Home > Blog

Security Vulnerability – POODLE – CVE-2014-3566

Posted on: No Comments

Overview

In the last few weeks, We have had a number of questions regarding the new vulnerability nicknamed “POODLE” CVE-2014-3566.”  As for every vulnerability, we review each one carefully to determine the impact to our devices and services, and we try to make a recommendation to our customers on the anticipated impact of these vulnerabilities. In these last weeks, we have conducted a risk analysis of this new vulnerability, as well as we are testing all of our devices for this vulnerability. Since this new vulnerability is coming down on the heels of HeartBleed and Shellshock, I am anticipating that many people will be covering this new vulnerability.

Analysis13334048894_001d3e53d1_z

In our testing, we have found that many of our devices are impacted. This is in part because of the backward compatibility that we have built within our products. However, we have determined that very few customers are using these features, and we are actively removing the SSLv3 support for new firmware versions going forward. We have already fixed this issue in a number of devices, and we are in the middle of releasing new versions of firmware with this issue fixed.

Impact

As for every vulnerability, we review each one carefully to determine the impact to our devices and services, and we try to make a recommendation to our customers on the anticipated impact of these vulnerabilities. However, since we do not know each specific configuration and data that our customers are using for our products and services, it is always suggested that the customer review their unique situation and understand what the risk could be to their environment. However, we have found that with our products, that we rate this a “very low” impact.

Notice

Please check the official Digi and Etherios corporate response to poodle at http://www.digi.com/support/kbase/kbaseresultdetl?id=3619

 

As always, if you have any questions, feel free to email cloud.security@etherios.com, or security@digi.com

Look What I Made: XBee Project Updates

Posted on: No Comments

We are always finding amazing XBee projects. From robots, to rockets, to gardens–the creativity of XBee makers is endless. We have some new additions to the XBee Project Gallery and wanted to share them with you.  Let us know your favorite!

XBeeGallery

Wireless Firework Control System
It’s safe to say this is the most explosive project in the gallery. This wireless system allows you to control the launching of fireworks from a control unit that has 200 channels.

CanSat Solar Powered Data Collection
A team of student engineers from Guatemala needed a way to send data between a flying a rocket and a base station located on the ground. The rocket contained a payload, which collects sensor data as it falls back to the ground. What makes this project truly amazing is the fact that the whole system is solar powered!

Animatronic Ironman Suit
Yes, someone has made a full-scale replica of Ironman. No, it does not fly. You can find XBee inside the suit’s helmet. Wiring was used throughout the replica, but the designer ran into a problem when he needed to create a wireless helmet, so it would be easy to take on and off. There’s even a video of the suit in action.

Wireless Controlled Hand
Gabry built this for his final high school project. It consists of XBee and an Arduino Lilypad. The user puts on a glove and as they move their hand another robotic hand mimics the motion of the user.

Do you have an XBee project you would like featured in the XBee Project Gallery? You can submit your own or someone else’s project here.

The Pool Makes Headlines Around the World

Posted on: No Comments

The Pool, built by Jen Lewin, is an interactive light sculpture connected with XBee. It’s been a busy year for Jen as she’s been touring around the world sharing The Pool everywhere from Singapore, to Australia to Burning Man. Here are a few recent articles and videos that detail the travels of one of our favorite XBee projects.

[Video] Jen Lewin: Artist dazzles with light and sound installations | BBC

An Exclusive First Look at the Other-Worldly Art of Burning Man 2014 | Huffington Post

Festival of Lights Illuminates Downtown Cleveland | Design Boom

Sustainable Art Glows Bright in Singapore | NBC News

You can learn more about The Pool in the XBee Gallery. Check out Jen Lewin’s website and like her on Facebook to get more information on what she’s working on. Maybe you’ve been lucky enough to see The Pool first-hand? Share your photos with us at @XBeeWireless.

