Discover this podcast and so much more

Podcasts are free to enjoy without a subscription. We also offer ebooks, audiobooks, and so much more for just $11.99/month.

April Wright and Alyssa Miller - IoT platforms, privacy and security, embracing standards

April Wright and Alyssa Miller - IoT platforms, privacy and security, embracing standards

FromBrakeSec Education Podcast


April Wright and Alyssa Miller - IoT platforms, privacy and security, embracing standards

FromBrakeSec Education Podcast

ratings:
Length:
42 minutes
Released:
Feb 15, 2022
Format:
Podcast episode

Description

Alyssa Milller (@AlyssaM_InfoSec) April Wright (@Aprilwright)   Open Source issues (quick discussion, because I value your opinions, and supply chain is important in the IoT world too.) Log4j and OSS software management and profitability Free as in beer, but you pay for the cup… (license costs $$, not the software).  “If you make money using our software, you must buy a license” - not an end-user license   Open source conference at Whitehouse: https://www.zdnet.com/article/log4j-after-white-house-meeting-google-calls-for-list-of-critical-open-source-projects/ https://www.wsj.com/articles/white-house-convenes-open-source-security-summit-amid-log4j-risks-11642119406 “For too long, the software community has taken comfort in the assumption that open source software is generally secure due to its transparency and the assumption that many eyes were watching to detect and resolve problems,” said Kent Walker, chief legal officer at Google in a blog post published after the meeting. “But in fact, while some projects do have many eyes on them, others have few or none at all.”  Show was inspired by this Twitter conversation: https://twitter.com/aprilwright/status/1461724712455782400?t=Fv2tmSTXrn-SSjPCka3gxg&s=19   https://twitter.com/AlyssaM_InfoSec/status/1464661807751213056?t=CFy-hgcHo2a8NwowKYo0hg&s=19   IOT architecture (https://www.avsystem.com/blog/iot-ecosystem/) Open source IoT platforms: https://www.record-evolution.de/en/open-source-iot-platforms-making-innovation-count/   Cloud services - processing messages, register/de-register devices, pass messages to other devices/gateways Gateways -  Devices -  Mobile apps - SDKs -  integrations   Cloud services DO go offline, point of failure:https://www.datacenterdynamics.com/en/news/aws-us-east-1-outage-brings-down-services-around-the-world/ Connectivity and sharing mesh networks assumes you like your neighbors. Sidewalk Whitepaper: https://m.media-amazon.com/images/G/01/sidewalk/final_privacy_security_whitepaper.pdf   network vulnerabilities: https://fractionalciso.com/why-you-should-not-be-using-xfinitywifi-hotspots/  Stalking/privacy vs. tracking/surveillance   Fine GPS locations Nearby devices triangulate (via BLE, wifi, or 900mhz) We want to find our lost devices, but devices can be used for stalking https://www.autoevolution.com/news/police-claim-apple-has-unwillingly-created-the-most-convenient-stalking-device-179228.html   Just have an iPhone and you’ll be able to find a stalking device, just install a 100MB app (Ring, Alexa, etc) to detect all devices in the area, or use the right ecosystem to find these items (or know every possible device that could be used to track someone)   What do companies want with that information?   What is a ‘happy medium’ to allow you to find your dog, but not to track people? Device controls? Buzzers? (how loud can you make a noise in a small device?) Size issues, battery life, beaconing, self-identification (“Hi, I am a lost device…”) Is what Airtags doing enough to reduce the fear? Are we designing to edge cases? There are cheaper/easier ways to track someone (phones have a longer standby time than fetch/airtag/tile) How often do you lose your keys? Why is your dog not on a leash or properly trained? What will it take to make these kinds of devices more secure?  https://spectrum.ieee.org/why-iot-sensors-need-standards Will it take privacy protections to motivate IoT devices to design a better IoT device? Or force standards to be followed, like https://www.ioxtalliance.org/get-ioxt-certified? Or NIST standards: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-213-draft.pdf https://csrc.nist.gov/publications/detail/sp/800-213a/final - detailed specs Threat modeling, vulnerabilities in IoT networks and platforms   Does your Iot Platform give out SDKs for integrations or allowing 3rd party products or apps? https://www.iot-inspector.com/blog/advisory-multiple-issues-realtek-sdk-iot-supply-chain/   https:
Released:
Feb 15, 2022
Format:
Podcast episode

Titles in the series (100)

A podcast all about the world of Cybersecurity, Privacy, Compliance, and Regulatory issues that arise in today's workplace. Co-hosts Bryan Brake, Brian Boettcher, and Amanda Berlin teach concepts that aspiring Information Security Professionals need to know, or refresh the memories of the seasoned veterans.