Endpoint
8/10/2014
10:00 PM
Brian Prince
Brian Prince
Quick Hits
50%
50%

Small IoT Firms Get A Security Assist

BuildItSecure.ly, an initiative where researchers vet code for small Internet of Things vendors, in the spotlight at DEF CON 22.

LAS VEGAS — DEF CON 22 — There was a time when people did not have to think about an egg tray connected to the Internet. But those days are gone.

Researchers Mark Stanislav and Zach Lanier of Duo Security here today spotlighted the increasingly connected world of devices that comprise the Internet of Things (IoT), and how the IoT continues to be challenged when it comes to security. Their solution was the creation of BuildItSecure.ly, a partnership of vendors and researchers working to make sure devices that make up the IoT are built... well, securely.

BuildItSecure.ly, which was launched in February, is focused on small vendors and startups, Stanislav says. So far, the initiative has drawn support from vendors such as Dropcam, which was recently acquired by Google's Nest Labs, and Belkin as well as security researchers from companies such as IOActive and Lab Mouse Security. Bugcrowd is supporting the initiative as well, and the BuildItSecure.ly website contains links to information on security ranging from presentation slides to technical documents on standards and best-practices.

"All the researchers basically are doing this -- one, because they want to help some people; two, because they are getting research done and not being sued for it," says Stanislav. "They already have opt-in from these vendors.

"We're going to have researchers looking at pre-production hardware, doing assessments against them… and actually making the device better before they go to people's hands rather than after."

The emphasis is on small vendors, the researchers explain, because startups and smaller vendors may not have the resources and budget to focus on security. Many may not know how to react to a security researcher poking holes in their product, either.

"They don't quite get why you're coming to them telling them that their baby is ugly," says Lanier.

"They don't have the resources or the experience to necessarily deal with this," he adds, noting that security researchers likewise might not know how to approach a smaller vendor unused to dealing with the security community.

The stakes can be high: Take the research the firm publicized last year that uncovered security weaknesses in the IZON IP camera.

"The number of devices that we have in IoT where you have firmware going, we can barely update one router," Stanislav says. "What makes us think that we're going to update like hundreds of devices in our household in five years?"

The ecosystem of the Internet of Things is also messy, the researchers note.

"There's a lot going on just in terms of how diverse the technologies are," says Stanislav. "The ecosystem's really messed up right now. You see companies big and small trying to standardize and trying to make sense of it all, but really we don't see that quite yet, and I don't think we will for a while.

"The problem we've always had with embedded hardware is you get random OEMs, you have firmware that nobody's actually done a security audit of, kernels that are, like, 15 years old," he laments. "This is the kind of stuff that we are putting in our networks right now. So even if the device is new, the actual technology underlying it is probably not."

Brian Prince is a freelance writer for a number of IT security-focused publications. Prior to becoming a freelance reporter, he worked at eWEEK for five years covering not only security, but also a variety of other subjects in the tech industry. Before that, he worked as a ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Gary Scott
50%
50%
Gary Scott,
User Rank: Apprentice
8/12/2014 | 6:58:44 PM
Small firms don't have the resources to deal with IT security
You are right, the stakes are higher for smaller companies and they don't have the resources to deal with many security issues.  For example, I work with small and large companies regulated by the same data privacy laws.  

Both large and small companies must follow the same steps to comply (in my case it is data destruction) but the small company is at a disadvantage.  One small mistake and it could be bankruptcy.

 
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2012-2808
Published: 2015-04-01
The PRNG implementation in the DNS resolver in Bionic in Android before 4.1.1 incorrectly uses time and PID information during the generation of random numbers for query ID values and UDP source ports, which makes it easier for remote attackers to spoof DNS responses by guessing these numbers, a rel...

CVE-2014-9713
Published: 2015-04-01
The default slapd configuration in the Debian openldap package 2.4.23-3 through 2.4.39-1.1 allows remote authenticated users to modify the user's permissions and other user attributes via unspecified vectors.

CVE-2015-0259
Published: 2015-04-01
OpenStack Compute (Nova) before 2014.1.4, 2014.2.x before 2014.2.3, and kilo before kilo-3 does not validate the origin of websocket requests, which allows remote attackers to hijack the authentication of users for access to consoles via a crafted webpage.

CVE-2015-0800
Published: 2015-04-01
The PRNG implementation in the DNS resolver in Mozilla Firefox (aka Fennec) before 37.0 on Android does not properly generate random numbers for query ID values and UDP source ports, which makes it easier for remote attackers to spoof DNS responses by guessing these numbers, a related issue to CVE-2...

CVE-2015-0801
Published: 2015-04-01
Mozilla Firefox before 37.0, Firefox ESR 31.x before 31.6, and Thunderbird before 31.6 allow remote attackers to bypass the Same Origin Policy and execute arbitrary JavaScript code with chrome privileges via vectors involving anchor navigation, a similar issue to CVE-2015-0818.

Dark Reading Radio
Archived Dark Reading Radio
Good hackers--aka security researchers--are worried about the possible legal and professional ramifications of President Obama's new proposed crackdown on cyber criminals.