Skip to content
AppSec PodcastThe Application Security Podcast — home
45 min

Daniel Miessler -- OWASP IoT Top 10

With Daniel Miessler

OWASP Top 10

An IoT product’s attack surface extends well beyond the device in the box. Daniel Miessler explains that broader view while walking Chris and Robert through the 2018 OWASP IoT Top 10.

Listen

Audio hosted by Buzzsprout. Nothing loads until you press play.

Episode chapters · 15 chapters
  1. 00:00The 2018 IoT Top 10 with Daniel MiesslerAudio
  2. 01:27Daniel’s security origin storyAudio
  3. 04:25Why the IoT Top 10 existsAudio
  4. 07:30Manufacturers, developers, and other audiencesAudio
  5. 11:56Gathering data and deciding the rankingsAudio

About this episode

An IoT product’s attack surface extends well beyond the device in the box. Daniel Miessler explains that broader view while walking Chris and Robert through the 2018 OWASP IoT Top 10. Before reviewing the risks, he describes the project’s audience, how the team gathered and evaluated data, and the challenge of balancing recurring failures with emerging concerns. The list covers passwords, exposed services, ecosystem interfaces, updates, components, privacy, data protection, device management, defaults, and physical hardening. Real testing examples show how a secure-looking connection can hide other unprotected paths or services. Daniel closes with guidance for developers who want to understand their product’s full ecosystem and use the list as a starting point for better security decisions.

The Application Security Podcast is brought to you by Security Journey.

About Security Journey
Security Journey provides application security education for developers and everyone in the software development lifecycle.
Learn more about Security Journey

Connect with Daniel Miessler:
Daniel Miessler
OWASP Internet of Things project

Resources
OWASP Application Security Verification Standard
OWASP Proactive Controls
National Vulnerability Database
Cloud Security Alliance

Actionable

From this conversation

  1. Avoid known IoT security failures

    It's 10 things that you should avoid doing.

    6:42
  2. Create manufacturer-focused guidance

    But I do feel like manufacturers need a different project because I'm looking to launch a number of projects around this, but they will be independent rather than making this one larger.

    8:57
  3. Review broad IoT vulnerability sources

    It's in the OWASP IoT security channel, so people show up, they give feedback, but there was a core of about 10 people and we would go through all that data and we would then use our judgment, right?

    16:47
Transcript · 45 min conversation

0:00Chris RomeoHey folks, season 4, episode 22 of the AppSec Podcast. On this episode, we're joined by Daniel Miessler, who walks us through the IoT top 10 list from OWASP. They did a new release here for 2018, and we explore what is the project, how they gathered the data and made the choices, and then we walk through each of the items on the list from top to bottom. We hope you enjoy. The Application Security Podcast. Here we go. Hey folks, welcome to this episode of the Application Security Podcast. On this episode, Robert and I are joined by Daniel Miessler, who has some exciting news to share with us about a project at OWASP that's focused on Internet of Things. Daniel, for our listeners' sake, we always start with what's your security origin story before we can even get into all the cool things in the world of IoT. Our listeners have to know, how did you get started in security?

1:27Daniel MiesslerSo first, thanks for having me. Really appreciate it. I think it really started with the military, actually. I went into the military immediately after high school so I could escape my hometown. And I was infantry, actually, airborne infantry, but I also spent some time in the intelligence group over there. And just was really drawn to all the security stuff, all the good guy, bad guy type stuff. And from there, I went to university in South Georgia where the girl that I was with and still with was in college. And from there, I went into basically a general security engineer career, which was IDS, IPS, network security, that kind of stuff. From there, I went into pen testing at the next company and did a lot of breaking, and then went into AppSec and also doing pen testing. Then I went and led a practice at HP. Then I went to IOActive, and now I'm doing a different sort of adventure. But it basically started off as a generalist with a focus around NetSec, then went to AppSec. And then all through there, I was basically consulting. After my first couple positions, I was basically alternating back and forth between consulting positions and internal positions. Okay.

3:15Chris RomeoAnd so you've been involved with OWASP for a while too, right?

