19 ms·
The Mirai Botnet Is Proof the Security Industry Is Broken
- WhiteHat1 10y agoSo many devices are now connected to the Internet and potentially vulnerable. The basics definitely matter – changing default passwords, ensuring our internet is hosted on DDoS protection servers, etc. But who was going to warn the traffic engineer that their security camera is vulnerable or the new parents whose IP-connected baby monitor gets scanned by foreign hackers. We just want things to work and don’t realize that we’re at risk – even if our device is the target and not ourselves. Have you checked out this Mirai vulnerability scanner? Something everyone should do – whether a random home user or a large enterprise (and how many have CISOs?). It scans your IP and can pinpoint vulnerable devices: https://www.incapsula.com/mirai-scanner.html https://www.incapsula.com/mirai-scanner.html
- zeveb 10y ago> The major botnet of 2016 is simpler than the botnet of 1988. That, right there, is a damning indictment not only of our industry but also of our culture. We know how to secure systems. It's not magic. But — unlike for example physical hygiene — we haven't made the decision to make computer hygiene part of our culture. We look down on people who don't wash their hands, but we don't look down on people who use poor passwords. We teach children to cover their mouths when they cough, but we don't teach children not to plug a Windows machine into a network.
- 6DM 10y agoWorst of all, they think people who haven't learned about security deserve what happens to them...
- XaYdEk 10y agoBut when you tell someone "That's not secure, you can easily get hacked. You need to [insert good security practices here]", what response do you get ? In my experience, most answer along the lines of "So what ? What could they get ? I have nothing important." or "Why would anyone ever hack me ?" or "But I have an antivirus, doesn't that make me safe ?". And then spend the next 15 minutes explaining to them how things actually work and why they need to take it seriously and offer to help. 9 out of 10, they never reach out. And it's not their fault, but the way security in general is perceived.
- 6DM 10y agoI think it's just a general misunderstanding of what privacy means. I've explained several times and even convinced a few people that just because they think they have nothing to hide, they generally do have something they don't want someone to know about or see. At best they will just revert back to the "I have nothing to hide" mentality after a week. I think people outside of tech just don't see how damaging it can be when you loose privacy.
- XaYdEk 10y agoYou implement security in order to have privacy and I agree it's poorly understood in the digital realm, mostly because it's "out of sight and out of mind". I like to use an analogy I can't remember where I picked up and reductio ad absurdum to get them past this automatic response, because that's what it is and it's based in the horrid and dangerous "Nothing to hide, nothing to fear" saying. - The usual conversation - I ask them: "Do you have curtains ?" and they say: "Yes, of course" and I ask "Why ? I mean you have nothing to hide right ? What does it matter if someone can see what you are doing inside your house ?", usually they freeze for a second, "Because it's creepy". I continue "Well if it's creepy that someone would watch you in your house, isn't it just as creepy if they watched you online, what you read, what porn you watch, what you talk to your friends about ? Which do you think tells more about who you are ?". At this point silence and an increasingly worried look is the norm. I keep going: "It's not about hiding anything, it's about what is private. Otherwise why not tell everyone your darkest secret, your greatest fears, the thing you are most ashamed of doing in your life ? And that's why you should do [this or that]" But even so, it's true most default back quickly. Still a few call, ask, improve their practices. People only seem to take it seriously after they have been directly impacted in a powerfully damaging way. Edit: I have obviously had this conversation enough times to make this script in dealing with it. If you have to do it more than twice, automate it. :)
- nickysielicki 10y agoFor the sake of argument, why don't they deserve what happens to them? Most people don't understand how their car works. But if you own a car and you neglect to change the oil for 50k miles, or you put diesel into your tank and ruin your car, we don't blame the automotive industry for not informing you on proper maintenance. Just like with computers, the information is out there, and it's not the job of the automaker to make sure you know it. Why are computers different?
- 6DM 10y agoHowever, if it is a very wide spread problem then they will eventually install a light on your dash to notify you to change your oil. My wife's car currently does this. Since this is the first car she's ever owned, it's good because I don't think she would have known. We also have check engine lights and indicators for when a turn signal light bulb stops working. New cars even keep track of things like tire pressure. I don't expect the mechanic to take advantage of me and instead offer me fair service at a fair price. Luckily enough people have a natural interest in it that the competition keeps prices down. My argument is in the similar vein of those who aren't physically fit to win a fist fight. Doesn't mean they deserve to pushed around, robbed or beaten just because I'm stronger and a better fighter. No matter the analogy, if someone doesn't know better it doesn't automatically mean they deserve it. Peoples lives are busy, complicated and not everyone starts on the same ground or with the same capabilities.
