4 ms·
It's a little hard to distinguish worthwhile warnings from the near-constant din of finger-wagging
by oldmanjay 10y ago
It's a little hard to distinguish worthwhile warnings from the near-constant din of finger-wagging
- supergeek133 10y agoExactly, for as many legitimate problems I see posted I usually see double as mean fear-mongering stories.
- pdkl95 10y agoHow, exactly, are you identifying "fear-mongering stories"? Mislabeling real security issues as "fear-mongering" is how widespread security problems are created. When attacks can be trivially copied, even obscure security issues can become easily exploitable problems under attack from bulk exploitation tools.
- supergeek133 10y agoIt's a headline problem. Typically these issues are labeled as "all of IoT is terrible". For as many of these REAL security issues we face, there are many stories published that have no real-world impact. Examples: The story from defcon (or blackhat, cant remember which) about installing ransom-ware on your smart thermostat. The headlines were all "Hackers make thermostat ransom-ware" or "Your smart thermostat is now vulnerable to ransom-ware" A few points: - It required local access - It required an SD card reader - It also required the thermostat run a local HTTP server Another decent example were the SmartThings security holes from earlier this year: - It was mostly an oauth2 authorization issue (applications requesting grant types it didn't need) - The apps were actually independently developed (not ST official) and took some technical knowledge to deploy yourself - The rest were known security issues in the Zigbee protocol that SmartThings has little control over. Similar to this article. Or the botnet of cameras which is probably the most high-profile example and most relevant are labeled as "The IoT brought down the internet" That's a lesson for the makers of those cheap DVRs and Cameras, it was also a lesson in user documentation to avoid them doing stupid things. That's the only example in recent years I've seen that goes anywhere, but the problem is it's drowned out by nonsense and clickbait headlines.
- idlewords 10y agoHow... what's the sound of a finger wagging?
- oldmanjay 10y agoThe charitable response is that it was a metaphor. I would assume you understood that but it would mean you intentionally posted that terrible half-pun. I'd rather assume you just didn't realize it was a metaphor in the first place.
- geuis 10y agoVery slight swooshing.
- ChuckMcM 10y agobut I want the light saber sound when I wag my finger.
- jkestner 10y agoYou can hear a tsk-tsk-tsk in the joints if you listen closely.
- tptacek 10y agoWhat's great about this argument is how versatile it is. Climate change got you down? How about deforestation, or antibiotic overuse? Tired of people telling you not to write web applications in C? Your one liner seamlessly shuts down discussion in any of those debates! In fact: the finger-waggers have been right about this issue since approximately 1988, when Paul Graham's friend shut down much of the Internet with a tiny C program that shouldn't have been possible to write back then, but is in fact still possible to write in 2016.
- jlgaddis 10y agoFortunately, folks "woke up" a bit as a result of that event (granted, security wasn't really a concern at that time). Unfortunately, it was relatively quickly forgotten and it took another 10-15 years before security really became something that was looked at as anything other than an inconvenience or an impediment. I'm becoming more and more convinced that nothing is going to change (with regard to overall security in general) until we have some huge event that negatively impacts a large portion of the population in a major way. Until then, things will continue as they are, and security won't be taken seriously. I'm ready for the 2016 version of the 1988 sendmail worm (or perhaps something with the "average user"-visible impact of the 1990 AT&T crash), just to "get it over with" and get us moving forward.
- rhizome 10y agoThe lack of liability changes in the wake of the Target breach (at the very least) means that companies can foist whatever security model they feel like upon the market without any possible repercussions. You basically have to be VW compromising a highly regulated industry for there to be any negative effects beyond PR, and internet-accessible data is so far completely unregulated.
- the_unknown 10y agoAnd even then the benefits to ignoring the warnings for companies is still pretty powerful. VW may have been caught and punished in the US but here in Canada they are still dragging their feet with any mention of compensation to victims and our courts are letting them. "We can't keep driving these and feel good about ourselves. So something needs to be done and I just want an answer.… It's not about the initial mistake — it's what you do to make things better." http://www.cbc.ca/news/canada/toronto/vw-emissions-1.3708372 http://www.cbc.ca/news/canada/toronto/vw-emissions-1.3708372
- djsumdog 10y agoZigBee as a protocol was broken years ago. I saw a presentation at Ruxcon in Melbourne. The researchers have a pretty decent paper on it: http://cs.dartmouth.edu/~vibhu/wireless/PIPExploits.pdf http://cs.dartmouth.edu/~vibhu/wireless/PIPExploits.pdf Basically control frames run in the same band as the payload data, so if you put a ZigBee header half way down your packet and cause some noise, the inside application data turns into a new packet header. You can't do this on 802.11b/g/n/etc because the control data is send out of band from the application layer data. It's considerably different from the attack mentioned in this post, but we've know at least that the protocol has been broken for years.
- noselasd 10y agoWifi is far from immune from this: https://www.youtube.com/watch?v=euMHlV6MNqs https://www.youtube.com/watch?v=euMHlV6MNqs
- InclinedPlane 10y agoIt really isn't. Anyone in tech with two braincells to rub together could tell you that security is a hard problem. And yet there has been a consistent pressure in IoT enthusiasm which rested on the premise that security was a solved problem. Everything about IoT went against decades of hard-won wisdom about internet security: lessen your surface area, keep as much stuff off the internet (behind firewalls) as possible, constant vigilance through patching and staying up to date on vulnerabilities is important, use strong credentials to secure anything that could ever be reached from the internet. In short, that internet security was a big and difficult job, and a constant battle that required careful risk management. IoT enthusiasts dismissed all of that and never had a good counter-argument, just the insistence that nothing, not even security issues, should get in the way of how cool IoT devices could be. It was obvious that this would be a problem. And every security expert made mention of it. There is no "oops, well how were we to know?" about it.