For all those reasons and more the IoT stuff on my local network goes into a VLAN that only gets to see the gateway and nothing else. No local UDP, TCP or the like, the Ubiquiti gear I picked up a while back makes it pretty trivial to setup.
[1] https://en.wikipedia.org/wiki/Principle_of_least_privilege
I'm in no way a security/network export and I'm sure the people who came up with the current specs were smart people doing their best but it always seems a bit shit to me. I can send death packets to any device even if I'm not attached to the network and they're just honoured? Really? Was all this stuff created in a time when nobody actually considered bad people?
Yes. The Internet was designed in times where the primary worries were a) nuclear attacks causing major disruptions in the infrastructure, and b) pranksters. You can see that in the design of protocols, which assume all actors are participating in good faith. A lot of pieces of the Internet we still use were created for research community, where the default assumption was that everyone is acting benevolent (and if someone wasn't, they could be found and punished quickly through out-of-band means). I don't think anyone back then could ever imagine the amount of clueless, careless and evil people the commercialization of the Internet would bring to the network.
Tangentially, this is also why we're stuck with programming in environments subpar compared to what we had in the 70s. The level of control people had over their OS and software also implied total lack of security.
Sure, IoT devices are created today. But they follow defaults (which are insecure), because IoT vendors are cheap.
Maybe. But if we do, I'd love if there were allowances in the new design for creating isles where everything flies, and security is very low. I have two reasons for that:
One, security is - to some extent - mutually exclusive with capabilities. When everything is sandboxed and end-to-end encrypted, I can't inspect what a piece of software is doing, and I can't write code to make that piece of software do what I want. This flexibility is needed to make one's workflow efficient, and one's problems solvable (at least without waiting for someone else to solve them).
Two, hardening security has the distinct tendency for enabling vendor overreach and lock-in. The same techniques that secure your data from evil third parties can be used to secure "your" programs from you.
Edit: disclaimer: I work for Google, but my only contact with the home ecosystem is having a Chromecast.
I guess basic rules could be setup, but would there be a higher level way for that kind of orchestration
Incidentally it's concerns such as those raised in the article that drove my decision to use zigbee or z-wave devices for my HA setup where possible.
Not if the other devices on your network don't accept unauthenticated commands from anywhere. Which would seem like a pretty basic security feature.
The principle of least privilege, as a sibling pointed out, is important here because it sets the expectations of what a secure IoT device looks like. If we don't nip it in the bud now, this sort of lax security will become prolific even when more important information is at stake.
Google should be leading the pack on 'the right way' to do security on IoT. They know better.
If they can do that (minus the piracy warnings) without further interaction/firewalls being turned off, that’s an indication of more problems, not an indication that whatever the article is about isn’t a problem. You act like people getting on an average home network is unthinkable, but it happens all the time with visitors, weak passwords, broken wireless protocols….
You forgot one though, they might also be able to delete your MongoDB collections :)
OK, so printers aren't that mysterious. I can operate a CUPS server and whatnot. But I just can't muster enough concern to figure out how to access the network settings on my printer, and I'd be willing to wager I either need to boot into Windows, connect it to LAN, or both, to actually do this.
I would certainly be having a good look at those settings if that thing was connected to my network.
https://www.securityforrealpeople.com/2016/04/arris-motorola...
If you have access to the login page (and until recently, it was also available via WAN) you could do all fancy tricks by putting the right commands in the password field, including bricking the equipment itself.
[1] https://github.com/Nimayer/fastgate-toolkit/wiki/Get-a-root-...
People tried to contact the ISP and got no response back, of course.
As far as the local network, I think it can be assumed it’s insecure if you’re using any IoT devices. If not, then you might be able to trust it.
As I was touring this home of the future, there was a hack of the smarthome servers. And then it appeared--goatse. Goatse everywhere. On every wall, every cupboard front, every countertop, scaled to cover the entire surface, was goatse. It was horrible.
So much for the home of the future. Now you know why I distrust smarthome technology.
Given that most houses in most Western capital cities now cost millions and given that you can buy LCD panels for approximately the same price as bricks (for the same wall area) I do wonder why millionaires still stick with bricks. You could build a steel framed building and make all the walls, floors and ceilings from LCD panels saving yourself from having to have lights, pictures and regular TVs. With a few solar panels on the roof the electricity bill should be affordable too.
My imagination for this extended to having live scenes from the seaside to have an immersive view of sunnier climes. Your imagination went to goatse though, maybe your fears and browsing habits informed your dreams differently to mine.
This is _clearly_ the user's fault yes.
No, because Windows domain group membership is required (your uninformed amateur setup might be different).
> deleting all your Redis tables and Elastic Search indexes
Don't you think that development tools that are used by (supposed) professionals have different requirements regarding out-of-the-box default behavior than a consumer product?