- nickysielicki 10y ago> However, if it is a very wide spread problem then they will eventually install a light on your dash to notify you to change your oil. My wife's car currently does this. Since this is the first car she's ever owned, it's good because I don't think she would have known. We also have check engine lights and indicators for when a turn signal light bulb stops working. New cars even keep track of things like tire pressure. This is getting off subject, but I'm of the opinion that this trend is primarily motivated by locking people into a dealer for maintenance, not helping people maintain their vehicles. For example, I think BMW dealers are the only ones who have the ability to calibrate tire pressure sensors on bimmers, and some new cars are abandoning OBD-II ports. http://www.roadandtrack.com/car-culture/a30505/new-car-service/ http://www.roadandtrack.com/car-culture/a30505/new-car-servi... > My argument is in the similar vein of those who aren't physically fit to win a fist fight. Doesn't mean they deserve to pushed around, robbed or beaten just because I'm stronger and a better fighter. I don't think it's fair to compare these things. Of course no one deserves to be assaulted. And likewise, if someone sabotages your car or has a remote exploit for your computer, I find it hard to dish out blame. But beyond this, I think the only person who could possibly be responsible for the condition of their possessions is the owner, and I don't see why computers should be any different. Not knowing better or being too busy is not an excuse to be a party to a DDoS attack. You bought this computer, you plugged it in, and it was setup in a way where it was able to receive signals that made it send out signals that violate the contract you signed with your ISP and violate the laws that your representatives passed. "I didn't know" isn't an excuse in any other comparable situation. Just because computers are hard doesn't mean we should rework our entire legal framework. We shouldn't codify into law the idea that some subjects are obvious and should be enforced consistently, while some are beyond understanding (for most, for now), and ignorance is a viable excuse. It will inevitably become outdated. I'm held responsible if I have an old car rusting away in my backyard and it pollutes my neighbors well-water. And sure, it's harder to claim ignorance about a rusty car than it is to claim ignorance about a misconfigured computer, but I think the law has to be impartial about that.
- bbctol 10y agoIn this case, it's more like we look down on people who don't wash their hands, but don't care if the companies making soap also handle raw sewage. The tragedy of the modern botnet is that it wasn't even the fault of dumb consumers, but companies so careless they didn't give people the ability to set passwords in the first place!
- bad_user 10y agoI don't necessarily agree. Yes, we teach children to wash their hands, but first of all there's always a threshold over which people stop giving a damn. How many people are actually following their doctors' advice about diet and lifestyle? Heck, how many people actually take their medicine as prescribed? And there's also a danger in the other extreme. It's pretty bad that many people these days are self-medicating, many times with antibiotics or avoiding vaccines and it's even worse when they do it to their children. Something to think about. Don't get me wrong, I'm all for education. And just like sexual education, I'd introduce classes about online privacy in elementary school.
- jerf 10y ago"That, right there, is a damning indictment not only of our industry but also of our culture." Who is "our culture"? Are you part of the same "our culture" as the people who made and shipped these things? Since you're pretty much rhetorically constrained to answer "yes"... would those people agree with the answer you give? The culture I am actually part of is not perfect, certainly. The people who are in my culture still write the simplest cross-site-scripting attacks like they get paid bonuses for them. But the vast bulk of the people involved in the production of the hardware that the Mirai botnet took over would probably not agree that I am in "their culture", regardless of what I claim about it, and they'd probably feel the same way about you is my guess. Even if "we" do everything you would suggest, perfectly, Mirai still happens. Therefore, those suggestions can't be the solution. We must still address these problems via other mechanisms.
- oldmanjay 10y agoI guess it's important for some people to keep flogging Microsoft hatred but what does Windows have to do with anything here?
- achr2 10y agoMy toaster has to be certified that it meets certain minimum safety standards. It really seems that IoT and safety critical software/firmware should be required to pass a similar (bare minimum) certification.
- tkinom 10y agoToaster is required to pass safety standards because of the there is strong economic incentive (UL requirements) to do it. Without UL, it can't get on the shelf on any stores in US. There are no such thing and UL security requirements for IOT device. Time for such regulation? But "internet + regulation" normally raise a lot of objections internally from the IT industry. If someone (MSFT) proposes secure boot are required for all IOT devices, the first one to oppose it likely be EFF. :-)
- ctz 10y ago> There are no such thing and UL security requirements for IOT device. UL 2900-1.
- dfc 10y ago404 for every link to the standards. Awesome!
- tyingq 10y agoYou have to buy them... http://www.comm-2000.com/ProductDetail.aspx?UniqueKey=31733 http://www.comm-2000.com/ProductDetail.aspx?UniqueKey=31733
- dfc 10y agoYeah, I picked that up from reading the press release[1] that OP had originally included in the comment. What I was surprised to discover was the 404 error page when I clicked the individual links for the different standards. My expectation is that I would have been directed to a site to purchase them. [1]: http://ulstandards.ul.com/downloads/news-announcing-ul-2900-outlines/ http://ulstandards.ul.com/downloads/news-announcing-ul-2900-...
- iregistered4 10y agoCompletely incorrect claim, the IoT industry doesn't spend a penny on security, and therefore will be vulnerable to these type of attacks. If anything this is proof that the security industry does work, these attacks are happening on devices where there is no security budget - not on servers with large investments in security.
- OJFord 10y ago> the IoT industry doesn't spend a penny on security, Citation sorely needed [and not to be found].
- hvs 10y agoSo, "companies think that security is unnecessary" is a sign that the security industry is working?
- Beltiras 10y agoTBF the comparison is against a well defended server of which there is a great many examples.
- raesene9 10y agonope it's a sign of the strong market for lemons in IT products. There's no adequate way for consumers to differentiate between well secured products and badly secured products (every company will tell you "security is their top priority" if you ask them).
- XaYdEk 10y agoHow many pennies would've been needed to insert a simple page forcing you to change user/password combo and to choose a reasonably strong password after first boot ? In the case of Mirai it's not even a cost issue, just lacking good practices.
- drzaiusapelord 10y agoAnything that adds any interaction with the user will cost support time, thus dollars. Its easier for these companies to hard code a password in and have it "just work" with their mobile app or web interface than actually do security correctly. Until there are regulations in place to make them do this, they will not care.
- TACIXAT 10y agoI like how the author complains about cyberpocalypse conference talks then goes on to say the security industry is broken... Hard coded creds and the allowance of default creds isn't the security industry, it's the manufacturer.
