9 ms·
I feel like I'm missing out on a huge bulk of money simply because when I have ideas of "Internet of Things", I cant get over the security obstacles and cancel
by binarymax 11y ago
I feel like I'm missing out on a huge bulk of money simply because when I have ideas of "Internet of Things", I cant get over the security obstacles and cancel the ideas. If only I just didn't care (or didnt know) and just implemented whatever the heck brought in money from oblivious customers.
- Navarr 11y agoWouldn't the way to go about this be: Create an MVP (w/out much security) - get funding for the MVP, hire security experts, get over the obstacles?
- ajmurmann 11y agoI wonder if the competition wouldn't just skip the security, then beat you on the price because you are paying lots of money for security experts. Most customers don't care about/understand security and your company fails.
- Jtsummers 11y agoFind a way to demonstrate the flaws in various products, aim for non-consumer markets. Businesses that have an actual motivation to have secure devices like the hotel in the article would be more inclined to spend the extra money, especially if it at least eliminated a trivially hackable configuration like, again, in the article.
- na85 11y agoHire Russian black hats to sabotage the competition?
- mark-r 11y agoThe problem is that the entire industry would get a bad reputation, not just the competition. You might be shooting yourself in the foot.
- elorant 11y agoOr you could just implement them as-is, earn a shitload of money and then enhance their security in the next version or with a firmware update once you'll have the luxury of investing in R&D. At least it's better if a security-wary entrepreneur implements them instead of someone who simply doesn't give a flying fuck.
- joepie91_ 11y agoNo. Bolt-on security doesn't work. It is either possible to do something securely and won't really take significantly more time, or it's not possible to do it securely at all, and no future update is going to fix it.
- collyw 11y agoSo why do I bother clicking "install updates" on machine every few days?
- csydas 11y agoI think the parent post is talking about a design for security rather than fixing security bugs. A device or system designed without security in mind likely isn't going to get security as a priority at any point in its lifetime, or isn't going to be worked on by security minded folk. Any updates are likely going to be superficial, poorly implemented, or simply not a priority for the developers. In regards to IoT devices, as the article is lamenting, many are designed with no security in mind and instead seem to be thrown together as quick as possible to achieve a function, without considering the implications that a security breach may have with said device. (e.g., IoT baby monitors, thermostats, home locking systems)
- lmm 11y agoBecause in practice, for the moment, there is a difference between "insecure" and "insecure and being exploited in the wild".
- takeda 11y agoThere's a difference in security issues due to programming bug vs insecure design. If an application was created without security in mind in worst case it might require complete rewrite. In other cases it might be a whack-a-mole game. For example compare ssh vs application that simply opens port and starts bash as root. You can use both to control your server, but if you want to add security it would be a lot of work (you could incrementally add authentication, encryption, maybe restrict user what s/he can do but there will be million and one ways to escape). After fixing one issue after another without seeing the end you'll realize it would be less work to just rewrite it from scratch with security in mind. Security is not a feature, it is a process.
- dcexqm 11y agoUnder pressure in an interview, yesterday, I found myself saying "'The Internet of Things' is short for 'The Internet of Things you don't need, sending surveillance data you don't want, to people you don't know.'"
- brianwawok 11y agoI would have hired you
- ericzawo 11y agoMaybe they'll appreciate your honesty?
- deleted 11y ago[deleted]
- throweway 11y agoNah companies want obediant placid fungible workers not free thinkering radicals. Even the hipster ones that let you work remotely and choose your own projects and stuff.
- amelius 11y ago> to people you don't know What is worse, your data being sent to people you know or to people you don't know?
- ccvannorman 11y agoDepends -- WILL I know them afterwards?
- ovi256 11y agoThat's a puzzle question worthy of a board of ethics interview.
- ttctciyf 11y agoThere's surely a Wildean quote in there somewhere.. "The only thing worse than your data being sent to people you don't know..."
- goldenkey 11y agoI worked for a startup and found cross site scripting vulnerabilities and other issues like GET urls for deleting things. I was told to leave it alone and not "waste my time" because we dont have a lot of users and we weren't popular. I cringe at the justification. Security should be a necessary skill. It shouldnt be something after the fact
- rietta 11y agoThis is why I absolutely believe and publicly talk about security being a matter of developer ethics. I have used my walk away power to get a company to do the security they needed in a similar, but not quite the same type of situation. Here is the professional ethics piece of a talk I gave last year to a developer meetup: https://www.youtube.com/watch?v=dj196NhPyWs&t=43m36s https://www.youtube.com/watch?v=dj196NhPyWs&t=43m36s
- GFischer 11y agoI think they were right to tell you to leave them alone, but a better answer would be: "we'll add them to our backlog (or whatever way you manage issues or work), and get to them by X iteration". As long as you were really working on an MVP and not a version 1.x .
- jacquesm 11y agoThe problem is those things end up being forgotten or interfaced to in so many places that in the end they become un-fixable or won't be fixed to keep other stuff running. You need to do it right from day #1.
- GFischer 11y agoI was thinking more of a throwaway prototype, but the answers on other threads convinced me it wasn't good advice, and I don't know what stage the OP's startup is.
