Live data from Hacker News

Schneier: It's Time to Regulate IoT to Improve Cyber-Security

eweek.com

91–100 of 185 posts

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#91
post #73

Earlier quoted context omitted.

Yes. In the postwar period, the word regulation typically entails new laws, possibly a new regulating agency, and a mix of civil and/or criminal penalties. I think a more liberal interpretation of existing torts would be simpler, more just, and harder to game.

It also encourages the tiering of IoT such that insecure-and-cheap remains on the market and is pushed towards people who can least afford to be pwned. Regulation is not blind, but it does raise the floor.

"least afford"??? As though these IoT devices weren't pure bored yuppie disposable income in the first place?

I would figure large service providers, and big companies with fleets of marginally protected devices, would be the ones to bear most of the damages coming from shoddy IoT devices being pwned and rolled into larger ddos/ransomware/etc attacks.

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#92
post #87

Earlier quoted context omitted.

> opening the source code once security updates for the device stop, so consumers could help themselves That might help the readers of HN, but not users in general. Most users won't bother installing security updates for their PC if it's not forced on them. Updating one's light bulbs with something off github is a non-starter.

If it's at least theoretically possible for a knowledgeable user to fix their devices, that's a pretty big improvement over it being a totally unfixable black box. For something like a lightbulb most people wouldn't bother, but if it's something like a car, a person without the technical skills to fix it themselves can pay someone else to do it.

It’s an improvement ideologically, I suppose, but not a practical reduction in economic damage potential. In a very real sense it doesn’t matter it you have quit making something seriously damaging if you need to disable millions or hundreds of millions of devices—ie some automatic update functionality is in itself hugely more helpful than just opening it.

Ideally we would have this suggestion in addition to a stick to ensure people have an incentive to sell relatively secure hardware.

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#93
post #90

Earlier quoted context omitted.

Why would light bulbs need to be connected to the Internet for the use case of being turned on at a specific time? They'd just need to be connected to a timer for this. I mean, an Internet connected light bulb use-case would a bulb that flashed whenever a stock you owned went down in price, which is ridiculous despite being the least ridiculous example I could think of. IoT security cameras and an automated kitchen y…

It doesn’t matter whether you know of any use cases or not. Somebody else does. Don’t interfere with their liberties.

>Don’t interfere with their liberties.

that's well and good until they cause negative externalities

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#94

China already ignores safety and radio regulations. Sure, add more. They'll keep flooding Amazon and eBay with cheap crap and people will keep buying it. Good IoT will just become even more expensive. The only way to avoid a botnet apocalypse is to secure home routers. Outbound traffic should not be an automatic right. People should have to authorise each device for each type of traffic. I argued this long-hand when…

> People should have to authorise each device for each type of traffic

Nobody wants to do this. I'm a quarter way paranoid about electronic security and even I don't want to do this.

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#95

One simple way to improve your security at home is to have a "guest" WiFi network which is separate from your real one and which all these questionable IoT devices can use.

This is called network segmentation and it's the direction that the network security industry is moving.

It will be more complicated than just 2 networks and it should be based on behavior and trust rather than device type. Consumers don't yet have the tools to monitor/categorize devices based on behavior, but some corporations (like mine) offer platforms that automatically move risky devices to network segments to mitigate risk.

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#96
post #88
post #20

Even though many people scoff at the idea of government regulations, the economic incentives in IoT security are really all messed up and it's not really clear that the market will fix itself because so much of the damage can be externalized somehow. Does the manufacturer of a cheap and outdated IoT device care if it's participating in some ddos attack? Or like Schneier said, does the consumers care if they don't not…

> One thing that could hurt the market is maybe making manufacturers liable for the damages caused by security holes in their devices That's what insurance is for. Something like this was discussed in my torts class in law school, except that was long before IoT devices existed so it was about things like lawn mowers. The idea is that it might make the most sense economically to make the lawn mower manufacturer liabl…

How do you deal with insurance fraud if the manufacturer is the one paying for the insurance?

