3 ms·
"Assuming a competent user" is absolutely not what IoT is about, it shouldn't be what most of our decisions as engineers should be about. I don't want to have t
by cmdkeen 9y ago
"Assuming a competent user" is absolutely not what IoT is about, it shouldn't be what most of our decisions as engineers should be about. I don't want to have to be a "competent user" for my fridge, lightbulbs, sex toys - i.e. everything is potentially going IoT.
Separately, no - attacks like CSRF will quite happily be routed and compromise an incompetently designed IoT device.
- indigochill 9y agoI was thinking about blocking all traffic routed for the IoT device which comes from any address outside a set of explicitly trusted sources (such as the vendor's service and the user's smartphone or something). Then attacks like CSRF and default admin credentials become a moot point unless those trusted sources become compromised.
- cmdkeen 9y agoThat's how CSRF works - I get you to communicate to the device from your "trusted" smartphone or other device. There is nothing you can do at the routing level to protect against it. It is entirely up to the endpoint receiving the request to have implemented proper CSRF protection against attacks. CSRF has been around since 2001 and is in the OWASP top 10. It would be absolutely valid for regulators to require reasonable steps to be taken to prevent its abuse, along with similar attacks.