3 ms·
(replying from UTC+1) In fact it’s exactly a matter of anticipating. In most cases the SME is not prepared to deal with such issues (it lacks a structured IT
by babboste 10y ago
(replying from UTC+1)
In fact it’s exactly a matter of anticipating.
In most cases the SME is not prepared to deal with such issues (it lacks a structured IT department): this is why we try to play an active role in raising its awareness about security concerns. We explain which kinds of risks can arise with easily understandable examples (sometimes they are already known, most often they are not), trying to do it in plain business language: how an IoT platform can be fooled by fake devices, how it is possible to exploit vulnerabilities to gain fraudulent control of devices and the subsequent business consequences.
Then we move to explain the solutions we apply to this issues (always trying to do it as if we were speaking to a child). Four of them involves what you already mentioned:
- Good practices are applied by design (like generating strong random passwords for each device); despite being trivial these are far from representing a de-facto standard in a market where these issues have been neglected for a long time
- all vulnerable communication paths are encrypted
- integrity checks are performed by both sides to ensure that over the air updates are genuine
- over the air updates themselves allow you to patch the device (with security fixes, etc) while it is deployed on the field (which is relevant in a rapid prototyping scenario)
One last word on how SMEs could trust Iottly.
Proprietary enterprise software (both on-premise and SaaS) need to be submitted to security assessments performed by third party authorities. Ok, this is important and we do have plans for that in the future.
But, in addition to this, it turns out that a wide spreading of the same code base increases security, by enabling cross testing processes, performed by multiple independent parties in different application contexts.
And this is one of the main reasons why we open sourced Iottly.
It’s not that the SME itself can check the source code for security issues, but it very likely has IT consultants it trusts for everyday IT tasks, and these people can indeed perform an independent check if the source code is available.