A Teenager's IoT worm is bricking thousands of devices
zdnet.com
zdnet.com
Consumer devices and gadgets are not my main concern. Internet connected building automation is in similar sorry state. Someone will do large scale apartment automation systems attack, maybe just single manufacturer is targeted and as a result 5-15% of apartments go nuts at once. Just messing with the air conditioning can kill old and sick people until things get fixed.
The grid is able to cope with fluctuations in demand, but that's a totally different ballgame than switching massive loads on and off, synchronized to within something like 20 milliseconds (a single 50 Hz cycle), in a controlled, intentional and malicious way - and potentially worse, the attacker could observe the grid and react to the countermeasures (e.g. to detect how quickly the grid reacts, and trigger oscillations in some system never designed to deal with something like that).
I'd prefer to see ISPs/governments taking action against dangerous IoT devices in their network (sending probes to vulnerable devices and blocking Internet access until the owners of the devices have secured their shit or provide proof of running a honeypot). We can't really expect such measures from companies right now, but a tool like Brickerbot might kickstart a movement.
I'd prefer the bot to just change the password and disable vulnerable services though (which still might brick devices if their web servers are vulnerable). Still, I do believe that why device fallen to Brickerbot would have fallen to any other botnet within days anyway, so the botnet is not inherently bad in my opinion.
This problem should stary disappearing as soon as legislation is introduced by governments to make the parties producing software or hardware responsible for the stuff they dump on the open market. Until then, steps have to be taken to stop DDoS attacks as they are getting worse and worse.
Do you know of a country where this is true? I know there are some broadly worded laws in England against the use of "hacking tools" but there are so many legitimate uses of port scanning that it'd be hard to explain why a port scanner is any more of a hacker tool than traceroute is.
I'm not sure if there's even been a case to test it though, and as the general population becomes more tech savvy it seems unlikely such a conviction would be made for port scanning on it's own.
AKA the plausible end of open source. Once writing any program and sharing it can get you sued, people will stop doing that.
Such legislation should not be there to allow (class action) lawsuits but should be upheld by a government body, responding to complaints from the general public.
Problems with open source can also be solved by requiring companies who do not wish to take responsibility to give users to either sign a waiver (explicit, no TOS bullshit) or return the product immediately in exchange for money back. With open source software, there is no money given, so no problem. With closes source software, this highlights the vendor's behaviour regarding security support and might make consumers think twice before going with certain vendors.
Another way to do this would be to require vendors to put a clearly visible, standardised sticker/tag/image on their products detailing the support life cycle (warranty / software updates / security updates), similar to the nutrition information found on many food products. That way, consumers can shop around or hold a company responsible of their smart thermostat suddenly stops working because the company behind it got bought out by Google.
There are tons of variations of bases for legislation, but I don't see why physical and digital goods are that different.
If my CCTV system short cirtcuits and causes a fire, the company behind it can be held responsible for mot recalling the decices if the flaw was well known. If my CCTV camera has a known flaw that let's hackers in without authentication to record my alarm code so that they can break in, suddenly we're in the wild west of software support where you're on your own. Why is there such a difference?
In the US and UK (and I expect most countries) you don't need to charge for a product to be sued when it fails.
Also, it's not about making wi-fi light bulbs cost thousands of dollars, but if yours were on the cheap end, they are most likely garbage products with highly intentional planned obsolescence, and subsidized by data collection app you have to install, which is the whole point of making them in the first place. If such business model were to become unprofitable, I believe it would be a great win for the society (and the environment).
--
[0] - https://www.theguardian.com/science/2018/nov/26/uk-firm-sold...
Why can't products have a "declaration of security", like they have for EMI compatibility, safety standards and other such things? Declare that the manufacturer has taken reasonable steps to make the device secure and is liable for damage if that turns out to be untrue.
No, it isn't
>"This device has no security holes" is often not provable even if they try to secure it.
That's not how security compliance is determined
Just as is done with HIPAA compliance, NIST compliance, etc. there would be a framework of security controls that need to be adhered to
The hope would be that the former leads to the latter. "Making companies liable for doing a shoddy job" is rarely a thing that happens on its own, without pressure from below that's usually a reaction to incidents that hurt people.
