SlideShare uma empresa Scribd logo
1 de 15
Baixar para ler offline
A Survey of Structural
Insecurities in IoT
Jeff Katz
Senior Practice Lead IT / Engineering
Telefónica Germany NEXT GmbH
» The problem with this process is that no one
entity has any incentive, expertise, or even ability
to patch the software once it's shipped… We
simply have to fix this. «
-BRUCE SCHNEIER, Wired, 2014
Agenda
– Relevant quote
– Agenda
– Speaker Info
– Sales
– Channels
– Retail deep-dive
– Telefónica
– Geeny
~20 minutes | english
3
Jeff Katz
– American living in Germany for six years
– Founded companies in Finance, IT, Security
– Founded hardware accelerator called
HARDWARE.co
– Spoken around the world on Security and Privacy
in IoT
– Background in Electrical Engineering and
Embedded Development
– Currently working for Telefónica NEXT on IoT
Platform
4
What’s IoT?
5
• Industrial
• Agricultural
• Smart City
• Consumer (Smart Home, etc.)
There are
forecast to be
28 billion
connected
devices
worldwide by
2021
Almost 16
billion of them
will be loT
devices
loT devices will over-take
mobile phones as the
largest category of
connected devices in
2018
This will be driven by
the spread of smart
meters and
connected cars, as
well as by consumer
devices
The number of loT
devices in Western
Europe is
projected to
quadruple
between 2015 and
2021
The Consumer IoT Market
How an idea becomes an IoT solution
– Let’s pretend: We are ”Melkin” a
multinational consumer device
company, and we want to make a
connected baby monitor
– Two-way audio streaming, there’s an
app, etc.
Let’s explore who is involved to bring this
product to shelves
7
Any resemblance to any real companies or
products is strictly coincidental and not
intended. This is not the story of a real
product.
The Service
– We’re going to start with the App, and what we want the user experience to be
– External design agency engaged
– Click-dummy delivered
– External app agency engaged
– iOS, Android, etc. delivered under budget and time pressure
– Often developed before the hardware is even done
8
The ODM
– Factory in Guangzhou, China
– Manufactures Baby Monitors for many
multinational companies
– Take existing model that matches our
requirements
– Develop new plastics for it
– Firmware based on reference design from
Chipset Manufacturer
– Completely white-label
(This is a real company and this is really how
this works)
9
The Chipset Manufacturer
– Wants to sell chips
– Provides bare-minimum reference designs that show how to get something working
– Not responsible for end product, at all.
10
The Branded Device
– Purchased at retail from Big Box Store
– Provides the data and interface to provide the service
– What the customer installs in their home, next to their baby
– Connects to home WIFI
– Firmware developed by agency, based on reference from the ODM
– Melkin is responsible for warranty, sales, support, etc
11
The Platform
– Needs to connect the service to the device
– Should have minimal impact on the final cost
of the device
– Contracted by a third party, either build or
buy—Melkin doesn’t want to deal with it. Best
case, fully outsourced and managed. Worst-
case: Managed by Melkin
– Provides examples (firmware, app) how to
communicate with it
– Example: Arrayent
12
Overview
– App design: Outsourced
– App implementation: Outsourced
– Hardware Design: Outsourced
– Firmware: Outsourced, based on Outsourced example from Outsourced Chipset example
– Platform: Outsourced
– Seller: Retail Store
– Connectivity: Home WIFI (ISP), Home Router
– Final Product Responsibility: Melkin
13
What to do / Where to address?
– Let’s fix the perverse incentives: Companies require security but actively choose against suppliers who
price it in to offers.
– GDPR huge help—significant fines for bad behavior for end responsible company
– Need to spread responsibility to all involved parties
– Proliferation of bad examples: Let’s build security in from the very beginning—Chipset manufacturers,
Reference Designs, etc.
– Education and guides on what to look for in products
– More openness: Open source, open spec, open APIs,
– Financial incentives, positive or negative
14
Thank you. Let’s talk!
Jeff Katz
Senior Practice Lead IT / Engineering
Telefónica Germany NEXT GmbH
jeff@geeny.io • jeff.katz@telefonica.com • @kraln
https://developers.geeny.io
join the Geeny developer community

Mais conteúdo relacionado

Mais procurados

Jeremy Kane Beyond 2010 Presentation
Jeremy Kane Beyond 2010 PresentationJeremy Kane Beyond 2010 Presentation
Jeremy Kane Beyond 2010 Presentationeventwithme
 
2010 Nemertes Research Pilot House Awards Highlights
2010 Nemertes Research Pilot House Awards Highlights2010 Nemertes Research Pilot House Awards Highlights
2010 Nemertes Research Pilot House Awards HighlightsB-Port
 
Multifamily Technology For Today and Tomorrow
Multifamily Technology For Today and TomorrowMultifamily Technology For Today and Tomorrow
Multifamily Technology For Today and TomorrowMike Whaling
 
Practical Internet of Things Now -- What it is and six requirements for your ...
Practical Internet of Things Now -- What it is and six requirements for your ...Practical Internet of Things Now -- What it is and six requirements for your ...
Practical Internet of Things Now -- What it is and six requirements for your ...ReidCarlberg
 
2nd Annual M2M and IoT Strategies Summit - production-1-new brochure-2
2nd Annual M2M and IoT Strategies Summit - production-1-new brochure-22nd Annual M2M and IoT Strategies Summit - production-1-new brochure-2
2nd Annual M2M and IoT Strategies Summit - production-1-new brochure-2Jorge Rivero Sanchez
 
Ok, we're mobile. now what?
Ok, we're mobile. now what?Ok, we're mobile. now what?
Ok, we're mobile. now what?Brian Katz
 
Can the internet of things survive the coming war
Can the internet of things survive the coming warCan the internet of things survive the coming war
Can the internet of things survive the coming warJason Fernandes
 
Security Everywhere in the Digital Economy
Security Everywhere in the Digital EconomySecurity Everywhere in the Digital Economy
Security Everywhere in the Digital EconomyConnected Futures
 
TASK.IO Pitch Deck
TASK.IO Pitch DeckTASK.IO Pitch Deck
TASK.IO Pitch DeckSteve Walker
 
