Internet of Things Problems - Computerphile
Key Takeaways
Professor Ross Anderson discusses Internet of Things problems, emphasizing safety over privacy, with references to Secure Hashing Algorithm and Data Harvesting.
Full Transcript
up until now an awful lot of information security mechanisms and the policy debate has been about the use of security to protect the privacy of personal data and the confidentiality of business data but in the future once we get software and Communications in everything it's going to be much more about safety and this is going to change the policy debate as well because at present many people might not object too much to the idea that the FBI has a golden master key that lets them break into your iPhone and um read all your embarrassing um private chat messages but I think people will be very much more nervous about the idea that the FBI will have a golden master key that will enable them to break into your car remotely and turn it into a weapon that could kill you and if this golden master key is available also to other intelligence and police agencies around the world then perhaps that begins to become a real problem and we have to revisit the whole question of government special access to cryptographic keys and to systems in general so far people have talked about the possible privacy risks of the internet of things and we saw the kador being banned in Germany because it's basically a remotely commandable room bug and we also saw the meai botnet last year where some bad person recruited a couple 100,000 TV cameras to um dos um a DNS service which took Twitter offline for a few hours in the US Eastern Seaboard uh but I think that the big problem with the Internet of Things isn't going to be privacy um or availability is going to be safety what we're now doing is putting online an awful lot of devices um on which people depend for their lives and which can kill people if they go wrong the obvious cases are cars and medical devices but there are many more and the other thing that's going to make this complex and difficult is the fact that up until now um we've known how to make two kinds of Dependable system the first is a system like your mobile phone where you upgrade it every month to make sure that all the security flaws are patched but where you're expected to throw it away after two or three years and nobody bothers to patch really old versions of your phone software or your laptop software and the other type of thing that we build um is like cars and medical devices and um electricity substations and other durable things that we expect to last for 30 or 40 years now in the case of cars what we do is we test the software to death before the thing goes on sale and we hope that's going to be good enough and we never upgrade it afterwards unless there's some real Panic now this is going to change because Tesla is already shipping monthly software upgrades for their cars um Ford and BMW have already ship some upgrades and everybody will be doing this within 3 or 4 years all of a sudden your car becomes something like your phone or your laptop which gets a monthly software upgrade and this is great for some purposes and terrible for other purposes it's great because it means that if there's some safety vulnerability like for example when a a Tesla driver was killed when his car went into the back of a truck which was painted white because the sky was was gray and it wasn't visible enough um so something like that you can fix by shipping a software upgrade and it will be very very much cheaper than having to recall millions of cars and reflashing all the firmware at a cost of billions and billions and billions but although it brings us the possibility of steady growth in uh Vehicle Safety it brings a terrible cost with it which is that we've got to maintain the capability to patch that software not just for years but for decades and we don't know how to do that either in organizational terms or in technical terms so let me State the problem suppose you're working in Cambridge England or in Cambridge Massachusetts on some um software that will say help do navigation in um a Landover or a Jeep or a Ford or whatever that you expect to go on sale in 2020 how are you going to be able to patch that software in 2030 in 2040 there are small numbers of systems that have been maintained for a long time um for example um deep space probes um another example is avionic software um where basically stuff uh may be replaced or may it a midlife upgrade but where regular updates aren't expected because the kind of devices that you have in an air in in in an Airport's air traffic control system or in an aircraft aircraft's cockpit um tend not to be connected directly to the internet and so you don't have the same attack surface you don't suddenly have the need to patch stuff because of um shell shock or something like that which could actually um render it open to attack but in future we're looking at a a world in which all our cars are online all the time right because the car will be autonomous or at least partly autonomous it'll be communicating over the network it'll be downloading maps it'll be uh downloading traffic information it will be contributing to traffic information it will be getting updates of all sorts of kinds of of code and data it will be a very very complex beast and how we manage that um is going to be a big problem now at present we have serious problems in getting oems to patch systems like Android and so most of the Android phones in the world are insecure simply because they vendors um can't get it together or don't have the incentive to patch them now this is going going to become considerably worse once we start talking about cars because a car is not just a simple system that's made by one vendor anymore um the the brands that you buy be it Volkswagen or Mercedes or pujo or um General Motors or whatever are basically integrators who buy in components from lots and lots of people who sell the parts who sell the um the ABS who sell the automatic emergency breaking who sell in future the robo chauffeur which will actually drive you to work while you're sitting there hacking some code and so you've then got the technical problems and the business problems of how do you produce software upgrades which marry together code written by potentially dozens of different firms then there's a question of who's going to be liable for it all when things go wrong and then there's going to be the question of who pays for it all now at present um software firms try and get rid of the liability U for software going wrong and that's not going to be possible when software is in devices that can kill people legislators simply won't allow it uh laws in both America and Europe um see to it that if you sell a device that kills people then you're liable and it doesn't matter how often you get your users to click on the don't sue me button that basically doesn't work well for now we won't talk about exactly what's going on to see and understand the OB is for a lot of people it's very difficult to understand all the different being around make and it's if you do understand them to see what that somebody
Original Description
A hacked car that could kill you should be more worrying than a thousand lightbulbs taking Facebook offline. University of Cambridge's Professor Ross Anderson explains why safety should be higher on the agenda than privacy.
