[HH] Internet of Things Festival (IoTfest) video

Tom Metro tmetro+hhacking at gmail.com
Sat Feb 22 18:25:08 EST 2014


If you missed IoTfest (http://www.iotfestival.com/) that happened
Saturday, Feb 22, they have a YouTube channel with many hours of the
talks available:

http://www.youtube.com/channel/UCqfN8BuvNgbPBR8O9l87_VQ/videos

They currently have them in long-form captures of the live stream. They
said they'll be chopping them up into individual talks.

I caught the tail-end of the live stream, with a talk by Jim Gettys (the
"buffer bloat" guy), whose parting message was "Friends Don't Let
Friends Run Home Routers With Factory Firmware", and then a talk by Bob
Frankston (co-creator of VisiCalc), who talked about Insteon home
automation devices, among other things.

I think the speaker before Jim Gettys was Jeff Schiller on "Security in
IoT cannot be an afterthought!" He shared a security tip he learned from
Bitcoin: Instead of embedding your public key in your firmware, to
validate updates, which apparently makes your PKI more vulnerable to
attack, you embed a hash of the key, and supply the public key with the
update. And change your key for each update, which means you supply a
new hash with the update for the key that will be used for next update.

 -Tom



More information about the Hardwarehacking mailing list