Two Billion Records Exposed in 'Smart Home' Breach
secalerts.co
secalerts.co
As mentioned by others, I guess it really needs severe identity theft/abuse with vital services until people realize that today‘s IoT 'plug & play' is worse than than the level of 'plug & pray' we‘ve seen in the early PCI/USB/Win98 era (that only impacted your local device functionality).
I also DONT want those devices to be able to connect to the internet: I have a D-Link webcam that has (had?) some issues around being exploitable remotely via the MyDLink or whatever it‘s called service. I don’t want to have (more) devices sitting in my network that open it up from the inside.
Also I need my guests should be able to access the internet without me having to whitelist their MAC address.
If you do need low cost VLAN-capable gear I've had success with TP-Link switches and Mikrotik WiFi APs.
Like the "offer a guest network" button which, now I think of it, might already be enough.
It takes some work to get going, but it's amazing. Cheaper (no need to buy all those different hubs), more flexible (you can use node-red or any programming language to do exactly what you want), and way more secure (nothing leaves your home network unless you want it to).
It‘s mostly a blend of many different tutorials/blog posts/forums on hostapd, raspbian, dnsmasq and the likes.
I took notes during both times when I set this up (first time the sdcard died shortly after, no backup of sorts; second time some changes in drivers, raspbian lite and other tooling were different so I had to start over).
I thought this project would make a good first blog post, maybe I can gist some steps / bullet points next week or so.
I also do run HomeKit, homebridge but devices/hubs are in the dedicated network.
That's not even really 'exposed in breach', that's just 'exposed'.
It's like saying "someone stole my keys ... and if that wasn't bad enough they got the key ring!"
I completely agree that it doesn't make it less secure, but it does make it more.. 'oh come on'. I mean, nobody who was using it legitimately realised?
It's like installing a mysql db and leaving the root password blank because "welp it's the default config".
But they usually don't want to. It usually goes like that: we need some internal tool to do stats. All our people are busy on other projects. Let's get an intern to do that.
(FWIW I don't have any IoT devices in my house)
The problem is neither IoT nor ES - whoever built this just didn't bother to implement even basic security.
I'm not into the whole IoT thing but if I really had a need to control something from anywhere on the Internet, it would not rely on a centralised third-party service.
And this article had been published today... The database had been closed a day later on July 2.
Here the the original report instead of a Forbes article: https://www.vpnmentor.com/blog/report-orvibo-leak/
I was an victim of this recently when I got reports that my web app was down and when I investigated it I saw there was a password on redis preventing the app from connecting. I then found out the redis docker container was accepting connections from the outer internet with no password and someone had connected in and set a password on it (Probably just to alert me to the fact it was exposed). Thankfully there was basically nothing in redis so no user data was exposed.
Mark my words, eventually the world is going to see some sort of Fukushima scale internet of shit disaster caused by poor security/architecture. I'm not sure what form it will take, maybe mass pwnage of a device as commonplace as Amazon echo or Google home, but it will be bad.
If used by government actors, I imagine they'd use it every opportunity they could.
At the same time, IoT devices are being sold by companies who think that a 10 years support cycle is "a long time" and who frequently will drop support for devices when new models are released. The same companies often have terrible models for customer support.
I was at a presentation of Microsofts Azure Sphere OS. The presenter proudly proclaimed that they would have 10 year support cycle. Apparently I was the only one in the audience who felt that 10 years is at least 5 years short of what is needed.
I wish I were a hacker capable of such feats.
Or constantly toggling things that require power in sync, which would throw off the power grid system in some way.
Or making food rot in fridges.
Or randomly flashing lights on during night, interrupting people sleep.
There are many ways that some of those things can be statistically dangerous or life threatening at scale, either directly or by consequence.
</tinfoilhat>
Separately, I worry about smart devices that could be used to cause electrical fires, leaks, etc at scale. Triggering many devices in a target area to do some activity that sparks even small fires allows you a decent chance of creating large fires fairly easily without a single troop hitting the ground or firing a single bullet. With the impact we saw from the Camp Fire, the government's current... issues... Etc., that's terrifying.
[1] https://www.vpnmentor.com/blog/report-millions-homes-exposed... [2] https://www.vpnmentor.com/blog/report-theta360-leak/ [3] https://www.shodan.io/
If you're researching internet-facing setups of anything, shodan is an excellent resource. You'll still have to actually investigate and sample the data from the discovered locations, but that's where even rudimentary tooling comes along.
Would things meaningfully become more secure if we had a legal framework under which the information in the database belonged to each consumer? Or would a simple click-through license make that moot?
For instance, all my lights are controlled using IKEA's TRÅDFRI solution. Also, they are integrated into my own HomeAssistant instance (dockerized), which runs on my Unraid machine, which also hosts my data shares. Then we have FireTV's, Echo's, we have a Xiaomi vacuum robot, and so on. The FireTV should be able to access the data shares for playing back movies. Alexa can control our lights, too.
I'm still struggeling to find a "one size fits all" solution.
You would restrict/allow certain ports between VLANs, only allowing the port traffic you want.
Make sure the devices cannot see things in the physical world that you do not want to leak. Do not point a networked camera onto your sleeping room if you don’t want others to see inside.
Then, take effort so the devices that need to reach the devices that contain your own data are only allowed access you choose. A set top box may need to read your movies but does not need write access. It does not need unfettered access to your home network. You may be able to grant it access your shares but not the internet.
And buy reputable stuff, although the S in IoT is for security and that goes for all devices, some get more support and care than others.
https://www.vpnmentor.com/blog/report-orvibo-leak/
Which was posted a few days ago.
I hope Elastic makes it more difficult to make your cluster public by default in future versions.
[1] https://www.elastic.co/guide/en/elasticsearch/reference/curr...
(just to pick an example I'm familiar with).
;)
I did not explicitly say I would prefer neither to happen, but I wrongly assumed that would not be necessary to write, my apologies.