mastodon.cc is one of the many independent Mastodon servers you can use to participate in the fediverse.
Mastodon for Art

Administered by:

Server stats:

66
active users

#iot

7 posts6 participants0 posts today

Jedes Produkt ist nur so sicher wie seine Einzelteile: Am Wochenende wurde eine #Backdoor in einem #IoT-#Mikrocontroller entdeckt, der in geschätzt mehr als einer Milliarde IoT Devices verbaut ist. Und weil der Chip nur 2 EUR im Einkauf kostet, wird er auch in so vielen Endgeräten verbaut. Mit der Backdoor ist es u.a. möglich, sensible Daten abzugreifen, Geräte fernzusteuern oder #Schadsoftware zu verbreiten - Security by Design schaut anders aus:

bleepingcomputer.com/news/secu

BleepingComputer · Undocumented commands found in Bluetooth chip used by a billion devicesBy Bill Toulas

#Cybersecurity #Schwachstelle #IoT Devices: Eine ziemlich abenteuerliche Geschichte von einem Akira #Ransomware Angriff zeigt, dass Endpoint Detection and Response (#EDR) nicht immer hilft, wenn es an anderer Stelle im Unternehmensnetz weitgehend ungeschützte Einfallstore gibt - bis hin zu einer auf den ersten Blick vielleicht harmlos erscheinenden Webcam - darum macht Netzwerksegmentierung Sinn:

golem.de/news/cyberangriff-ana

Golem.de · Cyberangriff analysiert: Hacker verschlüsseln Unternehmensdaten über eine Webcam - Golem.deBy Marc Stöckel

Yikes, from an article that contains a lot more detail, but just to get your attention as to the impact part:

«The ubiquitous ESP32 microchip made by Chinese manufacturer Espressif and used by over 1 billion units as of 2023 contains undocumented commands that could be leveraged for attacks.

The undocumented commands allow spoofing of trusted devices, unauthorized data access, pivoting to other devices on the network, and potentially establishing long-term persistence.

"Exploitation of this backdoor would allow hostile actors to conduct impersonation attacks and permanently infect sensitive devices such as mobile phones, computers, smart locks or medical equipment by bypassing code audit controls."

The researchers warned that ESP32 is one of the world's most widely used chips for Wi-Fi + Bluetooth connectivity in IoT (Internet of Things) devices, so the risk is significant.»

People worried about this topic might also "enjoy" the recent Netflix series Zero Day.

And not to get too far afield, but hopefully it also didn't escape notice that there have been broad firings of qualified people in the US government for reasons related not to their technical skill or ability to protect our nation from issues like this, but because of irrelevant details of their private lives or personal leanings on issues of having fair and competent government, helping the needy, defending individual human freedom and dignity, or avoiding mass death in myriad ever-more-likely ways.

bleepingcomputer.com/news/secu

BleepingComputer · Undocumented commands found in Bluetooth chip used by a billion devicesBy Bill Toulas
Continued thread

I was not the only one who found the headlines of an #ESP32 #backdoor a wee bit overblown, and #TarLogic presentation reeking a wee bit of self promotion -

after reading all of it, i found myself slightly unimpressed and none too worried about #IoT #security ..

BleepingComputer has changed their headline

bleepingcomputer.com/news/secu

BleepingComputer · Undocumented commands found in Bluetooth chip used by a billion devicesBy Bill Toulas
Replied in thread

@ai6yr Sounds like the attacker would have to be close to your weather station to get Bluetooth connectivity before issuing low level commands.
Most fun, though not profit, could come from having the infected device spread the infection to its neighbours until no IoT devices remain on the planet.
#iot

86.000 #IoT Devices - eines der größten #Botnetze der letzten Jahre wurde durch Researcher von #Nokia ausfindig gemacht: Vor allem sind Netzwerkkameras und Netzwerk-Videorekorder betroffen - meistens Devices, die einmal in das Netzwerk gehängt und nie wieder aktualisiert werden - geschweige denn überhaupt jemals richtig vorkonfiguriert wurden:
"GreyNoise has published a list of IP addresses linked to Eleven11bot and confirmed to carry malicious actions" #cybersecurity
bleepingcomputer.com/news/secu

BleepingComputer · New Eleven11bot botnet infects 86,000 devices for DDoS attacksBy Bill Toulas

I need to find a plug that I can remotely operate via the internet. It should work via wifi. It would be nice if it were actually secure and not some massive security hole in the network. It would be used to power cycle a Raspberry Pi periodically when the Raspberry Pi crashes and I can't get to it in person for weeks at a time.

We are the Ariel OS project: developing an operating system for embedded systems in Rust, for a safer #IoT.

We just published our first 0.1 release, with which we already enable building portable multi-core applications on Cortex-M, RISC-V and ESP32 devices, using different link-layer and application layer networking protocols, including out-of-the-box secure communication.

ariel-os.org/ has all the links to examples, manual and API docs.

Ariel OS is a library operating system for secure, memory-safe, low-power Internet of Things, written in Rust - ariel-os/ariel-os
GitHubGitHub - ariel-os/ariel-os: Ariel OS is a library operating system for secure, memory-safe, low-power Internet of Things, written in RustAriel OS is a library operating system for secure, memory-safe, low-power Internet of Things, written in Rust - ariel-os/ariel-os