Mass Transit Demos and More at Arrow IoT Immersions

Next week, we’ll be heading down to Atlanta for Arrow IoT Immersions. This stop will be part one in a series of four events, where Arrow and other leading tech companies tour around the country sharing IoT technology and how it’s changing industries. At the show we’ll have three IoT demos to share with you. Here’s a little bit of information on what we’ll be up to during the event and where you can find us:

Mass Transit Bus with ConnectCore 6Digi at Arrow IoT Immersions
We’re extremely excited to be a part of the Mass Transit demo, which showcases how IoT tech is already changing our transit systems. Inside the bus, you will find a Digi ConnectCore 6. The ConnectCore 6, based on the Freescale i.MX6 processor, drives multiple high definition monitors that provide bus location data as well as vehicle diagnostic information to the driver. Other companies that will be on board this mass transit demo include: Intel, Microsoft, Advantech, Microchip, Eurotech.

If one connected transit demo isn’t enough, we have good news. We’ll also be showing off Digi’s Wireless Vehicle Adapter, aka WVA. This handy device opens up a local Wi-Fi network and streams real-time vehicle diagnostic information to a tablet. Stop by our kiosk in the Cloud Pavilion to give it a try. We’ll have a tablet loaded with an Android application for you to play with.

Connected Health Care
We’ll also be sharing how Internet of Things is changing healthcare. There’s an enormous opportunity to use internet connected devices to improve outpatient care. We’ve built a connected blood pressure cuff, which enables caregivers to provide excellent service to patients even if they are outside the hospital.

The blood pressure device was modified with XBee, which enables communication to the cloud. Since the device is connected to the internet, caregivers can easily set up alarms so they’re notified whenever an abnormal condition is met. You can try this demo out for yourself in the Medical Pavilion.

More Information for Arrow IoT Immersions
In addition to our demos, Digi CTO, Joel Young, will be a part of the Solutions Sessions alongside other technology experts. Specifically, they’ll be discussing how the Internet of Things is impacting business, specifically cloud computing and connecting from the network’s edge into the enterprise. Want to attend, but not yet registered? Head over to the IoT Immersions page to sign up.

One Small Step for XBee, One Giant Leap for Wireless

Posted on: 2 Comments

This winter, Soarex, a NASA sounding rocket, will be launched into space with XBee on-board.  The three-node network is the first XBee ZigBee network to go to space. The rocket will fly roughly 200 miles above earth to test a new parachute-like technology called an exo-brake. Exo-brakes are used to safely return samples from the Earth’s orbit as well as land spacecrafts on other planets that with much thinner atmospheres than Earth.

2
Typically the devices that collect samples are connected with wiring. The team chose to move away from traditional wiring and experiment with a wireless network for a number of reasons. For one, less cabling on the spacecraft means less weight, which reduces the amount of fuel needed. Another important feature is the ability to relay this data back down to earth via an Iridium satellite. The Soarex will monitor six different acceleration parameters as well as temperature and air pressure.

This wireless network is part of an effort by NASA to test the performance of wireless on a spacecraft and determine if it will be suitable for other applications. Due to the high cost associated with launching a rocket, the team must be extremely conservative when implementing new technology. Once the network performs multiple successful trials, the team will incorporate XBee into more and more vital missions.

When NASA chooses to experiment with new technology, the initial budget is relatively small, so the engineers went with off-the-shelf components to build out the network. The team is working with Digi’s XBee ZB modules, Arduino microcontrollers, and Sparkfun’s XBee adapter shields.  If the trial run is a hit, they’ll work to build a more customized solution– one that might even feature the XBee Plus!

Soarex will launch with XBee in January 2015. We’ll share some more information and let you know how it goes, so check back in! Until then, check out this video to get an idea of the wild ride XBee will be taking.

XBee Visits World Maker Faire New York 2014

Posted on: No Comments

Maker Faire is one of our favorite events of the year. We get to meet everyone that’s making with XBee, introduce others that may not be familiar, and see amazing projects like giant robotic giraffes and connected motorcycles. We’ve got tons of pictures to share with you from what was a great event.

XBee Projects

And if you stopped by our booth and looking to build any of the demos we had on display, visit examples.digi.com for instructions. Or if you’ve built a project with XBee, be sure to submit it to the XBee Gallery.

Thanks again to everyone that stopped by to hangout with us. Have photos or videos from Maker Faire that you’d like to share? Let us know in the comments section below or on Facebook or Twitter!

