3 ms·
Your article seems to directly contradict the idea that any sort of IoT / "smart" device was involved: > Fazio Mechanical Services just issued an official stat
by XMPPwocky 6y ago
Your article seems to directly contradict the idea that any sort of IoT / "smart" device was involved:
> Fazio Mechanical Services just issued an official statement through a PR company, stating that its “data connection with Target was exclusively for electronic billing, contract submission and project management.”
- bostik 6y agoWe should all remember to read PR statements with the assumption they aim to be technically true but come with an intent to deceive. Because what you quoted is a weaselly statement, and it neatly avoids answering the underlying questions. Namely: was that "exclusively" a contractual exclusion or a technically sound, enforceable exclusion? And on top of that, how was it secured? If the connection setup was breached, what was the maximum blast radius?
- XMPPwocky 6y agoNone of those questions seem to be relevant to whether or not there was some sort of smart device involved.
- bostik 6y agoI'm sorry, but in this case I disagree. Whether the device was smart or not is irrelevant. If there is a connected device in a supposedly otherwise secure network that allows traffic in or calls home, that device is an attack vector. Pure and simple. The only safe assumption is that such a thing is an insecure, unmaintainable black box that was put together by the cheapest fly-by-night contractor. A "smart" device is worse, and guaranteed to be a dumpster fire. One should not be allowed anywhere near a secure network, regardless of its function. Printers, VoIP phones, climate control systems, ... they're all the same.