IoT Devices Are Secretly Phoning Home (thenewstack.io)
An anonymous reader writes: A popular internet-enabled security camera "secretly and constantly connects into a vast peer-to-peer network run by the Chinese manufacturer of the hardware," according to security blogger Brian Krebs. While the device is not necessarily sharing video from your camera, it is punching through firewalls to connect with other devices. Even if the user discovers it, it's still extremely hard to turn off. Krebs notes that the same behavior has been detected in DVRs and smart plugs -- they're secretly connecting to the same IP address in China, apparently without any mention of this in the product's packaging. One security researcher told Krebs the behavior is an "insanely bad idea," and that it opens an attack vector into home networks.
Or shit. Buzzword bingo anyone?
c'mon, man. they're all doing it. damn you ET.
Anyone familiar with IoT knows that most of them phone home to report.
Don't waste your vote! Vote for whoever you want, unless you live in a swing state it won't matter anyways
It's really simple. It's separate from source code quality. If you have proprietary software running free on your device then you don't own the device, whoever set up the software owns it. Windows phones home because it's working for Microsoft. Your IOT devices phone home because they are working for a Chinese company. Your Android phone phones home because it's working for Samsung and your mobile operator. This is not different and it's not complicated.
The government has declared that the Chinese are trustworthy and that there is nothing to worry about. The devices are probably just checking for firmware updates.
Who are we kidding. The Chinese know about everything that goes on in this country - probably even moreso than the NSA. Every piece of hardware that enters this country from China should be assumed to be a spy device.
This is really really shocking!
Somebody better do something to stop all of this, real quick!
These used to be just IP Cameras, they have been around for years, but now they are suddenly being called IoT devices. I wish this I(di)oT fad would die off and people would just call a spade a spade (or even an IP Spade)
Depends on your perspective, doesn't it? If you are aiming to ensure that a cyber attack by the People's Liberation Army on the Imperialists will do a lot of damage, it seems like a GREAT idea...
That Internet of Things phoning home is some sort of secret, you've been living under a rock the last few years. Phoning home is what they are designed to do. It's the core principle of the IoT.
The shepherds did so well protecting the flock that the sheep no longer believed that wolves existed.
This "secret network" is a "DDNS network" so you can more easily connect to your camera from the Internet. Clickbait.
That's it - the two peers are your camera and your mobile device, not some fast torrent network or something.
Now, sure, this could've been documented better, but Krebs should also know better than to jump to hyperbole based on two letters and a number in a configuration screen.
Phoning home isn't notable unless you know what it's doing so for. It could be to send information back, or it could just be to just for updates etc.
Here's a list of reasons why I don't like the Internet of Things:
1) Internet of Things devices could watch me while I sleep.
2) Internet of Things devices could watch me while I pee.
3) Internet of Things devices could watch me while I make kaka.
4) Internet of Things devices could watch me while I pleasure myself.
5) Internet of Things devices could watch me while I wash my body in the shower.
6) Internet of Things devices could watch me while I relax in the tub.
7) Internet of Things devices could watch me while I brush my teeth.
8) Internet of Things devices could watch me while I make passionate love to my wife.
9) Internet of Things devices could watch me while I brush my hair.
10) Internet of Things devices could watch me while I read a book.
11) Internet of Things devices could watch me while I read Slashdot.
12) Internet of Things devices could watch me while I bake cake.
13) Internet of Things devices could watch me while I put in my contact lenses.
14) Internet of Things devices could watch me while I get ready to play golf.
15) Internet of Things devices could watch me while I do my laundry.
16) Internet of Things devices could watch me while I think about rugby.
17) Internet of Things devices could watch me while I tie my shoes.
18) Internet of Things devices could watch me while I celebrate the 4th of July.
19) Internet of Things devices could watch me while I water my flowers.
20) Internet of Things devices could watch me while I eat ham.
21) Internet of Things devices could watch me while I use my stapler to staple documents.
22) Internet of Things devices could watch me while I chew bubble gum.
23) Internet of Things devices could watch me while I check the oil in my car.
24) Internet of Things devices could watch me while I look for my TV remote.
25) Internet of Things devices could watch me while I blow my nose.
26) Internet of Things devices could watch me while I rearrange my stamp collection.
