<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Don't throw away your smart lightbulbs ... in Industry News</title>
    <link>https://community.isc2.org/t5/Industry-News/Don-t-throw-away-your-smart-lightbulbs/m-p/18798#M2216</link>
    <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/269736147"&gt;@wimremes&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Risk is in the eye of the beholder &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That's true; unfortunately many are blind to the risks or tend to overlook them. Most of us in IT Security are well aware of risks, and take measures to mitigate them --- but not everyone does.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In your case the probability &amp;amp; impact of someone exploiting the info from IoT devices is low, so the residual risk of using such devices is acceptable. I suppose there'd be little / no profit for someone ravaging through a dumpster to find an IoT light-bulb you've used...&amp;nbsp;&lt;img id="manwink" class="emoticon emoticon-manwink" src="https://community.isc2.org/i/smilies/16x16_man-wink.png" alt="Man Wink" title="Man Wink" /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But picture someone whose general IT Security is very lax, like in the situation below:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Single WiFi network with 1 SSID &amp;amp; a simple password that's rarely --- if ever --- changed.&lt;/LI&gt;&lt;LI&gt;End-points not being kept updated or secured with an EPS or firewall.&lt;/LI&gt;&lt;LI&gt;Simple account passwords, with little or no use of multi-factor authentication.&lt;/LI&gt;&lt;LI&gt;Identical / similar passwords used to secure multiple accounts,&lt;/LI&gt;&lt;LI&gt;Information --- including passwords --- stored locally and in plain text.&lt;/LI&gt;&lt;LI&gt;Use of info published on social networking sites as answers to security questions.&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://community.isc2.org/t5/Industry-News/Paying-ransomware-ransom/m-p/18751#M2214" target="_blank" rel="noopener"&gt;Preference to pay up&amp;nbsp;in the event of ransomware attacks&lt;/A&gt;&amp;nbsp;with no preventive actions after.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;And the list goes on. The scenario I've painted might seem incredulous, but I've seen many like it...&amp;nbsp;&lt;img id="manindifferent" class="emoticon emoticon-manindifferent" src="https://community.isc2.org/i/smilies/16x16_man-indifferent.png" alt="Man Indifferent" title="Man Indifferent" /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If this someone is sitting on a gold mine, uses IOT devices &amp;amp; fails to dispose of them properly, the potential gains of retrieving the devices &amp;amp; extracting info from them may be well worth it to someone with motivations.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 08 Feb 2019 09:46:47 GMT</pubDate>
    <dc:creator>Shannon</dc:creator>
    <dc:date>2019-02-08T09:46:47Z</dc:date>
    <item>
      <title>Don't throw away your smart lightbulbs ...</title>
      <link>https://community.isc2.org/t5/Industry-News/Don-t-throw-away-your-smart-lightbulbs/m-p/18685#M2204</link>
      <description>&lt;P&gt;... or smart anything else in the IoT world.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Pretty much every single IoT device you have connects to your wifi.&amp;nbsp; And therefore knows your wifi credentials.&amp;nbsp; And where (and how) do they &lt;A href="https://www.zdnet.com/article/this-smart-light-bulb-could-leak-your-wi-fi-password/" target="_blank" rel="noopener"&gt;store your network SSID and password&lt;/A&gt;?&lt;/P&gt;</description>
      <pubDate>Tue, 05 Feb 2019 16:47:04 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Don-t-throw-away-your-smart-lightbulbs/m-p/18685#M2204</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2019-02-05T16:47:04Z</dc:date>
    </item>
    <item>
      <title>Re: Don't throw away your smart lightbulbs ...</title>
