27
IoT from the consumer’s perspective Jorge Pinto

Presentation AP2SI IoT ESC - WordPress.com · Presentation_AP2SI_IoT_ESC Author: Freewind Rider Created Date: 6/15/2015 3:52:01 PM Keywords ()

  • Upload
    others

  • View
    3

  • Download
    0

Embed Size (px)

Citation preview

Page 1: Presentation AP2SI IoT ESC - WordPress.com · Presentation_AP2SI_IoT_ESC Author: Freewind Rider Created Date: 6/15/2015 3:52:01 PM Keywords ()

IoT from the consumer’s perspective

Jorge Pinto

Page 2: Presentation AP2SI IoT ESC - WordPress.com · Presentation_AP2SI_IoT_ESC Author: Freewind Rider Created Date: 6/15/2015 3:52:01 PM Keywords ()

AP2SI

Born in 2012, AP2SI is a non lucrative private association

characterized by:

� Openness by associating with every individual to help in

information security matters;

� Focus with the dedication to fulfill its objectives and mission;

� Non competitive: has no goal in information security services;

� Independent: not controlled by organizations.

� From concerned individuals to the society.

Page 3: Presentation AP2SI IoT ESC - WordPress.com · Presentation_AP2SI_IoT_ESC Author: Freewind Rider Created Date: 6/15/2015 3:52:01 PM Keywords ()

Mission

Actively contribute to the information security mindset

development in Portugal:

� Raising awareness to the value of information and requirements

to protect it;

� Developing guidelines/best practices to enhance knowledge

and help qualifying information security personnel;

Page 4: Presentation AP2SI IoT ESC - WordPress.com · Presentation_AP2SI_IoT_ESC Author: Freewind Rider Created Date: 6/15/2015 3:52:01 PM Keywords ()

What is the IoT ?

So….

(from the consumer’s perspective)

Page 5: Presentation AP2SI IoT ESC - WordPress.com · Presentation_AP2SI_IoT_ESC Author: Freewind Rider Created Date: 6/15/2015 3:52:01 PM Keywords ()
Page 6: Presentation AP2SI IoT ESC - WordPress.com · Presentation_AP2SI_IoT_ESC Author: Freewind Rider Created Date: 6/15/2015 3:52:01 PM Keywords ()

The IoT is cool, right?

So….

Well… yes… kind of….

Page 7: Presentation AP2SI IoT ESC - WordPress.com · Presentation_AP2SI_IoT_ESC Author: Freewind Rider Created Date: 6/15/2015 3:52:01 PM Keywords ()

http://www.networkworld.com/article/2905053/security0/smart-home-hacking-is-easier-than-you-think.html

Page 8: Presentation AP2SI IoT ESC - WordPress.com · Presentation_AP2SI_IoT_ESC Author: Freewind Rider Created Date: 6/15/2015 3:52:01 PM Keywords ()

http://www.theverge.com/2013/10/21/4863872/dick-cheney-pacemaker-wireless-disabled-2007

Page 9: Presentation AP2SI IoT ESC - WordPress.com · Presentation_AP2SI_IoT_ESC Author: Freewind Rider Created Date: 6/15/2015 3:52:01 PM Keywords ()

http://www.theregister.co.uk/2011/10/27/fatal_insulin_pump_attack/

Page 10: Presentation AP2SI IoT ESC - WordPress.com · Presentation_AP2SI_IoT_ESC Author: Freewind Rider Created Date: 6/15/2015 3:52:01 PM Keywords ()

http://www.mirror.co.uk/news/technology-science/technology/samsung-spy-telly-scandal-erupts-5131842

Page 11: Presentation AP2SI IoT ESC - WordPress.com · Presentation_AP2SI_IoT_ESC Author: Freewind Rider Created Date: 6/15/2015 3:52:01 PM Keywords ()

https://www.kickstarter.com/projects/522717158/cognitoys-internet-connected-smart-toys-that-learn

Page 12: Presentation AP2SI IoT ESC - WordPress.com · Presentation_AP2SI_IoT_ESC Author: Freewind Rider Created Date: 6/15/2015 3:52:01 PM Keywords ()

http://pdfaiw.uspto.gov/.aiw?PageNum=0&docid=20150138333&IDKey=1EF5AB92E988

Page 13: Presentation AP2SI IoT ESC - WordPress.com · Presentation_AP2SI_IoT_ESC Author: Freewind Rider Created Date: 6/15/2015 3:52:01 PM Keywords ()

http://www.hyundainews.com/us/en/media/pressreleases/43387/hyundai-is-the-first-automaker-to-launch-android-auto

