SlideShare une entreprise Scribd logo
1  sur  18
Télécharger pour lire hors ligne
Internet of Things (IoT) Midlands UK
Opening the Internet of Things:
for security, compatibility... and profit
by
Joe Fortey
jfortey [at] yahoo.com
(replace “at” with “@”)
Meetup #6: Show and Tell: 7pm Tuesday, July 29, 2014
Due to an issue in the application used to create this slideshow,
some web links may be rendered in a pale font.
All links should still be clickable, but if you have any problems,
please copy and paste links to your browser to access the websites.
The LIFX IoT Lightbulb
http://lifx.co/
- IoT lightbulbs, controllable from a smart phone,
connected in a mesh network, and to the
home network.
www.kickstarter.com/projects/limemouse/lifx-the-light-bulb-reinvented
- LIFX Kickstarter campaign, from Nov. 2012
The LIFX security breach
Security breach links:
http://contextis.com/blog/hacking-internet-connected-light-bulbs/
- the original blog on the LIFX hack, by the hackers.
www.arstechnica.com/security/2014/07/crypto-weakness-in-smart-led-lightbulbs-exposes-wi-fi-passwords/
- Tech press report on the breach.
The hacked and hacking tech:
https://en.wikipedia.org/wiki/6LoWPAN - 6LoWPAN Mesh network, used by LIFX. 6LoWPAN is an acronym of
IPv6 over Low power Wireless Personal Area Networks.
https://en.wikipedia.org/wiki/JTAG - The pin system used to hack the bulb
Bus-
blaster
JTAG
debugger
LIFX breach - security expert feedback
from “Security Now” Podcast 463, 8th July 2014 (1 of 2)
Steve Gibson:
"We've got secure protocols for doing all the kinds of
common things we want [on the Internet]... well-
established, very secure, bulletproof protocols. But we
don't have anything like that for the Internet of Things.
And so companies like [LIFX] are just making stuff up.
They're saying, well, you know, we're going to solve the
problem because there is no RFC yet for it. Well, we
need [an RFC]."
continued...
N.B. RFC = “Request for Comments”, see: https://en.wikipedia.org/wiki/Request_for_Comments -
"A Request for Comments (RFC) is a publication of the Internet Engineering Task Force (IETF) and the Internet Society,
the principal technical development and standards-setting bodies for the Internet. An RFC is authored by engineers and
computer scientists in the form of a memorandum describing methods, behaviours, research, or innovations applicable to
the working of the Internet and Internet-connected systems. It is submitted either for peer review or simply to convey
new concepts, information, or (occasionally) engineering humour. The IETF adopts some of the proposals published as
RFCs as Internet standards."
LIFX breach - security expert feedback
from “Security Now” Podcast 463, 8th July 2014 (2 of 2)
continued...
Fr. Robert Ballecer (edition show host):
"...This is just an example of Security Through
Obscurity. They figured, well, yeah, okay, we're using
a static key, but we're going to bake it into a chip that
no one will have access to. They won't be able to read
it, and it'll be fine. And any security expert worth his
salt would have sat next to them and said, "You know
you can't ever assume that anything you bake into an
IC is going to stay hidden."
Security flaws? - Not just start-ups!
Philips Smart lightbulbs suffer malware attacks:
http://arstechnica.com/security/2013/08/philips-hue-lights-malware-hack/
Belkin baby monitor hack:
http://www.mocana.com/blog/2013/10/25/baby-monitors-can-hacked/
Belkin WeMo hack:
http://www.cnet.com/uk/news/belkin-wemo-smart-home-networks-in-danger-of-hacks/
Not-so-smart super-loo? Maybe I'll just pass on that....
(screen-shot of an article from http://www.digitaltrends.com/home/smart-toilet-security-flaw/)
Not only security and privacy:
Proprietary, single-company development in short time-scales
(Internet time scales) may mean:
 unstable system designs, or
 poor implementation of good designs
But even if it is secure, is it compatible?
The IoT is about connectivity - of everything.
Without compatibility, it will remain....
...a sea of independent, isolated islands
of proprietary technology
The proprietary tech problem
On their own, SMEs and start-ups have limited
resources to do security and connectivity
successfully, or to build sufficient market share
to dominate in their sector.
Commercial protocols, platforms and standards
(e.g. Apple) may be:
 expensive to licence
 restrictive in who is allowed to partner
 Still subject to market forces / security
compromises / obsolescence
Options for the rest of us
1) Make do with a small market share and
possibly some big, nasty support issues
2) Sell out to a bigger business (if you can)
3) Collaborate with other businesses to build
common, open solutions
Current Open-IoT projects & initiatives
https://allseenalliance.org/ - The AllSeen Alliance, Led by the Linux Foundation, with perhaps the broadest remit and currently
largest in terms of members (see next slide).
https://www.alljoyn.org/ - Open source initiative from Qualcomm, this technology forms the basis of the AllSeen Alliance project.
http://www.hypercat.io/ - A UK-based initiative with 40+ members in public and private sectors, focused specifically on an open
information protocol for the IoT.
http://www.iiconsortium.org/ - An alliance with 60+ members, focused on industrial IoT implementations. Members include Intel,
IBM, AT&T, GE and Cisco and Microsoft.
http://www.openinterconnect.org/ - An alliance between six large businesses including: Atmel, Broadcom, Dell, Intel, Samsung
and Wind River, focused on open standards and solutions
http://www.threadgroup.org/ - A new wireless protocol, based on IEEE 802.15.4, compatible with objectives of some of the
other alliances. Parners include: Google's NEST Labs, Samsung, ARM, Freescale, Big Ass Fans, Silicon Labs, Yale Security.
http://openiot.eu/ - Open IoT middleware initiative, between a partnership of EU public and educational organisations.
http://standards.ieee.org/innovate/iot/ - Institute of Electrical and Electronics Engineers initiative for IoT standards.
http://www.itu.int/en/ITU-T/gsi/iot/Pages/default.aspx - The International Telecommunication Union initiative for IoT standards.
http://www.ipso-alliance.org/ - An alliance focused on auditing and analysis of standards developed by other groups
www.iot-competition.com - Smaller-scale initiative run as a competition, by Elector Magazine and Embedded Projects Journal,
(deadline: 1st August 2014).
...if you know of any more groups or initiatives, please get in touch.
AllSeen Alliance: some current members (note those I have circled!)
Additional resources
https://developer.apple.com/homekit/ - Apple's initiative for compatibility between
smart devices in the home - not an open standard, but partners include: Philips,
iHome, Osram Sylvania and Texas Instruments
http://www.ietf.org/ - Internet Engineering Task Force - a body responsible for
addressing broader internet standards and compatibility issues
http://www.ohwr.org/ - Open Hardware Repository, an initiative supported by CERN to
back development and sharing of open hardware solutions
https://opencryptoaudit.org/ - For open tech to succeed, a good audit culture needs to
be established. Here's one initiative, for open source crypto software and applications
https://www.grc.com/securitynow.htm - a useful resource for security news and
analysis
Conclusions
The recent proliferation of partnerships and projects aiming to address the issue
of IoT standards is encouraging, but warrants caution. Unless a focus is
maintained on truly open solutions, these groups will be tempted to compete
rather than collaborate, limiting progress and frustrating the intended
objectives for these initiatives.
Standardisation is important but openness even more so, to ensure freedom of
partner groups to share and integrate the best technology and solutions
without licensing or other legal restrictions, benefiting all parties equally and
accelerating progress.
It would be helpful for existing groups to communicate, seek common ground
and where possible, consolidate around solutions which are open in both
name and design, so that growth of a secure, compatible Internet of Things
can proceed unhindered.
© Joe Fortey, 2014

