Internet Chemotherapy
ghostbin.com
ghostbin.com
It all seems to start and end with technical ignorance of the typical customer. There are popular shows that help pepople choose better food, by exposing shenanigans food makers engage in. Perhaps there could be something similar for tech in the future. Something where a hacker comes on TV and makes a total ridicule of some IoT crap device, and the show uses it to constatntly repeats the basics, like changing default credentials, etc. Same schema that works with food shows, expose someone as an example and add some generally useful advice. Perhaps this might become feasible when IoT is more popular.
Masked comic book vigilantes aren't ever going to be a reality on the mean non-virtual streets of cities but on the Internet it seems we're confronted with something pretty much equivalent.
So here can consult all the old issue of Marvel and DC for a compendium of moral dilemmas and result.
Unbelievably, this is actually the case in Seattle.
Or maybe a bunch of actual researchers and government agencies working without praise while someone else writes a sensational story to take all of the credit. And the people believe it on the merits of it being the story they want to be true.
I can only see it as a win-win. Except the internet connected medical devices that are insecure which if affected by such purging bots would literally impact lives. I hope vigilante script kiddies don't get involved with good intent and cause havoc.
Victor Gevers is cited by Bleeping computer (https://www.bleepingcomputer.com/news/security/brickerbot-au...) as saying there are better ways of solving the problem than forcibly disabling/bricking devices. I'm curious what those are, though, since IoT manufacturers (speaking broadly) don't seem motivated right now to take even basic security precautions with their devices. I know some groups use sinkholes to redirect compromised devices, but while that can be useful for research it doesn't seem like it has the same motivational impact for change.
I see the normal manufacturers/sellers responsibility as the only good answer to the problem. I don't like solutions involving fines or large liabilities, because these can create wrong incentives to people/companies.
Doing security properly for these devices is not very expensive compared to scale they are being sold. Therefore I think simple things like increased return/warranty repair rates should provide enough incentive to focus on security.
Making manufacturers liable for incidental damage their devices do sends the message that they should avoid such damages as far as possible. That seems like a good message to me.
If device $20 device X does $20,000 damage to the hospital down the road, the fact that the consumer can return the device seems woefully insufficient.
If it were able to do that, then presumably that $20 device had eg a good amount of explosive in it, and therefore would be in no condition to return it to the store.
Unless you're alluding to that $20 device being used as a communications proxy, under a mistaken idea that the Internet has some concept of node trust. In reality, the hospitals $20k "damage" would be due to its own developers' negligence and demands for compensation should be placed squarely at the door of its suppliers and integrators.
What I did imply is that if I develop a device and put it on my network, then I'm essentially responsible for whatever damage it causes. Eg wiring a RPi to a heating element that will start a fire if left on continuously is a poor idea, regardless if the proximate cause is a cosmic ray bit flip or malevolent Internet noise.
'Cause certainly random average-consumer should know how dangerous adding crap to their network can be ... for others ... and certainly he/she is capable of making provisions for this.
Fortunately, modern legal theory actually does consider "who are talking about here, what can expected of them." in cases like this. Hospitals could theoretically sue IoT manufacturer on this as far my ianal knowledge goes and it's more that the manufacturers are distant cheap factories in China that prevents this.
Erm, no - the exact opposite. The consumer should look at the camera's manufacturer for their own connection being swamped, incurring overage charges, etc. In your scenario, if the hospital's only problem is that their Internet uplink is swamped, then they should be looking at their link provider for robust upstream shaping, etc. In the case of a simple traffic overload, nothing critical at the hospital should be affected because critical traffic should be segmented, or at least prioritized, over traffic from arbitrary endpoints. If there is more of an affect, then that is due to a further vulnerability that belongs to the hospital!
