I think it's rather brilliant. It is the manufacturer's responsibility to ship secure products. Here a consumer with a bricked product will demand a replacement/refund, putting pressure on the manufacturers to not ship shitty products. It's directly applying market pressure to sellers of insecure hardware, and that's a great thing.
> Here a consumer with a bricked product will demand a replacement/refund, putting pressure on the manufacturers to not ship shitty products.
If my shitty DLink camera suddenly stopped working, I wouldn't demand a refund - realistically, I'd just toss it in the bin and try to remember not to buy more DLink products. But I probably still would, if they were sufficiently cheap.
I imagine that calculus is similar for most people.
And DLink will continue to try to save money by releasing products without following proper security procedures because you will keep buying them because they are cheap.
It's tough for security to affect purchasing decisions because it's difficult to measure. I can measure horsepower, megapixels, gigabytes, milliamp-hours, etc. so it's easy to make purchasing decisions based on which of those things are important to me.
I think what you're suggesting is that enough bricked devices will cause consumers to demand security - maybe even some measurable metric, like a certification of external audit - as part of the standard product search.
But I don't think bricking a device necessarily ties into security in people's minds. If they permanently modified it to always show HACKED_BCUZ_DLINK_SUX whenever I try to load the camera feed, sure - but a bricked camera is just a failure. I don't even know if it got hacked, or if a capacitor blew, or if a rodent chewed through something crucial.
Please don't. With some funding from China, I'm currently running a massive worldwide operation, which allows me to spy on hundreds of millions of unsuspecting Master Lock users; allowing me to track, among other things, where every bike user is at all time, as well as record what they are doing.
If only it weren't for you meddling kid.
Analogies, aren't they great?
(Since it's apparent that sarcasm can't be read: "Stealing bikes" isn't the same bloody thing. Why even make that analogy?)
If this danger is real, isn't it best to inform the consumer, or perhaps use a lawsuit to force a recall, rather than destroying other people's hardware?
Does this concept apply to software? When the next large-scale RCE 0-day drops, does it make sense to use exploitation to destroy as much as possible in order to pressure the developers to ship a secure product? Since, the hacked machines certainly could allow an attacker lateral movement to sensitive data.
a lawsuit requires people 'smart' enough to even know they were hacked, and for a recall they need to decide if the cost of a recall is cheaper than legal/settlement fees, ( i learned this from Fight club) lol -- however -- WARRANTY replacements of devices because a hacker breached security and bricked it--this could be a LOT faster way to force them to recall.
How, like 5% of people that buy electronics actually turn in the warranty cards. No, they will sit on the shelf for years polluting the internet with DDOS attacks and spam.
>es it make sense to use exploitation to destroy as much as possible in order to pressure the developers to ship a secure product?
Yes. That is also why I backup data using multiple methods including off line ones.
Vigilante or blackhat doesn't matter. The next RCE will gladly spit copies of CryptoLocker everywhere if they could get ahold of it.
The internet is a dangerous and well connected place. If lived China, I would think it's funny if I wiped a few large US corporations off the map because they used a DLINK webcam. And there is only a tiny chance in hell they would ever find me.
There's a few things missing in this comparison, most notably the bike manufacturer isn't claiming the bike is already secure ("auto-locking" bikes) or making additional security challenging (bikes that locks are very hard to install on) or generally profiting from an environment of misinformation about bike theft and bike safety.
Additionally theft of property has a personal gain for you.
I'm not sure I ethically support the hacker's actions, but I don't think the bike example has the market/awareness effects that make it at all defensible.
What kind of stupid person would think that we could have a cooperative, functional society where I can just be careless with my bike, right?
What's the problem with these people?
Sarcasm aside, I live in Brazil, ask any Brazilian who stayed on an European country what was the biggest difference: "I could feel safe anytime, without worrying about my stuff".
That really shapes the mind and behaviour of people.