Contenu connexe

Tendances

ThingsConAMS 2017 - Mirko Ross - Internet of Shit Fails
ThingsConAMS 2017 - Mirko Ross - Internet of Shit FailsThingsConAMS 2017 - Mirko Ross - Internet of Shit Fails
ThingsConAMS 2017 - Mirko Ross - Internet of Shit FailsThingsConAMS
 
BCS ITNow 201409 - What's Going On
BCS ITNow 201409 - What's Going OnBCS ITNow 201409 - What's Going On
BCS ITNow 201409 - What's Going OnGareth Niblett
 
Webinar: Secure Offline and Online Updates for Linux Devices
Webinar: Secure Offline and Online Updates for Linux DevicesWebinar: Secure Offline and Online Updates for Linux Devices
Webinar: Secure Offline and Online Updates for Linux DevicesToradex
 
What in the World is Going on at The Linux Foundation?
What in the World is Going on at The Linux Foundation?What in the World is Going on at The Linux Foundation?
What in the World is Going on at The Linux Foundation?Black Duck by Synopsys
 
Internet of Things... Let's Not Forget Security Please!, by Eric Vyncke [APNI...
Internet of Things... Let's Not Forget Security Please!, by Eric Vyncke [APNI...Internet of Things... Let's Not Forget Security Please!, by Eric Vyncke [APNI...
Internet of Things... Let's Not Forget Security Please!, by Eric Vyncke [APNI...APNIC
 
IoT smart parking space
IoT smart parking space IoT smart parking space
IoT smart parking space mohamed elmasry
 
Strategies to Reap the Benefits of Software Patents in an Open Source Softwar...
Strategies to Reap the Benefits of Software Patents in an Open Source Softwar...Strategies to Reap the Benefits of Software Patents in an Open Source Softwar...
Strategies to Reap the Benefits of Software Patents in an Open Source Softwar...Black Duck by Synopsys
 
SFScon 2020 - Davide Ricci - FOSS management and license compliance must come...
SFScon 2020 - Davide Ricci - FOSS management and license compliance must come...SFScon 2020 - Davide Ricci - FOSS management and license compliance must come...
SFScon 2020 - Davide Ricci - FOSS management and license compliance must come...South Tyrol Free Software Conference
 
beware of Thing Bot
beware of Thing Botbeware of Thing Bot
beware of Thing BotBellaj Badr
 
ASEAN-JAPAN Cyber Security Seminar: How to fill your team gaps with training
ASEAN-JAPAN Cyber Security Seminar: How to fill your team gaps with trainingASEAN-JAPAN Cyber Security Seminar: How to fill your team gaps with training
ASEAN-JAPAN Cyber Security Seminar: How to fill your team gaps with trainingAPNIC
 
ICT Security 2010: Le minacce delle nuove tecnologie
ICT Security 2010: Le minacce delle nuove tecnologieICT Security 2010: Le minacce delle nuove tecnologie
ICT Security 2010: Le minacce delle nuove tecnologieAlessio Pennasilico
 
Cybersecurity and Internet Governance
Cybersecurity and Internet GovernanceCybersecurity and Internet Governance
Cybersecurity and Internet GovernanceKenny Huang Ph.D.
 