This Week in the Internet of Things: Friday Favorites

Posted on: No Comments

The Internet of Things is developing and buzzing all around us. Throughout the week we come across innovative projects, brilliant articles and posts that support and feature the innovators and companies that make our business possible. Here’s our list of favorites from this week’s journey on the Web.

1GRAIN1223.jpg
The Changing Face of High Tech in Minnesota | Star Tribune

Salesforce CEO Discusses New Wearables, Internet of Things Startup Fund | ZDNet

Lighting Up Future Utility Models | M2M Now

Using the Internet of Things to Deliver Effortless Customer Service | Salesforce

Internet of Things Can Increase Effectiveness of Field Workers | Rigzone

Please tell us in the comments below or Tweet us, @DigiDotCom- we would love to share your findings too. You can also follow all of the commentary and discussion with the hashtag #FridayFavorites.

A Simpler and More Intelligent Internet of Things with Digi and Temboo

Posted on: No Comments

The ongoing drought in the western United States underscores the importance of maintaining and conserving a reliable supply of fresh water—whether for drinking, irrigation, fire control or manufacturing, reliable water storage is essential. Of course, half the battle in maintaining a water supply is managing it: once a tank system has been installed and filled, water must be properly distributed when it is needed and retained when it is not. If tanks are remote and many are spread over a wide area, monitoring them can become a costly and time-consuming obligation.

Screen Shot 2014-09-04 at 12.03.09 PMThese are the sorts of challenges that Digi and Temboo are overcoming by building a more intelligent Internet of Things. A network of Digi hardware running Temboo Choreos is flexible and smart—devices can be programmed to execute a wide variety of processes, and be reprogrammed without being interrupted. This is a solution that combines ease of automation with the trustworthiness of manual control. To illustrate the solution’s benefits, and demonstrate how the whole system works, we’ve built a model of the water tank problem. This system puts Temboo and Digi to work, keeping water levels right where they ought to be.

Our tank monitoring solution uses an XBee ZigBee radio to wirelessly exchange sensor information and remote control commands using Digi’s new XBee Gateway, a programmable device that joins ZigBee mesh networks to the Internet. A small Temboo client written in Python is installed on the XBee Gateway, allowing it to connect to over one hundred different web services using Temboo Choreos. With Temboo, the memory constraints of the small devices in the network cease to be an obstacle to intelligent behavior, as much of the code required to execute complex processes is offloaded to the cloud.

In our model, a sensor attached to the XBee radio monitors the water level of our tank, and sends those readings to the XBee Gateway. If the tank leaks and the water level falls, a response is triggered on the gateway. First, the gateway uses Temboo’s Yahoo Weather Choreos to check the forecast for rain. Temboo’s Nexmo Choreos are then used to telephone the relevant individual with an automated voice message that gives a real time rain forecast and offers a choice of actions to take by entering a number on the phone’s keypad.

Screen Shot 2014-09-04 at 11.56.33 AMIf a storm is on its way, there is an option to ignore the alert. If the leakage does not need to be urgently addressed, there is an option to schedule a maintenance event for the future, which the Temboo program on the gateway handles via a Google Calendar Choreo . If the situation is urgent, however, there is another option to activate a backup pump at a different point in the XBee network and refill the tank.  Of course, all of this will only work properly if the sensor and gateway are powered on and functioning, so our system needs to be prepared for any loss of connectivity—if, for any reason, transmission of the level of water in the tank stops, another Temboo Choreo will file a Zendesk ticket to alert support that the system needs attention.

The most exciting thing about this model, however, is that it is only a small example of a massively scalable system. XBee technology can connect hundreds of different devices in a much larger network, and Temboo’s Library contains over two thousand other Choreos that can be used to execute an immense variety of tasks. Modifying the behavior of the Temboo program on the gateway to, for example, switch notification services is just a matter of changing Choreos, a simple task.  Digi’s hardware and Temboo’s software are coming together to build a lighter, smarter and much easier to use Internet of Things.

Demo created using:

Are you using Temboo or XBee in your Internet of Things application? You can share how you’re using wireless technology by tweeting us at @XBeeWireless and @Temboo.