Internet of Things Problems - Computerphile

Computerphile · Intermediate ·📐 ML Fundamentals ·9y ago

Key Takeaways

Professor Ross Anderson discusses Internet of Things problems, emphasizing safety over privacy, with references to Secure Hashing Algorithm and Data Harvesting.

Full Transcript

up until now an awful lot of information security mechanisms and the policy debate has been about the use of security to protect the privacy of personal data and the confidentiality of business data but in the future once we get software and Communications in everything it's going to be much more about safety and this is going to change the policy debate as well because at present many people might not object too much to the idea that the FBI has a golden master key that lets them break into your iPhone and um read all your embarrassing um private chat messages but I think people will be very much more nervous about the idea that the FBI will have a golden master key that will enable them to break into your car remotely and turn it into a weapon that could kill you and if this golden master key is available also to other intelligence and police agencies around the world then perhaps that begins to become a real problem and we have to revisit the whole question of government special access to cryptographic keys and to systems in general so far people have talked about the possible privacy risks of the internet of things and we saw the kador being banned in Germany because it's basically a remotely commandable room bug and we also saw the meai botnet last year where some bad person recruited a couple 100,000 TV cameras to um dos um a DNS service which took Twitter offline for a few hours in the US Eastern Seaboard uh but I think that the big problem with the Internet of Things isn't going to be privacy um or availability is going to be safety what we're now doing is putting online an awful lot of devices um on which people depend for their lives and which can kill people if they go wrong the obvious cases are cars and medical devices but there are many more and the other thing that's going to make this complex and difficult is the fact that up until now um we've known how to make two kinds of Dependable system the first is a system like your mobile phone where you upgrade it every month to make sure that all the security flaws are patched but where you're expected to throw it away after two or three years and nobody bothers to patch really old versions of your phone software or your laptop software and the other type of thing that we build um is like cars and medical devices and um electricity substations and other durable things that we expect to last for 30 or 40 years now in the case of cars what we do is we test the software to death before the thing goes on sale and we hope that's going to be good enough and we never upgrade it afterwards unless there's some real Panic now this is going to change because Tesla is already shipping monthly software upgrades for their cars um Ford and BMW have already ship some upgrades and everybody will be doing this within 3 or 4 years all of a sudden your car becomes something like your phone or your laptop which gets a monthly software upgrade and this is great for some purposes and terrible for other purposes it's great because it means that if there's some safety vulnerability like for example when a a Tesla driver was killed when his car went into the back of a truck which was painted white because the sky was was gray and it wasn't visible enough um so something like that you can fix by shipping a software upgrade and it will be very very much cheaper than having to recall millions of cars and reflashing all the firmware at a cost of billions and billions and billions but although it brings us the possibility of steady growth in uh Vehicle Safety it brings a terrible cost with it which is that we've got to maintain the capability to patch that software not just for years but for decades and we don't know how to do that either in organizational terms or in technical terms so let me State the problem suppose you're working in Cambridge England or in Cambridge Massachusetts on some um software that will say help do navigation in um a Landover or a Jeep or a Ford or whatever that you expect to go on sale in 2020 how are you going to be able to patch that software in 2030 in 2040 there are small numbers of systems that have been maintained for a long time um for example um deep space probes um another example is avionic software um where basically stuff uh may be replaced or may it a midlife upgrade but where regular updates aren't expected because the kind of devices that you have in an air in in in an Airport's air traffic control system or in an aircraft aircraft's cockpit um tend not to be connected directly to the internet and so you don't have the same attack surface you don't suddenly have the need to patch stuff because of um shell shock or something like that which could actually um render it open to attack but in future we're looking at a a world in which all our cars are online all the time right because the car will be autonomous or at least partly autonomous it'll be communicating over the network it'll be downloading maps it'll be uh downloading traffic information it will be contributing to traffic information it will be getting updates of all sorts of kinds of of code and data it will be a very very complex beast and how we manage that um is going to be a big problem now at present we have serious problems in getting oems to patch systems like Android and so most of the Android phones in the world are insecure simply because they vendors um can't get it together or don't have the incentive to patch them now this is going going to become considerably worse once we start talking about cars because a car is not just a simple system that's made by one vendor anymore um the the brands that you buy be it Volkswagen or Mercedes or pujo or um General Motors or whatever are basically integrators who buy in components from lots and lots of people who sell the parts who sell the um the ABS who sell the automatic emergency breaking who sell in future the robo chauffeur which will actually drive you to work while you're sitting there hacking some code and so you've then got the technical problems and the business problems of how do you produce software upgrades which marry together code written by potentially dozens of different firms then there's a question of who's going to be liable for it all when things go wrong and then there's going to be the question of who pays for it all now at present um software firms try and get rid of the liability U for software going wrong and that's not going to be possible when software is in devices that can kill people legislators simply won't allow it uh laws in both America and Europe um see to it that if you sell a device that kills people then you're liable and it doesn't matter how often you get your users to click on the don't sue me button that basically doesn't work well for now we won't talk about exactly what's going on to see and understand the OB is for a lot of people it's very difficult to understand all the different being around make and it's if you do understand them to see what that somebody