Webinar–You've Got Your Open Source Audit Report–Now What?
Webinar–You've Got Your Open Source Audit Report–Now What? Webinar–You've Got Your Open Source Audit Report–Now What?
Webinar–You've Got Your Open Source Audit Report–Now What? Synopsys Software Integrity Group
 
The IoT: Internet of Threats?
The IoT: Internet of Threats?The IoT: Internet of Threats?
The IoT: Internet of Threats?TechWell
 
Open Source Movement
Open Source MovementOpen Source Movement
Open Source MovementMesut Yılmaz
 

Tendances (20)

2011 NASA Open Source Summit - Forge.mil
2011 NASA Open Source Summit - Forge.mil2011 NASA Open Source Summit - Forge.mil
2011 NASA Open Source Summit - Forge.mil
 
ThingsConAMS 2017 - Mirko Ross - Internet of Shit Fails
ThingsConAMS 2017 - Mirko Ross - Internet of Shit FailsThingsConAMS 2017 - Mirko Ross - Internet of Shit Fails
ThingsConAMS 2017 - Mirko Ross - Internet of Shit Fails
 
BCS ITNow 201409 - What's Going On
BCS ITNow 201409 - What's Going OnBCS ITNow 201409 - What's Going On
BCS ITNow 201409 - What's Going On
 
Webinar: Secure Offline and Online Updates for Linux Devices
Webinar: Secure Offline and Online Updates for Linux DevicesWebinar: Secure Offline and Online Updates for Linux Devices
Webinar: Secure Offline and Online Updates for Linux Devices
 
Iot ppt
Iot pptIot ppt
Iot ppt
 
What in the World is Going on at The Linux Foundation?
What in the World is Going on at The Linux Foundation?What in the World is Going on at The Linux Foundation?
What in the World is Going on at The Linux Foundation?
 
Internet of Things... Let's Not Forget Security Please!, by Eric Vyncke [APNI...
Internet of Things... Let's Not Forget Security Please!, by Eric Vyncke [APNI...Internet of Things... Let's Not Forget Security Please!, by Eric Vyncke [APNI...
Internet of Things... Let's Not Forget Security Please!, by Eric Vyncke [APNI...
 
IoT smart parking space
IoT smart parking space IoT smart parking space
IoT smart parking space
 
Strategies to Reap the Benefits of Software Patents in an Open Source Softwar...
Strategies to Reap the Benefits of Software Patents in an Open Source Softwar...Strategies to Reap the Benefits of Software Patents in an Open Source Softwar...
Strategies to Reap the Benefits of Software Patents in an Open Source Softwar...
 
SFScon 2020 - Davide Ricci - FOSS management and license compliance must come...
SFScon 2020 - Davide Ricci - FOSS management and license compliance must come...SFScon 2020 - Davide Ricci - FOSS management and license compliance must come...
SFScon 2020 - Davide Ricci - FOSS management and license compliance must come...
 
beware of Thing Bot
beware of Thing Botbeware of Thing Bot
beware of Thing Bot
 
ASEAN-JAPAN Cyber Security Seminar: How to fill your team gaps with training
ASEAN-JAPAN Cyber Security Seminar: How to fill your team gaps with trainingASEAN-JAPAN Cyber Security Seminar: How to fill your team gaps with training
ASEAN-JAPAN Cyber Security Seminar: How to fill your team gaps with training
 
AEGIS Newsletter 4
AEGIS Newsletter 4AEGIS Newsletter 4
AEGIS Newsletter 4
 
ICT Security 2010: Le minacce delle nuove tecnologie
ICT Security 2010: Le minacce delle nuove tecnologieICT Security 2010: Le minacce delle nuove tecnologie
ICT Security 2010: Le minacce delle nuove tecnologie
 
Cybersecurity and Internet Governance
Cybersecurity and Internet GovernanceCybersecurity and Internet Governance
Cybersecurity and Internet Governance
 
Webinar–You've Got Your Open Source Audit Report–Now What?
Webinar–You've Got Your Open Source Audit Report–Now What? Webinar–You've Got Your Open Source Audit Report–Now What?
Webinar–You've Got Your Open Source Audit Report–Now What?
 
The IoT: Internet of Threats?
The IoT: Internet of Threats?The IoT: Internet of Threats?
The IoT: Internet of Threats?
 
Webinar–What You Need To Know About Open Source Licensing
Webinar–What You Need To Know About Open Source LicensingWebinar–What You Need To Know About Open Source Licensing
Webinar–What You Need To Know About Open Source Licensing
 
Open Source Movement
Open Source MovementOpen Source Movement
Open Source Movement
 
Webinar–That is Not How This Works
Webinar–That is Not How This WorksWebinar–That is Not How This Works
Webinar–That is Not How This Works
 

Similaire à Opening the IoT - Joe Fortey - IoT Midlands Meet Up - 29/07/14

Supply Chain Security and Compliance for Embedded Devices & IoT
Supply Chain Security and Compliance for Embedded Devices & IoTSupply Chain Security and Compliance for Embedded Devices & IoT
Supply Chain Security and Compliance for Embedded Devices & IoTSource Code Control Limited
 
The Internet of Things: We've Got to Chat
The Internet of Things: We've Got to ChatThe Internet of Things: We've Got to Chat
The Internet of Things: We've Got to ChatDuo Security
 
Home automation using internet of things
Home automation using internet of thingsHome automation using internet of things
Home automation using internet of thingsAbhishek Bhadoria
 
OASIS: open source and open standards: internet of things
OASIS: open source and open standards: internet of thingsOASIS: open source and open standards: internet of things
OASIS: open source and open standards: internet of thingsJamie Clark
 
OASIS: How open source and open standards work together: the Internet of Things
OASIS: How open source and open standards work together: the Internet of ThingsOASIS: How open source and open standards work together: the Internet of Things
OASIS: How open source and open standards work together: the Internet of ThingsJames Bryce Clark
 
