Robots turning on their makers is a science-fiction staple. Until last week, that felt remote for most people. Then a cyberattack, not a physical one, tied up some of the world’s largest tech companies and showed how risky always-on internet devices can be.
Ironically named Mirai, Japanese for “future,” malware hijacked millions of Internet of Things (IoT) devices that nobody thought needed serious security, and used them to take down one of the world’s major DNS providers. The hit on Dyn left Twitter, Spotify, and many other sites and services unreachable.
Not the first, and not the last
The immediate problem looks contained, but the outlook is poor. This was not the first attack of its kind, and it will not be the last. Many home gadgets go online for convenience even when they barely need to, and ship with little or no security so costs stay low and design stays clean. Attackers can take them over with simple software and aim traffic at a single target.
Friday’s DDoS in the United States reportedly used around 10 million IoT devices. When that many clients hit one hub at once, the service slows or stops. With no security controls, the only blunt fix is to power devices off.
Users rarely know the protections exist
Some IoT products do use password gates for remote access, but most owners never hear about them. Factory defaults often never change, or no password is set at all, so outside access is trivial. Even when people know a password exists, they may lack the skill to change it, and many devices lack a simple interface.
To blunt future attacks, makers may need to meet clear security standards. Regulators and manufacturers share that job, and little is happening yet. Newer products might take security more seriously, but nothing today reliably stops another Friday-style wave.
Experts say the next few months will live under that shadow. Work is underway to prevent repeats, yet until defenses harden, every smart device that simplifies life can also complicate it. For users, the immediate task is to turn on any available protections on internet-capable gear and replace defaults with stronger passwords.
Source: Mashable