INTERNET OF TARGETS Leif Nixon Sarcasm a pair vibrator with - - PowerPoint PPT Presentation

internet of targets
SMART_READER_LITE
LIVE PREVIEW

INTERNET OF TARGETS Leif Nixon Sarcasm a pair vibrator with - - PowerPoint PPT Presentation

INTERNET OF TARGETS Leif Nixon Sarcasm a pair vibrator with bluetooth wtf? no wifi no food no wifi no food do you have devices that need your wifi to be working? security cameras thermostats smart appliances smoke alarms smart


slide-1
SLIDE 1

INTERNET OF TARGETS

Leif Nixon

slide-2
SLIDE 2

Sarcasm

slide-3
SLIDE 3
slide-4
SLIDE 4

a pair vibrator

slide-5
SLIDE 5

with bluetooth

slide-6
SLIDE 6

wtf?

slide-7
SLIDE 7
slide-8
SLIDE 8
slide-9
SLIDE 9
slide-10
SLIDE 10
slide-11
SLIDE 11
slide-12
SLIDE 12
slide-13
SLIDE 13
slide-14
SLIDE 14
slide-15
SLIDE 15
slide-16
SLIDE 16
slide-17
SLIDE 17
slide-18
SLIDE 18
slide-19
SLIDE 19

no wifi – no food

slide-20
SLIDE 20

no wifi – no food

slide-21
SLIDE 21

do you have devices that need your wifi to be working? security cameras thermostats smart appliances smoke alarms smart tv/dvr security alarm smart lighting random crap iot happily, there is an iot solution for that!

slide-22
SLIDE 22
slide-23
SLIDE 23
slide-24
SLIDE 24
slide-25
SLIDE 25
slide-26
SLIDE 26

philips hue uses zigbee light link (which is totally different from zigbee home automation)

slide-27
SLIDE 27

The ZLL pre-installed link key is a secret shared by all certified ZLL devices. It will be distributed only to certified manufacturers and is bound with a safekeeping contract.

slide-28
SLIDE 28

zigbee light link secret master key

9F 55 95 F1 02 57 C8 A4 69 CB F4 2B C9 3F EE 31

slide-29
SLIDE 29
slide-30
SLIDE 30

send udp packet to port 48899:

HF-A11ASSISTHREAD +ok AT+WSKEY

returns:

wifi access key

slide-31
SLIDE 31

but you already know the wifi access key, right? fun feature: loss of wifi > 10 mins? start AP!

slide-32
SLIDE 32

but you already know the wifi access key, right? fun feature: loss of wifi > 10 mins? start AP!

slide-33
SLIDE 33

if remote control via Internet is enabled you can do this from remote single auth factor: the bulb’s mac address – easily bruteforced

slide-34
SLIDE 34

for some reason, the bulb provides an http proxy allowing connections to arbitrary hosts on internal network

slide-35
SLIDE 35
slide-36
SLIDE 36
slide-37
SLIDE 37
slide-38
SLIDE 38

Olle Angst: Why is the world full of idiots? Idiot: What do you mean?

slide-39
SLIDE 39

why, oh why?

slide-40
SLIDE 40

START-UPS lack of time lack of funds abandonware

slide-41
SLIDE 41

MASS MARKET price pressure no consumer interest shiny > secure

slide-42
SLIDE 42

TRADITIONAL VENDORS no competence

slide-43
SLIDE 43

CRITICAL SYSTEMS

slide-44
SLIDE 44

SOFTWARE FAULT

slide-45
SLIDE 45

SOFTWARE FAULT

slide-46
SLIDE 46

Your car – redefined

slide-47
SLIDE 47

MARKETING MATERIAL: Telia Sense connects to your car’s

  • nboard computer, giving you

access to important data and enabling you to control certain functions remotely.

slide-48
SLIDE 48

OBD-II – ONBOARD DIAGNOSTICS

slide-49
SLIDE 49

IS REMOTE ACCESS TO THE CAN BUS REALLY A GOOD IDEA?

