It's actually the main relevant part of the analogy.
It goes to veracity.
There's a person who gave a public talk about manipulating Bitcoins with weak private keys in order to alert the owners that they were vulnerable. But he did it in a way that verified to the owner he hadn't in fact stolen the coins (moving small portions around or maybe signing with the key, I can't remember). He also mentioned in the public talk that the owners of those Bitcoins were totally freaked out by this, and most were never convinced that he was acting in good faith (which is probably a smart assumption on their part).
So the fact that he didn't steal the coins is completely relevant-- it's the very reason he could give a public talk on what is still grey area behavior.
Your hypothetical thief, on the other hand, is clearly mendacious. You have him claiming, "If I don't capitalize on it, then people won't understand the costs/risks." That is clearly false from my real-world example above, and if he tried to give a public talk about how his theft benefited society he'd be arrested.
Your point that I couldn't have given a public talk had I stolen the coins is completely correct. I still spoke with a lawyer about it ahead of time, though. :-P
There was another person, who was somewhat less scrupulous, who would simply steal the coins and watch for someone to complain in public about it, then offer to return them. They use a pseudonym and as far as I can tell have vanished.
By saying clearly different, I don't mean to minimize the actions of the vigilante. One of the chief characteristics of civil disobedience, for example, is to resolve that could it be question. By receiving the unjust punishment the dissident displays good faith with proponents and opponents. I don't yet see how pseudonymous hacktivism keeps that good faith with the public. And that seems to relegate it either be small scale, symbolic acts like this or large-scale grey hat stuff that brings lots of unwanted risks/cooptation/etc.
That's what the IoT vendors did. ;)
Also, if the device is bricked very quickly after buying it and installing it, the consumer will very likely simply return it to the retailer as defective, which again pushes costs back to the manufacturer.
So, yeah, even in softwarw one can do as you suggest. Multiple times it's been done with things improving across the board. In DO-178B, an additional effect is an ecosystem of tooling, reusable components, and consultants sprang up to make each project a bit cheaper and less risky.
I know it's fashionable to blame the MBAs instead of blame ourselves, but at the end of it, we're the ones who write insecure code. And I don't think that if you give an engineer an extra week or two to focus on security that you'd end up with a measurably more secure device. Securing something is a different skillset from building it.
Pentests are probably the answer.
Or to put it another way, if we're not proposing to bring in an outside team to conduct a pentest, what's the alternative?
Pentests are, to be clear, great, and there are plenty of people who Dunning-Kruger their way through security decisions. But time is definitely a factor in this stuff.
It just seems like pentests need to move from "nice" to "necessary." (Part of that is reducing their cost from $60k to $6k.)
Security needs to cost to demand talent. The real solution to this problem, I think is that failure to secure needs to cost (whether in monetary or criminal terms) or it isn't relevant to business concerns.
> security is inherently and inescapably expensive somewhere in the chain
...is the thing that needs to change. Presumably using more automation (e.g. employing more software like http://lcamtuf.coredump.cx/afl/), such that "pen-testing" shifts from being a labor cost to a capital cost.
It's the hard stuff that is context- and environment-dependent to a degree that it resists automation.
Put OpenBSD and OpenSSH on them with configuration explained in a good book on the subject. Write your apps in memory-safe language that validates external input. The End [for vast majority of attacks in IoT space]. It's not as hard as you detractors claim. They just don't care.
Nothing I said implied bolting anything on prior to involving upper management.
ANY decision at any time during the process can be overruled by any MBA. That needs to change.
In this, like most things, you need a balance. If you aren't commercially driven in some fundamental way you probably won't last long enough for any of this to make a difference.
Of course if you apply that the wrong way, you end up with devices that suck and/or harm users. This way leads to regulation typically, since Smiths invisible and myopic hand usually acts too slowly for people to be convinced it will get to the right place, if we just wait long enough.
I'm intrigued by this phrase, could you explain it please?
