Episode 377: Why there were 56 OT vulnerabilities this week

Episode 377: Why there were 56 OT vulnerabilities this week

Author: Stacey Higginbotham, tech journalist June 23, 2022 Duration: 57:32

This week we cover the Ericsson mobility report that offers some stats on cellular IoT connections, including the surprising nugget that we won’t see 4G/5G connections surpass 2G/3G connections until some time next year. Then we hit another report. This one is from NPR and covers the state of audio and smart speakers. It proves that growth is slowing for smart speakers and that we may not do as many things with voice as we think. In dystopian news we cover China using COVID tracking apps to lock down protesters, and Microsoft stopping sales of some facial recognition tools. In new product news we talk about the latest Philips Hue gear, a new material that could generate electricity for wearables, and new MCUs from NXP. We also address the closure of SmartDry and explain how Google’s update on the Nest Max Hub may break your Nest x Yale lock. We end by answering a listener question about more accurate motion sensors.

Our guest this week is Daniel dos Santos, head of security research at Vedere, a business unit of Forescout. He’s on the show to discuss why Forescout released 56 new OT vulnerabilities dubbed ICEFALL. He shares the design flaws that led to these vulnerabilities and more importantly, explains what needs to happen if compromised controllers or devices can’t be fixed. He also shares a startling stat about how many industrial customers are actually updating their devices after a vulnerability has been disclosed, and how to encourage more of them to address security flaws. If you want to learn more abut securing critical infrastructure, this is a good place to start.

Hosts: Stacey Higginbotham and Kevin Tofel
Guest: Daniel dos Santos, head of security research at Forescout
Sponsors: Nordic Semiconductor and Wirepas

  • There are still more 2G and 3G IoT connections than 4G/5G ones
  • With smart speakers it’s the same as it ever was
  • Are the new Hue track lights for you?
  • The ICEFALL vulnerabilities are a sign of progress actually.
  • This vendor says only one in ten patch their OT gear

The post Episode 377: Why there were 56 OT vulnerabilities this week appeared first on IoT Podcast - Internet of Things.


For anyone trying to make sense of a world where everything from your thermostat to a factory floor is getting smarter, The Internet of Things Podcast-Stacey On IoT offers essential context. Veteran tech journalist Stacey Higginbotham, who brings her experience from Fortune, and co-host Kevin Tofel break down the weekly flood of news, separating genuine innovation from mere hype. Their analysis spans the entire connected ecosystem, diving into the gadgets in our homes, the sensors transforming industrial workspaces, and the complex enterprise systems tying it all together. This isn't just theoretical; it's a practical guide to the business and technology decisions shaping our networked future. You'll hear from a range of voices that have built and critiqued this landscape, including pioneers like Vint Cerf, insightful commentators like Om Malik, and practitioners from companies such as Amazon, AT&T, and IBM Watson. Listening to this podcast provides a crucial framework for understanding the real-world implications of connectivity, whether you're an industry professional, a curious developer, or simply someone wondering how all these "smart" things actually work-and what they mean for privacy, security, and daily life. It's the clear-eyed conversation you need to navigate the ever-expanding Internet of Things.
Author: Language: en-us Episodes: 100

The Internet of Things Podcast - Stacey On IoT
Podcast Episodes
Episode 366: Meet a robot that weeds your garden [not-audio_url] [/not-audio_url]

Duration: 55:58
This week’s podcast starts with an update on the state of Bluetooth adoption courtesy of the Bluetooth SIG. We discuss adoption of Bluetooth in the smart home, adoption of Bluetooth mesh and why Kevin prefers NFC to Blue…
Episode 365: Helium gets a new name and $200 million [not-audio_url] [/not-audio_url]

Duration: 1:01:01
This week’s show was recorded on the road, but we still cover all of the big news starting with LoRaWAN network Helium changing its name to Nova Labs and raising $200 million. We then discuss research from MIT that offer…
Episode 364: Speed queens and Matter dreams [not-audio_url] [/not-audio_url]

Duration: 1:03:22
A week after the CSA said that the Matter smart home interoperability standard would be delayed we get a chance to talk about why the standard is delayed until fall, and what it means for consumers and smart home device…
Episode 363: How will DST affect the IoT? [not-audio_url] [/not-audio_url]

Duration: 1:00:06
This week, the U.S. Senate passed a bill that would make it possible for states to use Daylight Saving Time all year round, so we discuss what it means for IoT devices and whether or not it will be a return to Y2K. For c…
Episode 362: IoT security after Russia invaded Ukraine [not-audio_url] [/not-audio_url]

Duration: 56:29
This week’s show spends a lot of time on security in everything from an Amazon Echo to an infusion pump. But before we get to security stats, we offer a quick overview of Apple’s latest announcements. Then we pivot to di…
Episode 361: IoT builds a better mousetrap [not-audio_url] [/not-audio_url]

Duration: 1:03:28
This week’s show kicks off with a discussion about smarter robots and new funding for a Canadian general purpose robotics platform. Then we talk about Amazon’s further healthcare ambitions in a deal with Teledoc that let…
Episode 360: Europe’s planned IoT data law [not-audio_url] [/not-audio_url]

Duration: 52:47
The European Union is proposing new data regulations aimed at making it hard for companies to collect and use data as a barrier to competition. We talk about what it might mean for the IoT and Kevin also proposes that we…
Episode 359: Meet the man who “invented” the IoT back in 1985 [not-audio_url] [/not-audio_url]

Duration: 1:03:35
The National Institute of Standards and Technology has finally released its plans for securing the IoT, so we discuss what the plans are for a consumer-oriented cybersecurity label. We then give a quick update on the Sig…
Episode 358: Why Resideo’s First Alert buy makes sense [not-audio_url] [/not-audio_url]

Duration: 58:12
On this week’s show, we talk about the Resideo purchase of smoke detector company First Alert for $593 million and why it makes sense. Then we focus on connectivity with an update on the Sigfox receivership and a look at…
Episode 357: Too many companies are paying ransomware [not-audio_url] [/not-audio_url]

Duration: 58:35
This week we kick off the show with an explainer on Sigfox’s receivership before delving into grim news from Claroty, a cybersecurity firm. Claroty surveyed 1,100 IT and OT (operational technology) pros and discovered th…