How To Keep IoT From Becoming An IoTrash

Roberts, Wysopal, Doctorow, Wheeler, Giese

DEF CON 32 Main Stage · Day 1 · Main Stage

Overview

This DEF CON 32 panel, "Bricked and Abandoned: How to Keep the IoT From Becoming an Internet of Trash," delves into the critical and growing problem of abandonware and end-of-life (EOL) devices within the Internet of Things (IoT) ecosystem. Moderated by Paul Roberts of The Security Ledger and ReversingLabs, with a distinguished panel including Chris Wysopal (Veracode), Tara Wheeler (Red Queen Dynamics), and Corey Doctorow (author and activist), the discussion highlights the stark disparity between the physical lifespan of smart hardware and the significantly shorter support cycles for their embedded software. The panel argues that this disconnect transforms once-useful devices into insecure, unrepairable, and ultimately disposable "Internet of Trash," posing significant security, economic, and environmental challenges.

Watch on YouTube

Visual summary for How To Keep IoT From Becoming An IoTrash by Roberts, Wysopal, Doctorow, Wheeler, Giese
Visual summary for How To Keep IoT From Becoming An IoTrash by Roberts, Wysopal, Doctorow, Wheeler, Giese

Key moments

  1. 0:00 Talk introduction: IoT becoming Internet of Trash
  2. 1:00 Right-to-Repair movement's legislative successes
  3. 2:00 Core problem: software end-of-life for long-lived hardware
  4. 3:00 Panelist introduction: Chris Wysopal
  5. 3:50 Panelist introduction: Tara Wheeler
  6. 4:00 Panelist introduction: Corey Doctorow

How To Keep IoT From Becoming An IoTrash

Speakers: Roberts, Paul; Wysopal, Chris; Doctorow, Corey; Wheeler, Tara; Giese

Conference: DEF CON 32

YouTube: https://www.youtube.com/watch?v=tA7bpp8qXxI

Overview

This DEF CON 32 panel, "Bricked and Abandoned: How to Keep the IoT From Becoming an Internet of Trash," delves into the critical and growing problem of abandonware and end-of-life (EOL) devices within the Internet of Things (IoT) ecosystem. Moderated by Paul Roberts of The Security Ledger and ReversingLabs, with a distinguished panel including Chris Wysopal (Veracode), Tara Wheeler (Red Queen Dynamics), and Corey Doctorow (author and activist), the discussion highlights the stark disparity between the physical lifespan of smart hardware and the significantly shorter support cycles for their embedded software. The panel argues that this disconnect transforms once-useful devices into insecure, unrepairable, and ultimately disposable "Internet of Trash," posing significant security, economic, and environmental challenges.

The talk frames this issue as a direct consequence of prevailing intellectual property (IP) and copyright laws, coupled with decades of lax market consolidation oversight, which collectively grant manufacturers immense control over their products post-sale. While the burgeoning right to repair movement has made considerable strides in ensuring physical repairability, it often falls short of addressing the software obsolescence that renders devices functionally useless or insecure long before their hardware fails. The panelists underscore the urgent need for a more comprehensive approach that considers the entire lifecycle of smart devices, ensuring their longevity and security for consumers, businesses, and communities alike.

Why this talk matters is multifaceted. As IoT proliferates, from smart homes to critical infrastructure, the accumulation of insecure, unsupported devices creates an expanding attack surface. These "bricked and abandoned" devices are not just an inconvenience; they represent potential vectors for cyberattacks, data breaches, and environmental waste. The panel's discussion is a crucial call to action, urging a re-evaluation of current industry practices and regulatory frameworks to foster a more sustainable and secure future for connected technologies.

Background

▶ Watch: Talk introduction: IoT becoming Internet of Trash (0:00)

The genesis of this panel discussion stems from the successes and limitations observed within the right to repair movement. For years, activists and consumers have battled manufacturers who restrict access to parts, tools, and documentation necessary for repairing electronic devices. This movement has achieved notable legislative victories, with five U.S. states now enacting comprehensive electronics right-to-repair laws. These landmark legislations cover a broad spectrum of products, including home appliances, iPads, iPhones, and, significantly, agricultural devices like farm equipment in Colorado, and B2B devices such as Cisco routers. States like Colorado and Oregon have gone further, explicitly banning manufacturer practices like part serialization and part pairing, which are technical mechanisms designed to prevent unauthorized repairs by tying specific components to a device's unique identifier, rendering replacements unusable without manufacturer approval.

