This is also a business model problem. Consumer hardware companies do not have the margin to make and support software that needs to run for ten years or more. Before the iPhone, software and hardware were often different and had different business models.
Schneier: It's Time to Regulate IoT to Improve Cyber-Security
31–40 of 185 posts
Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security
#32IoT router/firewall might be one of the solution here, i.e. adding IoT pattern into existing routes/firewalls to protect IoT devices, in addition to your PCs and sometimes BYODs(smart phones etc).
It is very hard to make all IoT devices secure due to limited resource they have, so the first line of protection should be done on the router/firewall/gateway I think.
Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security
#33Sure, the idea of billions of devices around the world connected somehow is scary, but government regulation is not the answer. If anything, regulation needs to be decentralized. More open source, community involvement with reviews and discussions, more self regulation
Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security
#34Even though many people scoff at the idea of government regulations, the economic incentives in IoT security are really all messed up and it's not really clear that the market will fix itself because so much of the damage can be externalized somehow. Does the manufacturer of a cheap and outdated IoT device care if it's participating in some ddos attack? Or like Schneier said, does the consumers care if they don't not…
What reasonable case is there for making them not liable for the damages caused?
Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security
#35I guess it only took this long for enough people to become insane enough to justify a market for it.
Preach on brother Bruce!
Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security
#36This is also a business model problem. Consumer hardware companies do not have the margin to make and support software that needs to run for ten years or more. Before the iPhone, software and hardware were often different and had different business models.
Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security
#37Earlier quoted context omitted.
Why would light bulbs need to be connected to the Internet for the use case of being turned on at a specific time? They'd just need to be connected to a timer for this. I mean, an Internet connected light bulb use-case would a bulb that flashed whenever a stock you owned went down in price, which is ridiculous despite being the least ridiculous example I could think of. IoT security cameras and an automated kitchen y…
> despite being the least ridiculous example I could think of. A lighbulb flashes when visitors ring the doorbell, which is useful for people with visual impairment. the doorbell has a hidden rfid reader, and certain guests have an rfid card. the doorbell flashes differently for each visitor.
Take it one step further, and you could trigger it via an NFC read of your vistors' phones. This also would not need to connect to a network (beyond installing the app on the phones).
Actually, sounds like it might be a fun project to play with :D
Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security
#38Bullshit. What makes 'IoT' any different from an ordinary network-connected computer? You're either saying "it's time to regulate networked computing devices" or, "I want to carve out an easygoing regulation-free niche for MY product[s] to artificially excel in." I try not to be needleslly pessimistic, but this article has no definition of 'IoT' beyond 'networked computer with sensor', so three guesses as to which on…
I can easily update my Mac or my Windows PC. I also know that Apple and MS will be around for a while. How do I update my lightbulb? Who will make updates for? Maybe Phillips will for their product but what about smaller OEMs? What if the company quickly goes out of business like Juicero? Depending on what you buy and where you buy it do people even know who made it? Would you even know how to check for updates (assu…
Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security
#39Even though many people scoff at the idea of government regulations, the economic incentives in IoT security are really all messed up and it's not really clear that the market will fix itself because so much of the damage can be externalized somehow. Does the manufacturer of a cheap and outdated IoT device care if it's participating in some ddos attack? Or like Schneier said, does the consumers care if they don't not…
> opening the source code once security updates for the device stop, so consumers could help themselves That might help the readers of HN, but not users in general. Most users won't bother installing security updates for their PC if it's not forced on them. Updating one's light bulbs with something off github is a non-starter.
Edit: To complete the thought, it's not generally that hard to flash devices that support it, so a report that says "X,Y and Z have exploits, here are some options" could go a long way. Making devices support some minimum standard of local upgradability would help immeasurably.