Live data from Hacker News

Schneier: It's Time to Regulate IoT to Improve Cyber-Security

eweek.com

41–50 of 185 posts

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#43
post #20

Even though many people scoff at the idea of government regulations, the economic incentives in IoT security are really all messed up and it's not really clear that the market will fix itself because so much of the damage can be externalized somehow. Does the manufacturer of a cheap and outdated IoT device care if it's participating in some ddos attack? Or like Schneier said, does the consumers care if they don't not…

demanding opening the source code once security updates for the device stop

They probably don't even have the (usable) source code.

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#44
post #24

I don't think that government certification is the answer here. This will turn security into a check-mark. Companies will do the bare minimum to get certified and won't invest a penny more. This would solve some of the more extreme cases we see, but I doubt it'll make a real impact. Instead, I feel that accountability would work much better here. If you're selling an IoT device, and you haven't taken industry standar…

I think Schneier is right. The market has utterly failed here and there is no reason to think it will start working. Class action lawsuits are very slow and you have issues of trying to prove actual harm. To use his example if my TiVo is part of a botnet but continues working perfectly, have I been harmed in a way that’s likely to let me sue someone? What happens when you want to sue a company for lack of updates whe…

Make consumers liable. They're really the guilty (by negligence) party anyway, right? Okay, that would be a shock to the system. So grandfather in old devices and/or slowly phase it in.

That's still quite a chilling effect though. Well, maybe it should be. Now we're really careful about what we buy. But maybe it's too much. Who wants to expose themselves to a small chance of high liability? Okay, so allow insurance against said liability. Wouldn't that defeat the purpose? Well, no. Insurance companies would only insure against liability for devices they've vetted and approved.

Boom, market regulation. It works for cars (see IIHS).

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#45

On the surface, I agree with this. In practice I expect it to result in fewer products on the market that are more expensive and no more secure as this sort of regulation will simply select for large companies who are experts at paperwork and soft bribes. I wish I had a better idea.

...this sort of regulation will simply select for large companies who are experts at paperwork and soft bribes What do you mean "this sort?" Schneier just says "we need regulation", that's pretty definitely all the article says.

Any regulation tends to select for companies that can appear to comply at the lowest cost.

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#46

Of course Schneier would want regulation in Iot. That's literally billions of tax dollars that would go to his and other tech consulting and compliance companies. What we really should push for is Open source regulation. Naturally government is always behind on cutting edge tech issues. Open source regulation would improve the efficiency of regulation while saving billions of dollars.

Could you elaborate? I'm being genuine here when I say that I have no idea what you mean by Open Source Regulation.

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#47
post #24

I don't think that government certification is the answer here. This will turn security into a check-mark. Companies will do the bare minimum to get certified and won't invest a penny more. This would solve some of the more extreme cases we see, but I doubt it'll make a real impact. Instead, I feel that accountability would work much better here. If you're selling an IoT device, and you haven't taken industry standar…

I think Schneier is right. The market has utterly failed here and there is no reason to think it will start working. Class action lawsuits are very slow and you have issues of trying to prove actual harm. To use his example if my TiVo is part of a botnet but continues working perfectly, have I been harmed in a way that’s likely to let me sue someone? What happens when you want to sue a company for lack of updates whe…

From my POV all I can come up with that feels concrete is somehow trying to figure out a plan / system where we can ensure companies that should have a certain level of security can be held liable (no question) in a way that prevents things from being handled in a reactionary way. The problem I keep running into is that each and every scenario and company this type of system will effect will be a case-by-case basis.

I can't brainstorm many simple solutions that blanket cover many different types of businesses, markets and scenarios.

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#48
post #24

I don't think that government certification is the answer here. This will turn security into a check-mark. Companies will do the bare minimum to get certified and won't invest a penny more. This would solve some of the more extreme cases we see, but I doubt it'll make a real impact. Instead, I feel that accountability would work much better here. If you're selling an IoT device, and you haven't taken industry standar…

I think Schneier is right. The market has utterly failed here and there is no reason to think it will start working. Class action lawsuits are very slow and you have issues of trying to prove actual harm. To use his example if my TiVo is part of a botnet but continues working perfectly, have I been harmed in a way that’s likely to let me sue someone? What happens when you want to sue a company for lack of updates whe…

You're right, and perhaps ideally we should have a mix of both accountability and certification. I don't know who could or would sue TiVo for the attack, and I don't know how to solve the problem of out of business companies. This approach has its drawbacks.

However, give the certification process some thought too. I can see quite a few drawbacks here as well.

First, a significant advantage for established, rich companies. We'll be swamped with IoT from Apple, Google, Facebook and Amazon while small competitors have a hard time getting their products to the market.

Second, you'd need give the regulatory body access to both your software and your hardware. And what if the device is connected to some cloud server? That body may need to look at its code too to make sure that your control server is compliant. And what about the network? The database? Where does it end? And do you need to re-certify each and every version of your server? What if you introduce a security vulnerability?

Third, certification can't be a one-time deal. That protocol your lightbulb uses to talk to the microwave oven for whatever reason? Well, someone broke that and can now make both of them divulge your dirtiest secrets. The same regulatory body would have to keep track of such vulnerabilities and force manufacturers to update their devices - and what if the manufacturer has gone bankrupt? What if he doesn't want to update these devices? Are you going to force people to throw away their light bulbs? You'll have to, otherwise you're back to square one in which all devices are compromised, only now it takes a little bit longer.

Imagine the bureaucracy all of this will require.

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#49

One simple way to improve your security at home is to have a "guest" WiFi network which is separate from your real one and which all these questionable IoT devices can use.

That doesn't necessarily prevent them from infecting each other and other people/devices on the internet, or being used in attacks.

It's sort of like living in a neighborhood and having a rock pile you enjoy the aesthetics of, but know it's prone to having rattlesnakes move in, and instead of fixing the rattlesnake problem either as it happens or at the root, just putting a wall around your property excluding the pile. Sure, you're mostly safe, but when animals/children get bit, your solution starts to look quite a bit worse.

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#50
post #28

Earlier quoted context omitted.

I can easily update my Mac or my Windows PC. I also know that Apple and MS will be around for a while. How do I update my lightbulb? Who will make updates for? Maybe Phillips will for their product but what about smaller OEMs? What if the company quickly goes out of business like Juicero? Depending on what you buy and where you buy it do people even know who made it? Would you even know how to check for updates (assu…

You can, but you very well might not. And your desktop computer is a far, far more valuable target in terms of computing power and network connectivity. Should we be regulating that device as protection against your choosing or forgetting to not follow best practices?

> And your desktop computer is a far, far more valuable target in terms of computing power and network connectivity.

It’s also FAR more secure. IoT devices are often easy to hack. And while they may not have much horsepower they have a network connection. You won’t mine many Bitcoins but it doesn’t take a lot power to be part of a DDoS.

And I have one computer, one tablet, one phone. I may have 5 smart lightbulbs, a DVR, a security camera or two, a indoor/outdoor thermometer....

Post reply on HN