Hackers can infect network-connected wrenches to install ransomware
arstechnica.com
arstechnica.com
Because we need to track critical bolt rundowns (generically called fasteners) and tool condition.
That being said it doesn't need to be on the public internet, but it makes it a lot easier than setting up and managing a private network.
I'm not defending putting this tool on the public internet, but its very normal to put all kinds of stuff on the network in a manufacturing plant.
I'm sorry what? It's easier than setting up a portion of/separate LAN with no internet access? I mean, yes, in the strictest "lazy bastard" kind of way, sure. Can we not even ask that of businesses now?
Sure Bosch should've secured these things, that's a given and they should be rightly held to the fire to fix them. But also like... wifi routers have been a household staple piece of equipment since like.. 2008? Depending where you live? And we still can't ask business operators to do even the most basic due diligence in setting up their environment, or at the least, hiring someone who can?
This is like when you go to a restaurant and their access point is called Spectrum-Wifi-5G using WEP encryption with a password that's like, F8F023gX. Just well established that not a single fuck was given in doing this.
Have you ever worked in a manufacturing plant? Yes, the solution is TECHNICALLY very easy, but there's a bunch of gatekeepers that really slow things down.
The solution to the problem in front of you is always technically very easy and clear, but there are always a tremendous number of problems to be solved in a production manufacturing environment.
It's always the incentives. Always.
How many utterly mission critical e.g. CNC machines are run by a miraculously still functional Gateway desktop running Windows 98 Plus, camouflaged under a few decade's accumulation of rusty shavings from the nearby lathe?
And what difference would it make, anyway? In exchange for massively complicating every aspect of the monitoring and control tasks, you're just interposing the need to infect the battery firmware in order to pop the tool. Do you imagine the battery will be secure when the tool is not?
There are ways to solve the problem, it's just cheaper to make the tool an HTTP client and solve it on a server somewhere.
Updating the tool firmware, say - especially since with OTA updates unavailable for reason of the tool being forbidden to incorporate a radio, there's no other way to update the tool's firmware, not without complicating its design to expose a port rugged enough to survive the hard-knocks life an industrial tool is guaranteed to lead.
You might argue that this isn't worse than the current state of play - which would be true, but irrelevant, because in order to justify the massive cost and complication of this proposed design, you need to be able to show that the result is to a comparable extent better. You have yet to do that, and I doubt it can be done at all.
What are you on about? I'm arguing there were ways to solve the problem that didn't involve the tool connecting to the Internet. I don't need to show that my solution is better, because that has nothing to do with what I'm saying. And either way there's no "better" here. There's no objective measure of goodness. What's better to me and what's better to Bosch are not necessarily the same, and in fact they obviously aren't, as I never would have designed a tool this way, but then I don't have a tool manufacturing company.
You charge it once per shift, and you need an update every minute.
The dumb problem exists because of very real limitations.
Sorry sales team, your customer is dumb.
---
The previous step must be completed successfully before proceeding to the next step. A system records this information for posterity.
high precision factory gear in safety-critical applications seems like a reasonable use case to me.
Sometimes these sort of screwdrivers can drive other processes (e.g. once it confirms that the screw is correctly affixed, send a message to the manufacturing system to tick off that 'task' as complete at this station, and prompt the operative to start the next assembly task - the piece cannot move to the next manufacturing process until the screwdriver has confirmed all bolts are affixed at the right settings).
Which is why compromised USB thumb drives are a thing.
Air-gapping your OT network protects the average company from 99.99999% of threat actors. If you're attempting to create nuclear weapons and a western nation is trying to stop you, you're either going to be compromised or murdered. That doesn't mean Bob's metal stamping should put the IOT controllers for his steel presses onto the public internet.
How are you reconning what actual PLCs Bob is using? How do you know what versions are on those controllers? How do you even know the address of someone who works in a position that has physical access to the OT network in the first place?
I'm not using a logical fallacy, you're pretending that Stuxnet is applicable to the average business and it just isn't for a dozen reasons I can think of and probably 2 dozen I can't.
> And how are you planning on getting a USB drive from Russia onto an air-gapped steel press in the US?
Why does such an attack have to originate from Russia?
> you're pretending that Stuxnet is applicable to the average business
No, you have missed the point. Stuxnet shows that a USB attack can succeed even against a state actor. It does not show that a state actor is necessary to mount such an attack.
And you're basing this on what? All of the OT networks I deal with are physically secured. You're swiping a badge and being recorded before you get anywhere near the production floor.
>Why does such an attack have to originate from Russia?
Because someone in the US compromising an OT network with ransomware is going to prison for a LONNNNG with little to nothing to gain from it?
>No, you have missed the point. Stuxnet shows that a USB attack can succeed even against a state actor. It does not show that a state actor is necessary to mount such an attack.
