Black hats and whitegoods

commentary The Internet of Things will soon become a serious security problem unless we start dealing with it right now. "Our dishwashers will kill us!"? Not quite. It'll be the tumble dryer — coordinated by the TV.

Fridge

Your fridge could be attacked. (Credit: LG)

With dozens of smart, internet-enabled devices connecting to the grid, the risks are certainly multiplying. Are manufacturers paying enough attention to security? I suspect not.

I spent most of yesterday in an AusCERT conference stream covering SCADA industrial control systems, resilient enterprise networks, smart meters, hardware security and the like. The discussion was held under the Chatham House rule, so I can't attribute comments to specific individuals. But I was left with the distinct impression that the bad guys are indeed winning. Again.

Up at the industrial and critical infrastructure end it's all talk of Stuxnet versus SCADA, just like it was at the RSA Conference in February. Iran is already claiming to have been hit by a next-generation Stuxnet, a thing called Stars, and experts reckon we'll probably see low-rent copies of Stuxnet within a year. The information is out there, gleaned from reverse-engineering Stuxnet, and the technology is attractive to criminals.

Why run a protection racket against a casino when you can threaten an entire oil refinery?

Now, the energy industry already understands the risks involved with operating critical infrastructure. Or at least it thinks it does, and it spends time and money working on the problem. Other industries are less knowledgeable. That'll be a challenge, and some of what we're hearing isn't good.

SCADA networks are scanned and probed and hit with distributed denial-of-service attacks (DDoS) with increasing frequency. They can be taken over simply by inserting a USB key into a network-connected PC. We saw that demonstrated live on stage. You can't stop the worm spreading through the protected network because it uses the same ports as SCADA itself. If you block those ports to block the worm, you also block your ability to control your own system. That's a win for the attacker.

"The bad guys know as much about our networks as we do," said one clued-up network defender. "The cat and the mouse? The cat is always going to win, and we've got to build smarter mice."

That doesn't exactly sound optimistic.

However, it's the consumer arena that really needs more attention.

Once smart meters get installed — as is already happening in parts of Australia — we'll soon have devices connected to both the energy company's wireless mesh and the home LANs and WLANs. This means that they're potential gateways. TVs now come with webcams and microphones, so they're potential monitoring devices. Appliances from air conditioners to swimming pool filter pumps have the potential to affect the physical environment. In-home displays can be fed false data.

As one presenter put it, "From the smart meter point of view, every device in the house is potentially hostile." Where is the network boundary here? Who's responsible for what? At this stage that's unclear.

What about the security of these devices? We were shown myriad ways to extract the encryption keys from hardware. As Stephen Wilson from the Lockstep Group tweeted, "I've always thought key management is like car engine maintenance circa 1910. Not for the faint hearted. Nor the future. The science is fine, but the engineering clunky and supply chain totally f***ed up. Crypto keys matter to users as much as DLLs."

Or, as a conference presenter put it, "Key management is epic fail for many systems."

That doesn't exactly sound optimistic, either.

Communications minister Senator Stephen Conroy once used the smart dishwasher as his NBN wonder story. It'd negotiate its own electricity price late at night and you'd save a fortune. Why hack the well-protected PC to rope it into a botnet when you can DDoS from the kitchen appliances?

Or, after last month, the PlayStation?

When was the last time you heard a whitegoods or consumer electronics manufacturer talk about network security? You certainly don't see them at the conferences.

We've been here before. We hooked our PCs into the internet. They got pwned; we didn't know any better. We hooked our smartphones into the internet. They got pwned; we'd forgotten that smartphones are computers, too. Now we're hooking TVs and tumble dryers into the internet. Falling for this trap a third time wouldn't be a good look. So far it's all questions with very few answers, and time is running out.

Talkback

There is actually a consumer backlash against this. Customers are sick of computerized washing machines that cost $200 to have a circuit board replaced, and are demanding in ever increasing numbers for the "old fashioned" mechanical timers for washing machines, dryers, dishwashers etc..

I, for one, don't need an IP address for each individual piece of cutlery in the house.

When it comes to "smart" metering, I will decide when to operate an appliance. There is no way that I am going to allow an energy supplier to kill the stove mid-cooking, nor will I stand for the desperately needed air-conditioning being shut down down between 2pm and 6 pm in the afternoon.

