Dishwasher has directory traversal bug
theregister.co.uk
theregister.co.uk
I would not be surprised to see similar printed labeling requirements for IoT devices, in bite sized chunks that are more standardized than a device-specific EULA, e.g.:
This device runs on:
firmware A (unaudited)
web server B (UL approved)
update expiry date: Jan 1, 2020
This device may: capture video, sound, and/or user input
send user data to our servers
send aggregated user data to 3rd partiesAnd failing that, some Good Old All-American Common Law suits should do the industry a world of good. This product surely has an implied warranty of some kind.
Having an API totally makes sense here to have monitoring and error reporting.
I am in no way justifying the lack of security but I think its important to understand that its unlikely to be opened up for a free for all connected to the public internet.
Unfortunately, that kind of thought process is how you end up with dozens of vulnerable devices connected to a hospital intranet. Everything works fine as long as nobody tries anything fishy, but all you need is one device with a buggy Bluetooth implementation to bring down the whole house of cards and kill a bunch of people.
I vaguely recall something about a faulty hospital device with Bluetooth or Wi-Fi being posted here a little while ago, but I'm not certain.
Once you compromise one machine, you're inside the firewall and in a much better position to exploit vulnerabilities in other machines in the network.
>I am in no way justifying the lack of security but I think its important to understand that its unlikely to be opened up for a free for all connected to the public internet.
Considering hospitals and technology I don't think this distinction matters much. There only line of defense seems to be isolation but things like wireless devices are becoming more common.
From the manufacturer docs, that is the most common option for these things: https://www.miele.de/media/ex/hk/Professional/CSSD.pdf
Slightly cynical answer: In medical environments? Then the device on the other end of the serial connection is probably vulnerable and/or horribly outdated, either by being an embedded device made to the same (lack of) quality standards, or by being a desktop PC running Windows 2000, or software requiring to run as Domain Admin for no good reason, ...
That just gave me an idea...
https://www.shodan.io/search?query=%22PST10+WebServer%22
> No results found
Can't say I'm sad about that.
(Searching for just "PST" finds a single irrelevant SMB share.)
Even industrial washers that require reporting on temperatures reached and stuff like that don't really benefit from a connection.
1 - send the owner an urgent email in the event of catastrophic failure, i.e. drain blockage which might lead to overflow all over the kitchen floor.
2 - let owner know status of current cycle, in real time. Some people might like to know that, though I'm not sure why. Usually you run the dishes at night or during some open ended period of time so you don't have to care when it finishes.
You could theoretically control the appliance with a computer or mobile device. Why would you want to? Beats me, but it's one of those gimmicks that might please some gadget-happy segment of the consumer market.
What evil things could a hacker do to your dishwasher? Make it start in the middle of the night? Ruin the delicate plastic stuff?
I'd personally be very happy just to own a dishwasher that actually cleans stuff. I've had several dishwashers and have yet to see one that cleans as well as I can with my Scotch blue pad and Ajax.
Most users probably want to--or are required to--keep records about the cycle length, maximum temperature, and stuff like that. We had an older machine that printed this information on cash register paper, but clearly that's not ideal if you want the data to be stored and searchable.
Similarly, the remote monitoring/alarms could useful for keeping procedures on schedule.
Turning it into a botnet node, cf. Mirai.
If the only harm that came from Internet-all-the-things was that to the owners of the devices I'd welcome it; the person who buys this junk is one who deserves everything they get. It's the damage being done to the rest of us that is worth caring about.
Waste a lot of water/electricity. Run cold water only so it doesn't disinfect. Use it as a platform to attack other household devices. Most hackers would only have a motivation for the latter.
All of these various manufacturers are never going to get their act together. Even if they do, individually, the additional costs are likely to make them less competitive.
And sell the backend solution too for enterprises, and offer a hosting solution for small scaled deployments. There's definitely a market for that.
And imagine if you're the Mark Zuckerberg ("They 'trust me'. Dumb f*cks.") of all these devices. All that data...
Actually, they'll probably start trying to sell you copies of Norton or McAfee to keep it "safe" ...