Internet of Things security is so bad, there’s a search engine for sleeping kids
arstechnica.com
arstechnica.com
The mental calculation just doesn't work out for most things. My personal rule of thumb is:
benefitofmeaccessingXremotely(X) - costofotherpeopleaccesingXremotely(X)*riskofthathappening
Benefits being low for most things, costs high, and risks...uhmm...nah. Only exception I can think of is very limited amounts of sensors (eg. is X on?).What's the benefit of me turning on a gas stove remotely? Almost none. What's the cost of someone else turning on my gas stove? Really high. How much is the risk? Way too high.
Then there's smart devices, another component of IoT. But how much smarts do we actually want? Screens are nice. Making my shower multi touch isn't (capacitive touch + water = no bueno. Imagine water from hell scenario and no way of turning it off with your wet hands). Fridge compiling shopping lists automatically? Neat. Cheap android tablet that comes with a fridge glued to it? Nah.
The only utility I see is locally connected devices. Using your phone as a remote. That seems handy. To a certain degree, we have that. Extra points if I don't need to download an app for everything, because don't you dare tell me that your blue-tooth on/off switch needs a 15mb .apk. If I gave one about the 14.9mb of branding you're including, I'd download your press kit.
There's some utility in home IoT wudget-thingimabobs, but I'm almost certain we'll mess it up to no end in our excitement. There'll be some legitimately useful products coming from it, but most of it will be utterly cringe worthy in retrospect.
/rant('IoT')
The joys of being a killjoy and explaining why your toasters web interface won't do much good if you have to get up and insert the toast manually.
Or SmartXthing to introduce the obsolescence cycles of digital electronics to everything else. No sympathy.
I guess I'm just a bitter old person, and a way to young one at that.
To put your example in the perspective : how much useful would it be to operate the TV remote over the internet ? Yeah, it sounds cool that I've set the TV to channel 5, but I'm not there to watch it anyway, so it's kinda useless. Only thing that is now possible is some other people jerking around with the remote.
It's free, man. Sure, your TV will play some audio ads while you are entering the house, but then it'll switch to your favorite soap.
And yes, security is a huge concern. Privacy too.
Still parent makes a good point with "benefitofmeaccessingXremotely(X) - costofotherpeopleaccesingXremotely(X)*riskofthathappening". I'll add the "amountofdataimgivingaway+showingmeads"
(I spend an hour this afternoon trying to get tvheadend+Kodi working to do almost exactly this, to replace my Windows Media Center PVR)
Same for the EPG: the app offered by my ISP simply downloads it from the web, no need to connect to my TV.
I can no longer push buttons on the device itself, I have to spend 10 or 15 minutes a day, if I'm lucky, trying to find the "labor saving device", just so I can change the channel or pause a show.
At least some devices (e.g. - Roku) let you use your phone or tablet as the remotes (plural!), which I guess finally is actual progress.
Part of it is the adveillance business model: get people hooked on a technology so you can sell their personal info to marketers. The smart fridge compiling your shopping list knows even more about you than your supermarket loyalty card.
Part of it is ownership-to-rent: rather than let people buy an appliance and keep it for a decade, turn them into a revenue stream with mandatory updates, planned obsolecence, incompatibility, and so on.
And part of it is an attempt to automate away the awkward middleman in consumerism, the consumer: let devices spend money on their own behalf. This is HP's "instant ink" (https://instantink.hpconnected.com/us/en), a service where you let your printer order the most expensive liquid in the world on its own initiative.
Honestly, adveillance and order automation seem like they'll be useful. And abused. People hacking into celebrity fridges, script kiddies ordering toner and other very shady things on the ORM side will inevitably happen.
I will however plead the Stallman on ownership-to-rent. DRM on Keurigs and usage timers on light bulbs just feel underhanded. So opposed to that. That's an entirely different argument though.
