Re: Security for the Internet of Things and Other Things (Was: Re: Observations on (non-technical) changes affecting IETF operations)

"Livingood, Jason" <Jason_Livingood@comcast.com> Wed, 09 March 2016 17:41 UTC

Return-Path: <Jason_Livingood@comcast.com>
X-Original-To: ietf@ietfa.amsl.com
Delivered-To: ietf@ietfa.amsl.com
Received: from localhost (localhost [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 19CD712D814 for <ietf@ietfa.amsl.com>; Wed, 9 Mar 2016 09:41:48 -0800 (PST)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -1.902
X-Spam-Level:
X-Spam-Status: No, score=-1.902 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001] autolearn=ham autolearn_force=no
Received: from mail.ietf.org ([127.0.0.1]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id xGJL59Gk30ik for <ietf@ietfa.amsl.com>; Wed, 9 Mar 2016 09:41:46 -0800 (PST)
Received: from vaadcmhout02.cable.comcast.com (vaadcmhout02.cable.comcast.com [96.114.28.76]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 56C4C12D811 for <ietf@ietf.org>; Wed, 9 Mar 2016 09:41:46 -0800 (PST)
X-AuditID: 60721c4c-f79106d000001de0-57-56e06058311c
Received: from VAADCEX36.cable.comcast.com (vaadcmhoutvip.cable.comcast.com [96.115.73.56]) (using TLS with cipher AES256-SHA (256/256 bits)) (Client did not present a certificate) by vaadcmhout02.cable.comcast.com (SMTP Gateway) with SMTP id D5.F8.07648.85060E65; Wed, 9 Mar 2016 12:41:44 -0500 (EST)
Received: from VAADCEX37.cable.comcast.com (147.191.103.214) by VAADCEX36.cable.comcast.com (147.191.103.213) with Microsoft SMTP Server (TLS) id 15.0.1130.7; Wed, 9 Mar 2016 12:41:43 -0500
Received: from VAADCEX37.cable.comcast.com ([fe80::3aea:a7ff:fe12:38b0]) by VAADCEX37.cable.comcast.com ([fe80::3aea:a7ff:fe12:38b0%19]) with mapi id 15.00.1130.005; Wed, 9 Mar 2016 12:41:43 -0500
From: "Livingood, Jason" <Jason_Livingood@comcast.com>
To: Michael Richardson <mcr+ietf@sandelman.ca>, Jari Arkko <jari.arkko@piuha.net>
Subject: Re: Security for the Internet of Things and Other Things (Was: Re: Observations on (non-technical) changes affecting IETF operations)
Thread-Topic: Security for the Internet of Things and Other Things (Was: Re: Observations on (non-technical) changes affecting IETF operations)
Thread-Index: AQHReVjFkCte8W518EWaVghtWwYIrZ9Rg/yA///fNAA=
Date: Wed, 09 Mar 2016 17:41:43 +0000
Message-ID: <D305C9B8.12B536%jason_livingood@cable.comcast.com>
References: <E83FC2B4-867D-44C9-AE1B-F4C414ABD041@piuha.net> <4A95BA014132FF49AE685FAB4B9F17F657DF2330@dfweml701-chm> <EDFB7D0B-2A49-46BD-A84C-0E1FA07793FA@piuha.net> <20160307133944.GB25576@gsp.org> <56DD876C.6050008@cs.tcd.ie> <CAMm+LwiBT9S-twGVzC-7yVBZ9dHA3+8f4ffPv3LyoZ_8+kdqmw@mail.gmail.com> <32C28750-37FF-4EDC-B0A8-A532B175C201@piuha.net> <9806.1457534345@obiwan.sandelman.ca>
In-Reply-To: <9806.1457534345@obiwan.sandelman.ca>
Accept-Language: en-US
Content-Language: en-US
X-MS-Has-Attach:
X-MS-TNEF-Correlator:
user-agent: Microsoft-MacOutlook/14.5.8.151023
x-ms-exchange-messagesentrepresentingtype: 1
