15 ms·
How to force manufacturers to take IoT security seriously?
- DrNuke 9y agoFor what I see, this is a problem for the consumer market on one side and for the small manufacturers on the other. Big industrial players like General Electric, Bosch, Phillips, etc. are deep in this already with their QA protocols and their own software platforms, think of Predix.io. Nothing more than another line or an extension of home / office / factory appliances for them.
- patrickmn 9y agoIoT seems hopeless because - There are so many different kinds of devices and different hardware - Vendors want to maximize profits like everyone else, which entails making new devices all the time, and ending support on the last model fairly quickly (typically within two years,) but consumers regularly keep their devices for more than two years. - Hardware vendors historically were not software vendors. For many IoT makers, this is their first real foray into software. The mistakes being made are amateurish, at a level that we saw on PCs in the mid-90s. - Although there are some IoT standards, they're mostly concerned with communications, not the operating system. It feels like we're still 5+ years off from something as basic as automatic updates being a given (even just notifying users that an update is available and allowing them to easily install it is a challenge currently.) Two things that are really bothersome: - A huge number of IoT devices don't need the 'I'. They are perfectly capable of serving their purpose without an Internet connection (e.g. over Bluetooth,) but a huge attack surface is added to make you able to configure the device via a central website, or simply to monetize usage data. - It is futile to trust each vendor to have the security expertise to lock down every device. An "IoT operating system" would be highly desirable, but there is nothing anywhere near real world implementation, and given the heterogeneous of hardware components it doesn't seem likely something non-Linux-based will come along. Brickerbot is hostile and aggressive and shouldn't be necessary, but maybe it is. That's beside the point, though: Nobody has to be given permission to brick insecure IoT devices. Vendors don't feel it where it hurts (the bottom line,) and consumers increasingly just don't care (studies show people have grown accustomed to security incidents -- "it happens to everyone and everything; replace it and move on, there's nothing you can do") Hacks made Microsoft shape up in the 90s and early 2000s, but Windows has only become actually secure since after Vista. Maybe just don't buy IoT devices for another 5-10 years, or at least put them on a separate vlan. There are a bunch of groups trying to spread the word, but it doesn't seem many vendors are listening (or if they are, they don't have the capability to really secure their devices.) We've had some success with Securing Smart Cities working with local and state governments, and trying to address some of these issues before hilariously insecure IoT hardware becomes ubiquitous in cities/related to critical infrastructure: http://securingsmartcities.org/ http://securingsmartcities.org/ It's hard to see how it's not going to get much, much worse before it gets better.
- XorNot 9y agoLinux is very secure. The problem is linux is general purpose and that means it can do a lot of things. You don't need "non-linux" (and it would only help a little) - you need a set of sane defaults which eliminate attack vectors.
- patrickmn 9y agoLinux (as in distributions, homegrown or not) has "ok" security. But unless vendors go through a lot of steps to both lock it and what runs on it down, and make sure issues are addressed in a timely manner, it's not. The key will likely be something like Android, that's based on the Linux kernel, but locks the vendors into some notion of a safe environment, and applies updates in a timely manner (the Linux kernel still has frequent critical security fixes.) (Having vendors be able to articulate what the devices should be able to connect to or do, and having the OS/runtime enforce that would be a huge step forward.) But Android itself is also insecure primarily due to fragmentation and end-of-lifeing, hence the feeling of hopelessness.
- tajen 9y agoWant to create a startup? Create an SIoT certification and a Linux distrib which provides all services by default and in a compliant manner.
