IoT is a solution that has been looking for a problem for at least 20 years now. It's like every EE department in existence feels compelled to cram micros and ethernet into every toaster, thermostat and lightbulb. I guess it only took this long for enough people to become insane enough to justify a market for it. Preach on brother Bruce!
Schneier: It's Time to Regulate IoT to Improve Cyber-Security
101–110 of 185 posts
Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security
#102One simple way to improve your security at home is to have a "guest" WiFi network which is separate from your real one and which all these questionable IoT devices can use.
Far from bulletproof though - it limits risk, but does nothing to prevent those trusted devices from becoming infecting and having essentially free-reign (which when you use Windows as your main OS is far from a theoretical concern).
[0] Introduces a double-NAT, which isn't ideal, but hasn't caused me any issues in practice.
Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security
#103Even though many people scoff at the idea of government regulations, the economic incentives in IoT security are really all messed up and it's not really clear that the market will fix itself because so much of the damage can be externalized somehow. Does the manufacturer of a cheap and outdated IoT device care if it's participating in some ddos attack? Or like Schneier said, does the consumers care if they don't not…
Then they will sell two versions of the same product. One lets you voluntarily waive that requirement for the same price as today, or a "normal" version where it costs orders of magnitude more.
Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security
#104Even though many people scoff at the idea of government regulations, the economic incentives in IoT security are really all messed up and it's not really clear that the market will fix itself because so much of the damage can be externalized somehow. Does the manufacturer of a cheap and outdated IoT device care if it's participating in some ddos attack? Or like Schneier said, does the consumers care if they don't not…
demanding opening the source code once security updates for the device stop They probably don't even have the (usable) source code.
Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security
#105On the surface, I agree with this. In practice I expect it to result in fewer products on the market that are more expensive and no more secure as this sort of regulation will simply select for large companies who are experts at paperwork and soft bribes. I wish I had a better idea.
Something that already works are various forms of certification.
Examples are:
* "Norton protected" on websites
* Underwriters Laboratories on US products
* US DOD Trusted Computer System Evaluation Critera for how the US military checks the security of a product
* ISO 9001 for quality management
* Oregon Tilth for certifying organic products
Some of these are more valuable than others, but are at least a separate stamp of approval.
With my magic wand I'd have a group come together to form such a certifying organisation and provide it with a marketing budget. The marketing would mirror the success of "check for a green padlock on a website to know it is secure" - look for the stamp on a product box.
If that doesn't happen and there are more serious incidents is that consumers would look to Google, Apple, Amazon etc. eg if the proposed device doesn't work with the Apple hub and been vetted by Apple, then they wouldn't buy it.
Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security
#106Frankly, I'm tired of trying to find time to find specs (and then learn how it really works) to figure that out for myself; I secretly dread receiving anything networked for the holidays. It's difficult for me; most end-users have no hope of protecting themselves - and they seem to assume that any product sold must be safe. They assume it is regulated, in effect.
[0] Arguably the Internet is physically different than spectrum. Physics 'creates' the spectrum and its physical limitations make it a public good; there are only so many frequencies, and propagation is part of the equation. The Internet is a creation of humans and in theory can be recreated or modified at will. But that theory isn't realistic: The Internet cannot be replaced or substantially modified; the public has no realistic option of using a different Internet if they don't like this one. In any practical sense, it's a public good.
Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security
#107Earlier quoted context omitted.
It also encourages the tiering of IoT such that insecure-and-cheap remains on the market and is pushed towards people who can least afford to be pwned. Regulation is not blind, but it does raise the floor.
"least afford"??? As though these IoT devices weren't pure bored yuppie disposable income in the first place? I would figure large service providers, and big companies with fleets of marginally protected devices, would be the ones to bear most of the damages coming from shoddy IoT devices being pwned and rolled into larger ddos/ransomware/etc attacks.
Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security
#108Earlier quoted context omitted.
"least afford"??? As though these IoT devices weren't pure bored yuppie disposable income in the first place? I would figure large service providers, and big companies with fleets of marginally protected devices, would be the ones to bear most of the damages coming from shoddy IoT devices being pwned and rolled into larger ddos/ransomware/etc attacks.
At the moment, yes, they are at the high end of the market. In three years, you can expect that to be either in the process of moving downmarket. In five, they will be comfortably midmarket and still moving downward. And, the cheaper the device, the more corners cut in production. The more corners cut, the higher the likelihood that at least some of them are in terms of security.
I just think broadening the concept of liability in our industry to the point where some company's negligence is finally made an example of has a much better chance of improving things than a panel of regulatory agency appointees that have either already been paid as industry lobbyists, or are operating under the carrot of a future position as a highly-paid exec--just like the FCC, or Robert Rubin, or any of Trump's appointees, or so many others...
Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security
#109On the surface, I agree with this. In practice I expect it to result in fewer products on the market that are more expensive and no more secure as this sort of regulation will simply select for large companies who are experts at paperwork and soft bribes. I wish I had a better idea.
Without effective regulation I imagine you'd see aircraft falling out of the sky left and right because - and let's be honest here - safety is probably at the bottom of the priorities, both for manufacturers and airline operators.
Most people don't believe that accidents can happen to them. People rationalize the risk away, so they skimp on security to save a buck.
So, operators don't have incentive to maintain and upgrade their aircraft because that has only a negligible effect on performance, but costs a ton and the perceived risk is low. Manufacturers, likewise, have no incentive to produce safer airplanes because safety doesn't sell: range, capacity and fuel efficiency do.
Yet, air travel as never been safer. Seems to me like regulation works ok in this case.