8 ms·
So, you could; buy lots of these. Take the bulbs and hub and modify the software further. Since they come in a 'box'; you can put them back in the box and then
by georgefrick 11y ago
So, you could; buy lots of these. Take the bulbs and hub and modify the software further. Since they come in a 'box'; you can put them back in the box and then give them to people as gifts or promotional items.
You are now behind their firewall.
If you are a hacker and you manage to get into a factory in China or Taiwan or wherever that is making these; you swap out the base firmware with one of your own that dials home. You are now behind the firewall of all customers.
Just some random thoughts before bed.
- api 11y agoIoT is yet another reason firewalls are obsolescent as a security measure. A device is secure or it is not. There is no such thing as a safe network. Never really was, but now there really ain't.
- harryjo 11y agoIoT isn't the issue, cellular and long-range wifi networking is the problem -- there is no network boundaty anymore.
- api 11y agoIt's just yet another nail in the firewall's coffin. I cringe now when I read security people still talking about them as a first or really any meaningful line of defense.
- otabdeveloper 11y ago"All or nothing" is not how risk management works in the real world. P.S. 'Network security' is just a specific case of risk management.
- justinjlynn 11y agoI believe that at this point in time any network traversal should be considered an ultrahazardous activity. As most networks are beyond the control of the users and have little to no change control, it makes little sense to apply risk mitigation controls to them. When you consider the fact that users demand their information be available at all times, it makes much more sense, from a risk mitigation perspective, to focus on the elements you do have a semblance of control over -- the endpoints where the sensitive data is stored and processed and the protocols by which they communicate. There are well known and trusted means of securing data in transit. There is no excuse for relying on policy for mitigation where your policy can have no effect.
- acdha 11y agoI agree that defense in depth is a good idea, but one key factor to consider is cost. Having a basic firewall makes sense, if for no reason other than “documenting” your public services in one place, but many places are either lulled into a sense of complacency or spend inordinate amounts of time managing tons of rules trying to segregate internal hosts, update for every new network app, etc. It's that latter group which really needs to hear the truth that they should invest in endpoint security instead unless they have a high security threat and enough resources to do both.
- Cartwright2 11y agoWhen you say firewall, do you mean a firewall on the edge of a home LAN? Because I still see a firewall on each individual networked machine as being extremely important.
- JoshTriplett 11y agoYou don't need a firewall on individual machines either; just don't run network-facing services in the first place. At most, as a belt-and-braces security measure, you might want a system-wide prohibition preventing programs from listening on non-localhost (with exceptions for intentional servers, which should almost never happen on a client system). But that prohibition should primarily exist to catch programs misconfigured to listen on non-localhost, rather than leaving those programs running and just using a firewall to block them.
- nitrogen 11y agoThese days it's just as important to monitor and filter outgoing traffic to detect trojans and unfriendly devices trying to phone home.
- Cartwright2 11y ago> You don't need a firewall on individual machines either; just don't run network-facing services in the first place I disagree. Firewalls fail closed under user error. The solution you proposed (we'll call it conscientious-wall) fails open under user error. That's to say, once a firewall is set up it will protect me from outside intruders unless I specifically tell it not to. A "conscientious-wall" will not protect me from outside intruders unless I specifically remember to apply it whenever I install an application or download a software update. I'm still firmly in the camp of having at least an inbound firewall on every machine.
- mavhc 11y agoSounds like we need a firewall in the switch/AP
- 11y ago
- foota 11y agoI think there's an important distinction between firewalls for client security and firewalls for server security.
- pingec 11y agoLuckily, our devices have beefier security now. It`s much harder to spoof gmail or facebook or paypal these days.
- 746F7475 11y agoHow about completely separated WiFi network for all IoT junk?
- SmellyGeekBoy 11y agoGood idea. A lot of high end routers have an option for a "guest network" these days. Or just invest in a cheapo access point just for IoT devices.
- 746F7475 11y agoDepends on your paranoia level if you trust something like that, but most people have old wifi enabled routers just laying around
- PietdeVries 11y agoBut... As soon as your bridge for the lights is on some sort of guest AP/network, your client on your phone can't reach it anymore, and thus has to be on that same network. And that will annoy you quick enought to not try to install the extra or guest AP at all...
- 746F7475 11y agoDepends on the IoT device, some only have web interface that is controlled via manufacturers website, so as long as the actual device has internet connectivity you can do everything. Or maybe you can setup a "thorwaway" PC as a sort of proxy? Or maybe just one of the old (and sad) tablets/phones, depends on what you need/want to do and what kind of interfaces your IoT devices offer
- late2part 11y agoUsing a device that is controlled by an external "cloud" server is even worse - you've just given an untrusted 3rd party root access to a device on your lan.
- 11y ago
- ultramancool 11y agoUh, pretty sure firewalls are exactly how we can fix this. Use your firewall to enforce each device can only talk to what it needs to and can't do any harm internally. Without firewall: Here's direct access to everything on my network. With firewall: Oh no, you can hack all my smart lightbulbs and change their colours. This kind of thing is exactly you need firewalls for. Without a firewall this could pose a serious threat, with a firewall it's probably a good practical joke at best.
- api 11y agoIf your systems have a local firewall, services are jailed, OS is patched, etc. then direct access to it is not dangerous. Somewhere we decided to accept crap system and device security as normal because oh we'll just firewall it. That was never a good idea but the more cloud connected things we deploy it becomes completely untenable. Large corporate networks are already hostile territory due to BYOD. The only way to maintain the firewall as anything other than security theater is to lock everything down so much that nobody can get anything done. The whole approach is braindead. We don't see how stupid it is because it's grandfathered in.
- jessaustin 11y agoHaven't read TFA yet, but I think you're expecting too much from your firewall here. These bulbs are hosts, and they're inside the perimeter. They have been hacked, so they send malicious traffic to other inside hosts. What the hell is a firewall going to do about that?
- sbierwagen 11y agoJust don't route packets from the bulbs to your other devices.
- jessaustin 11y agoThat's a good idea, but that logic has to be on the switch. Unless one has a very simple network, the firewall is somewhere else.
- justinjlynn 11y agoBrilliant. As always, stay safe and stay legal.
- justinjlynn 11y agoWell, that didn't go over well. I'll show myself out.
- georgefrick 11y agoI wasn't proposing illegal activity. I was in an obscure way, pointing out how badly insecure devices are actually a double threat. They are a threat in their own right, but they are also a threat in that you can't assume they haven't been tampered with. I didn't down vote your comment or anything; but I think the general idea is to add to the conversation. Short quips generally turn gray... the rest of the thread under mine is mostly discussions of security options/concerns in regards to firewalls and networks.
- justinjlynn 11y agoDidn't mean to imply you were - just a saying in the locksmithing community. If you look below, I have contributed a tad more than a short quip. No worries.
- georgefrick 11y agoI didn't know it was a locksmithing term, that's actually interesting and I'll have to Google a bit. It also puts the comment into context; but I was probably not the only one to miss the whooshing sound.
- justinjlynn 11y agoNo worries -- there are times I feel I reside under a flight path so I'm sorry I sent a jet your way. Regarding the saying, I've probably heard it more often in the locksport community, actually. That's probably what I meant to say instead of locksmithing.
- 746F7475 11y agoAssuming the box is resealable you could just return it to the store in selling condition. Or little more unlikely you could by 10 from a different store, hax 'em, go to another store and put them back on the shelf
- nkrisc 11y agoSounds like just giving these to someone without modifying them would achieve the same effect.