- Klathmon 9y ago>A huge number of IoT devices don't need the 'I'. They are perfectly capable of serving their purpose without an Internet connection (e.g. over Bluetooth,) but a huge attack surface is added to make you able to configure the device via a central website, or simply to monetize usage data. I always feel the need to disagree with this. The biggest "value add" in most of my "connected" stuff is the fact that I can access and manage it from outside the home. Z-Wave light switches are nice, but being able to turn them off when I forgot to after i've left is a huge bonus (and taking it a step further and tracking my and my families phones and turning them all off when nobody is home automatically). A thermostat I can control when I'm on the couch is a convenience, but a thermostat that notices when I'm at work or the store or a friends house and turns off during that time saves tons of money and energy. A garage door that I can control from anywhere in my house is normal, but a garage door that I can have ensure it's closed when i'm not home, and that I can open for a friend that showed up to my house 20 minutes before I did is awesome. I really do think that the "I" in IoT is absolutely necessary (in many cases, not all), but I agree with the rest of your points. (before people start commenting on the tracking stuff, it's all implemented on a home-server where the phones literally "phone home" to that server, nothing is processed outside the house)
- sedky 9y agoIoT is going to change the world, so it's great to tackle this issue while it's in a premature stage
- passivepinetree 9y agoHere's a much more descriptive/informative article (linked to in the original article): https://arstechnica.co.uk/security/2017/04/rash-of-in-the-wild-attacks-permanently-destroys-poorly-secured-iot-devices/ https://arstechnica.co.uk/security/2017/04/rash-of-in-the-wi...
- cm2187 9y agoIn a way it is a bit unfair to IoT manufacturers. The problem is that to make something secure today, you need to be a network protocol specialist, a linux specialist, an expert cryptographer, etc. And guess who are IoT designers? Either a low level technician in a big western company or a guy hacking stuff together on the side of a factory floor in China. To me it is unreasonable to ever expect that all of them will be linux specialists, expert cryptographers, network specialists, etc. Fundamentally we are at the convergence of software and hardware, but the software is too complicated, give people too many ways to shoot themselves in the foot. I'd argue we need better software, not IoT manufacturers sinking ressources in hundreds of unrelated expertises.
- franciscop 9y agoThis is giving too much credit to IoT manufacturers as posing it as too difficult. Truth is, in most cases absolutely nothing is done to keep them secure (quite the opposite). To drive a car or keep people's Credit Card information you need certain certification. What makes no sense for me is to assume that keeping kids records on a public DB because someone has no clue on what they are doing is reasonable (for example). Or that needing an internet connection for turning off your heater is reasonable. We need to understand IoT is not a toy, we should require certification, fines or both.
- delecti 9y agoWe're reaching a point where it really doesn't matter why a given company isn't capable of making a bulletproof software addition to their hardware. When cars were giant steel death traps, car safety standards improved. You probably couldn't sell most 50's era cars today because of it. Similarly, I don't think it's unreasonable to hold IoT manufacturers accountable for releasing blatant security vulnerabilities into the wild (like that webcam that DDoS'd all those sites). This isn't an "aww, growing pains" kinda moment of care for the poor budding IoT industry. They need to realize that they must be held accountable. Edit: "bulletproof" isn't even what's being asked, but putting some thought into the security of their IoT devices is something we must demand of manufacturers
- 9y ago
- franciscop 9y agoThe title IMO is clickbait in the way of "discover how ___"; I'd change it to: "Bricking IoT devices gives incentives for better security".
- herghost 9y agoI agree. Updated.
- runeks 9y agoI think the morality of this issue is extremely interesting. A single insecure IoT device isn't a problem at all, but in huge quantities they become a form of Internet weaponry. Imagine if white hats were given legal immunity to hack devices that are easy to hack (for some definition of "easy") and, for example, replace the firmware with something that flashes some red text reading "contact manufacturer for replacement", and simultaneously closing the security hole in of which they came in the first place. This would be a sort of middle ground, giving consumers a minor annoyance rather than a bricked device, but still leveling the playing field between white hats and black hats. Perhaps adding a $1 bounty per device for the white hats, paid by the device manufacturer. Then the manufacturer would be forced to purchase insurance, who would want to look at the security of the software before giving a offer on the policy.
- inetknght 9y agoThis insurance concept is and interesting idea, I think. Unfortunately, insurance is all about risk management. In layman's terms: why bother worrying about security when you can just buy insurance for it. Then they'll pick up the tab for any problems, right?
