0% found this document useful (0 votes)
6 views2 pages

Risks of Smart Objects and IoT Security

The article discusses the risks associated with 'smart' objects connected to the Internet, highlighting incidents where hackers have taken control of vehicles and other devices. It argues that the current state of cybersecurity is inadequate for the mass adoption of these technologies, leading to potential privacy violations and safety hazards. The author calls for stricter regulations and a reevaluation of the necessity of connecting everyday objects to the Internet.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
6 views2 pages

Risks of Smart Objects and IoT Security

The article discusses the risks associated with 'smart' objects connected to the Internet, highlighting incidents where hackers have taken control of vehicles and other devices. It argues that the current state of cybersecurity is inadequate for the mass adoption of these technologies, leading to potential privacy violations and safety hazards. The author calls for stricter regulations and a reevaluation of the necessity of connecting everyday objects to the Internet.
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

Why ‘Smart’ Objects May Be a Dumb Idea

By Zeynep Tufekci
Aug. 10, 2015

A FRIDGE that puts milk on your shopping list when you run low. A safe that tallies the cash that is placed
in it. A sniper rifle equipped with advanced computer technology for improved accuracy. A car that lets you
stream music from the Internet.

All of these innovations sound great, until you learn the risks that this type of connectivity carries.
Recently, two security researchers, sitting on a couch and armed only with laptops, remotely took over a
Chrysler Jeep Cherokee speeding along the highway, shutting down its engine as an 18-wheeler truck
rushed toward it. They did this all while a Wired reporter was driving the car. Their expertise would allow
them to hack any Jeep as long as they knew the car’s I.P. address, its network address on the Internet. They
turned the Jeep’s entertainment dashboard into a gateway to the car’s steering, brakes and transmission.

A hacked car is a high-profile example of what can go wrong with the coming Internet of Things — objects
equipped with software and connected to digital networks. The selling point for these well-connected objects
is added convenience and better safety. In reality, it is a fast-motion train wreck in privacy and security.

The early Internet was intended to connect people who already trusted one another, like academic
researchers or military networks. It never had the robust security that today’s global network needs. As the
Internet went from a few thousand users to more than three billion, attempts to strengthen security were
stymied because of cost, shortsightedness and competing interests. Connecting everyday objects to this
shaky, insecure base will create the Internet of Hacked Things. This is irresponsible and potentially
catastrophic.

That smart safe? Hackers can empty it with a single USB stick while erasing all logs of its activity — the evidence
of deposits and withdrawals — and of their crime. That high-tech rifle? Researchers managed to remotely
manipulate its target selection without the shooter’s knowing.

Home builders and car manufacturers have shifted to a new business: the risky world of information technology.
Most seem utterly out of their depth.

Although Chrysler quickly recalled 1.4 million Jeeps to patch this particular vulnerability, it took the
company more than a year after the issue was first noted, and the recall occurred only after that spectacular
publicity stunt on the highway and after it was requested by the National Highway Traffic Safety Administration.
In announcing the software fix, the company said that no defect had been found. If two guys sitting on their couch
turning off a speeding car’s engine from miles away doesn’t qualify, I’m not sure what counts as a defect in
Chrysler’s world. And Chrysler is far from the only company compromised: from BMW to Tesla to General
Motors, many automotive brands have been hacked, with surely more to come.

Dramatic hacks attract the most attention, but the software errors that allow them to occur are ubiquitous. While
complex breaches can take real effort — the Jeep hacker duo spent two years researching — simple errors in
the code can also cause significant failure. Adding software with millions of lines of code to objects greatly
increases their potential for harm.

The Internet of Things is also a privacy nightmare. Databases that already have too much information about us
will now be bursting with data on the places we’ve driven, the food we’ve purchased and more. Last week, at
Def Con, the annual information security conference, researchers set up an Internet of Things village to show
how they could hack everyday objects like baby monitors, thermostats and security cameras.

Connecting everyday objects introduces new risks if done at mass scale. Take that smart refrigerator. If a single
fridge malfunctions, it’s a hassle. However, if the fridge’s computer is connected to its motor, a software bug or
hack could “brick” millions of them all at once — turning them into plastic pantries with heavy doors.
Cars — two-ton metal objects designed to hurtle down highways — are already bracingly dangerous. The
modern automobile is run by dozens of computers that most manufacturers connect using a system that is old
and known to be insecure. Yet automakers often use that flimsy system to connect all of the car’s parts. That
means once a hacker is in, she’s in everywhere — engine, steering, transmission and brakes, not just the
entertainment system.

For years, security researchers have been warning about the dangers of coupling so many systems in cars.
Alarmed researchers have published academic papers, hacked cars as demonstrations, and begged the
industry to step up. So far, the industry response has been to nod politely and fix exposed flaws without
fundamentally changing the way they operate.

In 1965, Ralph Nader published “Unsafe at Any Speed,” documenting car manufacturers’ resistance to spending
money on safety features like seatbelts. After public debate and finally some legislation, manufacturers were
forced to incorporate safety technologies.

No company wants to be the first to bear the costs of updating the insecure computer systems that run most
cars. We need federal safety regulations to push automakers to move, as a whole industry. Last month, a bill
with privacy and cybersecurity standards for cars was introduced in the Senate. That’s good, but it’s only a start.
We need a new understanding of car safety, and of the safety of any object running software or connecting to
the Internet.