When I first heard about it I was pretty dubious given government's track record on regulating technology, but its actually a really solid document, covering 13 guidelines which are specific enough to be useful, while not going deep into technical detail which will go out of date:
1. No default passwords
2. Implement a vulnerability disclosure policy
3. Keep software updated
4. Securely store credentials and security-sensitive data
5. Communicate securely
6. Minimise exposed attack surfaces
7. Ensure software integrity (this is probably my least favourite guideline, as it basically says you should check signatures on all firmware, by extension shutting down people's ability to control their own hardware with custom firmware)
8. Ensure that personal data is protected
9. Make systems resilient to outages
10. Monitor system telemetry data
11. Make it easy for consumers to delete personal data
12. Make installation and maintenance of devices easy
13. Validate input data
[1] (PDF) https://assets.publishing.service.gov.uk/government/uploads/...
WRT. 7, forcing secure boot is an overkill and pretty anticonsumer, IMO. There really needs to be a provision allowing for user-initiated software changes. If you're from UK, please let them know via e-mail to: securebydesign@culture.gov.uk.
I was worried about 10 (I don't really like the vendor collecting any telemetry on my IoT devices), but the actual document is more reasonable than the headline makes it sound - it's "if you're collecting telemetry - and keep in mind point 8 - then monitor it for security anomalies".
I sent them the following e-mail:
Hello,
I recently discovered your Code of Practice for Consumer IoT Security. After reading through the entire PDF, I'd like to commend you. It's a great document, and a great initiative - nicely striding the line of being specific enough to make a difference, while not constraining manufacturers and service providers too much in technology and business model choices. It's great that such a good document is taking lead on this issue.
That said, I'd like to strongly object to the point 7, "Ensure software integrity", in its current form. I strongly believe this would have a negative impact on both consumers and IoT security.
As a tinkerer (or "maker") and a leader in a community of tinkerers, I value the right and ability to flash alternative software on devices I own; software both made by myself and sourced from the world of Free/Open Source developers. It's what enables people like me to derive more value from our purchases, to innovate by experimenting with them, and most importantly - to help our families, friends and random strangers with less interest in technological minutea to derive more value from their own devices, including extending their usable lifetime way past the end of manufacturer's support.
Secure boot would prevent all of that, by removing the ability of end-users to modify software on devices they own. This goes against both the interests of end-users, IoT security and society at large for many reasons, including the following:
- Software provided on IoT devices is typically closed-source. Homegrown/community software is almost universally open-source, which means many more skilled professionals took a look at the code to ensure it is secure against attacks and does not secretly siphon off data, personal or otherwise.
- The ability to flash your own software means the IoT device lifetime is no longer determined by the lifetime of its manufacturers. When the original vendor decides to EOL the device, the community of users can still continue to provide timely security updates and feature improvements.
- Extending the lifetime of devices through the ability to install custom software also means the devices take longer before they end up on a landfill, thus reducing their environmental impact.
I kindly ask you to please reconsider the point 7 of your document. While its intentions are noble, its particular form is, in my opinion, counterproductive to the overall goals of the document. Please help create a future in which companies minding their users' interests can thrive, in symbiosis with a healthy community of tinkerers.
Regards, Jacek Złydach
More cynicism says that it will require IoT devices to be closed source in order to get a signature, and require government access and audit on running devices (to confirm integrity.) That may secretly be the backdoor clause. I'm probably wrong, but the UK government is fully committed to total surveillance, and the opposition either has no position or tacitly supports it.
If manufacturers would like to add some signature checking chip they can allready do that.
I wouldn't be too cynical, unless they make it illegal to modify the firmware.
No airplanes required. Just make flying cars.
Because its a moving target. A light switch that isn't going to burn my house down when I buy it will still be safe in 10 or 20 years. A "secure" piece of software of even minimal complexity almost certainly has many severe bugs yet to be discovered.
I worry that the effect of legislation like this would mean you could no longer buy a $25 router to hack around with or put OpenWRT on - the legal liability would make such products non-viable, leaving only expensive enterprise grade stuff for purchase. Maybe that's for the greater good in the long run, but it would still be something of a loss.