27) Internet of Things devices could watch me while I listen to the Backstreet Boys.
28) Internet of Things devices could watch me while I do my calisthenics.
29) Internet of Things devices could watch me while I search for a paper clip.
30) Internet of Things devices could send information about me to advertisers.
31) Internet of Things devices could let advertisers use the data unsuspectingly collected about me while I sleep.
32) Internet of Things devices could let advertisers use the data unsuspectingly collected about me while I pee.
33) Internet of Things devices could let advertisers use the data unsuspectingly collected about me while I make kaka.
34) Internet of Things devices could let advertisers use the data unsuspectingly collected about me while I pleasure myself.
35) Internet of Things devices could let advertisers use the data unsuspectingly collected about me while I wash my body in the shower.
36) Internet of Things devices could let advertisers use the data unsuspectingly collected about me while I relax in the tub.
37) Internet of Things devices could let advertisers use the data unsuspectingly collected about me while I brush my teeth.
38) Internet of Things devices could let advertisers use the data unsuspectingly collected about me while I make passionate love to my wife.
39) Internet of Things devices could let advertisers use the data unsuspectingly collected about me while I brush my hair.
40) Internet of Things devices could let advertisers use the data unsuspectingly collected about me while I read a book.
41) Internet of Things devices could let advertisers use the data unsuspectingly collected about me while I read Slashdot.
42) Internet of Things devices could let advertisers use the data unsuspectingly collected about me while I bake cake.
43) Internet of Things devices could let advertisers use the data unsuspectingly coll
How long before they start adding sneaky little sensors (cameras/microphones/etc) to random everyday objects without telling us? The sensors are cheap enough now that they wouldn't affect the overall price noticeably.
Unless we read the fine print, of course. I know I would read the EULA for a lava lamp just to find out why the heck they thought they needed one, but how many people wouldn't (And how soon before EULA requirements are relaxed)? Wifi devices are now cheap enough also not to affect the price noticeably either. They could easily connect just by trying a whole range of default wifi un/pw. Chances are more than half could find their way online with no effort from the user.
And of course wait until hacking these things becomes commonplace. (s) I'm sure these would be kept well patched (/s)
Tin foil hat much? Mark this comment and come back to it in 10 years (or even 5, probably 2). We're already there with the things we know about so far. (Samsung 'smart' TVs, 'smart' phones, Nest thermostats, etc)
I didn't ask for this future, but a whole hell of a lot of people did. I'd say careful what you wish for, but it's a bit late for that...
Windows 10 as well, but not so secretly since there's a lot of awareness from the anti-MS news sources.
So, as someone above said, they are all doing it.
"Punching through firewalls". Uh, you mean using STUN?
I'm sorry, but based on what we've been seeing, so far the entire Internet of Things is an insanely bad idea ... shoddy security by incompetent idiots who want more analytics data and ad revenue, and don't give a crap about your security.
Fuck that, I want my toaster connected to the internet why again?
That this is happening should no longer come as a surprise to anybody who has paid even the smallest amount of attention to how much of a mess the IoT is.
Lost at C:>. Found at C.
I'm a user of the now Arduino compatible ESP 8266-12E ever so popular IoT 2$ device. It's a WiFi on a chip + a nice 80 MHz microcontroller (32 bit) with 4MBit flash ram to boot, it's insanely cheap for what you actually get...
If you just use them as they are (With the AT+ command set, hayes compatible) - they already phone home because they can Upgrade the firmware - albeit you can initiate that yourself).
But unless you've got a WiFi hotspot with a firewall where you can Wireshark monitor your network traffic - you will have NO idea whether this thing is phoning home with a few extra details about your network, it's bad enough that it actually phones "home" with your IP address, I'm not sure if it does that - but it's def. worth an extra look. Anyone know the details about this? Have anyone tried looking into the ESP8266 series to see if they even phone home after they've been bootloaded with the Arduino Bootloader?
We've got to be a little careful about this - I agree completely - It's so tempting to just insert those wonderful all-in-one IoT devices here and there...and forget about the advanced details...because lets face it - they've made it wonderfully practical for us to use with very little skill or knowledge required to get these things talking to each other (while - perhaps...hiding a darker side).
What this world is coming to - is for you and me to decide.
