Hacker Newsnew | past | comments | ask | show | jobs | submit | XaYdEk's commentslogin

How many pennies would've been needed to insert a simple page forcing you to change user/password combo and to choose a reasonably strong password after first boot ?

In the case of Mirai it's not even a cost issue, just lacking good practices.


"How many pennies would've been needed to insert a simple page forcing you to change user/password combo and to choose a reasonably strong password after first boot ?"

These are written by outsourced developers who don't know anything about security. They wouldn't even think to develop something as simple as that.

You are obviously unaware of how this works, companies would have to hire consultants/penetration testers to assess the product first. Then they would spend even more money making the changes suggested by the consultants. So it would cost a lot of pennies.. actually.


Ok, I am aware of how it works, but I'm not talking pentests or hardening. I'm talking simple, cheap design choices in this case, that could've eliminated the whole Mirai debauchery.

In your app you already have a setup wizard, right ? Add one more page to the end "Hey, we're almost done! We just need to make sure your device is secure. Please choose a username and (strong) password." Edit: Because if you have a login, you already have the components in place, you are not developing a new feature.

This one simple, design choice would have cost very little, both in terms of development time and increase in support costs, because Support is a cost center that scales with your user base and your knowledge base. Obviously not pennies, but still small costs.

There is the classical point of diminishing returns from security investments, problem is for most IoT products, we are significantly left, towards zero investments and, at this point, small investments and a few smart design choices would yield significant returns in security.

And with developers that's exactly what I don't get. How has it not become internalized that allowing users to run the default user/pass combo is very poor idea ? I'm not asking for much, I don't expect them to know a lot about security, but not even adhering to some basic good practices of security is killing me.


" Ok, I am aware of how it works, but I'm not talking pentests or hardening. I'm talking simple, cheap design choices in this case, that could've eliminated the whole Mirai debauchery."

Then you are not talking about the security industry or its failure to work are you? Its a failure in the development industry to have basic security awareness.

If you don't engage the security industry for pentests or consulting. You can't go any blame them when you get hacked.


>Its a failure in the development industry to have basic security awareness. //

Is that really it? Surely even a high-school level developer will realise that having a device connected to the wild web with a default user:pass will be hacked easily.

I'd have thought the problem is not wanting to support customer calls saying "we changed the password and now can't access our device". So default user:pass and no prompt to change it (and a backdoor just in case) means lower support costs.


No, that dev will say "It will be behind a NAT, so it's fine to have a default user:pass"


> I'm talking simple, cheap design choices in this case, that could've eliminated the whole Mirai debauchery.

This is utterly ignorant of the facts, Mirai took advantage of weak passwords to spread, but was not dependent upon them.


Anything that adds any interaction with the user will cost support time, thus dollars. Its easier for these companies to hard code a password in and have it "just work" with their mobile app or web interface than actually do security correctly.

Until there are regulations in place to make them do this, they will not care.


Amen, the Security Industry is doing great, security is doing poorly.


But when you tell someone "That's not secure, you can easily get hacked. You need to [insert good security practices here]", what response do you get ?

In my experience, most answer along the lines of "So what ? What could they get ? I have nothing important." or "Why would anyone ever hack me ?" or "But I have an antivirus, doesn't that make me safe ?".

And then spend the next 15 minutes explaining to them how things actually work and why they need to take it seriously and offer to help. 9 out of 10, they never reach out. And it's not their fault, but the way security in general is perceived.


I think it's just a general misunderstanding of what privacy means. I've explained several times and even convinced a few people that just because they think they have nothing to hide, they generally do have something they don't want someone to know about or see. At best they will just revert back to the "I have nothing to hide" mentality after a week. I think people outside of tech just don't see how damaging it can be when you loose privacy.


You implement security in order to have privacy and I agree it's poorly understood in the digital realm, mostly because it's "out of sight and out of mind". I like to use an analogy I can't remember where I picked up and reductio ad absurdum to get them past this automatic response, because that's what it is and it's based in the horrid and dangerous "Nothing to hide, nothing to fear" saying.

- The usual conversation - I ask them: "Do you have curtains ?" and they say: "Yes, of course" and I ask "Why ? I mean you have nothing to hide right ? What does it matter if someone can see what you are doing inside your house ?", usually they freeze for a second, "Because it's creepy". I continue "Well if it's creepy that someone would watch you in your house, isn't it just as creepy if they watched you online, what you read, what porn you watch, what you talk to your friends about ? Which do you think tells more about who you are ?". At this point silence and an increasingly worried look is the norm. I keep going: "It's not about hiding anything, it's about what is private. Otherwise why not tell everyone your darkest secret, your greatest fears, the thing you are most ashamed of doing in your life ? And that's why you should do [this or that]"

But even so, it's true most default back quickly. Still a few call, ask, improve their practices. People only seem to take it seriously after they have been directly impacted in a powerfully damaging way.

Edit: I have obviously had this conversation enough times to make this script in dealing with it. If you have to do it more than twice, automate it. :)


By sending binary SMSs. There are multiple classes of SMS, including binary messages through which operators can access and change data directly on your SIM. Since that's also your crypto chip, yeah ...

TLDR: https://www.contextis.com/resources/blog/binary-sms-old-back...

If you have a few days: http://www.tamps.cinvestav.mx/~vjsosa/clases/redes/Mobile%20...

Edit: You might find them referenced as silent SMSs, because you never see any indication of receiving it.


Call it VeraCrypt, because TrueCrypt is dead now.


His defense will be that he never had criminal intention, that it was an unfortunate accident, that can be chalked up to inexperience and curiosity. That he didn't take measures to hide his identity and that he was attempting to report a security issue and that the version that dialed 911 is a very very stupid idea of a joke.

And the prosecution will argue that the very action of writing a piece of software that targets a critical infrastructure is proof of in itself of criminal intention.

It will be up to the judge, but hopefully he will be lenient.

This should serve as a warning for 2 things for you younger cats out there:

1. Learn how to disclose responsibly. Use proper channels for disclosing vulnerabilities and don't post exploits online like that (only after you have made contact, reported it and discussed a reasonable time table for patching or not at all). Or know the risk of full disclosure and go with that, but still never post a exploit like that online like that.

2. Any idea of a joke that involves the authorities should trigger a "Yeah, authorities are not well known for their sense of humor. They tend to not be amused" moment.

Edit: The attack against 911 was in the code itself and that argument won't stand a second in Court.

Be smart, stay safe, happy hacking!


Heaven forbid he gets a public defender who doesn't have the time to hear/understand the facts of his case because they're so swamped with other cases.


You just summed up most public defenders.

I hope he gets a real/competent lawyer.


Like any new technology early adopters pay way more, because economies of scale have yet to be achieved. Musk knows this, same with Tesla, he is marketing to a high-income target market first, because they are the ideal early adopters and it's easier to scale down rather than scale up features in a product.

And factoring in subsidies, electricity cost savings over a period 5-10 years, it might be more affordable than you think.


Facepalm.

Damn kids, they're all alike ...



Was wondering how long it took for someone to catch that. :)


The language is intentionally crap. Attribution is always difficult.


There's some software to intentionally mess up your writing style for easier anonymity

It is really hard to do that manually


You mean this: https://github.com/psal/anonymouth

Yes, it apparently is, we have a lot of personal tells.


To go with Lemmy "Regrets are always late and usually pointless" and to go with Frank "... I have a few, but then again too few to mention", except 1. not marrying her.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: