{"id":87,"date":"2016-11-14T06:51:25","date_gmt":"2016-11-14T06:51:25","guid":{"rendered":"https:\/\/www.jasonsblog.place\/?p=87"},"modified":"2017-01-02T00:54:22","modified_gmt":"2017-01-02T00:54:22","slug":"dealing-with-the-internet-of-things","status":"publish","type":"post","link":"https:\/\/www.jasonsblog.place\/index.php\/2016\/11\/14\/dealing-with-the-internet-of-things\/","title":{"rendered":"Dealing With the Internet of Things"},"content":{"rendered":"<p>The other day, I attended a meeting of the North Texas chapter of ISACA. \u00a0There, the information technology veteran, Austin Hutton, gave a presentation on the dangers of the Internet of Things (IoT). \u00a0I have <a href=\"https:\/\/www.jasonsblog.place\/index.php\/2016\/10\/06\/the-problems-with-the-internet-of-things\/\">written about the IoT<\/a> and how it can be used to devastating effect.\u00a0 One of the problems that Hutton talked about is that there are more IoT devices than there are people on earth.\u00a0\u00a0 Thousands are being manufactured and sold each day, and each one of these devices can be hacked to assist in an attack.\u00a0 And the problem is getting bigger.<\/p>\n<p>Most of those devices were poorly designed, and thus have no way of being updated. \u00a0The companies who make these devices have thin profit margins, so they cannot afford to make them secure.\u00a0 In some cases, the manufacturer buy the chips from other companies, so they are not directly responsible for its security. \u00a0The average IoT device can be easily hacked: a number of them have easy to crack passwords, or have flaws\u00a0that were not detected when they were being designed. \u00a0There are even programs which can auto-hack some of these devices. \u00a0All the hacker needs to do is learn the make and model of the IoT device, select the program, sit back, and gain control over it. \u00a0For those devices which are used as intended, they may be doing something illegal.<\/p>\n<p>Hutton gave the example of a Tempur-Pedic bed which can send the user&#8217;s data back to Tempur-Pedic for analysis so as to improve the user&#8217;s experience. \u00a0He then gave an example of someone else (specifically, his 14-year-old granddaughter) sleeping in the bed, and their data being sent to Tempur-Pedic without their permission.\u00a0 This can be considered breaking the law because she&#8217;s a minor. \u00a0How would that situation be resolved? \u00a0How can we at least minimize the damage from IoT devices?<\/p>\n<p>For one, education. \u00a0Though companies are really selling the convenience of IoT devices, consumers must learn how harmful IoT devices can be.\u00a0 The public needs to learn that these devices can be used to cause harm to our cities, and possibly to themselves.\u00a0 Recently, the business of a <a href=\"https:\/\/metropolitan.fi\/entry\/ddos-attack-halts-heating-in-finland-amidst-winter\">utilities company in Finland<\/a> was disrupted due to a DDoS attack, resulting in the heating for their customers being disabled. \u00a0What if this was the smart thermostats of many of their customers getting hacked?\u00a0 The attacker could lower the temperatures in these houses, or disable the thermostat, which would be a dangerous situation to homes in Finland during the winter. How else could these devices be attacked?\u00a0 An attendant to the meeting, David Hayes of Verizon, had one other scenario.<\/p>\n<p>There are utility companies in North America and Europe that use monitors called <a href=\"https:\/\/en.wikipedia.org\/wiki\/SCADA\">SCADAs<\/a> which can remotely control machines vital to a functioning city (one example is the water pumps which keep drinking water flowing through the city).\u00a0 What if, Hayes suggested, a hacker takes control of these pumps, and threatens to take them offline, or even increases their work to the point of destroying them, unless he is paid $100,000?\u00a0 Now we&#8217;re starting to see the cost of this problem.\u00a0 This cost will only increase, as malicious hackers devise ways of misusing these IoT devices.<\/p>\n<p>Another way we can minimize the damage from IoT devices is to ensure that your IoT devices can be modified such that only you can control it.\u00a0 If you can change the password, do it.\u00a0 Check that a default root password hasn&#8217;t been hardcoded into the device.\u00a0 If you can, find a device that can be updated (though few IoT devices have the capacity to be updated).\u00a0 On the government side, we&#8217;re going to need some form of\u00a0 oversight.\u00a0 For instance, no IoT device bought by\u00a0 the government can lack the ability to be updated.\u00a0 How about current IoT devices?\u00a0 There is little we can do about them.\u00a0 If we&#8217;re dependent on them, then it&#8217;s going to be difficult to replace them.\u00a0 Maybe for the average person it&#8217;s easy to change their IoT lightbulbs.\u00a0 But how can a maintenance manager at a company tell his bosses that, due to the threats these IoT devices have to the security of the company, they all have to be changed.\u00a0 How much will that cost?<\/p>\n<p>This is a growing problem that will grow more as these hacked IoT devices are used to facilitate these attacks.\u00a0 It is imperative that this problem be addressed now, rather then have some catastrophe occur, and involve the lives of thousands.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The other day, I attended a meeting of the North Texas chapter of ISACA. \u00a0There, the information technology veteran, Austin Hutton, gave a presentation on the dangers of the Internet of Things (IoT). \u00a0I have written about the IoT and how it can be used to devastating effect.\u00a0 One of the problems that Hutton talked [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[35,45,22,20,46,18,21,34,47],"class_list":["post-87","post","type-post","status-publish","format-standard","hentry","category-information-technology","tag-audit","tag-change-management","tag-ddos","tag-distributed-denial-of-service","tag-finland","tag-internet-of-things","tag-iot","tag-management","tag-scada"],"_links":{"self":[{"href":"https:\/\/www.jasonsblog.place\/index.php\/wp-json\/wp\/v2\/posts\/87","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.jasonsblog.place\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.jasonsblog.place\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.jasonsblog.place\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.jasonsblog.place\/index.php\/wp-json\/wp\/v2\/comments?post=87"}],"version-history":[{"count":17,"href":"https:\/\/www.jasonsblog.place\/index.php\/wp-json\/wp\/v2\/posts\/87\/revisions"}],"predecessor-version":[{"id":125,"href":"https:\/\/www.jasonsblog.place\/index.php\/wp-json\/wp\/v2\/posts\/87\/revisions\/125"}],"wp:attachment":[{"href":"https:\/\/www.jasonsblog.place\/index.php\/wp-json\/wp\/v2\/media?parent=87"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.jasonsblog.place\/index.php\/wp-json\/wp\/v2\/categories?post=87"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.jasonsblog.place\/index.php\/wp-json\/wp\/v2\/tags?post=87"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}