That's what the whole point of the IoT. If you are going to control your lights or toaster or whatever with your phone, OF COURSE it has to connect to an external server - so that you can connect to the device. Naturally, it's stupid, but that's the IoT for you.
Now that kids is why you don't tell any device that doesn't need to get out on the net what the gateway address is.
If you need to access it via the internet, then fair enough, but now we've got yet another example as to why we should use firewall settings to make sure they can only contact what you want them to contact.
Any IOT device that has access from a smartphone does something like this. If you look at the traffic from a Philips Hue hub you'll see SSDP broadcasts, NTP synchronisation and phoning home with details of it's local IP address and checking for updated firmware.
This article seems to be yet more anti-Chinese nonsense. There was a very similar one recently by an American "journalist" that didn't understand that NTP is a distributed protocol either and implied these devices were somehow infiltrating US homes and forming a secret network. It possibly inspired this article, though unfortunately I can't find the original just now to link to.
The answer is to put IOT devices in a DMZ/restricted guest network which more and more routers are supporting out of the box.
At the current state of affairs, almost all IoT devices are programmed using development environments provided by the semiconductor (e.g., http://www.nxp.com/products/so...). And most of these are a composition of open-source tools (i.e., GCC, Eclipse, etc.) with some proprietary interfacing software (e.g., something like JTAG to program the chip with). The vendor-specific IDEs (e.g., customized Eclipse) often come with networking libraries (i.e., something BSD sockets-esque for Internet) they made and /maybe/ some simple threading library (i.e., no operating system). The programs compile to real-time code and this code is then "flashed" to the chip/flash using something like JTAG. That's it. Security nightmare. The "obfuscation" of JTAG and compiling to ARM (versus x86) has let A LOT of companies do some crazy programming on IoT devices. My IoT camera has a physical kill-switch I use when I get home (i.e., I unplug it).
But unless you've got a WiFi hotspot with a firewall where you can Wireshark monitor your network traffic - you will have NO idea whether this thing is phoning home with a few extra details about your network, it's bad enough that it actually phones "home" with your IP address, I'm not sure if it does that - but it's def. worth an extra look.
And there's the rub. If you plant software in a million devices that come out of China, you have access to a million US Networks (usually in wealthier, higher-bandwidth homes) for attacks within those networks and attacks that use the network bandwidth to attack other targets. If you were in charge of corporate or state espionage in China, wouldn't you like to have access to the network of every software engineer or wealthy businessman who buys a new toy? How many IoT devices create a new vulnerability that can be exploited en masse or even for targeted attacks? How many can monitor wireless keyboard signals and read banking passwords?
And it is completely, absolutely, 100% unnecessary.
o Plug in not-yet configured device.
o Shortly thereafter, it accepts DHCP configuration. Now it has an IP.
o Then it vomits out a tiny UDP (broadcast) packet every 60 seconds or so that says "I'm a WackyWidget and my IP is Yad.daY.yad.daY"
o You start app, it listens for the UDP packet, when it hears it, it begins comm via TCP at the IP identified in the UDP broadcast. UDP broadcasts then cease until, or unless, the TCP (and possibly the DHCP) connection is dropped, in which case, begin again at whatever step is needed.
That's it. That's ALL of it. You need nothing more for an IP camera, a smart power plug, a smart lightbulb, an aquarium controller, the garage door opener, etc., etc., ad infinitum.
If you THEN want to expose WackyWidget to the WAN, you could enable that separately.
If you were out of your damned mind.
If you haven't yet figured out that "the cloud" is nothing but a way to take/get things from you -- money, data, ownership of media, etc. -- then you really need to look at all this harder.
I've fallen off your lawn, and I can't get up.
The question is, do you love Big Brother yet, or does your face have to be shoved into a box that contains hungry rats ?
Really Dice, scared shitless to mention the manufacturer?
Here is the Krebs link if you want the actual details and don't want to dig it out of the articles linked in the summary: http://krebsonsecurity.com/201...
I browse on +1 so AC's need not respond, I won't see it.
by this, one can get a false impression that this sort of thing is confined to a "chinese manufacturer ", when it isn't.
