New DDoS Attack record 1.5+ Tbps
bbc.com
bbc.com
It's scary to think about the potential for leveraging IoT devices for DDoS attacks. Your dishwasher, fridge, thermostat, mattress, chairs could all be partipants without you even knowing.
But, it seems that ISPs could play a more pivotal role in combating this, and that they'd have financial incentive to do so.
For instance, what if we built more security/detection into routers/gateways (especially those that ISPs push)?
What if we combined this with mandates for ISPs to better monitor their traffic and established minimum standards for doing so?
I won't be surprised if we see, before the end of the year, news along the lines of "Toaster catches virus, leaves owner with $5K data bill." Why bear any costs when you can pass them on to your captive customers?
If the network starts to serve an increasingly disproportionate amount of illegitimate traffic for n customers, then the ISP will have to increase throughput (and costs) to continue serving n customers.
It's tempting to argue that they could just pass the extra costs on to customers, but that obviously makes them less competitive, especially vs an ISP that better manages costs.
But would you notice if your thermostat was running a little slower than usual? Would it even occur to anyone that their dishwasher might have caught a virus? These things could participate in DDoS attacks all year long and nobody would suspect a thing. And even if someone did, fixing them would be much more difficult than taking your laptop to the nearest Best Buy (or even impossible, thanks to DRM).
But then I'd guess the crooks will just compromise the router itself.
I think it is silly. You think it is silly, but people will buy this crap. They think apps will solve their problems.
It's really more than sufficient to me. In fact, with everything else I have going on, I don't need my refrigerator texting me whenever it thinks it deserves my attention. That would actually be inconvenient.
Then, there's this hidden cost of the purported "convenience". More stuff updating, hacked etc. And, with the thousand other devices, now I have to spend time configuring what I want to manage, etc.
Reminds me of something I read years ago about the hidden costs of some tech. In one anecdote, subway riders were excited when A/C was installed on the train. Now, they could ride in comfort. What they didn't realize was the A/C exhaust heated the platform another 10 degrees or so, and they were actually less comfortable while waiting.
People with money to spend are choosing design, real estate (location over structure), experiences and food.
It's an arms race, and we measly individual consumers with real life concerns that don't center around defending our psyche from nonstop sensory ambush stand a very poor chance.
In all seriousness, it could be a good niche market "not internet capable".
Alternatively, in the summertime they could crank up your heat and potentially kill any pets you have at home.
http://www.recode.net/2016/9/29/13099092/samsung-exploding-r...
What if you have wood floors? What if water shorted electrical devices? All of this could cost you thousands in repairs.
My main concern is these devices causing bodily harm
That's a reasonable, genuine concern, and one that should require physical interlocks (not just software code) to guard against.That's a good situation for mandatory safety codes (such as the FDA requirements for 2 physical interlocks on microwaves [1]).
[1] http://www.accessdata.fda.gov/scripts/cdrh/cfdocs/cfcfr/CFRS...
In 99% of cases these devices are exploited using vulnerabilities in the software or configuration added by the vendor (such as telnet access with root:root), not bugs in Linux.
>open source
How exactly would a permissively licensed kernel get vendors to disclose the source code?
Most home/consumer routers lack the capability to throttle a specific device, and most consumers wouldn't think to configure this if the capability was there.
There's a good argument to say that they should be throttled by their own software, but the basic premise of the issue is that IoT software is badly designed, badly programmed, and badly maintained, so I wouldn't hold out much hope of throttling in the device itself.
Botnets are run for business and will attract well-paying customers if they can demonstrate that they can disable (nearly) any target. The fact that any client of a hosting company such as OVH is very bad news for the attackers and excellent advertisment for OVH.
I'm not saying someone should do it... but I'm not saying someone shouldn't do it.
Are the manufacturers stupid enough to put the items on the internet AND embed a self-destruct command...
Simple connect to one, and then overwrite the boot partition. Or rm -rf /. Or even just use the firewall to block all inbound and outbound connections (an IP camera isn't very useful if you can't view the feed).
Frankly, I would NEVER install such a device in my house. The engineering on many is (almost?) criminally flawed.
I would be all for such... preventative action... if it wouldn't also hurt the consumers. Unfortunately it is the end users that would lose.
I don't understand why most IoT devices require an Internet connection to work, for anything other than phoning home (data collection by the device provider). Of course, a Television is different than a Refrigerator here.
Unless you live in a mansion where the distance from devices becomes significant, couldn't your "Home PC/Tablet/phone" connect to your IoT device via bluetooth or on the subnet? Exploits are still possible, but the majority of them would be localized. The cost of slightly lower ease-of-use (which can be mitigated by good OS support) would appear to have numerous security benefits.
I'm not arguing that this is a good thing, but it does explain why the devices want remote access. In an ideal world, this would function through some kind of home hub device – a single point of communication between "outside" and "inside", which has many clear benefits. In practice, it's going to be difficult to do this; devices don't use any kind of shared protocol or system that would enable this.
I am currently working on an 'IoT' project, and it also connects to a central server, directly, over wifi, for exactly these reasons. It's hard to see what other approaches are possible at this stage, until there is some kind of industry-wide standard that's actually used by manufacturers.
This is exactly what I was suggesting, and thanks for your input!