- danielweber 10y ago"You didn't fix this problem a third-party created! You are at fault!"
- fulafel 10y agoThe "security industry" was never significantly involved in improving product security and software quality. They have roots in profiting from the deplorable state of PC security. Centralised firewalls, "intranets", and anti-virus products are not sustainable solutions to any of these problems - they're just so ingrained in the mindset of IT profiessionals that they self-perpetuate.
- tptacek 10y agoEndpoint security traces back to antivirus and PC security. Firewalls do not --- firewalls trace back to the Unix culture.
- eeZah7Ux 10y ago[citation needed]
- tptacek 10y agoNot really, no. But: the first commercial firewall was Ranum's DEC SEAL. Ranum is an old-school Unix programmer. The first book on firewalls is "Firewalls and Internet Security", by Bellovin and Cheswick, who previously created one of the first firewalls (predating DEC SEAL) and possibly coined the name. Both of them are, as you'd expert, Unix nerds. People were building firewalls in 1988, several years before there was even Trump Winsock, let alone a reason for PCs to need to filter Internet traffic.
- rudolf0 10y agoGood firewalls can make good security easier.
- viraptor 10y agoI get what you're going for but you're actually wrong. Both firewalls centralised or not (configure to prevent all access outbound apart from approved nodes) and intranets (put IoT in isolation) would actually prevent Mirai from both spreading and attacking anyone. But most people are not implementing either, because home router is all you need...
- MR4D 10y agoHow about a law that requires computerized devices to be shipped with unique passwords. That would be a start. Second, any computerized device must pass FTC/FCC/UL (pick one) tests for computer security before going on sale. There's more that can be done, but let's go after the simple stuff first.
- swalsh 10y agoNot sure that solves the problem either, perhaps UK has more stringent laws, or perhaps the US does. But if it's not universal a sufficiently large market can still be exploited to attack another. The internet is global. We need global regulations.
- usefulcat 10y agoIf the US or EU did that, it would still be a very good start simply due to the size of those markets.
- jws 10y agoThe law just needs to apply in a large enough region. Here in the US we got high efficiency switching wall warts instead of the slightly cheaper ones that idled away $4/yr because the EU demanded them, so manufacturers had to upgrade. Similar with lead free solder.
- MR4D 10y agoAgreed. Given consensus will take forever, I'd like to see the US or EU, somebody at lest, take the lead. Over time this will probably get worked into trade agreements anyway. But if we wait 10 years, it'll be too late, and we'll have killed the internet or given into draconian measures to stop the problem - which is what none of us want. Frankly, I don't even care if a given government has great security review - as long as they put a process in place it's a start that can be improved upon.
- onion2k 10y agoIf you want to go after the simple stuff then blocking significant outbound traffic at the ISP level from a home user account until they agree it's something they want to do is the most straightforward solution. No need to change much infrastructure, no need to test devices, and no need to have costly manufacturing processes. You could even let specific traffic through (Facebook live streaming, online gaming services, etc).
- ryanlol 10y agoYeah, no. Mirai doesn't have shit to do with the security industry. The security industry are the people who you hire to secure your things, victims of Mirai did not take advantage of the services provided by the security industry. More like, The Mirai Botnet Is Proof the Security Industry Is Going To Be Doing Fucking Great
- XaYdEk 10y agoAmen, the Security Industry is doing great, security is doing poorly.
- Analemma_ 10y agoI wish more people would talk about the economics of why netsec is such a garbage industry. It's a few honest people screaming to be heard above the din of snake-oil salesmen, but there's an economic reason that goes beyond "dumb users, incompetent programmers and CTOs who just look and speeds and feeds". The problem is there's weak correlation, or at least very difficult-to-see correlation, between the amount of effort you put in on security and the results you get. You could have no security and just get lucky and never get hacked. Or you could have great security and just get really unlucky and have a determined hacker. Or you could be spending uselessly and still getting lucky, although you (and your vendor!) attribute your good fortune to the product. This kind of information failure makes it really hard to have a functional and efficient market, even when everyone involved is honest. I don't have a good solution for this, which I why I hope someone smarter than me brings it up.
- 3pt14159 10y agoThe solution isn't to have random security consultants come in and kludge up your process and generate useless reports of irrelevant statistics. The solution is to have a red team on staff permanently, to offer bug bounties based on actual access, to install on-server monitoring for outdated packages (like Appcanary, the authors of this piece), to monitor outbound packets for suspicious behaviour (this is currently the hardest part, imo, since, other than detecting major viruses, it's largely domain and network specific), and to have an automated "take the servers off the internet" button for serious 0-days and leaked credentials. Also, always use HTTPS / HSTS lists and two factor authentication. You'll still get hacked, but you'll be far better off.
- tptacek 10y ago"Offer bug bounties based on actual access" why?
- 3pt14159 10y agoMaybe misworded, but actual access is a clear line on the spectrum that starts at reporting a potential DDOS attack on an endpoint to dumping all your users credit cards and passwords. Access to a server isn't necessarily access to a DB, but it's usually serious enough to warrant cash, no matter who you are.
- zby 10y agoMaybe we need liability for software vendors? With exemption for those who provide full source code.
- raesene9 10y agoA proposal I saw and liked was liability for software vendors based on what they charge for the software, so open source software doesn't have the problem, but people who bundle a load of open source software together, slap a management interface on it and charge loads of cash for that, do.
- danielweber 10y agoWhat if I give away the software and then sell support contracts?