- imgabe 9y agoInsurance can be a powerful force for creating standards. Most of the building codes in existence were created by the insurance industry. The NFPA (National Fire Protection Association) was originally sponsored by a collaboration of insurance underwriters. [1] Insurers want to make sure that a building meets the code before offering insurance on it. If a building collapses or burns down and it is later shown that it was not built to code, the insurance policy will be void. I imagine similar incentives would hold for IoT security. The insurance would be contingent on the manufacturer following all available best practices to show that they did all they could to make the device secure. [1] http://www.nfpa.org/about-nfpa/nfpa-overview/history-of-nfpa http://www.nfpa.org/about-nfpa/nfpa-overview/history-of-nfpa
- Zenst 9y ago
- tabeth 9y agoI know it's kind of a rhetorical question, but I think the answer is obviously: make it cost them significant amounts of money if they do not. So, the question then becomes, how do you make it cost them significant amounts of money?
- keyme 9y agoHere's an idea: There exists an FCC ID for every device that uses the RF spectrum. Similarly, there should be a similar required license for any device/product that operates on the Internet. The license should be easy to get initially (basic examination by 3rd party). However, once the product is out on the market, if it is shown to be demonstrably broken (insecure), the license is revoked. It now becomes illegal to operate or sell the product as-is (both for user and manufacturer). It now has to be disconnected from the Internet (or the user and manufacturer face a fine). Devices that are produced in very low quantities will be exempt from this (prototypes, specialty equipment, etc). This is similar to the mandatory safety checking of a motor vehicle. A cop pulls you over since your car mirrors are broken? You need to fix them before its legal to drive. Some one finds out that all models have a fatal life-endangering flaw? It is now both illegal to drive them, and to sell new ones (as-is). Note that in this case, manufacturers will always foot the bill and do a recall. I get that this is extreme. I don't see how anything else would work, though.
- StavrosK 9y agoI like this quote I saw here: > The "S" in "IoT" stands for "Security".
- Razengan 9y agoFrom another IoT comment [0] that I just posted: • Develop a standard interface/protocol for integrating IoT devices with the major mobile operating systems: • Upon unboxing an IoT device and first power-on, require physical contact (via NFC?) with user's primary smartphone/wearable, and register the device with the user's third-party cloud account (e.g. Apple's iCloud/HomeKit). • Only allow control of the IoT device from the smartphones/wearables that are signed into the user's iCloud/Google/Microsoft/etc. account. • Web interfaces for IoT control should require two-factor authentication on the user's smartphone/wearable, again like the web interfaces for iCloud/Google/Microsoft accounts. • Expose a different set of controls based on the user's physical distance from the IoT device, and the level of authentication on the controlling phone/wearable. For example: To unlock your front door you'd have to be standing right there (similar to unlocking a MacBook with the Apple Watch) but you could turn the lights on/off from across the world if you've unlocked your phone and entered your iCloud/Google/Microsoft password – and only from that phone. • Sharing control with spouses/family could be similar to how Family Sharing for the App Store currently works; set a level of access on each IoT device for each member, and fallback on asking the family "admins" for permission. No doubt there must be some non-apparent holes in this, but just throwing an idea out there. [0] https://news.ycombinator.com/item?id=14077965 https://news.ycombinator.com/item?id=14077965
- kbart 9y ago" Upon unboxing an IoT device and first power-on, require physical contact (via NFC?) with user's primary smartphone/wearable, and register the device with the user's third-party cloud account (i.e. Apple's iCloud/HomeKit)." Sorry, you lost me here. The last thing we need right now is another database of users' personal information. Why every gadget should be attached to my personal phone? "Only allow control of the IoT device from the smartphones/wearables that are signed into the user's iCloud/Google/Microsoft/etc. account." No again. It's enough Google owns my phone and email, I don't want it to own my home. What happens when Google's algorithm decides to ban you for no apparent reason (there are plenty of such horror stories around)? Tl;DR if that's the price to pay for IoT security, I'm resorting back to "dumb" devices or going to live in woods.