Well, I kinda get consumer IoT now, but I'm still confused why people are going on about it like it's the best thing since sliced blue-tooth. Guess I'm not imaginative enough. Guess I'll be the old grumpy paranoid man at the end of the road that never showers and orders his own ink.
But enthusiast IoT genuinely is exciting; people building little things tailored specifically to their needs. Not a multibillion dollar unicorn festival though.
Home automation has been a minority interest for decades, and likely to remain that way.
Actually, think of that awkward in between period for land line phones when LCD screens seemed like too much of an expense, but you could finally embed enough computing power to add several dozen layers of features whilst keeping the 9-10 button layout for cost reasons, which meant that almost all those features went unused, and necessary features became impossible to discover. Yeah, there was a manual, but who remembers all those numeric codes?
We took something simple and made it harder to use applying computing power to it, which is quite the achievement. And now there's IoT, and I'm counting on the same thing to happen. Bosh deciding to replace manual affordances with WiFi? Please, no. Kafka please. This 'boutta be worse than OEM androids.
Mentally I've put IoT in the same camp as VR and (soft) wearable electronics. Lots of excitement because it's living with the Jetsons stuff, combined with little awareness of the technical and economical challenges behind it, which limit potential applications to some carefully engineered niche products (say the Echo, Occulus, and maybe the fitbit. Notice how the Echo is "Internet of thing" for the most part, the Occulus big and wired and expensive, and the fitbit a bracelet because copper breaks when bent regularly, so you gotta have a solid piece) and hobbyists.
I'm sure there'll be a killer app coming out some time in the nearish future, but your altair basic still ain't quite the PC. I'm miffed at schlep blind tech people pretending it is. Y'all ain't got no demo, y'all got Techcrunch tellin' you bout the promised land is here and no engineer to slap some sense into you.
But if I start raving about that people think I'm crazy.
There is real value in the home automation side, but then there are the security concerns. Perfect examples are the HVAC and monitoring. When we're away it's nice to shut down the heat and AC but if it's January and we're coming back from the holidays that house needs to warm up before we get home. It's also nice to get an alert and video when motion is detected in the house while you're away- you can call the cops and respond with evidence immediately, or even possibly prevent your house from burning down. So yeah, there's a lot of value in conserving energy and protecting (or at least actively) monitoring the safety of your household.
My Amazon Echo gets used at least 50 times a day. Timers for timeouts for the kiddos, alarms for when it's time to go to bed, the weather report as I'm making my coffee, adding things to my shopping list. It genuinely makes life just a little bit easier.
That's just from a consumer prospective- if your company ran multiple properties or warehouses, shipped freight, etc. there are so many other fantastic possibilities as well.
I don't need a fridge connected to my google calendar, I don't need a TV connected to my Dropbox to show family pictures as a screensaver. I don't need a freaking Barbie doll that is recording every conversation my children send around it. These are generally bad ideas and poor implementations, and people are starting to see it.
We're in the hype cycle of IoT- we'll get to the valley of disillusionment after enough of the crappy devices piss people off, then we'll get a stable stream of meaningful product. IoT in principle isn't going away, there is actual value in some of these things. We just need the cream to rise to the top.
What's the value of a fridge that warns you when you're running low on something? Almost nothing. What's the value of a fridge that prints out a shopping list based on what it currently has? Some. What's the value of a fridge that automatically orders those things, has them delivered to your door and/or restocked inside it? Significant.
Why? Because we've already automated the basic 25-75% of most tasks (somewhere in the 1920s-1980s). The modern value proposition is binary: having to think about "it" any amount vs not having to think about "it" at all.
Saving time at "it" is more or less worthless at this point, because we've already automated most of the raw time away.
Or in other words: time spent in mental context switching dominates, and can only be avoided via 100% automation.
Stoplights? HVAC Systems? Carwashes? Ice Rinks? POWER PLANTS?