3:18Daniel MiesslerMm-hmm.

3:20Chris RomeoSo what's kind of your OWASP origin story? Have you been part of any particular chapters or other projects as well on top of the IoT stuff?

3:29Daniel MiesslerYeah, actually, I don't know, it's probably, I want to say maybe 8 years or so I've probably been involved with OWASP. Might be 10, I'm not sure. all this stuff seems to accelerate. But I was part of the mobile top 10 as well. I've also started a couple of others that— well, this one here, I started the Internet of Things one. But I'm also doing another one. We actually did it a number of years back, but we're gonna refocus on it and relaunch in 2019, which is with Jason Haddix. We are both doing game security for OWASP. So that we're really looking forward to. It's actually already pretty cool, but we're going to put a lot more effort into it.

4:23Robert HurlbutOh, very cool.

4:25Chris RomeoSo let's jump into kind of the, I guess, the project that's had recent kind of big activity here, and this is the Internet of Things Top 10 list. And so if you can start out, just give us some background about what is this Internet of Things top 10 project and why did you start it?

4:45Daniel MiesslerYeah. So the idea is basically to have a general list, a basic list. I got some pretty strong philosophical feelings around these OWASP projects and the lists. I think it's easy to go too deep into these things. not really be as functional anymore, especially since the OWASP advice that's out there right now, it's like really adding up. There's like 20 different groups and probably 50 if you really looked, but there's like 20 pretty dominant groups out there from government organizations to corporations or whatever that are putting out guidance. And some of them have like a quick 5 pages or 10 pages and other people are putting out like 200-page documents.

5:38Robert HurlbutYeah.

5:38Daniel MiesslerAnd they're putting so much work into it and they're doing actually great work. But if you bury your work inside of 200 pages, my opinion, my cynical opinion is that effectively you might not have done anything and no one will know the difference because people could barely read a one-page infographic, let alone parse 200 pages and do what's talked about in there. So we, we basically, we pulled everything back into simplicity. And the philosophy around the project overall is help as many people as possible with a single list, with very concise, very clear description of what to avoid. We also didn't focus on, is it a vuln? Is it a threat? Is it a risk? Because each one of those is like a separate religious combat situation.

6:41Robert HurlbutOkay.

6:42Daniel MiesslerSo we basically said, you know, these are things you shouldn't do. I mean, I've been in security for like, I guess, 20 years, right? So I used to really care about all these things and like just be so eager to fight with people about these definitions. And now I'm just over that. And it's all about, okay, how quickly can we explain this? Doesn't matter what we call it. It's 10 things that you should avoid doing. And here's the other critical thing about it. It's a combination of manufacturer, developer, and implementer for the enterprise and consumer, right? So it's like, It's a combination of all those different use cases wrapped into one list.

7:30Chris RomeoSo when we think about who this is for then, so who is the— so when we think about who's the primary consumer of this list, and you just mentioned manufacturer, developer, implementer, and then ultimately the end consumer, are all 4 of those people your target audience, or is there one of those groups that you really think you're speaking to more focused?

7:52Daniel MiesslerI think it's probably enterprise more just because I feel that enterprise are the people who are using these lists the most. That's my experience because I don't see too many consumers coming here to figure out what they should do.

8:10Chris RomeoYeah.

8:11Daniel MiesslerI'd like to see more, but I don't think they are. Manufacturers, I would say, is number one or number two. I would say it's manufacturers and and enterprise. But I think enterprise is a big one. So this is the second launch of the project. The first time was 2014. And when you looked at the activity around the list, it was really around how do we do metrics for IoT Top 10? And so they were rating their own products with vulns in terms of like they were looking at all their products during assessments. and then their whole product set, like their whole portfolio, and then rating them according to IoT Top 10.

8:57Robert HurlbutYep.

