by thedocgeek on Fri Mar 25, 2016 3:06 pm

Steve of has spoken a lot about IoT being a gateway into a home's network. He talked a lot about it on the TWIT podcast Security Now #551. Has Anyone listened to his views and reported what it means to users of Adafruit products?

by mikeadamz on Sat Mar 26, 2016 12:28 am

I think the problem with IOT security is not the people here, the makers, but the consumers. The audience here is much more likely to tinker with their devices, configure secure defaults, and keep things up to date. There may be some old Raspberry Pi's floating around, but I'd wager that the Arduino devices are pretty secure.

What is a risk, though, are all of the plug in and forget it type devices. Things like your internet router, smart security camera, etc.. These devices are usually set up once and never looked at again. Meanwhile, they're running web servers and other software that need to be maintained.

Some connected device manufacturers have caught on to this, though. For example, Nest products are auto updated without user consent or intervention. This keep things patched and secure, but at the cost of giving up a lot of control to the vendor.

That's one of the things that makes MQTT so attractive - it's all outbound connections from your device. It can consume data on one feed and maybe publishes data to another feed; all without the need to have a service listening. Devices with no running services are much more difficult to exploit.