x-ms-exchange-transport-fromentityheader: Hosted
x-originating-ip: [68.87.29.7]
Content-Type: text/plain; charset="iso-8859-1"
Content-ID: <DCD2D222BEE37C47892D18D6C1F7BB3B@cable.comcast.com>
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-CFilter-Loop: Forward
X-Brightmail-Tracker: H4sIAAAAAAAAA+NgFmpmleLIzCtJLcpLzFFi42JJKPa00I1IeBBmsHCekcWzjfNZLGbsW8Fm 0XOon91i4ofZjBYrPj5ldGD1OP6ggcXjwuqvTB5Llvxk8ti6ZDqbR8ucPcwBrFFcNimpOZll qUX6dglcGT3n7AsucFS8f32RtYHxCVsXIweHhICJRNfJ8C5GTiBTTOLCvfVAYS4OIYEtTBLX 7yxmBEkICRxklDi+RxoicYJRYsfzJawgCTYBM4m7C68wg9giAsESXYfWg9nMAukSP1bdZQRp EBaYwCjR+LiFBcQREZjIKHH0/FQWiA4riXXb/jKB2CwCKhKXjs9lA7F5BewlHu08wQKxrodZ YufH9WAJTgEjiVtnl4CtYAQ69vupNUwQ68Qlbj2ZzwTxhIDEkj3nmSFsUYmXj/+BnSoqoCdx 8NNKVoi4jsTZ608YIWwDia1L97FA2HISc1/fY4GYqSdxY+oUcBgxCzhIbNnqAxHWlli28DUz xJ2CEidnPoFqFZc4fGQH6wRGmVlILpqFZNIshEmzkEyahWTSAkbWVYxyZYmJKcm5GfmlJQZG esmJSTmpesn5ucmJxSUgehMjKGkUyfjsYPw0zeMQowAHoxIP72KHB2FCrIllxZW5hxglOJiV RHi544FCvCmJlVWpRfnxRaU5qcWHGKU5WJTEeR8k3g8TEkhPLEnNTk0tSC2CyTJxcEo1MK6d o/xLO2n3i8AlWT1LFfsD7nmHG8w4kNTqdHLiZ7dKz0sRUS/0V4UvLxeVeKv0XP3htCzPvz/f /Pt5RzFmdVOFVla+5MQJp3ks3CWW6J6pupt5OjNn2+FAn0/JhXGRjJrrpx/Vi1TUdqpzbS83 PaDHK1k++f98nb4JV+bv36z3d1cyz/7HCkosxRmJhlrMRcWJAC8dxtgWAwAA
Archived-At: <http://mailarchive.ietf.org/arch/msg/ietf/5bVq1rzGDHu4OHVwqdChIn9G8ew>
X-Mailman-Approved-At: Thu, 10 Mar 2016 08:07:44 -0800
Cc: Phillip Hallam-Baker <phill@hallambaker.com>, IETF <ietf@ietf.org>, Rich Kulawiec <rsk@gsp.org>
X-BeenThere: ietf@ietf.org
X-Mailman-Version: 2.1.17
Precedence: list
List-Id: IETF-Discussion <ietf.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/ietf>, <mailto:ietf-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/ietf/>
List-Post: <mailto:ietf@ietf.org>
List-Help: <mailto:ietf-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/ietf>, <mailto:ietf-request@ietf.org?subject=subscribe>
X-List-Received-Date: Wed, 09 Mar 2016 17:41:48 -0000

Sure, WiFi security is an issue for IoT. But there are probably much more
fundamental IoT security issues. IMHO I think one of the largest is the
lack of a secure & automatic (no end user interaction) software update
channel. 

- Jason



On 3/9/16, 9:39 AM, "ietf on behalf of Michael Richardson"
<ietf-bounces@ietf.org on behalf of mcr+ietf@sandelman.ca> wrote:

>
>Jari Arkko <jari.arkko@piuha.net> wrote:
>    > I want to add that the security problem for IOT is wider than
>setting
>    > up the secure wireless connectivity. I¹m going out on a limb and say
>    > that that in the networks that I work with, that¹s a largely solved
>    > problem modulo many non-IOT related updates that are being
>    > handled.
>
>I think the the problem of setting up the "secure" wireless connectivity
>is
>largely a distraction, and leads regularly to insecurity.
>
>I also think that the networks you speak of are largely vertically
>integrated.
>
>--
>Michael Richardson <mcr+IETF@sandelman.ca>, Sandelman Software Works
> -= IPv6 IoT consulting =-
>
>
>