8:57Daniel MiesslerSo that to me is a very enterprisey thing. There were a number of manufacturers who were saying, oh yeah, we should definitely not do these. But I do feel like manufacturers need a different project because I'm actually looking to launch a number of projects around this, but they will be independent rather than making this one larger. I think what manufacturers actually need are they need reference architectures. They need you to not say, hey, don't do that, don't do that, 'cause they hear that all day long. What they need to hear is, do this. Here's a solid implementation of TLS on a resource-constrained device, and here's exactly how you could build it. So I think that's what makes this more of an enterprise slash slash consumer-ish type situation.

9:49Chris RomeoSo you're almost talking about like a proactive controls for manufacturing in regards to IoT.

9:55Daniel MiesslerYeah, exactly, exactly. And what's cool about that is you mentioned proactive controls. I believe that's an active OWASP project. Yeah, so proactive controls is a really, really cool project. There's ASVS as well, which we're gonna be tightly partnering with. One thing I wanna get away from with this thing is just being all about the one project, right?

10:22Robert HurlbutYeah.

10:22Daniel MiesslerI really strongly pushed. So on the website, we actually have all the different projects that we looked at and parsed. We're going to do cross-linking with CSA. We're going to do the— there's a really cool project out of Europe called CTIA. So I basically wanted all these projects to be referencing each other. We're also going to put out a mapping. between our lists and these other lists as well, like CSA. But also—

10:53Chris RomeoWhat are those real quick? What are CTIA and CSA?

10:55Daniel MiesslerCSA is Cloud Security Alliance, and they have an IoT list. And CTIA, I'm not sure of the acronym, but it's a European security standards group.

11:10Chris RomeoOkay, so it's another list. So you're collaborating— not collaborating, but you're mapping to the other lists that are out there to provide, I guess, a contextual kind of a view into the fact that these things are likely pointing towards a lot of the same things.

11:27Daniel MiesslerYeah, exactly. And it's also just a heads up that these other things exist because people consume information in different ways, right? So they might look at ours and be like, yeah, I'm not so much into, you know, basic infographics. I need 47 paragraphs. And one of these other projects, which we link to directly and talk about, they might like that better. I mean, if you're truly into OWASP, you have to just be about getting people information that helps them.

11:56Chris RomeoYep. Yeah, that's very cool. So, I guess the $20,000 question then, when you have a top 10 list and you put it together, where did the data come from that allowed you to say such and such an item is number 1 and such and such an item is number 10? I ask this only because Robert and I, we had an interview with Andrew and the other folks who took on the OWASP Top 10 project.

12:24Robert HurlbutOh, yeah.

12:25Chris RomeoThere was a lot of drama in the OWASP universe with the last round of the OWASP Top 10, and Andrew and the team did a great job of coming in and making it data-driven and everything. Just based on that history, it makes me wonder from this particular list, Where's, where's this data coming from? And is it, you know, I'll just stop there. Where's the data coming from?

12:47Daniel MiesslerYeah, so we took a pretty dramatically different approach than the, the main canonical top 10. I think the data-driven approach, it does some things for you, but I don't think it does nearly as much as people think it does in terms of building a good list. I think there's kind of an assumption that data speaks truth, right? And when people look at a project, they're like, whoa, they use data, which I don't know what that means. You look at an algorithm and it tells you exactly what to put in the list, or you look at Excel and it tells you exactly what to put in the list. The reality, from my experience, with any sort of project like this is even if the data speaks to you, it's the team that actually still needs to make subjective decisions about the actual ordering of the list and about lots of different things like that. So I believe that data should guide, but that it should not be your one defense for how the list was made because In my experience, what happens is the data will tell you one thing and it just doesn't line up with reality exactly right. And if we're talking purely about ranking, that's fine. But data doesn't tell you how to wrap one volume into another.

14:19Robert HurlbutYep.

14:19Daniel MiesslerIt doesn't tell you how to title them. It doesn't tell you how— which one is a parent, which one is a child. Those are actually the most important things, is how you actually build the structure of the list. Which, which the data can't actually do anything for you on that. So if you were to perfectly build that structure and then use the data to rank it, that's fine. So, so what we did instead was we started with vuln lists, we started with NVD, just tons of different vuln databases that actually have live issues in them, right? We also took a bunch of proprietary stuff that, that we were allowed to from large manufacturers, which we were not really saying the names of them. We didn't get permission to say the names of them, but it's a number of the people on the team actually work for those companies, so it's not like a secret.

