Live data from Hacker News

What If We Put Warnings on IoT Devices?

troyhunt.com

101–110 of 159 posts

Re: What If We Put Warnings on IoT Devices?

#101

Earlier quoted context omitted.

Or how much of it there is. Parts per million/billion? I'm pretty interested in how much cadmium and mercury gets into my system because they're bad news for the brain. At the same time, mercury is also in air so it's kind of inescapable. Parts per billion is interesting information because then I can control how much I ingest the way I do for food that is fattening.

It would be much more useful if it were in the form of "This property contains substances determined by the state of California to be toxic to humans. The site report may be viewed in person at 123 Maple St, Suite 200, San Mateo, or electronically at https: //sitereport.ca.us/ " Then the print report would basically be a binder full of MSDS-like information sheets, along with the history of measurements recorded on t…

This is the same problem with the cookie law in Europe.

They allowed one single, generic, disclaimer which every site pops up.

If they'd demanded:

- a separate disclaimer for each domain (or at least company) setting a cookie

- a description of the purpose of the cookies (e.g. advertising, remembering log-ins)

Then the law might have actually achieved something.

Re: What If We Put Warnings on IoT Devices?

#102

In California, there is a law that basically everywhere (e.g. all apartment complexes) must have a sign that specifies that the compounds used on site can cause cancer or birth defects or whatever. But because the signs are pervasive, they are basically useless. This feels kind of like that.

I have always wondered if you included both what was cancer causing and what it would cost the company/location to get rid of it on the sign it would be even better.

Re: What If We Put Warnings on IoT Devices?

#103

I'm of the opinion that products which require a separate service to perform their advertised functions (i.e. a "cloud" service-- be it "free" with the product or subscription-based) should be clearly labeled as such. I know that I don't actually own anything that I can't self-host (or pay whoever I want to host it), but it's clear that most people don't. Public education on this front seems valuable to me (but, then…

> I'm one of those crazy people who believes in standards-based protocols and commodity hosting service). If that counts as crazy, then lock me up, because I'm crazy too. I'll second everything you said, but I'm not so sure it's entirely ignorance - I believe a large number of people just don't care (which is ignorance of another kind).

They don't know to care. That's why I think we need public education. As companies who make these "IoT" devices go bust and the various Internet-enabled cloud widgets the general public has purchased turn into bricks people will get an "education" of a sort.

Re: What If We Put Warnings on IoT Devices?

#104
post #34

I'm of the opinion that products which require a separate service to perform their advertised functions (i.e. a "cloud" service-- be it "free" with the product or subscription-based) should be clearly labeled as such. I know that I don't actually own anything that I can't self-host (or pay whoever I want to host it), but it's clear that most people don't. Public education on this front seems valuable to me (but, then…

Yes. There's this doorbell (400-1500 USD) that connects via internet to a central host, and then notifies you on your smartphone. Seems sort of a neat idea, but a house lasts several decades - is that startup and its server going to be around that long? http://www.doorbird.com

It also notifies that central host every time someone visits your home, and provides them with video and audio of that person. That doesn't seem like a "neat idea" at all.

"By visiting my front door, you agree to Doorbird's privacy policy"

Re: What If We Put Warnings on IoT Devices?

#105
post #77

Earlier quoted context omitted.

Right now I'm writing my bachelor's thesis on IoT platforms. I think the real problem is that there's no real established pattern for authentication (the way there is for things like signing up for a web app). You ship devices and there isn't a 'one true way' for authenticating them against your platform, authenticating the user, partnering the user with the device, and then encrypting all traffic from the device to…

> I think the real problem is that there's no real established pattern for authentication (the way there is for things like signing up for a web app). No. The real problem is that a device you bought requires internet access for no good reason, spies on you ("collects information") with no good reason, and becomes useless garbage once the company that sells it goes out of business or decides to terminate the product…

I agree with you, from the nerd perspective. The general public cares more about utility than privacy, unfortunately, but the equation is similar in both cases: are we getting more value than we’re giving up in control?

Much as HyperCard, Excel, etc have allowed non-nerds to solve their own problems or scratch an itch, there is room in IoT for these people to tinker. They just need the right tools and framing.

