@cotufa82
DevOps + IOT + Security
No Secrets!
$whoami
Diana Rodríguez
Google Developers Expert:
- Web Technologies - Google Maps Platform
- Google Cloud Platform - Firebase
Auth0 Ambassador
Python Developer Advocate @ Vonage
Google Developers Group Organiser @ GDG Durham
🦄 https://superdi.dev
🐦 @cotufa82
<likes> Food, Infrastructure, Food, Vue.js, Food, Travelling, IOT, Steven Universe </likes>
$whoami-NOT
DevOps & IOT!!?
Effects of DevOps
The adoption of DevOps culture, tools and agile engineering practices has, among other things, the nice effect of increasing the collaboration between the roles of development and operations. One of the main problems of the past (but also today in some realities) is that the dev team tended to be uninterested in the operation and maintenance of a system once it was handed over to the ops team, while the latter tended to be not really aware of the system’s business goals and, therefore, reluctant in satisfying the operational needs of the system (also referred to as “whims of developers”).
Vue.js Docs
Dream Team
It's all about the feedback...
- DevOps is about... faster time to feedback
- In the IOT world our feedback is about device performance and usage
- design and automate pipelines to improve the quality of our deliveries
- design our code to gain insight around performance and usage
- design our services to identify how we can drive the most value for customers && business
Collect data, perform analytics against that data, and tune it over time to achieve improvements in usage!!
- predictive maintenance (based on actual usage characteristics)
- improve energy consumption or other consumables to improve the quality of the service
- connected devices modify their performance based on customers' unique needs and actions.
- The same principles apply to Wearables & Industrial IOT
- Identify the reason!
- Establish a way to capture insights: on the device(s), a web service, etc...
- Is your update around customer satisfaction, engagement, or something else? How do you measure the effect of this update?
- Is it through the increase in consumption of a service, reduction in support calls, or some other metric?
- FEEDBACK LOOP - DELIVER
FEEDBACK === Faster and better enhancements/updates/repairs
Devices
Code
Infrastructure
SECURITY
* Source: Auth0
* Source: Auth0
- 52% of respondents believe that most IoT devices on the market right now DO NOT have the necessary security in place
- 49% of respondents don’t trust having their personal/private data tied to IoT devices – but still use them
- Only 18% of people trust having their personal data tied to IoT devices
- Nearly 35% claimed that the breaches of major companies have not had much of an effect on the trust or consumer interest in these brands
- 85% of developers surveyed have felt rushed to get an application to market due to demand/pressure in the last 6 months
- 90% of developers surveyed do not believe that IoT devices on the market currently have the necessary security in place
😱
Users Want Smart Homes, but Smart Home Device Security Isn’t Inviting
Wait.. Wearables too?
150 MILLION USERS...
Suggestions...
- Design and implement a secure model for your update process
- Secure product interfaces with authentication, integrity protection and encryption
- Obtain an independent security assessment of connected products
- Implement a secret key for root chains and security on devices
-
What devices are we using?
-
What information do we share?
-
What information do we have access to?
And a quick example...
And a quick example...
FEEDBACK
SECURITY
THANK YOU!!!
DevOps+IOT+Security: No Secrets
By Super Diana
DevOps+IOT+Security: No Secrets
- 1,006