15:26Chris RomeoAnd they gave you vulnerabilities, so they were providing you lists of vulnerabilities specific to their product?

15:34Daniel MiesslerYeah, exactly. So they're basically going across the entire portfolio and saying, what is your top 10? Right. And that's basically what we asked of these different groups. What is your top 10? We don't need to know details, just what is your top 10? And of course, the taxonomy didn't match, right, which is what we would expect. But we at least got to What are you seeing in the wild? Now we combined that and we had probably 4 or 5 of those datasets from extremely large manufacturers, like, you know, top whatever, 10, 20 in the world.

16:10Robert HurlbutOkay.

16:11Daniel MiesslerSo we started with that, but that was just like I said, that was like a guide. What we really did was go to all the vuln databases. of real issues in the world and extract from there what we're actually seeing and build lists from that. So it's like we're taking lists from vendors, we're taking lists from vulnerability databases, and the whole point of doing vuln databases is not to say what could be bad, but what do we know is bad, or what do we know is being found.

16:45Chris RomeoOkay.

16:47Daniel MiesslerThen we went to all these different IoT security projects, like probably over 100. And we spent months and months doing both of these for the vuln databases and for the projects to basically say, we don't want to leave any stone unturned in terms of like— And a lot of the— we looked at a lot of these lists and said, oh wow, we didn't consider that. We forgot about that and we need to incorporate that somewhere. So we learned so much by looking at actual vulns in actual products and by looking at situations that we hadn't seen before or weren't considering for our own list inside of other projects. And that together with a fairly tight-knit small team of around 10 or so core people and probably 25 or so like on and off people. We had an open project, by the way, so it's still open. It's in the OWASP IoT security channel, so people just show up, they give feedback, but there was a core of about 10 people and we would go through all that data and basically we would then use our judgment, right? And we believe that judgment really, really matters. We believe it's the most important thing. And what's really cool about this project, I don't know how it happened, but nobody fought. There was no, I mean, it was extremely, it was like the perfect project. I mean, it was literally, hey, have you considered this? Oh, wow. Thank you for bringing that up. I mean, it was, it was like a skit almost. I mean, it, it was like the polar opposite of when we had a few years back on the mobile top 10. It was kind of the opposite of that. But, um, That's where we ended up. We had this giant set of data of vulns and considerations, and then it was a matter of how do you build the categories? How do you prioritize them? And the first 3, actually the first 5, the first 5 were just utterly obvious using this methodology. And that was what was so cool about it. It's like, I'm not sure you could get the first 5 with a data-based approach. Because if you look at the 5, they're not the type of thing that you get from data because the vol name from data is going to be something different. So that to me speaks to the strength of this approach.

19:27Chris RomeoYeah. And I think it sounds like a very well thought out and executed approach. I guess one question that comes to me as I think about this this is it almost seems like a historical approach, which I think is good in the beginning of, you know, when lists like this are more new and everybody's already got lots of these problems. But is there any future looking in this top 10 list as it sits right now, or is it from where we sit right now in the IoT space that we got enough problems on the ground, we don't need to worry about the future?

20:02Daniel MiesslerYeah, we mostly led in the direction of the latter there. There is a little bit of future in here. The little bit of future is privacy and device management. So number 8, device management is basically how are you managing a fleet of these things? What are you able to do at a fleet level? Can you update TLS at a fleet level? Can you decommission something securely, that type of thing. And that was a little bit future-leaning because we weren't 100% sure whether that should be a top 10 item. I think it's still debatable, actually, if it should be, but we're pretty happy with it. And it is definitely one of the more future-leaning things. But in general, we were leaning towards the first thing that you mentioned, which is this is killing us right now. You know, this list is mostly what is really killing us right now. What is, and is about to get way worse because, you know, everyone has a story for how big IoT is growing, you know, 47 quadrillion things by next week or whatever.