- Silhouette 10y agoMaybe we need liability for software vendors? That's a common suggestion, but since no-one knows how to make completely secure systems yet, I don't think it's that simple. If you're talking about a general presumption that anyone selling software that has a security vulnerability becomes liable for any consequential losses, then it seems likely to result in only large businesses with the war chest to fight a liability action being able to make any sort of remotely risky software and/or in a new insurance industry popping up so that the problem reduces to money and the cost is ultimately passed on to software users in higher prices. While there might be some pressure to improve security as a result, the negative side effects could be far worse for the software industry as a whole. The next logical step is some sort of penalty for gross negligence or a repeated pattern of failures, where a supplier making reasonable efforts and following generally good security practices isn't at risk of being sent under instantly because of some new type of 0-day that no-one had seen before. But then you have to figure out what constitutes good practice and paying due care and attention, and that in itself is not an easy issue. With exemption for those who provide full source code. I don't see why that should make any difference. Having access to a huge amount of source code is only a benefit for security if you have the skill and resources to perform a detailed audit of your own, and if it's practical to spend that kind of time and money, and if you also have the authority to do something useful about any vulnerabilities you do find. If someone is giving software away for free as a kind gesture, that's one thing, but I don't see why anyone supplying software on a commercial basis should get out of jail free on security just because they provided source code access. The FOSS world provides ample evidence that many eyes do not, in fact, make all bugs shallow.
- CiPHPerCoder 10y agoI think it's erroneous to blame the security industry wholesale, tempting as it may be. Let's set blame aside for now. What caused this botnet? - The tendency of IoT/smart-device vendors to eschew engineering discipline - The tendency of _all_ companies to eschew security as an optional extra rather than the cost of admittance to the marketplace - The historical tendency of big companies /not/ being burned to the ground after a massive hack makes security a lower priority to many businesses - The lack of a secure automatic update infrastructure (which also led to a recall), for which the vendor could have mitigated the vulnerabilities used - General ignorance about the risks associated with default/weak/hard-coded security credentials (e.g. passwords) Now let's look at each line item and discuss possible solutions: + Regulation could help here. Require third party security assessments on IoT/smart devices to be sold? It's not the most elegant solution, but it would be a vast improvement over the current state of affairs. + This is a cultural problem that makes application security painful in every business vertical. It takes a lot of one-on-one communication to resolve. Seeing large companies lose their shirts over security negligence might change the conversation. + This is a huge problem for all software. (See link below.) + Education. Regarding secure automatic updates: https://paragonie.com/blog/2016/10/guide-automatic-security-updates-for-php-developers https://paragonie.com/blog/2016/10/guide-automatic-security-... Now let's circle back to blame. What is the security industry responsible for? In my view: - Failure to communicate with other industries and professions, such as electrical engineering. - Failure to communicate with developers in general. - Failure to educate people outside the industry of our own conventional wisdom. - Failure to learn the challenges that others are trying to overcome so security can be on the same team rather than yet another obstacle. Through the blog posts on my company's website and a concerted effort to clean up Stack Overflow, I've been trying to educate PHP developers about better security practices for the past couple of years. It pays forward in spades. The rest of the security industry could do a lot of good if they did the same for their own respective communities. The only problem with doing that is: There's no effective and ethical way to monetize it. I make more money from helping e-commerce sites recover from being hacked by easily preventable mistakes than I ever have from making the software that powers 30% of the Internet more secure. https://paragonie.com/blog/2015/12/year-2015-in-review https://paragonie.com/blog/2015/12/year-2015-in-review Solving the core problems is good for society, but society doesn't reward this behavior. The security industry is broken because society is broken.
- FussyZeus 10y agoBut is IS dumb programmers (or more likely, dumb programmer management) causing this problem. Every IoT company has the same workflow: you take thing out of the box, hook up thing, use your smartphone to connect to thing with some app, and then it works. Everyone expects this experience and it's stupid because somewhere there is a hardcoded password. This is made more asinine by the fact that we've had extremely easy to use methods of establishing trust between devices on a permanent basis, but because that would add three steps to the setup process the marketing people refuse to let it happen. Nobody wants to spend the money to do it right, and nobody wants to spend the money on devices that do it right so here we are and I see no way out of this situation.
- X86BSD 10y agoHow about both. Programmers for really stupid shit like this: https://news.ycombinator.com/item?id=12756006 https://news.ycombinator.com/item?id=12756006 And managers for... well to this day I have found absolutely ZERO use for management.
- peterwwillis 10y agoIt's actually proof that internet architecture in general is broken. Well, not broken; it was broken, and then healed in a weird way so there's extra cartilage sticking out causing annoyances and won't move as easily anymore. The security industry has absolutely nothing to do with the existence of a botnet that can take down massive internet infrastructure. The security industry just puts bandaids on shitty products. It's the internet architects/designers that are responsible for botnets. In order to make the internet very simple, very compatible, and decentralized and distributed, the design allows a baby monitor to send arbitrary traffic to any device on the global network. There is no good reason for this. The reason is, anything else would be complicated, and complicated things become expensive and troublesome. But that's not a good reason to allow baby monitors to take down internet services. The solution would be to segregate critical equipment address and protocol by function, and to put in strict controls in all routers to prevent illegitimate traffic from reaching the wrong equipment. This would not only improve security, it would make allocation of address space and application ports make some kind of practical sense, and allow for improvements in the way applications communicate over the internet, to say nothing of improved management of traffic. But nobody's going to change the design, so whatever.
