Saturday, December 15, 2018

"China Targets Control Over Internet of Things for Spying, Business" (IoT)

A smart piece from a surprising source.
I'm pretty sure this is the first time we've linked to the Free Beacon since they went all political in 2016, our thinking being readers can find that stuff, left, right, breatharian, whatev pretty much anywhere. I mean the barriers to entry for political commentary are set pretty low

Anyhoo, from the Washington Free Beacon, October 25:

Report warns Beijing working to dominate Internet
China is aggressively seeking to dominate the Internet of Things and plans to use access to billions of networked electronic devices for intelligence-gathering, sabotage, and business purposes, according to a forthcoming congressional report.

China for nearly a decade has been investing heavily in the emerging technology on the Internet of Things (IoT) and has made outpacing similar U.S. efforts one of the ruling Communist Party of China's highest strategic goals.

"China’s unique approach to the development of IoT and its enabling infrastructure poses significant challenges for U.S. economic and national security interests," says a report by the U.S.-China Economic and Security Review Commission due out Thursday.

"The highest echelons of the Chinese regime view IoT development and deployment as critical matters of China’s economic competitiveness and national security."

A major concern outlined in the report is China's efforts to uncover vulnerabilities in IoT systems that can be used by Beijing for strategic objectives in both peacetime and war, the report said.

"Aside from industrial control systems, unauthorized access to health care devices could kill patients and exploitation of smart car vulnerabilities could kill drivers and pedestrians alike, among other examples of possible misuse of data and devices that could have dire consequences," the report warns.

"The future destructive potential of unauthorized access to IoT devices appears potentially limitless."

The IoT is an ill-defined term for a global information and communication infrastructure. It is made up of linked devices ranging from biomedical devices for monitoring patients to self-driving cars to critical infrastructure.

The universe of IoT devices includes billions of electronic systems such as, video cameras, smart phones and smart watches, and industrial control systems used in electric grids.
Chinese IoT objectives include building "smart cities" that monitor public utilities, flows of people and traffic, underground pipelines, and air and water quality, the report said.

Other Chinese IoT plans include advanced remote industrial controls; medical IoTs; smart homes equipped with remote controls for appliances and security systems; and smart cars linking vehicle sensors to drivers, roads, cloud services, and other electronic devices.
The IoT is expanding rapidly and will be further enhanced with emerging advanced information technologies, such 5G cellular technology.

Use of 5G networks will increase the ability of networked devices to interact through faster data transfer speeds.
China, according to the report, is working on major programs to find vulnerabilities in IoT technology ostensibly for cyber security.

However, the report suggests the research is cover for plans to conduct for cyber espionage, sabotage, and military cyber reconnaissance using the Internet of Things.

One example of an IoT cyber attack took place in 2016 when the malware known as the Mirai botnet infiltrated thousands of linked devices by scanning the Internet for video cameras—most made in China—and DVRs that were not protected and easily accessed by using default passwords such as "password."

Mirai "commandeered some one hundred thousand of these devices, and used them to carry out a distributed denial of service (DDoS) attack against DynDNS that shut down many popular websites," the report said.

A second botnet called IoTroop targeted several brands of Chinese-made Internet Protocol cameras in late 2017.

A Chinese case discovered in 2016 by security researchers revealed that firmware update software made by the Shanghai ADUPS Technology Co. Ltd. was secretly siphoning off private data and sending it to China.

"ADUPS’s firmware update software is currently in use on more than 700 million low-end mobile phones and IoT devices around the globe, including devices in the United States," the report said.
Chinese IoT researchers also are preparing to use cyber attacks against the "Internet of Underwater Things" that has applications for submarine warfare.

"The imperfect availability of enemy location information in underwater warfare offers a strategic advantage to any nation with advanced underwater sensor technology, and compromised IoT devices and sensor networks operating underwater at a variety of depths could nullify any such advantage," the report said....MUCH MORE
HT to a friend to whom I mentioned the U.S.-China Economic and Security Review Commission in the context of what Huawei is up to.
We'll have more on that next week.