I believe this is a space where Raspberry Pi has some potential - as there are some open sourced projects that handle some of these functions. Personal anecdote: I recently bought a PiNoIR module and plan on building a (relatively primitive) apartment security system in which the machine the camera-pi "phones home" to can send my phone Twilio SMS if any motion is detected.
Problems I foresee is if the home computer is pwned, both devices can be exploited for the same nefarious task.
:EDIT: Granted, most consumers don't want to "DIY" as much as I do.
How do I check my cameras from work? When I realize I didn't remember to record my favorite program once I reach work, how do I fix that?
> couldn't your "Home PC/Tablet/phone" connect to your IoT device via bluetooth or on the subnet?
Not every customer has a NAT router setup at home.
> The cost of slightly lower ease-of-use (which can be mitigated by good OS support)
Lower hanging fruit would be not leaving a telnet server open on the box in the first place, which is apparently already more work than some of these companies are willing to invest. And I'm not sure how good OS support is supposed to make up for the lack of a NAT router, or how you're supposed to limit things to your home network when you want to access them from work - or how those two fundamentally incompatible goals are supposed to be made compatible by "good OS support".
Case in point, Musicbee - the excellent music player, has a little Android remote control app. It just operates via the local net behind the firewall. It's reliable and a well designed Android app.
If Samsung, Apple, or any startup were providing this it would send all your data to the website and the app would operate via the website too.
You'd gain the "convenience" of being able to change track and volume when out of earshot, and a web portal with adverts targeted on your listening and a pretty graph or two.
There's no need for my toaster, dishwasher to be web aware. Living on the local net would be enough for any of the features they give.
http://www.nbcnews.com/tech/security/kaspersky-smart-fridges...
In just a few years we may be dealing with tens of Tbps DDoS attacks thanks to the "explosion of IoT", unless IoT manufacturers get their shit together (perhaps also encouraged by aggressive government actions and fines against those who don't follow some set best practices on security).
>encouraged by aggressive government actions and fines...
Funny, I just replied to another comment that it seems near hopeless to expect this of manufacturers.
Seems that ISPs, on the other hand, might be able to play a more pivotal role.
ISPs have thin margins, and get paid to push bits. DDoS mitigation services are extremely expensive not because they are complex or novel but because they require significant resources (both in hardware and in software expertise).
If manufacturers are going to sling "shit" and we can't hold them accountable; consumers are going to buy the polished turds and we can't prevent them plugging it into their networks; and ISPs have little to zero incentive or ability to "filter out the bad traffic" then we're basically looking at a 5-10 year span of increasingly detrimental, expensive, and effective denial of service attacks.
Default free providers such at NTT, GTT, Zayo/AboveNet, Level3/Global Crossing, ATT, CenturyLink/Qwest, Deutsche Telekom, Vodafone/Cable & Wireless, and others commonly (but incorrectly) known as Tier 1/"backbone" providers peer with other networks in a settlement free (no money is exchanged, or, on an accounting basis, everything zeros out) fashion because they are "peers" in the strictest sense: same size, same reach, same markets (mostly...)
there is no danger for them in passing bits
Well, maybe there is a silver lining to Comcast and friends' data caps after all.
I agree device security ought to be better, but the free market can solve that. If a particular brand of toaster is constantly being hacked, the market would respond. I wouldn't expect an ice maker manufacturer to be held liable for poisoned water supplies.
It's a tough issue, but 'more government' isn't the answer. The government can barely keep their own data safe let alone be trusted to enforce how others ought to keep their's safe.
The FDA is supposed to keep medicines safe yet it has become a monster that adds billions to the costs of drug development. I am not saying to ditch the FDA, but I would be fearful of releasing a new IOT device required FDA-level approval. Your connected toaster would cost $9000.
If a particular brand of toaster is constantly being hacked, the market would respond
That depends whether "the market" is directly affected.If my toaster is hacked and starts getting used in a DDOS botnet - but still makes toast as expected - would I even know?
The way to ensure market forces influence this is to ensure that the market is negatively affected: whether that's their ISP disconnecting their internet, their device stopping working, etc.
How is the toaster connected to the Internet? If through wireless, a DDOS could easily use too much airtime, making every other wireless device in the same channel slower.
You wouldn't notice the toaster misbehaving, but you would notice everything else not working as well.
you would notice everything else not working as well
Assuming that my toaster didn't get owned on day 1, even as a tech-minded person, if my wifi suddenly started slowing down, I'd be considering a number of other alternatives before wondering whether my toaster had been hacked.Let's assume a little bit of packet-sniffing would uncover the cause, that's still only a very small minority of people with the skills and tools to go through that process.
Why are these devices being exposed to the internet?
Many home routers are horrifically insecure with numerous remote vulnerabilities. Many IoT devices have vulnerable and accessible interfaces locally and externally.
Now, I'm paranoid each time they push an upgrade without warning. It was them or an E.T?
Lastly, even if you're behind a firewall you're still not safe. For example DNS rebinding attacks. The least secure device on your network gets hacked, the attackers then use it to scan and exploit devices on the LAN. In the enterprise I avoid this by putting different classes of devices on different VLANs, but this comes with the side effect of being very expensive hardware wise and not easy for the average user to manage.
I have no idea of the liability of developers in this space, but the fact that the question even comes up in my mind certainly gives me pause.
I can't see this ending well.