I referenced the hospital's developers/suppliers for these further vulnerabilities - in those cases they should be looking at their network admins, or at the creators of the failing (defective) equipment. The crux of the End to End principle (ie the Internet) is that edge nodes have the intelligence, and thus requirement/responsibility, for discerning "good" traffic from "bad". And (as I said) coming at it from the other direction, general robust engineering principle dictates that physical devices "fail safe" no matter what noise is presented at their network ports.
Not sure that's true. I did a 18 month stint with a tiny (6 person) hardware startup - most of my time was spent ensuring our devices could auto-update their embedded Linux securely without bricking or losing any of the custom hardware specific capabilities. It's not an easy trick to pull off (big thanks to the ARCH Linux team for all their work that I built on), and there's ongoing cost involved to ensure newly discovered vulnerabilities have a process to be evaluated, patched, tested, and deployed to the fleet of devices.
Vulnerabilities and updates are inevitable, but the current volume of them is not, by orders of magnitude.
The volume of serious exploits could be reduced dramatically if we started to more seriously apply the principle of least authority (and an important technique and way of thinking about that is capability security -- in fact an important technique to make 'brickless updates' easier to achieve too, I suspect).
I think how to kick-start the industry to actually do that is a difficult problem.
edit- The main objective, of course, being allowing unattended atomic updates with as low a risk of bricking the device as possible. Usually these devices will be updating the whole root filesystem at a time, which is otherwise read-only. Ideally this is also done with as little downtime as possible. There is some work in this space in standardizing a solution, but it isn't really there yet, so it tends to get home-grown for each product.
(Source: I was the platform security guy for an IoT startup in 2013/14, for a company who no longer exists and who's only product run is still out there somewhere no longer getting security updates...)
And if I couldn't fix it or had no clue what any of these terms meant I should pay somebody to fix it for me. (No referrals)
:|
Would the intel community really need a botnet like this to operate?
Many of them are from Chinese companies and are being sold throughout Southeast Asia and South America.
"Paras Jha, Dalton Norman and Josiah were also a part of this normal Minecraft server entrepreneur game until they decided to force players from other servers on to theirs by clogging their networks. Therefore, Mirai came into existence and started performing for them very well. However, Mirai started outperforming the creator’s expectations, affecting the Internet outside Minecraft badly."
"The creators of Mirai found potential in the botnet and therefore went on to fine-tune it to improve its abilities. They even started leasing Mirai to other cybercriminals, who used them around the world for their own vested interests."
https://en.wikipedia.org/wiki/Mirai_(malware)
"Upon infection Mirai will identify "competing" malware and remove them from memory and block remote administration ports."
From an evolutionary perspective its an interesting example of 'fitness'
As humans fought fires, there was a buildup of flammable material in the forests, making each successive fire incrementally worse.
There is no such organization for the internet. So we are left with lone white-hats who risk personal safety to do some good. I wish there's a better way.
No good deed goes unpunished.
So, to tie it back to IoT: Would a 'controlled burn' (i.e. a bot which bricks vulnerable devices) only destroy the low hanging fruit (i.e easily exploitable devices) and leave the harder vulnerabilities in place, building up for the bigger fire in a years time?
0) Let it burn was how CA operated until we started fighting fires and building in unsafe spaces and it worked pretty well. The Thomas Fire is a good example of this problem. You can reduce the damage but there still will be damage.
1) Legal issues if you are detected and someone wants to "make an example" to be malicious doing this, even if you are found "not guilty" the consequences are non-negligible.
2) In any capitalist culture, prevention only becomes "cost effective" when multiple headline making disasters convince people in suits they will look like idiots if they don't pay at least lip service to prevention.
3) If a criminal ever figures out who you are and that you are invalidating their large $$ investment in a criminal attack, they may be willing to engage in criminal acts to stop you specifically and you don't have the legal protection and training a LE organization would have.
https://krebsonsecurity.com/2017/02/men-who-sent-swat-team-h...
> It’s been a remarkable week for cyber justice. On Thursday, a Ukrainian man who hatched a plan in 2013 to send heroin to my home and then call the cops when the drugs arrived was sentenced to 41 months in prison for unrelated cybercrime charges.