Go ahead and link some of the OT environments you've seen compromised by USB drive in the US. I work in the industry, you're going to be searching a lonnnnnnnnnnnnnng time to produce more than about 2 and both the ones I'm aware of were insiders who were immediately caught.
My knowledge of what I could do as an employee if I were to go rogue.
> Because someone in the US compromising an OT network with ransomware is going to prison for a LONNNNG with little to nothing to gain from it?
If they were caught.
> Go ahead and link some of the OT environments you've seen compromised by USB drive in the US.
There aren't many, but it's not because it's a difficult attack to mount. It's because there is a lot of lower lying fruit. You don't have to outrun the bear.
Someone did this to Iran's centrifuge controllers.
And IIoT makes lot of sense. Having worked with such products. You can monitor remotely equipment and even do data analysis on the data to find patterns. A real use of machine learning.
Not that it doesn't mean there shouldn't be very limited connection from singular or few gateway devices. And all of the other stuff stopping devices from connecting to and from internet...
You're subscription only allows 250 bolt twists. If you would like to upgrade your subscription, please visit www.wescrewyousoyoucancontinuetoscrewbolts.com
Every time a bolt turns more than 90 degrees BoltTweet(tm) will let all your friends and family know JUST HOW MUCH YOU LOVE BOLTS.
I don't know how many twists you are allowed, 250 seems a bit low. People can die if calibration procedures are not followed. If the manufacture says 250 twists, then you follow that 250 or you will lose millions in court.
That would depend on the accreditations involved, yeah? One would certainly hope that the manufacturer goes through a rigorous design and testing process to ensure that the recommended service/calibration interval is accurate and occurs before the tool wanders out of spec for whatever its intended task is.
As the end user you should presumably be able to reasonably adjust that service interval but it should require a similarly rigorous and documented process to determine how much more you can open it up, not just squinting at the wind and saying "eh they over-engineered it so I think we can get 30% more use out of before calibration"
That's where the accreditations and specs come in. If I'm torqueing down a new Ikea bookshelf, I really don't care. New tires at a chain shop? Middling, to the point that they don't over-ugga-dugga my lug nuts on and destroy the bolts. I'm gonna re-tighten them myself after a drive or two anyway. Bolts in a new airliner being tightened down at the plant? You bet I want that shit to be to-spec, and the tools, too.
how does this help some guy in a shop somewhere that doesn't need strict calibration schedules and bought the wrench secondhand or even firsthand?
In saying that, there were devices with similar restrictions before any IoT existed. Smoke alarms, CO alarms, breathalysers are all devices I’ve seen with enforced lifetime and/or usage counts.
Unpopular opinion: I'm not convinced we need internet connected wrenches for this. We may want or be excited about, e.g., monitoring torque with internet connected wrenches, but I'm not convinced we need them. This may be a scaling issue, related to being able to make things faster with less experience and oversight. I'm generally skeptical of the unintended consequences of scaling production like that, and it may be giving me a bias. But I stand by the statement that there is no fundamental requirement to make wrenches connect to the internet in order to manufacture sensitive equipment.
But there's real demand in the industry to use networked IoT devices wherever possible and harvest the data so you can do things like QC (hand an audit trail to your customer that all bolts have been tightened with the exactly right torque) or preventive maintenance.
No one wants to fall back to non-networked ways of manufacturing.
No one would care about IoT wrenches if they forced some app-based auth with mfa. We only care because we can trivially exploit them.
Companies like Bosch shipping these things insecure by default is the real problem. Near everything embedded does snmp 'public' with write options and very few devices force strong passwords or passwordless or force mfa. The embedded space is a mess and where computers were pre-2000.
This it the classic "we invented cars before seatbelts and don't want to spend money on safety anyways," scenario.
Regulation here is badly needed. The market won't fix this itself. Bosch isn't really hurt by this stuff. They can just blame operators, the same way Boeing blames pilots or airlines when their Max's crash or fall apart in the sky. This is a classic perverse incentive of capitalism at play here and now that politics has moved towards idealizing a low-regulatory environment, we're only going to see more awful scenarios like this.
This is my new benchmark for quality journalism: calling out half-arsed boilerplate press releases. This requires a journalist who genuinely understands the story, which is exceptionally rare outside of industry-specific journals.
I imagine the requirements document didn't say anything about the public internet.
The UX is always trash, the security is non-existent, the smart-components are always low-spec and low quality (displays?). Is adding £5, £10, £100 to the cost of a unit to do it right going to hurt _that_ much?
Genuinely, I don't understand. Surely one of these things costs at least 5 figures and are bought in multiples of tens or hundreds?
Split agency problem - the person who buys it is not the person who uses it. (I am not a fish - Seth Godin)
> nobody can hire a skilled team of software engineers to write proper code for this stuff?
