--- title: "Aditya Gupta -- The Exploitation of IoT" url: https://appsecpodcast.com/aditya-gupta-the-exploitation-of-iot/ date: 2017-10-10 duration_seconds: 1436 guests: ["Aditya Gupta"] topics: ["Vulnerabilities and Exploits"] audio: https://www.buzzsprout.com/1730684/episodes/8122704-aditya-gupta-the-exploitation-of-iot.mp3 transcript: true --- # Aditya Gupta -- The Exploitation of IoT *October 10, 2017 · 24 min* with [Aditya Gupta](https://appsecpodcast.com/guests/aditya-gupta/) on [Vulnerabilities and Exploits](https://appsecpodcast.com/topics/vulnerabilities/) [Audio](https://www.buzzsprout.com/1730684/episodes/8122704-aditya-gupta-the-exploitation-of-iot.mp3) ## Show notes Why can an IoT product look secure in one component and still fail as a complete system? Aditya Gupta, founder of Attify, joins Chris and Robert at AppSec USA to examine the gaps between hardware, firmware, radio communications, mobile applications, and web dashboards. He explains how fragmented development teams and unfamiliar protocols create security blind spots, and why authentication and secure design need attention before devices ship. The conversation covers resource constraints, firmware updates, physical access, and the way extracting information from one device can enable attacks against many others. Aditya also discusses practical learning resources and encourages developers to understand their entire product architecture rather than assuming that securing individual pieces will secure the whole. The Application Security Podcast is brought to you by [Security Journey](https://www.securityjourney.com/). About Security Journey Security Journey provides application security education for developers and everyone in the software development lifecycle. → [Learn more about Security Journey](https://www.securityjourney.com/) Connect with Aditya Gupta: → [Aditya Gupta and Attify](https://www.attify.com/about) Mentioned in this episode: → [Attify](https://www.attify.com/) → [OWASP IoT Top 10](https://owasp.org/www-project-internet-of-things/) Chapters: 00:00 The exploitation of IoT with Aditya Gupta 00:46 Aditya’s path from mobile security to IoT 02:03 Defining the Internet of Things 02:58 Where IoT development goes wrong 04:03 Security gaps between components and teams 05:48 Authentication failures and secure design 07:03 Practical security steps for developers 07:58 Protocol fragmentation and resource constraints 09:10 Designing the complete IoT system 11:17 Updating devices after deployment 17:30 How physical access exposes larger attack paths 20:48 Resources for learning IoT security ## Transcript *4,466 words · assemblyai* **0:05 Aditya Gupta:** The Application Security Podcast. Here we go. **0:09 Chris Romeo:** Hey folks, on this week's episode of the Application Security Podcast, Robert and Chris speak with Aditya at AppSecUSA. They talked to him about IoT and the many facets including pen testing, training, and mobile application security. As always, thanks for listening and enjoy. **0:46 Robert Hurlbut:** Well, hello friends, we're here at AppSecUSA, Chris and I, this week. And today we are going to be talking with Aditya, if I said it correctly. And he is— he actually did an IoT exploitation class, or how to break IoT, earlier this week. And so welcome. Introduce yourself, if you would, and let us know your origin story in security. How did you get into this? **1:14 Chris Romeo:** Yep, sure. So I started in security back in my university days. So I was interested in a lot of research in mobile application security and that, that is pretty much where I actually started off in security. And then I went ahead and like worked for a company called Preditiv. So there I got to learn like how corporates actually work, what is the entire SDLC cycle looks like, how to work with developers in order to fix security issues. And that actually led me starting my own company. And there we focus on like IoT pen testing, IoT training, mobile application security and all of that. So it's been like close to 5, 6 years since we have been running the company. And yeah, so now we are focusing on all IoT, which is the talk of the town these days. So pretty much everyone is talking about how insecure these devices are and all the ridiculous issues with them. **2:03 Robert Hurlbut:** Right, absolutely. So tell us about, you know, everybody has their own definition, but IoT, what is that? How do you, when you describe to somebody, what's that IoT stuff I hear about it? What do you tell people typically? **2:16 Chris Romeo:** So IoT, or the Internet of Things, is pretty much any device which can interact with the physical world around it, maybe for data collection purposes or for controlling its physical surroundings, those kind of purposes. So for a real-world example, let's say you have a light bulb at your home and you want to