If you aren't equipped to handle events like this, tangling with blackhats means a single opsec mistake is going to result in shit like that.
major internet disruption potentially larger than anything we've seen before, as in you and I and every single aspect of modern society that relies on the Internet (aka pretty much everything).
do you not see what will burn?
IoT being so hyped right now is specially troublesome since all they will care is time to market, and when the market is filled with insecure devices what else will there be to done?
It could also set up a pretty nice incentive structure. If a device is bricked due to a vulnerability, then the manufacturer should have to either repair or refund the device. Corporations will not respond properly until it impacts their bottom line.
Imagine the public backlash there would be if people knew that the government was scanning and hacking devices for the purpose of national security...
As backwards as it seems I think people like the story of a rogue hacker more than the government protecting them.
/s ?
If so, chortle chortle.
The one point I disagree with is blaming the consumer. The simple truth is that security protocols have terrible UX, and until that improves nothing will change. Personally, I think it's time IoT was regulated and, in particular, we require a secure protocol at the time of deployment: IoT devices must be provably wiped, and then put into physical contact with an "owning" device before deployment. This, in turn, requires that people start using what I call a "Home Brain", a device who's primary purpose is to coordinate and secure all other devices that you physically own. I imagine simple versions to be as sophisticated as a router, and hackers might want to put together their own, something like a little home theater box. I suppose in a pinch your smartphone could work, too.
The irony, if running code from a post from the Brickerbot author would brick your laptop...
Before anybody else sends me the “Internet Chemotherapy” link or retweets it - it appears to be a wonderful piece of fan fiction. Deutsche Telekom suspect was arrested earlier this year, key details wrong, TR069 modem stuff was bad implementions crashing devices etc.
(I haven't confirmed this myself)
There are political solutions for these problems, but nobody will vote for them.
There are social solutions for these problems, but nobody wants to take responsibility.
Personally I'm waiting for a power plant to explode after someone runs a fuzzer on the internet. And for the inevitable law making security research illegal. And propaganda claiming foreign nations or terrorist organizations instigated the attacks (instead of bored 14 year olds, the more likely cause) used to support new pointless wars. And the intellectually flaccid xenophobic public, clamoring for more jobs and Internet-dependent TVs, fervently supporting it.
But it could be worse.
Run just a single instance something like this [1] (which isn't even well optimized) and within minutes you'll find vulnerable devices. It shouldn't be that easy to build a botnet.
And, yes, it's just making basic HTTP requests on port 80 so it's overlooking tons of devices. But I run this from my own devices and doing blast scans of ports other than 80 can look a bit suspicious.
I'm sorry to leave you in these circumstances, but the threat to my own
safety is becoming too great to continue. I have made many enemies. If
you want to help look at the list of action items further up. Good luck.
This sounds scary - like it came straight out from a movieThe author can be deliberately mimicking style or going through translation in order to avoid this kind of analysis.
For what its worth, the name rang a bell and I found this: https://gizmodo.com/this-hacker-is-my-new-hero-1794630960
The writings seem similar, for what little thats worth.
> "The real point is that if somebody like me with no previous hacking background was able to do what I did, then somebody better than me could've done far worse things to the Internet in 2017."
One person.
Then again, he might not have a "hacking background" but might have a strong embedded/networking background so he knows where to look, considering how he found exploits that blackhats missed.
So either he's that good or blackhats are two-bit[0] criminals.
[0] No pun intended.
Chemotherapy is essentially controlled killing, to mitigate or prevent uncontrolled killing. Just like (as someone said elsewhere in this thread) controlled burning is done to mitigate or prevent uncontrolled burning. And here we have controlled hacking to mitigate uncontrolled hacking.
Society doesn't support anybody killing, burning, or hacking, unless there's a way to know and recognize, that the person knows what they're doing. Which (the knowing and the recognizing) is a credentialing problem. It's the only difference between (doctors, police, firefighters, cybersecurity experts) and (quacks, vigilantes, arsonists and some-unknown-hacker), respectively. A guy I don't recognize as a surgeon, is just a masked man coming at me with a knife, even if he actually is a surgeon.