- 9y ago
- shad0wca7 9y agoThe healthy technology market will force IoT manufacturers to take security seriously. It is not the job of a government to punish a corporation for failing to implement what should now be basic tenets of product quality and suitability. The loss of customers and reputation should a major security concern arise is a serious market driver and calls for regulation will only ensure that nobody does anything until a multitude of governments agree on a standard. As further food for thought, do you honestly trust the government to make the best choices for your security as a private citizen?
- vog 9y agoI don't buy that argument. If "customers and reputation" were sufficient, we wouldn't need regulations on the safety of e.g. medical stuff, food and cars. (And history, as well as comparison with other countries, confirms that we do need those.) Whenever one needs to establish a minimum of quality (and this is what that's ultimatively about), establishing laws mostly works, while trusting the market mostly fails. Markets are good at many things, but are really bad at establishing a minimum of quality (or provision with basic supplies, for that matter).
- Gracana 9y ago> The loss of customers and reputation should a major security concern arise The potentially nice thing about regulation is that you can have some level of trust in a compliant manufacturer. In your example, customers don't know anything about the security of their chosen vendor until a breach happens.. At which point, presumably they leave that manufacturer (and they fix their shit or die), and go to a new manufacturer who hasn't had a breach yet, or has used PR expertise to hide their mishaps, or... maybe they are actually secure. But who knows? Customers don't have the details they need to do anything but hop about randomly between manufacturers.
- Bartweiss 9y ago> The healthy technology market will force IoT manufacturers to take security seriously. What? It might force companies not to bleed user data, yeah - people got pretty upset about the dolls spying on their children. But "enabling a DDoS" is a textbook externality. It doesn't hurt the device buyers appreciably, most of them don't even know it's happening, but it causes lots of harm to someone who didn't contract with the company. More broadly: do you see any evidence at all that the market is actually solving this? It's pleasant to say an efficient market would handle this, but the market we actually have is one where people sell broken products to customers who pay before the flaws are revealed, then move on to a new company name if their reputation gets bad enough. Add in overseas production so that you can't even sue if the seller violates a contract, and the real-world market isn't making any progress on this.
- ziikutv 9y agoWould it be worth an effort if there was an open source protocol of secure communication of IOT devices? For example, many solutions use MQTT, why not make a secure TCP/UDP one by implementing one of the higher layers in OSI stack?
- AnonNo15 9y agoBy aggressively exploiting insecure devices and maximizing damages to the end customer. Either IoT market will die because of this or the IoT will become IoST - internet of secure things.
- Zenst 9y agoI would like some kind of standard for testing that is recognises, in much the same way the FTC tests radio related items for compliance. Which reminds me that it is not a new issue and a read of few years back raises concerns for IoT and security, by the FTC: https://www.ftc.gov/system/files/documents/reports/federal-trade-commission-staff-report-november-2013-workshop-entitled-internet-things-privacy/150127iotrpt.pdf https://www.ftc.gov/system/files/documents/reports/federal-t...
- bitwize 9y agoLiability. Liability, liability, liability.
- jpalomaki 9y agoFor consumer devices the solution could be the consumer protection legislation. For example in EU the manufacturers/sellers are responsible for the devices after the sale. The exact time is not defined, but I believe for average consumer electronics 2 years is kind of minimum. During that period the manufacturer is responsible for defects in the products. The responsibility means they need to fix them, provide new (working) gadget or provide financial compensation. If we would defined that device with a known security vulnerability is broken, the manufacturers/resellers would need to take action. Suddenly there would be direct financial consequences for shipping broken devices for which updates don't exist. I'm sure this would quite quickly lead to manufacturers putting more effort on providing updates and maybe even to proactively preventing security issues.
- dwheeler 9y agoBricking devices is unlikely to help; the manufacturer already got his money. Indeed, economics are the fundamental problem - the manufacturer has zero incentives to do anything correctly. Laws can't solve all problems, but I think they could help. See "What laws should be created to improve computer security?" - https://www.dwheeler.com/essays/law-security.html https://www.dwheeler.com/essays/law-security.html - because I think some could help.
- ardiri 9y agoeasy - educate them. http://ardiri.com/blog/utls_defining_lightweight_security_for_iot_part_10 http://ardiri.com/blog/utls_defining_lightweight_security_fo...