Skip to content
AppSec PodcastThe Application Security Podcast — home
24 min

Aditya Gupta -- The Exploitation of IoT

With Aditya Gupta

Vulnerabilities and Exploits

Why can an IoT product look secure in one component and still fail as a complete system? Aditya Gupta, founder of Attify, joins Chris and Robert at AppSec USA to examine the gaps between hardware, firmware, radio communications, mobile applications, and web dashboards.

Listen

Audio hosted by Buzzsprout. Nothing loads until you press play.

Episode chapters · 12 chapters
  1. 00:00The exploitation of IoT with Aditya GuptaAudio
  2. 00:46Aditya’s path from mobile security to IoTAudio
  3. 02:03Defining the Internet of ThingsAudio
  4. 02:58Where IoT development goes wrongAudio
  5. 04:03Security gaps between components and teamsAudio

About this episode

Why can an IoT product look secure in one component and still fail as a complete system? Aditya Gupta, founder of Attify, joins Chris and Robert at AppSec USA to examine the gaps between hardware, firmware, radio communications, mobile applications, and web dashboards. He explains how fragmented development teams and unfamiliar protocols create security blind spots, and why authentication and secure design need attention before devices ship. The conversation covers resource constraints, firmware updates, physical access, and the way extracting information from one device can enable attacks against many others. Aditya also discusses practical learning resources and encourages developers to understand their entire product architecture rather than assuming that securing individual pieces will secure the whole.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with Aditya Gupta:
Aditya Gupta and Attify

Resources
Attify
OWASP IoT Top 10

Actionable

From this conversation

  1. Coordinate security across every IoT component

    You've got like different things— hardware, embedded devices, radio communication, mobile app, web dashboard, all of that. So not a single developer can focus on all of those particular areas, right? So you have different teams working on different things, and if they don't coordinate properly, you'll end up having issues between the communication of 2 components.

    4:03
  2. Threat-model IoT systems during initial planning

    If threat modeling and the initial planning is done correctly, that can help reduce a lot of security issues.

    5:29
  3. Follow OWASP guidance for embedded-device security

    OWASP has like an embedded security guide. So they can follow that while building embedded devices.

    7:15
  4. Review each protocol's security capabilities

    You have to dig deep into the documentation, figure out what are the different security features that they allow you to do.

    8:19
  5. Design for secure firmware updates and credential changes

    That is one of the things that comes in the design process, like how much flexibility do we have to give to the users in order to have them control the, the firmware upgrades or change the default creds on the device or those things.

    11:31
Transcript · 24 min conversation

0:05Aditya GuptaThe Application Security Podcast. Here we go.

0:09Chris RomeoHey folks, on this week's episode of the Application Security Podcast, Robert and Chris speak with Aditya at AppSecUSA. They talked to him about IoT and the many facets including pen testing, training, and mobile application security. As always, thanks for listening and enjoy.

0:46Robert HurlbutWell, hello friends, we're here at AppSecUSA, Chris and I, this week. And today we are going to be talking with Aditya, if I said it correctly. And he is— he actually did an IoT exploitation class, or how to break IoT, earlier this week. And so welcome. Introduce yourself, if you would, and let us know your origin story in security. How did you get into this?

1:14Chris RomeoYep, sure. So I started in security back in my university days. So I was interested in a lot of research in mobile application security and that, that is pretty much where I actually started off in security. And then I went ahead and like worked for a company called Preditiv. So there I got to learn like how corporates actually work, what is the entire SDLC cycle looks like, how to work with developers in order to fix security issues. And that actually led me starting my own company. And there we focus on like IoT pen testing, IoT training, mobile application security and all of that. So it's been like close to 5, 6 years since we have been running the company. And yeah, so now we are focusing on all IoT, which is the talk of the town these days. So pretty much everyone is talking about how insecure these devices are and all the ridiculous issues with them.