Simon Saneback ITEM 2018
Simon Saneback ITEM 2018Simon Saneback ITEM 2018
Simon Saneback ITEM 2018ITEM
 
Paul Clayton, Head of New Services Development at Procserve - The Future of B...
Paul Clayton, Head of New Services Development at Procserve - The Future of B...Paul Clayton, Head of New Services Development at Procserve - The Future of B...
Paul Clayton, Head of New Services Development at Procserve - The Future of B...Global Business Events
 
Programmable Telecoms is Hard - The immmr Story
Programmable Telecoms is Hard - The immmr StoryProgrammable Telecoms is Hard - The immmr Story
Programmable Telecoms is Hard - The immmr StorySebastian Schumann
 
The Application Of Applications
The Application Of ApplicationsThe Application Of Applications
The Application Of ApplicationsLiam Thorpe-Young
 
Who's Afraid of Mobile Capture?
Who's Afraid of Mobile Capture?Who's Afraid of Mobile Capture?
Who's Afraid of Mobile Capture?AIIM International
 
From Lego to Plasticine. Molding a platform for product development, Werner E...
From Lego to Plasticine. Molding a platform for product development, Werner E...From Lego to Plasticine. Molding a platform for product development, Werner E...
From Lego to Plasticine. Molding a platform for product development, Werner E...Alan Quayle
 
The Business Case for OSGi Technology & Unveiling Release 4 - Susan Schwarze,...
The Business Case for OSGi Technology & Unveiling Release 4 - Susan Schwarze,...The Business Case for OSGi Technology & Unveiling Release 4 - Susan Schwarze,...
The Business Case for OSGi Technology & Unveiling Release 4 - Susan Schwarze,...mfrancis
 
Low Coding and Citizen Development - Gert Vonck (Apple)
Low Coding and Citizen Development - Gert Vonck (Apple) Low Coding and Citizen Development - Gert Vonck (Apple)
Low Coding and Citizen Development - Gert Vonck (Apple) Patrick Van Renterghem
 

Mais procurados (20)

Jeremy Kane Beyond 2010 Presentation
Jeremy Kane Beyond 2010 PresentationJeremy Kane Beyond 2010 Presentation
Jeremy Kane Beyond 2010 Presentation
 
2010 Nemertes Research Pilot House Awards Highlights
2010 Nemertes Research Pilot House Awards Highlights2010 Nemertes Research Pilot House Awards Highlights
2010 Nemertes Research Pilot House Awards Highlights
 
Multifamily Technology For Today and Tomorrow
Multifamily Technology For Today and TomorrowMultifamily Technology For Today and Tomorrow
Multifamily Technology For Today and Tomorrow
 
Practical Internet of Things Now -- What it is and six requirements for your ...
Practical Internet of Things Now -- What it is and six requirements for your ...Practical Internet of Things Now -- What it is and six requirements for your ...
Practical Internet of Things Now -- What it is and six requirements for your ...
 
2nd Annual M2M and IoT Strategies Summit - production-1-new brochure-2
2nd Annual M2M and IoT Strategies Summit - production-1-new brochure-22nd Annual M2M and IoT Strategies Summit - production-1-new brochure-2
2nd Annual M2M and IoT Strategies Summit - production-1-new brochure-2
 
Ok, we're mobile. now what?
Ok, we're mobile. now what?Ok, we're mobile. now what?
Ok, we're mobile. now what?
 
Can the internet of things survive the coming war
Can the internet of things survive the coming warCan the internet of things survive the coming war
Can the internet of things survive the coming war
 
Security Everywhere in the Digital Economy
Security Everywhere in the Digital EconomySecurity Everywhere in the Digital Economy
Security Everywhere in the Digital Economy
 
About Motwin
About MotwinAbout Motwin
About Motwin
 
L20 Personalised World
L20 Personalised WorldL20 Personalised World
L20 Personalised World
 
TASK.IO Pitch Deck
TASK.IO Pitch DeckTASK.IO Pitch Deck
TASK.IO Pitch Deck
 
Simon Saneback ITEM 2018
Simon Saneback ITEM 2018Simon Saneback ITEM 2018
Simon Saneback ITEM 2018
 
Paul Clayton, Head of New Services Development at Procserve - The Future of B...
Paul Clayton, Head of New Services Development at Procserve - The Future of B...Paul Clayton, Head of New Services Development at Procserve - The Future of B...
Paul Clayton, Head of New Services Development at Procserve - The Future of B...
 
Programmable Telecoms is Hard - The immmr Story
Programmable Telecoms is Hard - The immmr StoryProgrammable Telecoms is Hard - The immmr Story
Programmable Telecoms is Hard - The immmr Story
 
The Application Of Applications
The Application Of ApplicationsThe Application Of Applications
The Application Of Applications
 
Who's Afraid of Mobile Capture?
Who's Afraid of Mobile Capture?Who's Afraid of Mobile Capture?
Who's Afraid of Mobile Capture?
 
From Lego to Plasticine. Molding a platform for product development, Werner E...
From Lego to Plasticine. Molding a platform for product development, Werner E...From Lego to Plasticine. Molding a platform for product development, Werner E...
From Lego to Plasticine. Molding a platform for product development, Werner E...
 
The Business Case for OSGi Technology & Unveiling Release 4 - Susan Schwarze,...
The Business Case for OSGi Technology & Unveiling Release 4 - Susan Schwarze,...The Business Case for OSGi Technology & Unveiling Release 4 - Susan Schwarze,...
The Business Case for OSGi Technology & Unveiling Release 4 - Susan Schwarze,...
 