      <link>https://community.isc2.org/t5/Industry-News/Don-t-throw-away-your-smart-lightbulbs/m-p/18709#M2206</link>
      <description>&lt;P&gt;I don't know how this works in the US but here I bring light bulbs and other electronics to a specific location. From there, an adversary would have to :&lt;/P&gt;&lt;P&gt;(a) gain access to the location and find "my" bulb.&lt;/P&gt;&lt;P&gt;(b) extract the passwords&lt;/P&gt;&lt;P&gt;(c) war drive a zone of about 20 square km to find "my" network.&lt;/P&gt;&lt;P&gt;(d) sit outside my door (there is no obvious line of sight location that would give them distance)&lt;/P&gt;&lt;P&gt;(e) profit?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Given a dedicated IoT SSID when push comes to shove, I guess I'll be fine.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Feb 2019 12:35:16 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Don-t-throw-away-your-smart-lightbulbs/m-p/18709#M2206</guid>
      <dc:creator>wimremes</dc:creator>
      <dc:date>2019-02-06T12:35:16Z</dc:date>
    </item>
    <item>
      <title>Re: Don't throw away your smart lightbulbs ...</title>
      <link>https://community.isc2.org/t5/Industry-News/Don-t-throw-away-your-smart-lightbulbs/m-p/18728#M2208</link>
      <description>&amp;gt; wimremes (Newcomer III) posted a new reply in Industry News on 02-06-2019 07:35&lt;BR /&gt;&lt;BR /&gt;&amp;gt; I don't know how this works in the US but here I bring light bulbs and other&lt;BR /&gt;&amp;gt; electronics to a specific location.&lt;BR /&gt;&lt;BR /&gt;Ah, yes, but where does it go after that?&lt;BR /&gt;&lt;BR /&gt;And, from teaching in the States, I know that most USians are not real big on&lt;BR /&gt;recycling, so dead smart lightbulbs become yet another treasure for dumpster&lt;BR /&gt;divers.&lt;BR /&gt;&lt;BR /&gt;&amp;gt; From there, an adversary would have to : (a)&lt;BR /&gt;&amp;gt; gain access to the location and find "my" bulb. (b) extract the passwords (c)&lt;BR /&gt;&amp;gt; war drive a zone of about 20 square km to find "my" network. (d) sit outside my&lt;BR /&gt;&amp;gt; door (there is no obvious line of sight location that would give them distance)&lt;BR /&gt;&amp;gt; (e) profit?&lt;BR /&gt;&lt;BR /&gt;Given that an awful lot of our (developed nations in total) high tech waste tends&lt;BR /&gt;to end up in third world countries being torn apart for scrap, lots and lots and&lt;BR /&gt;*lots* of drives and other memory storage is available for the taking (or, at least,&lt;BR /&gt;very minimal cost). This is a potentially huge source of data breach material.&lt;BR /&gt;&lt;BR /&gt;And, it's not that hard to profit. Oh, sure, nobody is likely to go after your&lt;BR /&gt;specific lightbulb to break into your specific wifi network. But they can harvest&lt;BR /&gt;tons of credentials and sell them. And there are many mapping sources that can&lt;BR /&gt;track down SSIDs without you having to war-drive all over town. (I can turn off&lt;BR /&gt;GPS and *still* have my location determined to within tens of metres, just by the&lt;BR /&gt;wifi networks around me.)&lt;BR /&gt;&lt;BR /&gt;&amp;gt; &amp;nbsp; Given a dedicated IoT SSID when push comes to shove, I guess I'll&lt;BR /&gt;&amp;gt; be fine.&lt;BR /&gt;&lt;BR /&gt;I wouldn't bet on it. At least, I wouldn't bet *much* ...&lt;BR /&gt;&lt;BR /&gt;====================== (quote inserted randomly by Pegasus Mailer)&lt;BR /&gt;rslade@vcn.bc.ca slade@victoria.tc.ca rslade@computercrime.org&lt;BR /&gt;We die only once, and for such a long time. - Moliere&lt;BR /&gt;victoria.tc.ca/techrev/rms.htm &lt;A href="http://twitter.com/rslade" target="_blank"&gt;http://twitter.com/rslade&lt;/A&gt;&lt;BR /&gt;&lt;A href="http://blogs.securiteam.com/index.php/archives/author/p1/" target="_blank"&gt;http://blogs.securiteam.com/index.php/archives/author/p1/&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://is.gd/RotlWB" target="_blank"&gt;https://is.gd/RotlWB&lt;/A&gt;</description>