You see a huge company from the outside. From the inside it's a small team[0] in a cost center[1] who are always overworked.
0. https://www.bitsaboutmoney.com/archive/the-long-shadow-of-ch...
1. https://swizec.com/blog/the-3-budgets/ ; https://news.ycombinator.com/item?id=38851051
"We've hacked your torque wrenches since adoption & changed the torque values to deceive your Quality Control on random random bolts on random aircraft. Pay us ransom to tell you which fasteners on which products were changed or recall them all."
Re-torquing every bolt on an aircraft would be ungodly expensive.
But when bit ignored that threat would be easy to deal with, just get some indicator beam type torque wrenches and occasionally check what the dial tells you about the point the trigger-type triggers.
This is why the thing is networked. Easier, more reliable, to pull that data (and then verify it was complied with) automatically from the network. In the most precision kind of work of that kind some decades ago, every bolt and hole would have a little sticker/tag on it, and there would be double-and triple-checked lists.
And this is why the vulnerability is particularly alarming. An attacker who targeted and compromised a manufacturer using these could, I dunno, slightly alter all the bolts used on an airplane, in a very specific way, so it is prone to failure prematurely.
These sorts of vulnerabilities have the same sort of potential for economic/national targets in a sophisticated (probably state-backed) attack, similar to that one which destroyed all those centrifuges in Iran: https://en.wikipedia.org/wiki/Stuxnet
Hmmm...
Except it's real. In many "smart" devices, including industrial wrenches, security is an afterthought.
I wonder if we would be better off making manufacturers legally liable for selling utterly insecure, accessible-in-the-open devices.
- choose (at least one) small SoC, with hopefully solid open credentials - Define that as the “floor” for IoT devices. - run a minimal kernel on it, enough that anyone can easily extend - provide ten years worth of security patches and updates - provide helluva good test rig
The people who built this were wrench engineers not nginix hackers - if their wrench cost 7p per unit more (but so did all the completion) do they mind as long as “that’s the standard way”
Or am I dreaming?
Bosch officials emailed a statement that included
the usual lines about security being a top priority
It seems Ars Technica have made a typo; should read "lies".Did we forget about STUXNET? This IS very hard to do, but NOT unlikely.
More complexity, more chances for things to go wrong. Combine that with Murphy's Law and this is what you get.
Also how does the internet connected torque wrench know what bolt it is being used on? If you have different bolts, it wouldn't know. If you have only a single bolt, you could just use a single setting.
> Also how does the internet connected torque wrench know what bolt it is being used on?
I don't think most of them do, although this has been a focus area of some augmented reality tools. In most cases now, this is a task the technician has to do, regardless of the wrench they are using.
What I linked isn't connected to a network at all, what is your point here?
In most cases now, this is a task the technician has to do, regardless of the wrench they are using.
Then how would a network connected torque wrench make sure that airplane bolts are tightened better than a digital torque wrench? I think you're losing track of the context of this thread.
It reduces the potential for human error by automating part of the process and therefore reducing cognitive load and human err.
> What I linked isn't connected to a network at all, what is your point here?
My point is that you can leverage the advantages of a network connected wrench while also mitigating concerns about internet connectivity by just configuring the network. You don't have to use a tool with fewer features.
What is it automating that a digital torque wrench doesn't?
My point is that you can leverage the advantages of a network connected wrench
What are the advantages?
Factories do not spend huge sums of money on automated tooling for no reason. Automation in factories decreases human err and increases the quality and speed of output.
Again, this isn't a network feature.
Automation in factories decreases human err and increases the quality and speed of output.
Right, this is something that has been done already without networking.
I find it strange that anyone would be confused about the benefits of distributing information over a network on this website.
If you think these features have no utility, then why are factories buying them?
Maybe you can set new values (although wouldn't that imply that everything before it was wrong and wouldn't people need to check each one to make sure they're right anyway?) but then you end up having people ransomwear your wrenches.
Again, the ransomware issue is easily mitigated. Not only can software be fixed, the wrenches can be also kept airgapped.
Also it is worth noting that there isn't any ransomware in the wild for these wrenches. This was a research exercise.
All it's doing is shifting the blame away from the one who should actually be responsible for the work.
No computer.
Not sure if that means there is an issue with it or whether people are just "borrowing" it.
...and with these "smart" wrenches, it's up to the software developers, network administrators, hardware manufacturers, etc. All of which have to do a good job.
People like talking about supply chain attacks these days. A mechanical torque wrench has a much smaller dependency graph and can be easily calibrated and checked with a simple weight and a lever, and can't be programmed to behave subtly different every 12th bolt. These, on the other hand...
Because I very much appreciate the fact that some of my tools will not break my wrist, like the old dumb high power tools like to do.
Yes, torque wrenches benefit a lot from a "computer".
Neither did the GP say anything about network.
--Scotty