Open Source Insight: Securing IoT, Atlanta Ransomware Attack, Congress on Cyb...
Open Source Insight: Securing IoT, Atlanta Ransomware Attack, Congress on Cyb...Open Source Insight: Securing IoT, Atlanta Ransomware Attack, Congress on Cyb...
Open Source Insight: Securing IoT, Atlanta Ransomware Attack, Congress on Cyb...Black Duck by Synopsys
 
FI-WARE Basic Guide
FI-WARE Basic GuideFI-WARE Basic Guide
FI-WARE Basic GuideFIWARE
 
Standards and Open Source for Big Data, Cloud, and IoT
Standards and Open Source for Big Data, Cloud, and IoTStandards and Open Source for Big Data, Cloud, and IoT
Standards and Open Source for Big Data, Cloud, and IoTBob Marcus
 
The Internet of Things
The Internet of ThingsThe Internet of Things
The Internet of ThingsOmkar Shinge
 
4.Jan Holler, Vlasios Tsiatsis, Catherine Mulligan, Stefan Avesand, Stamatis ...
4.Jan Holler, Vlasios Tsiatsis, Catherine Mulligan, Stefan Avesand, Stamatis ...4.Jan Holler, Vlasios Tsiatsis, Catherine Mulligan, Stefan Avesand, Stamatis ...
4.Jan Holler, Vlasios Tsiatsis, Catherine Mulligan, Stefan Avesand, Stamatis ...huong Tran thu
 
IoT Security Risks and Challenges
IoT Security Risks and ChallengesIoT Security Risks and Challenges
IoT Security Risks and ChallengesOWASP Delhi
 
Exploring open hardware in mass produced mobile phones
Exploring open hardware in mass produced mobile phonesExploring open hardware in mass produced mobile phones
Exploring open hardware in mass produced mobile phonesRohini Lakshané
 
The Convergence of IT, Operational Technology and the Internet of Things (IoT)
The Convergence of IT, Operational Technology and the Internet of Things (IoT)The Convergence of IT, Operational Technology and the Internet of Things (IoT)
The Convergence of IT, Operational Technology and the Internet of Things (IoT)Jackson Shaw
 
Breaking the barriers of Internet of Things (IoT)
Breaking the barriers of Internet of Things (IoT)Breaking the barriers of Internet of Things (IoT)
Breaking the barriers of Internet of Things (IoT)Dr. Mazlan Abbas
 
Internet Of Things and Open Source
Internet Of Things and Open SourceInternet Of Things and Open Source
Internet Of Things and Open SourceMobodexter
 
OSS - enterprise adoption strategy and governance
OSS -  enterprise adoption strategy and governanceOSS -  enterprise adoption strategy and governance
OSS - enterprise adoption strategy and governancePrabir Kr Sarkar
 
IIOT – Opportunities & Challenges (How-To Start Your IoT Project).pdf
IIOT – Opportunities & Challenges (How-To Start Your IoT Project).pdfIIOT – Opportunities & Challenges (How-To Start Your IoT Project).pdf
IIOT – Opportunities & Challenges (How-To Start Your IoT Project).pdfDr. Mazlan Abbas
 
SIM Portland IOT - Sandhi Bhide - (09-14-2016)
SIM Portland IOT - Sandhi Bhide - (09-14-2016)SIM Portland IOT - Sandhi Bhide - (09-14-2016)
SIM Portland IOT - Sandhi Bhide - (09-14-2016)sandhibhide
 

Similaire à Opening the IoT - Joe Fortey - IoT Midlands Meet Up - 29/07/14 (20)

Supply Chain Security and Compliance for Embedded Devices & IoT
Supply Chain Security and Compliance for Embedded Devices & IoTSupply Chain Security and Compliance for Embedded Devices & IoT
Supply Chain Security and Compliance for Embedded Devices & IoT
 
The Internet of Things: We've Got to Chat
The Internet of Things: We've Got to ChatThe Internet of Things: We've Got to Chat
The Internet of Things: We've Got to Chat
 
Home automation using internet of things
Home automation using internet of thingsHome automation using internet of things
Home automation using internet of things
 
OASIS: open source and open standards: internet of things
OASIS: open source and open standards: internet of thingsOASIS: open source and open standards: internet of things
OASIS: open source and open standards: internet of things
 
OASIS: How open source and open standards work together: the Internet of Things
OASIS: How open source and open standards work together: the Internet of ThingsOASIS: How open source and open standards work together: the Internet of Things
OASIS: How open source and open standards work together: the Internet of Things
 
Open Source Insight: Securing IoT, Atlanta Ransomware Attack, Congress on Cyb...
Open Source Insight: Securing IoT, Atlanta Ransomware Attack, Congress on Cyb...Open Source Insight: Securing IoT, Atlanta Ransomware Attack, Congress on Cyb...
Open Source Insight: Securing IoT, Atlanta Ransomware Attack, Congress on Cyb...
 
FI-WARE Basic Guide
FI-WARE Basic GuideFI-WARE Basic Guide
FI-WARE Basic Guide
 
IoT : Whats in it for me?
IoT : Whats in it for me? IoT : Whats in it for me?
IoT : Whats in it for me?
 
