Live data from Hacker News

Schneier: It's Time to Regulate IoT to Improve Cyber-Security

eweek.com

121–130 of 185 posts

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#121
post #3

Not that I'm a fan of government regulation for technology issues like this but the security situation is beyond a joke. For one, it's time to hold companies (and executives!) accountable for security of the data they are charged with protecting, often without your consent (eg Equifax). For another, insufficient product liability for companies being lax--even negligent--with security. Honestly I don't see an outcome…

> And all for what? So you can turn the lights on after you go through multiple steps to unlock your phone?

The fact that they're IoT devices is kind of irrelevant, as is their function. The underlying question is: to what extent should manufacturers be made responsible for the damage their products cause?

If you make an electric heater that routinely combusts during normal operation, your customers and the state have some recourse against you – not that it would happen, because there are generally standards in that industry. But if you make a device that quietly becomes part of a botnet, you really aren't going to suffer; even the reputational issues are generally minimal.

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#122

On the surface, I agree with this. In practice I expect it to result in fewer products on the market that are more expensive and no more secure as this sort of regulation will simply select for large companies who are experts at paperwork and soft bribes. I wish I had a better idea.

> I wish I had a better idea Something that already works are various forms of certification. Examples are: * "Norton protected" on websites * Underwriters Laboratories on US products * US DOD Trusted Computer System Evaluation Critera for how the US military checks the security of a product * ISO 9001 for quality management * Oregon Tilth for certifying organic products Some of these are more valuable than others, b…

What about VW though? They got around regulation.

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#123

On the surface, I agree with this. In practice I expect it to result in fewer products on the market that are more expensive and no more secure as this sort of regulation will simply select for large companies who are experts at paperwork and soft bribes. I wish I had a better idea.

> this sort of regulation will simply select for large companies who are experts at paperwork and soft bribes.

Which are exactly the kind of companies who can do good engineering, so why wouldn't they do that instead?

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#124

Watch this go terribly wrong. Honestly, I don't understand why consumers lack the restraint to simply not buy unfinished products, but this is where the leverage to improve IoT security has to come from. If today's IoT devices are such a liability, then prove it in court; but don't think that you can write a law that ensures security instead of mere standardization. Meticulously studying the introduction and effects…

It can be all but impossible to do so (try finding a "dumb" major appliance currently), nor can buyers deterrmine or distinguish what is or isn't "finished", or what will be supported in 18 months, let alone 18 years.

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#125
post #23

This is also a business model problem. Consumer hardware companies do not have the margin to make and support software that needs to run for ten years or more. Before the iPhone, software and hardware were often different and had different business models.

So ... how do you fix, or route around, the bad business model?

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#126

Earlier quoted context omitted.

> That's what insurance is for What are the outcomes for using insurance, and what are the outcomes for using regulation? Does anyone know the answers in a technical policy sense (not in a philosophical sense)? They are different tools useful for different problems. Thinking out loud, insurance seems like a poor solution when people will suffer serious, irreparable harm. If the lawnmower severs a foot, then an insura…

> What are the outcomes for using insurance, and what are the outcomes for using regulation? Bad question, false dichotomy: these are not apples-to-apples comparisons. How about some minimal regulations that include an insurance requirement?

Even "insurance" is a distraction, the argument is really about tort law (which raises the insurance rates, case by case.) Note that ordinary risks aren't economically insurable, almost by definition, so corporations insure far less than most people would guess. A building burning down is an ordinary risk for a conglomerate so it may not be insured - insurance is too expensive since the company can more cheaply absorb the risk itself.)

So I agree: yes, the existence of tort law sometimes obviates the need for regulation; but has hardly banished regulation or the need for it entire!

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#127
post #88
post #20

Even though many people scoff at the idea of government regulations, the economic incentives in IoT security are really all messed up and it's not really clear that the market will fix itself because so much of the damage can be externalized somehow. Does the manufacturer of a cheap and outdated IoT device care if it's participating in some ddos attack? Or like Schneier said, does the consumers care if they don't not…

> One thing that could hurt the market is maybe making manufacturers liable for the damages caused by security holes in their devices That's what insurance is for. Something like this was discussed in my torts class in law school, except that was long before IoT devices existed so it was about things like lawn mowers. The idea is that it might make the most sense economically to make the lawn mower manufacturer liabl…

[deleted]

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#128

On the surface, I agree with this. In practice I expect it to result in fewer products on the market that are more expensive and no more secure as this sort of regulation will simply select for large companies who are experts at paperwork and soft bribes. I wish I had a better idea.

How does regulation work in the aviation industry? The impression I have is that regulation in that space is pretty effective. Without effective regulation I imagine you'd see aircraft falling out of the sky left and right because - and let's be honest here - safety is probably at the bottom of the priorities, both for manufacturers and airline operators. Most people don't believe that accidents can happen to them. P…

> and let's be honest here - safety is probably at the bottom of the priorities, both for manufacturers and airline operators

The bottom, really? That's a pretty bold statement to make, and a disservice to the work those have done to ensure we have thousands of safe flights every single day. I'm certainly not arguing against airline regulation, but I don't believe that's the only thing holding them back from crashing planes on the regular.

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#129
post #88
post #20

Even though many people scoff at the idea of government regulations, the economic incentives in IoT security are really all messed up and it's not really clear that the market will fix itself because so much of the damage can be externalized somehow. Does the manufacturer of a cheap and outdated IoT device care if it's participating in some ddos attack? Or like Schneier said, does the consumers care if they don't not…

> One thing that could hurt the market is maybe making manufacturers liable for the damages caused by security holes in their devices That's what insurance is for. Something like this was discussed in my torts class in law school, except that was long before IoT devices existed so it was about things like lawn mowers. The idea is that it might make the most sense economically to make the lawn mower manufacturer liabl…

> I'm not sure it could work for IoT, though, because a lot of IoT devices are made by new companies that probably will not be around long.

If we regulate insurance so that a product needs to be backed by a 10-year liability insurance, it might have 2 good outcomes to fix this:

1) the insurance company might ask a lot of hard questions and require audits, plans, etc 2) the insurance company might require escrow to the iot device's update mechanism in case of bankruptcy, so they can remote-brick the devices

It's unlikely that the reality would be so rosy though - mainly the claims against the insurance would likely be too small in many cases. It might help in 10 years against the biggest ddos botnets. Not nearly as good as direct regulation.

Re: Schneier: It's Time to Regulate IoT to Improve Cyber-Security

#130
post #20

Even though many people scoff at the idea of government regulations, the economic incentives in IoT security are really all messed up and it's not really clear that the market will fix itself because so much of the damage can be externalized somehow. Does the manufacturer of a cheap and outdated IoT device care if it's participating in some ddos attack? Or like Schneier said, does the consumers care if they don't not…

> opening the source code once security updates for the device stop, so consumers could help themselves That might help the readers of HN, but not users in general. Most users won't bother installing security updates for their PC if it's not forced on them. Updating one's light bulbs with something off github is a non-starter.

That right there is the problem that regulation is meant to solve. The manufacturer is the one in position to enable ease of _secure_ updates. Right now the manufacturers are not doing that.

Try walking into Home Depot and asking the salesperson how to update the firmware on the lightbulbs he is selling. You will get your sanity questioned, especially once you explain _why_ it is important to update.

Post reply on HN