21:17Robert HurlbutYeah.

21:17Daniel MiesslerAnd, but all those things are coming out with stuff on this list, right? There's hardly any products that don't come out that that come out that don't have these problems. So we're really confident and that's exactly what we want this list to be, right? We want this list to be the absolute worst. There's actually another list of vulns, right? IoT, Internet of Things vulnerabilities is a list and there's many more items on this list and a lot of the items are inside these containers or whatever, but we could make a list that's 70 vulns in it, but we do believe that these are the worst 10.

22:00Chris RomeoAfter the break, Daniel walks us through the IoT top 10 list. The Application Security Podcast operates with support from Security Journey. A security belt program provides the 3 pillars of successful AppSec training: learning, application, and experience. Visit us on the web at www.securityjourney.com to learn how you can teach and empower your developers using a new kind of security training. Now let's hear number 1 on the list from Daniel.

22:39Daniel MiesslerYeah, sure. So, um, Number 1 was the most— it was the easiest of the entire list. And it's actually like that all the way down the list. So it's weak, guessable, or hardcoded passwords. Basically, all the work that went into this one went into the naming and the text around it, right? So it's brute-forced, publicly available, or unchangeable credentials, right? So this one, we believe, is the number 1 issue. It's because this is what's causing the ability for botnets to take things over, or largely. It's not the only thing, but it's largely what's powering botnets by just being able to log into them. So that one was pretty obvious to us. Insecure network services, number 2, is basically unneeded listening services that can cause drama, whether that's port 22 with credentials that are guessable, or that's like port 23, or UPnP, something like that.

23:51Chris RomeoSo this is all your— this is things that are normally combated by hardening, general kind of hardening approaches. The things that are— these are— so the IoT devices in general are leaving these things just kind of running and hanging out there.

24:05Daniel MiesslerYeah, exactly. For number 2, really, really the hardening point that you make could actually— yeah, I would say it would fix a lot of the top, top 3.

24:21Robert HurlbutYeah.

24:23Daniel MiesslerDoing a hardening thing. But again, being cynical, that hardening is one of the things that everyone knows should happen, but hardly ever does happen. So that's number 2. Number 3, insecure ecosystem interfaces. This was the biggest change from the list from 2014.

24:43Robert HurlbutOkay.

24:44Daniel MiesslerWhat we basically did was we combined backend API and mobile, right? So, and any other interface that gets you onto this system. This number 3 is super critical because what we're talking about here is, let's say you have whatever, a home router, okay? And you buy this thing, comes in a box, you're looking at it, it's whatever, it's blue and it's got 2 little antennas on it. Everyone, you know, a lot of people think that this is IoT. Turns out though, the first thing you do is you connect a mobile app to it. Okay, that mobile app is attack surface. And what do you know, it's got a cloud listening component. And that cloud listening component, you know, sits in the cloud and listens on port 443, and it's got its own credential infrastructure. And what do you know, the router actually reaches out to that cloud component and provides a listener and allows you to tap into whatever that is, that camera, that router, that thermostat, whatever it is. So now you have this mobile app which could cause problems, and you have the cloud functionality. So number 3 is basically what is the ecosystem that allows you to abuse or misconfigure or otherwise do something undesirable to this IoT system?

26:12Chris RomeoOkay.

26:13Daniel Miessler4 is lack of secure updates. So this is— we say secure updates because lack of update mechanism is bad enough, but secure updates, we're basically saying So I've done a whole bunch of IoT testing myself as a practitioner, and the worst case I've ever seen was basically a download that comes from a server, unsigned, unencrypted, no validation during the install. But it gets better because it was an FTP server, and if you FTP to the server and you ls over there, you see all the software for the entire company, including yours. So it's every product they ever made sitting on an FTP server and it's writable. So you could just, you could backdoor, rewrite, and redistribute software. And the entire fleet of their products was coming to that specific FTP server to get it. So it's like, There's like 4 or 5 different volumes there, probably more if you wanted to be crazy with it, but this is basically capturing that. It's validation firmware, making sure it's coming over encrypted and making sure there's validation before it gets installed.