2:03Robert HurlbutRight, absolutely. So tell us about, you know, everybody has their own definition, but IoT, what is that? How do you, when you describe to somebody, what's that IoT stuff I hear about it? What do you tell people typically?

2:16Chris RomeoSo IoT, or the Internet of Things, is pretty much any device which can interact with the physical world around it, maybe for data collection purposes or for controlling its physical surroundings, those kind of purposes. So for a real-world example, let's say you have a light bulb at your home and you want to control it with your smartphone. So that is a really good example of how IoT is playing a major role in our day-to-day lives.

2:41Robert HurlbutYeah, okay, very good. And so in this conference, you spoke about, or you led a class on breaking IoT, or how can you do some security with IoT. So there are some developers who are putting some things together for IoT, right?

2:57Chris RomeoYeah.

2:58Robert HurlbutThey're building some applications that run on these devices that connect out through the internet or other means to other things. So tell us some of the things that are happening with developers working in IoT? Are there, yeah, some things that you may have seen in terms of things they're doing now?

3:16Chris RomeoYeah, so funny enough, like developers are making the same mistakes which they used to do like back in 2001, 2002 in web applications and in the early days of mobile applications. So it's pretty much the same mistakes like hardcoded issues, like hardcoded credentials, leaking API keys, not encryption enabled and all of that. So the same mistakes which they used to make in the early days, That is coming back all over again in the IoT world. And that is really causing a serious problem because with IoT it can go like much, much critical. So you can have like an insulin pump or a heart rate monitor. And if those things are not secured, you can even have the potential to kill a person.

3:56Robert HurlbutSure. So why do you think that's happening? Is it just because it's so new and people are just having, oh, I'll deal with that later?

4:03Chris RomeoI mean, why do you think? So one of the problems with IoT and the developers actually working on it is because IoT is like such a vast topic to like work on. So you've got like different things— hardware, embedded devices, radio communication, mobile app, web dashboard, all of that. So not a single developer can actually focus on all of those particular areas, right? So you have different teams working on different things, and if they don't coordinate properly, you'll end up having issues maybe between the communication of 2 components. Like the radio communication might not be secured in the way like the mobile application communicates with the device. So I think overall it's a lack of awareness issue. So developers don't actually know how to secure it. And also because they don't have enough resources where they can look for like, how do I actually secure this particular device? What all things do I have to look for? So maybe I have taken care of encryption of the firmware, but is my hardware actually secure? So yeah.

5:02Aditya GuptaSeems like there might be an architecture problem here. And so you're describing kind of developers that are in a segmented environment where the problem is so big that they're dealing with separate pieces of the problem themselves without the bigger picture. And so, I mean, do you think that's part of the challenge here is that there's just not— like in the enterprise, we have a whole group called architects, right? And all they do is look at, okay, we're going to do all these 75 things and when they all come together, here's how we're going to ensure it's secure. Do you see that in IoT?

5:29Chris RomeoYes. So that's also one of the biggest issues in IoT. So if threat modeling and the initial planning is done correctly, that can actually help reduce a lot of security issues. But yeah, I haven't seen it implemented very well in like most of the companies I've worked with. Yeah, I haven't either.

5:48Robert HurlbutI wondered the same, that there seems like a lack of that understanding of architecture threat modeling, as you mentioned, secure design. Those are just starting to— some people talking about it, but I see more issues. In fact, that was another thing I was kind of thinking about here is what are some other issues that you're seeing? I know you mentioned the pacemaker that was recent where there was an authentication issue where anybody could get in. What are some other issues that you've seen?

6:12Chris RomeoSo the issues have been in pretty much like all the different components. So I have seen a lot of issues in the radio-based attacks, like a lot of medical devices, a lot of smart home devices. So they have radio-based attacks as simple as you can capture the radio packets and you can replay them back and be able to control the particular device. And then you have things like the hardware is not properly protected. So if you just open up the device, you can actually dump the firmware from it and then have a look at the entire secrets. The usual response that I've seen from developers and even like the team leads and the VP of engineering and all of that is, who is actually going to come after my particular hardware or who is going to attack maybe the Zigbee protocol that I'm using, it's so new, it is secure by default, which it is not. And yeah.

