5 ms·
Imagine if all those IP cameras, routers, NAT boxes and what-have-you had been designed with one simple policy: the internet port doesn't work until the user se
by wokky 10y ago
Imagine if all those IP cameras, routers, NAT boxes and what-have-you had been designed with one simple policy: the internet port doesn't work until the user sets a password.
Even very lame passwords might be expected to reduce the effectiveness of this attack approach by an order of magnitude or two.
- stephen_g 10y agoI was just saying to a friend yesterday that this would be a great policy. I think it would go a long way. But the problem remains that these devices, more often than not just don't get updated. So in a year or two, there will probably be a handful of exploitable issues that won't ever get patched...
- necessity 10y agoHow many Windows users are using a pirated version of their operating system that gets no updates? How many of those using the genuine version ignore/disabled it? How many update their anti-virus? Custom ROM users? How many Ubuntu users ignore the updates? ...
- Drdrdrq 10y ago> How many Ubuntu users ignore the updates Hopefully not many, though I could never understand why unattended-updates package is not installed and enabledby default.
- petre 10y agoBecause it breaks things. Updates sometimes break things and require human intervention to get the device running properly again. This can happen since systems use different hardware. With IoT it's an issue to a lesser extent, but you can also brick those with an upgrade.
- oneeyedpigeon 10y agoBetter an individual device has some trivial breakage for a short period of time than the whole Internet breaks. I don't think we're there yet, but it feels like we'll need to take some pretty draconian steps if we continue the way we're going. Doesn't it make sense for 99% of IoT devices to only be able to communicate via a router over WiFi?
- Drdrdrq 10y agoWe are talking about common desktop PCs with more or less standard set of packages, not about server machines. I seriously doubt there are any breakages there.
- samuellb 10y agoI've noticed that sometimes updates to Firefox cause it to stop working until it's restarted. If you're writing a long message, or filling in some form, or if you have an order confirmation page open, then you might lose that data. I've never seen that happen in native GNU/Linux applications, though. I guess it might be related to the XUL stuff in Firefox. But given that Firefox (and Chrome/ium) are memory hogs that eventually get OOM killed, you need to restart them periodically anyway, so it might not make a big difference if the OS does auto-updates in the background.
- maccard 10y agoThe windows 10 anniversary update was a nightmare for me, my office, and seemingly a lot of people[0]. Note that the update installed itself too, opting to alert me at 7pm one evening while my machine was running unattended that it was going to restart in 15 minutes. [0] http://www.telegraph.co.uk/technology/2016/08/25/windows-10-anniversary-update-keeps-breaking-pcs/ http://www.telegraph.co.uk/technology/2016/08/25/windows-10-...
- kikoreis 10y agoActually, it is installed and enabled by default as of 16.04 LTS; see https://wiki.ubuntu.com/Security/Features https://wiki.ubuntu.com/Security/Features for the detail.
- madeofpalk 10y agoGiven that all these devices were 'hacked' using just the default credentials, exploits in the software aren't as relevant here.
- andrewflnr 10y agoToday they aren't. Once the fruit lying on the ground is exhausted, they'll get serious about the low-hanging software exploits
- stephen_g 10y agoThe point of my comment was that, yes, this kind of policy would be good and might have stopped this attack. But it wouldn't solve the whole problem, just make it a tiny bit more difficult for the attackers. Definitely worth doing, but we will need to address the culture of 'ship and forget' also or we will just have the same problem but with software exploits.
- deleted 10y ago[deleted]
- detaro 10y agoIf routers weren't such a crapshot security wise as well, they'd be a great integration point. Most better routers nowadays can already isolate devices from the internet/whitelist specific domains (family filter functions) and offer VPNs from the outside. From a technology perspective that's most of the pieces you need. Make a better UPnP implementation with user confirmation, make it easier to configure and everybody can get their devices nicely isolated-but-accessible.
- throwaway13337 10y agoMost modem/routers that ISPs give you come with a password that is defaulted to something random - different for every device - and a sticker with that password somewhere on the physical device. That seems like the best solution. Now we just need to enforce that as a standard with internet connected devices.
- Crosseye_Jack 10y agoAfter a period of time of coming out of the box and set to open, followed by predictable passwords, followed by a lack of rate limiting on WPS and vulnerable TR-06 setups and the always present mistakes in router firmware allowing remote exploits. Now if only we could get a standard router manufactures to stick to :-P Sadly I can see IoT having to go though the same slow learning curve.
- Thlom 10y agoHaha, yes. Except when the password isn't random. The biggest ISP in Norway delivered multimodems with seemingly random SSID and password. That worked fine, until someone figured out that the password were derived from the SSID with an algorithm (Or something along those tracks, I can't remember the specifics). Now we had thousands upon thousands of basically free wifi hotspots!
- jessaustin 10y agoMaybe that was the intention? Not of management, obviously, but perhaps of someone who actually set things up...
- chrischen 10y agoOr rather just block problematic IPs and make the user secure their systems or noth have access.
- idlewords 10y agoYou can imagine why that's a non-starter. You'd be locking millions of people out of their Internet access with no workable way for them to get it back. Just imagine how many scammers would pop up to 'secure' things for people locked offline.
- s_kilk 10y agoWhat you're proposing is a massively worse ddos vector than anything seen so far. Hacking a webcam would no longer lead to the ability to ddos websites, it would be a direct and total shutdown of the domestic internet supply.
- chrischen 10y agoNo it shifts our priorities. Once people realize they can't access 90%of the internet unless they reinstall their OS or unplug all network devices, people will become more vigilent.
- pimlottc 10y agoDo we have any idea of what proportion of devices are "owned" via default or unset passwords, as opposed to actual exploits?
- madeofpalk 10y agoIt's understood that the recent DDOS attack on Dyn via the Mirai bonet was entirely made of up IoT devices with just 62 default passwords https://news.ycombinator.com/item?id=12766950 https://news.ycombinator.com/item?id=12766950
- petre 10y agoOr ship every new device with a different randomly generated 10+ character password and writing it on the device's label just like the MAC address. I agree you would need physical access to the device to gain access to it but you can always change the password to avoid this. There are vendors that already do this with the WiFi key.
- adrianratnapala 10y agoThis would be a nice improvement, but as others point out, more flaws will exist and be exploited. Really this is about incentives: manufactures and users have little incentive to worry about security if the losers are third-party the targets of a DDOS. Things will only improve when there is liability: either the manufacturers or the users get fined when their stuff becomes an attack vector. Fining users will probably never be politically possible, but I suspect it would be the better option.
- oneeyedpigeon 10y agoWhy do you think fining users would be the better option?
- adrianratnapala 10y agoI think fining manufactures would lead to scenarios where we fight the last war, much like how the 2008 financial crisis was not prevented by the existing nest of regulations which were passed to prevent the previous crises. That is fining manufacturers would lead to strict and expensive regulations saying just how things must be done, but which are laughed at by baddies developing new exploits that work within these particular rules. On the other hand, if the rule is "if your box does bad stuff, then you must pay" -- then consumers will look to security as part of the good reputation of the vendor. That extra layer of indirection is what I look for to avoid "last war" type scenarios.