27:37Chris RomeoYeah, and so with number 4, I remember in the early days of IoT when it was lack of update mechanism. Are you still seeing that across the devices that are releasing and 2018, now going into 2019, or have— are people at least providing some update mechanism?

27:54Daniel MiesslerI would say it's, it's way better. I don't know the actual numbers because that would be hard to count, but I would say, yeah, I don't know, it really depends on enterprise versus, you know, ICS versus all these different areas, but I would say it's got dramatically better. I would say somewhere around, I don't know, 25 to 50% are still coming out without the ability to update. But I would say that a good, good proportion are doing updates now.

28:30Chris RomeoOkay, great.

28:31Daniel MiesslerSo 5 is huge. Insecure outdated components. We've had another Lots of different research around this. A number of our friends, a bunch of people on the project actually did some research around this. It turns out a lot of people are building IoT products based on like fragments of like web server code from like 2009. They just grabbed them off the internet, pushed them into this thing, and if you look at the code itself, it's just some random snippet that serves web pages with tons of known vulnerabilities. And this is basically how a lot of these projects are built. They're just these Frankensteins of horrible, horrible code from over 10 years ago. And this is a well-known problem inside of just regular enterprise security and regular software security. So we're just bringing it to light here in IoT as well.

29:35Chris RomeoYeah. When I, you know, kind of stopping now that we're at the halfway point through this list, I just, as I found myself kind of mentally going down the list and kind of comparing this to the OWASP Top 10, the general Top 10 list. And, you know, when I see number 1, I think that's very consistent with the authentication issues in the bigger, in the, you know, kind of OWASP Top 10 general list. And then I see, you know, insecure outdated components. another direct mapping there. So definitely a lot of cohesion between what's impacting IoT and what's impacting general web development.

30:12Daniel MiesslerYeah, I would agree with that. I think the way I think of IoT, which is a little bit different than most people, I think, is it's just everyday objects made available to the world. Right. So I think the fact that that overlaps with web is extremely expected, right? Because web is the most likely way you would make an object available. So that syncs up fine with me.

30:41Chris RomeoAll right, let's pick up with 6, privacy. Not that anybody really pays attention to privacy in this day and age. I mean, it seems like it doesn't even get that much attention, but I'm being sarcastic.

30:52Daniel MiesslerI know, I know. Yeah, I think this one almost goes without saying. It's a little bit strange to figure out how that interacts with an IoT device. I think it really comes back down to kind of the number 3 situation. So you're, you're doing a given, you're implementing a given product, but where else is it gathering information? Most likely, if there's a desktop interface, if there's a mobile interface, it could be asking you for different permissions. It could be what is it sending to the backend? So this is one of the things I really love to do as a practitioner is I wrote a little program or whatever. I think it's still on GitHub. What was it called? Oh, Caparser. Caparser, whatever. It's like a PCAP parser. And basically what I would do is I would— I have a tap at the house. I run an IoT device through the tap, and what I do is I capture every single thing that the ecosystem does, even the device, even the mobile system. And then there's this little piece of code which you can get off GitHub inside of this project. It will actually break apart the PCAP. It'll break it into individual connections, and then it does a word search against each connection for clear text sensitive content. And what's really cool is it shows you, you ask the dev, and I've done this before, you ask the dev, hey, how many backend connections do you think you have? And they're like, well, I know the so-and-so server is in whatever, Missouri, and that's the backend. And then we have one advertiser, so 2.

32:38Robert HurlbutOkay.

32:39Daniel MiesslerI'm like, well, here the answer is 19. Did you know about these other 17 connections going to random places? And most people don't know. So the question is, what are all those connections? How much of your data is in those connections? Is it sensitive? And that really, as you know, privacy is all about knowledge that the person has about what's happening, not so much what is happening. Right.

33:05Robert HurlbutYeah.