control it with your smartphone. So that is a really good example of how IoT is playing a major role in our day-to-day lives. **2:41 Robert Hurlbut:** Yeah, okay, very good. And so in this conference, you spoke about, or you led a class on breaking IoT, or how can you do some security with IoT. So there are some developers who are putting some things together for IoT, right? **2:57 Chris Romeo:** Yeah. **2:58 Robert Hurlbut:** They're building some applications that run on these devices that connect out through the internet or other means to other things. So tell us some of the things that are happening with developers working in IoT? Are there, yeah, some things that you may have seen in terms of things they're doing now? **3:16 Chris Romeo:** Yeah, so funny enough, like developers are making the same mistakes which they used to do like back in 2001, 2002 in web applications and in the early days of mobile applications. So it's pretty much the same mistakes like hardcoded issues, like hardcoded credentials, leaking API keys, not encryption enabled and all of that. So the same mistakes which they used to make in the early days, That is coming back all over again in the IoT world. And that is really causing a serious problem because with IoT it can go like much, much critical. So you can have like an insulin pump or a heart rate monitor. And if those things are not secured, you can even have the potential to kill a person. **3:56 Robert Hurlbut:** Sure. So why do you think that's happening? Is it just because it's so new and people are just having, oh, I'll deal with that later? **4:03 Chris Romeo:** I mean, why do you think? So one of the problems with IoT and the developers actually working on it is because IoT is like such a vast topic to like work on. So you've got like different things— hardware, embedded devices, radio communication, mobile app, web dashboard, all of that. So not a single developer can actually focus on all of those particular areas, right? So you have different teams working on different things, and if they don't coordinate properly, you'll end up having issues maybe between the communication of 2 components. Like the radio communication might not be secured in the way like the mobile application communicates with the device. So I think overall it's a lack of awareness issue. So developers don't actually know how to secure it. And also because they don't have enough resources where they can look for like, how do I actually secure this particular device? What all things do I have to look for? So maybe I have taken care of encryption of the firmware, but is my hardware actually secure? So yeah. **5:02 Aditya Gupta:** Seems like there might be an architecture problem here. And so you're describing kind of developers that are in a segmented environment where the problem is so big that they're dealing with separate pieces of the problem themselves without the bigger picture. And so, I mean, do you think that's part of the challenge here is that there's just not— like in the enterprise, we have a whole group called architects, right? And all they do is look at, okay, we're going to do all these 75 things and when they all come together, here's how we're going to ensure it's secure. Do you see that in IoT? **5:29 Chris Romeo:** Yes. So that's also one of the biggest issues in IoT. So if threat modeling and the initial planning is done correctly, that can actually help reduce a lot of security issues. But yeah, I haven't seen it implemented very well in like most of the companies I've worked with. Yeah, I haven't either. **5:48 Robert Hurlbut:** I wondered the same, that there seems like a lack of that understanding of architecture threat modeling, as you mentioned, secure design. Those are just starting to— some people talking about it, but I see more issues. In fact, that was another thing I was kind of thinking about here is what are some other issues that you're seeing? I know you mentioned the pacemaker that was recent where there was an authentication issue where anybody could get in. What are some other issues that you've seen? **6:12 Chris Romeo:** So the issues have been in pretty much like all the different components. So I have seen a lot of issues in the radio-based attacks, like a lot of medical devices, a lot of smart home devices. So they have radio-based attacks as simple as you can capture the radio packets and you can replay them back and be able to control the particular device. And then you have things like the hardware is not properly protected. So if you just open up the device, you can actually dump the firmware from it and then have a look at the entire secrets. The usual response that I've seen from developers and even like the team leads and the VP of engineering and all of that is, who is actually going to come after my particular hardware or who is