Re: What If We Put Warnings on IoT Devices?

#106

In California, there is a law that basically everywhere (e.g. all apartment complexes) must have a sign that specifies that the compounds used on site can cause cancer or birth defects or whatever. But because the signs are pervasive, they are basically useless. This feels kind of like that.

I once saw a sign on a door of a hotel in the bay area that said something like "this door leads to an area with stuff that can cause cancer". If you went through that door, you ended up outside.

Technically, the sign wasn't wrong, but come on California...

Re: What If We Put Warnings on IoT Devices?

#107
post #63

Simple rule: I buy it, I own it and it should not need an external service to operate. If it does then I'm not buying it. None of those grafted on services for me, I really have yet to see anything that was so compelling that I would give up and consent to essentially renting a device and having an account with some service to make it useful. That way you also don't need to warn anybody about the lousy security, I'm…

> it should not need an external service to operate. If it does then I'm not buying it. And how do you know, pre-purchase, whether it does?

Usually there is something to be found on the internet about whatever it is that you are about to purchase and this most of the time is pretty accurate about hidden online components that ought to be disclosed but aren't. For instance the Nest, when I first heard about it I was interested, when I realized it is tied to a service I decided not to buy it. Ditto smart doorlocks and other clever IoT stuff that seemed attractive until I found out that it requires 'always on' internet and is hard or even impossible to upgrade besides not being clear about what data is being sent to the mothership.

My navigator is an elderly TomTom, my phone an old Nokia and so on. I seem to be stuck in stuff that is now a generation or two behind the times but I've yet to be convinced that the 'new' stuff is better in a way that outweighs the privacy and security risks.

Re: What If We Put Warnings on IoT Devices?

#108

Simple rule: I buy it, I own it and it should not need an external service to operate. If it does then I'm not buying it. None of those grafted on services for me, I really have yet to see anything that was so compelling that I would give up and consent to essentially renting a device and having an account with some service to make it useful. That way you also don't need to warn anybody about the lousy security, I'm…

While this is still possible (usually) when buying physical goods, it is getting to be nearly impossible for software. Good luck buying professional grade graphics or video editing software without getting signing away any agency over the software. In fact, depending on how you view "intellectual property" laws, anything that isn't public domain could be considered a "grafted on service"

Like with the various hardware bits that I use this would probably cause me to get stuck in the past at some point in time. Fortunately for me my tools are free (text editor, compiler) but I can see that in some professions you are now forced into buying a subscription for software where you'd much rather just pay for a license and the occasional update. Congratulations at becoming a dairy cow, even so this article was about IoT and there most services feel grafted on without any kind of improved functionality, in the case of software-by-subscription (which I think is a fairer name that software-as-a-service) one could argue that the distribution model has changed but the functionality is roughly what you pay for. Not that there aren't obvious drawbacks to software 'in the cloud'.

Re: What If We Put Warnings on IoT Devices?

#109
post #28

Earlier quoted context omitted.

> It would be interesting to have a word for devices that is sort of like 'organic' for food. > It would indicate that the device is self-contained and has no connectivity. "Well-designed"?

>"Well-designed"? Very good one. A good candidate would have been "smart", but unfortunately it is already taken to mean the opposite.

I use "dumb". Sure, it sounds negative, but when used in context it's easy to understand for anyone that knows about "smart devices".

Re: What If We Put Warnings on IoT Devices?

#110
post #104
post #34

Earlier quoted context omitted.

Yes. There's this doorbell (400-1500 USD) that connects via internet to a central host, and then notifies you on your smartphone. Seems sort of a neat idea, but a house lasts several decades - is that startup and its server going to be around that long? http://www.doorbird.com

It also notifies that central host every time someone visits your home, and provides them with video and audio of that person. That doesn't seem like a "neat idea" at all. "By visiting my front door, you agree to Doorbird's privacy policy"

Couldn't the same be said about all the other shitty cloud-connected surveillance cameras? Not saying that justifies it, just that this is a bigger problem then just those awful internet of doorbells
Post reply on HN