If your intentions are good, you should take the trouble to get some kind of credentials, which can take many forms. (If your intentions are not-so-good then it makes a lot more sense to bypass that, but also for the public to put you in the "untrusted" basket.) This guy bypassed credentialing, and that places him in the realm of those who are not trusted no matter what kind of good they do. Now he can't continue. Instead of that, imagine there was a public debate about the relevant issues and this or a similar effort had actual public consensus and resources behind it.
Now of course I'll grant there are numerous problems with the political process and consensus-building and all the rest of it. It takes a long time to get anything done, and learning how to hack is actually the easy part. Good news: This is actually not the emergency he claims it is. What's the worst-case scenario, the whole internet goes down tomorrow? Well, it's only the internet. There are ways of getting food, water and shelter without using a network at all. Nobody has forgotten how to use pen & paper. Even blankets will still work without an internet. (Not if these IoT clowns have their way of course.) Whatever, don't listen to me, I'm older and I lived almost half my life quite happily in a world where nobody had the internet, yet still everything got done.
Anyway, the other thing is, a "state of emergency" is how all sorts of atrocities and shitty decisions are justified by governments, so it's not something to emulate. The attendant issues deserve to be publicly recognized, debated, decided and then tackled. Maybe it's wishful thinking to demand that much from people today.
1 day is an inconvenience
1 week is major hurdle but can be overcome
1 month and people may start being laid off because they can't do their jobs and clients are cancelling services that they can't use
Now how many people over-saturating an internetless job market will it take for food, water and shelter to become a problem is something to study.
This may be an exaggeration, but since we are considering worst case scenarios.
And credentials are merely a way to build consensus around what is due process and who can determine it. The net effect is the same, but the process for achieving it is without consensus. This is another example of no proper channels existing, and individuals taking matters into their own hands.
aka vigilantism. Sometimes it's required, but it signals that a proper channel should exist for such purposes.
Link's not working. Anyone got a copy?
edit: I would recommend extreme caution with that file. I'm still reading, but strings like this are worrying:
'busybox cat /dev/urandom >/dev/sda &''GET /cgi-bin/supervisor/CloudSetup.cgi?exefile=(cat%20/dev/urandom%20%3e/dev/mtdblock3%20%26);(cat%20/dev/urandom%20%3e/dev/mtdblock4%20%26);(cat%20/dev/urandom%20%3e/dev/mtdblock6%20%26);(cat%20/dev/urandom%20%3e/dev/sda2%20%26);((sleep%2017;route%20del%20default)%20%26) HTTP/1.0\r\nCookie: SSID=%%CUSTOM1%%\r\n\r\n'
I don't think the string is .. worrying on its own given that, you know, this thing is meant to kill IOT/etc devices that are insecure. I'd argue that just given the source (the internet) is enough reason to be wary.
What's up with all the stuff like "if 81 - 81: ..."? Won't that just evaluate to false and never run?
Frame it as ISP "conditioning" or as "criminal attack", fact of the matter is he committed crimes and now he's feeling the heat so he's putting out re-framed confessions to get the jump on his accusers and try to save his skin.
Then again, people can be more complicated than I give them credit for, and he might actually be a good hacker. It has happened before. I don't know. Let the investigators find out the truth. We have no reason to trust him.
Stopped reading there.
The same as the fact I did not lock my door do not allow anyone to rob my home, that I did not replace my fire detector batteries is no excuse for anyone to set it alight, etc.
To me good security starts by catching this guy and if he had done the damage he claims he had then make him pay for it.
Only when one had been hold accountable for what he has done should we go after companies for negligence, no?
"I discovered this security hole then proceeded to exploit it and damage some random system/workflow for the sake of demonstration" should not be acceptable.