Original Description

A hacked car that could kill you should be more worrying than a thousand lightbulbs taking Facebook offline. University of Cambridge's Professor Ross Anderson explains why safety should be higher on the agenda than privacy. SHA: Secure Hashing Algorithm: https://youtu.be/DMtFhACPnTY Data Harvesting: https://youtu.be/2lEhamPHh3k Golden Key - FBI vs Apple iPhone: https://youtu.be/6RNKtwAGvqc http://www.facebook.com/computerphile https://twitter.com/computer_phile This video was filmed and edited by Sean Riley. Computer Science at the University of Nottingham: http://bit.ly/nottscomputer Computerphile is a sister project to Brady Haran's Numberphile. More at http://www.bradyharan.com
Watch on YouTube ↗ (saves to browser)
Sign in to unlock AI tutor explanation · ⚡30

Playlist

Uploads from Computerphile · Computerphile · 0 of 60

← Previous Next →
1 Follow the Cookie Trail - Computerphile
Follow the Cookie Trail - Computerphile
Computerphile
2 EXTRA BITS - Follow the Cookie Trail - Computerphile
EXTRA BITS - Follow the Cookie Trail - Computerphile
Computerphile
3 Musical Floppy Drives - Computerphile
Musical Floppy Drives - Computerphile
Computerphile
4 The Hair Algorithm - Computerphile
The Hair Algorithm - Computerphile
Computerphile
5 Getting Sorted & Big O Notation - Computerphile
Getting Sorted & Big O Notation - Computerphile
Computerphile
6 Quick Sort - Computerphile
Quick Sort - Computerphile
Computerphile
7 Hyper History and Cyber War - Computerphile
Hyper History and Cyber War - Computerphile
Computerphile
8 Entropy in Compression - Computerphile
Entropy in Compression - Computerphile
Computerphile
9 Original Elite on the BBC B - Computerphile
Original Elite on the BBC B - Computerphile
Computerphile
10 IP Addresses and the Internet - Computerphile
IP Addresses and the Internet - Computerphile
Computerphile
11 A Career in Video Games - Computerphile
A Career in Video Games - Computerphile
Computerphile
12 Error Detection and Flipping the Bits - Computerphile
Error Detection and Flipping the Bits - Computerphile
Computerphile
13 Programming BASIC and Sorting - Computerphile
Programming BASIC and Sorting - Computerphile
Computerphile
14 Birthplace of the World Wide Web - Computerphile
Birthplace of the World Wide Web - Computerphile
Computerphile
15 Punch Card Programming - Computerphile
Punch Card Programming - Computerphile
Computerphile
16 Programming Paradigms - Computerphile
Programming Paradigms - Computerphile
Computerphile
17 CERN Computing Centre (and mouse farm) - Computerphile
CERN Computing Centre (and mouse farm) - Computerphile
Computerphile
18 Error Correction - Computerphile
Error Correction - Computerphile
Computerphile
19 Home-Made Code - Computerphile
Home-Made Code - Computerphile
Computerphile
20 Security of Data on Disk - Computerphile
Security of Data on Disk - Computerphile
Computerphile
21 Gesture Controls - Computerphile
Gesture Controls - Computerphile
Computerphile
22 How Intelligent is Artificial Intelligence? - Computerphile
How Intelligent is Artificial Intelligence? - Computerphile
Computerphile
23 Encryption and Security Agencies - Computerphile
Encryption and Security Agencies - Computerphile
Computerphile
24 Virtual Machines Power the Cloud - Computerphile
Virtual Machines Power the Cloud - Computerphile
Computerphile
25 Hacking Websites with SQL Injection - Computerphile
Hacking Websites with SQL Injection - Computerphile
Computerphile
26 How Huffman Trees Work - Computerphile
How Huffman Trees Work - Computerphile
Computerphile
27 Cracking Websites with Cross Site Scripting - Computerphile
Cracking Websites with Cross Site Scripting - Computerphile
Computerphile
28 Cloud Computing (Cloudy with a Chance of Pizza) - Computerphile
Cloud Computing (Cloudy with a Chance of Pizza) - Computerphile
Computerphile
29 Texting Cabbage with a Recorder - Computerphile
Texting Cabbage with a Recorder - Computerphile
Computerphile
30 Hashing Algorithms and Security - Computerphile
Hashing Algorithms and Security - Computerphile
Computerphile
31 How YouTube Works - Computerphile
How YouTube Works - Computerphile
Computerphile
32 How NOT to Store Passwords! - Computerphile
How NOT to Store Passwords! - Computerphile
Computerphile
33 A New Golden Age of Video Games - Computerphile
A New Golden Age of Video Games - Computerphile
Computerphile
34 A Universe of Triangles - Computerphile
A Universe of Triangles - Computerphile
Computerphile
35 Cross Site Request Forgery - Computerphile
Cross Site Request Forgery - Computerphile
Computerphile
36 The True Power of the Matrix (Transformations in Graphics) - Computerphile
The True Power of the Matrix (Transformations in Graphics) - Computerphile
Computerphile
37 The Great 202 Jailbreak - Computerphile
The Great 202 Jailbreak - Computerphile
Computerphile
38 EXTRA BITS - Printing and Typesetting History - Computerphile
EXTRA BITS - Printing and Typesetting History - Computerphile
Computerphile
39 Triangles to Pixels - Computerphile
Triangles to Pixels - Computerphile
Computerphile
40 The Problem with Time & Timezones - Computerphile
The Problem with Time & Timezones - Computerphile
Computerphile
41 The Visibility Problem - Computerphile
The Visibility Problem - Computerphile
Computerphile
42 Lights and Shadows in Graphics - Computerphile
Lights and Shadows in Graphics - Computerphile
Computerphile
43 The Penguin Barcode - Computerphile
The Penguin Barcode - Computerphile
Computerphile
44 Typesetters in the '80s - Computerphile
Typesetters in the '80s - Computerphile
Computerphile
45 The Font Magicians - Computerphile
The Font Magicians - Computerphile
Computerphile
46 The Little Mac with the Big Bite - Computerphile
The Little Mac with the Big Bite - Computerphile
Computerphile
47 EXTRA BITS - More on the Original Mac at 30 - Computerphile
EXTRA BITS - More on the Original Mac at 30 - Computerphile
Computerphile
48 XP to Ubuntu with an 8yr old Hacktop - Computerphile
XP to Ubuntu with an 8yr old Hacktop - Computerphile
Computerphile
49 EXTRA BITS - Hacktop Real-Time Boot Comparison - Computerphile
EXTRA BITS - Hacktop Real-Time Boot Comparison - Computerphile
Computerphile
50 EXTRA BITS - Making a Bootable USB in Linux - Computerphile
EXTRA BITS - Making a Bootable USB in Linux - Computerphile
Computerphile
51 EXTRA BITS - Installing Ubuntu Permanently - Computerphile
EXTRA BITS - Installing Ubuntu Permanently - Computerphile
Computerphile
52 The Dawn of Desktop Publishing - Computerphile
The Dawn of Desktop Publishing - Computerphile
Computerphile
53 What is Bootstrapping? - Computerphile
What is Bootstrapping? - Computerphile
Computerphile
54 Reverse Polish Notation and The Stack - Computerphile
Reverse Polish Notation and The Stack - Computerphile
Computerphile
55 Home-Made Z80 Retro Computer - Computerphile
Home-Made Z80 Retro Computer - Computerphile
Computerphile
56 Should Everybody Learn to Code? - Computerphile
Should Everybody Learn to Code? - Computerphile
Computerphile
57 Programming in PostScript - Computerphile
Programming in PostScript - Computerphile
Computerphile
58 Heartbleed, Running the Code - Computerphile
Heartbleed, Running the Code - Computerphile
Computerphile
59 YouTube's Secret Algorithm - Computerphile
YouTube's Secret Algorithm - Computerphile
Computerphile
60 YouTube Search & Discovery - Computerphile
YouTube Search & Discovery - Computerphile
Computerphile