33:05Daniel MiesslerAnd whether or not they have permission. So that's that one. 7 is kind of like a— this is a very network security, very core security type of issue. It's just plain old, how secure is it at rest and how secure is it in transit? And this one has a little bit of mixing with a lot of the other ones, right? But anytime we do an IoT assessment and we find something being stored insecurely on the device or being sent over the air without good encryption or protection, then that would hit on this one if it didn't hit somewhere else.

33:53Chris RomeoHow prevalent is that today? Like, I guess maybe I'm living in a glass house or something, but I kind of imagine that everybody's using TLS to protect all the streams that are going in and out of devices and things. Am I just living on a mountain somewhere?

34:10Daniel MiesslerI think you're largely right. I think the issue is that the first few connections, like going back to that developer conversation, the first few connections, Like all their main stuff, usually that's TLS'd correctly. It's those other connections that they don't know about, like analytics servers. I tested an app once, it was female health actually. So it was very sensitive sort of diary entries about sexual activity and menstrual activity and all this type of really sensitive stuff. It was like a diary, and their analytics platform was taking a copy of the application-entered data and sending it to the analytics server clear text.

35:04Chris RomeoOoh.

35:04Daniel MiesslerYeah, it was nasty. So I think there's a lot of situations where they do the main few connections that they're aware of well, but these other little ancillary connections going to things that they're not really aware of might not get that protection. So I think we're still seeing that a decent amount. But again, like the other one, I think this is getting much better.

35:28Robert HurlbutOkay.

35:29Chris RomeoSo then we touched on number 8, lack of device management, in our kind of other walkthrough. But if I remember, this is the idea that we don't have— that you can't do anything fleet-wide for most most installations these days.

35:44Daniel MiesslerYeah, exactly. This is basically how aware are you monitoring and response? This was a really key phrase that we put in there. Basically, how aware are you of your fleet? And thinking here, it's like this could be vehicle security. This could be, you know, you got a fleet of whatever, electric vehicles or Semi-trucks that whatever. This is a little bit future leaning like we talked about. It's just how aware are you of their current state? How aware are you if something bad was happening and how quickly could you respond? 9, insecure default settings. This one is a little bit strange and honestly, It's probably the one I like the least, but I also think it's quite powerful. So this is definitely manufacturer-focused, right? Because this is not something that a consumer can do anything about, or an enterprise. This is all about don't put a feature as a manufacturer in there where you have whatever TLS 5.9 or whatever— it doesn't exist— but you don't have some really strong security setting that's in there but not turned on. Because the message here is if it's not turned on by default, you largely basically shouldn't even have put it in there because people will run the default settings in most cases.

37:18Chris RomeoYeah, I mean, it's good to give them, you know, when I worked at a large tech company, we went through the process of saying, okay, when dealing with default settings, What we want to do is we want to give them what we think is the best possible secure solution, but then give them the, the toggle button to turn it off. And then if they choose to turn it off, so be it. That's not— our hands are clean because we did what we could do to make them secure, and they made an active decision to go the other direction.

37:45Daniel MiesslerYeah, no, absolutely. I think that's the right way. And then, uh, the last one here is physical hardening. And this is— this was interesting. It actually didn't take us long to get to this point. Basically, physical access, as we all know, is a game changer, right? If you have physical access, you're basically gonna get there. You're gonna be able to compromise it in most cases. The idea here is to try to make it a little bit harder And that being, of course, important for the overall security of the product. The reason we have it on the list is because it's such high impact. The reason it's only number 10 is because on the scale of Internet of Things, most Internet of Things devices by definition are not local to you and are not local to an attacker. So the actual attack surface is usually not Including physical. And that's why we have it so low on the list, but it's a very high impact. So we, we believe it was worth being on the list, just not very high.

38:57Chris RomeoYeah, that makes sense. And when I think about that, I think of like my neighbor that has a Ring doorbell, for example, and that Ring doorbell sits outside because it's a doorbell, right? But I could walk up and I could yank that thing off the side of the house and I could try to mess with it because I had physical access to it. And so, yeah, I think it makes sense as a number 10. It's important, but it's not more important than anything else you have on this list. But still, it's something that we don't tend to think about when we consider IoT.