7:01Robert HurlbutOkay.

7:02Aditya GuptaOkay.

7:03Robert HurlbutSo in terms of, we already talked about architecture, what are some other things that developers can do that you can think of that they can, you know, make this more secure other than just some basic practices, but are there some specific things they can think about? Yep.

7:15Chris RomeoSo one of the things they can actually do is OWASP also has like an embedded security guide. So they can actually follow that while building embedded devices. And for the other devices, it's more about work, like, like we discussed earlier, the teams working together and in sync with all the different possible issues that there could be. So making sure that the radio communication, if you're implementing that, that is secured by yourself. So don't rely on, let's say, Zigbee is securing my entire communication, which it won't unless you ask it to do. Or make sure that your hardware is actually properly protected. There are physical protections in it rather than just having the serial communication interfaces or JTAG interfaces left wide open.

7:58Robert HurlbutOkay. So things like, for example, you mentioned ZigBee. I was looking at that recently. And so there are some things I know ZigBee is supposed to be one of the more secure ways of communication, but is— how would developers typically find those things out? I mean, are they looking for those things? How would they know that they need to do some extra steps? Beyond, I mean, asserts.

8:19Chris RomeoYeah, yeah. So that is also like one of the biggest problems because if you start looking into— so one of the things with IoT is it's so much fragmented, like everyone is coming up with their own standards, their own protocols. So you don't have like a really big security group working on a particular technology. And if you want to look for like, how do I secure this particular protocol that I'm using? So you have to dig deep into the documentation, figure out what are the different security features that they allow you to do. And also making sure that it works well with your devices because in IoT devices or even in general embedded devices, you have very, very low resource. So with low resource, you can only do a certain amount of things. You can't implement like really good encryption as such. So you have to figure out like the, what's the best balance between the security and the usability of the product. Okay.

9:10Robert HurlbutAll right. So we talked about some design, we talked about some things that developers can do. What are some other things that they're having to deal with? A person that's developing an IoT application on a device, what are some other things that they need to be thinking about?

9:26Chris RomeoSo one of the other things is like a lot of IoT device developers come from the electronics hobbyist background. If you talk of like, let's say, the embedded device area. And what they typically do is they develop the prototype on maybe one of the development boards or one of the low-end boards and then port the entire solution to the commercial devices, get the prototype ready, and then have the actual device. So a lot of security issues which were there in the original dev board, they might think that the new board which they are using is actually protecting everything for them. So it's also a mentality thing because when you are like a hobbyist or doing it in like your free time, You just focus on the functionality that you have to implement, and if it works, it's all good for you.

10:13Robert HurlbutYeah.

10:13Chris RomeoSo, okay.

10:15Aditya GuptaWhat's the impact of the startup world? It seems like IoT, sure, some big players have large solutions in the IoT space, but from my perspective, it seems like a lot of these companies are startups.

10:29Chris RomeoAnd what have you seen from your experience as far as how the startup side of this is either approaching security or not So yeah, so a lot of startups, like I think almost all the startups that I have worked with, so they are not approaching security that well that they should be doing because most of them are VC funded and they have gotten the money to actually put the product out in market and they don't realize that security plays a major role in that particular process and they have to get the return of investment for their investors and that's what they all focus on. Like as soon as they can get the product out to the market.

11:04Robert HurlbutMm-hmm.

11:04Chris RomeoAnd that is also one of the issues, like, as they grow, it kind of sticks with them. And even the next product releases will be like, will be having a strict, like, tight deadline, and that will end up creating a lot of issues with them.

11:17Robert HurlbutAnd so also with IoT, I know several times I've seen this where, you know, once it's out there and if they haven't thought through security initially, it's deployed into a device, it's harder to update, right?