going to attack maybe the Zigbee protocol that I'm using, it's so new, it is secure by default, which it is not. And yeah. **7:01 Robert Hurlbut:** Okay. **7:02 Aditya Gupta:** Okay. **7:03 Robert Hurlbut:** So in terms of, we already talked about architecture, what are some other things that developers can do that you can think of that they can, you know, make this more secure other than just some basic practices, but are there some specific things they can think about? Yep. **7:15 Chris Romeo:** So one of the things they can actually do is OWASP also has like an embedded security guide. So they can actually follow that while building embedded devices. And for the other devices, it's more about work, like, like we discussed earlier, the teams working together and in sync with all the different possible issues that there could be. So making sure that the radio communication, if you're implementing that, that is secured by yourself. So don't rely on, let's say, Zigbee is securing my entire communication, which it won't unless you ask it to do. Or make sure that your hardware is actually properly protected. There are physical protections in it rather than just having the serial communication interfaces or JTAG interfaces left wide open. **7:58 Robert Hurlbut:** Okay. So things like, for example, you mentioned ZigBee. I was looking at that recently. And so there are some things I know ZigBee is supposed to be one of the more secure ways of communication, but is— how would developers typically find those things out? I mean, are they looking for those things? How would they know that they need to do some extra steps? Beyond, I mean, asserts. **8:19 Chris Romeo:** Yeah, yeah. So that is also like one of the biggest problems because if you start looking into— so one of the things with IoT is it's so much fragmented, like everyone is coming up with their own standards, their own protocols. So you don't have like a really big security group working on a particular technology. And if you want to look for like, how do I secure this particular protocol that I'm using? So you have to dig deep into the documentation, figure out what are the different security features that they allow you to do. And also making sure that it works well with your devices because in IoT devices or even in general embedded devices, you have very, very low resource. So with low resource, you can only do a certain amount of things. You can't implement like really good encryption as such. So you have to figure out like the, what's the best balance between the security and the usability of the product. Okay. **9:10 Robert Hurlbut:** All right. So we talked about some design, we talked about some things that developers can do. What are some other things that they're having to deal with? A person that's developing an IoT application on a device, what are some other things that they need to be thinking about? **9:26 Chris Romeo:** So one of the other things is like a lot of IoT device developers come from the electronics hobbyist background. If you talk of like, let's say, the embedded device area. And what they typically do is they develop the prototype on maybe one of the development boards or one of the low-end boards and then port the entire solution to the commercial devices, get the prototype ready, and then have the actual device. So a lot of security issues which were there in the original dev board, they might think that the new board which they are using is actually protecting everything for them. So it's also a mentality thing because when you are like a hobbyist or doing it in like your free time, You just focus on the functionality that you have to implement, and if it works, it's all good for you. **10:13 Robert Hurlbut:** Yeah. **10:13 Chris Romeo:** So, okay. **10:15 Aditya Gupta:** What's the impact of the startup world? It seems like IoT, sure, some big players have large solutions in the IoT space, but from my perspective, it seems like a lot of these companies are startups. **10:29 Chris Romeo:** And what have you seen from your experience as far as how the startup side of this is either approaching security or not So yeah, so a lot of startups, like I think almost all the startups that I have worked with, so they are not approaching security that well that they should be doing because most of them are VC funded and they have gotten the money to actually put the product out in market and they don't realize that security plays a major role in that particular process and they have to get the return of investment for their investors and that's what they all focus on. Like as soon as they can get the product out to the market. **11:04 Robert Hurlbut:** Mm-hmm. **11:04 Chris Romeo:** And that is also one of the issues, like, as they grow, it kind of sticks with them. And even the next product releases will be like, will