Standards and Open Source for Big Data, Cloud, and IoT
Standards and Open Source for Big Data, Cloud, and IoTStandards and Open Source for Big Data, Cloud, and IoT
Standards and Open Source for Big Data, Cloud, and IoT
 
The Internet of Things
The Internet of ThingsThe Internet of Things
The Internet of Things
 
4.Jan Holler, Vlasios Tsiatsis, Catherine Mulligan, Stefan Avesand, Stamatis ...
4.Jan Holler, Vlasios Tsiatsis, Catherine Mulligan, Stefan Avesand, Stamatis ...4.Jan Holler, Vlasios Tsiatsis, Catherine Mulligan, Stefan Avesand, Stamatis ...
4.Jan Holler, Vlasios Tsiatsis, Catherine Mulligan, Stefan Avesand, Stamatis ...
 
IoT Security Risks and Challenges
IoT Security Risks and ChallengesIoT Security Risks and Challenges
IoT Security Risks and Challenges
 
Exploring open hardware in mass produced mobile phones
Exploring open hardware in mass produced mobile phonesExploring open hardware in mass produced mobile phones
Exploring open hardware in mass produced mobile phones
 
The Convergence of IT, Operational Technology and the Internet of Things (IoT)
The Convergence of IT, Operational Technology and the Internet of Things (IoT)The Convergence of IT, Operational Technology and the Internet of Things (IoT)
The Convergence of IT, Operational Technology and the Internet of Things (IoT)
 
Internet of Things: Trends and challenges for future
Internet of Things: Trends and challenges for futureInternet of Things: Trends and challenges for future
Internet of Things: Trends and challenges for future
 
Breaking the barriers of Internet of Things (IoT)
Breaking the barriers of Internet of Things (IoT)Breaking the barriers of Internet of Things (IoT)
Breaking the barriers of Internet of Things (IoT)
 
Internet Of Things and Open Source
Internet Of Things and Open SourceInternet Of Things and Open Source
Internet Of Things and Open Source
 
OSS - enterprise adoption strategy and governance
OSS -  enterprise adoption strategy and governanceOSS -  enterprise adoption strategy and governance
OSS - enterprise adoption strategy and governance
 
IIOT – Opportunities & Challenges (How-To Start Your IoT Project).pdf
IIOT – Opportunities & Challenges (How-To Start Your IoT Project).pdfIIOT – Opportunities & Challenges (How-To Start Your IoT Project).pdf
IIOT – Opportunities & Challenges (How-To Start Your IoT Project).pdf
 
SIM Portland IOT - Sandhi Bhide - (09-14-2016)
SIM Portland IOT - Sandhi Bhide - (09-14-2016)SIM Portland IOT - Sandhi Bhide - (09-14-2016)
SIM Portland IOT - Sandhi Bhide - (09-14-2016)
 

Plus de WMG, University of Warwick

Introduction to Productivity Slides, Skills and Productivity
Introduction to Productivity Slides, Skills and Productivity Introduction to Productivity Slides, Skills and Productivity
Introduction to Productivity Slides, Skills and Productivity WMG, University of Warwick
 
Nigel Maris & Tom Screen, Assembled Electronics Solutions Ltd
Nigel Maris & Tom Screen, Assembled Electronics Solutions LtdNigel Maris & Tom Screen, Assembled Electronics Solutions Ltd
Nigel Maris & Tom Screen, Assembled Electronics Solutions LtdWMG, University of Warwick
 
Emma Hockley, Big Bear Plastics, Thermoforming and Materials
Emma Hockley, Big Bear Plastics, Thermoforming and MaterialsEmma Hockley, Big Bear Plastics, Thermoforming and Materials
Emma Hockley, Big Bear Plastics, Thermoforming and MaterialsWMG, University of Warwick
 
Neil Reynolds, WMG University of Warwick, Innovations in Composite Materials ...
Neil Reynolds, WMG University of Warwick, Innovations in Composite Materials ...Neil Reynolds, WMG University of Warwick, Innovations in Composite Materials ...
Neil Reynolds, WMG University of Warwick, Innovations in Composite Materials ...WMG, University of Warwick
 
Polymer Innovation Network "Innovations in Plastic Processing"
Polymer Innovation Network "Innovations in Plastic Processing"Polymer Innovation Network "Innovations in Plastic Processing"
Polymer Innovation Network "Innovations in Plastic Processing"WMG, University of Warwick
 
Robert Harrison, WMG - IIoT and Industry 4.0 in Automation Systems Engineering
Robert Harrison, WMG - IIoT and Industry 4.0 in Automation Systems EngineeringRobert Harrison, WMG - IIoT and Industry 4.0 in Automation Systems Engineering
Robert Harrison, WMG - IIoT and Industry 4.0 in Automation Systems EngineeringWMG, University of Warwick
 

Plus de WMG, University of Warwick (20)

Dr Weisi Guo, University of Warwick
Dr Weisi Guo, University of WarwickDr Weisi Guo, University of Warwick
Dr Weisi Guo, University of Warwick
 
Mike Waters,Coventry City Council
Mike Waters,Coventry City CouncilMike Waters,Coventry City Council
Mike Waters,Coventry City Council
 
Dr Rick Robinson, amey
Dr Rick Robinson, ameyDr Rick Robinson, amey
Dr Rick Robinson, amey
 
Amanda Randle, AQMesh
Amanda Randle, AQMeshAmanda Randle, AQMesh
Amanda Randle, AQMesh
 
Io t #11 introduction and closing slides
Io t #11 introduction and closing slidesIo t #11 introduction and closing slides
Io t #11 introduction and closing slides
 
Failure Mode Effect Analysis
Failure Mode Effect AnalysisFailure Mode Effect Analysis
Failure Mode Effect Analysis
 
Mythbusting alm for circulation
Mythbusting alm for circulationMythbusting alm for circulation
Mythbusting alm for circulation
 
