Showing posts with label IoT. Show all posts
Showing posts with label IoT. Show all posts

Monday, September 24, 2018

Peekaboo

Taiwanese based-company NUUO who makes camera firmware has recently issued a patch for a zero-day vulnerability named Peekaboo (CVE-2018-1149, CVE-2018-1150) that exploits IoT video recorder software. The vulnerability was discovered by Jacob Baines, a senior research engineer at Tenable. From Tenable's blog on CVE-2018-1150 specifically:
If a file named /tmp/moses exists, the backdoor is enabled. It permits the listing of all user accounts on a system, and allows someone to change any account’s password. This would, for example, permit an attacker to view the camera feeds, view CCTV recordings, or remove a camera from the system entirely. This vulnerability has a CVSSv2 Base Score of 4.0 and a Temporal Score of 3.2, and is rated Medium severity. 
This is a very odd artifact. We weren’t able to determine if it’s leftover development code or if it was maliciously added. To be able to activate and utilize the backdoor, an attacker would need to be able to create the file “/tmp/moses,” so the attack would require some form of access or need to be combined with another exploit. Its existence and lack of obfuscation in the code is the real mystery.
Bleeping Computer article.

Monday, September 17, 2018

Smarter IoT Privacy Protections for Kids (CA SB 327)

From a WaPo article:
A bill to set cybersecurity standards for Web-connected devices — from thermostats to webcams to cars — is awaiting Gov. Jerry Brown’s (D) signature after cruising through the state legislature late last month. If Brown signs it, California would become the first state to pass legislation to govern security of the Internet of Things...
The California bill, SB-327, seeks to address some of those flaws, setting baseline cybersecurity standards for IoT devices where none exist. 

A most recent bill analysis is posted at California's Legislation Information website. The analysis includes a summary of existing law, a summary of this bill, background, comments, fiscal effects, and those groups in support and those opposed with a brief summary of their arguments. Here are some comments from the 8/28/18 Senate Floor Analysis:
Consumer devices that connect to the internet have moved well beyond the traditional desktop PC to include a wide variety of consumer electronics, such as microwaves, refrigerators, and children’s toys. While such capabilities may increase product functionality, many consumers are uninformed about the consequences of owning connected devices. Consumers may buy a device without realizing how it makes use of the internet, what types of information it collects, and how that information is used, until well after they have begun using the device in their home. Some internet connected toys, for example, prompt children to provide personal data verbally - including their parents’ names, the name of their school, and where they live – and explicitly reserve the right to conduct direct marketing towards kids. An alarming number of these internet connected devices lack even the most basic security features, rendering them vulnerable to hacking and coordinated cyber attacks.
This bill creates a common sense security requirement for internet connected devices that can evolve as technology evolves. Mirroring a provision in California’s Data Breach Law, this bill requires manufacturers to equip their devices with reasonable security features appropriate to the nature of the device and the information it collects.

Wednesday, September 12, 2018

IoT Security and the Looming Legal ‘Feeding Frenzy’

The lawyer who is representing the 220,000 plaintiffs in the 2015 Jeep hack class action lawsuit,  Ijay Palansky, presented at Black Hat USA 2018. He outlines the potential pathways of harm for the IoT including DDoS attacks, IoT ransomware, data breaches, privacy-related events, potential for cyber-physical, etc. He offers that there are currently few precedents or standards of care for how the law applies to tech and the complex IoT supply chain ecosystem. Here are his presentation slides and abstract:
Legal Liability for IOT Cybersecurity Vulnerabilities
There has been much discussion of "software liability," and whether new laws are needed to encourage or require safer software. My presentation will discuss how -- regardless of whether new laws are passed -- a tidal wave of litigation over defective IoT cybersecurity is just over the horizon.
The presentation will focus on a well-known example: Charlie Miller and Chris Valasek's 2015 Jeep hack. I'm lead counsel in the ongoing federal litigation over the cybersecurity defects Charlie and Chris exposed, and that are shared by 1.4 million Chrysler vehicles. As far as I know, our case is one of the first, and the biggest, that involves claims that consumers should be compensated for inadequate cybersecurity in IoT products.
This case is the tip of the iceberg. IOT products are ubiquitous, and in general their cybersecurity is feeble, at best. In the event of a cyberphysical IoT hack that causes injury, there are established legal doctrines that can be used to impose liability every company involved in the design, manufacturing, and distribution of an exploited IoT device or even its cyber-related components. Such liability could be crippling, if not fatal, for organizations that don't know how to properly handle and prepare for potential lawsuits.
Taking steps to minimize legal exposure before an accident happens or a lawsuit is filed—in the design, manufacture, product testing, and marketing phases of an IoT product—can be the difference between life and death for IoT companies. Knowing what steps to take and how to take them requires an understanding of the core legal principles that will be applied in determining whether a company is liable.
Article.