When it comes to the existing FIR technology that is used to turn off-peak hot water on and off and even X10 systems that can adjust your lighting and heating automatically, the data transfer rate is far too slow for anyone to be concerned about information disappearing from their PCs.

TreknologyTreknology May 17th, 2011
Report offensive content Reply (0) (0)

But what if by allowing them to turn off devices you could pay a much lower rate for electricity? Or it was the choice of having some, or none? Networks will need all the help they can get, I fear.

suzanne.tindalsuzanne.tindal May 17th, 2011
Report offensive content Reply (0) (0)
Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

Terms of Service - As a ZDNet registrant, and by using this service, you indicate that you agree to our Terms and Conditions and have read and understand our Privacy Policy.

Tech Blueprint

ZDNet Australia Live

The implications of NZ school Principals demanding access to student mobile devices | ZDNet http://t.co/jMSJXzpT

michael kors purse http://www.michaelkorshandbags-online.com/#37 ZLlrPzyxFdu

59 minutes ago by YJyqTygeShm on Kodak files for bankruptcy, sues Samsung

Google closes Motorola buy: http://t.co/9ezoLnSg

War talk dominates #AusCERT 2012 - http://t.co/WbuTt174 - #security #cyber

Nuance launches in car voice activated platform (Zack Whittaker ZDNet) http://t.co/9mFEA93c

Sage simplifies SMB payment management http://t.co/gbAKq1ku

A farewell to democracy: Kaspersky http://t.co/zE2SAGol via @zdnetaustralia

Private Cloud: 'Everyone’s got one. Where's yours?': Promising the business a cloud delivered within your own ... http://t.co/jCsDqPlj

BYOD: What the people think http://t.co/hR1pokPG

@ZDNet
R they joking? iPhone only way 2 go!
New 5 out in October (we think) & will kill all copycat phones, AGAIN!!

Android's biggest security flaws - Security - News - ZDNet Australia http://t.co/6nYZRvhh
@sjshock

Google: We now own Motorola Mobility http://t.co/oeFgovzl

@dougsteelman RT @dellsecureworks : Security researcher Tim Vidas of Dell SecureWorks outlines problems with the Androi…http://t.co/BE4LmItr

EMC hones focus on hybrid cloud, big data http://t.co/To6Qpsz4 #bigdata #XBRL #GRC $$

#Security researcher Tim Vidas of @DellSecureworks outlines some concerns with the #Android operating system: http://t.co/gV8MgCiN

Article and Infographic: Retailers attracting the next-gen customer http://t.co/UL3E2Fct #socialmedianews

adgtqMkWiDg //www.2012chanelbagsforsale.com]chanel handbags RKaOBd krFiudOGrBw //www.2012chanelbagsforsale.com]chanel outlet GQXRRYsDNI...

5 hours ago by rfcdvpmubn on Deakin Uni opts for Cisco Unified Computing

“@Techmeme: TiVo streaming coming to iOS this summer (@jasonogrady / ZDNet) http://t.co/07L0ndoD ” < wonder if it will work in AU

Security researcher Tim Vidas of Dell SecureWorks outlines problems with the Android operating system: http://t.co/lA4t9ffu

Why I (now) hate Apple | ZDNet - http://t.co/f5v6BWxu

A farewell to #democracy: (according to)> #Kaspersky http://t.co/82GeK5Ik via @zdnetaustralia

I am not sure how this issue becomes an attack on Mr Turnbull. But I guess he is fair game. In any event I would have thought a Ddos woul...

6 hours ago by Doubt on National Botnet Network coming: Earthwave

RT @JamesVickery: Westpac board goes paperless with iPads http://t.co/L8V05zFs

I still use 98SE. Windows ME was an abortion in a bucket and Vista was ME without the bucket. My screen may look boring, but I jumped str...

6 hours ago by Treknology on Microsoft admits Vista was 'cheesy'

What is it [url=http://vintage-erotic.com/] retro xxx movies [/url]? And why all this it is possible to look free of charge?

6 hours ago by Drienlyinhibe on Australian police swoop on Warez community

Windows 8 includes enhanced multi-monitor support http://t.co/ZVfVHntw

This story has been voted 10 times in the last 24 hours!

7 hours ago, CeBIT 2012 opens: photos

Android users, you think only Apple are having security problems. See what is your major problem.
http://t.co/cjJYSOJw #infosec

RT @my_CISB: Android users, you think only Apple are having security problems. See what is your major problem.
http://t.co/cjJYSOJw #infosec

This story has been voted 15 times in the last 24 hours!

