Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Why embedded platforms does not give a damn about security? It looks like they just don't care.


It's not only embedded systems.

In general businesses care about short term profit (sure in the long term a hack is bad for business but share holders don't care except in the cases were it would be fatal to the business).

Engineers are pressed to get it done anyway possible and as fast a possible. The ones that push back get fired or moved to another project.

The fact remains that adding security and encryption requires more knowhow and adds a layer of complexity which results in more time required.


> Engineers are pressed to get it done anyway possible and as fast a possible. The ones that push back get fired or moved to another project.

This. Also incompetent engineering teams could be a major factor.


here's a scenario, let's say that GM goes hog wild after this and hires every expert security researcher with experience in this domain. they create an internal tiger team for security. they re-organize their entire product delivery pipeline to incorporate internal and external security audits and they publish everything they do. and they create and fund an open bug bounty program for bugs in all auto manufacturers (proxied through a non-profit) and make a "pwn2own for cars" or something and after five years, GM cars are measurably more secure than any other car manufacturer.

in this future in five years, do you buy GM? no? that's why they don't give a damn about security.


There are two factors in play here and your scenario only accurately measure one:

1) If GM cars security is the best of the market will it carry any weight in the purchase decision (as compared to all the other factors)?

2) If GM cars security is not the best of the market and one of their security incidents make headlines in mainstream TV and newspapers will it carry any weight in the purchase decision (as compared to all the other factors)?

People don't pay attention when things that are supposed to work properly do so but when they don't it carries a lot of weight in the purchase decision. See the Toyota slump [1] in the U.S. market share between 2009 and 2011 caused by many factors but certainly with a contribution of the bad news related to the recalls [2]

[1] http://online.wsj.com/mdc/public/page/2_3022-autosales.html#...

[2] https://en.wikipedia.org/wiki/2009%E2%80%9311_Toyota_vehicle...


Security is balanced against cost in a risk-based assessment. One of those factors is certainly bad publicity and lost sales, and that might actually be a fairly small number. But there are still other ways to weight the argument in favour of security. For example: regulatory fines, senate investigations, class action lawsuits, directors going to prison, cost of recalls, etc.

So although GM may not have much security pressure from the consumer, depending on the surrounding legal and regulatory environment, creating more secure cars might end up being a sensible move.

I guess what I'm saying is that I agree that currently there isn't as strong pressure for security as I'd like. But that can change and not just from the consumer/sales side.


You could make a "drive by" (in the literal sense) gizmo that bricks vulnerable cars, maybe even causes expensive physical damage. Can you start a car fire by controlling fuel pressure pumps and injectors, or destroy a turbocharger? Stick a ten minute delay in your injected code and you're long gone.

GM (or really, virtually any car manufacturer with the possible exception of Tesla) would be caught flat-footed.

Firmware in consumer products (especially where radio or network access is present) needs to have a security model. Car makers have been betting they didn't need to spend much money worrying about security; it doesn't look like that bet is going to pay off.

If this becomes a thing that any kid with $30 of electronics can do, dinosaur makers are toast.


I hate to break it to you, but any kid with USD 0.10 can start a fire in a car today. It requires a.) one rock and b.) one box of matches. Break a window with the rock, then throw lit matches onto the upholstery. Really, the threat model is NOT disaffected kids.


why do you specify "embedded" ? after each hack, when I see that X company stores password either unhashed, or weakly hashed, the conclusion is that almost no ones gives a damn about security. and no one will until failing to properly secure sensitive customer data is enforced with hefty fines.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: