SlideShare a Scribd company logo
#RSAC
SESSION ID:
Jason Hong
Security and Privacy Challenges for IoT
SEM-M01E
Professor
Carnegie Mellon University
@jas0nh0ng
#RSAC
2
#RSAC
3
#RSAC
Four New IoT Challenges for Privacy and Security
1. Intimacy of Devices and Data
4
Fun Facts about Millennials
– 83% sleep with their phones
– 90% check first thing in morning
– 1 in 3 use in bathroom
#RSAC
Four New IoT Challenges for Privacy and Security
1. Intimacy of Devices and Data
5
Fun Facts about Millennials
– 83% sleep with their phones
– 90% check first thing in morning
– 1 in 3 use in bathroom
Our smartphones already know:
– Who we know, where we go, what we like
#RSAC
Four New IoT Challenges for Privacy and Security
1. Intimacy of Devices and Data
6
Fun Facts about Millennials
– 83% sleep with their phones
– 90% check first thing in morning
– 1 in 3 use in bathroom
Our smartphones already know:
– Who we know, where we go, what we like
Will only become more intimate with IoT
– This also means new kinds of intrusive ads,
data breaches, accidental data sharing
#RSAC
Four New IoT Challenges for Privacy and Security
2. Physical Safety
7
Today, main problem is data breaches
Tomorrow, huge potential for many nasty scenarios
– Many new kinds of ransomware we haven’t imagined yet
o Malware that locks people out of their houses
o Malware that turns off thermostats in winter --> burst pipes
– Holding people and society virtually hostage
o Autonomous drones or vehicles deliberately crashing into things
o Implanted medical devices giving or receiving fake data
#RSAC
Four New IoT Challenges for Privacy and Security
3. Awareness of Devices
8
In my first year teaching at Carnegie
Mellon, met with students in their lab
Didn’t know until end of semester we
were being broadcast on Internet the
entire time!
– Do you see the camera?
#RSAC
Four New IoT Challenges for Privacy and Security
3. Awareness of Devices
9
#RSAC
Four New IoT Challenges for Privacy and Security
3. Awareness of Devices
10
More and more devices will be hard to notice
Ex. Mites “supersensor” under development at Carnegie Mellon
See http://mites.io
#RSAC
Four New IoT Challenges for Privacy and Security
4. Complexity and Scale
11
Lots of unexpected and emergent behaviors
#RSAC
How to Address These Privacy and Security Issues?
12
Better technical approaches
– Operating systems, networking, programming languages
Better UX design
– Better disclosures, awareness of devices, controls, decision making
Better developer support
– Most developers are C students
– Tools, education, best practices for privacy and security
Better laws, policies, and standards
– Mandatory cybersecurity insurance for manufacturers
– Tools to help policy makers, journalists, product reviewers
#RSAC
How to Address These Privacy and Security Issues?
13
Better technical approaches
– Operating systems, networking, programming languages
Better UX design
– Better disclosures, awareness of devices, controls, decision making
Better developer support
– Most developers are C students
– Tools, education, best practices for privacy and security
Better laws, policies, and standards
– Mandatory cybersecurity insurance for manufacturers
– Tools to help policy makers, journalists, product reviewers
#RSAC
How to Address These Privacy and Security Issues?
Operating Systems
14
Our team is developing an open source IoT Hub
– Think of it as a smarter WiFi router that protects IoT devices
How far can we go if devices have simple metadata?
– Ex. Here is my URL for software updates
– Ex. Here is my Manufacturer Usage Description (MUDs)
o Whitelist: this lightbulb communicates only with lights.intel.com
What basic services can IoT Hub offer for all devices?
– Ex. Disallow remote login for devices if well-known default password
– Ex. Centralize telemetry and learn patterns
#RSAC
How to Address These Privacy and Security Issues?
Awareness of Devices
15
Our team looking at physical dimension of IoT privacy
– Ex. Make it easy to see where camera is and where it’s pointed
– Want something cheap (so manufacturers will adopt) and effective
– Testing out LEDs, audio, virtual maps
LEDs off If device has camera -> LED on
#RSAC
How to Address These Privacy and Security Issues?
Awareness of Devices
16
LEDs off If device has camera -> LED on
#RSAC
Summary
17
IoT poses many new challenges to privacy and security
– Ex. Intimacy, physical security, awareness, complexity
Existing approaches for privacy and security insufficient
– Will require innovations in tech, UX, education, legal, standards
We’re not going to have many second chances for IoT, and
business as usual will be disastrous
Let’s make sure we create a world we would want to live in
Contact me at jasonh@cs.cmu.edu
#RSAC
18
#RSAC
19