11:29Chris RomeoYeah.

11:30Robert HurlbutSo that's an issue as well.

11:31Chris RomeoYeah, that's another issue, like, for Yeah, for IoT devices, if you talk of like any, any sort of IoT devices, smart homes or thermostats, all of that, it's so tough to actually upgrade the firmware for a non-technical user. So that also creates a lot of new security issues because if you have like existing threats out in the wild for a particular version and the users don't actually know how to upgrade the firmware, then they are at risk. So yeah, so that is also one of the things that comes in the design process, like how much flexibility do we have to give to the users in order to have them control the, maybe the firmware upgrades or change the default creds on the device or those sort of things.

12:13Robert HurlbutOkay, okay.

12:14Aditya GuptaSo when you say this is an awareness problem, do you mean that the IoT developers just, they don't have any awareness of security in general?

12:23Chris RomeoIs that what's been your experience as you're talking to these different So most of the teams I have talked to, Sudhadeep, they don't have any good security knowledge of the products that they are working on. So let's say even if you talk of, yeah, web and mobile is like pretty mature, they have a lot of resources. But if you talk of embedded radio, they don't have a lot of resources to look up to. And what they think is that the protocol or the technology they are using is actually doing all the work for them, which is not the case in pretty much everything.

12:56Robert HurlbutYeah.

12:56Chris RomeoYeah, so it's at the end, it's all about awareness because if they actually know how to secure these issues or what kind of issues actually exist in these platforms, then they can look for those solutions, but they don't. They are not just aware of the questions. Yeah.

13:11Aditya GuptaWhat's the craziest thing you've experienced here in testing IoT? And I understand you might have to protect the innocent by not saying who they are or anything, and that's cool too. But, you know, what is your craziest Craziest story.

13:26Chris RomeoSo it was one of the infrastructure pen tests that we were doing, and it involved like pretty much all the devices in the network— printers, uh, the automation devices, all of that. And we ended up, end up getting into their Wi-Fi by hacking a coffee machine. So the coffee machine was leaking the Wi-Fi credentials over Bluetooth, and if you just go near the coffee machine, sniff the traffic using Ubertooth One or something So you would be able to get the Wi-Fi credentials, connect to the network, and then—

13:55Robert HurlbutSo the coffee machine that could automatically fix them a cup of coffee in the morning was able to also allow you to get into the network and do it.

14:04Chris RomeoYes.

14:04Aditya GuptaI would not want to be the chief information security officer that's standing before the board and says, yeah, we did a penetration test and we got hacked, you know, as we were supposed to or as they were testing trying to do by our coffee machine. You go, you're just gone, you know, you're done.

14:21Robert HurlbutWow.

14:22Aditya GuptaOkay, so that's an interesting kind of use case. And, you know, from my perspective in IoT, we're putting IP network stacks on so many things that, like, why do we really need a coffee machine that's Wi-Fi enabled? Like, do we need that? Or, like, you know, what is our motivation here?

14:43Chris RomeoSo we don't actually need those devices as such, but it just makes our life simpler. if you look at the usability perspective, but it also introduces a lot of security issues. So that's the thing. Right.

14:55Aditya GuptaWow.

14:55Robert HurlbutYeah.

14:56Aditya GuptaSo do you have certain types of products that you primarily test? Are you testing in kind of the consumer space or, you know, are you transitioning? Are you doing things in the automobile space from IoT or what's the kind of range of industries that you're working with?

15:11Chris RomeoSo most of the devices that we have tests are catered toward like the consumer-oriented devices like smart home devices, wearables, a bit of medical devices. We have done a couple of automotive and infotainment system pen tests. But yeah, I think the consumer industry is way more insecure compared to like the automotive or, yeah, automotive industry.

15:35Aditya GuptaSo based on the results of all those pen tests, if you could only do one thing, if you could say, you know what, I can just wave my hand and this one thing will be eradicated from the IoT The whole world of IoT, as far as a security problem, what would be the one thing that you would say?

