Security fears for 'internet of things'

US officials have expressed concerns about cyber attacks that hijack internet-connected gadgets.

US officials are trying to reassure the public they are taking steps to counter new types of cyber attacks using the so-called "internet of things".

Such an attack recently rendered Twitter, Spotify, Netflix and dozens of other major websites unavailable.

The Department of Homeland Security says it held a conference call with 18 major communication service providers shortly after the attack on Friday and was working to develop a new set of "strategic principles" for securing internet-connected devices.

DHS said its National Cybersecurity and Communications Integration Center was working with companies, law enforcement and researchers to cope with attacks made possible by the rapidly expanding number of smart gadgets that make up the "internet of Things".

Such devices, including web-connected cameras, appliances and toys, have little in the way of security. More than a million of them have been commandeered by hackers, who can direct them to take down a target site by flooding it with junk traffic.

Several networks of compromised machines were directed to attack big customers of web infrastructure company Dyn last week, Dyn officials and security researchers said.

The disruption had subsided by late Friday night in America, and two of the manufacturers whose devices had been hijacked for the attack pledged on Monday to try to fix them.

But security experts said that many of the devices would never be fixed and that the broader security threat posed by the internet of Things would get worse before it gets better.

"If you expect to fix all the internet devices that are out there, force better passwords, install some mechanism for doing updates and add some native security for the operating system, you are going to be working a long time," said Ed Amoroso, founder of TAG Cyber and former chief security officer at AT&T.

Instead, Amoroso said he hoped that government officials would focus on recommending better software architecture and that business partners would insist on better standards.

In the meantime, fresh responses by two of the companies involved in the attacks illustrated the extent of the problem.

Chinese firm Hangzhou Xiongmai Technology Co Ltd, which makes components for surveillance cameras, said it would recall some products from the United States.

Another Chinese company, Dahua Technology, acknowledged that some of its older cameras and video recorders were vulnerable to attacks when users had not changed the default passwords. Like Xiongmai, it said it would offer firmware updates on its website to fix the problem and would give discounts to customers who wanted to exchange their gear.


Share

3 min read

Published

Source: AAP



Share this with family and friends


Get SBS News daily and direct to your Inbox

Sign up now for the latest news from Australia and around the world direct to your inbox.

By subscribing, you agree to SBS’s terms of service and privacy policy including receiving email updates from SBS.

Download our apps
SBS News
SBS Audio
SBS On Demand

Listen to our podcasts
An overview of the day's top stories from SBS News
Interviews and feature reports from SBS News
Your daily ten minute finance and business news wrap with SBS Finance Editor Ricardo Gonçalves.
A daily five minute news wrap for English learners and people with disability
Get the latest with our News podcasts on your favourite podcast apps.

Watch on SBS
SBS World News

SBS World News

Take a global view with Australia's most comprehensive world news service
Watch the latest news videos from Australia and across the world