L19 Network Platforms
L19 Network PlatformsL19 Network Platforms
L19 Network Platforms
 
Low Coding and Citizen Development - Gert Vonck (Apple)
Low Coding and Citizen Development - Gert Vonck (Apple) Low Coding and Citizen Development - Gert Vonck (Apple)
Low Coding and Citizen Development - Gert Vonck (Apple)
 

Semelhante a ThingsConAMS 2017 - Jeff Katz - A Survey of Structural Insecurities in IoT

External Device Integration with Mobile
External Device Integration with MobileExternal Device Integration with Mobile
External Device Integration with MobileSoftweb Solutions
 
(2019) Hack All the Way Through From Fridge to Mainframe (v0.2)
(2019) Hack All the Way Through From Fridge to Mainframe (v0.2)(2019) Hack All the Way Through From Fridge to Mainframe (v0.2)
(2019) Hack All the Way Through From Fridge to Mainframe (v0.2)Rui Miguel Feio
 
Streaming Processes: Creating a Start-up Within a Big Corporate (Mohammad Sha...
Streaming Processes: Creating a Start-up Within a Big Corporate (Mohammad Sha...Streaming Processes: Creating a Start-up Within a Big Corporate (Mohammad Sha...
Streaming Processes: Creating a Start-up Within a Big Corporate (Mohammad Sha...Executive Leaders Network
 
Written by Mark Stanislav and Tod Beardsley September 2015.docx
Written by Mark Stanislav and Tod Beardsley    September 2015.docxWritten by Mark Stanislav and Tod Beardsley    September 2015.docx
Written by Mark Stanislav and Tod Beardsley September 2015.docxjeffevans62972
 
Written by Mark Stanislav and Tod Beardsley September 2015.docx
Written by Mark Stanislav and Tod Beardsley    September 2015.docxWritten by Mark Stanislav and Tod Beardsley    September 2015.docx
Written by Mark Stanislav and Tod Beardsley September 2015.docxodiliagilby
 
Connecting Above the Cloud
Connecting Above the CloudConnecting Above the Cloud
Connecting Above the CloudPeter Coffee
 
Mti byod wp_uk
Mti byod wp_ukMti byod wp_uk
Mti byod wp_ukJ
 
Building a developer community around hardware + software
Building a developer community around hardware + softwareBuilding a developer community around hardware + software
Building a developer community around hardware + softwareAmanda Whaley
 
Home Security App Development.docx
Home Security App Development.docxHome Security App Development.docx
Home Security App Development.docxCMARIX TechnoLabs
 
Internet of Things- IoT Monetization Models
Internet of Things- IoT Monetization ModelsInternet of Things- IoT Monetization Models
Internet of Things- IoT Monetization ModelsSubrahmanyam KVJ
 
Building the Global "Cloud 2"
Building the Global "Cloud 2"Building the Global "Cloud 2"
Building the Global "Cloud 2"Peter Coffee
 
IoT Design Principles
IoT Design PrinciplesIoT Design Principles
IoT Design Principlesardexateam
 
IBM Mobile Overview for Ecosystem Partners
IBM Mobile Overview for Ecosystem PartnersIBM Mobile Overview for Ecosystem Partners
IBM Mobile Overview for Ecosystem PartnersJeremy Siewert
 
HASH-box - Business Plan Presentation
HASH-box - Business Plan PresentationHASH-box - Business Plan Presentation
HASH-box - Business Plan PresentationPROBOTEK
 
Smart home solutions
Smart home solutionsSmart home solutions
Smart home solutionsSteve Xing
 
GetShift - IoT Devices Done Right.
GetShift - IoT Devices Done Right.GetShift - IoT Devices Done Right.
GetShift - IoT Devices Done Right.Sean Greenhalgh
 

Semelhante a ThingsConAMS 2017 - Jeff Katz - A Survey of Structural Insecurities in IoT (20)

IS201 docks
IS201 docksIS201 docks
IS201 docks
 
External Device Integration with Mobile
External Device Integration with MobileExternal Device Integration with Mobile
External Device Integration with Mobile
 
(2019) Hack All the Way Through From Fridge to Mainframe (v0.2)
(2019) Hack All the Way Through From Fridge to Mainframe (v0.2)(2019) Hack All the Way Through From Fridge to Mainframe (v0.2)
(2019) Hack All the Way Through From Fridge to Mainframe (v0.2)
 
Streaming Processes: Creating a Start-up Within a Big Corporate (Mohammad Sha...
Streaming Processes: Creating a Start-up Within a Big Corporate (Mohammad Sha...Streaming Processes: Creating a Start-up Within a Big Corporate (Mohammad Sha...
Streaming Processes: Creating a Start-up Within a Big Corporate (Mohammad Sha...
 
Written by Mark Stanislav and Tod Beardsley September 2015.docx
Written by Mark Stanislav and Tod Beardsley    September 2015.docxWritten by Mark Stanislav and Tod Beardsley    September 2015.docx
Written by Mark Stanislav and Tod Beardsley September 2015.docx
 
Written by Mark Stanislav and Tod Beardsley September 2015.docx
Written by Mark Stanislav and Tod Beardsley    September 2015.docxWritten by Mark Stanislav and Tod Beardsley    September 2015.docx
Written by Mark Stanislav and Tod Beardsley September 2015.docx
 
Connecting Above the Cloud
Connecting Above the CloudConnecting Above the Cloud
Connecting Above the Cloud
 
Mti byod wp_uk
Mti byod wp_ukMti byod wp_uk
Mti byod wp_uk
 
Wu mobile
Wu mobileWu mobile
Wu mobile
 
Consumer tech invasion
Consumer tech invasionConsumer tech invasion
Consumer tech invasion
 
Building a developer community around hardware + software
Building a developer community around hardware + softwareBuilding a developer community around hardware + software
Building a developer community around hardware + software
 
Home Security App Development.docx
Home Security App Development.docxHome Security App Development.docx
Home Security App Development.docx
 
Internet of Things- IoT Monetization Models
Internet of Things- IoT Monetization ModelsInternet of Things- IoT Monetization Models
Internet of Things- IoT Monetization Models
 
Building the Global "Cloud 2"
Building the Global "Cloud 2"Building the Global "Cloud 2"
Building the Global "Cloud 2"
 
IBM Xforce Q4 2014
IBM Xforce Q4 2014IBM Xforce Q4 2014
IBM Xforce Q4 2014
 
IoT Design Principles
IoT Design PrinciplesIoT Design Principles
IoT Design Principles
 
IBM Mobile Overview for Ecosystem Partners
IBM Mobile Overview for Ecosystem PartnersIBM Mobile Overview for Ecosystem Partners
IBM Mobile Overview for Ecosystem Partners
 
HASH-box - Business Plan Presentation
HASH-box - Business Plan PresentationHASH-box - Business Plan Presentation
HASH-box - Business Plan Presentation
 
Smart home solutions
Smart home solutionsSmart home solutions
Smart home solutions
 
GetShift - IoT Devices Done Right.
GetShift - IoT Devices Done Right.GetShift - IoT Devices Done Right.
GetShift - IoT Devices Done Right.
 