slide-50
SLIDE 50
slide-51
SLIDE 51

THE NIXON PRINCIPLE: Things that can kill you shouldn’t be on the Internet.

slide-52
SLIDE 52
slide-53
SLIDE 53
slide-54
SLIDE 54
slide-55
SLIDE 55
slide-56
SLIDE 56
slide-57
SLIDE 57
slide-58
SLIDE 58

Suorva hydroelectric dam

slide-59
SLIDE 59
slide-60
SLIDE 60

OF COURSE IT’S NOT ON THE BLOODY INTERNET, ARE YOU CRAZY?

slide-61
SLIDE 61

it’s perfectly possible to build good iot systems, it just takes good engineering.

slide-62
SLIDE 62

IKEA TRÅDLÖS SMART LIGHTING

slide-63
SLIDE 63
slide-64
SLIDE 64
slide-65
SLIDE 65
slide-66
SLIDE 66

something needs to be done let’s do something

slide-67
SLIDE 67

for critical systems and services:

REGULATION

slide-68
SLIDE 68

Bekendtgørelse om udpegning af drikkevandsressourcer (bkg. nr. 246 af 15/03/2017) Bekendtgørelse om vandforsyningsplanlægning (bkg. nr. 831 af 27/06/2016) Bekendtgørelse om vandindvinding og vandforsyning (bkg. nr. 832 af 27/06/2016) Bekendtgørelse om indsatsplaner (bkg. nr. 912 af 27/06/2016)

slide-69
SLIDE 69

Bekendtgørelse om kvalitetskrav til miljømålinger (bkg.

  • nr. 914 af 27/06/2016)

Bekendtgørelse om uddannelse af personer, der udfører boringer på land (bkg. nr. 915 af 27/06/2016) Bekendtgørelse om delegation af miljøministerens beføjelser i …forskellige …love til Miljøstyrelsen (bkg. nr. 597 af 02/06/2016)

slide-70
SLIDE 70

Bekendtgørelse om vandkvalitet og tilsyn med vandforsyningsanlæg (bkg. nr. 802 af 01/06/2016) Bekendtgørelse om passagebidrag (bkg. nr. 160 af 26/02/2016) Bekendtgørelse om indhentelse af udtalelse om miljøskade m.v. (bkg. nr. 1460 af 07/12/2015) Bekendtgørelse om udførelse og sløjfning af boringer og brønde på land (bkg. nr. 1260 af 28/10/2013)

slide-71
SLIDE 71

Bekendtgørelse om kvalitetssikring på almene vandforsyningsanlæg (bkg. nr. 132 af 08/02/2013) Bekendtgørelse om miljøgodkendelse og samtidig sagsbehandling af ferskvandsdambrug (bkg. nr. 130 af 08/02/2012 Bekendtgørelse om individuel afregning efter målt vandforbrug (bkg. nr. 837 af 27/11/1998)

slide-72
SLIDE 72

HOW ABOUT Bekendtgørelse om NOT TO PUT YOUR WATERWORKS ON THE INTERNET

slide-73
SLIDE 73

for consumer devices:

REGULATION (maybe?)

slide-74
SLIDE 74

tires? wtf do i know about tires?

slide-75
SLIDE 75

tires? wtf do i know about tires?

slide-76
SLIDE 76

1905 ERA SERVICE ENTRANCE SWITCH

slide-77
SLIDE 77

MODERN COUNTERPART. BORING.

slide-78
SLIDE 78

MODERN COUNTERPART. BORING.

slide-79
SLIDE 79

nothing of this is easy but if we all work together we can make iot boring again

slide-80
SLIDE 80

nothing of this is easy but if we all work together we can make iot boring again

slide-81
SLIDE 81

nothing of this is easy but if we all work together we can make iot boring again

slide-82
SLIDE 82

THANK YOU @leifnixon