- Jtsummers 11y agoThat's technical debt, and it's hard to fix. A prototype, sure, it can have flaws, it's a proof of concept of feature X, not feature X SECURED. But then the release has to be a rewrite. If it's not, those flaws are more likely to become permanent. And when they do begin work on repairing their codebase, they'll spend several times the money and time to fix than if they'd spent some time early on. They'll also likely introduce numerous other issues in the process.
- vonmoltke 11y agoIn addition to this, my problem is usually, "I could solve that problem with $5 in discrete electronic components." :P
- Kliment 11y agoI build stuff like that - my approach is to limit capabilities to the absolute minimum, and anything that is not needed for function but necessary for debug/diagnostics stays on the device rather than going across the network. This limits the devices a fair bit - firmware update across the network with no local interaction is not allowed, nor is accessing the local data store. Want to email me and talk about this?
- collyw 11y agoWhich is exactly what a physical switch would do. No wireless internet, no GUI, just a switch.
- Kliment 11y agoAbsolutely - and for a light switch it's appropriate. As an example of a thing that needs internet to function, consider a heater controller that has a high power and low power mode depending on momentary cost of electricity - it fetches price data across the network, and it's important to log things like temperature at various points of the device for diagnostics. Now, it's very tempting to send the diagnostic data across the network, but this leaks usage information. It's also tempting to allow things like remote configuration, firmware updates and reading device memory for debug, but that can leak network access credentials or make the device a beachhead for access to the internal network. This is why any feature like that is to be avoided and, if present, needs to be activated from the device itself, not remotely. If you NEED remote control, see if you can limit its scope of functionality to the bare minimum, and consider who needs access to it - in the case of the heater controller, the provider of the pricing data doesn't need to know or control the state of the device, so there's no need to allow that on that connection. Where possible, make the device a CLIENT rather than a SERVER - have the device itself initiate connections, to an address that is entered by local interaction, rather than accept connections from anywhere. If you MUST break those rules and accept connections from anywhere, that's when you really need to spend a fuckton of effort securing every aspect of your device, client applications, and protocol.
- theklub 11y agoGood point, seems like places get sold products that are smoke and mirrors. If they knew what was going on in the background they would be shocked. Best plan is to build up a big customer base with a smoke and mirror product and then sell out and hope you don't get sued.
- moistgorilla 11y agoI thought you were supposed to implement it in a basic way then have the investor money pay for other people to think through your project
- draw_down 11y agoYes, I'm sure that the only thing standing between you and untold riches is your resistance to lax security measures in app-controlled sous vide machines.
- dsr_ 11y agoThe security risk in an app-controlled sous vide machine includes starting a fire that burns your house down. - Sous vide normally uses a water bath at a controlled low temperature over a long period of time. - Hike the temperature up past the boiling point, and the water is evaporated, allowing you to hike the temperature up to ignition points. - Or, cycle the electronics fast enough to overload the power supply. If it isn't designed well, either the wall circuit blows or the power supply bursts into flame. - In any case, the expectation of a long unattended cooking process means that human observers might not be in the loop.
- Johnny555 11y agoIt seems unlikely that the device received a UL certification without a simple thermal cutoff switch that is common even in low-end cooking appliances. Even without deliberate hackers, the device needs to contend with software errors, running without water, or a stuck relay that could leave it boiling dry and overheating.
- manarth 11y agoYou just need to look at Therac-25 for a device which lacked hardware interlocks/cut-offs, had flawed/buggy software interlocks, and still received certification.
- Johnny555 11y agoYou mean I only need to look back 35 years to a professional medical device built when computer control was still very new and that wasn't intended to be operated by unskilled consumers, and wasn't certified by to be safe for home use?
- throw918319 11y agoYep, you have to lose all shame to be successful. See also the subthread about MIFARE cards in the "towel with RFID" submission.
- rihegher 11y agomandatory: https://www.youtube.com/watch?v=9IG3zqvUqJY https://www.youtube.com/watch?v=9IG3zqvUqJY
- z3t4 11y agoYou have to put things in perspective. It just have to be secure enough. It's for example hard to build anything, if it has to endure a meteor strike.
- dazzla 11y agoAndroid/iOS is an interesting idea for a business. They already have secure app distribution. A private channel in the Google play store or via app store adhoc. Communication between the devices via a server should be possible at least using HTTPS but also private/public key encryption. Doesn't have to be an actual server just one of the devices in server mode. What could possibly go wrong?
- wpietri 11y agoI wish you would. The difference between you and the dunces building things like this hotel light system is that you know that there's a problem and will work to fix it. As the market matures, security will become more important. But the only companies with the chance to fix it will be the ones with substantial market share. And the people who will fix it best will be the ones, like you, thinking about security from the beginning. But that can only happen if people like you get in early and lay down the infrastructure in a way where security will at least be possible.
- 7952 11y agoI am coming to the conclusion that these devices should be treated like every other URL on the web. It should have TLs with a proper cert, a global domain name, wifi, and access controlled by something well known like Openid/oauth. With native apps and CORS firewall traversal is solvable without special protocols and adaptors.