Playing with data and industry 4.0
Playing with data and industry 4.0Playing with data and industry 4.0
Playing with data and industry 4.0
 
Applying Lean and Assessing plants
Applying Lean and Assessing plantsApplying Lean and Assessing plants
Applying Lean and Assessing plants
 
Introduction to Productivity
Introduction to Productivity Introduction to Productivity
Introduction to Productivity
 
Introduction to Productivity Slides, Skills and Productivity
Introduction to Productivity Slides, Skills and Productivity Introduction to Productivity Slides, Skills and Productivity
Introduction to Productivity Slides, Skills and Productivity
 
Nigel Maris & Tom Screen, Assembled Electronics Solutions Ltd
Nigel Maris & Tom Screen, Assembled Electronics Solutions LtdNigel Maris & Tom Screen, Assembled Electronics Solutions Ltd
Nigel Maris & Tom Screen, Assembled Electronics Solutions Ltd
 
Jon Cooper, Autonect
Jon Cooper, AutonectJon Cooper, Autonect
Jon Cooper, Autonect
 
Jeff Stewart, M2M CloudFactory
Jeff Stewart, M2M CloudFactoryJeff Stewart, M2M CloudFactory
Jeff Stewart, M2M CloudFactory
 
Chunyang Xu, Dekon Company Ltd
Chunyang Xu, Dekon Company LtdChunyang Xu, Dekon Company Ltd
Chunyang Xu, Dekon Company Ltd
 
Emma Hockley, Big Bear Plastics, Thermoforming and Materials
Emma Hockley, Big Bear Plastics, Thermoforming and MaterialsEmma Hockley, Big Bear Plastics, Thermoforming and Materials
Emma Hockley, Big Bear Plastics, Thermoforming and Materials
 
Neil Reynolds, WMG University of Warwick, Innovations in Composite Materials ...
Neil Reynolds, WMG University of Warwick, Innovations in Composite Materials ...Neil Reynolds, WMG University of Warwick, Innovations in Composite Materials ...
Neil Reynolds, WMG University of Warwick, Innovations in Composite Materials ...
 
Graeme Herlihy, Engel UK, MuCell Process
Graeme Herlihy, Engel UK, MuCell ProcessGraeme Herlihy, Engel UK, MuCell Process
Graeme Herlihy, Engel UK, MuCell Process
 
Polymer Innovation Network "Innovations in Plastic Processing"
Polymer Innovation Network "Innovations in Plastic Processing"Polymer Innovation Network "Innovations in Plastic Processing"
Polymer Innovation Network "Innovations in Plastic Processing"
 
Robert Harrison, WMG - IIoT and Industry 4.0 in Automation Systems Engineering
Robert Harrison, WMG - IIoT and Industry 4.0 in Automation Systems EngineeringRobert Harrison, WMG - IIoT and Industry 4.0 in Automation Systems Engineering
Robert Harrison, WMG - IIoT and Industry 4.0 in Automation Systems Engineering
 

Dernier

Take control of your SAP testing with UiPath Test Suite
Take control of your SAP testing with UiPath Test SuiteTake control of your SAP testing with UiPath Test Suite
Take control of your SAP testing with UiPath Test SuiteDianaGray10
 
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptxMerck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptxLoriGlavin3
 
Anypoint Exchange: It’s Not Just a Repo!
Anypoint Exchange: It’s Not Just a Repo!Anypoint Exchange: It’s Not Just a Repo!
Anypoint Exchange: It’s Not Just a Repo!Manik S Magar
 
Generative AI for Technical Writer or Information Developers
Generative AI for Technical Writer or Information DevelopersGenerative AI for Technical Writer or Information Developers
Generative AI for Technical Writer or Information DevelopersRaghuram Pandurangan
 
"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr BaganFwdays
 
DevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsDevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsSergiu Bodiu
 
What is Artificial Intelligence?????????
What is Artificial Intelligence?????????What is Artificial Intelligence?????????
What is Artificial Intelligence?????????blackmambaettijean
 
DSPy a system for AI to Write Prompts and Do Fine Tuning
DSPy a system for AI to Write Prompts and Do Fine TuningDSPy a system for AI to Write Prompts and Do Fine Tuning
DSPy a system for AI to Write Prompts and Do Fine TuningLars Bell
 
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek SchlawackFwdays
 
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024BookNet Canada
 
From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .Alan Dix
 
Time Series Foundation Models - current state and future directions
Time Series Foundation Models - current state and future directionsTime Series Foundation Models - current state and future directions
Time Series Foundation Models - current state and future directionsNathaniel Shimoni
 
How to write a Business Continuity Plan
How to write a Business Continuity PlanHow to write a Business Continuity Plan
How to write a Business Continuity PlanDatabarracks
 
WordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your BrandWordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your Brandgvaughan
 
"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii SoldatenkoFwdays
 
Training state-of-the-art general text embedding
Training state-of-the-art general text embeddingTraining state-of-the-art general text embedding
Training state-of-the-art general text embeddingZilliz
 
DevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache MavenDevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache MavenHervé Boutemy
 
SALESFORCE EDUCATION CLOUD | FEXLE SERVICES
SALESFORCE EDUCATION CLOUD | FEXLE SERVICESSALESFORCE EDUCATION CLOUD | FEXLE SERVICES
SALESFORCE EDUCATION CLOUD | FEXLE SERVICESmohitsingh558521
 
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc
 
Digital Identity is Under Attack: FIDO Paris Seminar.pptx
Digital Identity is Under Attack: FIDO Paris Seminar.pptxDigital Identity is Under Attack: FIDO Paris Seminar.pptx
Digital Identity is Under Attack: FIDO Paris Seminar.pptxLoriGlavin3
 

Dernier (20)

Take control of your SAP testing with UiPath Test Suite
Take control of your SAP testing with UiPath Test SuiteTake control of your SAP testing with UiPath Test Suite
Take control of your SAP testing with UiPath Test Suite
 
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptxMerck Moving Beyond Passwords: FIDO Paris Seminar.pptx
Merck Moving Beyond Passwords: FIDO Paris Seminar.pptx
 
Anypoint Exchange: It’s Not Just a Repo!
Anypoint Exchange: It’s Not Just a Repo!Anypoint Exchange: It’s Not Just a Repo!
Anypoint Exchange: It’s Not Just a Repo!
 
