9 ms·
I'm the author of the Gizmodo post. Having covered IoT hacks for a few years, it's obvious that drastic measures would be necessary to convince manufacturers to
by adamclarkestes 9y ago
I'm the author of the Gizmodo post. Having covered IoT hacks for a few years, it's obvious that drastic measures would be necessary to convince manufacturers to build more secure products. While I'm not necessarily endorsing this hacker's methods, I do salute his taking a stand. It might land him in jail. But still, the mission is worthwhile.
- tptacek 9y agoDid you not have any input into this headline? It is a clear endorsement.
- adamclarkestes 9y agoMy editor thought it might be too extreme, but I was sure that careful readers would latch on to the tongue-in-cheek intentions. Maybe I was wrong. I still stand by the statement.
- deleted 9y ago[deleted]
- thomble 9y agoOh please. Your "editor" was probably like: "gr8 b8 m8."
- josefresco 9y agoI think the headline reads as personal, and therefore a lighter endorsement than something like "This Hacker is Our new Hero" or "This Hacker is a Hero".
- mnarayan01 9y agoFor those confused by this comment, the actual title of the piece is: "This Hacker Is My New Hero".
- josst 9y agoJust FYI you have a small mistake here: "So why did the Janit0r result to destruction". Should be "resort" I think.
- adamclarkestes 9y agoFixed. I will now install a dead rat under our copy editor's desk...
- wolly 9y agoI find the arguments for "taking a stand" quite weak. Normally with subcultures that break the law or in other ways inconvenience people the moral argument is that you're doing something that isn't available to you (often as a group) and your actions themselves are meaningful (often because it makes it available to you). I don't really see in this case how they (or mostly anyone) is unable to improve IoT (or general) security through other means or that the consequences of the actions themselves are any different from other forms of attacks on software (like credit card fraud, denial of service or ransomware). The arguments from the "hacker" gets especially weak when they conclude that consequences of breaking IoT devices is worthwhile, but the consequences of IoT devices breaking the Internet doesn't have the same effects. Even though you could argue that it's far harder for most people to influence overall Internet security than IoT security and therefor the moral arguments for breaking the Internet as a way of improving it should be slightly easier to make.
- nickpsecurity 9y ago"I don't really see in this case how they (or mostly anyone) is unable to improve IoT (or general) security through other means" Really? How about you show me the evidence that people are... through "other means"... improving IOT security of these devices enough that DDOS isn't a big problem any more. I'd love to hear what you've done to convince all the vendors to focus on secure devices instead of profit when targeting markets that will deliver profit regardless of security. Most of us in INFOSEC haven't been able to convince much past a subset of software and hardware developers to focus on improving security. The only time vendors ever delivered secure or safe solutions was when sound regulations were forced on them with a requirement they were followed before a purchase was made. That was TCSEC and DO-178B respectively.
- petra 9y agoThat's true. Altough i wonder: why didn't someone with deep security expertise, maybe ARM with it's mbed,created something developers can't harm, and on the other hand, issue a product label saying:"this is protected by our stack..." ? I could see that be attractive to some b2b buyers, attracting devs, further strengthening the value of said label , increasing marketshare and reducing costs, and creating a positive feedback.
- hectorr 9y agoHe's providing an economic benefit to society - internalizing (to consumers) the externality of IOT botnets. It's now on the consumers to further internalize to cost to manufacturers through product selection, class action, or both.
- 086421357909764 9y agoHow does your opinion change with Phishing attacks? I'm going to steal funds from businesses by phishing vulnerable people, because If I don't capitalize on it, then people won't understand the costs / risks.
- LinuxBender 9y agoThe person bricking IoT's isn't getting money from that. If they did, I would hope they or you did, I would hope each of you would donate to charities.
- 086421357909764 9y agoWhat they get is irrelevant, it's someone using their skill set to make others aware of a flaw. I would argue it's the exact same premise. I'm going to phish people & cause them a financial cost to teach them to be safe.
- jancsika 9y ago> What they get is irrelevant It's actually the main relevant part of the analogy. It goes to veracity. There's a person who gave a public talk about manipulating Bitcoins with weak private keys in order to alert the owners that they were vulnerable. But he did it in a way that verified to the owner he hadn't in fact stolen the coins (moving small portions around or maybe signing with the key, I can't remember). He also mentioned in the public talk that the owners of those Bitcoins were totally freaked out by this, and most were never convinced that he was acting in good faith (which is probably a smart assumption on their part). So the fact that he didn't steal the coins is completely relevant-- it's the very reason he could give a public talk on what is still grey area behavior. Your hypothetical thief, on the other hand, is clearly mendacious. You have him claiming, "If I don't capitalize on it, then people won't understand the costs/risks." That is clearly false from my real-world example above, and if he tried to give a public talk about how his theft benefited society he'd be arrested.