More Related Content

PPTX
How We Will Fail in Privacy and Ethics for the Emerging Internet of Things
PPTX
Helping Developers with Privacy
PPTX
Privacy for Mobile Sensing Systems
PPTX
Are my Devices Spying on Me? Living in a World of Ubiquitous Computing
PPTX
Privacy and Security for the Emerging Internet of Things
PDF
IOT Security - ICCT College of Engineering
PPTX
Cybersecurity-Real World Approach FINAL 2-24-16
PDF
ZION: Security and Internet of Things
How We Will Fail in Privacy and Ethics for the Emerging Internet of Things
Helping Developers with Privacy
Privacy for Mobile Sensing Systems
Are my Devices Spying on Me? Living in a World of Ubiquitous Computing
Privacy and Security for the Emerging Internet of Things
IOT Security - ICCT College of Engineering
Cybersecurity-Real World Approach FINAL 2-24-16
ZION: Security and Internet of Things

What's hot (20)

PDF
PPTX
Internet of Things & Wearable Technology: Unlocking the Next Wave of Data-Dri...
PDF
Why You’ll Care More About Mobile Security in 2020 - Tom Bain
PDF
The criticality-of-security-in-the-internet-of-things joa-eng_1115
PPTX
How Can Policymakers and Regulators Better Engage the Internet of Things?
PPTX
Advanced threat protection and big data
PPTX
Ethical issues in internet of things
PPTX
IoT advatage and disadvantage
PPTX
The challenge of security awareness
PPTX
NTXISSACSC2 - Bring Your Own Device: The Great Debate by Brandon Swain
PDF
"Technology, Ethics, and Social Work"
PPTX
All The Things: Security, Privacy & Safety in a World of Connected Devices
PDF
Telefónica security io_t_final
PDF
Security and Privacy Big Challenges in Internet of things
PPTX
The importance of authenticity in cyber security training and education
PDF
Security and Privacy in IoT and Cyber-physical Systems
PDF
From Identity to Ownership Theft
PDF
Exploring the Educational Potential of the Internet of Things (Internet of Th...
PPTX
What’s the big deal with the internet of
PDF
NTXISSACSC1 Conference - Cybersecurity 2014 by Andrea Almeida
Internet of Things & Wearable Technology: Unlocking the Next Wave of Data-Dri...
Why You’ll Care More About Mobile Security in 2020 - Tom Bain
The criticality-of-security-in-the-internet-of-things joa-eng_1115
How Can Policymakers and Regulators Better Engage the Internet of Things?
Advanced threat protection and big data
Ethical issues in internet of things
IoT advatage and disadvantage
The challenge of security awareness
NTXISSACSC2 - Bring Your Own Device: The Great Debate by Brandon Swain
"Technology, Ethics, and Social Work"
All The Things: Security, Privacy & Safety in a World of Connected Devices
Telefónica security io_t_final
Security and Privacy Big Challenges in Internet of things
The importance of authenticity in cyber security training and education
Security and Privacy in IoT and Cyber-physical Systems
From Identity to Ownership Theft
Exploring the Educational Potential of the Internet of Things (Internet of Th...
What’s the big deal with the internet of
NTXISSACSC1 Conference - Cybersecurity 2014 by Andrea Almeida
Ad

Similar to Security and Privacy Challenges for IoT (20)

DOCX
Security and Privacy considerations in Internet of Things
PDF
Internet of Things (IoT) Security and Privacy Recommendations by Jason Living...
PDF
A New Security Paradigm for IoT (Internet of Threats)
PDF
CIS 2015 How to secure the Internet of Things? Hannes Tschofenig
PDF
From IT to IoT: Bridging the Growing Cybersecurity Divide
PPTX
Mayur Seminar.pptxbgvyezuvdt as bijvyivutctr
PPTX
Privacy and security in IoT
PDF
RSA2015: Securing the Internet of Things
PDF
This Time, It’s Personal: Why Security and the IoT Is Different
PDF
Technology & Policy Interaction Panel at Inform[ED] IoT Security
DOCX
Addressing security and privacy in io t ecosystem v0.4
PPTX
Security issues and solutions : IoT
PDF
Security in Cyber-Physical Systems
PDF
internet of thingsssssssssssssssssssssss
PDF
Exfiltrating Data through IoT
PDF
[TestWarez 2017] Securing the Internet of Things
PPTX
Iot cyber security
PPTX
Chapter 6 - IT Culture and the Society - Lesson 1.pptx
PDF
assignment help experts
PPTX
The Internet of Fails - Mark Stanislav, Senior Security Consultant, Rapid7
Security and Privacy considerations in Internet of Things
Internet of Things (IoT) Security and Privacy Recommendations by Jason Living...
A New Security Paradigm for IoT (Internet of Threats)
CIS 2015 How to secure the Internet of Things? Hannes Tschofenig
From IT to IoT: Bridging the Growing Cybersecurity Divide
Mayur Seminar.pptxbgvyezuvdt as bijvyivutctr
Privacy and security in IoT
RSA2015: Securing the Internet of Things
This Time, It’s Personal: Why Security and the IoT Is Different
Technology & Policy Interaction Panel at Inform[ED] IoT Security
Addressing security and privacy in io t ecosystem v0.4
Security issues and solutions : IoT
Security in Cyber-Physical Systems
internet of thingsssssssssssssssssssssss
Exfiltrating Data through IoT
[TestWarez 2017] Securing the Internet of Things
Iot cyber security
Chapter 6 - IT Culture and the Society - Lesson 1.pptx
assignment help experts
The Internet of Fails - Mark Stanislav, Senior Security Consultant, Rapid7
Ad

