If my shitty DLink camera suddenly stopped working, I wouldn't demand a refund - realistically, I'd just toss it in the bin and try to remember not to buy more DLink products. But I probably still would, if they were sufficiently cheap.
I imagine that calculus is similar for most people.
It's tough for security to affect purchasing decisions because it's difficult to measure. I can measure horsepower, megapixels, gigabytes, milliamp-hours, etc. so it's easy to make purchasing decisions based on which of those things are important to me.
But I don't think bricking a device necessarily ties into security in people's minds. If they permanently modified it to always show HACKED_BCUZ_DLINK_SUX whenever I try to load the camera feed, sure - but a bricked camera is just a failure. I don't even know if it got hacked, or if a capacitor blew, or if a rodent chewed through something crucial.
If only it weren't for you meddling kid.
Analogies, aren't they great?
(Since it's apparent that sarcasm can't be read: "Stealing bikes" isn't the same bloody thing. Why even make that analogy?)
Does this concept apply to software? When the next large-scale RCE 0-day drops, does it make sense to use exploitation to destroy as much as possible in order to pressure the developers to ship a secure product? Since, the hacked machines certainly could allow an attacker lateral movement to sensitive data.
How, like 5% of people that buy electronics actually turn in the warranty cards. No, they will sit on the shelf for years polluting the internet with DDOS attacks and spam.
>es it make sense to use exploitation to destroy as much as possible in order to pressure the developers to ship a secure product?
Yes. That is also why I backup data using multiple methods including off line ones.
Vigilante or blackhat doesn't matter. The next RCE will gladly spit copies of CryptoLocker everywhere if they could get ahold of it.
The internet is a dangerous and well connected place. If lived China, I would think it's funny if I wiped a few large US corporations off the map because they used a DLINK webcam. And there is only a tiny chance in hell they would ever find me.
Additionally theft of property has a personal gain for you.
I'm not sure I ethically support the hacker's actions, but I don't think the bike example has the market/awareness effects that make it at all defensible.
What's the problem with these people?
Sarcasm aside, I live in Brazil, ask any Brazilian who stayed on an European country what was the biggest difference: "I could feel safe anytime, without worrying about my stuff".
That really shapes the mind and behaviour of people.
Isn't this actually a really common sentiment, though? I've lived in several places where leaving a bike unlocked for 5 minutes, or sloppily locked for an hour, means you're going to lose it.
That doesn't make the theft acceptable, but if a friend borrowed your bike and left it unlocked you'd still get mad at them.
Reshaping society so this stuff doesn't happen is great, but on an inside-view level we treat crime as sort of an inevitable "someone will do it" force.
I don't disagree with you, however I think there are some levels to this concept, e.g. how two different locations would differ if it was: a lost wallet, a somewhat clear opportunity for embezzlement, a bike stopped in front of a coffee shop?
The same kind of stupid person that doesn't realize they live in a ghetto called "The Internet".
This actually seems much closer to the IoT issue than theft. The maker and user of the device have created an inviting target which will cause harm to someone other than themselves. Even if the eventual attack is illegal, they can still be held accountable for making it so likely.
Note that "attractive nuisance" is specifically about trespassing children.
IANAL, and it's hear say, but I had thought this was something everyone knew.
Given the owner of the bike could conceivably be held liable for the use of their bike to commit crimes, the janit0r who decided to clean up this crap comes across as the lesser of two evils.
I find it reprehensible that the Gizmodo author (who is using his position as a journalist to encourage criminals) and HN commenters are applauding this hacker as if he's a hero of the people, fighting for a better future. He's directly harming individuals who have purchased products. This is not a friendly reminder to manufacturers to get their shit together. It's some guy illegally connecting to, taking control of, and bricking computers.
I've seen him referred to as a greyhat. No. Everything about this is strictly blackhat. This hacker deserves prison time. What a piece of lowlife scum. It really does sound like a 15 year old getting off on making waves, rather than someone who gives a damn about security.
Attacks on devices that have hardcoded weak credentials online aren't an event or an act. They're a force of nature, like erosion. No-one would be happy with someone building bridges that don't account for erosion. Nor is it ok to ship something that connects to the internet and doesn't account for the millions of automated bots that are prowling the web 24/7 looking for insecure devices.
The manufacturers are 100% to blame, and the worst thing is that they're not the ones that deal with the fall-out – innocent companies and consumers are.
Do you force the situation and make it mow into your yard and over a bunch of rocks to destroy it, or do you live with the danger?
I don't have an answer. In this situation you could at least talk to your neighbor. Without the ability to feasibly do that, I'm not sure I would fault either action.
The answer falls into an area that's somewhat unknowable with current information, which is why I can't fault either behavior.
As in, "the chance of getting hacked" < "the chance of the vigilante creating dangerous situations".
For example, maybe this person had a wife dying of cancer while Mirai destroyed his life's work, so in the same period he lost his wife and he lost his work.
Or, maybe he spent a lot of money trying to launch a new product through channels that were destroyed during one of the attacks, and unable to get his money back, had to close the venture.
Maybe he had to sleep in a data center for several months during the holidays and concluded the only reason he was doing this is because consumers and manufacturers aren't concerned with the damage they are doing, so he is going to make them become concerned about the damage they are doing.
The point is that we have no idea if this person has been harmed, and whether they have any other legitimate means of being made whole from harm done, as well as be able to protect themselves from future harm.
Clearly, the proposed solutions coming from industry "experts" is likely to make things worse, as the only other activities to "fight" Mirai seem to be to support legislation as a solution to a technical problem, and I'm really not clear on when this has ever worked, especially in a system that everything on the planet can connect to.
If you put a dangerous, unsecure device, live on the Internet, that can be used to attack other machines, you deserve to have your property be destroyed.