Live data from Hacker News

Schneier: It's Time to Regulate IoT to Improve Cyber-Security

eweek.com

51–60 of 185 posts

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#51
Always love Mr. Schneier, but I think torts would be a better way of handling this.

There are several problems with regulation: a) Whack-a-mole, new ideas and business models arise faster than the speed of government. b) Regulatory capture, like what happened to our banking regulations. c) More often than not, penalties are captured by the regulator, but compensation is not made to the injured parties. d) International law / trade agreement complications. I'm sure there are many more.

If manufacturers knew they'd be on the hook for damages in a dollar-to-dollar way, they'd put more engineering into their work, they would price it accordingly, and personally I'd be fine with that.

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#52
post #26

Earlier quoted context omitted.

Why would light bulbs need to be connected to the Internet for the use case of being turned on at a specific time? They'd just need to be connected to a timer for this. I mean, an Internet connected light bulb use-case would a bulb that flashed whenever a stock you owned went down in price, which is ridiculous despite being the least ridiculous example I could think of. IoT security cameras and an automated kitchen y…

> despite being the least ridiculous example I could think of. A lighbulb flashes when visitors ring the doorbell, which is useful for people with visual impairment. the doorbell has a hidden rfid reader, and certain guests have an rfid card. the doorbell flashes differently for each visitor.

That only needs a local wireless (or whatever) connection between the reader and the light. X10 et al did this over power lines over 20 years ago. Communicating over 802.11 - with or without the internet - adds complexity and exposes the device to the world.

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#53
post #24

Earlier quoted context omitted.

I think Schneier is right. The market has utterly failed here and there is no reason to think it will start working. Class action lawsuits are very slow and you have issues of trying to prove actual harm. To use his example if my TiVo is part of a botnet but continues working perfectly, have I been harmed in a way that’s likely to let me sue someone? What happens when you want to sue a company for lack of updates whe…

You're right, and perhaps ideally we should have a mix of both accountability and certification. I don't know who could or would sue TiVo for the attack, and I don't know how to solve the problem of out of business companies. This approach has its drawbacks. However, give the certification process some thought too. I can see quite a few drawbacks here as well. First, a significant advantage for established, rich comp…

You’re right, it’s not easy. But even specifying hilariously trivial stuff like HTTPS, certificate pinning, no hardocded backdoors, and per-device random initial passwords would probably be a huge boon. Simple security without even talking about the problems on the service servers.

I imagine a market would appear for some of the basic software (Linux diaries, etc) to help make things easy for small companies that do want to do it all themselves.

I like the government idea because frankly I can’t think of anything else that would work (outside a rediculously improbable change in consumer behavior).

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#54
post #49

One simple way to improve your security at home is to have a "guest" WiFi network which is separate from your real one and which all these questionable IoT devices can use.

That doesn't necessarily prevent them from infecting each other and other people/devices on the internet, or being used in attacks. It's sort of like living in a neighborhood and having a rock pile you enjoy the aesthetics of, but know it's prone to having rattlesnakes move in, and instead of fixing the rattlesnake problem either as it happens or at the root, just putting a wall around your property excluding the pil…

Agreed, it's definitely not full-proof by any stretch. But it's amazing how many people enter their WiFi password into devices they really have no control over that can then for example sniff your network, slowly but steadily crack your passwords, possibilities are endless.

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#55
post #20

Even though many people scoff at the idea of government regulations, the economic incentives in IoT security are really all messed up and it's not really clear that the market will fix itself because so much of the damage can be externalized somehow. Does the manufacturer of a cheap and outdated IoT device care if it's participating in some ddos attack? Or like Schneier said, does the consumers care if they don't not…

> One thing that could kill the market is maybe making manufacturers liable for the damages caused by security holes in their devices, but regulation doesn't have to go that far to make an impact. What reasonable case is there for making them not liable for the damages caused?

You're right that they should be liable, but pragmatically it's maybe too much of a risk for smaller companies to face some potentially frivolous lawsuit for millions of damages supposedly caused by a ddos originating from some of their devices or something.

Surely the right idea in principle, though. I'm just not sure how realistic is it to implement in a smart manner.

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#56
post #24

Earlier quoted context omitted.

