4 ms·
I think the most valuable security feature for IoT devices is being able to work without contact with a central service. If the value of a device is tied to op
by iandanforth 3y ago
I think the most valuable security feature for IoT devices is being able to work without contact with a central service.
If the value of a device is tied to opening a connection to and occasionally retrieving code from a third party it is inherently insecure. All I have to do is buy the company that owns the central server (or compromise it in some other less visible way) and I now have the ability to introduce malicious code to all devices that are receiving 'security updates.' You won't be able to make a rule to prevent asset transfer (correct me if I'm wrong) so you won't be able to close this hole. And this assumes the manufacturer isn't malicious in the first place.
For people to be able to protect themselves and to protect the value of the property they have purchased (e.g. the company tanks and the central service is lost) a rule should exist mandating minimum useful functionality in a disconnected and/or self-managed environment.
- nickff 3y ago>"All I have to do is buy the company that owns the central server (or compromise it in some other less visible way) and I now have the ability to introduce malicious code to all devices that are receiving 'security updates.' You won't be able to make a rule to prevent asset transfer (correct me if I'm wrong) so you won't be able to close this hole." Has this actually been a problem in the past? I do not know of any examples of this, do you? I hate having to create and maintain accounts and subscriptions for so many devices, but I'm not sure it's a huge security problem.
- iandanforth 3y agoGoogle's acquisitions of Nest and Dropcam are the two which impacted me personally. Data ended up in the hands of people I didn't want, features were removed that I found essential. Perhaps others can volunteer their stories, I've largely opted out of IoT because of these experiences and concerns.
- hunter2_ 3y agoSuppose you buy a car from manufacturer A. You lose both keys (perhaps you and your partner each bring one on a canoe trip and capsize) so you have no choice but to ask the dealer to assign new ones. You find that Google now owns the entire brand A including its dealer network, and they only offer rekeying service in conjunction with an update that installs what you consider spyware. Do you opt out of the motor vehicle industry?
- wpm 3y agoI opted out of the entire motor vehicle industry for far less.
- SonOfLilit 3y agoThere are malicious actors in the business of buying popular App Store apps and introducing malware into updates.
- fireflash38 3y agoOr buying chrome extensions. Even domains.
- tomaskafka 3y agoThere are reports about Saudi stakeholders co-owning few billion stake Twitter with Elon just to be able to install people who exfiltrate data used for tracking and arresting journalists and activists, for example.
- KyleBerezin 3y agoThis is virtually impossible due to certs. If you want your device to keep its traffic secure with ssl or wss, you have to have valid certs. Thanks to apple, that either means a device with a 1 year expiration date, or an internet connection so you can periodically provide the device with new certs.