be having a strict, like, tight deadline, and that will end up creating a lot of issues with them. **11:17 Robert Hurlbut:** And so also with IoT, I know several times I've seen this where, you know, once it's out there and if they haven't thought through security initially, it's deployed into a device, it's harder to update, right? **11:29 Chris Romeo:** Yeah. **11:30 Robert Hurlbut:** So that's an issue as well. **11:31 Chris Romeo:** Yeah, that's another issue, like, for Yeah, for IoT devices, if you talk of like any, any sort of IoT devices, smart homes or thermostats, all of that, it's so tough to actually upgrade the firmware for a non-technical user. So that also creates a lot of new security issues because if you have like existing threats out in the wild for a particular version and the users don't actually know how to upgrade the firmware, then they are at risk. So yeah, so that is also one of the things that comes in the design process, like how much flexibility do we have to give to the users in order to have them control the, maybe the firmware upgrades or change the default creds on the device or those sort of things. **12:13 Robert Hurlbut:** Okay, okay. **12:14 Aditya Gupta:** So when you say this is an awareness problem, do you mean that the IoT developers just, they don't have any awareness of security in general? **12:23 Chris Romeo:** Is that what's been your experience as you're talking to these different So most of the teams I have talked to, Sudhadeep, they don't have any good security knowledge of the products that they are working on. So let's say even if you talk of, yeah, web and mobile is like pretty mature, they have a lot of resources. But if you talk of embedded radio, they don't have a lot of resources to look up to. And what they think is that the protocol or the technology they are using is actually doing all the work for them, which is not the case in pretty much everything. **12:56 Robert Hurlbut:** Yeah. **12:56 Chris Romeo:** Yeah, so it's at the end, it's all about awareness because if they actually know how to secure these issues or what kind of issues actually exist in these platforms, then they can look for those solutions, but they don't. They are not just aware of the questions. Yeah. **13:11 Aditya Gupta:** What's the craziest thing you've experienced here in testing IoT? And I understand you might have to protect the innocent by not saying who they are or anything, and that's cool too. But, you know, what is your craziest Craziest story. **13:26 Chris Romeo:** So it was one of the infrastructure pen tests that we were doing, and it involved like pretty much all the devices in the network— printers, uh, the automation devices, all of that. And we ended up, end up getting into their Wi-Fi by hacking a coffee machine. So the coffee machine was leaking the Wi-Fi credentials over Bluetooth, and if you just go near the coffee machine, sniff the traffic using Ubertooth One or something So you would be able to get the Wi-Fi credentials, connect to the network, and then— **13:55 Robert Hurlbut:** So the coffee machine that could automatically fix them a cup of coffee in the morning was able to also allow you to get into the network and do it. **14:04 Chris Romeo:** Yes. **14:04 Aditya Gupta:** I would not want to be the chief information security officer that's standing before the board and says, yeah, we did a penetration test and we got hacked, you know, as we were supposed to or as they were testing trying to do by our coffee machine. You go, you're just gone, you know, you're done. **14:21 Robert Hurlbut:** Wow. **14:22 Aditya Gupta:** Okay, so that's an interesting kind of use case. And, you know, from my perspective in IoT, we're putting IP network stacks on so many things that, like, why do we really need a coffee machine that's Wi-Fi enabled? Like, do we need that? Or, like, you know, what is our motivation here? **14:43 Chris Romeo:** So we don't actually need those devices as such, but it just makes our life simpler. if you look at the usability perspective, but it also introduces a lot of security issues. So that's the thing. Right. **14:55 Aditya Gupta:** Wow. **14:55 Robert Hurlbut:** Yeah. **14:56 Aditya Gupta:** So do you have certain types of products that you primarily test? Are you testing in kind of the consumer space or, you know, are you transitioning? Are you doing things in the automobile space from IoT or what's the kind of range of industries that you're working with? **15:11 Chris Romeo:** So most of the devices that we have tests are catered toward like the consumer-oriented devices like smart home devices, wearables, a bit of medical devices. We have done a couple of automotive and infotainment system pen tests. But yeah, I think the consumer industry is way more insecure compared to like the automotive or, yeah, automotive