- kbuchanan 9y agoThis captures the essence of the type of activism that I so dislike — an unaffected, third party (a person who doesn't use your bluetooth lightbulb) taking the job upon himself to tell you what level of security your lightbulb should employ... By breaking it.
- anonnyj 9y agoI'll choose a boogeyman you can perhaps appreciate: You bluetooth lightbulb is enabling pedophiles with anonymity, and you may take the fall when you're mistaken as the source of the requests. (You can swap out the boogeyman with terrorists, spammers, credit card thiefs, etc)
- rblatz 9y agohttps://www.theguardian.com/technology/2016/oct/26/ddos-attack-dyn-mirai-botnet https://www.theguardian.com/technology/2016/oct/26/ddos-atta... Very few people that use the internet were unaffected by shitty IoT security. And that seems like it was just the start of it's capabilities. Something needs to be done to destroy these cyber weapons. If your stupid light bulb is recruited into a cyber weapon, then it should be prevented from harming others.
- bryondowd 9y agoIs it an unaffected third party, when your unsecured lightbulb is participating in a DoS that knocks out some service he's relying on?
- Etheryte 9y agoHow is anyone unaffected when IoT devices with bad security break the net?
- jerf 9y agoWe're not unaffected anymore. Mirai did a lot of damage to a lot of people. Very diffuse damage, sure, but a lot of damage. Note we've had worms and such for decades now and most of them don't deliberately break things. It's generally far more profitable to exploit the resources than simply destroy them. Brickerbot almost certainly wouldn't be if we weren't all getting affected.
- JustSomeNobody 9y agoEngineering needs to stop being subordinate to anything but top management (if at all). An MBA can always outrank an engineer's decision and that is a big reason why we have crap devices out in the field.
- mnm1 9y agoWithout labor laws to back something like this up, all it does is get engineers fired. Non-software engineering fields do have such laws, I believe. An MBA cannot make a civil engineer build a bridge that is unsafe because they want to save money. After all, it's the project engineer's signature on the final work. (Please correct me if I'm wrong.) On the other hand, a large proportion of startups are doing something illegal or unethical and the only recourse for the engineer there is to quit or be fired. In some egregious cases, that may be worth it. Mostly, it's not. That's how our labor system is set up. I've always said, if you want to kill someone, start a corporation. It's the easiest way to get have someone else do it for you and get away with it. Anything less than murder in business is not even a consideration (unless the business gets punished which it most likely won't be).
- ComradeTaco 9y agoI am a structural EIT. Industry focus on safety is paramount. Seniority is very much respected so there are almost no young MBAs and they exist almost exclusively at the corporate level. Only a full engineer can legally stamp off on the final drawings and the accompanying calculations and I've never really seen a business type ever try to interfere in that.
- LoSboccacc 9y agoKeyword: legally. Spftware is often built to the cheapest spec that'll sell. Even peacemaker are often carring vulnerabilities.
- nickpsecurity 9y agoAerospace regulates software and hardware. Software standard is DO-178B. Thanks to it, the systems get great quality assurance. A common thing that emerged from that are partitioning RTOS's that separate critical and untrustworthy stuff. They also usually have trusted boot. The cheapest CPU I saw supporting those was a Freescale one for $4 a piece in quantities of 100 units. So, yeah, even in softwarw one can do as you suggest. Multiple times it's been done with things improving across the board. In DO-178B, an additional effect is an ecosystem of tooling, reusable components, and consultants sprang up to make each project a bit cheaper and less risky.
- 086421357909764 9y agoWhat would your perspective be if I took a stance to secure your vehicle, or the power company, or any myriad of others simply because I chose to? What do you do when I change my logic to, well this is a ZERO DAY exploit, but you need to be patched, without understanding the complexities of your device or network. Which we all know QA takes a while because of variables. Look at any microsoft patch for evidence of that. Your argument makes it seem like if I decide to weaponize the Shadow Brokers toolkit to lockdown and secure networks around the globe, i'm ok because my intentions are good and manufacturers should have secure code without 0 days. What happens when a proprietary driver or component fails because of a change made to the kernel or the way it handles driver functionality? Now I've broken / disabled something because I didn't know the intricacies and instead chose to do what I thought was right. "No good deed goes unpunished"
- srcmap 9y agoA bit like my neighbor's door is wide open. Some teenagers are taking over it. Instead of just close/lock the door for my neighbor or call the cop, I use a bulldozer to level the house to the ground. (zero out the flash.) In theory, the "vigilante" can offer his service to device manufacturer to help remotely clean/update the devices instead of just simply wiping them off the net.
- 086421357909764 9y agoThe point is how do you know the vigilante's fix won't have adverse side effects? EDIT* I agree with the bulldozer analogy.
- mannykannot 9y ago> The point is how do you know the vigilante's fix won't have adverse side effects? While you have raised some valid issues, this is not one of them. Having an unsecured device on the internet has some very definite adverse side-effects.
- 9y ago