SHA: Secure Hashing Algorithm: https://youtu.be/DMtFhACPnTY
Data Harvesting: https://youtu.be/2lEhamPHh3k
Golden Key - FBI vs Apple iPhone: https://youtu.be/6RNKtwAGvqc
http://www.facebook.com/computerphile
https://twitter.com/computer_phile
This video was filmed and edited by Sean Riley.
Computer Science at the University of Nottingham: http://bit.ly/nottscomputer
Computerphile is a sister project to Brady Haran's Numberphile. More at http://www.bradyharan.com
Watch on YouTube ↗
(saves to browser)
Sign in to unlock AI tutor explanation · ⚡30
Playlist
Uploads from Computerphile · Computerphile · 0 of 60
← Previous
Next →
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
Follow the Cookie Trail - Computerphile
Computerphile
EXTRA BITS - Follow the Cookie Trail - Computerphile
Computerphile
Musical Floppy Drives - Computerphile
Computerphile
The Hair Algorithm - Computerphile
Computerphile
Getting Sorted & Big O Notation - Computerphile
Computerphile
Quick Sort - Computerphile
Computerphile
Hyper History and Cyber War - Computerphile
Computerphile
Entropy in Compression - Computerphile
Computerphile
Original Elite on the BBC B - Computerphile
Computerphile
IP Addresses and the Internet - Computerphile
Computerphile
A Career in Video Games - Computerphile
Computerphile
Error Detection and Flipping the Bits - Computerphile
Computerphile
Programming BASIC and Sorting - Computerphile
Computerphile
Birthplace of the World Wide Web - Computerphile
Computerphile
Punch Card Programming - Computerphile
Computerphile
Programming Paradigms - Computerphile
Computerphile
CERN Computing Centre (and mouse farm) - Computerphile
Computerphile
Error Correction - Computerphile
Computerphile
Home-Made Code - Computerphile
Computerphile
Security of Data on Disk - Computerphile
Computerphile
Gesture Controls - Computerphile
Computerphile
How Intelligent is Artificial Intelligence? - Computerphile
Computerphile
Encryption and Security Agencies - Computerphile
Computerphile
Virtual Machines Power the Cloud - Computerphile
Computerphile
Hacking Websites with SQL Injection - Computerphile
Computerphile
How Huffman Trees Work - Computerphile
Computerphile
Cracking Websites with Cross Site Scripting - Computerphile
Computerphile
Cloud Computing (Cloudy with a Chance of Pizza) - Computerphile
Computerphile
Texting Cabbage with a Recorder - Computerphile
Computerphile
Hashing Algorithms and Security - Computerphile
Computerphile
How YouTube Works - Computerphile
Computerphile
How NOT to Store Passwords! - Computerphile
Computerphile
A New Golden Age of Video Games - Computerphile
Computerphile
A Universe of Triangles - Computerphile
Computerphile
Cross Site Request Forgery - Computerphile
Computerphile
The True Power of the Matrix (Transformations in Graphics) - Computerphile
Computerphile
The Great 202 Jailbreak - Computerphile
Computerphile
EXTRA BITS - Printing and Typesetting History - Computerphile
Computerphile
Triangles to Pixels - Computerphile
Computerphile
The Problem with Time & Timezones - Computerphile
Computerphile
The Visibility Problem - Computerphile
Computerphile
Lights and Shadows in Graphics - Computerphile
Computerphile
The Penguin Barcode - Computerphile
Computerphile
Typesetters in the '80s - Computerphile
Computerphile
The Font Magicians - Computerphile
Computerphile
The Little Mac with the Big Bite - Computerphile
Computerphile
EXTRA BITS - More on the Original Mac at 30 - Computerphile
Computerphile
XP to Ubuntu with an 8yr old Hacktop - Computerphile
Computerphile
EXTRA BITS - Hacktop Real-Time Boot Comparison - Computerphile
Computerphile
EXTRA BITS - Making a Bootable USB in Linux - Computerphile
Computerphile
EXTRA BITS - Installing Ubuntu Permanently - Computerphile
Computerphile
The Dawn of Desktop Publishing - Computerphile
Computerphile
What is Bootstrapping? - Computerphile
Computerphile
Reverse Polish Notation and The Stack - Computerphile
Computerphile
Home-Made Z80 Retro Computer - Computerphile
Computerphile
Should Everybody Learn to Code? - Computerphile
Computerphile
Programming in PostScript - Computerphile
Computerphile
Heartbleed, Running the Code - Computerphile
Computerphile
YouTube's Secret Algorithm - Computerphile
Computerphile
YouTube Search & Discovery - Computerphile
Computerphile
More on: Security Basics
View skill →Related Reads
📰
📰
📰
📰
Our Monitoring Said 62% of Retrievals Were Failing. The Bug Was Two Score Scales in One Column.
Dev.to AI
Same Time Last Year, development was so different. This is what 10 years of programming taught me.
Dev.to · SSK
The best config in your bake-off didn't win. Selection did.
Dev.to · Alexey Spinov
Your AI query did not change. The Postgres plan did.
Dev.to · Mads Hansen
🎓
Tutor Explanation
DeepCamp AI