9 ms·
We're Surrounded by Billions of Internet-Connected Devices. Can We Trust Them?
- stopadvertising 7y agoEvery time I try to buy some device that is LAN only and doesn't talk to the net, ever, I usually find zero options or few crappy, expensive choices. Why anyone would install a camera that then talks to some corporation's cloud is beyond me, I have zero interest in that.
- ohazi 7y agoThe problem is that LAN only can't be verified as long as that LAN also has a route to the public internet. It could be LAN only for the first week so that it passes your initial smoke test, and then goes on to do whatever it wants. Or a firmware update could add new mothership pinging features. If you want LAN only, you really need to put the device on a LAN that is actually isolated, and use a trusted device to bridge that gap so that you can shuttle commands and responses from your actual network. I cobbled together my own system that works kind of like this using a raspberry pi and hostapd, and it works quite well for most things.
- mikestew 7y agoIf you're looking specifically for cameras, go get some Foscams, and use something, anything but the software that comes with them. I use a Synology NAS that can talk to cameras, but there are tons of other options that can talk to generic cameras. The only time the cameras have any interaction with the internet is when the Synology decides to send the stream to my phone. As far as the cameras know, there is no internet. And if you dig around and aren't all that choosy on features, you can often find Foscams on close out or otherwise dirt cheap. Some I have were $35, with panning; no optical zoom at that price, though.
- ryeights 7y agoBetterridge's law of headlines strikes again: https://en.m.wikipedia.org/wiki/Betteridge's_law_of_headlines https://en.m.wikipedia.org/wiki/Betteridge's_law_of_headline...
- ZenModeRy 7y agolol nice share
- deleted 7y ago[deleted]
- CapitalistCartr 7y agoIOT devices use standard, commonly available boards and chips, which are meant for widely varied applications, so offer wifi/Internet connectivity easily. So companies can add that "feature" painlessly by applying a snippet of (usually OSS) code. And collecting all the customer data they can is a bonus. No penalty of zero security, major upside if they sell it. This is dangerous to all of us, even if you don't own any IOT devices.
- wil421 7y agoMy brother and father in law bought a bunch cheap WiFi security cameras off of amazon. People online were complaining they phone home all kinds of stuff to Chinese IPs. My father in laws other cameras are Nest which phone to Google but it’s a selling point. I was going to put the Chinese cameras on a subnet but I don’t want to complicate his network. My father in law has 3 routers with 3 WiFi networks competing with each other; office, living room and outside but that’s a story for another day...at least I got him to replace it with a UniFi AP. I like UniFi protect because all the data stays at my house and their cameras are strictly no subscriptions.
- blacksmith_tb 7y agoI have three Wyze cams, which pretty much fit the bill of "cheap WiFi security cams which phone home to Chinese IPs". Though you can flash them with other firmware, if you want to control that. Personally, being in the US, I am less worried about Chinese companies sharing my data with US corps or government agencies (that doesn't seem too likely, somehow) but I would certainly be more nervous if I lived in the PRC. I suppose there's still the possibility they could be compromised to try attack other machines on my network, but those aren't wide open.
- jandrese 7y agoMaybe it wouldn't be a bad idea to blackhole those IP ranges on your router? Maybe you're not afraid of the PRC company directly, but who says they aren't going to try to make a buck selling your data to whomever asks?
- deleted 7y ago[deleted]
- pjc50 7y agoI don't think they can be trusted to be either secure or reliable or even supported. Any of them could be remotely disabled at any time as the parent company goes out of business. On the other hand, at the moment they're mostly in frivolous devices. As they become ubiquitous this is going to demand EU-level intervention, just like the existing WEEE directive against lockout chips on printer cartridges. Americans will be stuck with caveat emptor levels of consumer protection.
- jodrellblank 7y agocaveat the neighbour of the emptor, whatever that is in Latin. Your neighbour’s video doorbell will have the easiest time picking up on your face, but your neighbour’s cloud WiFi AP will surely see your WiFi devices coming and going in WiFi range through the day, and how long will it be before Siri is listening to your upstairs neighbor’s footsteps and telling you they’re unusually quiet for this time of the week and maybe you should check on them in the mandatory gig economy of social care?