Generative AI for Technical Writer or Information Developers
Generative AI for Technical Writer or Information DevelopersGenerative AI for Technical Writer or Information Developers
Generative AI for Technical Writer or Information Developers
 
"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan"ML in Production",Oleksandr Bagan
"ML in Production",Oleksandr Bagan
 
DevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platformsDevEX - reference for building teams, processes, and platforms
DevEX - reference for building teams, processes, and platforms
 
What is Artificial Intelligence?????????
What is Artificial Intelligence?????????What is Artificial Intelligence?????????
What is Artificial Intelligence?????????
 
DSPy a system for AI to Write Prompts and Do Fine Tuning
DSPy a system for AI to Write Prompts and Do Fine TuningDSPy a system for AI to Write Prompts and Do Fine Tuning
DSPy a system for AI to Write Prompts and Do Fine Tuning
 
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
"Subclassing and Composition – A Pythonic Tour of Trade-Offs", Hynek Schlawack
 
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
 
From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .From Family Reminiscence to Scholarly Archive .
From Family Reminiscence to Scholarly Archive .
 
Time Series Foundation Models - current state and future directions
Time Series Foundation Models - current state and future directionsTime Series Foundation Models - current state and future directions
Time Series Foundation Models - current state and future directions
 
How to write a Business Continuity Plan
How to write a Business Continuity PlanHow to write a Business Continuity Plan
How to write a Business Continuity Plan
 
WordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your BrandWordPress Websites for Engineers: Elevate Your Brand
WordPress Websites for Engineers: Elevate Your Brand
 
"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko"Debugging python applications inside k8s environment", Andrii Soldatenko
"Debugging python applications inside k8s environment", Andrii Soldatenko
 
Training state-of-the-art general text embedding
Training state-of-the-art general text embeddingTraining state-of-the-art general text embedding
Training state-of-the-art general text embedding
 
DevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache MavenDevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache Maven
 
SALESFORCE EDUCATION CLOUD | FEXLE SERVICES
SALESFORCE EDUCATION CLOUD | FEXLE SERVICESSALESFORCE EDUCATION CLOUD | FEXLE SERVICES
SALESFORCE EDUCATION CLOUD | FEXLE SERVICES
 
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data PrivacyTrustArc Webinar - How to Build Consumer Trust Through Data Privacy
TrustArc Webinar - How to Build Consumer Trust Through Data Privacy
 
Digital Identity is Under Attack: FIDO Paris Seminar.pptx
Digital Identity is Under Attack: FIDO Paris Seminar.pptxDigital Identity is Under Attack: FIDO Paris Seminar.pptx
Digital Identity is Under Attack: FIDO Paris Seminar.pptx
 

