‹ BackHN Continuity

Thread

Hackers Got Inside a Flock Camera

586 points · 270 comments · driverdan

  1. killbot5000 · · focus · HN ↗
    This is pure laziness aka “reduced time to market” on the part of Flock.

    It takes time and effort to think through proper secure boot architecture and to implement key management in a way that doesn’t kill developer productivity.

    Their product managers, though, should have realized that setting these up in unsecured public spaces means that their threat model really does include local physical access to everything.

    Using off the shelf hardware and software stacks all but guarantees attackers have tools at their fingertips to exploit said physical access.

    Given all the recent exploits hitting the kernel, there’s a good chance that there exists an exploitable over-the-air vulnerability present in their WiFi/bluetooth stack, too.

    1. dietr1ch · · focus · HN ↗
      I really hate how Product Managers somehow get to take the reins of engineering teams instead of having to sell them product ideas.

      It's madness, they often lack the technical skills and "optimise away" requirements surfaced by eng teams they don't comprehend or just don't like having to deal with.

      1. pixl97 · · focus · HN ↗
        Because software engineering is not professional engineering.

        Now, this doesn't always stops management, but when you have to have an engineering signoff it does make things a bit more difficult.

        1. robocat · · focus · HN ↗
          Do you feel like an inadiquate imposter or something? I'm assuming you work in software.

          Watch some engineers in other disciplines and you soon recognise that many of them have about the same responsibility as a software engineer. Design is design.

          Or read about engineering failures like flight QF32 (mostly a success story):

            A paperwork review showed that the required signatures were missing from 131 out of 138 retrospective concessions issued between 2009 and 2011
          
          <a href="https:&#x2F;&#x2F;admiralcloudberg.medium.com&#x2F;a-matter-of-millimeters-the-story-of-qantas-flight-32-bdaa62dc98e7" rel="nofollow">https:&#x2F;&#x2F;admiralcloudberg.medium.com&#x2F;a-matter-of-millimeters-...

          Australian Quantas, with a UK Rolls Royce engine on an Airbus, with engines maintained in Aussie.

          Safety is now often made up of interlocking: regulations, standards, quality systems, safety management systems, insurance, international legal contracts. Certified engineers and signatures are usually only a very small part of those systems.

          Certification matters less than you might think across international borders.

          Perhaps I&#x27;m a cynic, but beliefs in certification seem so irrational to me. What is it? Jealous desires for status? Desire to have guilds&#x2F;gatekeepers? Complete misunderstanding of how safety occurs in &quot;real&quot; engineering?

          1. stonogo · · focus · HN ↗
            Your conclusion seems at odds with your evidence: the quote you reference indicates that a professional engineer was meant to examine the &#x27;retrospective concessions&#x27; and did not. The result was that no qualified engineer was taking responsibility for their quality. Fixing the process meant getting credentialed engineers to assess and incur liability for the solutions, which is how the professional engineering licensure system is supposed to work.
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.