Yes!
https://www.youtube.com/watch?v=5cWck_xcH64
EDIT: I looked at his more recent talk from last November ... the situation has not improved
"115 batshit stupid things you can put on the internet in as fast as I can go by Dan Tentler"
https://www.youtube.com/watch?v=hMtu7vV_HmY
Featuring Spanish Chicken Controls
The really disturbing thing about a lot of these IoT devices with sensors and remote communications in the future will be when they no longer rely on an explicit Internet connection being provided via the home network, and instead use some sort of mesh arrangement where they can get online independently and you won't even know about it. At that point, I think robust laws about both disclosure and the ability to opt out will probably be necessary.
They also tend to be physically smaller but often with a higher native resolution than TV/movie standards, so not the best fit for efficiently showing that kind of content.
Without available firmware updates, you forgot to add.
https://www.shodan.io/search?query=port%3A8099+unknown+messa...
So each TV will be a dumb screen. Output is provided by two Raspberry Pies - one for each of the first two HDMI inputs. HDMI 1 = monitoring, HDMI 2 = office IPTV. The TV feed network is physically separated from everything else, and connected to a dedicated switch. With no uplink to internet.
And to give some context, we discussed our setup with some of the Cloudflare engineers in London. They consider our setup "pretty hardcore". From a company that lives by security, we consider that a compliment.
As long as the general approach remains "take a device, slap some nodejs on it, deploy" then the whole endeavour is doomed to a spectacular (and potentiall bloody) failure.
For better or worse, this trend is going to keep going until something truly egregious happens and either market forces or government regulation steps in. Hopefully we'll see a pattern similar to that we've seen with desktop computers, where there'll be some messy worms or viruses that infect enough people that the big players in the field start taking these threats seriously.
Here are the results: https://www.youtube.com/watch?v=fJyWngDco3g
There was some discussion of this on the excellent Nova episode "Rise Of The Hackers", where they mentioned that the damage to the generator was extensive enough that it would not be just a quick in place repair. It would have to be replaced, which could take months (they don't have these things lying around in stock...). If someone did a successful coordinated attack on several power plants, it quite possibly could knock a very large number of people off the grid for many months.
We need to stop allowing this. If this trend of putting everything online without paying serious attention to security continues, two things are going to happen:
1. The bad guys are going to succeed at some point in causing a major disaster. If we are lucky it will just cause widespread economic loss and inconvenience. More likely, though, there will be widespread loss of life too.
2. You think 9/11 prompted too big a swing in the wrong direction on the "safety vs. civil liberties" scale? That will seem quaint and mild in comparison once an attack knocks a large region off the grid for months, or causes a chemical plant to release a large toxic cloud, or takes down air traffic control, and so on.
There's no grey area here. Get this wrong and there's potential for foreign state or terrorist attacks that are as destructive - in their own way - as 9/11.
Currently IOT has the makings of the next Pearl Harbour. It would be good if that didn't happen.
Industrial control software doesn't get the attention that normal software does because it takes a specially-seasoned consulting sales person to get industrial software on the docket for a consultancy. The really good consultancies are overbooked anyways (the big 5 Internet firms buy consultant/years the way smaller firms buy consultant/hours), so there's not much incentive for the best talent to get applied to these projects.
If Charlie Miller and Chris Valasek hadn't gotten on stage in track suits to talk about car hacking, the same might be true of automotive, but now every consultancy wants a car-hacking practice.
I've managed a few energy-sector projects. The targets were really, really bad.
When you're building a target, security aneeds to be designed for across the board. If you want to shortcut your way out of that, don't use general-purpose operating systems and don't build networks.
Federal regulations have gone from 20,000 pages in 1970, to 80,000 this year. With a 60% increase just since 1990. The US loves regulation. And that's just at the Federal level, there's an entire government system nearly the size of the Federal Government at the State level.