It may be hard to fix security on the digital Internet, but the Internet of Things should not be built on this faulty
foundation. Responding to digital threats by patching only exposed vulnerabilities is giving just aspirin to a very
ill patient.

It isn’t hopeless. We can make programs more reliable and databases more secure. Critical functions on Internet-
connected objects should be isolated and external audits mandated to catch problems early. But this will require
an initial investment to forestall future problems — the exact opposite of the current corporate impulse. It also
may be that not everything needs to be networked, and that the trade-off in vulnerability isn’t worth it. Maybe
cars are unsafe at any I.P.

Zeynep Tufekci is an assistant professor at the School of Information and Library Science at the University of
North Carolina and a contributing opinion writer.

Common questions

Powered by AI

Reconsidering the connection of everyday objects to the Internet may be necessary due to the significant security and privacy risks posed by the Internet of Things. With millions of lines of code being added to objects, there is an increased likelihood of coding errors that can lead to catastrophic failures, such as entire networks of devices being compromised simultaneously. Furthermore, the mass collection and storage of data by these connected devices add to privacy concerns, making the trade-off between convenience and security substantial .

The lack of robust Internet security stems from its initial design, aimed at connecting users who already trusted one another, such as academic researchers and military networks. As the Internet expanded to accommodate billions of users, efforts to enhance its security were hindered by cost concerns, shortsightedness, and conflicting interests. Inadequate security measures have allowed vulnerabilities to persist, thereby affecting any entity connected to the Internet, including the rapidly proliferating Internet of Things. This inherently weak foundation has failed to support the secure integration of everyday objects, resulting in significant privacy and security challenges .

Past automotive safety challenges are analogous to present digital security issues in that both have faced industry resistance due to cost concerns. In the 1960s, car manufacturers were reluctant to adopt safety features like seatbelts until legislative action forced their hand. Similarly, the automotive industry today is slow to address the fundamental digital security vulnerabilities inherent in modern vehicles, often settling for temporary fixes to exposed flaws instead of comprehensive security overhauls. This reflects a broader trend of hesitance to invest in safety until external pressures necessitate change .

Zeynep Tufekci suggests that improving the security of Internet-connected objects will require isolation of critical functions and the implementation of external audits to catch vulnerabilities early. Such measures necessitate an initial investment to prevent future issues, counteracting the corporate tendency to avoid upfront costs. Additionally, not all objects need to be networked, as the trade-off between connectivity and increased vulnerability may not be justified .

The mass data collection by Internet of Things devices has severe implications for privacy as these devices gather extensive data about individual activities, including location, consumption patterns, and potentially sensitive personal information. This data accumulation results in large databases that are complex to secure and manage, increasing the risk of breaches and unauthorized access. Consequently, this poses significant threats to individual privacy by allowing detailed monitoring and profiling of users without adequate safeguards .

Early Internet design was centered around connecting trusted users, such as researchers and military personnel, without robust security measures. This foundational weakness affects modern security infrastructures by enabling vulnerabilities exploited through the Internet of Things. As everyday objects are connected, these inherited security flaws become prominent, allowing for significant security breaches, privacy issues, and the challenge of managing extensive, insecure connections. The scale of connectivity intensifies potential risks, since minor errors can propagate through large networks of interconnected devices .

The Internet of Things in the automotive industry poses significant security risks, as demonstrated by the hacking of a Chrysler Jeep Cherokee. Researchers were able to remotely disable the vehicle's engine while it was on a highway, highlighting the vulnerability of network-connected cars to remote attacks. These vehicles often use outdated and insecure systems to connect various components like the steering, brakes, and transmission, making them susceptible to hackers once they breach the system. Security issues stem from the inherent lack of robust security protocols in early Internet designs, coupled with the industry's slow response to these vulnerabilities .

Federal regulations could significantly influence the automotive industry's approach to digital security by mandating minimum cybersecurity and privacy standards. Such legislation would compel manufacturers to systematically address security challenges, prompting the industry-wide adoption of robust security frameworks. Historical precedents demonstrate that regulatory requirements lead to broad safety improvements, similar to how regulations enforced the inclusion of seatbelts. Current legislative actions, though nascent, indicate movement towards enforcing comprehensive digital safety measures in vehicles .

Car manufacturers have shown significant resistance to addressing security concerns related to the Internet of Things by not fundamentally changing how they incorporate software and computer systems into automobiles. Despite security researchers repeatedly warning about the dangers of interconnected systems, manufacturers have often only addressed exposed vulnerabilities rather than overhauling their insecure systems. Historically, this resistance mirrors the reluctance exhibited by the industry to incorporate basic safety features, requiring legislative action to implement necessary safety technologies .

Patching vulnerabilities is insufficient for long-term IoT security because it addresses only known issues, leaving underlying systemic weaknesses unaddressed. This approach is akin to treating symptoms rather than the root causes, making systems temporarily secure but still fundamentally vulnerable to future or unknown threats. Continuous patching also does not solve the problem of inadequate security protocols inherited from early Internet infrastructure, necessitating a comprehensive reengineering of systems to isolate critical functions and implement preventive security measures .

You might also like