In 2017, we saw that IoT devices were abused for the Mirai botnet. How did it come to this? Was it related to the design of the IoT devices or was it due to a lack of overarching oversight? Through personal research and experience, I have concluded that the issues surrounding IoT devices have various causes. Firstly, there are competing and incompatible standards.
An overarching international oversight of IoT devices is lacking. Additionally, the data in IoT devices is not or poorly encrypted. There is also a lack of proper password protection, or hardcoded default passwords can be found in the device. IoT devices are easy to use, and many users think that security is therefore also well taken care of. This is a major misconception. There are also IoT devices that are overly complicated to use or have complex interfaces. I will elaborate on these factors that hinder the safe use of IoT devices.
Competing and incompatible standards
In the world of IoT, many standards and wireless technologies are used, such as Z-wave, RFID, homeRF, ZigBee, and WiMAX. They use different radio frequencies (RF) and a mix of spectrum technologies and modulations that can cause incompatibility. Many IoT devices operate on different international unregulated frequencies such as the Industrial, Scientific, and Medical band (ISM 2.4 GHz), the Unlicensed National Information Infrastructure (U-NII), and various RFID-related frequencies. There is no oversight regarding frequency ranges, while the use of RFID is strictly regulated within individual countries.
Lack of useful regulatory oversight
Many IoT devices fall under different and sometimes conflicting regulatory organizations. In the United States, the device may fall under the jurisdiction of the Federal Communications Commission (FCC) or the US Toy Standard ASTM F963-16. No or weak encryption The most notable aspect related to IoT devices is the lack of security of the data. This concerns the location and data storage but also the mechanism used to move the data and ways in which information is transported to and from the device. The majority of IoT devices do not encrypt data. Thus, it is possible to access this data with little to no knowledge.
Lack of password protection
We see that certain IoT devices are insufficiently or not at all equipped with password protection. It also happens that hardcoded default passwords can be found in the device. Lists of default passwords circulate on the internet. This way, gaining access to such an IoT device is a piece of cake. This development has opened the door to massive abuse, as we saw in 2017 during the DDoS attack by the Mirai botnet. The construction of this botnet was made possible because the attackers exploited these default passwords.
Simple interface
For IoT devices, ease of use is paramount. The devices must primarily provide benefits and convenience to the user. This often translates into easy operation. Due to accessibility, many users think that security is also well taken care of. This is a misconception. The cause is often a lack of knowledge on this subject.
Complicated instructions
In addition to easy-to-use IoT devices, we also see the opposite: devices that are incredibly complicated to use. Due to the complexity, many users fail to follow the security advice. For example, they skip changing the default password because they do not understand how to do it.
Scos Software
Since the Internet of Things is still an unknown area for many people, many business users plan to learn more about it. SCOS Software from Hoofddorp offers a special Cloud & Internet of Things training for this purpose: www.scos.training