Page 14: Presentation AP2SI IoT ESC - WordPress.com · Presentation_AP2SI_IoT_ESC Author: Freewind Rider Created Date: 6/15/2015 3:52:01 PM Keywords ()

http://www.ibm.com/smarterplanet/us/en/ibmwatson/health/

Page 15: Presentation AP2SI IoT ESC - WordPress.com · Presentation_AP2SI_IoT_ESC Author: Freewind Rider Created Date: 6/15/2015 3:52:01 PM Keywords ()

http://news.discovery.com/tech/biotechnology/electronic-tattoos-for-baby-and-you-140311.htm

Page 16: Presentation AP2SI IoT ESC - WordPress.com · Presentation_AP2SI_IoT_ESC Author: Freewind Rider Created Date: 6/15/2015 3:52:01 PM Keywords ()

IoT funnel

Page 17: Presentation AP2SI IoT ESC - WordPress.com · Presentation_AP2SI_IoT_ESC Author: Freewind Rider Created Date: 6/15/2015 3:52:01 PM Keywords ()

we know that everyone can code

…and…

…but, can they code securely?

Page 18: Presentation AP2SI IoT ESC - WordPress.com · Presentation_AP2SI_IoT_ESC Author: Freewind Rider Created Date: 6/15/2015 3:52:01 PM Keywords ()

http://www.gfi.com/blog/most-vulnerable-operating-systems-and-applications-in-2014/

An average of 19 vulnerabilities per day were reported in 2014, according to the data

from the National Vulnerability Database (NVD) - http://nvd.nist.gov/

Page 19: Presentation AP2SI IoT ESC - WordPress.com · Presentation_AP2SI_IoT_ESC Author: Freewind Rider Created Date: 6/15/2015 3:52:01 PM Keywords ()

http://uk.businessinsider.com/google-play-vs-apple-app-store-2015-2?r=US

Page 20: Presentation AP2SI IoT ESC - WordPress.com · Presentation_AP2SI_IoT_ESC Author: Freewind Rider Created Date: 6/15/2015 3:52:01 PM Keywords ()

what can we do?

…so…

to raise consumer awareness

and improve security using market rules

Page 21: Presentation AP2SI IoT ESC - WordPress.com · Presentation_AP2SI_IoT_ESC Author: Freewind Rider Created Date: 6/15/2015 3:52:01 PM Keywords ()

One way is to promote self assessments

Euro NCAPEnergy efficiency

Another is to legislate

Better yet – use both

Page 22: Presentation AP2SI IoT ESC - WordPress.com · Presentation_AP2SI_IoT_ESC Author: Freewind Rider Created Date: 6/15/2015 3:52:01 PM Keywords ()

Score

Access Controls

Code Testing

UserAgreements

Transparency

Privacy

EncryptionTampering

Resilience

Supply chain

Cloud

Page 23: Presentation AP2SI IoT ESC - WordPress.com · Presentation_AP2SI_IoT_ESC Author: Freewind Rider Created Date: 6/15/2015 3:52:01 PM Keywords ()

No testing

Full testing

Page 24: Presentation AP2SI IoT ESC - WordPress.com · Presentation_AP2SI_IoT_ESC Author: Freewind Rider Created Date: 6/15/2015 3:52:01 PM Keywords ()

Building Code for Medical Device Software Security by Tom Haigh e Carl Landwehrhttp://cybersecurity.ieee.org/images/files/images/pdf/building-code-for-medica-device-software-security.pdf

Five Star Automotive Cyber Safety Frameworkhttps://www.iamthecavalry.org/wp-content/uploads/2014/08/Five-Star-Automotive-Cyber-Safety-February-

2015.pdf

This presentation was inspired by:

https://www.youtube.com/watch?v=oqe6S6m73Zw

Page 25: Presentation AP2SI IoT ESC - WordPress.com · Presentation_AP2SI_IoT_ESC Author: Freewind Rider Created Date: 6/15/2015 3:52:01 PM Keywords ()

http://www.theregister.co.uk/2015/05/13/19_beeelion_of_electronics_waste_illegally_dumped_says_un/

Page 26: Presentation AP2SI IoT ESC - WordPress.com · Presentation_AP2SI_IoT_ESC Author: Freewind Rider Created Date: 6/15/2015 3:52:01 PM Keywords ()

Thank you for your time

Questions?

Page 27: Presentation AP2SI IoT ESC - WordPress.com · Presentation_AP2SI_IoT_ESC Author: Freewind Rider Created Date: 6/15/2015 3:52:01 PM Keywords ()

Find us on:

https://ap2si.org

https://facebook.com/ap2si

[email protected]