- clarry 10y agoHow do you tell illegitimate and legitimate traffic apart? In many cases the only difference between a DDoS and normal operation is the volume of traffic at the victim host.
- peterwwillis 10y agoI'm not sure, but like I said, separate first by address and function. This could work a hundred different ways. I could give examples but they'd be off the top of my head and not properly designed.
- clarry 10y agoI'm sure you could come up with a hundred different improperly designed ways off the top of your head. And it wouldn't work. And trying to design it properly, you'd probably come to the conclusion that it won't work (without causing massive disruption and breaking everything we've built so far).
- delecti 10y ago"Seatbelts don't work!" Says widow of man killed in car crash while not wearing a seatbelt.
- Silhouette 10y agoI suspect we've already lost at "Security Industry". Obviously defence in depth and dedicated security tools have their place in a networked environment, but you can't just outsource the problem or fix it with some bolted on extra. Some concerns simply have to be addressed as an integral part of whatever software or device is being made. If we don't do that, well, we've just seen the result.
- _pdp_ 10y agoThere is no cure for weak passwords.
- raesene9 10y agoOf course there is, in cases like this anyway. The problem here wasn't weak passwords, it was that all the passwords were the same, so it was trivial to automate the attack (well that and the devices had a command injection vuln.) That can be fixed by requiring users to set a unique password on setup, or shipping each device with a different password. This exact problem occurred in the UK where ADSL router manufacturers used to ship the same wireless WEP/WPA key on all devices, many got compromised, and now they ship with a unique key per device.
- maze-le 10y agoThis may be the cure in this case, but unique/automated passwords can go horribly wrong too. I once was the owner of a Vodafone EasyBox, a cheap and crappy router with pre-configured wlan wpa-keys. They looked randomly enough, but were a crude mixture of your mac-adress and router serial number[0]. It turns out, the bits of the mac adress (wich were always on the same digit) reduced the length of the unknown parts of the key to 16. The rest 65535-something key-bits could easily be brute forced. I just had the good fortune to configure my wifi- network myself, so I had to put in my own keys. Many other people didn't, and who could blame them, they were probably happy the thing worked in the first place... [0]: https://www.wardriving-forum.de/wiki/Standardpassw%C3%B6rter#Arcor_.2F_EasyBox_.2F_Vodafone https://www.wardriving-forum.de/wiki/Standardpassw%C3%B6rter...
- raesene6 10y agoSure there are bad implementations, but the principle that you can fix this kind of problem is there, just need to give the manufacturers enough incentive to spend the effort to a) implement this process and b) get a compentent security review to ensure it's not easily broken.
- _pdp_ 10y ago
- tptacek 10y agoThe security industry has been "broken" for as long as there has been a security industry. When I left Network Associates in 1999 to start a chat company, leaving the security industry to do something non-security was already a cliche. It's true, the 1U rackmount netsec industry does virtually nothing to prevent consumer electronics vendors from shipping terribly insecure code. I don't like the netsec industry either. But: so what? The reality is, very few companies are buying 1U rackmount snake oil (or Nth generation antivirus products like endpoint protection tools) to stop things like Mirai. We're not even talking about the same budget. The "security industry" is not in fact chartered with stopping things like Mirai. So Mirai is a weird complaint to level at it.
- ontoillogical 10y ago> When I was your age I was leaving the security industry before it was cool I'm not interested in leaving the security industry. I'd rather work to change it. I'm a millennial, I guess :) > The "security industry" is not in fact chartered with stopping things like Mirai. So Mirai is a weird complaint to level at it. No one "chartered" the industry to do anything. You're right, a metal box or an AV isn't going to prevent your IoT product from shipping with default creds on telnet, but don't you think the industry is complicit in drowning out the good advice to not do that in a sea of noise and then blaming the victims?
- tptacek 10y agoNo? I am having a hard time seeing any intersection between either of the major two branches of the security industry (PC security and network security) and IoT botnets. There's a major failure happening, but it's not attributable to the security industry. It's a failure of the computing industry as a whole.
- brians 10y agoIf there will always be crap out there, everyone's going to need an immune system. Long term, we can wish for a fancy adaptive one. In the short term, we probably just get an analogue to inflammation---something like the DDoS network scrubbing industry. That doesn't try to stop IoT botnets; it just extracts rent for keeping some people safe from them.
- raesene9 10y agoI don't see this as a failure of the "security industry" (I put that in quotes as it's very hard to say who is and is not part of that group) The simple fact is that there are very limited economic incentives for a company in the IoT space to spend money on security, and as a result they don't. It's not easy for an ordinary consumer to differentiate between a company who just says "security is our top priority" and one who puts meaningful effort behind that (e.g. there is a strong market for lemons here). Also there's no effective regulation which could substitute for that information. In other markets (property, consumer goods, food and drink) we have safety regulations as it was recognised that consumers can't effectively differentiate. In IoT and other areas of IT this doesn't exist, so there's nothing to stop insecure devices being sold. As to the "security industry" well there have been enough practitioners warning about this, to limited effect. Realistically there's a limited amount that can be done without some form of top-down intervention.
- herghost 10y agoIt's not the failure of the security industry, it's the success of market forces over the security industry. Normal folk want to consume new gadgets because that's the culture we have. So it's a race to put new gadgets with new features in front of people. Sure, as a customer I could insist on my manufacturer having taken security seriously and having their products thoroughly tested and reviewed and hardened and patchable and all that good stuff, but then I'm going to have to pay more money for my gadget than my buddy here who just wants to be able to flush his toilet from his smartphone. There is literally no consequence for manufacturers of poor quality products where the impact isn't directly impacting their own consumers, and so there's no market force that is going to address this. When viewed this way, it's a classic case of where we need government/legislature involvement.
