Live data from Hacker News

Schneier: It's Time to Regulate IoT to Improve Cyber-Security

eweek.com

21–30 of 185 posts

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#21
post #3

Not that I'm a fan of government regulation for technology issues like this but the security situation is beyond a joke. For one, it's time to hold companies (and executives!) accountable for security of the data they are charged with protecting, often without your consent (eg Equifax). For another, insufficient product liability for companies being lax--even negligent--with security. Honestly I don't see an outcome…

> And all for what? So you can turn the lights on after you go through multiple steps to unlock your phone? I wanted network-connected lightbulbs so I could have them turn on at the time I needed to wake up, when that time was well before dawn. I never installed them because I didn't know how to secure them and my schedule got more reasonable, but I think the use case is pretty compelling.

Why would light bulbs need to be connected to the Internet for the use case of being turned on at a specific time? They'd just need to be connected to a timer for this.

I mean, an Internet connected light bulb use-case would a bulb that flashed whenever a stock you owned went down in price, which is ridiculous despite being the least ridiculous example I could think of.

IoT security cameras and an automated kitchen you phone to, to prepared you dinner if you were coming home unexpected seems like the least crazy IoT device an individual could own - most IoT stuff seems more like what a global company would want rather than an individual.

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#24

I don't think that government certification is the answer here. This will turn security into a check-mark. Companies will do the bare minimum to get certified and won't invest a penny more. This would solve some of the more extreme cases we see, but I doubt it'll make a real impact. Instead, I feel that accountability would work much better here. If you're selling an IoT device, and you haven't taken industry standar…

I think Schneier is right. The market has utterly failed here and there is no reason to think it will start working. Class action lawsuits are very slow and you have issues of trying to prove actual harm. To use his example if my TiVo is part of a botnet but continues working perfectly, have I been harmed in a way that’s likely to let me sue someone?

What happens when you want to sue a company for lack of updates when the company went out of business 6mo after it was created (like Juciero)? You can’t sue them, where a law could have forced them to be secure from the start or put up a bond to support the devices for a while.

Companies will do the bare minimum to get certified? You realize that’s a massive jump compared to what happens now.

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#25

Of course Schneier would want regulation in Iot. That's literally billions of tax dollars that would go to his and other tech consulting and compliance companies. What we really should push for is Open source regulation. Naturally government is always behind on cutting edge tech issues. Open source regulation would improve the efficiency of regulation while saving billions of dollars.

This is the correct answer.

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#26

Earlier quoted context omitted.

> And all for what? So you can turn the lights on after you go through multiple steps to unlock your phone? I wanted network-connected lightbulbs so I could have them turn on at the time I needed to wake up, when that time was well before dawn. I never installed them because I didn't know how to secure them and my schedule got more reasonable, but I think the use case is pretty compelling.

Why would light bulbs need to be connected to the Internet for the use case of being turned on at a specific time? They'd just need to be connected to a timer for this. I mean, an Internet connected light bulb use-case would a bulb that flashed whenever a stock you owned went down in price, which is ridiculous despite being the least ridiculous example I could think of. IoT security cameras and an automated kitchen y…

> despite being the least ridiculous example I could think of.

A lighbulb flashes when visitors ring the doorbell, which is useful for people with visual impairment. the doorbell has a hidden rfid reader, and certain guests have an rfid card. the doorbell flashes differently for each visitor.

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#27

On the surface, I agree with this. In practice I expect it to result in fewer products on the market that are more expensive and no more secure as this sort of regulation will simply select for large companies who are experts at paperwork and soft bribes. I wish I had a better idea.

...this sort of regulation will simply select for large companies who are experts at paperwork and soft bribes

What do you mean "this sort?" Schneier just says "we need regulation", that's pretty definitely all the article says.

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#28

Bullshit. What makes 'IoT' any different from an ordinary network-connected computer? You're either saying "it's time to regulate networked computing devices" or, "I want to carve out an easygoing regulation-free niche for MY product[s] to artificially excel in." I try not to be needleslly pessimistic, but this article has no definition of 'IoT' beyond 'networked computer with sensor', so three guesses as to which on…

I can easily update my Mac or my Windows PC. I also know that Apple and MS will be around for a while.

How do I update my lightbulb? Who will make updates for? Maybe Phillips will for their product but what about smaller OEMs? What if the company quickly goes out of business like Juicero?

Depending on what you buy and where you buy it do people even know who made it? Would you even know how to check for updates (assuming they exist)?

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#29
post #20

Even though many people scoff at the idea of government regulations, the economic incentives in IoT security are really all messed up and it's not really clear that the market will fix itself because so much of the damage can be externalized somehow. Does the manufacturer of a cheap and outdated IoT device care if it's participating in some ddos attack? Or like Schneier said, does the consumers care if they don't not…

> opening the source code once security updates for the device stop, so consumers could help themselves

That might help the readers of HN, but not users in general. Most users won't bother installing security updates for their PC if it's not forced on them. Updating one's light bulbs with something off github is a non-starter.

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#30
One thing that should be happening is that ISPs should have to monitor traffic to look for DoS agents, bad bots and perhaps some common vulnerabilities, with the ability to throttle the pipe or shut it off if problems aren't remedied.

Regulating IoT is tougher, but is analogous to licensing the airwaves.

Post reply on HN