      <pubDate>Wed, 06 Feb 2019 18:38:04 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Don-t-throw-away-your-smart-lightbulbs/m-p/18728#M2208</guid>
      <dc:creator>rslade</dc:creator>
      <dc:date>2019-02-06T18:38:04Z</dc:date>
    </item>
    <item>
      <title>Re: Don't throw away your smart lightbulbs ...</title>
      <link>https://community.isc2.org/t5/Industry-News/Don-t-throw-away-your-smart-lightbulbs/m-p/18769#M2215</link>
      <description>&lt;P&gt;Risk is in the eye of the beholder &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;A href="https://xkcd.com/538/" target="_blank" rel="noopener"&gt;https://xkcd.com/538/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Feb 2019 10:24:57 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Don-t-throw-away-your-smart-lightbulbs/m-p/18769#M2215</guid>
      <dc:creator>wimremes</dc:creator>
      <dc:date>2019-02-07T10:24:57Z</dc:date>
    </item>
    <item>
      <title>Re: Don't throw away your smart lightbulbs ...</title>
      <link>https://community.isc2.org/t5/Industry-News/Don-t-throw-away-your-smart-lightbulbs/m-p/18798#M2216</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.isc2.org/t5/user/viewprofilepage/user-id/269736147"&gt;@wimremes&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Risk is in the eye of the beholder &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That's true; unfortunately many are blind to the risks or tend to overlook them. Most of us in IT Security are well aware of risks, and take measures to mitigate them --- but not everyone does.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In your case the probability &amp;amp; impact of someone exploiting the info from IoT devices is low, so the residual risk of using such devices is acceptable. I suppose there'd be little / no profit for someone ravaging through a dumpster to find an IoT light-bulb you've used...&amp;nbsp;&lt;img id="manwink" class="emoticon emoticon-manwink" src="https://community.isc2.org/i/smilies/16x16_man-wink.png" alt="Man Wink" title="Man Wink" /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But picture someone whose general IT Security is very lax, like in the situation below:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Single WiFi network with 1 SSID &amp;amp; a simple password that's rarely --- if ever --- changed.&lt;/LI&gt;&lt;LI&gt;End-points not being kept updated or secured with an EPS or firewall.&lt;/LI&gt;&lt;LI&gt;Simple account passwords, with little or no use of multi-factor authentication.&lt;/LI&gt;&lt;LI&gt;Identical / similar passwords used to secure multiple accounts,&lt;/LI&gt;&lt;LI&gt;Information --- including passwords --- stored locally and in plain text.&lt;/LI&gt;&lt;LI&gt;Use of info published on social networking sites as answers to security questions.&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://community.isc2.org/t5/Industry-News/Paying-ransomware-ransom/m-p/18751#M2214" target="_blank" rel="noopener"&gt;Preference to pay up&amp;nbsp;in the event of ransomware attacks&lt;/A&gt;&amp;nbsp;with no preventive actions after.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;And the list goes on. The scenario I've painted might seem incredulous, but I've seen many like it...&amp;nbsp;&lt;img id="manindifferent" class="emoticon emoticon-manindifferent" src="https://community.isc2.org/i/smilies/16x16_man-indifferent.png" alt="Man Indifferent" title="Man Indifferent" /&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If this someone is sitting on a gold mine, uses IOT devices &amp;amp; fails to dispose of them properly, the potential gains of retrieving the devices &amp;amp; extracting info from them may be well worth it to someone with motivations.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Feb 2019 09:46:47 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Industry-News/Don-t-throw-away-your-smart-lightbulbs/m-p/18798#M2216</guid>
      <dc:creator>Shannon</dc:creator>
      <dc:date>2019-02-08T09:46:47Z</dc:date>
    </item>
  </channel>
</rss>