The only answer that makes any sense at all is funamdental legislation that any product where the primary product is the physical article and not the software must publish the source to included software. That way even if IoT devices are abandoned or become insecure we can update our own hardware.
Most people would not be able to maintain their own devices, but we can easily end up with OpenWRT / DDWRT style products for each class of IoT device if they are required to be freedom respecting. Then techies will naturally instruct their peers to use supported devices, and the natural progression should get us most of the way to where we are today on routers - the liberated ones are recommended and can be supported by the community even if the OEM abandons them, and the ones that are not are a red flag to avoid. The only problem today is that since there is no compulsion to liberate routers a lot of them are sold to ignorant consumers who do not realize the mistake they are making.
So maybe that should be a regulation? Like with how cigarettes must inform consumers of how dangerous they are, proprietary IoT devices must have an FCC general warning their security is out of the users control.
Another problem with regulating software security is that it will inevitably involve licensing software security assessors (it's hard to meaningfully require audits without doing that). The history of licensed security auditors is not reassuring; the economics predict a race-to-the-bottom, and that's what you get (see: PCI).
I too am not in favor (at this point) of requiring licensed assessors to approve software after it is complete, at least for most products. Embedded medical devices, vehicle control systems, and things like that probably should have an outside assessment.
I'd be happy for now just having some rules to try to make it so IoT device breaches are mostly due to bugs in the implementation of a good design, rather than due to the producers not having a clue about security.
I think we are fast approaching (if we have not already past) the point where good security practices are something that almost every programmer and software architect should know and practice. There should be basic coverage of this in the standard computer science/software engineering curriculum, and there should be more extensive coverage as an optional part of the curriculum. If you take these optional courses, your degree is "B.S. in Computer Science and Computer Security" (BS CSCS). (There should also be a way to get this training outside of college, and get some sort of certificate that you have had this training).
Those making products that reach the thresholds for regulation should have to have someone with a BS CSCS (or a certification of equivalent security training) who signed off on the architecture, development standards, and testing process used for the product.
My expectation is that as everything (for better or worse) gets connected, the vast majority of CS students will go for the CSCS option and so people with a BS CSCS will not be significantly harder to find or more expensive to hire than people with just a BS CS, and so even small new companies should be able to afford them once they get past the point of the founders doing all the work and start hiring employees.
The vast majority of exploits against IoT devices do not involve new exploits. They involve ridiculously ancient exploits, like finding plaintext passwords embedded in the firmware, or adding something like "&admin=1" to the end of a URL.
If we could get to the point where breaking an IoT device requires something like finding a hole in, say, the TLS protocol (or in a widespread TLS library), rather than just looking because the damn thing doesn't use encryption at all, we'd be vastly better off than we are now.
This is what I meant when I said, "I'd be happy for now just having some rules to try to make it so IoT device breaches are mostly due to bugs in the implementation of a good design, rather than due to the producers not having a clue about security".
Right now far too many devices are vulnerable even if they are 100% bug free.
For IOT, the bigger problem is that most of this stuff is getting deployed on BOM constrained designs, so they can't take advantage of safe programming environments, but instead pretty much have to link random C libraries together.
Building codes change, but certifications for electricians/plumbers/whatever seem to work well enough.
The certifications I've heard of all come with an expiration date. The professional organizations I've heard of all require at least a little bit of ongoing study from their members.
I don't see why what works well enough everywhere else wouldn't work well enough here?
There is good regulation and bad regulation, but regulation can accelerate innovation. With or without regulation, addressing this problem with more standardization of secure software and hardware infrastructure would reduce the need for human assessors (or at the very least, push what they're worrying about higher in the stack). Addressing it with licensing and more humans is probably not the kind of regulation I'd look for. So could there be bar-raising regulation that encouraged infrastructural solutions that benefited the industry as a whole?