Despite these legislative triumphs, a fundamental problem persists, forming the core of the panel's concern: the lifespan of hardware versus software support. As Paul Roberts articulates, a smart refrigerator with a touchscreen panel might have a physical hardware lifespan stretching "a couple decades or more." However, the manufacturer's commitment to supporting the software running on that panel, including security updates and feature enhancements, often extends for only "three years, five years, something like that." This creates a critical vulnerability point. Once software support ends, devices become susceptible to unpatched vulnerabilities, rendering them insecure and potentially dangerous to the networks they connect to.

This disparity is exacerbated by the prevailing legal and economic landscape. Current intellectual property (IP) and copyright laws, originally designed for static content, are ill-suited for the dynamic nature of software-driven hardware. These laws, combined with decades of government inaction regarding market consolidation, have granted manufacturers "pretty wide latitude" over products once sold to the public. This unchecked power allows companies to dictate the functional lifespan of devices through software support policies, effectively forcing consumers and businesses into a cycle of premature obsolescence and replacement, regardless of the physical durability of the hardware. The result is a growing inventory of functionally obsolete but physically sound devices—the "Internet of Trash"—that continues to pose risks and drain resources.

Key Findings

▶ Watch: Core problem: software end-of-life for long-lived hardware (2:00)

The panel identified several critical findings regarding the trajectory of IoT devices and their eventual obsolescence, collectively painting a grim picture of the "Internet of Trash" phenomenon. The central discovery is the profound mismatch between the physical durability of hardware and the ephemeral nature of software support. While a smart appliance or industrial IoT device might be engineered to last for decades, its embedded software, which dictates its functionality and security posture, often receives active support for only a fraction of that time, typically three to five years. This planned obsolescence, driven by manufacturer policies rather than hardware failure, is a significant contributor to the problem.

Another key finding relates to the limitations of the otherwise successful right to repair movement. While recent legislative victories in states like Colorado and Oregon have empowered consumers and independent repair shops to physically mend devices by banning restrictive practices like part serialization and part pairing, these laws primarily address mechanical and component-level repairs. They do not, for the most part, compel manufacturers to provide long-term software updates or security patches for devices whose hardware remains perfectly functional. This means that even a physically repairable device can become a security liability or functionally useless once its software is no longer updated, effectively creating a "bricked" experience without physical damage.

Furthermore, the panel highlighted that the current legal and economic frameworks heavily favor manufacturers, granting them undue control over the entire lifecycle of their products. Intellectual property rights and copyright laws, initially conceived for different contexts, are now leveraged to restrict access to diagnostic tools, firmware, and software updates. This, coupled with a historical lack of government intervention in market consolidation, has allowed a few dominant players to dictate terms that prioritize new sales over product longevity and consumer rights. This leads to a situation where consumers, businesses, and even critical infrastructure operators are "at the mercy of manufacturers," unable to secure or maintain their investments in smart technology over the long term.

Finally, the talk implicitly underscores the escalating security risks posed by this trend. An ever-increasing number of unsupported IoT devices connected to home and enterprise networks translates directly into an expanding attack surface. These devices, no longer receiving security patches, become ideal targets for botnets, data exfiltration, and entry points for broader network compromises. The panel's findings collectively emphasize that the "Internet of Trash" is not merely an inconvenience or an environmental concern; it is a burgeoning cybersecurity crisis that demands immediate and systemic attention.

Technical Deep Dive

▶ Watch: Panelist introduction: Chris Wysopal (3:00)

The technical ramifications of unsupported IoT devices extend far beyond mere inconvenience, creating a complex web of vulnerabilities and operational challenges. The core of the problem lies in the software lifecycle management practices—or lack thereof—for embedded systems within IoT hardware. Unlike traditional computing platforms where OS and application updates are often independent of hardware vendors, IoT devices frequently rely on proprietary firmware and software stacks that are tightly coupled with the manufacturer's ecosystem.