- lawpoop 10y ago> Sure, as a customer I could insist on my manufacturer having taken security seriously and having their products thoroughly tested and reviewed and hardened and patchable and all that good stuff How exactly would you insist on that? Ask them? Aren't they going to tell you, "Yes, it's very secure, no worries"?
- lazaroclapp 10y ago> How exactly would you insist on that? How about "show me three different independent security audits by researchers or firms I trust who didn't find major issues in your product"? Sure, there needs to be a sizable group of people demanding that (and be willing to have it be the difference between a $500 and a $5K smart TV), but it is possible. For corporate IoT in certain settings, it might even be plausible.
- tajen 10y agoYou should be on top. Just as we have FCC approvals before you connect a device to 3G, landlines or to the power grid, we'll have to have approvals for all devices connected to the internet. And the top test of the list is a penetration test by a preapproved firm. Note that open-sourcing the firmwares would go great lengths in building a better world: Less spying, more upgradeability, more confidence in the tools, easier pentests and a legacy of new code for future generations.
- cellis 10y agoIm not a security guru, but I've thought of a couple solutions to the problem of botnets. 1) A consortium of manufacturers of IoT devices banding together and signing an "autopatch" or "autohack" agreement. This would be an open source, public hack-and-patch society that freezes out any manufacturers that don't agree to it. All customers would simply sign in their EULA that their devices are authorized to be "patched" by any means necessary if found to be insecure by the auto-hackers. 2) As botnets at the Mirai scale are now a matter of national security, make the NSA do its job and do roughly what is outlined in 1. Controversial, sure, but you can be damn sure that they already know about these unpatched devices and how to exploit them.
- jknoepfler 10y agoI don't understand why the lack of security in embedded devices is an indictment of.a 'security industry.' That's like 'drunk driving proves failure of the seatbelt industry.'
- _audakel 10y agoGreat example of how to promote your company. Provide genuinely insightful and useful information that will help people even of they don't use your product. It's almost like good karma.
- viraptor 10y agoI prefer when people do that without trying to discredit whole industry which wasn't even involved in the problem. If anyone remotely interested in security was included in the IoT production, we wouldn't be talking about Mirai.
- djrogers 10y agoThis is not a failure of the security industry - the security industry is targeted at the enterprise, largely not the host of the vulnerable IoT devices involved. Don't get me wrong, there are tons of ways in which the security industry fails (the biggest IMHO is buying/selling things that only get implemented in a half-@$$ed manner or not at all), but this is like blaming the Airline industry for a train wreck. Perhaps the real problem is that for home users there really is no security industry to speak of? A handful of features on WiFi APs that get turned off if they break your XBOX games, and maybe some desktop AV. That's pretty much it - and I'm not sure we can ever expect much more..
- yxhuvud 10y agoBlaming the security industry is wrong, but so is blaiming the users. If a faulty lamp catch fire, then it is the one who made the lamp that is at fault, not the user. Make the vendors responsible for the damages that their products create!
- michaelbuckbee 10y agoI think you are making a great point here: different sectors have different security needs. At the consumer level, I think users really need help from their ISPs. My provider (Cox.net) already emails me if they detect outbound activity matching virus activity. Though I can't say it doesn't make me at least a little nervous about their inspection of my traffic habits, this ISP level intervention is at least something concrete that could happen in the near term to blunt these types of attacks. For Enterprises, I see the big failing is mostly around the focus on external threats (APT+Scary Hackers) with no consideration for the much greater danger of internal threats [1]. This is the "dumb" stuff like someone quitting to move to a competitor and the day before they give notice they copy every file off the file server to a thumb drive "just in case they need it". Or even the new scary forms of user assisted ransomware. 1 - The guy that runs HaveIBeenPwned.com has a free course on this I've been sending around https://info.varonis.com/the-enemy-within https://info.varonis.com/the-enemy-within that explains it in terms an executive might understand.
- ChefDenominator 10y agoI have observed that "proof" should be translated as "evidence", and I generally think such article titles lead to pointless look-at-me hyperbole. Authors who fail to understand the important difference between those words will likely have nothing critically interesting to add to most discussions.
- Animats 10y agoAs I said previously, someone needs to bring negligence suits against some IoT vendors, wholesalers, and retailers. Start with the retailers, like Amazon. They'll find the supply chain for you as they try to pass the buck. It worked with hoverboards. There's a problem at the China end with crap low-end devices driving out the good ones. Here's a good example: solid state relays, useful little devices for safely switching AC power with a logic level signal. Look at this Fotek solid state relay on Amazon.[1] That's a counterfeit. Fake manufacturer name. Fake UL and CE marks. Here's UL's warning notice on counterfeit Fotek solid state relays, and how to recognize fakes.[2] There are lots of unhappy customers; the fake ones have been reported to overheat, melt, or stick in the ON condition. Every Fotek relay on Amazon that I can find is fake. The fakes are real solid state relays with grossly exaggerated power ratings. For real ones, cost goes up with power. The fakes all cost about the same regardless of nameplate power rating. Here's an especially bad one: a "100 amp" version.[3] The real Fotek, in Taiwan, doesn't even make a 100 amp version in that form factor - the terminals aren't big enough for 100 amps. The result is that nobody is selling legit solid state relays on Amazon. They exist; you can buy them through Digi-Key or Mouser. They cost about 2.5x the fake price. But Amazon has been totally conned. (The ones on eBay are fake, too.) Worse, if you're a legit solid state relay maker in China, you have a hard time selling. The counterfeits have pushed the price down too far. Back to hoverboards. There are now UL-approved hoverboards. They don't catch fire. Heavy pressure on China suppliers worked. That needs to happen with insecure IoT devices. [1] https://www.amazon.com/Frentaly-24V-380V-Solidstate-Arduino-Raspberry/dp/B017A1QUGO/ https://www.amazon.com/Frentaly-24V-380V-Solidstate-Arduino-... [2] http://www.ul.com/newsroom/publicnotices/ul-warns-of-solid-state-relay-with-counterfeit-ul-recognition-mark-release-13pn-52/ http://www.ul.com/newsroom/publicnotices/ul-warns-of-solid-s... [3] https://www.amazon.com/Industrial-FOTEK-Protective-SSR-100DA-control/dp/B017W7N7F8 https://www.amazon.com/Industrial-FOTEK-Protective-SSR-100DA...