I'd hate to inject insurers into this world, but one way might be to require IoT manufacturers to carry some sort of indemnification against potential consumer damages, and the insurers drive the security quality. In the 1990s, it was insurers, tired of anesthesia-related malpractice losses, who created back-pressure on the profession to put better clinical standards in place, and errors related to anesthesia-related causes dropped, as did premiums for practitioners following the guidelines. Everyone benefited--especially the patients.
But in the IoT world today, there are no meaningful incentives around securing devices, and consumers have little influence.
The problem is that I think the security gains will also be marginal, and the innovation harm will be significant.
In particular, the history of security standards, which you bring up as an example of "good regulation", is checkered.
I agree with you that mandatory insurance could be a "middle way" between intrusive regulation and no regulation. But that's essentially the structure the payments industry uses with PCI, and PCI has been a race-to-the-bottom.
The real innovators will then not be able to come to market because the don't have $750k extra laying around for 6 months of burn waiting for/obtaining certifications, bonds, insurance etc.
Edit: In theory, I agree with OP, but in practice, these things almost always end up being more about permission than proficiency so we end up with corruption instead of competence.
So the regulation ends up being "go through the security process" (take something like PCI compliance as your model). This always ends up being a crappy fit because the guy doing the process can typically only throw out a list of "best practices" that may or may not make any sense for any particular application, and in any event aren't comprehensive enough. It's also wildly expensive, since the process is embedded in a regulatory-certified person who charges N$ / hour.
Empirically the best you can do absent some specific industrial setup is a series of bright-line rules like "don't store passwords in the clear", but that's far from sufficient.
The one which would make the most sense to me is something like a souped-up CERT: researchers report vulnerabilities to them, staff grades the severity, and a company has increasingly strict penalties if the fix isn't shipped within certain timeframes. Imagine if e.g. Samsung, Lenovo, etc. executives knew that their personal assets would be frozen in the U.S. if they continued not to support all of the millions of vulnerable Android devices?
The main thing I'd hope an approach like this could avoid would be the PCI bureaucracy you mentioned where a company might choose to avoid riskier areas rather than being required to expensively audit a process.
It's a bit like the laws for junk faxes or illegal telemarketing calls. You don't have to take them to court or prove actual damages, you just press the "statutory damages" button when an actual violation occurs.
I could see some difficulty arising from people who are breached not because of some fault with the product, but because the people made their password "password" or whatever. But maybe this would just encourage manufacturers to make it difficult to set up their devices insecurely.
There might be problems with people knowing that they're breached. To combat this, you might make the $500 (or whatever amount) payable to anybody who accesses such a device in good faith. These "find an insecure web cam pointed at a baby" web sites would go from voyeuristic amusements to money makers.
Just some random ideas....
Yeah, that's exactly the kind of thing I was thinking about for market incentives. Right now the immediate cost to a company is zero so the only question is whether it'll cost them future sales. Even a simple refund of the purchase price would be a big shift.
I rather like the bounty idea, too, particularly if we could combine it with some sort of clearing house so e.g. the person who finds an unprotected webcam doesn't have a reason (or excuse) to identify the owner.
How do you define reasonable security practices? If there's PII, what's reasonable then? What's reasonable today OAuth, tokens, 2FA was over the top crazy/impractical/expensive/impossible in 2001. You think there's going to be a committee evolving this crap every month in perpetuity?
On top of that, if actual harm comes to users of these devices as a result of these devices then we already have plenty of consumer laws protecting them. Granted, they're going to have to come up with ways to apply it sometimes and you're going to have to prove it was that device that allowed the harm, but we have it.
I will say this though: I'm mostly okay with laws (whether they exist or not yet) that say that if your negligence or stupidity was the root cause, as a manufacturer of these goods, you are on the hook for a multiplier of damages. There are a lot of companies out there that know they are pushing shit to market in a race to the bottom and then just claim security is hard and they tried their best when clearly, they knew about an 8 year old bug and shipped anyway. I'm that case, I'm okay with hitting them hard.
