Blog-Eintrag -

The Hacked Jeep is not alone

As I wrote about in the blog post “Demystifying Security and Identities for Internet of Things” it is essential to implement security by design. The recent article in Wired shows how the threat is real and even though causing accidents might not be the prime target it points out that we need to take what we have learnt when opening up systems and API to the IoT world and not just care about remote access to IoT, its also about how different objects in the near perimeter act and are authorized to act.

The Chrysler example is just one of many and I’m sure we will see a lot more in the future and attacks and vulnerabilities that can have a major effect on financial systems and national security.

What the article also points out is the area of Life Cycle Management, IoT needs to have Life Cycle Management and be have the capability of updating the security technology and policies in place at the device. In the Chrysler case it has issued a recall of 1.4 million vehicles to address the issue.

Just as a reminder, 5 steps to help you address IoT security

  1. Activation of Objects
  2. Provisioning of Identities to Objects
  3. Authentication of Objects and Authorization of the Access
  4. Secure Transport of Data from and to and object and Security of Data at Rest on the Object
  5. De-activation of Objects including revocation of identities, clean-up of data and reset of the object

/Per Hägerö

CTO

Links

Themen

  • Daten, Telekom, IT

Kategorien

  • nexus

Kontakt

Zugehörige Meldungen

  • neXus liefert Dienstausweislösung für die Gemeinde Ale

    Gemeinsam mit neXus hat die Gemeinde Ale eine Lösung für die Produktion und Verwaltung von Dienstausweisen für alle seine Mitarbeiter entwickelt. Die Gemeindeverwaltung plant, dem gesamten Personal eine sichere Identifizierungs-Lösung bereitzustellen, die sowohl zur sicheren Anmeldung am Arbeitsplatz-PC als auch für den Zugang zu Gebäuden, für Druckaufträge und vieles mehr verwendet werden kann.

  • neXus Hauptquartier auf Liste der stilvollsten Arbeitsplätze der Welt

    Das neXus Hauptquartier befindet sich seit zwei Jahren in Telefonplan, dem ehemaligen Standort von Ericsson im Süden von Stockholm. Die vom Architekturbüro MER gestalteten Geschäftsräume wurden nun zu einem der 35 aufregendsten Arbeitsplätze der Welt ernannt.

  • Identitätsmanagement für Banken

    Am 12. Februar 2016 erörterte das Finanzmagazin gi geldinstitute einen in einem Artikel über neXus die Wichtigkeit eines professionellen Identitätsmanagements für Banken.

  • The SCIM standards just grew up to become RFC's

    Integrity and simplicity for both users and IT-departments just took a huge step forward on the Internet. The SCIM specifications, System for Cross-Domain Identity Management, are now published as publications by the Internet Engineering Taskforce (IETF) as RFC7643 and RFC7644. At neXus we are super proud because we have been playing a key part of the specifications.

  • Server Name Indication and Hybrid Access Gateway

    ​SNI is an extension to TLS that has been around for a while, since 2003, but is becoming more and more important as installations become multi tenant with customers from completely different organizations.