A Firewall for Internet of Things(ieeexplore.ieee.org)
ieeexplore.ieee.org
A Firewall for Internet of Things
https://ieeexplore.ieee.org/document/7945418/
7 comments
Homekit routers achieve a similar result by isolating each device from every device on the network then utilises a white list approved by the manufacturer for internet connectivity or at the user's option blocking all internet connectivity altogether.
It's much more realistic that IoT devices need to exist in a sandbox, the utterly massive number of devices and security threats ensures that IoT devices will forever be a persistent weak point in a network.
Commonly-cited example for IoT devices being hacked: https://www.businessinsider.com/hackers-stole-a-casinos-data...
alternative link: https://www.entrepreneur.com/business-news/a-casino-gets-hac...
It's much more realistic that IoT devices need to exist in a sandbox, the utterly massive number of devices and security threats ensures that IoT devices will forever be a persistent weak point in a network.
Commonly-cited example for IoT devices being hacked: https://www.businessinsider.com/hackers-stole-a-casinos-data...
alternative link: https://www.entrepreneur.com/business-news/a-casino-gets-hac...
I really like the IoT/smarthouse concept, but exactly due to security issues, I'm pretty much limited to esp8266/32 devices with tasmota support, and zigbee devices with zigbee2mqtt support, just to keep the crap off the internet, and only connected to my HomeAssistant server.
It kinda sucks, since it's impossible to find some stuff, because it only supports some cloud-based tech, but there are more and more devices appearing that fulfill a need and can work entirely within my home network.
It kinda sucks, since it's impossible to find some stuff, because it only supports some cloud-based tech, but there are more and more devices appearing that fulfill a need and can work entirely within my home network.
My main firewalling issue is my new car, with a SIM card built-in somewhere, formally "just to being able to switch on AC/heating from remote, locate the car etc" but built-in with unknown level of real access from someone else computers. Next threats are not only from that: "smart grid" for charging (and discharging) cars will be another and so on.
The real issue is that without MANDATORY free software and open hw we have no real choice but trust someone else not only trusting for it's honesty but also for the quality of it's work in safety terms.
If a thief came in my home knowing I'm not there and steal something I have a good enough insurance, such kind of "safety issue" is already fixed. If someone attempt to penetrate my homeserver FOR THE PART I know of (i.e. the FLOSS OS/stuff it run) I can protect myself, I have offline backups etc. I have NO POSSIBLE PROTECTION for:
- State services, often handled by private subcontractors, for instance for taxes. Sure SO FAR I still have paper backups of anything, but in a future they will not be there;
- Smart devices capable of physically attacking something, like a self-driving car hitting a school groups on a trip stating I was in control, not in auto-pilot mode and that my control was fully effective to break/steer anyway, or a generic attack locking some cars in strategic places on the road networks paralyzing traffic for hours and so on.
Most people do not understand even the possibility and implications of such threats, BUT THOSE WHO UNDERSTAND and accept passively or even worse implement such systems should feel themselves guilty for crimes against humanity up front...
The real issue is that without MANDATORY free software and open hw we have no real choice but trust someone else not only trusting for it's honesty but also for the quality of it's work in safety terms.
If a thief came in my home knowing I'm not there and steal something I have a good enough insurance, such kind of "safety issue" is already fixed. If someone attempt to penetrate my homeserver FOR THE PART I know of (i.e. the FLOSS OS/stuff it run) I can protect myself, I have offline backups etc. I have NO POSSIBLE PROTECTION for:
- State services, often handled by private subcontractors, for instance for taxes. Sure SO FAR I still have paper backups of anything, but in a future they will not be there;
- Smart devices capable of physically attacking something, like a self-driving car hitting a school groups on a trip stating I was in control, not in auto-pilot mode and that my control was fully effective to break/steer anyway, or a generic attack locking some cars in strategic places on the road networks paralyzing traffic for hours and so on.
Most people do not understand even the possibility and implications of such threats, BUT THOSE WHO UNDERSTAND and accept passively or even worse implement such systems should feel themselves guilty for crimes against humanity up front...
Wouldn't that just be a regular wall?
There is no good, non-handwave-y (e.g. tiny additional BOM cost, tiny additional complexity for the firmware and plastic molds for the case) reason for IoT device manufacturers not including physical on-off switches for the devices' onboard radios.