- farnsworth 10y agoThat first one only has one review: "Sure." Five stars.
- hinkley 10y ago
- mjevans 10y agoOn the very sub topic of "we don't know how to write secure code"; yes, we actually do. Of course we know how to write secure code, code that meets a rigorous and well engineered design that eliminates invalid outcomes as a result. The problem is such code is slow and expensive to produce. Good, Fast, Cheep; pick (at most) two. Security cameras optimize for Cheep first and fast second, so of course we see issues like this.
- cloudjacker 10y ago> The major botnet of 2016 is simpler than the botnet of 1988. There’s something wrong in how we do security, and at Appcanary, we think it’s a complete lack of focus on the basics. Or a complete focus on making money. Capitalism has refined itself over 30 years, and firms realize that security is expensive, making products is a lot cheaper than it used to be, and even if you invested in security, there could still be something unforeseen that compromises your system. Nobody wants to be Sony or Microsoft and their litany of security woes.
- skoussa 10y agoI work in the infosec field and I think it is unfair to blame the whole industry. I think the whole technology field is to blame here (although I really don't like to play the blame game). By the way, I have been around the security industry for around 10 years, and the same exact conversation has been going on. 10 years ago it was the Web, then around 7 years ago it was Mobile, now it is IOT, several years from now, we are going to have the same conversation regarding a different technology unless we do something regarding the root causes. The root causes are the following: 1- Security more often than not is an afterthought. When you are trying to go to market, under tight deadlines, burning the night oil, nobody has time, energy or money to think about security. 2- The lack of security education by most of the stakeholders (upper management, product managers, engineers, etc) does not help and keep security a taboo, in most organization, nobody has the title of making the software secure. So it falls into nobody's lap 3- While, I have all the respect to the profession of honest sales, some salesmen ruined it for all of us, feasting on the lack of education mentioned above. Trying to sell tools/services as the silver bullet to the security problem, an idea that is very well received by someone who does not understand the problem and really looking for a silver bullet 4- At the end of the day, the real issue is that security is a cost center, there is no ROI for the business for doing security other than avoiding problems that "could" happen in the future. That being said, there are three classes for clients I have seen doing security: 1- Heavy losses: for banks for example, the risk of losing money is quiet real and tangible. Besides they (at least in the U.S) under heavy regulations to do so. But their real motivation is risk mitigation. 2- Regulations (worst reason to do security): such as the PCI industry, they have to do security checks to avoid fines. This category usually try to do the minimum to get by. 3- Proactiveness: hats off to this category, as they don't really have to do it other than they think that this is something that must be done. Solutions: 1- More education 2- More education 3- More education 4- Implement more security controls natively into frameworks (output encoding, entity frameworks, etc) and browsers (such as CSP policy, etc) 5- More fines for companies that don't really take the minimum amount of steps to ensure data confidentiality and integrity.
- pnathan 10y agoI'm fond of the idea of fines. Having seen what audits mean, I trust them about as far as I can throw a full-size African elephant bull.
- rini17 10y agoIf someone reputable was testing all these devices for such basic flaws and published the results, then IT managers could use that to back their buying decisions. That would actually cause vendors to listen. I don't think it is impossible to do, or even monetize such service.
- Pica_soO 10y agoThe basic idea of the state distributing policing to public vendors, who should apply it as they see it fit, after the customer-trader relationship already ended is broken.
- chubot 10y agoApparently the author of Mirai leaked the source code and even provided comments and build instructions. I found this a bit baffling. He seems immature and vain, because his motive is apparently to taunt someone with how smart he is, but the code is indeed pretty awesome and educational. It's a little sad that commercial software is so ugly and that black hat software is elegant (though I guess it has to be, because it's under rather severe "environmental pressures"). https://github.com/jgamblin/Mirai-Source-Code/blob/master/ForumPost.md https://github.com/jgamblin/Mirai-Source-Code/blob/master/Fo... At first, I was also kinda shocked that it had this simplistic list of hard-coded user names and passwords (mentioned in the article). But I guess I've worked in the software industry long enough that it makes sense. Computers are so ubiquitous and on reflection it's not a surprise that you can pull down hundreds of thousands of machines with this technique!!! Can anyone shed light on the economics of releasing source code? I would think this would make your botnet much less valuable. Apparently someone found a vulnerability in his HTTP parser, which I don't think would have happened without the source code. So did the author shoot himself in the foot for reasons of pride, or is there something else going on? https://github.com/jgamblin/Mirai-Source-Code/blob/master/mirai/bot/scanner.c#L124 https://github.com/jgamblin/Mirai-Source-Code/blob/master/mi... // Set up passwords add_auth_entry("\x50\x4D\x4D\x56", "\x5A\x41\x11\x17\x13\x13", 10); // root xc3511 add_auth_entry("\x50\x4D\x4D\x56", "\x54\x4B\x58\x5A\x54", 9); // root vizxv ...