Mais de ThingsConAMS

ThingsConAMS 2017 - Mirko Ross - Internet of Shit Fails
ThingsConAMS 2017 - Mirko Ross - Internet of Shit FailsThingsConAMS 2017 - Mirko Ross - Internet of Shit Fails
ThingsConAMS 2017 - Mirko Ross - Internet of Shit FailsThingsConAMS
 
ThingsConAMS 2017 - Ame Elliott - User Experience: IoT security & privacy
ThingsConAMS 2017 - Ame Elliott - User Experience: IoT security & privacyThingsConAMS 2017 - Ame Elliott - User Experience: IoT security & privacy
ThingsConAMS 2017 - Ame Elliott - User Experience: IoT security & privacyThingsConAMS
 
Ame Elliott UX security ThingsCon 2017 workshop
Ame Elliott UX security ThingsCon 2017 workshopAme Elliott UX security ThingsCon 2017 workshop
Ame Elliott UX security ThingsCon 2017 workshopThingsConAMS
 
ThingsCon Salon 6 - Fashion Tech - WEtec
ThingsCon Salon 6 - Fashion Tech - WEtecThingsCon Salon 6 - Fashion Tech - WEtec
ThingsCon Salon 6 - Fashion Tech - WEtecThingsConAMS
 
ThingsCon Salon 6 - Fashion Tech - Eef Lubbers
ThingsCon Salon 6 - Fashion Tech - Eef LubbersThingsCon Salon 6 - Fashion Tech - Eef Lubbers
ThingsCon Salon 6 - Fashion Tech - Eef LubbersThingsConAMS
 
ThingsCon Salon 6 - Fashion Tech - Welcome - Iskander Smit
ThingsCon Salon 6 - Fashion Tech - Welcome - Iskander SmitThingsCon Salon 6 - Fashion Tech - Welcome - Iskander Smit
ThingsCon Salon 6 - Fashion Tech - Welcome - Iskander SmitThingsConAMS
 
ThingsCon Amsterdam 2016 - keynote Usman Haque
ThingsCon Amsterdam 2016 - keynote Usman Haque ThingsCon Amsterdam 2016 - keynote Usman Haque
ThingsCon Amsterdam 2016 - keynote Usman Haque ThingsConAMS
 
ThingsCon Amsterdam 2016 - Smart Citizen workshop - Usman Haque
ThingsCon Amsterdam 2016 - Smart Citizen workshop - Usman HaqueThingsCon Amsterdam 2016 - Smart Citizen workshop - Usman Haque
ThingsCon Amsterdam 2016 - Smart Citizen workshop - Usman HaqueThingsConAMS
 
ThingsCon Amsterdam 2016 - Alper Cugun
ThingsCon Amsterdam 2016 - Alper CugunThingsCon Amsterdam 2016 - Alper Cugun
ThingsCon Amsterdam 2016 - Alper CugunThingsConAMS
 
ThingsCon Amsterdam 2016 - Workshop Internet of Toys - Wouter Reeskamp
ThingsCon Amsterdam 2016 - Workshop Internet of Toys - Wouter ReeskampThingsCon Amsterdam 2016 - Workshop Internet of Toys - Wouter Reeskamp
ThingsCon Amsterdam 2016 - Workshop Internet of Toys - Wouter ReeskampThingsConAMS
 
ThingsCon Amsterdam 2016 - Welcome by Iskander Smit and Marcel Schouwenaar
ThingsCon Amsterdam 2016 - Welcome by Iskander Smit and Marcel SchouwenaarThingsCon Amsterdam 2016 - Welcome by Iskander Smit and Marcel Schouwenaar
ThingsCon Amsterdam 2016 - Welcome by Iskander Smit and Marcel SchouwenaarThingsConAMS
 
ThingsCon Amsterdam 2016 - Workshop Products as Agents - Nazli Cila, Iskander...
ThingsCon Amsterdam 2016 - Workshop Products as Agents - Nazli Cila, Iskander...ThingsCon Amsterdam 2016 - Workshop Products as Agents - Nazli Cila, Iskander...
ThingsCon Amsterdam 2016 - Workshop Products as Agents - Nazli Cila, Iskander...ThingsConAMS
 
ThingsCon Amsterdam 2016 - Block exchange - workshop intro - Chris Speed
ThingsCon Amsterdam 2016 - Block exchange - workshop intro - Chris SpeedThingsCon Amsterdam 2016 - Block exchange - workshop intro - Chris Speed
ThingsCon Amsterdam 2016 - Block exchange - workshop intro - Chris SpeedThingsConAMS
 
Helma van Rijn presents Linkx
Helma van Rijn presents Linkx Helma van Rijn presents Linkx
Helma van Rijn presents Linkx ThingsConAMS
 
Justyna Zubrycka presents Vai Kai
Justyna Zubrycka presents Vai Kai Justyna Zubrycka presents Vai Kai
Justyna Zubrycka presents Vai Kai ThingsConAMS
 
Ismael Velo Feijoo presents Misc Toys
Ismael Velo Feijoo presents Misc ToysIsmael Velo Feijoo presents Misc Toys
Ismael Velo Feijoo presents Misc ToysThingsConAMS
 
Wouter Reeskamp presents the work of StudioSophisti
Wouter Reeskamp presents the work of StudioSophisti Wouter Reeskamp presents the work of StudioSophisti
Wouter Reeskamp presents the work of StudioSophisti ThingsConAMS
 
Thingscon Salon #4 - The Things Network Eindhoven - Lorna Goulden
Thingscon Salon #4 - The Things Network Eindhoven - Lorna GouldenThingscon Salon #4 - The Things Network Eindhoven - Lorna Goulden
Thingscon Salon #4 - The Things Network Eindhoven - Lorna GouldenThingsConAMS
 
Thingscon salon 4 intro iskander smit
Thingscon salon 4 intro iskander smitThingscon salon 4 intro iskander smit
Thingscon salon 4 intro iskander smitThingsConAMS
 
