Changing IoT device passwords won’t stop new attacks


Changing IoT device passwords won't stop new attacks
Reading time: 4 minutes

Every market must develop strategies to make IoT devices and networks more secure.

Changing IoT device passwords won't stop new attacks

The Internet of Things is no longer just a concept and its application has already extrapolated the intended uses for devices with that characteristic. This is because in October 2016 Internet of Things devices were used extensively during DDoS (service navigation) attacks for training purposes. botnet which bring down various Internet servers, interrupting the service of giants like Twitter, Netflix, Spotify, Airbnb, Reddit, Etsy, SoundCloud and even himself The New York Times.

Articulos que te pueden interesar8 promises of innovation that the Internet of Things will bring to companies8 promises of innovation that the Internet of Things will bring to companies

To carry out the gigantic attack, which reached up to 1 Tbps, the largest of any type recorded until then, the hackers they used a botnet composed of IoT devices, mainly cameras and other video equipment connected to the Internet. Through a software called Miraithat he uses malware emails the phishing to infect from a single computer to a home network, the malware It was automatically deployed to all types of IoT devices, forming the network to search the Internet for devices with little or no security included.

According to the company Symantecthis type of attack tends to grow significantly and multiply due to problems – or even lack – of security of IoT devices, making them easy targets to hack malware pre-programmed with commonly used standard passwords, such as “admin” or the famous “1234” sequence. The creator himself Mirai He later states that only use combinations of accesses and common passwords like the ones mentioned were enough to connect to 380 thousand devices.

Once the attacks tend to grow, the problem cannot be solved by simply changing passwords. The situation requires an industry-wide effort and blaming users alone will not help find an efficient solution.

In this way, it is necessary for device manufacturers to take responsibility for providing a secure environment for the IoT, in an effort that involves the entire chain, especially regarding the installation, connection and integration so that a device can have with other devices or applications, such as Wi-Fi routers and services in Cloud. Currently, when a device is brought home, it is added to the home network. The forms of its configuration and security requirements will be established during its use, regarding the security and privacy of that device.

Meanwhile, the manufacturers themselves have not yet implemented many security practices or models in this process. And that’s where the entire industry comes in, in the sense of more forcefully determining a set of security practices and technologies for the lifecycle of that device. Below are some strategies to convert your IoT device to more secure networks:

Articulos que te pueden interesar9 benefits of hyperconvergence for businesses9 benefits of hyperconvergence for businesses

-Changing master passwords: Changing passwords, as mentioned, does not eliminate risks, ensuring that all master passwords are changed to strong passwords is an important step, as usernames and passwords for most IoT devices can easily be contracted over the internet, making them vulnerable.

Update IoT Device: As long as device security patches are available, updating is necessary as a device with an outdated configuration is an easy target for hackers. hackers;

-Disable the Universal Plug and Play (UPnP) in routers;

-Be careful when purchasing: when purchasing IoT devices, check that they come from companies that enjoy a good reputation in the technology field. This may be reflected in the price, but is more safety-oriented;

-Usage of tokens– Instead of just using passwords when a device is added to the network, you can require configuration through the use of tokens. Once new devices connect to the Internet in an «intelligent» way, generally via a Wi-Fi network, the password in this case is recorded on the device and stored. This makes it difficult to offer network access customizations for different devices.

Therefore, offering a token security would be an alternative to use for Wi-Fi router authentication. In the case of devices that also require connection to the Cloudthis alternative could be used. With the model of OAuth tokenpeople wouldn’t be forced to hand out their passwords for an account that will be connected to a device. The device does not see the password, but uses a credential token always authenticate;

-Solutions that advance as a mechanism and eliminate the need for password-based authentication: To imagine the risks associated with using passwords as the only authentication option, the IT industry has generally worked on some solutions, such as OAuth, OpenID Connect Yes Fast online identitysolutions that integrate or eliminate the need for password-based authentication. The same needs to be done for IoT. In this sense, there are already initiatives from groups that are starting to create protocol standards in device-to-device communication, but in the meantime they need to make a leap to provide greater security in authentication and authorization. For example: Just as computers communicate via HTTP, these connected devices can use protocols better suited to their limitations, based on a model OAuth for those same protocols.

As we have seen, the scenario is rather nebulous when it comes to digital security, especially in IoT devices. The main recommendation – and action – is to be as fast as cybercriminals, which becomes a challenge for industries providing security solutions.

Sources:

http://www.darkreading.com/endpoint/changing-iot-passwords-wont-stop-attacks-heres-what-will/a/d-id/1327416?

http://cio.com.br/tecnologia/2016/10/24/ataques-provienentes-de-multiplas-plataformas-iot-devem-se-intensificar/

https://seginfo.com.br/2016/10/18/como-o-uso-de-logins-e-senhas-padrao-facilitou-a-criacao-de-uma-botnet-de-dispositivis-iot/

http://itforum365.com.br/noticias/detalhe/121919/ataques-ddos-baseados-em-internet-das-coisas-manual-de-sobrevivencia

latest posts published

Personal Branding or cult of personality?

Developing your personal brand is important for your career growth and progress as a leader ...
the rich snippet filters from Google

6 Key SEO Steps Before Launching a New Website

I hear many companies talk about how their website isn't very effective. Why are there ...
Communicating in the heart of the financial crisis

Communicating during the financial crisis

A few years ago, we crossed a financial crisislong, sometimes giving the impression that it ...
détente

11 good resolutions to give a boost to your 2019

Here we go, the year is ending, it's time to reflect! What has this year ...

It all starts with an idea

All the most powerful companies began with something delicate and hard to grasp. A thought ...
Content marketing books inc

6 marketing and creativity books to read this year!

If you're similar to me, you likely have a book open next to your bed, ...
Inbound Marketing Buying Funnel

Content Marketing: Do You Really Have to Offer All Your Content?

Fresh, high-quality content is a steady source of traffic because of natural sharing. It provides ...
Entrepreneurs and content marketing: 16 quotes to encourage you 1

Entrepreneurs and content marketing: 16 quotes to encourage you

Do you enjoy quotes? I have them all around me in my workplace, on the ...
Through these best SEO and social media practices, discover how to significantly increase your blog's audience. #Blog #SEO #Contentmarketing

9 tips to increase your blog audience!

Build and grow your blog audience it can quickly become a full-time job. Outside of ...
find influencers

How to find and identify influencers?

Influencer, influencer, where are you hiding? With the rise of social networks while still keeping ...

Leave a Reply

Tu dirección de correo electrónico no será publicada. Los campos obligatorios están marcados con *