- NickNameNick 10y agoThe best theory I've heard about the authors motivations is that after knocking Krebs offline, with a world record dos, they wanted to muddy the waters a little. By releasing the source code and letting everyone else fight for control of the botnet, it would be much harder for anyone to trace the original attack back to them.
- moron4hire 10y agoMaybe someone with a public level of accountability--say the government--should start an adversarial inspection and certification program. Think about how we don't let cars on public roads unless they pass inspection, to verify that they aren't a ticking time-bomb in the middle of the highway--or no more so than usual. Unlike vehicle registration, it wouldn't require you to have to do anything other than keep your system maintained. If you want to put your computer on the internet, be prepared to get port-scanned by the US Digital Service once a year/month/week/whatever, attempting to take your computer off the 'net. If it succeeds, then that's one machine that could have been--but now won't be--part of a botnet. ChoasMonkey as a public works project.
- youdontknowtho 10y agoThe security industry? Try the software industry. We produce software and systems that are insecure. Until someone assigns a cost to failing to provide secure software and systems it will continue to happen.
- rdiddly 10y agoSpeaking of a voice in the wilderness, any way we can stop saying stuff "is broken?" It's glib, imprecise, far too easy to say, and is becoming cliché. It's provocative kind of like clickbait. And it's self-evident - Everything exists on a continuum of "brokenness" a.k.a. entropy and is therefore at least partly "broken" at all times.
- wnevets 10y agoThe free market has decided security of IoT doesn't matter.
- dredmorbius 10y agoMarkets consistently under-assess complexity, in both value and const components. Simple systems are easy to assess and communicate. Complex systems are hard (expensive) to assess and communicate. This results in several asymmetries: 1. Complex systems are communicated in an oversimplified mode. 2. Asymmetries exist between buyers and sellers of products (Akerloff's "Market for Lemons". 3. Asymmetries exist for all parties over time in realising the long-term costs (or benefits) of systems. In the most pathological instance, a party (or parties) actively frustrate the process of widespread awareness of these costs -- lead, asbestos, tobacco, sugar, CO2, etc., etc. Corollary: security is a complex product.
- dredmorbius 10y agos/const/cost/
- finishingmove 10y agoWhat "security industry"? In how many companies nowadays is sitting and thinking things through an encouraged approach? It goes against the current economical values. The problem are not IoT vendors, the problem is money-driven economics.
- skywhopper 10y agoThe success of Mirai is hardly the fault of the security industry. The security industry has been howling about lax default device security for decades, and how dumb it is to put your TV directly on the Internet, much less your refrigerator or your lightswitch. The electronics industry is the correct target. The only way out of this mess is regulation of what types of devices can be sold and how they must be secured. The electronics industry and online retailers need to get together and figure this out and come up with a UL for IoT, or the government will step in and make them all a lot more unhappy.
- digi_owl 10y agoThe way i see it is that we are using general purpose computers to do the job of single purpose electronics. But a GPC will always remain a GPC, and thus they are susceptible to being re-purposed no matter the number of "safeguards" we put in place to prevent it.
- mrob 10y agoThis could be fixed by legalizing purely destructive hacking of IoT devices. To gain immunity from prosecution the hacker would need to demonstrate that the device is completely bricked and no remote access is possible. IoT manufacturers would then be able to post bounties for destruction of competitor's products and the free market would solve the problem very quickly. This will result in harm to third parties who did not act maliciously, but that's already happening now. With this change in law the total harm will probably be less because the problem will be solved for real, which will dramatically reduce or eliminate the possibility of "black swan" events causing very serious harm (eg. shutdown of critical infrastructure).
- unethical_ban 10y ago"As long as the thief drives my car straight into the ocean, it's ok for him to take it" I'm glad you're thinking outside the box, but that kind of "immunity", if it were ever to be authorized in an emergency (attacks on power grids lasting hours or days), it should only be carried out by the government with a warrant, and with the understanding that people may die or lose property due to the sudden, public destruction of millions of devices.
- mrob 10y agoIf you wait for that emergency then it's already too late, because any attacker competent enough to carry out that attack is likely competent enough to close the vulnerability they used to get access.
- ngneer 10y agoLANGSEC
- evilDagmar 10y agoThe Moral botnet doesn't have anything to do with the "security industry", largely because the vendors involved ignored each and every recommendation made by said industry since at least the 90's if not earlier. The blame for this debacle falls squarely on the heads of the vendors who produced these trusting (if not downright gullible) devices in the first place.
- SFJulie 10y agoJust remember how Feynman described how he was opening military safe during los alamos project (one of the most super highly sensitive project of WWII) : 25% of the safe where having default combinations. I guess we can draw a conclusion here: security assumptions about who the users are is not in sync with human nature. Security is failing the same way as architects would fail making the assumption stairs with one meter high steps are okay. IT security is failing because their model of human beings is plain and flat wrong, hence, computer security as designed by our brightest mind is wrong. Don't force feed to human requirements of fuck given they don't have.
- aaron695 10y agoEveryone seems to be making money to me?
- sirmiller 10y agoThe Mirai Botnet is proof that the internet (i.e. IP) is broken. We need trusted sender trails for packages. Now.