- pjc50 7y ago> mandatory gig economy of social care? More likely the Ring camera will spot someone that's not in the national Amazon facial database and urge you to report them to ICE.
- ben_w 7y agoA WiFi hotspot with enough antennas can be run as a wall penetrating radar and measure pose, heart rate, and breathing, so a white-hat system would call the ambulance well before any humans could reach the scene even from the next apartment in the same corridor. I’m more worried about blackmailers prying into sex lives.
- IHLayman 7y agoIn a related vein of your comment: "After being challenged as to whether homeowners should tell guests smart devices - such as a Google Nest speaker or Amazon Echo display - are in use before they enter the building, he concludes that the answer is indeed yes."[0] * [0]: https://www.bbc.com/news/technology-50048144 https://www.bbc.com/news/technology-50048144
- _wldu 7y agoZero Trust. This is a basic network security tenet that was first introduced in 2010: https://www.darkreading.com/attacks-breaches/forrester-pushes-zero-trust-model-for-security/d/d-id/1134373 https://www.darkreading.com/attacks-breaches/forrester-pushe...
- xyzzy_plugh 7y ago> Can We Trust Them? Of course not.
- semiotagonal 7y ago> But Kennedy's biggest concern at the moment is in the area of automotive safety No doubt. I was pricing out a Mercedes online, and looking through the summary one of the standard features was "over-the-air updates". That is the last thing in the world I want. An expensive car shouldn't be acting like an Android phone. It shouldn't be connected to the internet at all. If it's updating anything other than the entertainment system, then they're completely nuts. Get the internet out of my car, I already have a phone for that.
- aledalgrande 7y agoIsn't that the same as Tesla?
- Ensorceled 7y agoI think the person you are replying to would also dislike this feature in a Tesla.
- semiotagonal 7y agoThat's true, I'm not looking to buy a Tesla. I'd include touchscreens as another problem but that's separate from the article's subject.
- dvdhnt 7y agoI appreciate your consistency. We've been looking to buy an electric vehicle and thought Tesla was a no-brainer. Random reports of software issues have persuaded us to wait. Now, I'm learning there are more options from more mature brands that just don't receive as much attention as Tesla.
- ZenModeRy 7y agoAccording to a Bloomberg survey of 5,000 model 3 owners, 98% say they would buy it again and the vehicle had surpassed their expectations. 99% percent of respondents said they would recommend the Model 3 to their family or friends. I live in Puerto Rico where a Tesla doesn't make much sense due to the infrastructure, but these numbers still made my neck hurt with a little bit with FOMO.
- deleted 7y ago[deleted]
- deleted 7y ago[deleted]
- dsalzman 7y agoIOT. The S stands for security.
- freeflight 7y agoSome like to call it the IoS, but there the S most certainly doesn't stand for security [0]. [0] https://twitter.com/kcimc/status/1099934485301276673 https://twitter.com/kcimc/status/1099934485301276673
- choward 7y agoSadness?
- nwallin 7y agoThe s stands for... Something else. www.reddit.com/r/theinternetofshit
- JohnFen 7y agoI think the clear answer to this is "no" on a couple of different levels. I don't think it's safe to trust that the actual communications are properly secured, and I don't think it's safe to trust the companies that these devices report to.
- moonbug 7y agoBetteridge.
- phs318u 7y agoWe need something like this: https://foundation.mozilla.org/en/privacynotincluded/ https://foundation.mozilla.org/en/privacynotincluded/ expanded to every type of IoT. Imagine a kind of mandatory labelling for any device with data-capture and/or telemetry capabilities.
- Havoc 7y agoYeah the cheap IoT stuff is just wild. No passwords / weak security is pretty much the norm
- smacktoward 7y agoShort answer: no. Long answer: noooooooooooo.
- forgingahead 7y agoNo. /end thread
- ubertakter 7y agoNo. Next question please.