7 hours ago, Lenovo ThinkPad 3G tablet (32GB)

RT @aimee_maree: "For Buytaert, Drupal owes much of its success to being open source" http://t.co/RdnHB2y9 #Drupal

Malware charges users for free Android apps on Google Play - http://t.co/Zhnf2rtw

Well I don't know what they have done with their EFTPOS machines, local one in WA Coles Express I used this morning and I normally do "ch...

7 hours ago by harryinthesoup on Coles ditches PINs in payment pilot

@TaschaD More information: http://t.co/8rfUsQJ0 I guess I shall simply go without.

RT @zdnetaustralia: The Westpac board have gone paperless using iPads and a secure, home-grown app environment: http://t.co/F1d17bvF ^LH

Chrome overtakes IE: does it matter? http://t.co/JRvKsVdn

"For Buytaert, Drupal owes much of its success to being open source" http://t.co/RdnHB2y9 #Drupal

RT @JamesVickery: Westpac board goes paperless with iPads http://t.co/L8V05zFs

Microsoft's big bet: Windows 8's 'too many cooks' problem http://t.co/8AdrUAWA

RT @JamesVickery: Westpac board goes paperless with iPads http://t.co/L8V05zFs

Will Windows Phone's bumpy start eventually lead to success? http://t.co/OSmxT8k6

@Wellsie777 @zdnetaustralia can be done http://t.co/jIlgdXJ4 I once had 2 phones with the same number without even trying!

ルブタンは彼が彼の靴に女性が感じる方法を好む、 クリスチャンルブタンポンプ これは彼がそれらを...

8 hours ago by Coiffboarieri on Reservoir blogs: Fan fakes Tarantino diary

US, Australia team up on cybersecurity - Security - News - #ZDNet Australia http://t.co/rG2aTskD

6.7 M last ditch attempt - interesting - The Auckland region (population 1.4 mil) has estimated to have spent less than this in total ...

10 hours ago by debsteele on Vic scraps HealthSMART system

Interesting - no mention of Win 98/ME/2000 ... which heralded Internet access for millions of users ? I thought Win 98/ME would be the mo...

12 hours ago by gouranga on Microsoft admits Vista was 'cheesy'

An Application like Good from Good Technologies does the same thing, working with the enterprise email server and is off the shelf.

12 hours ago by Helpdesk123 on Westpac board goes paperless with iPads

Never mind a "B+" version, go for "C" and put in a few extras. I'd like a high speed ADC (100Msps) but that's just me... Final size? Equ...

12 hours ago by sa_penguin on Raspberry Pi architect mulls design change

what a non-story. these thing happen all the time. is zdnet short on material?

13 hours ago by paulwrussell on Spotify launch suffers redirect bungle

4 months old phone died. Took 6 weeks, three visits to the authorised repairer (Fonebiz) to "fix it". 2nd hand untested parts used, I say...

13 hours ago by paracin on Sony Ericsson Xperia Arc S

It's easy to rubbish an old operating system long after the rest of the world has already passed judgement upon it. I would be far more i...

14 hours ago by ramnet on Microsoft admits Vista was 'cheesy'

If Vista is cheesy, Metro is an over-ripe Stilton.

14 hours ago by meski on Microsoft admits Vista was 'cheesy'

you are kidding right - what qualification do you have to make such wildy stupid statements - do you really have customers who pay you fo...

15 hours ago by rant rant rant on National Botnet Network coming: Earthwave

Exactly. There are two topics of discussion, that are co-mingled; 1) Unauthorized software was put on the company device, by an IT person...

18 hours ago by lamont on ABC's Bitcoin miner tackled in minutes

First off, Bitcoin is not a virus. Second off, the only way to generate Bitcoins, is by using a Bitcoin miner. More information on this h...

1 day ago by rizowski on ABC's Bitcoin miner tackled in minutes

When an operating system is sold it should not launch until an approved security service is purchased online with a list of approved supp...

1 day ago by Kevin Cobley on National Botnet Network coming: Earthwave

Admits? Don't fall for their marketing. Vista was beautiful. Microsoft has a history of trashing their older OSes.

1 day ago by anonymuos on Microsoft admits Vista was 'cheesy'

Facebook Activity

Keep up with ZDNet Australia

ZDNet Events Calendar

ZDNet Events Calendar