I think Schneier is right. The market has utterly failed here and there is no reason to think it will start working. Class action lawsuits are very slow and you have issues of trying to prove actual harm. To use his example if my TiVo is part of a botnet but continues working perfectly, have I been harmed in a way that’s likely to let me sue someone? What happens when you want to sue a company for lack of updates whe…

Make consumers liable. They're really the guilty (by negligence) party anyway, right? Okay, that would be a shock to the system. So grandfather in old devices and/or slowly phase it in. That's still quite a chilling effect though. Well, maybe it should be. Now we're really careful about what we buy. But maybe it's too much. Who wants to expose themselves to a small chance of high liability? Okay, so allow insurance a…

I’m a software developer. I’ve worked for a network security company.

I don’t think I’m qualified to try to do that for something I might buy, let alone ‘normal’ people.

That’s one of the problems with the market approach. The information assymetry is so big that it’s not a reasonable demand on a person for a $15-20 lightbulb.

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#57
While we all lament about incentives & regulation which are out of our control, there are still a lot of technical issues to solve, perhaps we can start there.

A few examples: - It's currently pretty hard to add HTTPS on a router admin page. - Browsers can't do service detection on a local network, so we have to resort to central servers to manage headless devices (or ugly, unreliable local IPs). - Punching through firewalls / NAT is still hard, so we again resort to central servers.

It's really fucking hard to do IoT at scale, in a easy-to-use way that's secure and that respects the user's privacy. I think we can solve that.

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#58
post #16
post #6

Earlier quoted context omitted.

Same reason it's illegal to drive a car that's not certified for roads or build a building that don't meet safety standards. You have a right to pose a danger to yourself. You don't have a right to pose a danger to others.

In my opinion you should be liable for any such danger you pose to others with the ability to shift that liability to whoever sold you source of such danger while assuring you that it is safe. In fact it is then inconsequential whether some device puts you in direct danger or in danger of somebody comming after you for putting them in danger.

> In my opinion you should be liable for any such danger you pose to others with the ability to shift that liability to whoever sold you source of such danger while assuring you that it is safe.

Right. So you, the little guy, is going to shift the blame to a rich company that does this for a living. Say it's a company such as Google which makes some IoT devices. Would you be able to prove in court, and in front of their engineers and lawyers that they've sold you an insecure device? Do you even have access to their source code?

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#59
post #26

Earlier quoted context omitted.

Why would light bulbs need to be connected to the Internet for the use case of being turned on at a specific time? They'd just need to be connected to a timer for this. I mean, an Internet connected light bulb use-case would a bulb that flashed whenever a stock you owned went down in price, which is ridiculous despite being the least ridiculous example I could think of. IoT security cameras and an automated kitchen y…

> despite being the least ridiculous example I could think of. A lighbulb flashes when visitors ring the doorbell, which is useful for people with visual impairment. the doorbell has a hidden rfid reader, and certain guests have an rfid card. the doorbell flashes differently for each visitor.

"A lighbulb flashes when visitors ring the doorbell, which is useful for people with visual impairment. the doorbell has a hidden rfid reader, and certain guests have an rfid card. the doorbell flashes differently for each visitor."

How is this an example of something that needs to be connected to the Internet. My point is most examples are about local connect to justify a jump into a world-wide, insecure net.

I mean, all the light bulb examples are contrived because a PHONE has all information-conveying ability of a light bulb and is designed for information-conveyance. Light bulb are designed for the light-consumption needs of those nearby and examples of light-bulb-control at a distance are either poor substitutes for phones or "weirdness" - haunted houses and art-happenings.

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#60
post #43
post #20

Even though many people scoff at the idea of government regulations, the economic incentives in IoT security are really all messed up and it's not really clear that the market will fix itself because so much of the damage can be externalized somehow. Does the manufacturer of a cheap and outdated IoT device care if it's participating in some ddos attack? Or like Schneier said, does the consumers care if they don't not…

demanding opening the source code once security updates for the device stop They probably don't even have the (usable) source code.

Arm recently announced an open source firmware for IoT devices. Now all it takes is for OEMs to want to replace their proprietary firmware with this (while keeping all bits open source as they extend it).

https://www.arm.com/news/2017/10/a-common-industry-framework

Post reply on HN