Thingscon Salon 4 - DATAStudio Klaas Kuitenbrouwer
Thingscon Salon 4 - DATAStudio Klaas KuitenbrouwerThingscon Salon 4 - DATAStudio Klaas Kuitenbrouwer
Thingscon Salon 4 - DATAStudio Klaas KuitenbrouwerThingsConAMS
 

Mais de ThingsConAMS (20)

ThingsConAMS 2017 - Mirko Ross - Internet of Shit Fails
ThingsConAMS 2017 - Mirko Ross - Internet of Shit FailsThingsConAMS 2017 - Mirko Ross - Internet of Shit Fails
ThingsConAMS 2017 - Mirko Ross - Internet of Shit Fails
 
ThingsConAMS 2017 - Ame Elliott - User Experience: IoT security & privacy
ThingsConAMS 2017 - Ame Elliott - User Experience: IoT security & privacyThingsConAMS 2017 - Ame Elliott - User Experience: IoT security & privacy
ThingsConAMS 2017 - Ame Elliott - User Experience: IoT security & privacy
 
Ame Elliott UX security ThingsCon 2017 workshop
Ame Elliott UX security ThingsCon 2017 workshopAme Elliott UX security ThingsCon 2017 workshop
Ame Elliott UX security ThingsCon 2017 workshop
 
ThingsCon Salon 6 - Fashion Tech - WEtec
ThingsCon Salon 6 - Fashion Tech - WEtecThingsCon Salon 6 - Fashion Tech - WEtec
ThingsCon Salon 6 - Fashion Tech - WEtec
 
ThingsCon Salon 6 - Fashion Tech - Eef Lubbers
ThingsCon Salon 6 - Fashion Tech - Eef LubbersThingsCon Salon 6 - Fashion Tech - Eef Lubbers
ThingsCon Salon 6 - Fashion Tech - Eef Lubbers
 
ThingsCon Salon 6 - Fashion Tech - Welcome - Iskander Smit
ThingsCon Salon 6 - Fashion Tech - Welcome - Iskander SmitThingsCon Salon 6 - Fashion Tech - Welcome - Iskander Smit
ThingsCon Salon 6 - Fashion Tech - Welcome - Iskander Smit
 
ThingsCon Amsterdam 2016 - keynote Usman Haque
ThingsCon Amsterdam 2016 - keynote Usman Haque ThingsCon Amsterdam 2016 - keynote Usman Haque
ThingsCon Amsterdam 2016 - keynote Usman Haque
 
ThingsCon Amsterdam 2016 - Smart Citizen workshop - Usman Haque
ThingsCon Amsterdam 2016 - Smart Citizen workshop - Usman HaqueThingsCon Amsterdam 2016 - Smart Citizen workshop - Usman Haque
ThingsCon Amsterdam 2016 - Smart Citizen workshop - Usman Haque
 
ThingsCon Amsterdam 2016 - Alper Cugun
ThingsCon Amsterdam 2016 - Alper CugunThingsCon Amsterdam 2016 - Alper Cugun
ThingsCon Amsterdam 2016 - Alper Cugun
 
ThingsCon Amsterdam 2016 - Workshop Internet of Toys - Wouter Reeskamp
ThingsCon Amsterdam 2016 - Workshop Internet of Toys - Wouter ReeskampThingsCon Amsterdam 2016 - Workshop Internet of Toys - Wouter Reeskamp
ThingsCon Amsterdam 2016 - Workshop Internet of Toys - Wouter Reeskamp
 
ThingsCon Amsterdam 2016 - Welcome by Iskander Smit and Marcel Schouwenaar
ThingsCon Amsterdam 2016 - Welcome by Iskander Smit and Marcel SchouwenaarThingsCon Amsterdam 2016 - Welcome by Iskander Smit and Marcel Schouwenaar
ThingsCon Amsterdam 2016 - Welcome by Iskander Smit and Marcel Schouwenaar
 
ThingsCon Amsterdam 2016 - Workshop Products as Agents - Nazli Cila, Iskander...
ThingsCon Amsterdam 2016 - Workshop Products as Agents - Nazli Cila, Iskander...ThingsCon Amsterdam 2016 - Workshop Products as Agents - Nazli Cila, Iskander...
ThingsCon Amsterdam 2016 - Workshop Products as Agents - Nazli Cila, Iskander...
 
ThingsCon Amsterdam 2016 - Block exchange - workshop intro - Chris Speed
ThingsCon Amsterdam 2016 - Block exchange - workshop intro - Chris SpeedThingsCon Amsterdam 2016 - Block exchange - workshop intro - Chris Speed
ThingsCon Amsterdam 2016 - Block exchange - workshop intro - Chris Speed
 
Helma van Rijn presents Linkx
Helma van Rijn presents Linkx Helma van Rijn presents Linkx
Helma van Rijn presents Linkx
 
Justyna Zubrycka presents Vai Kai
Justyna Zubrycka presents Vai Kai Justyna Zubrycka presents Vai Kai
Justyna Zubrycka presents Vai Kai
 
Ismael Velo Feijoo presents Misc Toys
Ismael Velo Feijoo presents Misc ToysIsmael Velo Feijoo presents Misc Toys
Ismael Velo Feijoo presents Misc Toys
 
Wouter Reeskamp presents the work of StudioSophisti
Wouter Reeskamp presents the work of StudioSophisti Wouter Reeskamp presents the work of StudioSophisti
Wouter Reeskamp presents the work of StudioSophisti
 
Thingscon Salon #4 - The Things Network Eindhoven - Lorna Goulden
Thingscon Salon #4 - The Things Network Eindhoven - Lorna GouldenThingscon Salon #4 - The Things Network Eindhoven - Lorna Goulden
Thingscon Salon #4 - The Things Network Eindhoven - Lorna Goulden
 
Thingscon salon 4 intro iskander smit
Thingscon salon 4 intro iskander smitThingscon salon 4 intro iskander smit
Thingscon salon 4 intro iskander smit
 