Such laws won't work, however, without a regulatory framework that ensures that -- for example -- click-through EULAs aren't used to lock customers into sleazy "binding arbitration" agreements that sacrifice their rights in return for permission to use an appliance they bought in good faith.
It may be difficult for regulators to keep up with specific technologies, but much tougher consumer rights protection is essential in order to hold negligent manufacturers responsible, because it's cheaper for the cowboy manufacturers to hire a lawyer to draft some dodgy contract boilerplate than it is for them to hire security experts and ship a safe product.
I think, at least in the US, we need much stronger consumer advocacy laws, something with teeth that can't be arbitrated down by a group of expensive lawyers.
We'd have to find a balance though, as we are already way too litigious and we'd be stifling innovation out of fear of getting accused of negligence.
> We'd have to find a balance though, as we are already way too litigious and we'd be stifling innovation out of fear of getting accused of negligence.
If we're "way too litigious" to the point of stifling innovation, then I think the problem and solution are in a completely different area than this.
That being said, let the bad actors fail. Let their names get dragged through the mud, let the big companies sober up after a few too many VTech/Mattel/LG style failures that make the headlines. Let them either back out of the market because this shit is hard to keep secure, let them work with someone who can, or let them triple down and figure it out themselves. We're going to see a lot of failures, but we'll be better for it.
I've connected my own devices around my house (securely), use z-wave, and consumer home automation hubs/hardware, as well as some well known stuff like Nest and Amazon Echo. I don't ever want to go back to NOT having these things.
I've accounted for many of the likely failure points by these very well regarded manufacturers and I've firewalled my network very tightly, among many other things. But damn it, I've seen the future and I don't want to go back. It's too nice, too convenient, and adds too much real value.
It's your decision to buy their goods, no one should be preventing anyone from trying to enter the market just because you get the heebie jeebies or don't see the value. Someone else does- or no one else does and they fold up shop.
It is also assumed that these devices have unfettered internet access. Most of them can do HTTPS. Either you allow it or you don't. How many Barbie dolls have been having inappropriate conversations with children that a human would otherwise be arrested for? How many televisions are feeding audio from families back to a company? How long is this data saved? Who has access to it? When must it be destroyed? What legal protections does anyone have against data abuse? What is deemed data abuse? If it turns out I am being spied on, what binding agreement do I have with the manufacturer and seller that will make them feel pain? Are they obligated to give me more than, "We're sorry. Gosh, we're just so darn sorry."
Sorry, no. These devices need to be recycled before they are ever used.
The trouble with this is that "actual harm" in a legal context tends to mean something that can be proven in some specific context and have some specific monetary value attached to it.
Personally, I think harm is also done if someone knows their financial details might have leaked and then worries about their credit record and future financial security, or if someone discovers that a creep somewhere in another country has been watching their baby sleeping, or if a "smart" TV has been transmitting personal conversations of whatever nature from the living room to someone else. However, if we're only talking "actual damages", how do you decide what financial compensation is appropriate in such cases?
In reality, the most damaging violations probably aren't the ones with tangible financial losses attached, because financial losses can at least be made good after the fact. You can't make up for lost time, though maybe you can at least assign some nominal value to compensate for time spent on things like updating credentials after a breach. No amount of money can make up for the kind of distress caused to a teenager if a compromised device leaks something like their diary or an intimate video of them getting changed and the results go all around their school.
If security and privacy implications for the Internet of Things are to be taken seriously, I suspect the laws will need updating so that (a) there is a presumption of harm in cases where personal information leaks to an unintended party, and (b) there is a punitive value attached to leaks that cause non-monetary damage, with that value being very high for leaks that cause severe and/or ongoing distress.
I don't think this needs regulation. All it needs is a scale of meaningful penalties, leading up to company-destroying fines and/or jail time for executives for the most serious infringements caused by gross negligence or malice.
