I have discussed the trend towards ignoring security in production of devices on the Internet of Things. From a recent article, it appears that some companies are going a bit further. A Chinese security-camera company called Foscam designed their cameras to connect in a peer-to-peer network--regardless of who owns them. The P2P networking was built into the cameras and was not able to be deactivated, and it is essentially centrally monitored by a Chinese domain. Customer complaints eventually caused Foscam to develop firmware updates and patches that disabled the feature for those that desired it. This event is not limited to Foscam: according to the article, multiple Chinese-made products use the same Chinese domain for networking purposes.
From a security perspective, this is concerning. Security cameras are usually assumed to be secure, but programming the customers' cameras to connect to each other (and to foreign computers) automatically over the Web makes that assumption rather questionable. If the domain was spoofed, for example, then the traffic could be effectively rerouted and controlled by an attacker. Or if an attacker posed as a security camera and accessed the P2P network, he/she could potentially compromise the security of real cameras they connected to. From a national perspective, one wonders how wise it is to have any level of control of our security cameras routed through a foreign entity.
What is concerning is that the company assumed this action with IoT devices was okay. Sure, they may have had purely evil motives, but it seems unlikely considering that they provided firmware updates and patches that resolved the issue. The fact that an IoT company took the liberty to hard-wire automatic networking in security cameras shows how far security can be from the mind of IoT developers. IoT security is becoming ever more important--and unfortunately it appears that this fact is not being recognized in much of the IoT world.
No comments:
Post a Comment