Which is great, in theory. But devices in Europe are just as accessible to Brazilians as they are to anyone else. Unless a device is locked down to local access, you can't have "safe neighborhoods".
> What kind of stupid person would think that we could have a cooperative, functional society where I can just be careless with my bike, right?
Isn't this actually a really common sentiment, though? I've lived in several places where leaving a bike unlocked for 5 minutes, or sloppily locked for an hour, means you're going to lose it.
That doesn't make the theft acceptable, but if a friend borrowed your bike and left it unlocked you'd still get mad at them.
Reshaping society so this stuff doesn't happen is great, but on an inside-view level we treat crime as sort of an inevitable "someone will do it" force.
> Reshaping society so this stuff doesn't happen is great, but on an inside-view level we treat crime as sort of an inevitable "someone will do it" force.
I don't disagree with you, however I think there are some levels to this concept, e.g. how two different locations would differ if it was: a lost wallet, a somewhat clear opportunity for embezzlement, a bike stopped in front of a coffee shop?
I understand what you're implying, but no one is "allowing" their hardware to be used criminally. At least in the U.S., our personal property system is permissive i/e you may not use my things without permission. So, using an IoT device as provided by the manufacturer is "allowing" its misuse so much as leaving my backyard gate unlocked is "allowing" criminals to park their stolen goods in my backyard.
Ok, but we do have "attractive nuisance" laws. If you leave out a trampoline next to barbed wire, you can be accountable even if you didn't actually permit anyone to use it.
This actually seems much closer to the IoT issue than theft. The maker and user of the device have created an inviting target which will cause harm to someone other than themselves. Even if the eventual attack is illegal, they can still be held accountable for making it so likely.
Honestly, I've never heard of a law like that. The U.S. is a big place; whereas that may be the case in parts of the country, in the south where I'm from, that's never become known to me, especially in the rural areas where I grew up. Instead, the people using your things without permission are at the very least trespassing.
IANAL, and I can't find a definitive statement of where the doctrine applies, but I see it referenced in cases in many US southern states (AL, GA, AR, KY, FL, TX). I know that the particulars vary in many states, based on precedent and statute, but I'm not aware of anywhere it's absent entirely. Hopefully someone more knowledgeable will come along and clarify.
Note that "attractive nuisance" is specifically about trespassing children.
It's a very well entrenched common law concept. The same goes for swimming pools: if you build a swimming pool and don't put an adequate fence around it, and a kid comes by, jumps in and drowns, you're probably going to be found liable (not criminally, but you can be successfully sued for it)
The only attractive nuisance laws I've heard of applied to children. If you have a swimming pool without a fence, and a child sneaks onto your property and drowns you are liable.
IANAL, and it's hear say, but I had thought this was something everyone knew.
A poor choice of words on my part. That aside, the point remains: poorly secured IoT devices cause real harm to others in a way that a poorly secured bike does not.
Very different. If you can bust an insecure lock you can steal a bike. If you bust an insecure IoT device, you can steal data from potentially thousands or millions of people.
I am not sure this is a good analogy. Stealing a bike only effects one person. an IoT device that brings down the internet in a DDOS attack impacts everyone.
Well, the manufacturer provided lock is a piece of string connected to an index card that says "do not open", and the bikes are being regularly used in crimes against the public at large.
Given the owner of the bike could conceivably be held liable for the use of their bike to commit crimes, the janit0r who decided to clean up this crap comes across as the lesser of two evils.
I feel like a more accurate analogy is that you are going to start breaking into poorly secured garages and destroy people's bikes so that the owner can't ride them anymore.
While I am on the fence with a lot of what is happening, I would have thought a more appropriate analogy would be to: Break into a poorly secured garage, that has been sold as a single unit to the customer, seal the door and any other access via welding so that no one can ever use the garage ever again.
No. The product is going to be out of warranty, the manufacturer is going to refuse to replace the device, and suddenly a customer is out hundreds or thousands of dollars out of their own pocket. IoT devices are not cheap.