Adam Smith used the phrase "invisible hand" to describe the way markets reward certain business ventures. The previous poster called the invisible hand "myopic" in reference to consumers being focused on cheap devices with features that immediately benefit themselves.
On the one hand, this certainly makes a lot of sense, especially these days with so many stories about terrible engineering (either just bad or as a result of unethical behavior) causing real harm.
On the other hand, it's precisely organizations like this (effectively guilds or unions) that tech "leaders" try to disrupt. They tend to be pretty conservative.
If engineers run the shop you might even end up with another Uber. And we all know what a disaster that is.
However, at some level, MBAs and engineering need to be on level terms. If there's a conflict it can be resolved by going higher up the chain and both sides have the opportunity to make their case.
The idea here is that no engineer would knowingly sign off on something bad.
Being able to put your foot down doesn't allocate resources for security updates.
Note we've had worms and such for decades now and most of them don't deliberately break things. It's generally far more profitable to exploit the resources than simply destroy them. Brickerbot almost certainly wouldn't be if we weren't all getting affected.
Best case scenario: users claim warranty and replace their devices something better
Worst case scenario: users need to buy new gear, they probably won't buy from that same manufacturer because last one died for no apparent reason. Really worst case scenario: users buy again the same cr*p and dies again, until they realize that brand is worthless and buy something a bit better. Doesn't seem so bad, if the alternative is having their machines taking down businesses and users...
FTFY
Im only having a few possibilities come to mind that are life-threatening. Most are just annoying or financial drain. If we add painful, maybe make an epileptic's screen on SmartTV blink fast like the attack on the web site. Turn off people's alarm clock enough they get fired and loose health insurance before major operation. Im really having to stretch it here.
How about in arsenic? The Internet of Things is mostly insecure trash that will only be fixed by throwing it away. The manufacturers know this, and simply don't care.
John J. Citizen should be thankful if the person who finds it only wants to deactivate it rather than use it to poison him / shoot him / run him over. No matter who finds it though, it's tough luck for that person; they're the owner of that item in name only, if they don't secure it.
Society has decided in some cases (in domains well-understood by legislators, unlike IoT) that the person doesn't deserve to keep that item if they don't secure it. Example: "Improper storage of a firearm" or the like, is literally a crime in many jurisdictions and can result in losing your gun license. Creating a burden on or a danger to society through your neglect has in that case been affirmed to be unacceptable. The law will catch up with this too, I hope.
Very few people that use the internet were unaffected by shitty IoT security. And that seems like it was just the start of it's capabilities. Something needs to be done to destroy these cyber weapons. If your stupid light bulb is recruited into a cyber weapon, then it should be prevented from harming others.
Right now, we're beginning to treat DDoSes in that "infectious agent"/"your responsibility if you don't act to protect yourself" way. So many people do them, so often and so easily, that "shutting down the botters" one-by-one will never make DDoSes go away. So we have to just figure out how to deal with them. (Which will, coincidentally, make DDoSes actually go away, if everyone ends up immune to them such that it's no longer useful to do one.)
But, annoyingly, we still handle bots programmed to scan for and exploit software vulnerabilities (worms, ransomware, what-have-you) as only intentional malicious action on the part of their original author, to be solved by catching the author. (Not that you can't catch the author—but that won't stop a worm, and especially won't stop someone else from just slightly-modifying and then re-releasing the worm.) We haven't bothered nearly at all with the "how do we make software vulnerabilities, as a class, less exploitable" part of the equation.
Personally, I'm hoping that this decade sees "A-Life" computer worms, that self-modify using (machine-readable?) 0days they discover by spidering the web from their infected hosts. Computers would be being attacked with novel exploits, even with no new malware authors to do the attacking! Then we'd really have to treat vulnerabilities as a fact of life to secure around, rather than something we can stop by just stopping people from bothering to exploit them.
Yes, this a rotten situation, and I sympathize with the motivation. No, I don't think we should blithely disregard the fact that the worm is likely causing genuine harm and that it was in fact created to cause harm.
