Are all IoT vulnerabilities easily avoidable?

frogboy

In memoriam 1961-2018
Thread author
Verified
Top Poster
Well-known
Jun 9, 2013
6,720
Every vulnerability or privacy issue reported for consumer connected home and wearable technology products since November 2015 could have been easily avoided, according to the Online Trust Alliance (OTA).
iot.png


“In this rush to bring connected devices to market, security and privacy is often being overlooked,” said Craig Spiezle, OTA Executive Director and President. “If businesses do not make a systemic change we risk seeing the weaponization of these devices and an erosion of consumer confidence impacting the IoT industry on a whole due to their security and privacy shortcomings.”

The most significant failures
To come up with its findings, OTA researchers analyzed publicly reported device vulnerabilities from November 2015 through July 2016. The researchers found the most glaring failures were attributed to:

1. Insecure credential management including making administrative controls open and discoverable.

2. Not adequately and accurately disclosing consumer data collection and sharing policies and practices.

3. The omission or lack of rigorous security testing throughout the development process including but not limited to penetration testing and threat modeling.

4. The lack of a discoverable process or capability to responsibly report observed vulnerabilities.

5. Insecure or no network pairing control options (device to device or device to networks).

6. Not testing for common code injection exploits.

7. The lack of transport security and encrypted storage including unencrypted data transmission of personal and sensitive information including but not limited to user ID and passwords.

8. Lacking a sustainable and supportable plan to address vulnerabilities through the product lifecycle including the lack of software/firmware update capabilities and/or insecure and untested security patches/updates.

Full Article. Are all IoT vulnerabilities easily avoidable? - Help Net Security
 
L

LabZero

9) No guarantee that these failures will be solved!

Manufacturers invest on how to present the product, praising mainly the technical features.
It is true, however, that security IoT is a problem that needs to be addressed at the institutional level.
 

ElectricSheep

Level 14
Verified
Top Poster
Well-known
Aug 31, 2014
655
What vulnerabilities? Simply don't buy any of these things and you're safe! The vulnerabilities I have is if I break my finger and cannot operate the light switch:p:p
 
Last edited:
  • Like
Reactions: Logethica

Myriad

Level 7
Verified
Well-known
May 22, 2016
349
"Are all IoT vulnerabilities easily avoidable? "

The short answer to that is a definite NO !


The only way to avoid them right now is to avoid buying such devices .

At least until such a time as the major manufacturers wake up , sit down together , and hammer out a set of
solid international protocols to lock down the security risks .

And when will that happen ?

Probably not before some congressman ( or president ) gets all of their sensitive emails hacked via their fridge/freezer .


 

NekoHr

Level 3
Verified
Well-known
Feb 5, 2016
139
What vulnerabilities? Simply don't buy any of these things and you're safe!

I agree with you on not buying these things (if we are talking about fridge and microwave) but same problems exist in mobile phones and television (and lately you almost can't buy them without "smart" features). Mobile phones are worst, you buy new one, get 2-3 updates and than nothing and it is fully functional computer with your whole digital persona on it.
 

Myriad

Level 7
Verified
Well-known
May 22, 2016
349
but same problems exist in mobile phones and television (and lately you almost can't buy them without "smart" features)

I remember reading last year about a new TV from a major manufacturer ( I won't mention the name ) that monitors speech in the room
and responds to any TV related words ( eg "Channel" or "Volume" ) .

If so , that is surely the IoT security vulnerability from hell !

Or did I just imagine that ?

Somebody please tell me that I didn't :)
 
  • Like
Reactions: ElectricSheep

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top