Masses of security holes in networked devices
Summary
In 2014 researchers at the French institute Eurécom automatically analysed 32,356 firmware files of networked devices. 693 images contained at least one hole, 38 of them previously unknown; more than 300 showed signs of backdoors, for example in a device from the Belkin Wemo series. They also collected 109 private RSA keys from more than 400 images.
Ideas
- Automated firmware analysis finds security problems on a large scale.
- Preset user accounts with weak passwords were widespread.
- Private keys in public firmware render the encryption of all devices worthless.
- A Wemo device executed commands as root when sent certain multicast packets.
Insights
- Manufacturers use the same keys and components across many devices.
- What is in public firmware is no longer a secret.
Facts
- Almost 700 images contained preset user accounts; in 58 cases the hashes were cracked.
- Popular passwords were pass, logout, helpme and none at all.
- In 41 cases the researchers found the private key and certificate together.
References
Critique
- The report hardly names any manufacturers, so readers cannot match their own devices.
Recommendations
- Put IoT devices in a separate network segment without access to other systems.
- Where possible, replace manufacturer firmware with maintained open alternatives such as OpenWrt.
Links to the original source and the Web Archive open in a new tab.