Live data from Hacker News

What If We Put Warnings on IoT Devices?

troyhunt.com

131–140 of 159 posts

Re: What If We Put Warnings on IoT Devices?

#131

In California, there is a law that basically everywhere (e.g. all apartment complexes) must have a sign that specifies that the compounds used on site can cause cancer or birth defects or whatever. But because the signs are pervasive, they are basically useless. This feels kind of like that.

The signs in California aren't useless because the signs are useless; they're useless because of the specific implementation.

If you do have an area with known-dangerous substances, and don't put up the sign, you get hit with a penalty significant enough to hurt. If you don't have anything dangerous, but do put up a sign, nothing bad happens to you. So rather than actually check for what's there and put up the sign only when relevant, everyone errs on the side of "better put up the sign just in case".

Re: What If We Put Warnings on IoT Devices?

#132
Z-wave and encrypted ZigBee controlled products work pretty well for in-home automation. Communication is encrypted between devices.

The problem can be the Z-wave/ZigBee controller which may very well require Internet and Cloud access to "phone home."

I avoid using IoT devices that I can't re-program or if nothing is available except some proprietary/cloud driven device I isolate them into their own little network space, so they can't attack the rest of the network or "phone home" unless I let them. Sometimes, that isn't possible and that's when 30 day return privileges come in real handy.

The ability to trace the packets coming off of most IoT devices is fascinating and sometimes scary. A lot of devices are like the recent OnePlus smartphones that record and send most everything to their "true master" the manufacturer of the device. At least, with a Oneplus you can fix that, by reflashing the phone.... which is not true of most IoT devices being sold today.

Have you noticed that BestBuy seems to only sell IoT devices that will "phone home?"

Re: What If We Put Warnings on IoT Devices?

#133
I get the humor value, but isn't this just elitism from the software folks? Should we add similar warnings to websites of startup companies? Or during the installation of pretty much every single OS?

I saw some folks recommending punitive damages against IoT companies that ship this insecure junk. Well how about prosecuting software devs who introduce security vulnerabilities?

Re: What If We Put Warnings on IoT Devices?

#134

Z-wave and encrypted ZigBee controlled products work pretty well for in-home automation. Communication is encrypted between devices. The problem can be the Z-wave/ZigBee controller which may very well require Internet and Cloud access to "phone home." I avoid using IoT devices that I can't re-program or if nothing is available except some proprietary/cloud driven device I isolate them into their own little network sp…

You gotta have a link for what you said about the OnePlus.

Re: What If We Put Warnings on IoT Devices?

#135

Z-wave and encrypted ZigBee controlled products work pretty well for in-home automation. Communication is encrypted between devices. The problem can be the Z-wave/ZigBee controller which may very well require Internet and Cloud access to "phone home." I avoid using IoT devices that I can't re-program or if nothing is available except some proprietary/cloud driven device I isolate them into their own little network sp…

You gotta have a link for what you said about the OnePlus.

There was a post on /r/Android about it [1], but it seems like you can toggle this off by disabling device analytics in the settings.

[1]: https://www.reddit.com/r/Android/comments/75ev0z/oxygenos_is...

Re: What If We Put Warnings on IoT Devices?

#136

Earlier quoted context omitted.

This is the same problem with the cookie law in Europe. They allowed one single, generic, disclaimer which every site pops up. If they'd demanded: - a separate disclaimer for each domain (or at least company) setting a cookie - a description of the purpose of the cookies (e.g. advertising, remembering log-ins) Then the law might have actually achieved something.

TBH, you need to put a cookie warning only if you use cookies for stuff like tracking and advertising. Logins and general site functionality are extempt from that. Basically, cookie warning on site means the site tracks you.

I did not know this. I do not think cookie warning == site tracking. Many of those pop-ups are people thinking they need it due to the law.

Re: What If We Put Warnings on IoT Devices?

#137

In California, there is a law that basically everywhere (e.g. all apartment complexes) must have a sign that specifies that the compounds used on site can cause cancer or birth defects or whatever. But because the signs are pervasive, they are basically useless. This feels kind of like that.

I think the current champion for disgusting-but-necessarily-put-out-of-mind required California signage is the "pool diarrhea rules". See for example:

https://boingboing.net/2016/09/07/the-messy-fight-to-stop-ca...

Re: What If We Put Warnings on IoT Devices?

#138
post #98

Earlier quoted context omitted.

Well, a doorbell is not exactly a part of the foundation and it is easily replaced. My house from the 1930's has seen several doorbells already.

This isn't limited to the doorbell. It's the doorbell, the stereo system (Sonos), the connected garage door, the alarm, the security cameras, the thermostat, ... they're all dependent on their dedicated app. When the vendor stops updating the app that goes with a 5-yo product that they no longer sell, at some point that app will no longer work under the new version of your mobile OS (iOS 16? 17?), and you'll have to…

> There's a huge amount of obsolescence coming down the pike in 5-10 years.

I think that's okay, overall. These things should all be considered prototypes and shouldn't be expected to last forever. [I also think a certain about of obsolescence is sensible and even good given the potential upsides to maintaining people or teams capable of designing, manufacturing, and supporting specific products or services.]

Re: What If We Put Warnings on IoT Devices?

#139

Earlier quoted context omitted.

I've actually always appreciated that we have that... coming from a less liberal place, it made me feel like the state really cared about peoples' safety over the safety of corporations, and it's usually easy enough to find more information online about the compounds.

Trying using a CA compliant gas can to fill up your CA compliant riding mower then put said mower in reverse and back it out of wherever it's parked. For bonus points do so without a helper. Stickers and warnings are one thing. Mandating consumer safety features can go wrong easily. In some areas "this product not for sale in CA" is a marketable feature. On small engines it means it's tuned to run well instead of min…

Is it such a bad thing to value reduce emissions from some of the worst forms of easily avoidable pollution, i.e. spilled gas and two stoke engines?

If you were around when the air quality in LA was almost as bad as what we are seeing now in places like Beijing, you might agree with some of the provisions that were enacted (and were hugely successful at reducing pollution not only in CA, but elsewhere due to said "features".)

Re: What If We Put Warnings on IoT Devices?

#140
post #27

Simple rule: I buy it, I own it and it should not need an external service to operate. If it does then I'm not buying it. None of those grafted on services for me, I really have yet to see anything that was so compelling that I would give up and consent to essentially renting a device and having an account with some service to make it useful. That way you also don't need to warn anybody about the lousy security, I'm…

> Simple rule: I buy it, I own it and it should not need an external service to operate. If it does then I'm not buying it. That's a good rule, but good luck opting out once most manufacturers no longer give you an option.

Surely the idea of overt, explicit labelling about the risks of using these devices is to create the possibility of competing brands using their better security/privacy as an advantage, and thus promote more secure and private products?

I've long advocated the basic idea from the article here, but in a much more blunt way, with explicit warnings about the potential consequences:

Identity theft is the fastest rising crime in COUNTRY.

The average victim loses $X permanently and takes Y months to get their life back.

THIS PRODUCT DOES NOT MEET PRIVACY STANDARD Z SO YOU ARE MORE LIKELY TO BECOME A VICTIM IF YOU USE IT. COMPETING PRODUCTS MAY BE AVAILABLE.

(Or something along those lines. You get the idea.)

Post reply on HN