Recently uploaded (20)

PDF
DP Operators-handbook-extract for the Mautical Institute
PDF
Video forgery: An extensive analysis of inter-and intra-frame manipulation al...
PDF
Encapsulation theory and applications.pdf
PPTX
Digital-Transformation-Roadmap-for-Companies.pptx
PDF
MIND Revenue Release Quarter 2 2025 Press Release
PDF
Microsoft Solutions Partner Drive Digital Transformation with D365.pdf
PDF
Univ-Connecticut-ChatGPT-Presentaion.pdf
PDF
Heart disease approach using modified random forest and particle swarm optimi...
PPTX
Group 1 Presentation -Planning and Decision Making .pptx
PDF
project resource management chapter-09.pdf
PDF
Approach and Philosophy of On baking technology
PPTX
Programs and apps: productivity, graphics, security and other tools
PDF
A comparative study of natural language inference in Swahili using monolingua...
PDF
Building Integrated photovoltaic BIPV_UPV.pdf
PDF
Getting Started with Data Integration: FME Form 101
PDF
WOOl fibre morphology and structure.pdf for textiles
PDF
Enhancing emotion recognition model for a student engagement use case through...
PPTX
TLE Review Electricity (Electricity).pptx
PPTX
OMC Textile Division Presentation 2021.pptx
PDF
Accuracy of neural networks in brain wave diagnosis of schizophrenia
DP Operators-handbook-extract for the Mautical Institute
Video forgery: An extensive analysis of inter-and intra-frame manipulation al...
Encapsulation theory and applications.pdf
Digital-Transformation-Roadmap-for-Companies.pptx
MIND Revenue Release Quarter 2 2025 Press Release
Microsoft Solutions Partner Drive Digital Transformation with D365.pdf
Univ-Connecticut-ChatGPT-Presentaion.pdf
Heart disease approach using modified random forest and particle swarm optimi...
Group 1 Presentation -Planning and Decision Making .pptx
project resource management chapter-09.pdf
Approach and Philosophy of On baking technology
Programs and apps: productivity, graphics, security and other tools
A comparative study of natural language inference in Swahili using monolingua...
Building Integrated photovoltaic BIPV_UPV.pdf
Getting Started with Data Integration: FME Form 101
WOOl fibre morphology and structure.pdf for textiles
Enhancing emotion recognition model for a student engagement use case through...
TLE Review Electricity (Electricity).pptx
OMC Textile Division Presentation 2021.pptx
Accuracy of neural networks in brain wave diagnosis of schizophrenia