When a manufacturer declares a device end-of-life (EOL) for software support, it means that several critical technical processes cease:

  1. Security Patching: This is arguably the most significant technical issue. Modern software, especially networked software, inevitably contains vulnerabilities. Without ongoing security patches, known flaws remain unaddressed, making these devices prime targets for exploitation. This can range from simple denial-of-service attacks to full device compromise, allowing attackers to pivot to other systems on the network.
  2. Feature Updates and Bug Fixes: Beyond security, EOL status means no new features, no performance improvements, and no fixes for non-security-related bugs. This can lead to degraded functionality, incompatibility with newer services, and a general decline in the user experience, even if the hardware is physically sound.
  3. API and Cloud Service Deprecation: Many smart devices rely on backend cloud services for their core functionality (e.g., voice assistants, remote control, data analytics). Manufacturers can deprecate or shut down these APIs and services without recourse for users of EOL devices, rendering them completely inoperable regardless of their local software state. This effectively bricks the device from a functional perspective, even if the hardware is fully powered and connected.
  4. Interoperability Issues: As other devices and network protocols evolve, unsupported IoT devices may struggle to maintain interoperability. This can lead to fragmentation within smart home or enterprise environments, where older devices cannot communicate or integrate with newer ones, hindering the creation of cohesive smart systems.

The discussion around part serialization and part pairing further illuminates the technical control manufacturers exert. These practices involve embedding unique identifiers in components (e.g., a specific screen, battery, or sensor) and linking them cryptographically or via firmware to the device's main board. If a user attempts to replace a failed component with an identical, off-the-shelf part, the device's software might detect a "mismatch" and refuse to function, display a warning, or operate in a degraded mode. This is achieved through firmware-level checks that verify the authenticity and pairing of components, often using cryptographic signatures or unique hardware identifiers. While manufacturers claim this ensures quality and security, it technically serves to monopolize repairs and enforce reliance on proprietary repair channels. Banning these practices, as Colorado and Oregon have done, forces manufacturers to relax these software-enforced component restrictions, allowing for more open repair.

From a network perspective, an "Internet of Trash" creates a vast reservoir of zombie devices. These devices, often with weak default credentials or unpatched vulnerabilities, are easily co-opted into botnets for distributed denial-of-service (DDoS) attacks, spam campaigns, or cryptocurrency mining. The Mirai botnet, for example, famously exploited default credentials and known vulnerabilities in insecure IoT devices like IP cameras and DVRs, demonstrating the real-world impact of a large pool of unmanaged, insecure hardware. The sheer volume and diversity of IoT devices make their collective security posture a critical concern for global internet stability.

The panel's emphasis on B2B devices like Cisco routers in right-to-repair legislation highlights an even more critical technical dimension. Enterprise-grade networking equipment, while perhaps not "IoT" in the consumer sense, shares the same software dependency. If a business cannot repair a critical router due to part pairing or is forced to operate it with EOL software, the implications for network uptime, data integrity, and compliance are severe. The technical deep dive into this problem reveals that it's not just about consumer frustration, but about systemic risks to digital infrastructure.

Demo / Proof of Concept

▶ Watch: Panelist introduction: Tara Wheeler (3:50)

This session was presented as a panel discussion, focusing on the systemic issues and policy implications surrounding IoT abandonware and end-of-life devices. As such, no live technical demonstration or proof of concept was presented by the speakers. The objective was to analyze the problem, discuss its context within the right-to-repair movement, and explore potential solutions through expert dialogue rather than showcasing specific exploits or technical interventions.

Defensive Implications

▶ Watch: Panelist introduction: Corey Doctorow (4:00)

The proliferation of unsupported and insecure IoT devices presents a significant challenge for individuals and organizations alike, demanding a multi-faceted defensive strategy. For consumers, the primary defensive implication revolves around informed purchasing decisions and network segmentation. Individuals should prioritize buying devices from manufacturers with transparent and robust software support policies, clearly outlining the duration of security updates and feature support. Furthermore, isolating IoT devices on a separate VLAN (Virtual Local Area Network) or guest network can limit their ability to interact with more sensitive devices (like personal computers or data storage) if compromised. Regularly checking for and installing available firmware updates, even if infrequent, is crucial for maintaining whatever security posture the device still possesses.

For businesses and critical infrastructure operators, the defensive implications are more complex and carry higher stakes. Organizations must implement rigorous asset management practices to track all connected IoT devices, their manufacturers, and their respective EOL dates. This includes maintaining an inventory of firmware versions and understanding the security implications of each. Network segmentation becomes even more critical in enterprise environments, using firewalls and access controls to strictly limit communication pathways for IoT devices. Devices that are past their EOL date and cannot be replaced or updated should be considered high-risk and either decommissioned, isolated in highly restricted networks, or rigorously monitored for anomalous behavior.