15:52Chris RomeoSo the one thing that would actually reduce a lot of security issues would be hardware protections.

15:57Aditya GuptaOkay, so what do you mean by hardware protection?

16:00Chris RomeoSo by hardware protection, you mean like if an attacker actually opens up the device, he's not able to access the serial interfaces, he's not able to dump the firmware, and so on.

16:10Robert HurlbutSorry, yeah, I remember.

16:13Chris RomeoSo a lot of devices, like even extremely critical devices, as soon as you open them up, you look at the chips, and just by looking at the chip numbers, you can connect to them and dump the firmware.

16:22Aditya GuptaRight. So what's the solution to that? Like, how does an IoT hardware provider mitigate that challenge?

16:29Chris RomeoSo there could be like a number of solutions. One could be— one of the solutions that I have seen is just by kind of scratching off the surface so that no one can actually read the chip number. That would make it like super difficult to get the pinouts and then connect to that. And the other solution is to have like all sort of hardware epoxy and all of that on top of it so that no one can actually connect to it. And they thought, yeah.

16:54Aditya GuptaSo if we think about like, like a modern manufacturer, I don't, I don't care who it is, but a modern manufacturer that makes television sets, for example, do they go to that level of of like doing epoxy and things like that to disguise because nobody's attacking the hardware. But even though, I mean, our TVs are connected, like, I mean, you can buy it. I don't have a Wi-Fi connected TV, but you can buy one that has Wi-Fi.

17:18Robert HurlbutVoice activated and all those things.

17:20Aditya GuptaSo why does IoT need these hardware protections whereas the rest of the industry hasn't really adopted them for other consumer products?

17:30Chris RomeoRight, so with IoT, the hardware protection is— so the hardware in IoT is typically a way for you to get access to the other components. It provides you a lot of intelligence for all the other components. So how does the device interact with other devices? And all these secrets you can actually get from the firmware, or how 2 different chips are interacting with each other. So if you could just tap into or sniff those particular signals, you get to see what kind of data is transferred between maybe like 2 different chips. So an attacker won't actually go ahead and attack the physical device in like every home, right? like using the physical techniques. But if he has one of those devices, he can use the physical techniques to actually get a lot more information to perform like radio-based attacks or even web-based attacks and all of that.

18:16Aditya GuptaSo you buy one. IoT devices are so cheap that anybody who wants to attack them, you can buy one for $50, $100, whatever, and then tear it apart.

18:26Chris RomeoYep.

18:26Aditya GuptaAnd craft your attack based on what you learn, and then you can then put an attack out that goes after everybody.

18:32Chris RomeoExactly.

18:33Aditya GuptaLike the cam— like, I mean, did you have Do you have any— have you kind of looked closely at the camera, the Chinese manufacturer of the camera?

18:42Chris RomeoYeah.

18:42Aditya GuptaI mean, that's an IoT device in the end. I mean, what are your thoughts on kind of that type of a situation? What do you see as the challenges that happen there?

18:49Chris RomeoSo cameras and baby monitors, a lot of those devices actually come from China. And you'd see them with all the different products in the US market and they would be having like the same security issues. So maybe a particular version of custom HTTP server which has like this exact same issues in all the different products. So yeah.

19:09Aditya GuptaOkay, so that's something else you have to be thinking about is not only the quality of the software itself, but where are the components coming from. You may have untrusted components that get, to save money, be spread across a number of different products.

19:26Chris RomeoRight, so you have to look at the entire supply chain rather than the end device that you have with you.

19:31Robert HurlbutRight, so different points in the supply chain could could add something in that could make sense.

19:35Chris RomeoAnd yeah, even with the latest hacks that we have seen, not only concerning with IoT, we have seen a lot of hacks around like there's a particular component developed by another company and that has led to the compromise of the entire solution.

19:49Aditya GuptaNow, do you have any IoT devices on your home network?

