While much of the news about IoT focuses on the feats of hackers, not as much is given to the reasons why the IoT can be hacked. After all, it's more sensational to talk about remotely controlling a Jeep Cherokee than to discuss why the Cherokee's CAN bus was vulnerable in the first place. However, discussing the flaws are more important. So that's what we'll do!
In Bruce Schneier's article "The Internet of Things Is Wildly Insecure — And Often Unpatchable", he describes several weak areas in the Internet of Things:
In Bruce Schneier's article "The Internet of Things Is Wildly Insecure — And Often Unpatchable", he describes several weak areas in the Internet of Things:
- There isn't a lot of effort put into securing embedded computers. These embedded computers, which are at the core of the IoT, are produced with as little expense as possible due to a slim profit margin. The companies putting the chips in their system also don't have much incentive to secure the chip--after all, if they bought the chip, why should they have to reprogram it?
- The software on the computers is old, and it is difficult or impossible to upgrade. As Windows XP was discontinued, there was an enormous amount of pressure to upgrade computer systems. Why? Because Microsoft stopped securing XP, making it unsafe to continue using for sensitive business work. With IoT devices, though, the story is different. In a survey Bruce mentions, it was discovered that the average age of router software is 4-5 years older than the hardware it's on. Thus, a 3-year old router would have an 8-year old operating system. To make matters worse, he says that, "it’s often impossible to patch the software or upgrade the components to the latest version." because much of the software's source code isn't accessible. Thus, the latest possible software is the outdated software already on most IoT devices.
- Fixes, when available, are hard to install. For most "regular" computers, security updates are simply downloaded and installed; it's all automated. How many security updates would not be installed if this wasn't the case? Automatic updates are rare in the IoT world, and available patches/fixes need to be manually installed. Most users don't have the time or know-how to install a patch like that.
- More and more IoT devices are coming out. This isn't one of the main points in Bruce's article, but its' worth mentioning. If developers are not focusing on the security issue but are instead creating more and more devices, each with its own security flaws, then wouldn't the conclusion be that they are adding to the problem?
So if you were a hacker, and you had to break into a network, which of these two would you break into: a Macbook Pro, with regular automatic updates, the most recent OS X, a firewall, and an antivirus, or a smart TV, with a 4-year old operating system, no security patches in 3 years, and as much network access as the Macbook? Generally speaking, it would be much easier to break into the TV. This is a typical IoT device. And with the focus of production being on more and more devices, each with its unique weaknesses, it it unusual that the Internet of Things is the way it is?
No comments:
Post a Comment