I find it reprehensible that the Gizmodo author (who is using his position as a journalist to encourage criminals) and HN commenters are applauding this hacker as if he's a hero of the people, fighting for a better future. He's directly harming individuals who have purchased products. This is not a friendly reminder to manufacturers to get their shit together. It's some guy illegally connecting to, taking control of, and bricking computers.
I've seen him referred to as a greyhat. No. Everything about this is strictly blackhat. This hacker deserves prison time. What a piece of lowlife scum. It really does sound like a 15 year old getting off on making waves, rather than someone who gives a damn about security.
How are the manufacturers not to blame? One way or another, these devices are getting hacked. Only most of the time, they're taking down Playstation Network or GitHub rather than being bricked.
Attacks on devices that have hardcoded weak credentials online aren't an event or an act. They're a force of nature, like erosion. No-one would be happy with someone building bridges that don't account for erosion. Nor is it ok to ship something that connects to the internet and doesn't account for the millions of automated bots that are prowling the web 24/7 looking for insecure devices.
The manufacturers are 100% to blame, and the worst thing is that they're not the ones that deal with the fall-out – innocent companies and consumers are.
It's sort of like your neighbor having an automated lawnmower, and you knowing that with a careful placement of rocks the image recognition will fritz and it will happily start mowing into your yard, over your petunias and possibly your small children and animals. You're fairly certain that there are other problems with it you don't know about as well.
Do you force the situation and make it mow into your yard and over a bunch of rocks to destroy it, or do you live with the danger?
I don't have an answer. In this situation you could at least talk to your neighbor. Without the ability to feasibly do that, I'm not sure I would fault either action.
Think about it. If you have kids or pets or flowers, seems like it would be prudent trigger the event in a more safe, and known environment than to leave to chance (of injury to property or 3rd party). Seems like talking to the neighbor happened over a decade ago to me.
Sure, depending on the chances of it happening. The problem is that we don't know what the chances are, and as a species we're fairly bad at assessing stuff like that in general. If it's a million-to-one chance, there are probably plenty of other more worthy perils to be concerned with first. If it's a hundred-to-one chance, it may be an imminent threat. Which is it? How do you trust that the person telling you the odds isn't vastly over or under estimating the chances?
The answer falls into an area that's somewhat unknowable with current information, which is why I can't fault either behavior.
I disagree. We know that the probability of it happening again is very high, seeing as it has already happened multiple times, and no serious action has been taken to improve the situation. If we were speculating about a theoretical risk, I would agree with you.
I think the issue is less the chance of the lawnmower going wild by itself (because screw that, I don't care how small the chance is, it's not acceptable), and more the chance of the lawnmower exploding, taking out your eye when you trigger it's failure it yourself.
As in, "the chance of getting hacked" < "the chance of the vigilante creating dangerous situations".
This statement and others like it here seem to assume that the hacker has not been directly affected by the infected devices.
For example, maybe this person had a wife dying of cancer while Mirai destroyed his life's work, so in the same period he lost his wife and he lost his work.
Or, maybe he spent a lot of money trying to launch a new product through channels that were destroyed during one of the attacks, and unable to get his money back, had to close the venture.
Maybe he had to sleep in a data center for several months during the holidays and concluded the only reason he was doing this is because consumers and manufacturers aren't concerned with the damage they are doing, so he is going to make them become concerned about the damage they are doing.
The point is that we have no idea if this person has been harmed, and whether they have any other legitimate means of being made whole from harm done, as well as be able to protect themselves from future harm.
Clearly, the proposed solutions coming from industry "experts" is likely to make things worse, as the only other activities to "fight" Mirai seem to be to support legislation as a solution to a technical problem, and I'm really not clear on when this has ever worked, especially in a system that everything on the planet can connect to.
> It takes a special kind of entitled to destroy people's things and to then blame others (the manufacturers) for it.
If you put a dangerous, unsecure device, live on the Internet, that can be used to attack other machines, you deserve to have your property be destroyed.