First, let's fix your analogy: If you don't lock your door, this is generally not an issue for the general public, i.e. it doesn't impact anyone else negatively, just you in case you get robbed. A better analogy for this case here would be that you leave your door unlocked every day on purpose AND have a huge arsenal of guns, rifles, etc. right in your entrance room, all loaded up ready to be used. If I'd encounter that, the least I'd do is call the cops; the only problem here is that if I call the police telling them my neighbor Bob is running an insecure IoT device that can be used for DDoS attacks against anyone on this planet, they won't do shit. So if the police told me they don't care about your publicly accessible arsenal of weaponry then yes, I think it would be a good idea to try and prevent anyone from accessing it.
> Only when one had been hold accountable for what he has done should we go after companies for negligence, no?
That would mean we shouldn't punish anyone for putting individual people or the general public in danger unless something bad actually happenes. This is not true in other scopes too, there's a lot of things you can get fined/arrested for that don't actually hurt anyone but just have the potential to.
> "I discovered this security hole then proceeded to exploit it and damage some random system/workflow for the sake of demonstration" should not be acceptable.
My take on this: "I discovered this security hole that others were exploiting to DDoS other parties on the Internet, so I proceeded to exploit it too and damage some random system/workflow to prevent this abuse from continuing"
Still, I want to reiterate that the society I want to live in is not one where we are protected by perfect bulletproof fences but one where vandalism is not a cause of fame.
Your "lock my door" analogy is not complete. Imagine if you don't only don't lock your door, but also abandon your home, so criminals squat in there - and they end up terrorizing the whole neighborhood. Wouldn't it be logical for the police to at least barricade the place somehow? May be even fill doors and windows with cement, or take other measures to prevent squatting.
It would still make it unusable for you, and you'd have to renovate if you ever return - but many would argue that it's a reasonable way of preventing the damage to the whole community around you.
Imagine the following scenario: Manufacturer's sell weapons cabinets to people. Only weapons cabinets are not hidden in your home, instead they are put out on the street. And now comes the dangerous part: These weapon's cabinets do not lock. Because the manufacturer decided that locks are not necessary. If someone comes along, should he just ignore this or should he make the weapons unusable? Because that is what these devices will be used as: weapons.
In your analogy I would say its not that people are leaving these weapons cabinets on the street unlocked, but don't know that its possible to lock or hide them.
Another good example would be cars, if you went to the showroom and someone showed you a two cars, one with no locks on the door that was easy to start without the keys, and one that had proper security the choice would be easy and you could understand what you're seeing.
If you go to a shop and someone shows you two IOT devices that do the same thing, and look identical, you cant really see anything that helps you learn about the security features, and as an average person if you're told one has certain "tech speak" security words you don't understand are you really going to make the choice to spend more money to protect against something you don't fully understand, that you don't see any effect from?
Yes manufacturers should be made to release products that are secure and respond to security issues in a timely manner, but we also need to educate people that computers aren't some magical box beyond their understanding, blaming owners in these cases would I think make the issue worse.
If you consider that the majority of people who have the internet get their ISP to set up their router, and only have a basic understanding of what that device does, how can we expect people to understand what the potential issues of open ports or vulnerable firmware are? And then could these people even be educated to the level we would need for them to be responsible for securing their own devices?
It's more like discovering a remote-controlled car can be hacked and allow terrorists to drive it into crowds of people, and you have an option to brick such cars. I'd brick them all.
> Deutsche Telekom Mirai disruption in late November 2016. My hastily assembled initial TR069/64 payload only performed a 'route del default' [...]
AFAIK this is not what happened. Deutsche Telekom had one major incident on November 27th 2016, but that incident was caused by a denial of service attack [1]. Given that the routers in question don't even run Linux, 'route del default' is not really an option anyways, making the first claim of the story likely to be fabricated.
This seems to be a good fictitious story, but nothing else.
[1] https://comsecuris.com/blog/posts/were_900k_deutsche_telekom...