I predict that it will be increasingly difficult to buy household products without IoT features. Furthermore, I predict that many of these products will be essentially non-functional unless you connect them to your network. You've all read about the Nest thermostat. What a fucking fiasco!
In such a scenario, this leaves people with essentially two options:
1) Don't buy TVs, refrigerators, or thermostats that are "smart" or "web enabled" or whatever we are calling the Internet of Shit this week. Unfortunately, smart devices will win out over the long run, because people will buy more of them than regular devices. Advertising will convince people that they need a web-enabled refrigerator, and GE will make more and more of them. Eventually, regular devices will become a niche market. Ever tried buying a non-1080P monitor at an actual store? Maybe something with more vertical resolution than what I had on my desk in high school? I haven't looked lately, but between 2012-2015, this was basically impossible. Ever tried buying a new manual transmission car? Get ready to look around. I bet in ten years you will have the same problem finding a microwave without WiFi and a fucking touch screen.
2) Join your IoT devices to a network segregated from your regular LAN and police the traffic at the router. It would be fool of you guys to not do this already, but this is already over the heads of most consumers. This approach is probably rife with other caveats.
This whole IoT thing makes me uneasy, although most of my philosophical problems with the privacy aspects apply equally to smart phones (computer in my home, on my network, with sensors, can talk to its mothership without my knowledge, who knows that it is really doing, etc.) ... and I have one of those right next to me.
What a time to be alive!
Welcome back, buddy. We missed you.
I'd take P2P-assisted streaming over Teh Cloud any day.
from the no-shit-sherlock dept?
CLI paste? paste.pr0.tips!
if you know the ip address its probably some irc control channel like they did back in the 90s !eject cdrom or !stuck rudder for upcoming aircraft hits should be a show. either way since the worlds ending everyday the pain may as well be shared by the knaves and the high and might blight both.
What's good for the goose is good for the gander. You just need to stop calling it "phoning home" and start calling it "telemetry", then it's OK, apparently.
with legislation: (a) that this must be documented (what, where to, ...) and (b) how to switch it off. However that will not happen: (1) most of the legislators do not understand the problem; (2) those that do realise that this would stop $OurCountry products from doing this at the behest of GCHQ/NSA/... So it shall be ignored.
There might be some movement when some government high ups are, through one of these, exposed: in bed with a hooker; snorting white powder; accepting money\Wcampaign-contributions from a known crook; ... although I suspect that it will be easier to sue/bribe the media than fix the problem.
I have an Orvibo S20 which I control from my laptop. It keeps charge level between 30-70% because that is supposed to prolong battery life. But I digress.
This device can also be controlled from a cell phone not on the local network. In order to do this it has to connect to something in the cloud that will relay commands. Who knows what else it sends? Surely the connection would provide my IP address and perhaps router and modem model (and of course my ISP.)
That's not a capability I need or want so I use parental controls to deny Internet access. Maybe some day I'll open that up and sniff the traffic to see what it sends.
Worse yet, if it could call out, what might it bring back? Firmware update with new capabilities? No thanks!
NSA\GCHQ or China!
Big Blothel is watching you!
I've abandoned my search for truth; now I'm just looking for some useful delusions.
Set up a honeypot consisting of a Chinese DVR and a bunch of security cams pointing at pictures of Minuteman ICBMs sitting in their silos. Sit back and watch your IP address get hacked.
Have gnu, will travel.
Skippy ... if you think I waste any fucking time giving a crazy idiot like you any "guff", you sorely over-value your place in your universe.
I'm not your personal stalker, I just ignore your stupid drivel and inane bullshit. Don't flatter yourself.
Lost at C:>. Found at C.
We did?
Faster! Faster! Faster would be better!
And this is news?
How?
IoT manufacturers tell you this if you read the literature.
New Headline: "Schools in America attempt to teach maths to students!" More at 11:00pm.
Oh boy, fuckwad is back with his unintelligible dribble.
All right, who fucked up? I just blew a +1, Underrated to help this guy out, and some smartass has to go and make sure in the meantime that he can't get a +5, Troll now.
Now go take a long, hard look in the mirror and ask yourself what you've done.
Not to say this is fine, but that THEY ARE BOTH WRONG.
We would stop buying these cams but we wouldn't do anything but complain and suck it up for windows, though, hence the bloody obvious statement that this is no different from Windows.
