" bulbs are probaably what the OP is looking for.

Re: IoT Goes Nuclear: Creating a ZigBee Chain Reaction

#86
post #37

Earlier quoted context omitted.

Any manufacturer who has to recall a device cares very much about it.

Those IoT manufacturers must be lucky then. They haven't been sued because of a insecure lightbulb yet.

"Yet" is the key word. Even rumors are sometimes enough and as powerful as lawsuits.

Market forces are really powerful. See Samsung's recent troubles -- once everything was fine, and then -- BAMM! - their phone sales went down without any external regulation. (pun intended.)

Re: IoT Goes Nuclear: Creating a ZigBee Chain Reaction

#87

Earlier quoted context omitted.

Right. Using "standard cryptographic techniques" is not sufficient when you are using the wrong technique for the job.

I had a discussion once, back when I was wearing a crypto hat, which went like this: Me: "Yes triple-DES is reasonably secure, how do you exchange keys?" Them: "That is part of the connection setup." Me: "Great, how do you protect the keys during setup?" Them: "What do you mean?" Me: "What form of encryption do you use when you're doing the setup, and sending over the keys?" Them: "Well we really can't encrypt the se…

Trying to learn some more about crypto, what sort of answer would you be looking for? Would Diffie-Hellman be appropriate?

Re: IoT Goes Nuclear: Creating a ZigBee Chain Reaction

#89
post #47

Clearly, absolutely no one saw this coming, nor did anyone warn us. :-) How else do you explain how woefully unprepared we are?

I think ZigBee has already been deprecated in favor of Thread, which seems to be slightly more focused on security, although it's still probably nowhere near where it needs to be. The vendors of Thread devices probably care even less about security and, for instance, choose to make every single one of their devices Internet-accessible instead of creating gateway apps for a local mesh network of devices. https://www.t…

Note that ZigBee should have a lower attack surface than the Hue/LightLink extension. The regular ZigBee protocol requires a Coordinator in the mesh network, most of the LightLink protocol deals with doing away with that requirement.
Post reply on HN