19:52Chris RomeoYes, I have, but it's like on a separate network.

19:55Aditya GuptaSegmented to protect the normal function of the home network.

20:00Chris RomeoI used to have like a Philips But then there were like so many security issues.

20:05Robert HurlbutWell, that's a good point, putting it on a separate network. Yeah, all those things separate from your main network. That's a very good idea.

20:12Aditya GuptaYeah, I mean, you think about the average consumer though, you know, we can do that. That makes sense to us because we live and breathe and we just love security. But, you know, my mom's not going to have a segmented network for devices. So, I mean, I think that's the call to action. I think that's what you're trying to point out here to the industry. industry is that the average consumer is not going to be able to do the things that we can do to secure these devices. The devices have to secure themselves. They have to be as strong as they possibly can be and protect the data of the people who are buying this stuff.

20:45Robert HurlbutRight.

20:46Chris RomeoYep. Right.

20:48Robert HurlbutWell, you know, just as we kind of wrap up, are there some good resources that for developers, architects, others that want to know more about IoT security and want to do this right. So some good resources?

21:00Chris RomeoSo yeah, so there are a couple of resources if anyone is interested in IoT security. So most of them are blogs. So one is a blog run by Craig Hefner, which is called devtty0.com. The other is one that I put together, iotpentestingguide.com. And I also recently wrote a book on IoT hacking, which is called IoT Hacker's Handbook. And then you also have the OWASP projects on embedded device security and the firmware security. security and all of that. So yeah, that's also like, there are so less resources in IoT as of now. So you have to make sure that whatever the resources you have, like all the information to you and whatever you are interested in, dig deep into it by yourself because the IoT security industry is not yet that mature.

21:46Robert HurlbutI was wondering, are there— there are probably not very many standards at the moment in terms of trying to make sure that, okay, this is what it's called a secure IoT implementation, not really there yet.

21:57Chris RomeoSo you have to figure out a solution that works best for you based on all the resources that you find.

22:02Aditya GuptaIsn't there an IoT Top 10?

22:06Chris RomeoYes, from OWASP. Yeah, there is an IoT Top 10 as well.

22:09Aditya GuptaIs that updated and is that a good reference or resource for people? It seems like when I looked at it, it was like 2013, '14, like it might be a little bit dated because IoT is moving even faster than the rest of the technology world. So I mean, what are your thoughts on that? Do you use the IoT Top 10 or recommend it to clients?

22:27Chris RomeoYeah, so the IoT Top 10 is, uh, yeah, also something I recommend to the clients. So the new version is still in the draft mode. So yeah, it is a good starting point maybe to figure out like what are the different categories of security issues, but as of now it doesn't dig deep into like what are the specific security issues and let's say privacy-based issues or firmware-based issues. So it gives you like good starting points but, uh, leaves you over there as of today. Like, so you need to just make sure that if you're looking for firmware security, which you may get familiar with from the OWASP Top 10, then you have to look for all the possible resources online on what are the different— what are the best ways to do firmware security. But yeah, it's a good start. Okay, yeah, okay, great.

23:13Robert HurlbutWell, Aditya, thank you for joining us today. We appreciate the opportunity to speak with you, and we've learned a lot here about IoT security. security and some things we need to be watching for, and our listeners if they're moving along this path. But again, thank you.

23:26Chris RomeoAppreciate it. Yeah, thanks a lot, Robert and Chris. Yeah, it was a pleasure. Thanks for listening to the Application Security Podcast. If you enjoy the podcast, please do us a favor and visit the iTunes Store and give us a 5-star rating. Our intro music is 8-Bit Kung Fu by Born and TJ, and the outro is Southern Delight by Stefan Cartenberg. You can find us on Twitter @AppSecPodcast or on the web at www.appsecpodcast.org.

4,466 words · transcript by assemblyai

More on Vulnerabilities and Exploits

View all episodes →

Get Reasonable AppSec: new episodes and useful picks from the archive.