Thingscon Salon 4 - DATAStudio Klaas Kuitenbrouwer
Thingscon Salon 4 - DATAStudio Klaas KuitenbrouwerThingscon Salon 4 - DATAStudio Klaas Kuitenbrouwer
Thingscon Salon 4 - DATAStudio Klaas Kuitenbrouwer
 

Último

Pooja 9892124323, Call girls Services and Mumbai Escort Service Near Hotel Gi...
Pooja 9892124323, Call girls Services and Mumbai Escort Service Near Hotel Gi...Pooja 9892124323, Call girls Services and Mumbai Escort Service Near Hotel Gi...
Pooja 9892124323, Call girls Services and Mumbai Escort Service Near Hotel Gi...Pooja Nehwal
 
Top Rated Pune Call Girls Saswad ⟟ 6297143586 ⟟ Call Me For Genuine Sex Serv...
Top Rated  Pune Call Girls Saswad ⟟ 6297143586 ⟟ Call Me For Genuine Sex Serv...Top Rated  Pune Call Girls Saswad ⟟ 6297143586 ⟟ Call Me For Genuine Sex Serv...
Top Rated Pune Call Girls Saswad ⟟ 6297143586 ⟟ Call Me For Genuine Sex Serv...Call Girls in Nagpur High Profile
 
call girls in Dakshinpuri (DELHI) 🔝 >༒9953056974 🔝 genuine Escort Service 🔝✔️✔️
call girls in Dakshinpuri  (DELHI) 🔝 >༒9953056974 🔝 genuine Escort Service 🔝✔️✔️call girls in Dakshinpuri  (DELHI) 🔝 >༒9953056974 🔝 genuine Escort Service 🔝✔️✔️
call girls in Dakshinpuri (DELHI) 🔝 >༒9953056974 🔝 genuine Escort Service 🔝✔️✔️9953056974 Low Rate Call Girls In Saket, Delhi NCR
 
8377087607, Door Step Call Girls In Kalkaji (Locanto) 24/7 Available
8377087607, Door Step Call Girls In Kalkaji (Locanto) 24/7 Available8377087607, Door Step Call Girls In Kalkaji (Locanto) 24/7 Available
8377087607, Door Step Call Girls In Kalkaji (Locanto) 24/7 Availabledollysharma2066
 
❤Personal Whatsapp Number 8617697112 Samba Call Girls 💦✅.
❤Personal Whatsapp Number 8617697112 Samba Call Girls 💦✅.❤Personal Whatsapp Number 8617697112 Samba Call Girls 💦✅.
❤Personal Whatsapp Number 8617697112 Samba Call Girls 💦✅.Nitya salvi
 
Sweety Planet Packaging Design Process Book.pptx
Sweety Planet Packaging Design Process Book.pptxSweety Planet Packaging Design Process Book.pptx
Sweety Planet Packaging Design Process Book.pptxbingyichin04
 
Jordan_Amanda_DMBS202404_PB1_2024-04.pdf
Jordan_Amanda_DMBS202404_PB1_2024-04.pdfJordan_Amanda_DMBS202404_PB1_2024-04.pdf
Jordan_Amanda_DMBS202404_PB1_2024-04.pdfamanda2495
 
RT Nagar Call Girls Service: 🍓 7737669865 🍓 High Profile Model Escorts | Bang...
RT Nagar Call Girls Service: 🍓 7737669865 🍓 High Profile Model Escorts | Bang...RT Nagar Call Girls Service: 🍓 7737669865 🍓 High Profile Model Escorts | Bang...
RT Nagar Call Girls Service: 🍓 7737669865 🍓 High Profile Model Escorts | Bang...amitlee9823
 
💫✅jodhpur 24×7 BEST GENUINE PERSON LOW PRICE CALL GIRL SERVICE FULL SATISFACT...
💫✅jodhpur 24×7 BEST GENUINE PERSON LOW PRICE CALL GIRL SERVICE FULL SATISFACT...💫✅jodhpur 24×7 BEST GENUINE PERSON LOW PRICE CALL GIRL SERVICE FULL SATISFACT...
💫✅jodhpur 24×7 BEST GENUINE PERSON LOW PRICE CALL GIRL SERVICE FULL SATISFACT...sonalitrivedi431
 
Peaches App development presentation deck
Peaches App development presentation deckPeaches App development presentation deck
Peaches App development presentation decktbatkhuu1
 
Vip Mumbai Call Girls Bandra West Call On 9920725232 With Body to body massag...
Vip Mumbai Call Girls Bandra West Call On 9920725232 With Body to body massag...Vip Mumbai Call Girls Bandra West Call On 9920725232 With Body to body massag...
Vip Mumbai Call Girls Bandra West Call On 9920725232 With Body to body massag...amitlee9823
 
Recommendable # 971589162217 # philippine Young Call Girls in Dubai By Marina...
Recommendable # 971589162217 # philippine Young Call Girls in Dubai By Marina...Recommendable # 971589162217 # philippine Young Call Girls in Dubai By Marina...
Recommendable # 971589162217 # philippine Young Call Girls in Dubai By Marina...home
 
Brookefield Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
Brookefield Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...Brookefield Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
Brookefield Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...amitlee9823
 
Design Inspiration for College by Slidesgo.pptx
Design Inspiration for College by Slidesgo.pptxDesign Inspiration for College by Slidesgo.pptx
Design Inspiration for College by Slidesgo.pptxTusharBahuguna2
 
Editorial design Magazine design project.pdf
Editorial design Magazine design project.pdfEditorial design Magazine design project.pdf
Editorial design Magazine design project.pdftbatkhuu1
 
HiFi Call Girl Service Delhi Phone ☞ 9899900591 ☜ Escorts Service at along wi...
HiFi Call Girl Service Delhi Phone ☞ 9899900591 ☜ Escorts Service at along wi...HiFi Call Girl Service Delhi Phone ☞ 9899900591 ☜ Escorts Service at along wi...
HiFi Call Girl Service Delhi Phone ☞ 9899900591 ☜ Escorts Service at along wi...poojakaurpk09
 
WhatsApp Chat: 📞 8617697112 Call Girl Baran is experienced
WhatsApp Chat: 📞 8617697112 Call Girl Baran is experiencedWhatsApp Chat: 📞 8617697112 Call Girl Baran is experienced
WhatsApp Chat: 📞 8617697112 Call Girl Baran is experiencedNitya salvi
 
