IncredulousDane142
kiwifarms.net
- Joined
- Dec 2, 2019
Shotty security for SCADA, "Smart" products, coffee pots pretty much anything you can slap a NIC in and call it "modernized"
Follow along with the video below to see how to install our site as a web app on your home screen.
Note: This feature may not be available in some browsers.
Rename the thread to IoT """Security"""
All of it. Security in IoT products are a joke because they were never designed with security in mind.
I remember fucking around with shodan.io with my teacher and classmates in college. Those were definitely both a learning experience and fun.Hence the existence of shodan.io
Just casually watching the security cameras of buildings in Asia.I remember fucking around with shodan.io with my teacher and classmates in college. Those were definitely both a learning experience and fun.
Even if I did- how is it acceptable for these vendors to be shipping with (really old) 2.x kernels, default passwords and open ssh servers, and unauthenticated and insecure means for firmware updates (not that the firmware updates will ever be used for security patches anyway)?
Really, it's a pity that China hasn't put together a reference Linux distro that can be mandated for all these things, along with mandatory updates to the base system and public executions for anyone who runs their outside-accessible servers as root or ships with default passwords for anything that allows owning the device.
Also for a lot of them, it's not just the money. Usually custom development work like that is initially done by an expert contractor and the gaggle of Rajneeshes they grab off Fiver couldn't get halfway through a header file without getting lost.The ancient kernels are usually a direct result of changes to the kernel source to make the hardware work. These customizations are often done with, lets say, little attention to kernel development guidelines, to put it mildly.
The end result can really sometimes only called being "linux-alike" but not really a proper kernel anymore. They have all sorts of issues with spagetti code, breaking stuff to make shit work, bypassing security features in the laziest way possible to make stuff work easier and so on. The code changes are often "chinese dude with degree in electrical engineering" quality. Usually the changes are peppered all over the kernel code in the most atrocious "14 day C tutorial" ways and that's also why porting this stuff to make a properly maintained mainline driver for the hardware in question is often akin to just rewriting the driver completely from the ground up. When the chinese company doing that atrocity feels like adhering to the GPL (they often don't, nobody does anything about that anyways) and publishes the source, you often can't even recompile their kernel with harmless different options (support for other filesystems etc.) because shit will break. It's that bad. Changes are of course never documented. That'd amount to additional work hours.
That the same kinds of people won't care about maintaing and updated userland to their kernel-soup doesn't need to be explained.
The problem is that these companies see linux and it's software landscape more as a cheap platform to support their current chinkshit hardware with and hack something together to make it work and don't care what will happen with it three months down the road when the product is already out the door. They even care less about the users' saftey with outdated kernels that often can't even really be patched if you were to port back security stuff. They don't want to invest the work and money to support mainline and write proper drivers and maintain them. They don't want to spend money on maintaining firmware updates. This will never change as this cheap hackery is an integral part of the chinese-gadget-shovelware business model. The only way to resolve this is to not buy such products.
All of it. Security in IoT products are a joke because they were never designed with security in mind.
why are internet-connected light bulbs even a thing
Some people are simultaneously technophiles & too lazy to RTFM to understand.why are internet-connected light bulbs even a thing
If a huge disaster happened now, people would be much more helpless than in just 20 years ago. Than just 10 years ago.Some people are simultaneously technophiles & too lazy to RTFM to understand.