Right now we have script-kiddy teenagers; Real Soon Now there won't be much reason to expect your average 5-year-old with a Youtube account, won't be able to slap together something like a ransomware worm from readily-available components, that will spread itself a billionfold. And, amongst 7 billion people and growing, there's going to be a lot of kids thinking that that sounds like a fun time.
The only thing to really stop this from being the world we live in, is making worms irrelevant.
(And what we do in the short term, about this case? Honestly, I haven't bothered to think about it. Too "identity politics.")
What do you do when I change my logic to, well this is a ZERO DAY exploit, but you need to be patched, without understanding the complexities of your device or network. Which we all know QA takes a while because of variables. Look at any microsoft patch for evidence of that. Your argument makes it seem like if I decide to weaponize the Shadow Brokers toolkit to lockdown and secure networks around the globe, i'm ok because my intentions are good and manufacturers should have secure code without 0 days. What happens when a proprietary driver or component fails because of a change made to the kernel or the way it handles driver functionality? Now I've broken / disabled something because I didn't know the intricacies and instead chose to do what I thought was right.
"No good deed goes unpunished"
Instead of just close/lock the door for my neighbor or call the cop, I use a bulldozer to level the house to the ground. (zero out the flash.)
In theory, the "vigilante" can offer his service to device manufacturer to help remotely clean/update the devices instead of just simply wiping them off the net.
EDIT* I agree with the bulldozer analogy.
While you have raised some valid issues, this is not one of them. Having an unsecured device on the internet has some very definite adverse side-effects.
This is where your analogy breaks. Who is your neighbor on the internet? The most logical answer I have is "Everyone with a public IP".
Next, who is the internet police? Sorry folks, there isn't one. If my neighbors house is open, I would call the cops for two reasons. First I don't want to see their stuff damaged. But also, it creates a public nuisance. Some variant of criminals (say drug users or stupid teens) could take up residence in their house, possibly even burning it down, which would make it a direct threat to me.
And that's the problem with our current internet police. They will gladly try to arrest you for breaking into someones house. But they will not bust the 100,000 houses that leave their front door open inviting crime into the neighborhood.
I'd say you are changing topics. The topic at hand is about devices that are designed to be insecure, because the involved parties just don't care. The manufacturer KNOWS yet doesn't care because the issue doesn't cause him any harm, and the user just doesn't know.
We are talking about devices that willingly expose themselves to the internet (oftentimes without any valid reason to), that are all factory-setup with the same credentials (and no must-change on first use policy), etc.. This is just malpractice, not 0-day vulnerabilities.
Bottom line, vigilantism has a cost and picking and choosing morality of ideals based on your sole opinion is neither appropriate or legal. laws exist for a reason.
I don't really see in this case how they (or mostly anyone) is unable to improve IoT (or general) security through other means or that the consequences of the actions themselves are any different from other forms of attacks on software (like credit card fraud, denial of service or ransomware).
The arguments from the "hacker" gets especially weak when they conclude that consequences of breaking IoT devices is worthwhile, but the consequences of IoT devices breaking the Internet doesn't have the same effects. Even though you could argue that it's far harder for most people to influence overall Internet security than IoT security and therefor the moral arguments for breaking the Internet as a way of improving it should be slightly easier to make.
Really? How about you show me the evidence that people are... through "other means"... improving IOT security of these devices enough that DDOS isn't a big problem any more. I'd love to hear what you've done to convince all the vendors to focus on secure devices instead of profit when targeting markets that will deliver profit regardless of security. Most of us in INFOSEC haven't been able to convince much past a subset of software and hardware developers to focus on improving security.
The only time vendors ever delivered secure or safe solutions was when sound regulations were forced on them with a requirement they were followed before a purchase was made. That was TCSEC and DO-178B respectively.
Altough i wonder: why didn't someone with deep security expertise, maybe ARM with it's mbed,created something developers can't harm, and on the other hand, issue a product label saying:"this is protected by our stack..." ?
I could see that be attractive to some b2b buyers, attracting devs, further strengthening the value of said label , increasing marketshare and reducing costs, and creating a positive feedback.