industry. **15:35 Aditya Gupta:** So based on the results of all those pen tests, if you could only do one thing, if you could say, you know what, I can just wave my hand and this one thing will be eradicated from the IoT The whole world of IoT, as far as a security problem, what would be the one thing that you would say? **15:52 Chris Romeo:** So the one thing that would actually reduce a lot of security issues would be hardware protections. **15:57 Aditya Gupta:** Okay, so what do you mean by hardware protection? **16:00 Chris Romeo:** So by hardware protection, you mean like if an attacker actually opens up the device, he's not able to access the serial interfaces, he's not able to dump the firmware, and so on. **16:10 Robert Hurlbut:** Sorry, yeah, I remember. **16:13 Chris Romeo:** So a lot of devices, like even extremely critical devices, as soon as you open them up, you look at the chips, and just by looking at the chip numbers, you can connect to them and dump the firmware. **16:22 Aditya Gupta:** Right. So what's the solution to that? Like, how does an IoT hardware provider mitigate that challenge? **16:29 Chris Romeo:** So there could be like a number of solutions. One could be— one of the solutions that I have seen is just by kind of scratching off the surface so that no one can actually read the chip number. That would make it like super difficult to get the pinouts and then connect to that. And the other solution is to have like all sort of hardware epoxy and all of that on top of it so that no one can actually connect to it. And they thought, yeah. **16:54 Aditya Gupta:** So if we think about like, like a modern manufacturer, I don't, I don't care who it is, but a modern manufacturer that makes television sets, for example, do they go to that level of of like doing epoxy and things like that to disguise because nobody's attacking the hardware. But even though, I mean, our TVs are connected, like, I mean, you can buy it. I don't have a Wi-Fi connected TV, but you can buy one that has Wi-Fi. **17:18 Robert Hurlbut:** Voice activated and all those things. **17:20 Aditya Gupta:** So why does IoT need these hardware protections whereas the rest of the industry hasn't really adopted them for other consumer products? **17:30 Chris Romeo:** Right, so with IoT, the hardware protection is— so the hardware in IoT is typically a way for you to get access to the other components. It provides you a lot of intelligence for all the other components. So how does the device interact with other devices? And all these secrets you can actually get from the firmware, or how 2 different chips are interacting with each other. So if you could just tap into or sniff those particular signals, you get to see what kind of data is transferred between maybe like 2 different chips. So an attacker won't actually go ahead and attack the physical device in like every home, right? like using the physical techniques. But if he has one of those devices, he can use the physical techniques to actually get a lot more information to perform like radio-based attacks or even web-based attacks and all of that. **18:16 Aditya Gupta:** So you buy one. IoT devices are so cheap that anybody who wants to attack them, you can buy one for $50, $100, whatever, and then tear it apart. **18:26 Chris Romeo:** Yep. **18:26 Aditya Gupta:** And craft your attack based on what you learn, and then you can then put an attack out that goes after everybody. **18:32 Chris Romeo:** Exactly. **18:33 Aditya Gupta:** Like the cam— like, I mean, did you have Do you have any— have you kind of looked closely at the camera, the Chinese manufacturer of the camera? **18:42 Chris Romeo:** Yeah. **18:42 Aditya Gupta:** I mean, that's an IoT device in the end. I mean, what are your thoughts on kind of that type of a situation? What do you see as the challenges that happen there? **18:49 Chris Romeo:** So cameras and baby monitors, a lot of those devices actually come from China. And you'd see them with all the different products in the US market and they would be having like the same security issues. So maybe a particular version of custom HTTP server which has like this exact same issues in all the different products. So yeah. **19:09 Aditya Gupta:** Okay, so that's something else you have to be thinking about is not only the quality of the software itself, but where are the components coming from. You may have untrusted components that get, to save money, be spread across a number of different products. **19:26 Chris Romeo:** Right, so you have to look at the entire supply chain rather than the end device that you have with you. **19:31 Robert Hurlbut:** Right, so different points in the supply chain could could add something in that could make sense. **19:35 Chris Romeo:** And yeah, even with the latest hacks that we have seen, not only concerning