Security and Privacy Challenges for IoT

  • 1. #RSAC SESSION ID: Jason Hong Security and Privacy Challenges for IoT SEM-M01E Professor Carnegie Mellon University @jas0nh0ng
  • 4. #RSAC Four New IoT Challenges for Privacy and Security 1. Intimacy of Devices and Data 4 Fun Facts about Millennials – 83% sleep with their phones – 90% check first thing in morning – 1 in 3 use in bathroom
  • 5. #RSAC Four New IoT Challenges for Privacy and Security 1. Intimacy of Devices and Data 5 Fun Facts about Millennials – 83% sleep with their phones – 90% check first thing in morning – 1 in 3 use in bathroom Our smartphones already know: – Who we know, where we go, what we like
  • 6. #RSAC Four New IoT Challenges for Privacy and Security 1. Intimacy of Devices and Data 6 Fun Facts about Millennials – 83% sleep with their phones – 90% check first thing in morning – 1 in 3 use in bathroom Our smartphones already know: – Who we know, where we go, what we like Will only become more intimate with IoT – This also means new kinds of intrusive ads, data breaches, accidental data sharing
  • 7. #RSAC Four New IoT Challenges for Privacy and Security 2. Physical Safety 7 Today, main problem is data breaches Tomorrow, huge potential for many nasty scenarios – Many new kinds of ransomware we haven’t imagined yet o Malware that locks people out of their houses o Malware that turns off thermostats in winter --> burst pipes – Holding people and society virtually hostage o Autonomous drones or vehicles deliberately crashing into things o Implanted medical devices giving or receiving fake data
  • 8. #RSAC Four New IoT Challenges for Privacy and Security 3. Awareness of Devices 8 In my first year teaching at Carnegie Mellon, met with students in their lab Didn’t know until end of semester we were being broadcast on Internet the entire time! – Do you see the camera?
  • 9. #RSAC Four New IoT Challenges for Privacy and Security 3. Awareness of Devices 9
  • 10. #RSAC Four New IoT Challenges for Privacy and Security 3. Awareness of Devices 10 More and more devices will be hard to notice Ex. Mites “supersensor” under development at Carnegie Mellon See http://mites.io
  • 11. #RSAC Four New IoT Challenges for Privacy and Security 4. Complexity and Scale 11 Lots of unexpected and emergent behaviors
  • 12. #RSAC How to Address These Privacy and Security Issues? 12 Better technical approaches – Operating systems, networking, programming languages Better UX design – Better disclosures, awareness of devices, controls, decision making Better developer support – Most developers are C students – Tools, education, best practices for privacy and security Better laws, policies, and standards – Mandatory cybersecurity insurance for manufacturers – Tools to help policy makers, journalists, product reviewers
  • 13. #RSAC How to Address These Privacy and Security Issues? 13 Better technical approaches – Operating systems, networking, programming languages Better UX design – Better disclosures, awareness of devices, controls, decision making Better developer support – Most developers are C students – Tools, education, best practices for privacy and security Better laws, policies, and standards – Mandatory cybersecurity insurance for manufacturers – Tools to help policy makers, journalists, product reviewers
  • 14. #RSAC How to Address These Privacy and Security Issues? Operating Systems 14 Our team is developing an open source IoT Hub – Think of it as a smarter WiFi router that protects IoT devices How far can we go if devices have simple metadata? – Ex. Here is my URL for software updates – Ex. Here is my Manufacturer Usage Description (MUDs) o Whitelist: this lightbulb communicates only with lights.intel.com What basic services can IoT Hub offer for all devices? – Ex. Disallow remote login for devices if well-known default password – Ex. Centralize telemetry and learn patterns
  • 15. #RSAC How to Address These Privacy and Security Issues? Awareness of Devices 15 Our team looking at physical dimension of IoT privacy – Ex. Make it easy to see where camera is and where it’s pointed – Want something cheap (so manufacturers will adopt) and effective – Testing out LEDs, audio, virtual maps LEDs off If device has camera -> LED on
  • 16. #RSAC How to Address These Privacy and Security Issues? Awareness of Devices 16 LEDs off If device has camera -> LED on
  • 17. #RSAC Summary 17 IoT poses many new challenges to privacy and security – Ex. Intimacy, physical security, awareness, complexity Existing approaches for privacy and security insufficient – Will require innovations in tech, UX, education, legal, standards We’re not going to have many second chances for IoT, and business as usual will be disastrous Let’s make sure we create a world we would want to live in Contact me at jasonh@cs.cmu.edu

Editor's Notes

  • #3: https://commons.wikimedia.org/wiki/File:Dell_Desktop_Computer_in_school_classroom.jpg Two decades ago, computers were primarily large unattractive boxes that came with a monitor, keyboard, and mouse
  • #4: Explosion of form factors Offer a lot of potential benefit to society, in terms of healthcare, urban planning, safety, and more But also pose new kinds of challenges to privacy and security
  • #5: Some researchers have said that there is nothing new about privacy and security for IoT That it’s just the same as what we’re already facing I would strongly disagree Let me tell you about four new challenges for privacy and security for IoT
  • #10: This is not a hypothetical problem, and it’s not just cameras too https://www.washingtonpost.com/technology/2019/01/17/airbnb-refunds-guest-who-found-indoor-cameras-during-his-familys-stay/?noredirect=on&utm_term=.b9131e272fd1 http://jeffreybigham.com/blog/2019/who-is-watching-you-in-your-airbnb.html#h.jbbecf75fxlp
  • #11: This is not a hypothetical problem, and it’s not just cameras too https://www.washingtonpost.com/technology/2019/01/17/airbnb-refunds-guest-who-found-indoor-cameras-during-his-familys-stay/?noredirect=on&utm_term=.b9131e272fd1 http://jeffreybigham.com/blog/2019/who-is-watching-you-in-your-airbnb.html#h.jbbecf75fxlp
  • #12: Ok Glass, take a picture -> everyone’s Glass took a picture We’ll have more and more examples of these kinds of unexpected behaviors as the number of devices increases