This video highlights the importance of safety in the Internet of Things, with Professor Ross Anderson discussing the potential risks and consequences of prioritizing privacy over safety. Viewers will learn about the need for robust security measures in IoT development. The video also touches on related topics such as Secure Hashing Algorithm and Data Harvesting.

Key Takeaways
  1. Understand the basics of IoT and its potential risks
  2. Learn about the importance of safety in IoT development
  3. Explore the role of Secure Hashing Algorithm in data protection
  4. Discuss the consequences of prioritizing privacy over safety
💡 Safety should be a higher priority than privacy in IoT development, as the consequences of a security breach can be catastrophic.

Related Reads

📰
Our Monitoring Said 62% of Retrievals Were Failing. The Bug Was Two Score Scales in One Column.
Learn how a simple bug in score scales caused 62% of retrievals to fail and how to identify similar issues in your monitoring data
Dev.to AI
📰
Same Time Last Year, development was so different. This is what 10 years of programming taught me.
A developer reflects on 10 years of programming experience and shares key takeaways on how the field has evolved
Dev.to · SSK
📰
The best config in your bake-off didn't win. Selection did.
Learn how selection bias affects model evaluation and why the best config in your bake-off didn't win
Dev.to · Alexey Spinov
📰
Your AI query did not change. The Postgres plan did.
Learn how Postgres plan changes can impact AI query performance without altering the SQL query itself
Dev.to · Mads Hansen
Up next
The Adam Optimizer is Just Momentum + RMSProp
DataMListic
Watch →