From a broader perspective, organizations should advocate for and support legislative efforts that mandate longer software support lifecycles and promote open-source firmware options where feasible. The concept of security by design must extend to the entire product lifecycle, not just initial deployment. This includes demanding secure boot mechanisms, regular security audits, and transparent vulnerability disclosure programs from IoT vendors. Furthermore, the development of community-driven firmware or third-party patching initiatives could offer a lifeline for devices abandoned by their original manufacturers, requiring a legal framework that allows for such modifications without violating IP laws.

Ultimately, the defensive strategy against the "Internet of Trash" requires a shift in mindset: recognizing that a connected device's security is only as strong as its weakest, most unsupported link. Proactive planning for device refresh cycles, robust network architectures, and a commitment to advocating for industry-wide change are paramount to mitigating the risks posed by this growing problem.

Key Takeaways

  • Software Obsolescence Threatens Hardware Longevity: The core issue is the stark disparity between the decades-long lifespan of IoT hardware and the mere 3-5 years of software support from manufacturers, leading to premature functional obsolescence.
  • Right to Repair is Progress, But Insufficient: While the right-to-repair movement has secured significant legislative wins in states like Colorado and Oregon, banning practices like part serialization and part pairing for physical repairs, these laws often do not address the critical problem of long-term software support and security updates.
  • Manufacturers Wield Excessive Control: Current IP and copyright laws, coupled with unchecked market consolidation, grant manufacturers broad latitude to dictate the post-sale life of smart products, often prioritizing new sales over product longevity and consumer security.
  • Insecure Devices Create a Growing Attack Surface: Unsupported IoT devices, lacking security patches, become "abandonware" that poses significant cybersecurity risks, serving as potential entry points for botnets, data breaches, and broader network compromises.
  • Economic and Environmental Impact is Significant: The "Internet of Trash" contributes to substantial electronic waste and forces consumers and businesses into costly, unnecessary replacements, despite physically functional hardware.
  • Urgent Need for Systemic Change: Addressing this problem requires a multi-pronged approach involving legislative reform to mandate longer software support, industry accountability for product lifecycles, and user awareness regarding device security and longevity.

About the Speaker(s)

Paul Roberts served as the moderator for this panel. He is the Publisher and Editor-in-Chief at The Security Ledger, the Head of Editorial Content at ReversingLabs, and the founder of the new nonprofit Secure Resilient Future Foundation (Surf). His work often focuses on issues like the right to repair and the broader implications of technology policy.

Chris Wysopal is the CTO of Veracode, a company specializing in application security and testing technology. He has a notable background as a vulnerability researcher and renowned hacker with The L0pht. In 1998, Chris, along with six of his L0pht colleagues, provided pivotal testimony before the U.S. Senate on matters of U.S. government cybersecurity, highlighting his long-standing expertise in the field.

Tara Wheeler is the founder and CEO of Red Queen Dynamics. She also holds a position as a Senior Fellow in Global Cyber Policy at the Council on Foreign Relations. Wheeler is a recognized speaker and writer, frequently addressing topics such as cyber warfare, security best practices, and future trends in cybersecurity.

Corey Doctorow is a prominent figure known for his work as a science fiction writer, author, activist, and journalist. He has penned numerous books, with his most recent works including "The Bezel" and "The Lost Cause." In 2020, Doctorow was inducted into the Canadian Science Fiction and Fantasy Hall of Fame, acknowledging his significant contributions to literature and advocacy.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

This panel dissects the critical problem of IoT abandonware, highlighting the stark disconnect between hardware longevity and ephemeral software support. It effectively frames this as a systemic issue driven by outdated IP laws and market consolidation, rather than just a consumer inconvenience. The discussion provides valuable insights into the limitations of current right-to-repair efforts and outlines the escalating security, economic, and environmental risks, offering a compelling call for legislative and industry-wide change.

Heather Calloway (CISO) — STRONG ACCEPT

This DEF CON panel insightfully tackles the growing liability of IoT abandonware, where durable hardware is rendered insecure and unusable by premature software end-of-life. It correctly frames this as a critical governance and business risk, stemming from institutional failures in intellectual property law and market oversight, rather than merely a technical problem. The discussion provides a clear understanding of the systemic challenges and offers actionable insights for security leaders to address long-term device security through procurement, asset management, and policy advocacy.

→ Top-rated talks at DEF CON 32 Main Stage

All talks from DEF CON 32 Main Stage