Showing posts with label things. Show all posts
Showing posts with label things. Show all posts

Friday, March 11, 2016

Hello Infiltrators - Our Doors are Wide Open

Image courtesy: https://en.wikipedia.org/wiki/File:Gossamer_restored.jpg
In the 1946 classic ‘Hair Raising Hare,’ Bugs Bunny asks, ‘Have you ever have the feeling you were being watched? Like the eyes of strange things are upon you?’ Like Bugs often did, he breaks the fourth wall and involves the audience directly, invoking a feeling that someone is looking over your shoulder.

Today, it is likely the case that you are being watched by the strange (internet of) things that are starting to infiltrate our homes, cars, bodies and the whole of society. While there is a mad rush by people purchasing these things and a similar rush for companies to develop applications and services around those, many are not pausing to either understand the risks or build security into the products.
From home security systems to surveillance cameras to baby monitors to televisions to thermostats, examples pour in daily about flaws and vulnerabilities that leave you, your family and your home exposed. The way things are going, even if you’ve closed and locked your front door physically, that door is wide open to the digital world.

Here are just a few recent examples.

Might as well start with our dwellings. Security researchers at Rapid7 found flaws in in Comcast’s Xfinity Home Security system that would cause it to falsely report that the home’s windows and doors are closed and secured even if they’ve been opened. It also failed to detect an intruder’s motion inside the house. Attacking the system’s communications protocol, they used radio jamming equipment to block the signals that pass from the door, window, or motion sensor to the home’s baseband hub. The system didn’t notice the communication was breached and essentially, failed open without any alert to the owner. When the jammers were turned off, it took minutes to hours for the sensors to reconnect and still didn’t give any indication that a catastrophe could have occurred.
Next, to some of the things inside the insecure house. Experts are predicting that as more connected, smart-TVs enter the home, this will be an avenue for the bad guys to breach your home network. Almost half of U.S. households already have a smart-TV and close to 70% of the sets sold this year will have connectivity capabilities. A threat researcher with Symantec was able to infect his new Andriod-based smart-tele with some ransomware. Within a few seconds, the TV was locked and unusable with the fear inducing pay-up-pop-up ransom note.

Also giving outsiders a view of the inside, Princeton researchers found that certain IoT thermostats were leaking customer zip codes over the internet in clear text. Fortunately, when the manufacturer was notified they quickly issued a patch. There are many horror stories about strangers watching and talking to children via insecure baby monitors. Add to that, toys that record your kid's conversations puts the whole family at risk.

And out on the road, we’ve seen how researchers were able to control a Jeep and last week, researchers were able to remotely control any of the Nissan Leaf’s functions by using the mobile app’s insecure APIs. The unsecured APIs allowed anyone who knows the VIN of a car to access non-critical features like climate control and battery charge management from anywhere on the Internet. Also, someone exploiting the unauthenticated APIs can see the car's estimated driving range. They too, pulled access to the app until they can properly secure the infrastructure and application that supports the mobile app.

Lastly, if you think this is contained within a consumer based household, think again. A recent Ponemon/Lookout survey revealed that an average of 1,700 malware laced mobile devices per company, connect to an enterprise network. Wait ‘til all the insecure wearables start connecting. Employees are often referred to as the weakest link. Today it is mostly their insecure mobile devices but multiply that by a wardrobe, now the risk is enhanced.

ps

Related:

Wednesday, January 20, 2016

Internet of Insider Threats

Identify Yourself, You Thing!

Imagine if Ben Grimm, aka The Thing, didn’t have such distinctive characteristics like an orange rocky body, blue eyes or his battle cry, ‘It’s Clobberin’ Time!’ and had to provide a photo ID and password to prove he was a founding member of the Fantastic Four. Or if the alien in John Carpenter’s The Thing gave each infected life-form the proper credentials to come and go as they please. Today the things we call ‘Things’ are infiltrating every aspect of society but how do organizations identify, secure and determine access for the 15+ connected chips employees will soon be wearing to the office? And what business value to they bring?

Gartner refers to it as the ‘Identity of Things’ (IDoT) and an extension to identity management that encompasses all entity identities, whatever form those entities take. According to Gartner, IoT is part of the larger digital business trend transforming enterprises. It means that the business, the people/employees and the ‘things’ are all responsible in delivering business value. The critical part is the relationships between or among those participants so the business policies and procedures can reflect those relationships. Those relationships can be between a device and a human; a device and another device; a device and an application or service; or a human and an application or service.