> On top of that, if actual harm comes to users of these devices as a result of these devices then we already have plenty of consumer laws protecting them.
When was the last time a software company was held liable for their software not working correctly, and exposing users unnecessarily? Most of them EULA their way out of any lawsuit to begin with.
Regulations on hardware devices do not stop innovation in hardware. One can say there are far few hardware startups than software startups, but I don't think regulations are the main reasons of this difference.
Which will not turn away a dedicated geek, but will give a hint to an average soccer mom.
If a product leaks pictures of your kids to the internet when it is used normally, the product is defective. If the problem was caused by a bad design[1], then the manufacturer should be liable for their negligence.
Yes, this would make entire categories of currently-used software unusable. It would probably require recalling many current and upcoming products. Adding complex network features (or any network connectivity at all) would also add liability risk, so this would also discourage (but not ban) throwing internet connectivity on everything.
As Dan Geer recommended[2], when the product is Free Software (including the build environment), the end user has the ability to defend themselves, liability can probably be limited to a refund. However with proprietary software or embedded devices where changing the software is not practical, the manufacturer should be liable for any damage their products cause.
I'm sure there will be a lot of resistance to this idea, as many products currently rely on bad design (smart TVs, nest), but allowing a security-free internet of things to happen would be a yet another Sword Of Damocles hanging over our head. Liability may be bad, but the problems that will happen if we connect everything to the internet without serious would be much worse.
[1] "bad design" would not include things outside o f the manufacturer's control, such as new way to weaken crypto or a completely new attack method. Buffer overflows, protocol design problems, incorrect configuration or permissions, unauthenticated updates or other downloads, and sending plaintext over a network should count.
That would be simple if companies weren't able to lawyer up and weasel out of any and all liability that doesn't come with explicit standards required by ... regulation. What makes the definition of "defective" vs "not defective" in determining liability is regulation. Regulations don't have to be "fine X will be levied if Y" it can be "Y is required for product Z". That is regulation and it is how we define liability in the legal system. What you are proposing -- establishing bad design -- is the basic definition of regulation.
So maybe you're talking about changing the law, but good luck with that.
2025: Every object in your home has a IP address & the password is Admin
[0] http://www.jwcn.eurasipjournals.com/content/pdf/1687-1499-20... [1] https://www.cs.berkeley.edu/~daw/papers/15.4-wise04.pdf
Since the web is now getting "engaged" to the devices with CoAP and other protocols I wanted to create awareness of how bugs can spill over into the real world and do real damage there. If hacked insulin pumps or baby monitors don't scare you enough how about hacking a train? https://media.ccc.de/v/32c3-7490-the_great_train_cyber_robbe... ?? (everyone should probably watch this simply because SCADA strangelove guys are crazy and awesome)
Anyway to counteract the usually very "marketing intensive" tone of IoT groups on LinkedIn I decided to start this IoT Security group: https://www.linkedin.com/groups/4807429 it would be great to see people from all camps (IoT is a combination of 3 silos: 1) embedded, 2) web 3) infosec) actively contributing with technical topics in this group. I will keep it open to posts from marketeers but am heavily policing it for blogspam and remove any posts that are not security related).
Also I have some ideas about hackerspaces (http://hackerspaces.org/) which IMO every city should have and support. They're needed to propagate knowledge between these individual camps properly. (my contact details are in my profile in case you are interested to discuss more offline).
I'm not an embedded engineer type, so the security burden I saw being hefted upon my shoulders felt much more onerous than the typical REST type API I've been accustomed to.
At this point, I cannot imagine writing an app using IoT while at the same time feeling confident in understanding every bad security use-case.
Perhaps `IoT Security Expert` is an up-and-coming career path, but it's not a job description for the faint of heart nor for the one-off developer to be able to approach with any sense of confidence.
> verifies that known invalid credentials don't permit access
you need a second test: "use invalid credentials, then try to download file, expect failure", i.e. a sequence of actions in a single test.
