DIY Smart Home Security? Meh
blog.seekintoo.com
blog.seekintoo.com
An interesting read but isn't it kind of missing the point? Most people running a home grown security system via one of the main IoT hubs just want basic security against your average smash and grab criminal. They aren't doing it because it's "popular and trendy" - it's a relatively easy way to monitor your home without the cost of traditional home security systems.
To be clear (i.e. avoid the usual negativity of IoT thread on HN - "No one should use IoT because it's so insecure!" etc), personally I think this type of breakdown is something that should be encouraged - hopefully it'll push device manufacturers towards making more secure products. iSmartAlarm is being sold specifically as a security system so they should be open to criticism if they aren't any more secure than a basic IoT hub with a few sensors...
It would also be interesting to see similar analysis against COTS/commercial grade security systems.
People buy a $200 Nest Cam because they just want simple visual security (e.g., something is going to happen I just want evidence).
It's good to expose the flaws, but criminals don't know whether the relay switch on the window frame is hard-wired or not, or whether a camera is hidden which records to its memory card and not even part of the IoT. The array of cheap devices we have available to protect, deter and monitor our homes is awesome.
This is the best point. Police officers I have talked to advised against using the "Protected by ____" signs and use a generic "Alarm system installed" sign so criminals wouldn't have an idea what you are using. The best criminals can get into anything, and if you tell them what system they're using it's just going to make it easier for them. You can have one of these "cheap" systems but it may take the criminal just as long to figure out how to break into your house "safely" if they don't have that knowledge before.
If this is the attack vector that concerns you, then you should probably start by installing secure doors and windows.
IMO, cameras don't get you much beyond giving you some after-the-fact information. And smart-locks don't get you much of anything.
Easy insurance claim when I'm out of the house and an audible alarm when I'm home. That's all I want really. Things can be replaced, and for the most part, by someone else if I can prove it. If your alarm goes off and you yell 'get the fuck out of my house', they probably will.
If they don't, at least you aren't supprised or unaware when they get to you.
I think the concern here is stated in the article; "I'm attacking a established radio network protocol developed by TI that is used in hundreds, if not thousands of other products that could have also made the same fatal implementation mistakes."
The problem is this device protects against smash and grab criminals, but it literally opens the door and reduces the barrier of entry for more sophisticated, remote attackers. Adding this type of vulnerability to Shodan would mean these devices can be identified, attacked and remotely controlled by any remote attacker, giving them information about the target they never had originally.
I don't think it's too far fetched to imagine an "AirTasker" criminal network, where a remote (sophisticated) attacker links up with a "smash and grab" criminal for hands-and-feet on the ground, agrees to split proceeds and work as a team on something like this.
Personally, I find this very disturbing. A security device manufacturer should take their security, and the responsible disclosure of vulnerabilities, far more seriously than they appear to be to-date.
The "smash and grab" criminal would have some pre-built arduino/raspberry pi/sdr combo that has to be within radio proximity of the building, but once in signal range, the remote person can work their magic.
The chapter on physical security and alarm systems is riveting.
Physical security systems are best thought about holistically (barriers, locks, surveillance, alarms, response force, their interactions, etc.) and in terms of what they are protecting from whom.
In terms of his threat model, an alarm like this would protect against Derek and Charlie, and maybe make Bruno do some work, and stand no chance against Abdurrahman's PhDs. That's okay. Most targets interesting to Derek and Charlie aren't interesting to Bruno, so there is no need to engineer for him.
For targets that are interesting, the military and the insurance industry have some very sophisticated work on specifying and certifying the protection systems for high-value objects such as priceless art and plutonium. They won't buy iSmartAlarm, and that's okay.
The full text of the chapter is free: http://www.cl.cam.ac.uk/~rja14/Papers/SEv2-c11.pdf
If you're serious about home security, then you may want to hardwire your devices and VLAN isolate your security/control network to give some semblance of closed-circuitness. I will always hardwire when possible and concentrate on physical attack vectors.
When you're going up against someone who knows how to use a spectrum analyzer and jammer, then you might have bigger problems.
In the same way that web developers grab Bootstrap and get a beautiful-enough site working out of the box, this company found a Bootstrap-for-wireless-communications framework and chip from TI.
What they didn't do is customize it for their needs (security-hardening) nor use any non-default configuration.
Point is, using a pre-built building-block component to speed up your go-to-market isn't inherently bad. In fact, you might even argue that an alarm company who rolled their own fly-by-night wireless protocol would raise more eyebrows.
(Btw, I'm building DIY home automation around esp8266-based iTead Sonoff sensors.)
You get what you pay for in some respects.
Some of these products are more expensive than their counterparts because of the amount of time and effort put into security and overall design of the product.
But if I see a deal online for $200 home security DIY and my closest pro install costs $X over Y years, the actual technical security of the product doesn't come first in a consumer's mind. I know until I worked in the space, I can't say I thought of it either.
Is that the case? It was my impression that the lack of security is pretty much ubiquitous in the IoT space and expensive brands basically do all the same crap. Is there any vendor that stands out, e.g. by saying "we'll do security reviews and guarantee updates when vulnerabilites show up for at least X years"?
They showed a ransomware takeover of a thermostat. Everyone started freaking out. Here is what they didn't say though: - You needed physical access - Thermostats are replaceable (as in put a new one on the wall) - It was not a major brand to my knowledge.
Something you have to think about is path of least resistance.
Your support guys are exceptionally good at communication and have great patience. Especially Adrian G!
Apologies for the unsolicited feedback...
I work on this: https://developer.honeywell.com
I also wrote some of our Alexa skills.
Our security systems having an Open API is half a technical problem and half a legal/PR one, as you can imagine. That being said.. there are some scraped projects out there.
Oh, and I believe I saw a really slick looking HTML5 version of Total Connect. I can ask.
Something dumb, hardwired, and preferably with a couple of way to call out over a phone line really seems like the best option in my opinion.
That said something like the Vista doesn't seem impossible to install yourself for someone with a basic understanding of electrical circuits.
I know more of our high/mid end systems use all wireless sensors now.
The problem with many of these devices is that they're all too willing to talk to things that don't have their key. That makes them vulnerable to attacks.
I've used Saleae autobaud before and it really likes to end up a few percent off from the actual bitrate. I'm guessing it actually was 56700, but there was enough slack that it worked anyway.
Beyond that, a great article. Highlights well the complexities of securing wireless devices.