For instance, how does the system(s) know that the wearable asking for Wi-Fi access is the one connected to your wrist? It really doesn’t since today’s Identity and Access Management (IAM) systems are typically people-based and unable to scale as more entities enter the workplace. Not to mention the complexity involved with deciding if the urine powered socks the VP is wearing gets access. The number of relationships between people and the various entities/things will grow to an almost unmanageable point. Could anyone manage a subset of the expected 50 billion devices over the next 4 years? And set policies for data sharing permissions? Not without a drastic change to how we identify and integrate these entities.

Talk about the Internet of Insider Threats. That's IoIT for those counting.

Gartner suggests that incorporating functional characteristics of existing management systems like IT Asset Management (ITAM) and Software Management Systems (SAM) within the IAM framework might aid in developing a single-system view for IoT. The current static approach of IAM doesn’t take into account the dynamic relationships, which is vital to future IAM solutions. Relationships will become as important as the concept of identity is for IAM in the IDoT, according to Gartner.

My, your, our identities are unique and have been used to verify you-are-you and based on that, give you access to certain resources, physical or digital. Now our identities are not only intertwined with the things around us but the things themselves also need to verify their identity and the relationship to ours.

I can hear the relationship woes of the future:
A: I’m in a bad relationship…
B:Bad!?! I thought you were getting along?
A:We were until access was denied.
B:What are you talking about? You guys were laughing and having a great time at dinner last night.’
A:Not my fiancé…it’s my smart-watch, smart-shoes, smart-socks, smart-shirt, smart-pants, smart-belt, smart-glasses, smart-water bottle, smart fitness tracker and smart-backpack.'
IT said, 'It’s not you, it’s me.'

ps

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Tuesday, December 15, 2015

Blog Roll 2015

It’s that time of year when we gift and re-gift, just like this text from last year. And the perfect opportunity to re-post, re-purpose and re-use all my 2015 blog entries. If you missed any of the 89 attempts including 59 videos, here they are wrapped in one simple entry. I read somewhere that lists in blogs are good. I broke it out by month to see what was happening at the time and let's be honest, pure self-promotion.

Thanks for reading and watching throughout 2015.

Have a Safe and Happy New Year.

January 2015
February
March
April
May
June
July
August
September
October
November
December
And a couple special holiday themed entries from years past.
ps
Related

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Wednesday, December 2, 2015

Arguing with Things

As more things get connected, we may find ourselves disagreeing with them.

We all argue, especially if you’re passionate about something. Sometimes it’s with our spouse, sometimes with friends or co-workers and sometimes we scold objects that aren’t doing what we want them to do, ‘Ah, come on pen…don’t run out of ink now!!’ As more of these things get connected and are interacting with us, will you find yourself arguing with inanimate objects even more?

echoThe other day I was talking to my wife about Alexa (the Amazon Echo) and suddenly from the other room we hear, ‘I will add that item to the shopping cart.’ We looked at each other and simultaneously said, ‘What was that?’ with the added ‘jinx’ that quickly follows. We walked over to the device and started interrogating it as to what it just added to the cart. ‘I don’t understand the question…I can’t seem to find what you are looking for…I can’t understand what you said,’ were the various responses. These answers would drive a detective to charge it with obstructing justice. This is not a complaint against Echo mind you, we like it. It just couldn’t understand our questions until we asked the right way.

It also seems to have feelings. My daughter told it that it was stupid (for not understanding us) and Echo replied with, ‘That’s not very nice.’ M3S looked at me, looked at Alexa and then apologized to the cylinder. Not sure if she forgave us, but we’re a little more courteous around her now. Over at The Guardian, Rory Carroll experienced the same thing and he writes about how these home robots hear everything and the types of data captured by many of these home services. There are no more boundaries between home and the outside world. 

When I’m in the car and pass the intended route, the GPS keeps telling me to make my first legal U-turn, even though I know where I’m going. On a few occasions I’ve quipped, ‘Stop bossing me around!’ It ignores me and keeps reiterating that I’m going the wrong way. Tossing it in the back seat doesn’t help.

With the holiday season upon us and wish lists getting fulfilled, you may find that in 2016, your quarrels will be with gaming consoles, thermostats, fitness trackers, security cameras, refrigerators and other gadgets instead of humans.

I guess that’s better than making a scene at the dinner table.*

ps

* Except in cases where smart utensils have been deployed.

Related

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Wednesday, November 11, 2015

Connecting the Threads

What was first used to protect humans from the outside elements is now monitoring our body's inside environment.

According to eMarketer.com, wearable usage will grow almost 60% in 2015 verses 2014. This year, almost 40 million U.S. adults will use wearables, including smartwatches and fitness trackers. And that's only 16% of the penetrable market. They expect that number double in two years with close to 82 million adults wearing something connected by 2018. Almost two in five internet users by 2019. You probably think that it'll be all those youngsters growing up with connected objects but over the next four years, older Americans will see the biggest growth with the flood of wearable health monitor devices. Don't fret, I'm sure that new outfit for special occasions will monitor something. These connected wearables will soon be able to cover our body.

