The S in IoT stands for security. You'll never secure all the Things
- Reference: 1709964010
- News link: https://www.theregister.co.uk/2024/03/09/opinion_column_security_sjvn/
- Source link:
You see, while it wasn't true that [1]smart toothbrushes were behind a reported Distributed Denial of Service (DDoS) attack, they could have been. More to the point, some DDoS attacks already start from the gadgets on your wrist, in your pocket, and scattered around your home.
For example, last year, Nokia noted in its [2]2023 Nokia Threat Intelligence Report that IoT botnet DDoS attacks increased fivefold from 2022 to 2023. Indeed, more than 40 percent of all DDoS traffic today comes from IoT botnets.
[3]
We should have seen this coming. The first significant IoT botnet DDoS attacks, which used the [4]LizardStresser DDoS tool , wrecked the 2015 holiday season for many Xbox Live users when it knocked the service offline for days during the peak Christmas season. In 2016, LizardStresser hackers followed up with a 400Gbps attack backed by more than 1,200 video cameras.
[5]
[6]
It's only got worse since then. A lot worse. You might not think that small gadgets like smart lightbulbs, thermostats, and, yes, toothbrushes, could do that much damage, and you'd be right. Individually, they don't count for much. But, when you coordinate some of the more than [7]5 trillion - that's trillion with a T - IoT devices , it's another story entirely.
So, why is IoT security that bad? Let me count the ways.
[8]
First, IoT devices tend not to have operating systems as such, but rather firmware that also acts as an operating system. In short, any security problems in the firmware are easily accessible to a would-be attacker. Additionally, far too often, firmware hasn't been as security-hardened as operating systems.
In fact, way too many "smart" devices are using old, dumb software with known security problems. As the FBI noted in 2022, many [9]medical IoT devices [PDF] run outdated, insecure software.
[10]Are you ready to back up your AI chatbot's promises? You'd better be
[11]Mozilla CEO quits, pushes pivot to data privacy champion... but what about Firefox?
[12]The Land Before Linux: Let's talk about the Unix desktops
[13]Your pacemaker should be running open source software
[14]Bricking it: Do you actually own anything digital?
How many? According to Armis, a security company, [15]39 percent of nurse call systems have critical, unpatched common vulnerabilities and exposures (CVEs). Oh, and infusion pumps, which provide fluids to patients? 30 percent of them have unpatched CVEs.
Would it surprise you to know that 19 percent of medical IoT units run on no longer supported versions of Windows? I didn't think so. I'd rather not go to the hospital anyway, but knowing that some of the equipment my life may depend on is unsafe? No, just no.
Making IoT attacks even easier, junkier IoT devices don't use secure networking. Insecure networks are also especially vulnerable to man-in-the-middle (MITM) attacks. That makes stealing credentials mindlessly simple.
[16]
All this stems from the simple fact that IoT security is an afterthought
A more obvious but all too common problem is that many IoT devices come with weak default passwords or, worse still, shared hardcoded passwords. Yes, it makes it easier for Joe public to set the gadget up, but it's also an open invitation for any hacker to enlist your device in a botnet.
Of course, these vulnerabilities could be fixed… if IoT manufacturers gave a damn about security. Many don't. Many don't update their firmware at all.
To them, your security is a cost. You bought the gadget, it's your problem now.
What can you do about it? Not a lot, to be honest. So, I prefer never to buy any "smart" device. You see, there is no "S" for security in IoT. Never has been, and I doubt very much there ever will be.
You can only buy from vendors that prioritize security. Finding out which ones do that can be almost impossible, as they don't make it easy to find.
I can say one thing, though: If an IoT device runs Windows, just say no. Windows is hard enough to secure in a computer; in standalone hardware, it's almost impossible. The simple fact that medical devices, of all the things you'd want to really secure, frequently run obsolete versions of Windows says everything I need about how seriously their manufacturers take security.
It all comes down to the bottom line. What truly matters to the many who make IoT devices is the M for money. They could care less about securing software, especially keeping it patched and secure after it's in your hands. You're much safer with dumb devices than you ever will be with smart ones. ®
Bootnote
* Yep, [17]Carnegie-Mellon’s Computer Science Department already had an internet-connected Coke machine back in 1992.