It's a bit like guerilla pot hole repair crews: https://www.citylab.com/equity/2017/03/portland-anarchists-w...
Worked in a bug bounty program for a spell, there are some young folks out there with borderline scary levels of talent and tenacity. Making this about the age of the person doesn't really add anything. (This is coming from a relative dinosaur, so maybe I'm just age-sensitive haha)
The 'S" in 'IoT' stands for 'Security'
Alas, I do not remember whose comment was that.Not that I condone destroying people's property to accomplish that, but at least there is a potential upside.
I recently read the Shockwave Rider [1] in which the word 'worm' was first coined, thanks to the discussion on HN [2] on Stand on Zanzibar. Can recommend both books for those into SciFi and would like to thank the community.
[1] https://en.wikipedia.org/wiki/The_Shockwave_Rider [2] https://news.ycombinator.com/item?id=19879830
And that 14-year old is living in Europe, not Iran.
Please leave the propaganda out of your tech news, zdnet.
Anyway, my immediate thought (before the article got to the teen) was that this attack might have be spillover from an attack by the US on Iranian systems. Or at least an hint at how exposed Iran's digital infrastructure might be to future attack from the US in light of recent events. Or maybe how this will get Iran to tighten up it's digital infrastructure before such an attack from the US could happen.
I also immediately didn't think that the origin of Cashdollar's attack had anything to do with the origin of the creator or perpetrator.
But maybe like me they turn on a VPN and are now operating out of "China" or "Turkey" or, gasp, "San Francisco".
I think SF would be a good look to potential investors.
Probably just a typo but in case not: interpreted.
I'm the ZDNet reporter who wrote the story.
What in God's green earth are you talking about?
The article says the hacker's server is rented from an Iranian company. And yes, despite your ignorant claims, the IP address is the C2 server.
What imagined propaganda are you talking about?
I read the article a few times and I don't think there is any anti-Iran sentiment in it at all.
So yeah, factually correct maybe, but very biased by selective editing. That's textbook propaganda. If you don't see that you're part of it.
I agree that IoT is a real problem, and I fear people will realize too late, with an accident or something, but this kid should have known better, depending in how it unfolds he could be in trouble.
basically its like knowing a computers root password with remote access apparently from anywhere. it looks pretty simple but effective and many iot devices are known for their lack of or lacking in security measures.
If otoh you brick the device in a way that requires flashing via jtag and suddenly have hundreds of people all over the country return their broken webcam to WalMart you make a little more impact. The thing is, it would have to keep happening for stores to start noticing a pattern and start caring. If it was a one time thing it might be cheaper for then to just throw them in the trash and hand out new ones or refund.
And... more trash. Ugh
Maybe people who set the same password on the whole fleet and don't make the user override it?
Come on, you can't take the responsibility from well-paid incompetent professionals and put it on a teenager from a third-world country.
My IoT devices are on my network but you would need to get yourself inside my network to talk to them. I'm not exposing ports for my lights...
One of the selling points of things like smart thermostats is the you can remotely control them; you can set them to your preferred temperature as you are traveling home so it will be nice when you arrive.
>The BrickerBot author argued that it would be better if the devices were destroyed, rather than sit around as cannon fodder for DDoS botnets, and haunting the internet for years.
... yea, broadly I'd agree. IoT vendors are causing a tragedy of the commons, inflicting quite a lot of damage without feeling any of the pain because it hits others.
It's the sort of thing that should be addressed by legislation of some kind, but absent that (which includes nearly all international cases)... what else can you do to stop the worst offenders?
When appropriate measures have massively failed, what are the alternatives? Vigilante actions are one option, as is "watch the whole thing burn down", and probably an infinite variety of stuff in the middle and along different axes. What's your preferred option?
edit: also, it's not quite "may [do] something worse". Insecure IoT things are used as botnets. Frequently. It's not a hypothetical threat at all, it's just a question of scale / frequency.
So, in a way, yes. I do. So do lots of people when they go to urgent care rather than the ER, knowing that the ER could bankrupt them, and they'd rather risk the delay. I don't have numbers off the top of my head, but I don't think it's as uncommon as you seem to think it is.