198643Even with that growth, adults are still exploring the value of wearables, above the wow-cool factor, for the real benefit of the investment. With prices still high for many of these gadgets, the adoption will be slightly lower than the recent mad rush for smartphones and tablets. Yet like many new technologies, as sticker-shock drops, the adoption grows. In addition, as more apps are developed to work with this new wardrobe, more people are likely to use it...just like the mobile device market. After all, that's what these things are - mobile devices. And once that happens, the advertisers will be all over that segment, which is currently very sparse.

And what typically follows mass adoption of technology? Vulnerabilities and security risks.

More connected personal devices in the office means more enterprise security risks. Whether it be from smartwatches having access to sensitive corporate data or the lost bandwidth from all the updates and alerts sent to these devices. Corporate BYOD security policies could soon include smartwatch use or any other wearable that poses a risk to the organization. As Steven Wright says, 'Right now I'm having amnesia and déjà vu at the same time.' BYO2.0

And we haven't even touched on the lack of security being built into some of these devices.

From insulin pumps, to glucose meters to pacemakers, anything that is wireless enabled is vulnerable to attack. While the bad guys are always looking for an easy score, it could also be the disgruntled employee looking to fix someone's wagon. And when I say fix, I really mean break. There are also privacy concerns for those who might be wearing smart eyewear. That casual, always awkward conversation at the urinal now takes on new meaning. For highly sensitive meetings, there could be a clothes rack and changing station so someone doesn't need to strip down just to participate. Forget about spy pens with wireless mics, my shirt's logo has a camera weaved into the seam.

All is not lost though, as there will be plenty of top 10 lists guiding you so you do not become a social (real world) outcast. WT VOX has put together it's Top 10 Worst Wearable Tech Devices So Far list. From a tie that has a QR code built into its back, to smartwigs, selfie-hats and drum pants, they explore the wild gadgets that are clamoring to cover our body. And on the flip side, they also look at the 10 Wearables and IoT Companies To Watch In 2015. Here, you get a glimpse of the future of smart lighting, dealing with big data, new IoT chipsets, IoT cloud platforms and other entities focused on our networked society.

Hashtag: Amazing.

ps

Related:
Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Wednesday, October 21, 2015

Wearables Head to Tail

Have you sent Santa your list of all the wearables you'll want under the tree this year? Maybe you've asked for a fitness tracker, a health monitor or that fancy new smart watch. But don't stop there!

As we continue to integrate technology with our desire for self-improvement and lifestyle control, a slew of wearables - from arm bands to socks to bras to a dog tail-wagging monitor - will be clipped, adhered, buttoned, inserted, ingested or worn to gather our vitals, movement and lives as we toast 2015 goodbye.

wearing techNaughty or nice, if you're still unsure which wearables you want watching you, Fjord (part of Accenture Interactive) has a nifty infographic showing the multitude of gadgets for various body parts. From the head to upper body to wrists to feet to anywhere, our body has become both the controller and interface according to Fjord. Their research indicates that about 70% of wearables are intended to monitor our body in some way, with the remaining 23 percent designed for communication. 59% of these health-oriented devices monitor your health and 48 percent track fitness. Around 7% can help a person sleep better. Fjord predicts that wearable technology will become a growing trend for health care providers and digital applications for health care organizations have become a growing area of focus for Fjord.

On your head you can wear a smart cycling helmet which takes your pulse and reports it to a smartphone app or a brain activity measurement tool to help understand and improve focus.

On your upper body you can have a sensor and app tell you when you are slumping to improve posture or a t-shirt designed to capture biometrics or even the Microsoft Smart Bra designed to measure perspiration and heart rate in order to detect emotional triggers.

Of course for the wrist we got the smart watches and fitness trackers but there is also devices that can tell you about sun exposure, how much food you've eaten and calories burned during the feeding frenzy.

For your feet and pretty much anywhere on or in your body, there are smart socks that track your running technique with sensors around the ankle, sensors in the sole of shoes to measure motion parameters, gadget sensors that fit in your pocket for movement measurements and even second skin type materials that stick anywhere on the body and provides personalized health data on a variety of measurements. And if that's not enough, there are ingestible sensors that can monitor how much medicine is absorbed by the body and the PillCam that gives you a colonoscopy by having a light and two color video cameras within the pill.