with IoT, we have seen a lot of hacks around like there's a particular component developed by another company and that has led to the compromise of the entire solution. **19:49 Aditya Gupta:** Now, do you have any IoT devices on your home network? **19:52 Chris Romeo:** Yes, I have, but it's like on a separate network. **19:55 Aditya Gupta:** Segmented to protect the normal function of the home network. **20:00 Chris Romeo:** I used to have like a Philips But then there were like so many security issues. **20:05 Robert Hurlbut:** Well, that's a good point, putting it on a separate network. Yeah, all those things separate from your main network. That's a very good idea. **20:12 Aditya Gupta:** Yeah, I mean, you think about the average consumer though, you know, we can do that. That makes sense to us because we live and breathe and we just love security. But, you know, my mom's not going to have a segmented network for devices. So, I mean, I think that's the call to action. I think that's what you're trying to point out here to the industry. industry is that the average consumer is not going to be able to do the things that we can do to secure these devices. The devices have to secure themselves. They have to be as strong as they possibly can be and protect the data of the people who are buying this stuff. **20:45 Robert Hurlbut:** Right. **20:46 Chris Romeo:** Yep. Right. **20:48 Robert Hurlbut:** Well, you know, just as we kind of wrap up, are there some good resources that for developers, architects, others that want to know more about IoT security and want to do this right. So some good resources? **21:00 Chris Romeo:** So yeah, so there are a couple of resources if anyone is interested in IoT security. So most of them are blogs. So one is a blog run by Craig Hefner, which is called devtty0.com. The other is one that I put together, iotpentestingguide.com. And I also recently wrote a book on IoT hacking, which is called IoT Hacker's Handbook. And then you also have the OWASP projects on embedded device security and the firmware security. security and all of that. So yeah, that's also like, there are so less resources in IoT as of now. So you have to make sure that whatever the resources you have, like all the information to you and whatever you are interested in, dig deep into it by yourself because the IoT security industry is not yet that mature. **21:46 Robert Hurlbut:** I was wondering, are there— there are probably not very many standards at the moment in terms of trying to make sure that, okay, this is what it's called a secure IoT implementation, not really there yet. **21:57 Chris Romeo:** So you have to figure out a solution that works best for you based on all the resources that you find. **22:02 Aditya Gupta:** Isn't there an IoT Top 10? **22:06 Chris Romeo:** Yes, from OWASP. Yeah, there is an IoT Top 10 as well. **22:09 Aditya Gupta:** Is that updated and is that a good reference or resource for people? It seems like when I looked at it, it was like 2013, '14, like it might be a little bit dated because IoT is moving even faster than the rest of the technology world. So I mean, what are your thoughts on that? Do you use the IoT Top 10 or recommend it to clients? **22:27 Chris Romeo:** Yeah, so the IoT Top 10 is, uh, yeah, also something I recommend to the clients. So the new version is still in the draft mode. So yeah, it is a good starting point maybe to figure out like what are the different categories of security issues, but as of now it doesn't dig deep into like what are the specific security issues and let's say privacy-based issues or firmware-based issues. So it gives you like good starting points but, uh, leaves you over there as of today. Like, so you need to just make sure that if you're looking for firmware security, which you may get familiar with from the OWASP Top 10, then you have to look for all the possible resources online on what are the different— what are the best ways to do firmware security. But yeah, it's a good start. Okay, yeah, okay, great. **23:13 Robert Hurlbut:** Well, Aditya, thank you for joining us today. We appreciate the opportunity to speak with you, and we've learned a lot here about IoT security. security and some things we need to be watching for, and our listeners if they're moving along this path. But again, thank you. **23:26 Chris Romeo:** Appreciate it. Yeah, thanks a lot, Robert and Chris. Yeah, it was a pleasure. Thanks for listening to the Application Security Podcast. If you enjoy the podcast, please do us a favor and visit the iTunes Store and give us a 5-star rating. Our intro music is 8-Bit Kung Fu by Born and TJ, and the outro is Southern Delight by Stefan Cartenberg. You can find us on Twitter @AppSecPodcast or on the web at www.appsecpodcast.org. --- Source: https://appsecpodcast.com/aditya-gupta-the-exploitation-of-iot/