Endpoint
8/10/2014
10:00 PM
Brian Prince
Brian Prince
Quick Hits
50%
50%

Small IoT Firms Get A Security Assist

BuildItSecure.ly, an initiative where researchers vet code for small Internet of Things vendors, in the spotlight at DEF CON 22.

LAS VEGAS — DEF CON 22 — There was a time when people did not have to think about an egg tray connected to the Internet. But those days are gone.

Researchers Mark Stanislav and Zach Lanier of Duo Security here today spotlighted the increasingly connected world of devices that comprise the Internet of Things (IoT), and how the IoT continues to be challenged when it comes to security. Their solution was the creation of BuildItSecure.ly, a partnership of vendors and researchers working to make sure devices that make up the IoT are built... well, securely.

BuildItSecure.ly, which was launched in February, is focused on small vendors and startups, Stanislav says. So far, the initiative has drawn support from vendors such as Dropcam, which was recently acquired by Google's Nest Labs, and Belkin as well as security researchers from companies such as IOActive and Lab Mouse Security. Bugcrowd is supporting the initiative as well, and the BuildItSecure.ly website contains links to information on security ranging from presentation slides to technical documents on standards and best-practices.

"All the researchers basically are doing this -- one, because they want to help some people; two, because they are getting research done and not being sued for it," says Stanislav. "They already have opt-in from these vendors.

"We're going to have researchers looking at pre-production hardware, doing assessments against them… and actually making the device better before they go to people's hands rather than after."

The emphasis is on small vendors, the researchers explain, because startups and smaller vendors may not have the resources and budget to focus on security. Many may not know how to react to a security researcher poking holes in their product, either.

"They don't quite get why you're coming to them telling them that their baby is ugly," says Lanier.

"They don't have the resources or the experience to necessarily deal with this," he adds, noting that security researchers likewise might not know how to approach a smaller vendor unused to dealing with the security community.

The stakes can be high: Take the research the firm publicized last year that uncovered security weaknesses in the IZON IP camera.

"The number of devices that we have in IoT where you have firmware going, we can barely update one router," Stanislav says. "What makes us think that we're going to update like hundreds of devices in our household in five years?"

The ecosystem of the Internet of Things is also messy, the researchers note.

"There's a lot going on just in terms of how diverse the technologies are," says Stanislav. "The ecosystem's really messed up right now. You see companies big and small trying to standardize and trying to make sense of it all, but really we don't see that quite yet, and I don't think we will for a while.

"The problem we've always had with embedded hardware is you get random OEMs, you have firmware that nobody's actually done a security audit of, kernels that are, like, 15 years old," he laments. "This is the kind of stuff that we are putting in our networks right now. So even if the device is new, the actual technology underlying it is probably not."

Brian Prince is a freelance writer for a number of IT security-focused publications. Prior to becoming a freelance reporter, he worked at eWEEK for five years covering not only security, but also a variety of other subjects in the tech industry. Before that, he worked as a ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Gary Scott
50%
50%
Gary Scott,
User Rank: Apprentice
8/12/2014 | 6:58:44 PM
Small firms don't have the resources to deal with IT security
You are right, the stakes are higher for smaller companies and they don't have the resources to deal with many security issues.  For example, I work with small and large companies regulated by the same data privacy laws.  

Both large and small companies must follow the same steps to comply (in my case it is data destruction) but the small company is at a disadvantage.  One small mistake and it could be bankruptcy.

 
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading December Tech Digest
Experts weigh in on the pros and cons of end-user security training.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-5395
Published: 2014-11-21
Multiple cross-site request forgery (CSRF) vulnerabilities in Huawei HiLink E3276 and E3236 TCPU before V200R002B470D13SP00C00 and WebUI before V100R007B100D03SP01C03, E5180s-22 before 21.270.21.00.00, and E586Bs-2 before 21.322.10.00.889 allow remote attackers to hijack the authentication of users ...

CVE-2014-7137
Published: 2014-11-21
Multiple SQL injection vulnerabilities in Dolibarr ERP/CRM before 3.6.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) contactid parameter in an addcontact action, (2) ligne parameter in a swapstatut action, or (3) project_ref parameter to projet/tasks/contact.php; (4...

CVE-2014-7871
Published: 2014-11-21
SQL injection vulnerability in Open-Xchange (OX) AppSuite before 7.4.2-rev36 and 7.6.x before 7.6.0-rev23 allows remote authenticated users to execute arbitrary SQL commands via a crafted jslob API call.

CVE-2014-8090
Published: 2014-11-21
The REXML parser in Ruby 1.9.x before 1.9.3 patchlevel 551, 2.0.x before 2.0.0 patchlevel 598, and 2.1.x before 2.1.5 allows remote attackers to cause a denial of service (CPU and memory consumption) a crafted XML document containing an empty string in an entity that is used in a large number of nes...

CVE-2014-8469
Published: 2014-11-21
Cross-site scripting (XSS) vulnerability in Guests/Boots in AdminCP in Moxi9 PHPFox before 4 Beta allows remote attackers to inject arbitrary web script or HTML via the User-Agent header.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Now that the holiday season is about to begin both online and in stores, will this be yet another season of nonstop gifting to cybercriminals?