Verified Trusted Call Girls Adugodi💘 9352852248 Good Looking standard Profil...
Verified Trusted Call Girls Adugodi💘 9352852248  Good Looking standard Profil...Verified Trusted Call Girls Adugodi💘 9352852248  Good Looking standard Profil...
Verified Trusted Call Girls Adugodi💘 9352852248 Good Looking standard Profil...kumaririma588
 
Abortion pill for sale in Muscat (+918761049707)) Get Cytotec Cash on deliver...
Abortion pill for sale in Muscat (+918761049707)) Get Cytotec Cash on deliver...Abortion pill for sale in Muscat (+918761049707)) Get Cytotec Cash on deliver...
Abortion pill for sale in Muscat (+918761049707)) Get Cytotec Cash on deliver...instagramfab782445
 
Whitefield Call Girls Service: 🍓 7737669865 🍓 High Profile Model Escorts | Ba...
Whitefield Call Girls Service: 🍓 7737669865 🍓 High Profile Model Escorts | Ba...Whitefield Call Girls Service: 🍓 7737669865 🍓 High Profile Model Escorts | Ba...
Whitefield Call Girls Service: 🍓 7737669865 🍓 High Profile Model Escorts | Ba...amitlee9823
 

Último (20)

Pooja 9892124323, Call girls Services and Mumbai Escort Service Near Hotel Gi...
Pooja 9892124323, Call girls Services and Mumbai Escort Service Near Hotel Gi...Pooja 9892124323, Call girls Services and Mumbai Escort Service Near Hotel Gi...
Pooja 9892124323, Call girls Services and Mumbai Escort Service Near Hotel Gi...
 
Top Rated Pune Call Girls Saswad ⟟ 6297143586 ⟟ Call Me For Genuine Sex Serv...
Top Rated  Pune Call Girls Saswad ⟟ 6297143586 ⟟ Call Me For Genuine Sex Serv...Top Rated  Pune Call Girls Saswad ⟟ 6297143586 ⟟ Call Me For Genuine Sex Serv...
Top Rated Pune Call Girls Saswad ⟟ 6297143586 ⟟ Call Me For Genuine Sex Serv...
 
call girls in Dakshinpuri (DELHI) 🔝 >༒9953056974 🔝 genuine Escort Service 🔝✔️✔️
call girls in Dakshinpuri  (DELHI) 🔝 >༒9953056974 🔝 genuine Escort Service 🔝✔️✔️call girls in Dakshinpuri  (DELHI) 🔝 >༒9953056974 🔝 genuine Escort Service 🔝✔️✔️
call girls in Dakshinpuri (DELHI) 🔝 >༒9953056974 🔝 genuine Escort Service 🔝✔️✔️
 
8377087607, Door Step Call Girls In Kalkaji (Locanto) 24/7 Available
8377087607, Door Step Call Girls In Kalkaji (Locanto) 24/7 Available8377087607, Door Step Call Girls In Kalkaji (Locanto) 24/7 Available
8377087607, Door Step Call Girls In Kalkaji (Locanto) 24/7 Available
 
❤Personal Whatsapp Number 8617697112 Samba Call Girls 💦✅.
❤Personal Whatsapp Number 8617697112 Samba Call Girls 💦✅.❤Personal Whatsapp Number 8617697112 Samba Call Girls 💦✅.
❤Personal Whatsapp Number 8617697112 Samba Call Girls 💦✅.
 
Sweety Planet Packaging Design Process Book.pptx
Sweety Planet Packaging Design Process Book.pptxSweety Planet Packaging Design Process Book.pptx
Sweety Planet Packaging Design Process Book.pptx
 
Jordan_Amanda_DMBS202404_PB1_2024-04.pdf
Jordan_Amanda_DMBS202404_PB1_2024-04.pdfJordan_Amanda_DMBS202404_PB1_2024-04.pdf
Jordan_Amanda_DMBS202404_PB1_2024-04.pdf
 
RT Nagar Call Girls Service: 🍓 7737669865 🍓 High Profile Model Escorts | Bang...
RT Nagar Call Girls Service: 🍓 7737669865 🍓 High Profile Model Escorts | Bang...RT Nagar Call Girls Service: 🍓 7737669865 🍓 High Profile Model Escorts | Bang...
RT Nagar Call Girls Service: 🍓 7737669865 🍓 High Profile Model Escorts | Bang...
 
💫✅jodhpur 24×7 BEST GENUINE PERSON LOW PRICE CALL GIRL SERVICE FULL SATISFACT...
💫✅jodhpur 24×7 BEST GENUINE PERSON LOW PRICE CALL GIRL SERVICE FULL SATISFACT...💫✅jodhpur 24×7 BEST GENUINE PERSON LOW PRICE CALL GIRL SERVICE FULL SATISFACT...
💫✅jodhpur 24×7 BEST GENUINE PERSON LOW PRICE CALL GIRL SERVICE FULL SATISFACT...
 
Peaches App development presentation deck
Peaches App development presentation deckPeaches App development presentation deck
Peaches App development presentation deck
 
Vip Mumbai Call Girls Bandra West Call On 9920725232 With Body to body massag...
Vip Mumbai Call Girls Bandra West Call On 9920725232 With Body to body massag...Vip Mumbai Call Girls Bandra West Call On 9920725232 With Body to body massag...
Vip Mumbai Call Girls Bandra West Call On 9920725232 With Body to body massag...
 
Recommendable # 971589162217 # philippine Young Call Girls in Dubai By Marina...
Recommendable # 971589162217 # philippine Young Call Girls in Dubai By Marina...Recommendable # 971589162217 # philippine Young Call Girls in Dubai By Marina...
Recommendable # 971589162217 # philippine Young Call Girls in Dubai By Marina...
 
Brookefield Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
Brookefield Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...Brookefield Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
Brookefield Call Girls: 🍓 7737669865 🍓 High Profile Model Escorts | Bangalore...
 