That test is evidently missing from my heating system's web interface, which has exactly this problem. There's a box to type in a PIN code, and it lets you proceed / retry correctly. But it's not necessary to bother with this, you can change the temperature without authenticating if you know the URL.
http://www.nytimes.com/interactive/2015/07/03/upshot/a-quick...
You're totally right that you should have a unit test that verifies failure with invalid credentials, not just success with valid credentials. But a lot of programmers are not as smart as you are here!
I actually uncovered a bug in a JWT library once when I wrote a test for my application to verify that an invalid token would be rejected.
Let's just say there was no corresponding test in the libraries test suite.
people want a webcam they can plug in and use, most people don't consider the features it offers nor do they secure it beyond what is enabled by default. webcams are a thing, like it or not, and they use the internet, like it or not.
if you think a rascally teenager turning your webcam lights on in the middle of the night is bad, wait until he changes your e-fridge settings and all your food spoils.
For one example, I recently moved into a newly refurbished apartment. It has underfloor heating, with a central control box and remote sensors/controllers in each room. [1] It cost something like €1500-€2500, plus installation, plus the pipes etc.
The central control box has an ethernet port and MicroSD slot, which takes a ZIP downloaded from the manufacturer's site.
I set this up, and was disappointed to see just how terrible the provided software is. There's no Android app, and the iPhone app costs a further €15 [2]. It has only the most basic functionality: see and change the target temperature in a room, and change which program runs (day/night/off/preset1/2/3). The most-needed thing — to change the preset timings without 100 presses of a 5-button LCD interface — isn't possible.
The web interface is the iPhone app implemented as a Java applet making HTTP calls to the server. It's too big to fit on my laptop's screen. There's an 'authenticate' call, but it's optional — the app requires using it, and the call gives the correct pass/fail response, but there's no session handling so there's no need to make this call before reading or changing temperatures.
The Java applet at least means it's not easy to do a Google search for the web interface, but I just found this site [3]. There are a few results, but from a long time ago.
[1] http://www.billigvvs.dk/Varmesystemer-Gulvvarme-Roth-gulvarm...
[2] https://itunes.apple.com/dk/app/roth-touchline/id498448526?m...
The IoT is turning consumers into inadvertent sysadmins. For the first time in the history of computing, inexpensive consumer products are functioning as servers. These servers are often dreadfully insecure, e.g. internet-accessible root access with a default password.
The market for a $50 IP camera is inherently different to the market for an $800 IP camera.
I had a Linksys WVC11B IP camera like 12 years ago, I don't remember how expensive it was but it was definitely cheap and targeted consumers for home use.
"Peiter “Mudge” Zatko is a member of the high-profile L0pht hacker group who testified before Congress in 1998, and since he's gone on to head cybersecurity research at the Defense Advanced Research Projects Agency (DARPA) before joining Google in 2013. In June, Zatko announced he was leaving the search giant to form a cybersecurity NGO modelled on Underwriters Laboratories."
and above that, a section about a similar "consumer reports" style rating organization. that was also the first time i'd heard of the group i am the cavalry, which seems like a cool idea (in principle, at least, without really knowing much about the actual group).
and i understand this objection to that sort of approach:
"It’s not the same quality problem... UL is about accidental failures in electronics. CyberUL would be about intentional attacks against software. These are unrelated issues. Stopping accidental failures is a solved problem in many fields. Stopping attacks is something nobody has solved in any field. In other words, the UL model of accidents is totally unrelated to the cyber problem of attacks."
it is a very different problem in a lot of ways, but that doesn't mean that an approach similar in spirit or presentation is doomed to failure. and i think it does fit into the broad category of messy consumer information problems that are hard to solve with specific detailed regulation.
You're increasing your support cost by a factor of 100 to 500, and that's a very conservative estimation.
No, I recommend delivering cars with brakes and brake fluid because that saves support costs.