I daresay that this situation even applies to "most people", or at least a very sizeable proportion of the global workforce.
You are priced per body part based on your income. Your health is most certainly defined in dollars.
So, vigilantees concerned about damage to innocent people keep breaking into the windows, stealing the guns, unloading them, and tossing them into landfills. I'd be like: "Stop putting your guns in front of the windows. Be a responsible gun owner." Enough broken windows and stolen guns might incentivize them to do that.
It's IMO somewhat comparable to culling high-risk farm animals to prevent widespread disease outbreaks.
Where do you have legal authority to do a vigilante culling of your neighbor’s herd, because you decided something about them merited it?
> Where do you have legal authority to do a vigilante culling of your neighbor’s herd, because you decided something about them merited it?
I am not making the argument that this is legally defensible. You can by definition not have legal authority to engage in vigilantism. It's from an ethical and practical perspective that I draw the analogy.
On the matter of legality, the difference you point out applies, but also goes both ways. There is no legal framework around "culling" insecure devices, and very little regulation.
Let's hope this forces manufacturers to improve their security. That's the main good that needs to come out of this.
They have generally had mixed success, from the ones I've read about. Pretty often there are side effects that aren't good (e.g. bricking some devices, excess traffic due to being too successful, that kind of thing)
But yea, in this case I think it's clearly too complex. There are thousands of different things hooked up to the internet, and you can't fix all of them at once.
You'd need a JTAG cable and a fresh firmware image to fix that. Hardly something within the reach of a typical home user.
If they wait too long, then the result is more sales, which increases profit for the whole ecosystem that produces these devices. But if it's more common and results in returns and exchanges, the result is less profit, which might finally put some pressure where it needs to be.
It's an interesting problem in that the value of hackale/wormable IoT devices stems from their sheer number. In a way the culpability of any singular vendor for any singular sale is low by and of itself; it's only large in aggregate of all the vendors' products ever sold & still deployed.
This is a reverse of, but comparable to, the low value of personal data being gathered&processed (or stolen) - for every singular individual, the value/loss is exceedingly low. The value lies in the aggregate of the data; the whole is much more than the sum of its parts. Thus the prosecution of things like the Equifax hack, or the insecure IoT devices is pretty spotty at best.
Perhaps we need a new, specialized legislation & judiciary for cases where network effects dominate.
That said, I agree there's a sort-of similar pattern here, which I feel underlies many of the biggest problems of our era - including climate change. The pattern is that there's a lot of entities - individual, small and large companies - engaging in transactions, and each transaction has a small negative - some personal data stolen here, some toaster joining the botnet there, some trivial amount of carbon emitted elsewhere. The negatives however add up, and ultimately manifest as huge and international problems.
We definitely need to develop legislative methods that would combat this pattern at the structural level, regardless of the business domain it shows itself in.
That doesn't entirely match the current situation, but there probably is a some responsibility that lays with consumers for buying crappy devices from companies with no track record for keeping them updated. It's not always simple to reason about, but it is something to consider next time there's a decision to buy some cheaper device from some no name company or from some well known company (that hopefully has some sort of support lifetime at least).
The thing missing is somebody to define that severe security vulnerability is considered as a defect in the product. Once this is done, consumers can either demand the seller to fix the problem, replace product or give refund. This should pretty quickly create a financial incentive to sell products which get updates.
Still, yea, this is exactly the kind of thing that needs to become commonplace. Hopefully it will be, though this is far from the first time that something like this has happened and here we still are.
Still, even just the fact that companies are now thinking about this and providing ways to download/delete your data makes me love the GDPR.
Easy to do the same thing here, as long as the company has (and wants to keep having) presence in the EU that's enough to enforce standards worldwide.
It would be just the question of somebody testing it. Take a relatively new() device with unpatched security hole, try to get it replaced/refunded and if necessary proceed to court to get a decision on the matter.
Although I wonder if any vendor actually wants to go to court arguing that a product with severe security issue is actually working as intended.
() Safe bet should be a device purchased less than 2 years ago, since that seems to be the time the vendor is at least responsible for defects.
Or an incentive not to sell in Europe.
Of course that doesn't fix the global problem.