4 ms·
You're mostly right. I think several do give a shit about security but they both lack the knowledge of what it takes to reasonably secure something like this a
by mdip 3y ago
You're mostly right. I think several do give a shit about security but they both lack the knowledge of what it takes to reasonably secure something like this and are somewhat powerless/misled into believing they don't need to care.
The first problem is that companies that add wireless/IoT capabilities to devices have nothing to do with their implementation/security beyond writing a cheque. I used to work for a company that created IoT devices for huge brands[0]. They make a toothbrush, a lightbulb or a vacuum cleaner. They're good at that, but they bring in someone else to either "wholesale create an IoT product" or collaborate on its creation where the "IoT pieces" (and their security) were farmed out to us.
Of course, we didn't have much to do with the creation of the product, either. We (frequently) used a white-label Chinese product -- often, but not always, explicitly chosen by the manufacturer. In fact, the large brands often insist on a specific Chinese provider for long-term maintenance/cost savings[1].
We receive a "dev board" and device that consists of an ESP8266/ESP32 bolted onto whatever it's IoT-ing, and a cloud service (hosted in the country of origin; almost always China). The developers involved write a mobile app and some firmware that interacts with the cloud web service -- which we have no control over/cannot work around or suggest additional security layers -- and we integrate it. It creates an impenetrable SEP field[2].
Companies who care about security care about it up to some industry defined standard that has some form of acronym (the names of which escape me these days) which involve, basically, filling out a form or two attesting (truthfully) to the requirements but that serve only to shield those involved in the process from responsibility beyond whatever the acronym-defining organization thinks to ask. It involved passing a lot of those questions off to the third-party who runs the cloud service, who -- surprise, surprise -- know what boxes to check to receive payment.
[0] I love my former employer so I'm leaving the brands off, but at least one product involved was popular enough that my parents received one as a gift for Christmas ... it was fun explaining that some code I had written was running on their phone.
[1] The pattern (one that we didn't advocate) went "hire us to build the initial, user-friendly, polished version of the app" then pass it onto said OEM to maintain/update it between hardware versions. To the extent that the first version could be secured, it is (until it's not). They don't trust the OEM to write the initial version, but once it's out there, augmenting it costs 1/10th the price and that's about all their willing to pay after the initial product is created.
[2] Someone Else's Problem (Douglas Adams -- Hitchhiker's Guide to the Galaxy).