Live data from Hacker News

Schneier: It's Time to Regulate IoT to Improve Cyber-Security

eweek.com

101–110 of 185 posts

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#101

IoT is a solution that has been looking for a problem for at least 20 years now. It's like every EE department in existence feels compelled to cram micros and ethernet into every toaster, thermostat and lightbulb. I guess it only took this long for enough people to become insane enough to justify a market for it. Preach on brother Bruce!

I'm surprised more people aren't willing to consider not having the IoT as the solution. It doesn't look like we'll get a decent solution to security anytime soon and the average person doesn't seem to get much out it anyway. It's just more trouble than it's worth.

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#102

One simple way to improve your security at home is to have a "guest" WiFi network which is separate from your real one and which all these questionable IoT devices can use.

That's precisely what I do - all of my trusted devices are behind a second router[0], with anything untrusted (family devices, devices that only need Internet access and not e.g. access to my NAS) being effectively treated as if they weren't on my local network.

Far from bulletproof though - it limits risk, but does nothing to prevent those trusted devices from becoming infecting and having essentially free-reign (which when you use Windows as your main OS is far from a theoretical concern).

[0] Introduces a double-NAT, which isn't ideal, but hasn't caused me any issues in practice.

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#103
post #20

Even though many people scoff at the idea of government regulations, the economic incentives in IoT security are really all messed up and it's not really clear that the market will fix itself because so much of the damage can be externalized somehow. Does the manufacturer of a cheap and outdated IoT device care if it's participating in some ddos attack? Or like Schneier said, does the consumers care if they don't not…

> maybe making manufacturers liable for the damages caused by security holes in their devices

Then they will sell two versions of the same product. One lets you voluntarily waive that requirement for the same price as today, or a "normal" version where it costs orders of magnitude more.

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#104
post #43
post #20

Even though many people scoff at the idea of government regulations, the economic incentives in IoT security are really all messed up and it's not really clear that the market will fix itself because so much of the damage can be externalized somehow. Does the manufacturer of a cheap and outdated IoT device care if it's participating in some ddos attack? Or like Schneier said, does the consumers care if they don't not…

demanding opening the source code once security updates for the device stop They probably don't even have the (usable) source code.

Well, they probably would if they had an incentive to do so.

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#105

On the surface, I agree with this. In practice I expect it to result in fewer products on the market that are more expensive and no more secure as this sort of regulation will simply select for large companies who are experts at paperwork and soft bribes. I wish I had a better idea.

> I wish I had a better idea

Something that already works are various forms of certification.

Examples are:

* "Norton protected" on websites

* Underwriters Laboratories on US products

* US DOD Trusted Computer System Evaluation Critera for how the US military checks the security of a product

* ISO 9001 for quality management

* Oregon Tilth for certifying organic products

Some of these are more valuable than others, but are at least a separate stamp of approval.

With my magic wand I'd have a group come together to form such a certifying organisation and provide it with a marketing budget. The marketing would mirror the success of "check for a green padlock on a website to know it is secure" - look for the stamp on a product box.

If that doesn't happen and there are more serious incidents is that consumers would look to Google, Apple, Amazon etc. eg if the proposed device doesn't work with the Apple hub and been vetted by Apple, then they wouldn't buy it.

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#106
We can think of the Internet as a public resource, like the electromagnetic spectrum.[0] The FCC regulates what can use the spectrum, requiring that devices do so safely, in a manner that will not interfere with other devices or cause harm to people or property. The same could (and I think should) be required of devices that connect to the Internet.

Frankly, I'm tired of trying to find time to find specs (and then learn how it really works) to figure that out for myself; I secretly dread receiving anything networked for the holidays. It's difficult for me; most end-users have no hope of protecting themselves - and they seem to assume that any product sold must be safe. They assume it is regulated, in effect.

[0] Arguably the Internet is physically different than spectrum. Physics 'creates' the spectrum and its physical limitations make it a public good; there are only so many frequencies, and propagation is part of the equation. The Internet is a creation of humans and in theory can be recreated or modified at will. But that theory isn't realistic: The Internet cannot be replaced or substantially modified; the public has no realistic option of using a different Internet if they don't like this one. In any practical sense, it's a public good.

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#107
post #73

Earlier quoted context omitted.

It also encourages the tiering of IoT such that insecure-and-cheap remains on the market and is pushed towards people who can least afford to be pwned. Regulation is not blind, but it does raise the floor.

"least afford"??? As though these IoT devices weren't pure bored yuppie disposable income in the first place? I would figure large service providers, and big companies with fleets of marginally protected devices, would be the ones to bear most of the damages coming from shoddy IoT devices being pwned and rolled into larger ddos/ransomware/etc attacks.

At the moment, yes, they are at the high end of the market. In three years, you can expect that to be either in the process of moving downmarket. In five, they will be comfortably midmarket and still moving downward. And, the cheaper the device, the more corners cut in production. The more corners cut, the higher the likelihood that at least some of them are in terms of security.

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#108

Earlier quoted context omitted.

"least afford"??? As though these IoT devices weren't pure bored yuppie disposable income in the first place? I would figure large service providers, and big companies with fleets of marginally protected devices, would be the ones to bear most of the damages coming from shoddy IoT devices being pwned and rolled into larger ddos/ransomware/etc attacks.

At the moment, yes, they are at the high end of the market. In three years, you can expect that to be either in the process of moving downmarket. In five, they will be comfortably midmarket and still moving downward. And, the cheaper the device, the more corners cut in production. The more corners cut, the higher the likelihood that at least some of them are in terms of security.

We are governed by people who have trouble agreeing that 30 year olds propositioning minors is a bad thing.

I just think broadening the concept of liability in our industry to the point where some company's negligence is finally made an example of has a much better chance of improving things than a panel of regulatory agency appointees that have either already been paid as industry lobbyists, or are operating under the carrot of a future position as a highly-paid exec--just like the FCC, or Robert Rubin, or any of Trump's appointees, or so many others...

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#109

On the surface, I agree with this. In practice I expect it to result in fewer products on the market that are more expensive and no more secure as this sort of regulation will simply select for large companies who are experts at paperwork and soft bribes. I wish I had a better idea.

How does regulation work in the aviation industry? The impression I have is that regulation in that space is pretty effective.

Without effective regulation I imagine you'd see aircraft falling out of the sky left and right because - and let's be honest here - safety is probably at the bottom of the priorities, both for manufacturers and airline operators.

Most people don't believe that accidents can happen to them. People rationalize the risk away, so they skimp on security to save a buck.

So, operators don't have incentive to maintain and upgrade their aircraft because that has only a negligible effect on performance, but costs a ton and the perceived risk is low. Manufacturers, likewise, have no incentive to produce safer airplanes because safety doesn't sell: range, capacity and fuel efficiency do.

Yet, air travel as never been safer. Seems to me like regulation works ok in this case.

Post reply on HN