[193645] in North American Network Operators' Group

home help back first fref pref prev next nref lref last post

Re: IoT security

daemon@ATHENA.MIT.EDU (valdis.kletnieks@vt.edu)
Thu Feb 9 16:14:20 2017

X-Original-To: nanog@nanog.org
From: valdis.kletnieks@vt.edu
X-Google-Original-From: Valdis.Kletnieks@vt.edu
To: William Herrin <bill@herrin.us>
In-Reply-To: <CAP-guGVaD+wbAXWJhg_dAYNph1XiAe-6i_nC+bckWzk1D34t_A@mail.gmail.com>
Date: Thu, 09 Feb 2017 15:18:15 -0500
Cc: "nanog@nanog.org" <nanog@nanog.org>, Rich Kulawiec <rsk@gsp.org>
Errors-To: nanog-bounces@nanog.org

--==_Exmh_1486671495_2886P
Content-Type: text/plain; charset=us-ascii

On Thu, 09 Feb 2017 14:54:26 -0500, William Herrin said:

> Is there some way an industry association could overcome this? Perhaps
> have some trivial way to assign each model of IoT device some kind of
> integer and have the device report the integer instead of its plain
> text manufacturer and hardware model number? Where the assigned
> integer is intentionally not published by the industry association
> though of course trivially determinable by anyone who owns one of the
> devices.

Or anybody who knows how to use the internet to look for reports of owners who
have issues.  All it takes is one smarter than the average bear user posting
"I've got a MobyWombat 3000 light bulb, and it keeps sending 1193432542 to some
server someplace...."

> Wouldn't especially impair building a database of vulnerable
> devices but it would raise the bar for trying to turn the

If it doesn't *heavily* impair building a database of vulnerable devices,
it's not a solution to the problem under discussion.




--==_Exmh_1486671495_2886P
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Comment: Exmh version 2.5 07/13/2001

iQEVAwUBWJzOh40DS38y7CIcAQK/Xwf/b20yXSbW3PysYBycv3X1zfuY8Mel6VCy
oOPwGVavNDbQesiDWxIVndiOD3PryrX0bFZspyOqjyTGWI17YIVWSNmTF7UfBLAh
GJropJPxW8rcYxl2vkkdf89X/2QaKRdcCIooWuF0AupA+nu/Y5lSBO+BC+x36iqn
nBZgZq3VAtH5GlzlhixQA191wX+TrQmGRn2D/xU5xOMEMj8gHeoVV/k3MmPwPgKQ
wqm9TKZl6xim+mKiCNKTbOpMXQdr9ny75OfO/qnSAw1XkqKdFFrA82hsyd4zDRxp
EC2mVZ5WeRLOm+ZnFiX0QYdm9l58TrOSSbsy7kJwN5OTQew2Kmbh4g==
=6f7G
-----END PGP SIGNATURE-----

--==_Exmh_1486671495_2886P--

home help back first fref pref prev next nref lref last post