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#97
post #88
post #20

Even though many people scoff at the idea of government regulations, the economic incentives in IoT security are really all messed up and it's not really clear that the market will fix itself because so much of the damage can be externalized somehow. Does the manufacturer of a cheap and outdated IoT device care if it's participating in some ddos attack? Or like Schneier said, does the consumers care if they don't not…

> One thing that could hurt the market is maybe making manufacturers liable for the damages caused by security holes in their devices That's what insurance is for. Something like this was discussed in my torts class in law school, except that was long before IoT devices existed so it was about things like lawn mowers. The idea is that it might make the most sense economically to make the lawn mower manufacturer liabl…

Doesn't that mean that every single insurance payout will have to involve the courts, taking a long time and not always panning out? If I have an accident I probably need the money on the kind of time-scale that my bills are due on, not the time scale on which courts operate. Even then, that's ignoring the huge overhead introduced.

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#98
post #88
post #20

Even though many people scoff at the idea of government regulations, the economic incentives in IoT security are really all messed up and it's not really clear that the market will fix itself because so much of the damage can be externalized somehow. Does the manufacturer of a cheap and outdated IoT device care if it's participating in some ddos attack? Or like Schneier said, does the consumers care if they don't not…

> One thing that could hurt the market is maybe making manufacturers liable for the damages caused by security holes in their devices That's what insurance is for. Something like this was discussed in my torts class in law school, except that was long before IoT devices existed so it was about things like lawn mowers. The idea is that it might make the most sense economically to make the lawn mower manufacturer liabl…

> That's what insurance is for

What are the outcomes for using insurance, and what are the outcomes for using regulation? Does anyone know the answers in a technical policy sense (not in a philosophical sense)? They are different tools useful for different problems.

Thinking out loud, insurance seems like a poor solution when people will suffer serious, irreparable harm. If the lawnmower severs a foot, then an insurance payout isn't really sufficient; regulations should prevent that from happening in the first place. More broadly, my point is that there are larger issues than economics.

> Presumably, the manufacturer will pass on the costs of those insurance premiums to the consumers.

In economics, that is not the case. Businesses don't price goods at 'cost-plus'; they don't look at their costs and add a profit margin. Think of the soda at the movie theater on one hand, and on the other the car being sold at a loss because the market is soft; think of software. Like all businesses, the lawnmower manufacturer already is pricing their product at the level that maximizes total sales revenue, which depends on supply and demand; raising the price will reduce revenue (probably because unit volume will decrease too much to be compensated for by per-unit revenue increase). If they could raise the price and bring in more revenue, they would have done that already.

There is an issue of elasticity: If your customers' alternatives are limited - i.e., if they can't go without your product, if there are limited competitors and substitutes - then you can raise prices more easily. A Van Gogh painting is highly inelastic; lawnmowers are much less so.

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#99

There are two pieces here, and Schneier (or at least this tiny summary of him) is wrong on both. First, yes of course automobiles are regulated and should be. The fact that some things that are and should be regulated include embedded internet hosts does not mean that all devices that include embedded internet hosts should be regulated. This is basic logic. Second, holding one set of botnet victims responsible for th…

> consider that ISPs have lots of money and they actually could reduce DOS attacks; why not hold them responsible?

You could hold ISPs liable, and they would block untrusted IoT garbage at the network level. Or you could hold IoT garbage producers liable, and they would make security changes and/or pay ISPs to do some firewalling. Either way, the costs and results will probably turn out about the same.

The best solution, of course, would be having fewer things uselessly connected to the internet.

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#100

China already ignores safety and radio regulations. Sure, add more. They'll keep flooding Amazon and eBay with cheap crap and people will keep buying it. Good IoT will just become even more expensive. The only way to avoid a botnet apocalypse is to secure home routers. Outbound traffic should not be an automatic right. People should have to authorise each device for each type of traffic. I argued this long-hand when…

> People should have to authorise each device for each type of traffic.

Seems somewhat unreasonable to expect people to know what traffic a device needs, and if you ask too much, people will just default to allowing it without even thinking about it (I still occasionally see people suggesting using a DMZ to make online games work, rather than forwarding the necessary ports [and even that seems rarely required]).

Post reply on HN