Opening the IoT - Joe Fortey - IoT Midlands Meet Up - 29/07/14

  • 1. Internet of Things (IoT) Midlands UK Opening the Internet of Things: for security, compatibility... and profit by Joe Fortey jfortey [at] yahoo.com (replace “at” with “@”) Meetup #6: Show and Tell: 7pm Tuesday, July 29, 2014
  • 2. Due to an issue in the application used to create this slideshow, some web links may be rendered in a pale font. All links should still be clickable, but if you have any problems, please copy and paste links to your browser to access the websites.
  • 3.
  • 4. The LIFX IoT Lightbulb http://lifx.co/ - IoT lightbulbs, controllable from a smart phone, connected in a mesh network, and to the home network. www.kickstarter.com/projects/limemouse/lifx-the-light-bulb-reinvented - LIFX Kickstarter campaign, from Nov. 2012
  • 5.
  • 6. The LIFX security breach Security breach links: http://contextis.com/blog/hacking-internet-connected-light-bulbs/ - the original blog on the LIFX hack, by the hackers. www.arstechnica.com/security/2014/07/crypto-weakness-in-smart-led-lightbulbs-exposes-wi-fi-passwords/ - Tech press report on the breach. The hacked and hacking tech: https://en.wikipedia.org/wiki/6LoWPAN - 6LoWPAN Mesh network, used by LIFX. 6LoWPAN is an acronym of IPv6 over Low power Wireless Personal Area Networks. https://en.wikipedia.org/wiki/JTAG - The pin system used to hack the bulb Bus- blaster JTAG debugger
  • 7. LIFX breach - security expert feedback from “Security Now” Podcast 463, 8th July 2014 (1 of 2) Steve Gibson: "We've got secure protocols for doing all the kinds of common things we want [on the Internet]... well- established, very secure, bulletproof protocols. But we don't have anything like that for the Internet of Things. And so companies like [LIFX] are just making stuff up. They're saying, well, you know, we're going to solve the problem because there is no RFC yet for it. Well, we need [an RFC]." continued... N.B. RFC = “Request for Comments”, see: https://en.wikipedia.org/wiki/Request_for_Comments - "A Request for Comments (RFC) is a publication of the Internet Engineering Task Force (IETF) and the Internet Society, the principal technical development and standards-setting bodies for the Internet. An RFC is authored by engineers and computer scientists in the form of a memorandum describing methods, behaviours, research, or innovations applicable to the working of the Internet and Internet-connected systems. It is submitted either for peer review or simply to convey new concepts, information, or (occasionally) engineering humour. The IETF adopts some of the proposals published as RFCs as Internet standards."
  • 8. LIFX breach - security expert feedback from “Security Now” Podcast 463, 8th July 2014 (2 of 2) continued... Fr. Robert Ballecer (edition show host): "...This is just an example of Security Through Obscurity. They figured, well, yeah, okay, we're using a static key, but we're going to bake it into a chip that no one will have access to. They won't be able to read it, and it'll be fine. And any security expert worth his salt would have sat next to them and said, "You know you can't ever assume that anything you bake into an IC is going to stay hidden."
  • 9. Security flaws? - Not just start-ups! Philips Smart lightbulbs suffer malware attacks: http://arstechnica.com/security/2013/08/philips-hue-lights-malware-hack/ Belkin baby monitor hack: http://www.mocana.com/blog/2013/10/25/baby-monitors-can-hacked/ Belkin WeMo hack: http://www.cnet.com/uk/news/belkin-wemo-smart-home-networks-in-danger-of-hacks/
  • 10. Not-so-smart super-loo? Maybe I'll just pass on that.... (screen-shot of an article from http://www.digitaltrends.com/home/smart-toilet-security-flaw/)
  • 11. Not only security and privacy: Proprietary, single-company development in short time-scales (Internet time scales) may mean:  unstable system designs, or  poor implementation of good designs But even if it is secure, is it compatible? The IoT is about connectivity - of everything. Without compatibility, it will remain....
  • 12. ...a sea of independent, isolated islands of proprietary technology
  • 13. The proprietary tech problem On their own, SMEs and start-ups have limited resources to do security and connectivity successfully, or to build sufficient market share to dominate in their sector. Commercial protocols, platforms and standards (e.g. Apple) may be:  expensive to licence  restrictive in who is allowed to partner  Still subject to market forces / security compromises / obsolescence
  • 14. Options for the rest of us 1) Make do with a small market share and possibly some big, nasty support issues 2) Sell out to a bigger business (if you can) 3) Collaborate with other businesses to build common, open solutions
  • 15. Current Open-IoT projects & initiatives https://allseenalliance.org/ - The AllSeen Alliance, Led by the Linux Foundation, with perhaps the broadest remit and currently largest in terms of members (see next slide). https://www.alljoyn.org/ - Open source initiative from Qualcomm, this technology forms the basis of the AllSeen Alliance project. http://www.hypercat.io/ - A UK-based initiative with 40+ members in public and private sectors, focused specifically on an open information protocol for the IoT. http://www.iiconsortium.org/ - An alliance with 60+ members, focused on industrial IoT implementations. Members include Intel, IBM, AT&T, GE and Cisco and Microsoft. http://www.openinterconnect.org/ - An alliance between six large businesses including: Atmel, Broadcom, Dell, Intel, Samsung and Wind River, focused on open standards and solutions http://www.threadgroup.org/ - A new wireless protocol, based on IEEE 802.15.4, compatible with objectives of some of the other alliances. Parners include: Google's NEST Labs, Samsung, ARM, Freescale, Big Ass Fans, Silicon Labs, Yale Security. http://openiot.eu/ - Open IoT middleware initiative, between a partnership of EU public and educational organisations. http://standards.ieee.org/innovate/iot/ - Institute of Electrical and Electronics Engineers initiative for IoT standards. http://www.itu.int/en/ITU-T/gsi/iot/Pages/default.aspx - The International Telecommunication Union initiative for IoT standards. http://www.ipso-alliance.org/ - An alliance focused on auditing and analysis of standards developed by other groups www.iot-competition.com - Smaller-scale initiative run as a competition, by Elector Magazine and Embedded Projects Journal, (deadline: 1st August 2014). ...if you know of any more groups or initiatives, please get in touch.
  • 16. AllSeen Alliance: some current members (note those I have circled!)
  • 17. Additional resources https://developer.apple.com/homekit/ - Apple's initiative for compatibility between smart devices in the home - not an open standard, but partners include: Philips, iHome, Osram Sylvania and Texas Instruments http://www.ietf.org/ - Internet Engineering Task Force - a body responsible for addressing broader internet standards and compatibility issues http://www.ohwr.org/ - Open Hardware Repository, an initiative supported by CERN to back development and sharing of open hardware solutions https://opencryptoaudit.org/ - For open tech to succeed, a good audit culture needs to be established. Here's one initiative, for open source crypto software and applications https://www.grc.com/securitynow.htm - a useful resource for security news and analysis
  • 18. Conclusions The recent proliferation of partnerships and projects aiming to address the issue of IoT standards is encouraging, but warrants caution. Unless a focus is maintained on truly open solutions, these groups will be tempted to compete rather than collaborate, limiting progress and frustrating the intended objectives for these initiatives. Standardisation is important but openness even more so, to ensure freedom of partner groups to share and integrate the best technology and solutions without licensing or other legal restrictions, benefiting all parties equally and accelerating progress. It would be helpful for existing groups to communicate, seek common ground and where possible, consolidate around solutions which are open in both name and design, so that growth of a secure, compatible Internet of Things can proceed unhindered. © Joe Fortey, 2014