Design Inspiration for College by Slidesgo.pptx
Design Inspiration for College by Slidesgo.pptxDesign Inspiration for College by Slidesgo.pptx
Design Inspiration for College by Slidesgo.pptx
 
Editorial design Magazine design project.pdf
Editorial design Magazine design project.pdfEditorial design Magazine design project.pdf
Editorial design Magazine design project.pdf
 
HiFi Call Girl Service Delhi Phone ☞ 9899900591 ☜ Escorts Service at along wi...
HiFi Call Girl Service Delhi Phone ☞ 9899900591 ☜ Escorts Service at along wi...HiFi Call Girl Service Delhi Phone ☞ 9899900591 ☜ Escorts Service at along wi...
HiFi Call Girl Service Delhi Phone ☞ 9899900591 ☜ Escorts Service at along wi...
 
WhatsApp Chat: 📞 8617697112 Call Girl Baran is experienced
WhatsApp Chat: 📞 8617697112 Call Girl Baran is experiencedWhatsApp Chat: 📞 8617697112 Call Girl Baran is experienced
WhatsApp Chat: 📞 8617697112 Call Girl Baran is experienced
 
Verified Trusted Call Girls Adugodi💘 9352852248 Good Looking standard Profil...
Verified Trusted Call Girls Adugodi💘 9352852248  Good Looking standard Profil...Verified Trusted Call Girls Adugodi💘 9352852248  Good Looking standard Profil...
Verified Trusted Call Girls Adugodi💘 9352852248 Good Looking standard Profil...
 
Abortion pill for sale in Muscat (+918761049707)) Get Cytotec Cash on deliver...
Abortion pill for sale in Muscat (+918761049707)) Get Cytotec Cash on deliver...Abortion pill for sale in Muscat (+918761049707)) Get Cytotec Cash on deliver...
Abortion pill for sale in Muscat (+918761049707)) Get Cytotec Cash on deliver...
 
Whitefield Call Girls Service: 🍓 7737669865 🍓 High Profile Model Escorts | Ba...
Whitefield Call Girls Service: 🍓 7737669865 🍓 High Profile Model Escorts | Ba...Whitefield Call Girls Service: 🍓 7737669865 🍓 High Profile Model Escorts | Ba...
Whitefield Call Girls Service: 🍓 7737669865 🍓 High Profile Model Escorts | Ba...
 

ThingsConAMS 2017 - Jeff Katz - A Survey of Structural Insecurities in IoT

  • 1. A Survey of Structural Insecurities in IoT Jeff Katz Senior Practice Lead IT / Engineering Telefónica Germany NEXT GmbH
  • 2. » The problem with this process is that no one entity has any incentive, expertise, or even ability to patch the software once it's shipped… We simply have to fix this. « -BRUCE SCHNEIER, Wired, 2014
  • 3. Agenda – Relevant quote – Agenda – Speaker Info – Sales – Channels – Retail deep-dive – Telefónica – Geeny ~20 minutes | english 3
  • 4. Jeff Katz – American living in Germany for six years – Founded companies in Finance, IT, Security – Founded hardware accelerator called HARDWARE.co – Spoken around the world on Security and Privacy in IoT – Background in Electrical Engineering and Embedded Development – Currently working for Telefónica NEXT on IoT Platform 4
  • 5. What’s IoT? 5 • Industrial • Agricultural • Smart City • Consumer (Smart Home, etc.)
  • 6. There are forecast to be 28 billion connected devices worldwide by 2021 Almost 16 billion of them will be loT devices loT devices will over-take mobile phones as the largest category of connected devices in 2018 This will be driven by the spread of smart meters and connected cars, as well as by consumer devices The number of loT devices in Western Europe is projected to quadruple between 2015 and 2021 The Consumer IoT Market
  • 7. How an idea becomes an IoT solution – Let’s pretend: We are ”Melkin” a multinational consumer device company, and we want to make a connected baby monitor – Two-way audio streaming, there’s an app, etc. Let’s explore who is involved to bring this product to shelves 7 Any resemblance to any real companies or products is strictly coincidental and not intended. This is not the story of a real product.
  • 8. The Service – We’re going to start with the App, and what we want the user experience to be – External design agency engaged – Click-dummy delivered – External app agency engaged – iOS, Android, etc. delivered under budget and time pressure – Often developed before the hardware is even done 8
  • 9. The ODM – Factory in Guangzhou, China – Manufactures Baby Monitors for many multinational companies – Take existing model that matches our requirements – Develop new plastics for it – Firmware based on reference design from Chipset Manufacturer – Completely white-label (This is a real company and this is really how this works) 9
  • 10. The Chipset Manufacturer – Wants to sell chips – Provides bare-minimum reference designs that show how to get something working – Not responsible for end product, at all. 10
  • 11. The Branded Device – Purchased at retail from Big Box Store – Provides the data and interface to provide the service – What the customer installs in their home, next to their baby – Connects to home WIFI – Firmware developed by agency, based on reference from the ODM – Melkin is responsible for warranty, sales, support, etc 11
  • 12. The Platform – Needs to connect the service to the device – Should have minimal impact on the final cost of the device – Contracted by a third party, either build or buy—Melkin doesn’t want to deal with it. Best case, fully outsourced and managed. Worst- case: Managed by Melkin – Provides examples (firmware, app) how to communicate with it – Example: Arrayent 12
  • 13. Overview – App design: Outsourced – App implementation: Outsourced – Hardware Design: Outsourced – Firmware: Outsourced, based on Outsourced example from Outsourced Chipset example – Platform: Outsourced – Seller: Retail Store – Connectivity: Home WIFI (ISP), Home Router – Final Product Responsibility: Melkin 13
  • 14. What to do / Where to address? – Let’s fix the perverse incentives: Companies require security but actively choose against suppliers who price it in to offers. – GDPR huge help—significant fines for bad behavior for end responsible company – Need to spread responsibility to all involved parties – Proliferation of bad examples: Let’s build security in from the very beginning—Chipset manufacturers, Reference Designs, etc. – Education and guides on what to look for in products – More openness: Open source, open spec, open APIs, – Financial incentives, positive or negative 14
  • 15. Thank you. Let’s talk! Jeff Katz Senior Practice Lead IT / Engineering Telefónica Germany NEXT GmbH jeff@geeny.io • jeff.katz@telefonica.com • @kraln https://developers.geeny.io join the Geeny developer community