Get our [18]Tech Resources
[1] https://www.theregister.com/2024/02/09/a_look_at_fortinet_week/
[2] https://www.nokia.com/about-us/news/releases/2023/06/07/nokia-threat-intelligence-report-finds-malicious-iot-botnet-activity-has-sharply-increased/
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offprem/edgeiot&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZexBWLKKzWZPVXzUFf-PnAAAAEI&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://www.theregister.com/2016/07/01/lizardstresser_ddos/
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offprem/edgeiot&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZexBWLKKzWZPVXzUFf-PnAAAAEI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offprem/edgeiot&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZexBWLKKzWZPVXzUFf-PnAAAAEI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[7] https://www.sciencedirect.com/science/article/abs/pii/S0167404823000068
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offprem/edgeiot&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZexBWLKKzWZPVXzUFf-PnAAAAEI&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[9] https://www.ic3.gov/Media/News/2022/220912.pdf
[10] https://www.theregister.com/2024/02/23/opinion_column/
[11] https://www.theregister.com/2024/02/09/opinion_column_mozilla_ceo_quits/
[12] https://www.theregister.com/2024/01/27/opinion_column/
[13] https://www.theregister.com/2024/01/12/column/
[14] https://www.theregister.com/2023/12/22/opinion_column/
[15] https://www.armis.com/newsroom/press/armis-identifies-the-riskiest-medical-and-iot-devices-in-clinical-environments/
[16] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_offprem/edgeiot&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZexBWLKKzWZPVXzUFf-PnAAAAEI&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[17] https://www.cs.cmu.edu/~coke/history_long.txt
[18] https://whitepapers.theregister.com/
"We should have seen this coming"
All too many of us Reg commentards did.
But there is also an L in IoT, for "La-la-la" with your fingers in your ears.
And it's not just the firmware, the older and cheaper hardware is also insecure by design. Secure from the ground up is still rare.
Why I still refuse a smartmeter to this day.
As I've said before
The only smart thing here is between my ears - and that's getting a bit debatable!
Some smart devices have strong security
Some manufacturers have put significant effort into ensuring products become non-functional if the purchaser stops paying a monthly fee. Securing against someone with physical access requires skill, attention to detail and firmware updates to patch vulnerabilities. That monthly fee is absolutely necessary to fund ensuring customers cannot do what they want with their purchases.
Re: Some smart devices have strong security
I'm not sure you're describing security there. To me, that sounds much more like simple lock-in.
It's a security for the vendor, to be sure, but it secures the vendors financials, not my security.
Re: Some smart devices have strong security
It's a security for the vendor...
Mission accomplished... Who cares about the "consumer"? They are just plebs to extract money from.
(truth and sarcasm unite in this one)
IoT ? Not for me
But I'm not going to go dissing on hospital stuff. I'm very happy that we have hospitals, insecure as they are. The people who are there want to help, they really do. You have to want to help when you're paid so little for saving people's lives, or even just making them slightly better. As I am getting on in age (60 is an asteroid that is looming ever larger on my horizon), I think that, if push comes to shove, I will gladly accept an insecure pump or whatever if it gives me more years to be with my family.
Yes, I would definitely prefer that medical thingamajigs be secure, it would certainly be reassuring, but I think I can stand the insecurity if my life is on the line.
But in my house ? Never.
I can get my fat ass of the couch and go for the dumb, stupid, secure switch.
I would never want to buy even so much as a so-called "Smart TV"; I stick to computer monitors. The poor history of all TV vendors in regards to patching and maintaining their sets is horrendous , with the products going out of support far sooner than I'd expect a TV to actually die.
And no wonder. Once the product is sold, the revenue stream dries up. And if you're going to get such poor and short lived maintenance for a TV costing hundreds or thousands of dollars, how much do you think they're going to put into maintaining your security on your fridge or washing machine?
I cannot imagine any security-conscious IT person owning "smart home" components at all!
They are risky
But using only those that can be controlled locally, putting them on their own subnet and denying internet access to everything on that subnet goes some way toward mitigating the risks.
There is an S
I doesn’t stand for security. Amusingly, and not to be cruel to the author, but go back and read this noble rag’s own coverage of the rise of the IoT s—storm.
Both in the articles and the commentary, this was foreseeable and foreseen.
We literally told them so. We never stopped. We pointed out that once the crap shipped we would be stuck with it online and causing problems till it ended up in a landfill. That could take decades.
Welcome to the future you chose by ignoring us. We told you this would happen. Have a nice day.