Not to be left out, your pet is also pawing up their list and DogStar Life is working on building TailTalk, a tail-mounted sensor intended to track your dog's emotions based on tail movements. Built into this tail clip-on is an accelerometer and gyroscope so it knows the difference between happy tail-wagging when you walk in the door verses when the tail is tucked or standing at attention. The sensor then sends the information to an app that translates the movement data into emotions, telling you if your dog is stressed, happy or crazy thrilled.

And soon, I'm sure, there will be one that measures your significant other's reaction to the lame gift you got them. Like the evil eye death stare data isn't enough.

ps

Related

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Wednesday, October 14, 2015

The Wave of Change at Tech Events

ninja bowlI attend a lot of technology trade shows throughout the year and still remember going to my first technology event for F5 back in 2004. Small, almost high school science fair type booths handing out glossy flyers of the latest product along with our famous squeeze balls.

And for the years that followed, the events, booths,sessions and presentations got bigger and better...but the expo vendors were still almost exclusive to technology providers. The attendees came from different industries and walks of life but they were there to learn about the latest tech solutions offered by these semi-tented companies.

Until now.

Recently, at events like MWC, RSA, VMworld and AWS re:Invent, I've started noticing a number of traditionally non-technology specific vendors exhibiting and positioning within technology events. Granted, over the years there have been a smattering of one-offs at events and of course there is CES but these days, there seems to be more historically non-tech companies appearing and exhibiting at tech events.

But it makes total sense.

I really took notice during Mobile World Congress earlier this year where a number of auto manufactures had huge displays showing their software-driven connected cars and how mobile technologies are enabling these internet connected devices. Most auto manufacturers are already partnering with multiple service providers and technology companies to bring mobility, connectivity and interaction to the car.

And then just recently at AWS re:Invent, amongst all the technology companies, there was an apparel, shoe and fitness manufacturer highlighting the technology within their wearables. Along with clothing, these companies are becoming software and data warehouses connecting them directly to the consumer. It is not just about the cool laces anymore, it's about measuring the impact of your foot to the ground and automatically adjusting the cushion. It's about getting instant feedback about your golf swing from the shirt you are wearing. It's about measuring your vitals to ensure your activity is healthy and productive.

And that is all about the embedded technology.

As more home appliances, wearables, automobiles, cameras, fitness trackers, and any other of these sensors and actuators powering the Internet of Things gets connected and generates data, I suspect we'll be seeing more ovens, autos, shoes and other stuff appearing at these industry events.

I think it's an interesting trend to observe.

ps

Related:

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Friday, October 2, 2015

IoT: Tabs to be Read Later

I've been traveling a bit over the last month and my tabs-to-read-later pile is growing. We'll be at AWS re:Invent next week so I thought I'd unload some of the IoT stories that caught my eye recently, that I'm finally getting to read. Apologies if this is old news to you.

tabs

One I've been holding on to almost the longest is an interesting INC article Our Future Will be Analog, Not Digital. Geoffrey James talks about the Internet of Things and how people think the convenience of connectivity is more important than the risks involved. He talks about how snail mail, cash and unplugging are tending up along with how analog objects are becoming status symbols. This is a good one if you think all this connectivity will become so hackable and fragile that no one will want to use it.

Next from The Economist, saying on the IoT theme, is Their own Devices. From Barbie's to cars to televisions, compromised computers are all over the place and few companies have the incentive to take security seriously within their widgets. There needs to be a change in corporate culture especially within non-computer companies. From the early days of the boiler explosions and crashes on railways to the safety of cars in the 70's to the hacks of medical devices today, we all need to recognize that connected devices need protection. And so do we.

To that, from Mashable, is how Major automakers are forming an alliance to tackle cybersecurity.With the growing concerns and actual demonstrations of cars getting breached, the Alliance of Automobile Manufacturers and the Association of Global Automakers are forming an Information Sharing and Analysis Center, according to Automotive News. Chris Perkins says, the creation of the Information Sharing and Analysis Center (ISAC) represents an important proactive step from the industry to address these hacks before they happen.

The last couple years during the NFL season, I've written some stories about technology in sports including Are You Ready For Some...Technology!! and more recently with Will Deflate-Gate Lead to Micro-Chipped Footballs? On Ars Technica, David Kravets goes deeper into the sensor technology being used by the NFL this year with How the NFL—not the NSA—is impacting data gathering well beyond the gridiron. He talks about how RFID is being used to track all the player's movements and how they will use the 2 to 3 gigs of data generated each game. Also how teams can use the data for training and coaching along with how console gaming might use it and how it could affect fantasy bets. Very interesting article on how all this connectivity plays into the games we watch, play and enjoy.

OK, that's it for now and thanks for the chance to clean up some of my browser tabs. Now I got room for the next bunch.

ps

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]