6 ms·
IoT seems hopeless because - There are so many different kinds of devices and different hardware - Vendors want to maximize profits like everyone else, which
by patrickmn 9y ago
IoT seems hopeless because
- There are so many different kinds of devices and different hardware
- Vendors want to maximize profits like everyone else, which entails making new devices all the time, and ending support on the last model fairly quickly (typically within two years,) but consumers regularly keep their devices for more than two years.
- Hardware vendors historically were not software vendors. For many IoT makers, this is their first real foray into software. The mistakes being made are amateurish, at a level that we saw on PCs in the mid-90s.
- Although there are some IoT standards, they're mostly concerned with communications, not the operating system. It feels like we're still 5+ years off from something as basic as automatic updates being a given (even just notifying users that an update is available and allowing them to easily install it is a challenge currently.)
Two things that are really bothersome:
- A huge number of IoT devices don't need the 'I'. They are perfectly capable of serving their purpose without an Internet connection (e.g. over Bluetooth,) but a huge attack surface is added to make you able to configure the device via a central website, or simply to monetize usage data.
- It is futile to trust each vendor to have the security expertise to lock down every device. An "IoT operating system" would be highly desirable, but there is nothing anywhere near real world implementation, and given the heterogeneous of hardware components it doesn't seem likely something non-Linux-based will come along.
Brickerbot is hostile and aggressive and shouldn't be necessary, but maybe it is. That's beside the point, though: Nobody has to be given permission to brick insecure IoT devices. Vendors don't feel it where it hurts (the bottom line,) and consumers increasingly just don't care (studies show people have grown accustomed to security incidents -- "it happens to everyone and everything; replace it and move on, there's nothing you can do")
Hacks made Microsoft shape up in the 90s and early 2000s, but Windows has only become actually secure since after Vista. Maybe just don't buy IoT devices for another 5-10 years, or at least put them on a separate vlan.
There are a bunch of groups trying to spread the word, but it doesn't seem many vendors are listening (or if they are, they don't have the capability to really secure their devices.) We've had some success with Securing Smart Cities working with local and state governments, and trying to address some of these issues before hilariously insecure IoT hardware becomes ubiquitous in cities/related to critical infrastructure: http://securingsmartcities.org/ http://securingsmartcities.org/
It's hard to see how it's not going to get much, much worse before it gets better.
- XorNot 9y agoLinux is very secure. The problem is linux is general purpose and that means it can do a lot of things. You don't need "non-linux" (and it would only help a little) - you need a set of sane defaults which eliminate attack vectors.
- patrickmn 9y agoLinux (as in distributions, homegrown or not) has "ok" security. But unless vendors go through a lot of steps to both lock it and what runs on it down, and make sure issues are addressed in a timely manner, it's not. The key will likely be something like Android, that's based on the Linux kernel, but locks the vendors into some notion of a safe environment, and applies updates in a timely manner (the Linux kernel still has frequent critical security fixes.) (Having vendors be able to articulate what the devices should be able to connect to or do, and having the OS/runtime enforce that would be a huge step forward.) But Android itself is also insecure primarily due to fragmentation and end-of-lifeing, hence the feeling of hopelessness.
- tajen 9y agoWant to create a startup? Create an SIoT certification and a Linux distrib which provides all services by default and in a compliant manner.
- Klathmon 9y ago>A huge number of IoT devices don't need the 'I'. They are perfectly capable of serving their purpose without an Internet connection (e.g. over Bluetooth,) but a huge attack surface is added to make you able to configure the device via a central website, or simply to monetize usage data. I always feel the need to disagree with this. The biggest "value add" in most of my "connected" stuff is the fact that I can access and manage it from outside the home. Z-Wave light switches are nice, but being able to turn them off when I forgot to after i've left is a huge bonus (and taking it a step further and tracking my and my families phones and turning them all off when nobody is home automatically). A thermostat I can control when I'm on the couch is a convenience, but a thermostat that notices when I'm at work or the store or a friends house and turns off during that time saves tons of money and energy. A garage door that I can control from anywhere in my house is normal, but a garage door that I can have ensure it's closed when i'm not home, and that I can open for a friend that showed up to my house 20 minutes before I did is awesome. I really do think that the "I" in IoT is absolutely necessary (in many cases, not all), but I agree with the rest of your points. (before people start commenting on the tracking stuff, it's all implemented on a home-server where the phones literally "phone home" to that server, nothing is processed outside the house)