4 ms·
Ring stored WiFi credentials in plaintext on their video doorbells -- would you say it requires a cryptographer, a network specialist and an embedded device exp
by YCode 9y ago
Ring stored WiFi credentials in plaintext on their video doorbells -- would you say it requires a cryptographer, a network specialist and an embedded device expert to know that was a terrible move for a home security device you can walk up and physically rip off the outside of someone's house?
IoT manufacturers don't have to contract Linus Torvald to review their code, but it's entirely reasonable to expect IoT manufacturers to use existing best practices to secure these products.
- patcheudor 9y agoI would say, based on my experience that indeed it does require some level of specialization which most don't have today. I'm fighting with an IoT manufacturer right now because they ship the same root private key on every one of their devices. This is a pretty simple concept to understand: "Are all your device privates derived from the same key? Do you ask your users to install your public root to get past security warnings?" Yet they clearly don't understand PKI 101 and think what they are doing is completely appropriate because they are "following standards" while of course missing the bigger picture entirely.
- Bartweiss 9y agoYeah, these are not subtle embedded-systems bugs were talking about. These are frequently things that would make any halfway-experienced programmer or sysadmin refuse a release. If your security failure gets revealed and the entire software industry screams "what were you thinking?!", you don't get to plead that finding the bug was too tricky and complex. Hell, the Ring issue wouldn't even require one direct employee to avoid. You could solve that in a 30 minute call to an "is this obviously terrible?" hotline.