39:29Daniel MiesslerYeah. Well, and here's a great example. Let's say you have that doorbell and you're an attacker and you're in the same city as this doorbell that you want to attack. If number 1 existed, you could attack all the doorbells in the world.

39:48Chris RomeoYep.

39:49Daniel MiesslerAnd if number 10 exists, you've got to go to that house.

39:52Chris RomeoYeah, you got to be physically in that space. Yeah, that's definitely— so this is definitely a nice list. And, you know, it's— I've been doing security as long as you have. You know, there's nothing I can't argue with anything you have on this list. It's like, it's—

40:12Daniel MiesslerOh, that's awesome.

40:13Chris RomeoIt's the, it's the, the things that I think are kind of the most, most important.

40:18Robert HurlbutAbsolutely. Hey, Daniel, great conversation. Thank you again for joining us today. Just a couple of things to wrap up. One thing I was wondering about, I was just hearing about some things that developers may miss, like, for example, extra connections and things like that. What are some, maybe some takeaways for a developer who is seeing this list and what they should think about first, second, so forth to get started?

40:46Daniel MiesslerWell, the biggest takeaway is to look at their current product and to go through each of these and say, do I have these problems? Especially starting at the top and going down. I think that is the most important thing. And the thing about it is you get diminishing return, right? As you go down, if you do the first 3 and you lock that out and you are solid on those first 3, you get much less benefit from continuing on. But if you were to do whatever, number 8, but not do 1, 2, and 3, then it wouldn't be nearly as good. So—

41:30Robert HurlbutYeah.

41:31Daniel MiesslerI think the prescriptive guidance for exactly what to do is so detailed and varied and hard to attack that our intention is to basically link out to these other projects or start these other projects for reference architectures. The main takeaway for a developer or a manufacturer is to look at this list from the top, starting at the top, and make sure they don't have these issues.

41:59Robert HurlbutOkay, great. And secondly, you mentioned the Slack channel or maybe some other ways to get in touch and follow up. I'm looking at the project page. I know there are a lot of links here, as you mentioned, other projects and so forth, but there are some other ways to do some follow-up, like for example, the Slack channel.

42:19Daniel MiesslerYeah, the Slack channel is absolutely the best way to interact with the team and to become part of the team. There's no like, there's no vetting. There's no, well, it's not like we're just taking anyone, but we're not doing interviews or anything. It's like you show up, you have good ideas, you're part of the team. It's very, I don't know what that's egalitarian or whatever. So the idea is you show up in the Slack channel, give feedback, and if it's good feedback, it's going to get incorporated. We had probably 25, 30 different people coming in over the course of the year. giving feedback. And like I said, probably around 10 or so core project team members.

43:06Robert HurlbutGreat, thank you.

43:10Chris RomeoSo Daniel, I just want to thank you for taking the time to walk us through this. I know this is going to help our listeners as they're starting to think through what does security look like in an IoT world. And so I would just want to congratulate you and the team for what I know is hundreds, if not thousands of hours that have gone into this in total. And I mean, I think most people know this, but just in case some of our listeners don't, OWASP doesn't pay the big bucks to people. So this is all volunteer. This is all done by people that just love security. And so Daniel, thank you for taking the time with us today.

43:47Robert HurlbutThank you.

43:47Chris RomeoAnd please let the team know that we appreciate them as well as they work to make the Internet of Things more secure.

43:54Daniel MiesslerAwesome. Thanks a lot for having us. Thanks for listening to the Application Security Podcast. If you enjoy the podcast, please do us a favor and visit the iTunes Store and give us a 5-star rating. Our intro music is 8-Bit Kung Fu by Born and TJ, and the outro is Southern Delight by Stefan Cartenberg. You can find us on Twitter @AppSecPodcast or on the web at www.appsecpodcast.org.

6,541 words · transcript by assemblyai

More on OWASP Top 10

View all episodes →

Get Reasonable AppSec: new episodes and useful picks from the archive.