In the hope that enough people will tell MS to STFU that they'll stop treating their customers like serfs.
And that's not just Free Software Foundation propaganda, it's simple capitalism. If only the device vendor can control the software that runs on the device then it's a monopoly situation and we've all seen how well they work. If you have the source and the ability to reflash the device, then there is competition among third-party firmware vendors and only the ones that provide value to the end user will succeed.
I am TheRaven on Soylent News
See subject: "...Attack the messenger" - Ineffective illogical answer from you, Mr. failed Ad Hominem attack slinger you prove yourself to be.
APK
P.S.=> I can say back to you, in a language you understand (since you use it yourself & when in rome I do as the romans do, speaking to them in their OWN language, illogical though yours is) that you're nothing more than a mere "ne'er-do-well" BIG talker, but not a doer like myself-> http://news.slashdot.org/comme... - & there's NO disputing that (validly) - proof's in the pudding... apk
It gets dark at night, and water is wet...
Giant fucking DUH! to the idiots who didn't think would happen...
Even if the user discovers it, it's still extremely hard to turn off.
Why? Does it continue to draw energy from the ether after you unplug it?
Sounds like an 80s episode of The Twilight Zone...
systemd is Roko's Basilisk.
You just gave him your time you hypocritical illogical imbecile and You show us you're not 1/2 as good as apk is in computing either as a foaming at the mouth loon like yourself's incapable of good works like apk produces in his program.
Skippy gstoddart you just wasted our time with your inane drivel and you didn't ignore apk like you say you do either liar. He got to you so well you had to act a child.
Spy features could just as easily be hidden in hardware. Unless you want to verify the die and masks used, you still have no clue what this device can do.
Only the State obtains its revenue by coercion. - Murray Rothbard
Its been known for years that Windows, Various phone apps, and a plethora of other device "phone home", often sending unpleasant amounts of information. Perhaps its time for router/phone manufacturers to step up and offer some easy to use tools to allow individuals to limit what communications these devices are allowed. Customers should also scoff at devices demanding access to the home network, I know I'll never buy another Roku as the last one I bought would not set up on the guest network along with demanding I give it a credit card and set up an account.
I don't know what jackwagon keeps upvoting this copypasta, but knock it off already.
IoT is merely the second step in the development of SkyNet, T2000 s, and the slightly strange life of several Sarah Connors...
If you want to monitor from your phone, you should get a dedicated server, static IP, with protections abounding.
An IoT is, and will be, a weak link if anything is able to send or receive. IoT will also be an auditory/visual probe that medical practitioners will envy.
NSA/CIA/FBI/DHS/DHR/etc will not be evnvious, since they will be using it....
China will not be envious, they are already watching....
Corporations: If you want to monitor my home for any purpose, then come offer to buy it. But I wont have Iot at home.
Get off my Lawn!
Oh but wait, civil libertarians and privacy advocates are "concerned!" There now, don't you feel better?
This is a red herring. If everything you bought was open source, would that INCREASE or DECREASE you level of security? The EULAs I agree to every day are open source, but do I bother reading them? Even if the code was available for every little thing you used, you would still be relying on trust.. or else you would be spending all day fiddling with every little thing.
Phone home functionality can be hidden in the hardware, on a remote server, in a text file, or literally anywhere. The only way to control all your electronics is to make them all yourself, and anyone who even tries doing that is basically living in the stone age.
It's you replying ac now - I really meant what I said, & I honestly don't understand why you'd give me crap!
* I'm out there protecting folks as well as speeding them up with a program that does a LOT MORE for a LOT LESS using what people already have natively (especially on PC's, since like you, the rest are either just TOYS or appliances that really don't NEED to be hooked up online).
APK
P.S.=> Here's what blows my mind - From the sounds of it FROM YOU no less? Hey, you're a lot like me (except I actually do something about internet speed & security - you don't, or @ least nothing I can see or use as I've created)...
Want to know when Skynet was born? Ask the IoT.
Replace "could" with "designed to" and you're closer, even if the "design" is by omission of protective measures rather than overt creepiness.
I hate the stupid name. Didn't we all agree to call this the PAN (Personal Area Network) Like 20 years ago? Stupid marketing people.